Threat Brief — 2026-08-01 — Zero-click watering holes, DPRK supply chain
South Korean authorities warn of zero-click compromise through hacked news and medical sites, while the DPRK-linked npm supply-chain attack has expanded to four JavaScript packages. Separately, the Flying Eagle Android RAT infrastructure has grown to 170 detected servers. A new LLM jailbreak-resistance rating and Google's restriction of RuStore abroad round out the day.
Top items
- Zero-click watering-hole infections via hacked news and medical sites. South Korea warns that simply visiting compromised news and hospital websites can leak all stored passwords — no clicks or downloads required. This is a high-severity drive-by model that could affect any organisation whose users browse affected sites from corporate networks. (src: securitylab-ru)
- DPRK Sapphire Sleet npm supply-chain attack expands to four packages. Amazon now attributes the hijacking of four popular JavaScript packages to North Korean threat actors, a development beyond the original debug-and-chalk scope first reported 2026-07-30 by The Hacker News. Organisations consuming npm dependencies should audit for the affected packages. (src: securitylab-ru) — Developing; first reported 2026-07-30 by The Hacker News.
- Flying Eagle Android RAT infrastructure reaches 170 servers. Researchers have identified 170 active servers for the Flying Eagle malicious platform, which impersonates law-enforcement apps to harvest financial credentials. This extends the story first reported 2026-07-29 by The Hacker News about the source leak evolving into malware-as-a-service. (src: securitylab-ru) — Developing; first reported 2026-07-29 by The Hacker News.
- FAR.AI publishes first LLM jailbreak-resistance rating. The inaugural model-security benchmark ranks major language models on their susceptibility to guardrail bypass — with one example reportedly generating instructions for building a nuclear device for $58. Relevant for teams deploying or evaluating LLM-powered tooling. (src: securitylab-ru)
- Google to effectively block RuStore app distribution outside Russia. New Android installation rules will make distributing apps from Russia's RuStore nearly impossible abroad, effectively quarantining Russian-origin mobile software to a domestic audience. Low direct technical risk but notable for geopolitical supply-chain fragmentation. (src: securitylab-ru)
Themes
Supply-chain trust erosion continues. The DPRK npm hijack expansion and Flying Eagle's server growth both illustrate adversaries weaponising trusted distribution channels — package registries and app stores alike. Combined with Google's geo-fencing of RuStore, the pattern underscores afragmenting global software ecosystem where origin and provenance increasingly determine access.
===
THREAT-TOPICS===
[{"slug":"zero-click-watering-hole-south-korea","headline":"Zero-click drive-by infections via hacked news and medical sites","findingIds":[4716],"status":"new"},{"slug":"npm-debug-chalk-hijack-attributed-north-korea-sapphire-sleet","headline":"DPRK Sapphire Sleet npm attack expands to four JavaScript packages","findingIds":[4717],"status":"developing","development":"Scope widened from debug and chalk to four popular JS packages per Amazon attribution"},{"slug":"flying-eagle-android-rat-source-leak","headline":"Flying Eagle RAT infrastructure grows to 170 detected servers","findingIds":[4715],"status":"developing","development":"170 active servers discovered, expanding beyond initial source-leak report"},{"slug":"far-ai-llm-jailbreak-rating","headline":"FAR.AI releases first LLM jailbreak-resistance benchmark","findingIds":[4719],"status":"new"},{"slug":"rustore-google-geo-restriction","headline":"Google moves to block RuStore app distribution outside Russia","findingIds":[4718],"status":"new"}]
