LogoLogo

Podcasts

Newsletters

Videos

Catalog

People

About

Search

Risky Bulletin Newsletter

August 12, 2026

Risky Bulletin: Russian hackers adopt the fake job interview tactics

Written by

Catalin Cimpanu
Catalin Cimpanu

News Editor

This newsletter is brought to you by enterprise browser maker Island. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.

One of Russia's elite military hacker groups is targeting system administrators and IT professionals in Ukraine using fake job interviews as a malware delivery vector.

Ukraine's CERT says the campaign began in May and is ongoing.

The attacks have been linked to UAC-0145, a sub-group of Sandworm, a veteran cyber unit inside Russia's GRU military intelligence agency.

Using fake job interviews as a malware delivery vector has been a popular tactic used by Iran and North Korea for several years. It's been used initially for cyber-espionage, but is now a popular entry vector for many of North Korea's financially-motivated operations, especially the ones targeting the cryptocurrency and Web3 developer community. China has also done this, but they usually use job interviews to recruit insiders, rather than hack their targets.

As for the attacks targeting Ukrainian IT admins, they aren't anything particularly special or extraordinary, when compared to what we've seen from the DPRK and Iran.

GRU hackers scour job portals for individuals advertising their skills as IT professionals, contact them off-site, usually via Telegram, and arrange a job interview.

The interview will involve completing several tests and tasks that will generally involve downloading special apps. These will deploy malware on the interviewee's system.

According to CERT-UA, UAC-0145 has both Windows and Linux malware on hand, to make sure they score a hit.

While this phase hasn't been detailed by Ukrainian investigators, the hackers will likely use the infected IT professional to collect passwords and credentials, and then pivot into other networks they might be managing.

The goal is likely to find companies or government networks from where the hackers could collect any kind of intelligence that might help Russia on the battlefield or in other ways, such as supply chain attacks or mounting other cyberattacks from compromised but legitimate infrastructure.

CERT-UA warns local IT professionals to be wary of the job offers they get.

Risky Business Podcasts

In this edition of Between Two Nerds, Tom Uren and The Grugq talk about examples of cyber resistance and whether they achieve their goals.


Breaches, hacks, and security incidents

Airplane WiFi hacked by naughty DEFCON participants: A Delta Airlines plane flying from Las Vegas to Atlanta was forced to shut down its passenger WiFi network due to a hack. The pilot turned off the WiFi signal after he was notified by the flight crew that a passenger jammed the plane's WiFi and was running their own network with an identical name. In a message sent to ground control, the pilot blamed the incident on passengers traveling home from the DEFCON security conference. [FOX5 Atlanta // View from the Wing // Reddit]

Air to Ground Message: NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFRENCE IN LAS THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL Area: Liberal, KS, USA Type: Boeing 757-200 A: #aadee4f6c99 F: #fdcd8d51430

— ACARS Drama (@acarsdrama.bsky.social) August 10, 2026 at 7:54 PM

CEVA breach impacts shipping across Europe: A cybersecurity breach at French shipping and logistics company CEVA is impacting freight delivery across large parts of Europe. The incident took place last week after hackers gained access to CEVA's systems and started leaking customer data on the dark web. Companies impacted by the hack include Valve's Steam hardware business, and Dutch online retailers Bol and De Bijenkorf. Many affected companies are notifying customers about the breach and days or weeks-long delays in product deliveries. [TechCrunch // NLTimes // De Bijenkorf // WccfTech] [h/t Natanael, Tech janitor]

UAE thwarts cyber campaigns: The UAE's Cyber Security Council claims the country's security team have stopped cyberattacks aimed to infiltrate and spy on its aviation, energy, and educational sectors. [Arab News]

Hackers breach Poland's MyDr: Polish authorities are investigating a breach of MyDr, a healthcare platform used by the country's hospitals. The platform allegedly stores data on almost 19 million Poles. Hackers claimed they exploited an XXE vulnerability to breach the app and steal customer files and its source code. The data is now being sold online. [MyDr // CyberDefense24]

LexisNexis hit by Metabase hacks: Legal software maker took down three IT systems after they were hit by hackers, part of the Metabase database zero-day attacks. [BleepingComputer]

