SecurityWeek reports that North Korean hackers have leveraged fraudulent job offers to compromise freelance software developers with malicious payloads as part of the DeceptiveDevelopment attack campaign, which has been underway since early last year.
Security researchers confirmed the malware’s nature after analyzing samples that mimicked popular apps such as WhatsApp as well as cellphone provider customer support tools.
First of the free tools is a comprehensive Semgrep and Opengrep ruleset that could be used in continuous integration and continuous deployment pipelines, which has yielded 94.3% and 88.4% accuracy in identifying nefarious code in PyPI and NPM packages, respectively.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.