‘It reads like a spy novel’: $280 million theft from Drift involved North Korean fake companies, cutouts
Drift officials said the operation began six months ago, when they were approached at a cryptocurrency conference by members of a company claiming to focus on quantitative trading.
Related Vulnerabilities
- CVE-2026-35601: Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output MEDIUM
- CVE-2026-34477: The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: i MEDIUM
- CVE-2026-5503: In TLSX_EchChangeSNI, the ctx->extensions branch set extensions unconditionally even when TLSX_Find MEDIUM
- CVE-2026-6012: A security vulnerability has been detected in D-Link DIR-513 1.10. This affects the function formSet HIGH
- CVE-2026-40190: LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in I MEDIUM
Related Coverage
Threat Actors