Security News

Cybersecurity news aggregator

⚔️
CRITICAL Attacks SecurityWeek

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws

A critical exploit chain in Siemens ROX II industrial OT switches leverages an arbitrary file disclosure flaw (CVE-2025-40948, CVSS 6.8) to enable a command injection (CVE-2025-40947, CVSS 7.5) for privilege escalation, which is then made persistent via a task scheduler vulnerability (CVE-2025-40949, CVSS 9.1). Affected Siemens RuggedCom ROX MX5000, MX5000RE, RX1400, RX1500, and RX1501 firmware versions are all prior to 2.17.1. Siemens has released a fix in firmware version 2.17.1 to remediate all three vulnerabilities.
Read Full Article →

Malware & Threats In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt. By SecurityWeek News | July 24, 2026 (10:20 AM ET) Flipboard Reddit Whatsapp Whatsapp Email SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights: Dolphin X malware leverages AI to profile victims Varonis Threat Labs discovered a new infostealer called Dolphin X that uses an AI behavioral profiler to score and prioritize infected users based on their activity and installed software. The malware targets more than 300 applications, aiming to exfiltrate everything from browser passwords and cryptocurrency wallets to SSH keys and cloud tokens. An infection on a developer’s machine could potentially grant attackers access to an entire production environment. Abbott investigates hack Advertisement. Scroll to continue reading. Abbott has disclosed a cybersecurity incident involving unauthorized access to a limited number of systems within its Cancer Diagnostics business. The company stated that the breach has not disrupted business operations, manufacturing, or patient care. The notorious ShinyHunters group has taken credit for the hack. Cyberattack disrupts internet services across 23 Maine towns A recent cyberattack targeting a telecommunications provider in Maine resulted in widespread internet service outages across 23 towns. The disruption impacted municipal networks and local government operations that rely on the regional telecom’s infrastructure. Palo Alto Networks details exploit chain in Siemens ROX II switches Unit 42 researchers identified three zero-day vulnerabilities in Siemens ROX II OT switches that can be chained together to achieve persistent root-level access. By exploiting an arbitrary file disclosure flaw (CVE-2025-40948), an attacker can gather sensitive system intelligence to facilitate a subsequent privilege escalation via command injection (CVE-2025-40947). The compromise is then cemented using a third vulnerability (CVE-2025-40949) in the web management task scheduler, allowing malicious code execution to survive system reboots. Ransomware gang demands millions from Swiss train manufacturer Stadler Swiss train manufacturer Stadler Rail has refused to pay a 10 million Swiss franc ($12 million) extortion demand from the Everest ransomware group following a targeted data theft incident. The attackers breached a data exchange platform shared with a supplier in mid-July, stealing technical information without impacting Stadler’s IT systems or global production operations. The company maintains that no critical security or personal data was compromised. German authorities dismantle Kratos phishing group German law enforcement authorities have successfully dismantled the Kratos phishing group following a coordinated operation. The takedown disrupts a dedicated cybercrime ring responsible for organized credential theft and phishing campaigns. Hundreds of Linux kernel vulnerabilities published in massive single-day drop The cybersecurity community observed an unprecedented release of 432 CVEs related to the Linux kernel within a 24-hour period. This massive influx of disclosures requires security teams to rapidly triage affected systems and evaluate patching priorities. Google launches CodeMender preview Google has launched the preview of CodeMender , a security service designed to help developers identify and remediate software vulnerabilities more efficiently. The tool integrates directly into development workflows to streamline finding and patching insecure code before it reaches production. Russian APT Laundry Bear exploits Zimbra flaw in espionage campaign A joint advisory from CISA and international partners warns that a Russian state-sponsored threat group, known as Laundry Bear, is actively exploiting a patched vulnerability ( CVE-2025-66376 ) in the Zimbra Collaboration Suite. The attackers use a view-based exploit that triggers simply by opening a malicious email, instantly exfiltrating the victim’s inbox. The espionage campaign targets Western government and commercial entities to silently gather intelligence for Russia. Dealer-installed security devices expose millions of vehicles to Bluetooth hijacking Researchers at UC San Diego discovered a vulnerability in aftermarket anti-theft systems manufactured by Acrisure, leaving at least 2.2 million vehicles susceptible to remote compromise. Attackers can exploit a hardcoded Bluetooth key from up to five yards away to unlock doors. Acrisure has since released a patch to secure the affected KARR and SWDS devices, which were installed primarily by dealerships in Southern California. “The vulnerability described in the research is highly complex and presents a low risk to customers under real-world conditions,” a KARR spokesperson told The Register . Related : In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint Related : In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting Written By SecurityWeek News Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from SecurityWeek News Assaf Keren Appointed New CISO of Meta Palo Alto Networks to Acquire Observability Platform Provider Embrace Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software Watch on Demand: Cloud & Data Security Summit In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive Latest News AegisAI Raises $36 Million for AI-Powered Email Security Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday Data Breach Confirmed After Australian Energy Giant Origin Is Hacked OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider Is Patching Dead? Vulnerability Management in the Post-Mythos Era Chick-fil-A Accounts Get Fried in Credential Stuffing Attack Abstract Raises $25 Million to Expand Composable Security Operations Platform Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer. John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox. Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer. More People On The Move Expert Insights Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Flipboard Reddit Whatsapp Whatsapp Email

Share this article