Sign in to baba News

The Desk, the news read to you every hour, is part of News Plus.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Sign in to baba News

One account across the web, iPhone and Android — your subscription follows it.

or use an email code

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Search stories

Type at least two characters. Results come from every newsroom baba reads.

↑↓ to move · ↵ to open · esc to close

Sign in to baba News

Sign in to keep asking. News Plus removes the daily limit.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

North Korean Hackers Use Fake LinkedIn Job Offers to Breach Security Systems

By דיגיטל
Translated & summarized from N12 by baba
The story · English

Cybersecurity researchers at Check Point have uncovered a new cyberattack campaign by the North Korean-linked hacker group Lazarus, targeting defense, aerospace, and security organizations. The campaign, dubbed Operation Dream Job, uses fake job offers sent via LinkedIn and messaging apps to trick employees into opening malicious files or installing malware. Victims receive seemingly legitimate job descriptions from well-known companies, but the attached files contain software that enables attackers to infiltrate their computers.

The attackers exploited a previously unknown Windows zero-day vulnerability (CVE-2026-68820) that allows privilege escalation after malware execution, granting them system-level control. Check Point reported the flaw to Microsoft on July 28, 2026; Microsoft confirmed it and released a patch on August 11, 2026. The malware, named Troy, functions as a backdoor with 17 commands, including file search, upload/download, process termination, and remote code execution.

Lazarus also used compromised legitimate infrastructure such as hacked websites, webmail servers, and CMS platforms to relay commands, making detection difficult. Some servers were breached using leaked credentials or unpatched vulnerabilities, and attackers even leveraged already compromised organizations to send phishing messages to new victims, exploiting their reputation.

Check Point emphasized the sophistication of the campaign, noting that the attackers combined legitimate branding, high search rankings, and trusted infrastructure to mask their operations. They advised organizations to immediately apply security updates, verify software sources, monitor network traffic for anomalies, and adopt a zero-trust approach even toward seemingly trustworthy sites and partners.

Lazarus is known for long-term espionage and financially motivated attacks, often impersonating recruiters to target sensitive industries. This campaign highlights the evolving complexity of cyber threats where trust can be forged and weaponized to breach critical systems.

Read the original at N12

Keep up with

N12Centre · Neve Ilan

Sign in to baba News

Sign in to follow newsrooms, topics and people.

or use an email code

You’ve used your five follows

News Plus follows as many newsrooms, topics and people as you like.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal
See News Plus

Sign in to baba News

Sign in to follow newsrooms, topics and people.

or use an email code

You’ve used your five follows

News Plus follows as many newsrooms, topics and people as you like.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal
See News Plus
Open the live terminal