Klaviyo shares customer passwords: Online marketing company Klaviyo misconfigured its sign-up form and sent customer details, including passwords, to third-party analytics services. [Melurna // TechCrunch]

Mozilla key leak: Mozilla has rotated a GPG signing key after an unencrypted version was accidentally committed to a private GitHub repository. The key is typically used to sign Firefox and Thunderbird artifacts and ensure their authenticity. Mozilla says it found no evidence that the previous, leaked key was abused. [Mozilla]

Fake DDoS attacks: There's a new pro-Kremlin hacktivist group named Server Killers that appears to be engaging in fake DDoS attacks. Nothing new here. Most are. [LinkedIn]

AI assistant hacks gym website: An AI assistant hacked a gym's website after its owner asked it to book an appointment. The agent exploited the website's unsecured API to kick customers from the waiting list and move its owner at the top of the queue. The misbehaving agent was identified as a local OpenClaw instance. [ABC]

Federal agency hires DPRK remote worker: An unnamed US federal agency has hired a North Korean remote IT worker. The FBI is currently investigating the incident after discovering the worker in late July. It is unclear how the worker passed the extensive background checks and identity proofing requirements needed to get government jobs. [FNN]

AI, general tech, and privacy

OpenAI expands Daybreak with two-tier access: OpenAI expanded on Monday access to its frontier models for cybersecurity defenders. The company split its Daybreak early access program for red and blue teams. Daybreak Red will be available for pen-testers and will have access to the company's new GPT‑5.6‑Cyber model. Daybreak Blue will provide access to models with custom guardrails designed to help secure networks. OpenAI created a tier for defenders after its models escaped a sandbox and hacked AI platform HuggingFace and the same OpenAI models later blocked HuggingFace from investigating the hack because of aggressive guardrails. [OpenAI]

Claude to add watermarks: To comply with the EU's new AI Act, Anthropic will start watermarking Claude output. [Claude]

"Claude models launched in the EU on or after August 2, 2026 will support machine-readable marking at launch. Generated text will carry embedded watermarks, and generated files will include digitally signed provenance metadata where supported."

More AI irony: Google's DeepMind team has admitted that its own AI might bork job applications and asked applicants to use a special form. You can't make this stuff up! This is the technology we're putting into everything but the AI devs can't rely on it themselves. [Bloomberg]

Edge to end MV2 by the end of the year: Microsoft will disable support for old Manifest V2 extensions in the Edge browser by the end of the year. The company says 95% of the extensions in the Edge Add-ons store have already migrated their code to the MV3 extensions API. There are currently 58 Edge extensions with significant userbases on the old MV2, and of those, only three don't have a newer MV3 alternative. [Windows Blog]

uBlock Origin throws the towel: uBlock Origin, today's largest and most successful ad blocker, says it will stop blocking Facebook ads due to the platform's unending updates that bypass its blocks. It's a sad day for the project when its staff gets overwhelmed by an advertising company. [Reddit]

BlueSky filtered following: BlueSky has rolled out a new feature that lets you follow an account and only see their posts and hide reposts. [BlueSky]

YouTube cuts creator pay: Once again, YouTube has put new hurdles up for creators trying to monetize their content on the platform. The main change is increased view limits for content before it can be monetized. YouTube Shorts creators are the most impacted, with their minimum views doubling next year. [YouTube Blog]

YouTube announced they’ll start screwing over small creators in February. They keep making $$ on Shorts but won’t pay out unless you have huge numbers. AND making it more difficult to join. We’ll need 10 million views in 90 days to get paid. I have just under 1 million with 50k subs. It’s a big 🖕🏻.

[image or embed]

— David Bloomberg #BB28 #Survivor #TheTraitors (@davidbloomberg.bsky.social) August 11, 2026 at 3:54 PM

Twitter wipes out ⅔ of its ad business: Ever since taking over Twitter, Elon Musk has managed to wipe out two-thirds of the platform's ad revenue. [TechDirt]

Grokipedia stopped working in April: Elon Musk's lame AI-powered Wikipedia clone—Grokipedia—hasn't processed any new edits since April 24. [Lawfare]

Grokipedia just stopped updating after eight months ... and it took another four for anyone to notice www.lawfaremedia.org/article/grok...

