SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.
This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment.
Here are this week’s highlights:
OnTrac hacked
Parcel delivery company OnTrac is notifying customers after attackers accessed its corporate network and certain files between March 20 and 22. The firm detected the activity on March 23 and engaged a third-party specialist to investigate the scope. No ransomware group has claimed the incident.
Adobe patches vulnerabilities in Bridge, Campaign Classic and Format Plugins
Adobe issued security updates addressing multiple critical vulnerabilities, including a heap-based buffer overflow in Format Plugins that enables arbitrary code execution, several flaws in Bridge allowing code execution and privilege escalation, and Campaign Classic flaws that permit arbitrary code execution and file system reads. The Campaign Classic patch carries Priority 1 rating for on-premise deployments. Adobe reports no known exploitation in the wild.
SonicWall VPN and firewall accounts hit by widespread credential stuffing
Huntress observed a broad credential stuffing campaign against SonicWall VPN and firewall accounts beginning July 25, with successful logins at 30 organizations so far. The activity originates from five DigitalOcean-hosted IP addresses and appears automated, with no post-compromise hands-on activity detected.
OpenAI releases open source Codex Security CLI
OpenAI has open-sourced the Codex Security CLI, a tool for scanning repositories, tracking findings across runs, verifying fixes, and integrating security checks into CI/CD pipelines. The early release is available via npm and GitHub, with the company inviting feedback as it continues development.
UK Department for Education loses 607,000 contact records
Hackers obtained approximately 607,000 records containing phone numbers and email addresses from the Department for Education in England. The department says the data does not include bank details or other sensitive information, the incident was contained quickly, and the risk to individuals is not considered high.
Amazon ties Axios, Debug and Chalk hacks to North Korea’s Sapphire Sleet
Amazon Threat Intelligence attributes the recent compromises of the popular Axios, Debug, and Chalk NPM packages, along with a typo-crypto incident, to the North Korean group tracked as Sapphire Sleet. AWS notes the group’s focus on high-download packages for broad downstream impact and highlights evolving supply-chain techniques including fragmented payloads and environment-aware malware.
Researcher seizes control of Volvo/Eicher vehicle management platform
A security researcher discovered unauthenticated internal APIs in VE Commercial Vehicles’ My Eicher platform that exposed customer, user, and vehicle data and enabled account takeover. VE Commercial Vehicles is a joint venture between Volvo Group and Eicher Motors. The flaws allowed full control over fleets of commercial vehicles in India and access to sensitive documents such as Aadhaar cards. The primary issues were fixed after disclosure, and the company later remediated additional concerns.
Claude Mythos uncovers stronger attacks on HAWK and reduced-round AES
Anthropic researchers using Claude Mythos Preview developed an improved key-recovery attack on the post-quantum signature scheme HAWK that roughly halves its effective security level, and a faster meet-in-the-middle attack on 7-round AES. Neither result affects currently deployed systems—HAWK is still a candidate and the AES work targets a reduced-round variant—but both demonstrate AI-assisted progress in cryptanalysis.
Related: In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
Related: In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint
Source:
www.securityweek.com


