In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research

Cyberattacks Abound as Companies Scramble to Stay Ahead of Threats

A recent spate of cyber incidents has highlighted the ongoing cat-and-mouse game between hackers and security professionals. From parcel delivery companies to government departments, no organization is immune to the threat of data breaches and system compromise.

OnTrac, a US-based parcel delivery company, was one of the latest victims of a cyberattack. Hackers gained access to its corporate network between March 20 and 22, accessing certain files in the process. The breach was detected on March 23, and an investigation is ongoing to determine the full extent of the damage. While no ransomware group has claimed responsibility for the attack, it’s a stark reminder that even seemingly secure organizations can fall victim to determined hackers.

Meanwhile, Adobe has issued patches to address multiple critical vulnerabilities in its Bridge, Campaign Classic, and Format Plugins software. The flaws include a heap-based buffer overflow in Format Plugins, which enables arbitrary code execution, as well as several other issues that allow code execution and privilege escalation. While no known exploitation has been reported, the patch is a timely reminder of the importance of keeping software up to date.

The SonicWall VPN and firewall accounts have also come under attack from a widespread credential stuffing campaign. Beginning on July 25, hackers attempted to log in to over 30 organizations using stolen credentials, with five DigitalOcean-hosted IP addresses at the center of the activity. While the incident is concerning, it’s worth noting that no post-compromise hands-on activity has been detected.

In a welcome development, OpenAI has open-sourced its Codex Security CLI tool. The tool allows developers to scan repositories for security vulnerabilities and track findings across multiple runs. By integrating security checks into CI/CD pipelines, organizations can ensure their code is free from flaws before they become a problem.

The UK Department for Education has also been targeted by hackers, who managed to obtain approximately 607,000 records containing phone numbers and email addresses. While the data does not include sensitive information such as bank details, the incident highlights the ongoing threat of data breaches in government departments.

Amazon’s Threat Intelligence team has attributed recent compromises of popular NPM packages to North Korea’s Sapphire Sleet group. The group is known for targeting high-download packages with broad downstream impact, and its techniques include fragmented payloads and environment-aware malware. This development underscores the importance of keeping software dependencies up to date and monitoring supply chain threats.

Finally, a security researcher has discovered unauthenticated internal APIs in VE Commercial Vehicles’ My Eicher platform, which exposed customer, user, and vehicle data. The flaws allowed hackers to gain full control over fleets of commercial vehicles in India and access sensitive documents such as Aadhaar cards. While the primary issues were fixed after disclosure, the incident highlights the need for organizations to regularly review their security posture.

In a separate development, researchers using Claude Mythos Preview have developed an improved key-recovery attack on the post-quantum signature scheme HAWK and a faster meet-in-the-middle attack on 7-round AES. While neither result affects currently deployed systems, it demonstrates AI-assisted progress in cryptanalysis and underscores the ongoing need for security professionals to stay ahead of emerging threats.

For organizations looking to stay ahead of the curve, this spate of cyber incidents serves as a timely reminder to prioritize security measures such as software updates, vulnerability scanning, and supply chain risk management. By staying vigilant and proactive, businesses can minimize their exposure to cyber threats and ensure their systems remain secure in an ever-evolving threat landscape.


Source: SecurityWeek — 2026-07-31