SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.
This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment.
Here are this week’s highlights:
Dolphin X malware leverages AI to profile victims
Varonis Threat Labs discovered a new infostealer called Dolphin X that uses an AI behavioral profiler to score and prioritize infected users based on their activity and installed software. The malware targets more than 300 applications, aiming to exfiltrate everything from browser passwords and cryptocurrency wallets to SSH keys and cloud tokens. An infection on a developer’s machine could potentially grant attackers access to an entire production environment.
Abbott investigates hack
Abbott has disclosed a cybersecurity incident involving unauthorized access to a limited number of systems within its Cancer Diagnostics business. The company stated that the breach has not disrupted business operations, manufacturing, or patient care. The notorious ShinyHunters group has taken credit for the hack.
Cyberattack disrupts internet services across 23 Maine towns
A recent cyberattack targeting a telecommunications provider in Maine resulted in widespread internet service outages across 23 towns. The disruption impacted municipal networks and local government operations that rely on the regional telecom’s infrastructure.
Palo Alto Networks details exploit chain in Siemens ROX II switches
Unit 42 researchers identified three zero-day vulnerabilities in Siemens ROX II OT switches that can be chained together to achieve persistent root-level access. By exploiting an arbitrary file disclosure flaw (CVE-2025-40948), an attacker can gather sensitive system intelligence to facilitate a subsequent privilege escalation via command injection (CVE-2025-40947). The compromise is then cemented using a third vulnerability (CVE-2025-40949) in the web management task scheduler, allowing malicious code execution to survive system reboots.
Ransomware gang demands millions from Swiss train manufacturer Stadler
Swiss train manufacturer Stadler Rail has refused to pay a 10 million Swiss franc ($12 million) extortion demand from the Everest ransomware group following a targeted data theft incident. The attackers breached a data exchange platform shared with a supplier in mid-July, stealing technical information without impacting Stadler’s IT systems or global production operations. The company maintains that no critical security or personal data was compromised.
German authorities dismantle Kratos phishing group
German law enforcement authorities have successfully dismantled the Kratos phishing group following a coordinated operation. The takedown disrupts a dedicated cybercrime ring responsible for organized credential theft and phishing campaigns.
Hundreds of Linux kernel vulnerabilities published in massive single-day drop
The cybersecurity community observed an unprecedented release of 432 CVEs related to the Linux kernel within a 24-hour period. This massive influx of disclosures requires security teams to rapidly triage affected systems and evaluate patching priorities.
Google launches CodeMender preview
Google has launched the preview of CodeMender, a security service designed to help developers identify and remediate software vulnerabilities more efficiently. The tool integrates directly into development workflows to streamline finding and patching insecure code before it reaches production.
Russian APT Laundry Bear exploits Zimbra flaw in espionage campaign
A joint advisory from CISA and international partners warns that a Russian state-sponsored threat group, known as Laundry Bear, is actively exploiting a patched vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite. The attackers use a view-based exploit that triggers simply by opening a malicious email, instantly exfiltrating the victim’s inbox. The espionage campaign targets Western government and commercial entities to silently gather intelligence for Russia.
Dealer-installed security devices expose millions of vehicles to Bluetooth hijacking
Researchers at UC San Diego discovered a vulnerability in aftermarket anti-theft systems manufactured by Acrisure, leaving at least 2.2 million vehicles susceptible to remote compromise. Attackers can exploit a hardcoded Bluetooth key from up to five yards away to unlock doors. Acrisure has since released a patch to secure the affected KARR and SWDS devices, which were installed primarily by dealerships in Southern California. “The vulnerability described in the research is highly complex and presents a low risk to customers under real-world conditions,” a KARR spokesperson told The Register.
Related: In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint
Related: In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting
