Back to Feed
Threat IntelligenceJul 31, 2026

In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research

OnTrac hacked, Adobe patches, UK DfE loses records, SonicWall accounts targeted, OpenAI open-sources tool, AWS links

Summary

This week's security news roundup includes a breach at parcel delivery company OnTrac, Adobe patching critical vulnerabilities, and the UK Department for Education losing 607,000 contact records. Additionally, AWS attributes NPM package compromises to North Korea's Sapphire Sleet, and a researcher found unauthenticated APIs in Volvo/Eicher's vehicle management platform.

Full text

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights: OnTrac hacked Parcel delivery company OnTrac is notifying customers after attackers accessed its corporate network and certain files between March 20 and 22. The firm detected the activity on March 23 and engaged a third-party specialist to investigate the scope. No ransomware group has claimed the incident. Advertisement. Scroll to continue reading. Adobe patches vulnerabilities in Bridge, Campaign Classic and Format Plugins Adobe issued security updates addressing multiple critical vulnerabilities, including a heap-based buffer overflow in Format Plugins that enables arbitrary code execution, several flaws in Bridge allowing code execution and privilege escalation, and Campaign Classic flaws that permit arbitrary code execution and file system reads. The Campaign Classic patch carries Priority 1 rating for on-premise deployments. Adobe reports no known exploitation in the wild. SonicWall VPN and firewall accounts hit by widespread credential stuffing Huntress observed a broad credential stuffing campaign against SonicWall VPN and firewall accounts beginning July 25, with successful logins at 30 organizations so far. The activity originates from five DigitalOcean-hosted IP addresses and appears automated, with no post-compromise hands-on activity detected. OpenAI releases open source Codex Security CLI OpenAI has open-sourced the Codex Security CLI, a tool for scanning repositories, tracking findings across runs, verifying fixes, and integrating security checks into CI/CD pipelines. The early release is available via npm and GitHub, with the company inviting feedback as it continues development. UK Department for Education loses 607,000 contact records Hackers obtained approximately 607,000 records containing phone numbers and email addresses from the Department for Education in England. The department says the data does not include bank details or other sensitive information, the incident was contained quickly, and the risk to individuals is not considered high. Amazon ties Axios, Debug and Chalk hacks to North Korea’s Sapphire Sleet Amazon Threat Intelligence attributes the recent compromises of the popular Axios, Debug, and Chalk NPM packages, along with a typo-crypto incident, to the North Korean group tracked as Sapphire Sleet. AWS notes the group’s focus on high-download packages for broad downstream impact and highlights evolving supply-chain techniques including fragmented payloads and environment-aware malware. Researcher seizes control of Volvo/Eicher vehicle management platform A security researcher discovered unauthenticated internal APIs in VE Commercial Vehicles’ My Eicher platform that exposed customer, user, and vehicle data and enabled account takeover. VE Commercial Vehicles is a joint venture between Volvo Group and Eicher Motors. The flaws allowed full control over fleets of commercial vehicles in India and access to sensitive documents such as Aadhaar cards. The primary issues were fixed after disclosure, and the company later remediated additional concerns. Claude Mythos uncovers stronger attacks on HAWK and reduced-round AES Anthropic researchers using Claude Mythos Preview developed an improved key-recovery attack on the post-quantum signature scheme HAWK that roughly halves its effective security level, and a faster meet-in-the-middle attack on 7-round AES. Neither result affects currently deployed systems—HAWK is still a candidate and the AES work targets a reduced-round variant—but both demonstrate AI-assisted progress in cryptanalysis. Related: In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws Related: In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint Written By SecurityWeek News Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from SecurityWeek News Bank of America to Acquire Cybersecurity Firm MDSecOkta to Acquire Identity Threat Detection Firm PermisoOnyx Security Raises $113 Million to Control AI Agents in the EnterpriseIn Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel FlawsAegisAI Raises $36 Million for AI-Powered Email SecurityIndustry Reactions to OpenAI Models Hacking Hugging Face: Feedback FridayAbstract Raises $25 Million to Expand Composable Security Operations PlatformAssaf Keren Appointed New CISO of Meta Latest News Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian HackersGoogle AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching PaceEU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in BrusselsPrompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 OrganizationsCritical Flaw Allowed to Azure Cosmos DB PwnageCareCloud Data Breach Impacts Over 350,000Critical Code Execution Vulnerability Patched in TeamCity CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MovePNC Financial Services Group has appointed Christian Winward as CISO.Brian Gumbel has joined Armadin as Chief Revenue Officer.EigenQ has appointed Mark Pecen as Vice Chairman and Alexander Truskovsky as CISO.More People On The MoveExpert Insights Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • mitre_attack — T1078
  • malware — Axios
  • malware — Debug
  • malware — Chalk

Entities

OnTrac (vendor)Adobe (vendor)SonicWall (vendor)OpenAI (vendor)AWS (vendor)Sapphire Sleet (threat_actor)