DarkSword emerges, “ShieldGuard” dismantled, NK IT worker army rakes in money

DarkSword emerges from suspected Russian hackers “ShieldGuard” dismantled after malware discovery North Korea’s fake IT worker army rakes in $500M/year Get links to all our stories in the show notes: https://cisoseries.com/cybersecurity-news-darksword-emerges-shieldguard-dismantled-nk-it-worker-army-rakes-in-money/ Huge thanks to our episode sponsor, Adaptive Security This…

SnappyClient Implant Blends Remote Access, Data Theft, and Stealth Evasion

A powerful new C2 implant called SnappyClient that blends remote access, credential theft, and stealthy evasion into a single, modular framework targeting Windows systems and cryptocurrency users.​ ThreatLabz first observed SnappyClient in December 2025, being deployed via the well-known HijackLoader malware family.…

Cisco Firewall Zero-Day Actively Exploited to Deliver Interlock Ransomware

Security research has uncovered an active Interlock ransomware campaign exploiting a critical zero-day vulnerability in Cisco Secure Firewall Management Centre (FMC) software. Utilizing this unauthenticated remote code execution flaw via the Amazon MadPot network, threat actors compromised enterprise environments for…