[image or embed]

— Casey Newton (@caseynewton.bsky.social) August 5, 2026 at 10:28 PM

Government, politics, and policy

FTC wants to be AI thought police: The FTC has proposed a policy update to allow itself to regulate AI models for ideological bias. The same policy also claims the agency has regulatory oversight over the entire AI sector, superseding state laws. According to CyberScoop, the proposal's public comments has seen massive criticism across the political spectrum. [CyberScoop]

NIST seeks AI adoption feedback for CVE: The US National Institute of Standards and Technology is seeking public feedback on how to use AI to manage the NVD program. The agency is looking for the best way to use AI to automate vulnerability triage and management tasks. The NVD program saw a huge backlog last year due to the rise in the number of AI-assisted bugs. [CyberScoop // CybersecurityDive // Federal Register, PDF]

NIST is asking for public input about keeping the National Vulnerability Database useful in the AI era: public-inspection.federalregister.gov/2026-16371.pdf

[image or embed]

— Eric Geller (@ericjgeller.com) August 11, 2026 at 5:30 PM

Water Cyber Shield Act: US lawmakers have introduced a bill that would allocate $300 million in funds every year to shore up the cybersecurity of water and wastewater management organizations. The Water Cyber Shield Act would also grant the US Environmental Protection Agency the power to establish standards and regulate cybersecurity in the water utility sector. The EPA would be allowed to conduct cybersecurity assessments and demand corrective actions. [Sen. Adam Schiff]

UK removes Chinese cams from Navy drones: The UK Royal Navy removed internet connectivity from cameras installed on Kraken marine drones. The cameras allegedly sent heartbeat connections to China, potentially revealing their location. The drones were set for use in several planned Gulf missions. The report didn't say which Gulf. :)  [The Telegraph]

EU telcos have had enough: While in the US, telcos are pushing for deregulation, in the EU, four of the continent's largest telcos are begging the bloc to get it together and pass tougher rules to block CSAM and avoid all the national regulatory bottlenecks and delays. [Politico Europe]

Thailand to "consider" better security after hack: Thai government officials are "considering" resetting all government passwords and adopting multi-factor authentication after a wave of hacks. At least 20 state agencies reported hacks. Data from some has been leaked on hacker forums, including employee credentials. [The Bangkok Post]

Sponsor section

In this Risky Business sponsor interview, Catalin Cimpanu talks with Michael Leland, Field CTO of Island, about the company's seamless expansion into SASE and enterprise AI.

Arrests, cybercrime, and threat intel

Portuguese to face trial for developing WormGPT: A Portuguese man is on trial for developing a malicious AI assistant for cybercriminals. The suspect developed a tool called WormGPT that he advertised on the dark web. The tool worked like ChatGPT but had no safety guardrails in place. The suspect allegedly made €25,000 from selling the tool to other hackers. He was arrested last year by Portuguese authorities after a tip from the FBI. [Publico // Portugal Weekly]

Romance scammers arrested in Hong Kong: Chinese police have arrested eight individuals who were running a dating scam operation out of Hong Kong. Four men and four women were taken into custody at the start of August. The group lured victims into online groups to enter "sugar daddy" and "sugar mommy" agreements. Victims were tricked into signing contracts and paying fees before meeting with their escorts. [China Daily]

The Com member gets years: The UK has sentenced a 20-year-old to two years in prison for an online abuse campaign that forced more than 100 girls worldwide into sexual and self-harm activity. Justin Swaddle was an active member of The Com online community under the aliases of "Epstein," "Moscow," and "Rugen." Swaddle approached young girls via social media, gained their trust, and then extorted them to carve his name on their bodies, physically harm, or sexually abuse themselves. [UK NCA]

Kravchuk (Quake3) profile: VulOne has published a profile on Anatoly Sergeevitsch Kravchuk, a Ukrainian hacker going by Quake3, a moderator of the XSS cybercrime forum and believed to be the main developer of the REvil ransomware. [VulOne]

FBI advises against storing nudes online: The FBI has advised Americans against storing nude and sexually explicit content on cloud, email, or social media accounts. The agency says hackers are specifically looking for this type of content to extort victims. The FBI says hackers don't care if victims are underage. [FBI IC3 PSA]

