Site navigation

Warning Issued Over North Korea-linked Supply Chain Attacks

Staff Writer

,

uk south korea warn of increasing north korea-linked cyber threat
The UK and South Korea have warned that North Korea state-linked cyber actors are increasingly leveraging supply chain product vulnerabilities to attack organisations.

The UK’s National Cyber Security Centre (NCSC) and South Korea’s National Intelligence Service (NIS) have observed a rise in zero-day vulnerabilities and exploits in third-party software being capitalised on by North Korean state-linked adversaries, providing them access to both specific targets and indiscriminate organisations alike.

Further, in their new joint warning, the security agencies stated that not only will the threat of these attacks likely increase further, but the attack methods themselves have become more sophisticated as well.

As an example, in March 2023, North Korea-based cyber actors leveraged a vulnerability of the MagicLine4NX security authentication programme to intrude into a target organisation’s — a media outlet’s — intranet. They then exploited a network-lined system vulnerability to gain access to private information and data.

In light of the rise of this specific kind of attack by state-linked actors, the security agencies have advised organisations to establish and implement mitigative measures, not least to monitor network infrastructure so that atypical traffic from supply chain applications can be detected.

The NCSC’s director of operations, Paul Chichester, commented on the situation: “In an increasingly digital and interconnected world, software supply chain attacks can have profound, far-reaching consequences for impacted organisations.

“Today, with our partners in the Republic of Korea, we have issued a warning about the growing threat from DPRK state-linked cyber actors carrying out such attacks with increasing sophistication.

“We strongly encourage organisations to follow the mitigative actions in the advisory to improve their resilience to supply chain attacks and reduce the risk of compromise.”

The NCSC and NIS consider these supply chain-oriented attacks to align with and help bolster wider priorities for North Korea. These include the generation of revenue, espionage, and the stealing of advanced technologies.


Recommended reading


The new joint warning — and the agencies’ accompanying recommendations — comes just days after it was announced that the UK had entered a “landmark” science and technology accord with South Korea.

Following the new agreement, the two countries are set to work closer together regarding collaborations and commitments on artificial intelligence, semiconductors, space cooperation, and other high-priority technological areas.

“The Republic of Korea is a tech powerhouse, and a vital partner to the UK,” science and technology secretary, Michelle Donelan, commented.

“We share the same values and face the same challenges: from creating future jobs and industries fit for the AI age, to bringing the power of science to bear on climate change and supporting ageing populations.

“As part of the new Accord between our two countries, this raft of agreements will future-proof our relationship for decades to come: a partnership that is already bearing fruit as we work closely together on the next AI Safety Summit.”

DIGIT Staff Writer Robot

Staff Writer

Staff Writer - DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data