In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research

A Week in Review: Notable Cybersecurity Developments Across Multiple Sectors

The past week has seen a flurry of cybersecurity-related news, with incidents affecting various industries and highlighting emerging threats. From compromised parcel delivery company networks to vulnerabilities in popular software tools, here’s a rundown of the most significant developments.

OnTrac, a US-based parcel delivery company, has informed its customers that hackers gained access to their corporate network between March 20 and 22. The breach was detected on March 23, and an external expert was brought in to investigate the extent of the damage. While no ransomware group has claimed responsibility for the incident, it serves as a reminder that even seemingly secure networks can be vulnerable to cyber threats.

Adobe recently released security updates addressing multiple critical vulnerabilities across several of its products, including Bridge, Campaign Classic, and Format Plugins. These flaws could allow arbitrary code execution, privilege escalation, or file system reads. Adobe reports no known exploitation in the wild, but users are advised to apply the patches as soon as possible to prevent potential attacks.

In another concerning development, a widespread credential stuffing campaign has been observed targeting SonicWall VPN and firewall accounts since July 25. The activity, which has successfully compromised login credentials at over 30 organizations, appears to be automated and originates from five DigitalOcean-hosted IP addresses. This incident highlights the importance of strong password management and multi-factor authentication.

OpenAI has made available its Codex Security CLI, an open-source tool designed for scanning repositories, tracking findings, and verifying fixes. The company invites feedback as it continues to develop the tool, which aims to integrate security checks into continuous integration/continuous deployment (CI/CD) pipelines.

Additionally, a hack on the UK’s Department for Education resulted in the unauthorized disclosure of approximately 607,000 records containing phone numbers and email addresses. While the department claims that sensitive information such as bank details was not compromised, this incident underscores the importance of robust data protection measures.

Amazon Threat Intelligence has linked recent compromises of popular NPM packages (Axios, Debug, and Chalk) to North Korea’s Sapphire Sleet group. AWS notes that this group focuses on high-download packages for broad downstream impact, highlighting evolving supply-chain techniques such as fragmented payloads and environment-aware malware.

Lastly, a security researcher discovered unauthenticated internal APIs in the My Eicher platform used by VE Commercial Vehicles, which exposed customer and vehicle data. The flaws enabled account takeover and full control over fleets of commercial vehicles in India. While primary issues were fixed after disclosure, this incident highlights the need for robust security testing and regular vulnerability assessments.

These incidents demonstrate the dynamic nature of the cybersecurity landscape and underscore the importance of staying vigilant and proactive. To mitigate potential risks, users are advised to:

* Regularly apply software patches and updates

* Implement strong password management practices and multi-factor authentication

* Conduct thorough security testing and regular vulnerability assessments

* Stay informed about emerging threats and vulnerabilities affecting your systems or tools

By taking these steps, organizations can better protect themselves against the evolving array of cyber threats.


Source: SecurityWeek — 2026-07-31