
🚨 UNC4899 breached a crypto firm after a developer AirDropped a trojanized archive from a personal device to a work machine. The file launched a fake Kubernetes CLI, opened a backdoor, pivoted into Google Cloud, exposed CI/CD tokens, and reset accounts to steal millions. 🔗 Full intrusion chain → thehackernews.com/2026/03/unc489…