UzCERT warns of mass RDP attacks: Uzbekistan's CERT sent out a security alert last week about mass-attacks targeting local organizations via RDP. [UzCERT on Telegram]

Banned Chrome extensions return: A cluster of malicious Chrome extensions that were caught and banned from the Web Store in January have now returned on the extensions portal with new versions. [Netskope]

npm malware: It's a day ending in "y," so there's new malware on npm. [SafeDep // Sonatype]

Explosion of large DDoS attacks: Cloudflare mitigated over 930 DDoS attacks that exceeded 1 Tbps in size in the first half of the year. The company says terabit-size attacks saw a five-fold increase since the start of the year. News and other media sites saw the most attacks. [Cloudflare]

More vulns exploited by ransomware gangs: CISA has updated its KEV catalog to warn that three bugs,CVE-2026-15409 and CVE-2026-15410 in SonicWall SMA1000 and CVE-2026-45659 in SharePoint, are now being exploited to drop ransomware on hacked networks. [CISA]

ShinyHunters claims Metabase hacks: The ShinyHunters hacking group claims to be behind the hack-and-pilfer campaign that targeted Metabase database servers using an SQL injection zero-day.

Malware technical reports

Gunra ransomware: CISA and several other agencies have published a technical deep dive into Gunra, a Ransomware-as-a-Service known for two things—attacks on critical infrastructure and its use by North Korean hackers. [CISA]

DeadLock ransomware: Microsoft has published a technical report on DeadLock, a ransomware strain that launched last year and is slowly being adopted by more and more affiliates. The ransomware's main features are its use of time-based cryptography and decentralized blockchain-based C2s. [Microsoft]

Abyssos RAT: Researchers have spotted a new RAT in late June. Written in C++, the new Abyssos RAT is still in development but has "post-exploitation framework features." [Zscaler]

Aeternum loader: PAN researchers look at Aeternum, a new malware loader that emerged this year. It's currently being used to drop XWorm and cryptominers. [PAN Unit42]

Project CAV3RN: Kaspersky looks again at CAV3RN, a modular espionage framework used against targets in Israel. No attribution, though. [Kaspersky]

Kimwolf v7: The Kimwolf, aka Aisuru, botnet is back online with a new version, surviving a March takedown by the FBI. [PAN Unit42]

Camview toolkit: Hunt researchers have identified a toolkit that was designed specifically for hacking Ukrainian security cameras and taking screenshots of their feeds. [Hunt Intelligence]

Sponsor section

In this sponsored Soap Box edition, Patrick Gray talks to Island CEO Michael Fey about some of the cool tricks in the Island enterprise browser. You can use it to tick off so many compliance boxes, and not just cybersecurity boxes. 

APTs, cyber-espionage, and info-ops

Serbian state-hacker arrested in Croatia: Croatian authorities have detained a suspected Serbian state-sponsored hacker. The suspect is accused of breaching several Croatian state institutions and public agencies. The largest targets include the Croatian Interior Ministry, the Croatian Tax Administration, and the country's automobile, pension, and health insurance databases. He was identified as 33-year-old businessman Georgije V. Croatian officials believe he worked for Servia's national intelligence agency BIA. [BalkanInsight // Jutarnji list]

Insolent Hyena moves from hacktivism to espionage: Russian security firm BI.ZONE says that a (likely Ukrainian) hacktivist group named Insolent Hyena is now collaborating with entities from the e-crime and espionage realms. [BI.ZONE]

Russian info-op aims to redivide Germany: Russia's Matryoshka disinformation group is running what appears to be a giant influence operation aimed at re-dividing Germany between East and West. [NewsGuard]

Lazarus deploys new Windows zero-day: North Korean hacking group Lazarus is using a zero-day to take full control over Windows systems. According to Check Point, the group has used the zero-day as part of its fake job interview campaigns this year. The zero-day is part of files sent to candidates as part of the job interview process. It exploits the Windows Ancillary Function Driver to obtain admin rights and deploy malware. Microsoft patched the zero-day this week as part of its monthly Patch Tuesday security updates. [Check Point // Check Point Research // CVE-2026-68820]

