Every story tagged Apt28, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
2 stories · open in the command center
North Korean state-sponsored hackers stole $290M in cryptocurrency from Kelp DAO by exploiting weak multi-signature security controls in cross-blockchain bridge infrastructure, marking the largest crypto theft of 2026. This attack underscores the escalating sophistication of nation-state threat actors targeting financial systems, with North Korea having stolen over $6 billion in crypto since 2017 to fund its regime. The incident highlights critical vulnerabilities in third-party integrations and multi-party verification systems that extend beyond cryptocurrency to any distributed digital asset infrastructure.
Russian military intelligence (GRU/APT28) has compromised 18,000-40,000 consumer routers globally to conduct sophisticated man-in-the-middle attacks targeting government and enterprise credentials, exploiting unpatched legacy devices and rapidly adapting tactics after public disclosures to harvest OAuth tokens and bypass multi-factor authentication. This represents a critical supply-chain security risk where consumer-grade infrastructure becomes a pivot point for targeting high-value government and enterprise networks, exposing the vulnerability of organizations whose security postures depend on third-party devices beyond their direct control. IT leaders must recognize that network perimeter defenses are insufficient when adversary-controlled infrastructure can intercept encrypted traffic and credentials—necessitating zero-trust architecture, continuous authentication verification, and aggressive device lifecycle management.