Urgent.News

What's breaking now, across thousands of outlets.

Tech

CrowdStrike finds possible bank hacker's CV among exposed AI logs

Suspected Chinese speaker used Claude Code and agentic pentesting tool ARTEX in attacks on South Korean lenders

CrowdStrike finds possible bank hacker's CV among exposed AI logs

The Register reports that CrowdStrike researchers have discovered possible bank hacker credentials within exposed AI logs, possibly identifying the attacker behind recent attacks on South Korean financial institutions. The logs contained operational details and a resume-writing request, which may belong to the attacker, though CrowdStrike cannot definitively confirm this connection.

The attacks affected at least five lenders, including Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank, and BNK Busan Bank. The researchers found references to the hacker, referred to as YY, in AI sessions associated with the attacks, alongside the use of ARTEX, a recently released open-source penetration-testing tool developed in China.

This incident demonstrates the evolving use of AI tooling by financially motivated threat actors to conduct multiple intrusions within a short time span.

Brief written by urgent.news from The Register's own syndicated text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

Why a square picture needs 24 x 30 stitches: gauge math for a crochet chart tool

I built a small, free, browser-only tool that turns an image into a single-crochet color chart. This post covers the one idea that makes it more useful than a plain pixelator: gauge.

  • Square pictures require 24 x 30 stitches due to gauge math
  • Tool converts images to single-color crochet charts
  • Limitations include size and complexity constraints

Treat Sales Handoffs as Explicit Workflow States

Treat Sales Handoffs as Explicit Workflow States A sales workflow should not treat “notification sent” as equivalent to “owner accepted.” Those are separate system states, and modelling them…

  • Distinguish between notification sent and owner accepted as distinct workflow states.
  • Create explicit model: RECEIVED → VALIDATED → ROUTED → ACCEPTED → NEXTACTIONRECORDED.
  • Implement retries with idempotency keys to avoid duplicate records.

We migrated the receiver but forgot the return trip

We migrated the receiver but forgot the return trip Same incident, different lesson. (If you're counting, this is the day our infrastructure decided to teach a whole curriculum — see also your webhook…

  • Receiver migrated to new server successfully
  • Return connection to processor not established
  • Sync job recreated within five minutes to resolve issue

More from Thursday 8 October →