惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
O
OpenAI News
Y
Y Combinator Blog
MyScale Blog
MyScale Blog
C
Check Point Blog
Vercel News
Vercel News
小众软件
小众软件
The Register - Security
The Register - Security
N
News and Events Feed by Topic
腾讯CDC
S
SegmentFault 最新的问题
H
Heimdal Security Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
S
Secure Thoughts
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Schneier on Security
Schneier on Security
G
GRAHAM CLULEY
云风的 BLOG
云风的 BLOG
S
Schneier on Security
J
Java Code Geeks
L
LINUX DO - 最新话题
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
P
Privacy & Cybersecurity Law Blog
Forbes - Security
Forbes - Security
Cisco Talos Blog
Cisco Talos Blog
L
LINUX DO - 热门话题
Scott Helme
Scott Helme
爱范儿
爱范儿
GbyAI
GbyAI
Simon Willison's Weblog
Simon Willison's Weblog
L
Lohrmann on Cybersecurity
Cloudbric
Cloudbric
W
WeLiveSecurity
The Hacker News
The Hacker News
V
V2EX
Last Week in AI
Last Week in AI
Hacker News: Ask HN
Hacker News: Ask HN
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Blog — PlanetScale
Blog — PlanetScale
Cyberwarzone
Cyberwarzone
Google Online Security Blog
Google Online Security Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
S
Security @ Cisco Blogs
P
Proofpoint News Feed
Google DeepMind News
Google DeepMind News
C
Cyber Attacks, Cyber Crime and Cyber Security
U
Unit 42
Webroot Blog
Webroot Blog
Martin Fowler
Martin Fowler
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed

Risky Business Features

Fortibleed: The bleeding edge of AI cybercrime What to do 'til the bugpocalypse gets here Mythos on your desk? Using local LLMs for code reviews Pitching security startups to VCs in the AI era How using open weight models can blow up in your face The state of the art in AI model jailbreaks Why NPM v12 won’t stop supply chain attacks Everything is getting much worse, much faster Solo podcast: A deep dive on TeamPCP How to survive supply chain attacks How the CopyFail disclosure went sideways NCSC’s Ollie Whitehouse on surviving the "bugpocalypse" What a great agentic AI deployment plan looks like Mythos smythos! How to find 0day with lesser models Solving the AI agent identity problem A deep dive on AI model distillation attacks Feature Interview: Nicholas Carlini, Anthropic A builder's perspective on Mythos and frontier models Mythos and 0day: Fixing exploits is not safety Mythos and 0day: A hacker’s perspective What happens after North Korea infiltrates? Why CISOs need to be more flexible in the AI era A Risky Biz Experiment: Hunting for iOS 0day with AI Interview: Former NSA and CIA cyber leaders on offensive AI When disaster strykes - Risky Business Media MCP is Dead - Risky Business Media They don't break in, they log in. What's an enterprise to do? A ridiculously deep dive into the Coruna Exploits Being a wartime CISO - Risky Business Media Former Adobe, Cisco and Salesforce CISO talks AI pentesting History Repeats: Security in the AI Agent Era
What to do about North Korean remote workers
James Wilson · 2026-02-27 · via Risky Business Features

Risky Business Features Podcast

February 27, 2026

Presented by

James Wilson

James Wilson

Technology Editor

In this podcast James Wilson chats with Brad Arkin about North Korea’s sprawling fake IT worker ecosystem. From fake interviews, to stolen identities, basement laptop farms and IP-KVM tricks, the North Koreans are operating a whole employment fraud industry.

Brad and James discuss how the scheme works in practice and the technical detection challenges defenders now face, like dealing with stolen or borrowed identities, bribed verification checks and multi-person operational chains. They also dig into why enterprises are largely on the back foot, and why there’s no single product you can buy to solve this.

As the former CISO of Adobe, Cisco and Salesforce, Brad has some firsthand experience dealing with this stuff!

Your browser does not support the audio element.

What to do about North Korean remote workers

0:00 / 27:55

Logo