๐ต๏ธ RESEARCH & DEEP DIVES
- DPRK Job Fraud Expands Beyond IT Into Healthcare, Sales and Marketing
DPRK-linked actors are using fraudulent hires to enter healthcare, sales and marketing roles.- Australian healthcare, financial services, sales and marketing employers have been affected.
- DPRK-linked workers used stolen or forged identities to obtain remote jobs beyond traditional IT roles.
- Investigators found Astrill VPN, IPRoyal Proxy and fraudulent identity documents in an Australian healthcare case.
- A financial-services laptop contained PiKVM and a Guermok USB capture card linked to remote laptop-farm access.
- PurpleDelta used 22 fabricated personas, AI tools and TrustID Card documents while applying to more than 1,100 companies.
๐ Source: huntress.com ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
๐ CVEs & KEV
-
CVE-2026-79748 โ CVSS 9.9 โ MCPHub: Authenticated non-admin user achieves RCE via POST /api/servers (miss...
-
CVE-2026-79744 โ CVSS 8.8 โ MCPHub: Missing Authorization on
PUT /api/system-configLets Any Non-Admin ... -
CVE-2026-79746 โ CVSS 8.1 โ MCPHub: Server-scoped bearer key gains access to an entire group via partial ...
-
CVE-2026-79750 โ CVSS 7.7 โ MCPHub authenticated horizontal IDOR: any non-admin user executes tools on ot...
-
CVE-2026-79749 โ CVSS 7.6 โ MCPHub: SSRF Guard Bypass via IPv6 Transition Addresses in URL ValidationMCPH...
-
CVE-2026-79745 โ CVSS 7.1 โ MCPHub: Missing Authorization on Built-in Prompt & Resource CRUD (Unauthorize...
-
CVE-2026-79747 โ CVSS 7.1 โ MCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary...
-
CVE-2026-79743 โ CVSS 6.9 โ MCPHub: Path Traversal via Malicious MCPB Manifest NameMCPHub is a unified hu...