The Matthew Chapman Podcast

State Actors, Zero-Days & NFC Relay Fraud

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 3:28

Here is your briefing for Thursday, August 13, 2026. North Korean IT workers are applying for remote developer jobs, passing interviews, and landing inside government agencies and private companies with legitimate credentials. The FBI is investigating at least one case where a suspected DPRK operative worked for a U.S. federal agency. Researchers who deliberately hired suspected Lazarus-linked developers into sandboxed environments documented forged identities, re-used infrastructure, and rapid pivots once inside. The operation flips the usual attacker model: instead of breaking in, the threat gets hired. That's the headline from The Hacker News, and it is the logical endpoint of years of remote-work expansion. The same hiring pipelines companies optimized for speed now route state-sponsored talent straight into production systems. Lazarus Group exploited a freshly patched Windows zero-day in the Ancillary Function Driver for WinSock (AFD.sys, CVE-2026-68820, CVSS 7.0) to escalate privileges and drop a previously unseen backdoor. The campaign targeted defense and aerospace firms in France, Germany, Brazil, and India as part of the long-running Operation Dream Job social-engineering effort. Microsoft shipped the fix in the August 2026 Patch Tuesday bundle. That's the headline from The Hacker News and Krebs on Security, and it is the usual pattern: a high-value zero-day lands in the hands of a sophisticated actor, gets used for targeted espionage, and only surfaces after the patch cycle catches up. Threat actors started exploiting CVE-2026-55040, a critical SharePoint authentication bypass patched in July, within days of Rapid7 publishing proof-of-concept code. The flaw allows impersonation, file disclosure, and data modification. It is already the fifth SharePoint vulnerability observed in active exploitation this year. That's the headline from The Hacker News, and it is another data point on how quickly public PoCs translate into real-world campaigns once the disclosure window opens. A new Android NFC relay malware family called WindRelay works with the SpyNote RAT to capture live card data via contactless payments and forward it to attackers in real time. The malware is sideloaded silently after initial RAT access, requires no screen sharing, and was first spotted in the wild in late 2025. Attacks begin with phishing or smishing to get the initial foothold. That's the headline from The Hacker News, and it shows how the contactless payment surface remains an attractive, under-defended channel for fraud even as mobile security tooling improves. Anthropic rolled out invisible watermarks on Claude-generated text that can flag machine output even when a human only edited the content. Some users are already complaining that the feature will catch them using the model for work or school assignments. Ars Technica notes the mark is designed to survive editing, which raises obvious questions about false positives and detection accuracy in the wild. That's the headline from Ars Technica and TechCrunch, and it is the predictable collision between safety tooling that wants to label everything and users who want the model to stay invisible when it is convenient. Five stories, one recurring theme. State actors are shifting from external intrusion to legitimate employment pipelines. Sophisticated groups like Lazarus continue to weaponize zero-days the moment they appear. Public PoCs accelerate exploitation of enterprise platforms. Mobile payment fraud tooling is getting more specialized. And the safety features companies add to their models are already generating user friction. The through-line is the same one we see every week: the abstractions we rely on for speed and convenience keep leaking at the seams. The organizations that treat every new integration, every new hire, and every new model output as potentially hostile will be the ones that still have options when the next one lands. That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow.

Support the show

Thursday Security Briefing Setup

SPEAKER_00

Here's your briefing for Thursday, August 13, 2026.

North Korean Developers Get Hired

SPEAKER_00

North Korean IT workers are applying for remote developer jobs, passing interviews, and landing inside government agencies and private companies with legitimate credentials. The FBI is investigating at least one case where a suspected DPRK operative worked for a U.S. federal agency, researchers who deliberately hire suspected Lazarus linked developers into sandboxed environments documented, forged identities, reused infrastructure, and rapid pivots once inside. The operation flips the usual attacker model, instead of breaking in, the threat gets hired. That's the headline from the Hacker News, and it is the logical endpoint of years of remote work expansion. The same hiring pipelines companies optimize for speed now route, state sponsored talent straight into

Lazarus Uses Windows Zero Day

SPEAKER_00

production systems. Lazarus Group exploited a freshly patched Windows Zero Day in the ancillary function driver for WinSock, AFD-Sys, CVE 2026-68820, CVSS 7.0 to escalate privileges and drop a previously unseen backdoor. The campaign targeted defense and aerospace firms in France, Germany, Brazil, and India as part of the long-running Operation Dream Job social engineering effort. Microsoft shipped the fix in the August 2026 Patch Tuesday bundle. That's the headline from the Hacker News and Krebs on security, and it is the usual pattern. A high value zero-day land in the hands of a sophisticated actor gets used for targeted espionage and only services after the patch cycle catches

SharePoint Bug Gets Weaponized Fast

SPEAKER_00

up. Threat actors started exploiting CVE 2026-55040, a critical SharePoint authentication bypass patched in July, within days of Rapid 7 publishing proof-of-concept code. The flaw allows impersonation, file disclosure, and data modification. It is already the fifth SharePoint of vulnerability observed in active exploitation this year. That's the headline from the Hacker News, and it is another data point on how quickly public pox translate into real-world campaigns once the disclosure window opens.

Android NFC Relay Fraud Goes Real Time

SPEAKER_00

A new Android NFC Relay malware family called WinRelay works with the SpyNote Rat to capture live card data via contactless payments and forward it to attackers in real time. The malware is side-loaded silently after initial Air AT access, requires no screen sharing, and was first spotted in the wild in late 2025. Attacks begin with phishing or submission to get the initial foothold. That's the headline from the Hacker News, and it shows how the contactless payment surface remains an attractive, underdefined channel for fraud even as mobile security tooling improves.

AI Watermarks Meet User Backlash

SPEAKER_00

Anthropic rolled out invisible watermarks on claw-generated text that can flag machine output even when a human only edited the content. Some users are already complaining that the feature will catch them using the model for work or school assignments. Rs Technica notes the mark is designed to survive editing, which raises obvious questions about false positives and detection accuracy in the wild. That's the headline from Rs Technica and TechCrunch. And it is the predictable collision between safety tooling that wants to label everything and users who want the model to stay invisible when it is convenient.

The Weekly Theme And Takeaways

SPEAKER_00

Five stories, one recurring theme. State actors are shifting from external intrusion to legitimate employment pipelines. Sophisticated groups like Lazarus continue to weaponize zero days the moment they appear. Public pox accelerate exploitation of enterprise platforms. Mobile payment fraud tooling is getting more specialized, and the safety features companies add to their models are already generating user friction. The through line is the same one we see every week. The abstractions we rely on for speed and convenience keep leaking at the seams. The organizations that treat every new integration, every new hire, and every new model output as potentially hostile will be the ones that still have options when the next

Closing Advice And Sign Off

SPEAKER_00

one lands. That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow.