SecurityWeek’s weekly cybersecurity news roundup highlights key stories across vulnerability disclosures, emerging attack methods, and other noteworthy events. This week’s highlights include the discovery of a new infostealer called Dolphin X, which leverages AI to profile victims and targets over 300 applications to exfiltrate sensitive data.
Dolphin X Malware
Varonis Threat Labs discovered Dolphin X, an AI-powered malware that uses a behavioral profiler to score and prioritize infected users based on their activity and installed software. The malware aims to exfiltrate everything from browser passwords and cryptocurrency wallets to SSH keys and cloud tokens. An infection on a developer’s machine could potentially grant attackers access to an entire production environment.
Abbott Cybersecurity Incident
Abbott disclosed a cybersecurity incident involving unauthorized access to a limited number of systems within its Cancer Diagnostics business. The company stated that the breach has not disrupted business operations, manufacturing, or patient care. The notorious ShinyHunters group has taken credit for the hack.
Cyberattack in Maine
A recent cyberattack targeting a telecommunications provider in Maine resulted in widespread internet service outages across 23 towns. The disruption impacted municipal networks and local government operations that rely on the regional telecom’s infrastructure.
Palo Alto Networks and Siemens ROX II Switches
Unit 42 researchers identified three zero-day vulnerabilities in Siemens ROX II OT switches that can be chained together to achieve persistent root-level access. By exploiting an arbitrary file disclosure flaw (CVE-2025-40948), an attacker can gather sensitive system intelligence to facilitate a subsequent privilege escalation via command injection (CVE-2025-40947).
Ransomware Gang Demands Millions
Swiss train manufacturer Stadler Rail has refused to pay a 10 million Swiss franc ($12 million) extortion demand from the Everest ransomware group following a targeted data theft incident. The attackers breached a data exchange platform shared with a supplier in mid-July, stealing technical information without impacting Stadler’s IT systems or global production operations.
German Authorities Dismantle Phishing Group
German law enforcement authorities have successfully dismantled the Kratos phishing group following a coordinated operation. The takedown disrupts a dedicated cybercrime ring responsible for organized credential theft and phishing campaigns.
Linux Kernel Vulnerabilities
The cybersecurity community observed an unprecedented release of 432 CVEs related to the Linux kernel within a 24-hour period. This massive influx of disclosures requires security teams to rapidly triage affected systems and evaluate patching priorities.
Google Launches CodeMender Preview
Google has launched the preview of CodeMender, a security service designed to help developers identify and remediate software vulnerabilities more efficiently. The tool integrates directly into development workflows to streamline finding and patching insecure code before it reaches production.
Russian APT Laundry Bear
A joint advisory from CISA and international partners warns that a Russian state-sponsored threat group, known as Laundry Bear, is actively exploiting a patched vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite. The attackers use a view-based exploit that triggers simply by opening a malicious email, instantly exfiltrating the victim’s inbox.
Dealer-Installed Security Devices Vulnerability
Researchers at UC San Diego discovered a vulnerability in aftermarket anti-theft systems manufactured by Acrisure, leaving at least 2.2 million vehicles susceptible to remote compromise. Attackers can exploit a hardcoded Bluetooth key from up to five yards away to unlock doors.
Source: SecurityWeek