North Korean hackers, APT37, are using Facebook to deliver RokRAT malware by tricking victims into installing a trojanized PDF viewer. This social engineering tactic highlights the group's evolving methods for deploying malware without changing its core functionality.
A critical pre-authentication remote code execution flaw in Marimo software is being actively exploited, allowing attackers to exfiltrate sensitive information from unsecured instances of this widely used Python notebook tool.
Read the full article at AboutDFIR G?? The Definitive Compendium Project
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.

![[AINews] The Unreasonable Effectiveness of Closing the Loop](/_next/image?url=https%3A%2F%2Fmedia.nemati.ai%2Fmedia%2Fblog%2Fimages%2Farticles%2F600e22851bc7453b.webp&w=3840&q=75)



