In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
This week’s cybersecurity news highlights a range of threats, including a new AI-powered malware (Dolphin X), a data breach affecting Abbott, widespread internet outages in Maine, zero-day vulnerabilities in Siemens switches, a ransomware attack against Stadler Rail, a phishing group takedown in Germany, and a massive influx of Linux kernel vulnerabilities. Additionally, a Russian APT group is exploiting a Zimbra flaw for espionage and a vulnerability in aftermarket anti-theft devices exposes millions of vehicles.
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. Here are this week’s highlights:
Dolphin X malware leverages AI to profile victims
Abbott has disclosed a cybersecurity incident involving unauthorized access to a limited number of systems within its Cancer Diagnostics business. The company stated that the breach has not disrupted business operations, manufacturing, or patient care. The notorious ShinyHunters group has taken credit for the hack.
Cyberattack disrupts internet services across 23 Maine towns A recent cyberattack targeting a telecommunications provider in Maine resulted in widespread internet service outages across 23 towns. The disruption impacted municipal networks and local government operations that rely on the regional telecom’s infrastructure.
Palo Alto Networks details exploit chain in Siemens ROX II switches
Unit 42 researchers identified three zero-day vulnerabilities in Siemens ROX II OT switches that can be chained together to achieve persistent root-level access. By exploiting an arbitrary file disclosure flaw (CVE-2025-40948), an attacker can gather sensitive system intelligence to facilitate a subsequent privilege escalation via command injection (CVE-2025-40947). The compromise is then cemented using a third vulnerability (CVE-2025-40949) in the web management task scheduler, allowing malicious code execution to survive system reboots.
Ransomware gang demands millions from Swiss train manufacturer Stadler
Swiss train manufacturer Stadler Rail has refused to pay a 10 million Swiss franc ($12 million) extortion demand from the Everest ransomware group following a targeted data theft incident. The attackers breached a data exchange platform shared with a supplier in mid-July, stealing technical information without impacting Stadler’s IT systems or global production operations. The company maintains that no critical security or personal data was compromised.
German authorities dismantle Kratos phishing group
German law enforcement authorities have successfully dismantled the Kratos phishing group following a coordinated operation. The takedown disrupts a dedicated cybercrime ring responsible for organized credential theft and phishing campaigns.
Hundreds of Linux kernel vulnerabilities published in massive single-day drop The cybersecurity community observed an unprecedented release of 432 CVEs related to the Linux kernel within a 24-hour period. This massive influx of disclosures requires security teams to rapidly triage affected systems and evaluate patching priorities.
Google launches CodeMender preview
Google has launched the preview of CodeMender, a security service designed to help developers identify and remediate software vulnerabilities more efficiently. The tool integrates directly into development workflows to streamline finding and patching insecure code before it reaches production.
Russian APT Laundry Bear exploits Zimbra flaw in espionage campaign A joint advisory from CISA and international partners warns that a Russian state-sponsored threat group, known as Laundry Bear, is actively exploiting a patched vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite. The attackers use a view-based exploit that triggers simply by opening a malicious email, instantly exfiltrating the victim’s inbox. The espionage campaign targets Western government and commercial entities to silently gather intelligence for Russia.
Dealer-installed security devices expose millions of vehicles to Bluetooth hijacking
Researchers at UC San Diego discovered a vulnerability in aftermarket anti-theft systems manufactured by Acrisure, leaving at least 2.2 million vehicles susceptible to remote compromise. Attackers can exploit a hardcoded Bluetooth key from up to five yards away to unlock doors. Acrisure has since released a patch to secure the affected KARR and SWDS devices, which were installed primarily by dealerships in Southern California. “The vulnerability described in the research is highly complex and presents a low risk to customers under real-world conditions,” a KARR spokesperson told The Register.