Vulnerabilities, security research, and bug bounty

Patch Tuesday: Yesterday was the August 2026 Patch Tuesday. We had security updates from Adobe, Microsoft, Ubuntu, Cisco, SAP, IBM, HPE, Dell, Ivanti, Supermicro, ASUS, TP-Link, Zoom, Schneider Electric, Siemens, Kubernetes, GNU Emacs, HashiCorp, Plesk, Intel, and AMD. Other projects and companies like Apple, Chrome, Firefox, NVIDIA, OpenSSL, Tails, Zyxel, D-Link, SonicWall, Samsung, Qualcomm, Google Pixel, AWS, GitHub, Check Point, Metabase, WordPress, Drupal, Django, RoundCube, N-able, Jenkins, cPanel, and Synology released security updates earlier this month.

Cisco zero-day: Cisco has patched a zero-day in its ASA, FMC, and FTD firewalls that was exploited in the wild to crash its security appliances. Cisco says the attacks were detected earlier this month. Crashing Cisco firewalls would allow attackers to access unprotected networks and resources. [Cisco, as CVE-2026-20349]

GhostJacking attack: AI security startup Tenet has developed a new technique to attack AI-powered IT and security tools. The new GhostJacking attack relies on getting blocked by security tools and leaving malicious or tainted data in logs. AI agents reading the logs would eventually execute the attacker's commands. [Tenet]

Zoomsday vulnerability: Zoom has patched a bug that could have allowed an attacker participating in a meeting to run malicious code across all participants. The Zoomsday bug required no interaction from meeting participants and worked across all Zoom OS clients. The bug was discovered with an AI tool and was patched this week. [A Security // Zoom patch]

Infosec industry

Threat/trend reports: APWG, Cloudflare, Dragos, Intruder, Kaspersky, MakeUK, Picus Security, and Zscaler have recently published reports and summaries covering various emerging threats and industry trends.

via Dragos

New tool—AgentSweep: Software engineer Ishan Naik has developed AgentSweep, a tool to find and redact secrets in your AI coding agent's local history.

X33fcon 2026 videos: Talks from the X33fcon 2026 security conference, which took place in June, are available on YouTube.

Risky Business podcasts

In this episode of Risky Business Features, James Wilson chats with Tinfoil co-founder Tanya Verma about how you can run a powerful LLM in the cloud without the inference provider seeing your prompts.

Recent Newsletters

  • Risky Bulletin: Russian hackers adopt the fake job interview tactics
  • Risky Bulletin: Pwnie Awards 2026 winners
  • Risky Bulletin: Meta's AI joins Anthropic and OpenAI in the hacky-hacky
  • Srsly Risky Biz: Being a North Korean Hacker Is About to Be Less Fun
  • Risky Bulletin: Hacker breaches Hungary's State Treasury

Recent Videos

  • Between Two Nerds: The cyber resistance!
  • Srsly Risky Biz: Being a North Korean hacker is about to be less fun
  • Between Two Nerds: Hackers vs the state
  • Srsly Risky Biz: Chipping away at Chinese AI risks
  • Risky Business (846): OpenAI built a fireplace out of wood

Recent Podcasts

  • Risky Business #848 -- OpenAI comes clean
  • Risky Bulletin: Russian hackers jump on the fake job interview train
  • Between Two Nerds: The cyber resistance!
  • Risky Bulletin: Two law firms pay giant ransoms
  • Sponsored: Island's expansion to SASE and enterprise AI
Risky Business Media

Risky Business

  • Home
  • Podcasts
  • Newsletters
  • Video
  • Sitemap

Risky Business Media

  • About
  • People
  • Advertising
  • Sponsor Enquiries: sales@risky.biz

Risky Connections

  • Risky Business on Apple Podcasts
  • Risky Business on Spotify
  • Risky Bulletin on Apple Podcasts
  • Risky Bulletin on Spotify
  • Risky Business Features on Apple Podcasts
  • Risky Business Features on Spotify
  • Risky Business Stories on Apple Podcasts
  • Risky Business Stories on Spotify
  • YouTube
  • LinkedIn

Risky Contacts

Risky Business Media Pty Ltd
PO Box 774
Byron Bay NSW 2481
General Email: editorial@risky.biz

© Risky Business Media 2007–2026. All rights reserved.
ABN 73 618 465 517