SecurityWeek roundup: AI in Korean bank breaches, poem-guided botnet, Empire Market founder gets 40 years
SecurityWeek's weekly cybersecurity roundup covers South Korea's probe into bank hacks possibly involving AI, Black Lotus Labs' analysis of PoeLLM malware whose C&C server is hidden in a GitHub poem, and a 40-year sentence plus $5 million fine for Empire Market co-founder Raheim Hamilton.
- PoeLLM targets LiteLLM, Ollama, Gotenberg and Gitea to mine crypto; its C&C address is encoded in a GitHub poem updated 11 times
- GhostAction pushed a secret-stealing workflow to 772 public GitHub repos, targeting 2,577 secrets including SSH keys and AWS and Azure credentials
- Hamilton got 40 years and a $5 million fine; Empire Market handled over 4 million transactions worth $430 million
- CVE-2026-47483 in Nvidia DCGM Exporter leaked telemetry from over 12,000 GPUs on ~2,100 hosts; fixed in version 4.8.2
Read next
Security