SecurityWeek Roundup: North Korea Hacks, OpenAI Tool, Adobe Patches, and Crypto Research
This week's cybersecurity news includes AWS linking North Korean actors to NPM package compromises, OpenAI open-sourcing a security CLI, Adobe patching critical flaws, and new cryptanalysis research.
SecurityWeek's latest cybersecurity news roundup covers a diverse range of significant developments, from nation-state activity and vendor vulnerabilities to open-source tool releases and cutting-edge research.
Amazon Web Services has attributed a series of recent supply-chain attacks targeting popular JavaScript libraries on the npm registry to the North Korean threat actor known as Sapphire Sleet. The group's tactics involve compromising high-download packages to achieve broad downstream impact, employing sophisticated techniques such as fragmented payloads and environment-aware malware to evade detection and maximize compromise.
In the realm of software security, Adobe has issued critical security updates for its Bridge, Campaign Classic, and Format Plugins. These patches address multiple vulnerabilities, including a heap-based buffer overflow in Format Plugins that could lead to arbitrary code execution, and several flaws in Bridge that permit code execution and privilege escalation. The Campaign Classic update is rated Priority 1 for on-premise deployments, though Adobe reports no known exploitation in the wild for these specific issues.
Meanwhile, SonicWall VPN and firewall accounts have been targeted in a widespread credential stuffing campaign observed by Huntress. The automated attacks, originating from DigitalOcean-hosted IP addresses, have successfully compromised accounts at approximately 30 organizations since July 25. While the campaign appears automated with no immediate post-compromise activity detected, it highlights the persistent threat of credential stuffing against network security devices.
OpenAI has contributed to the open-source community by releasing its Codex Security CLI. This tool is designed to enhance AI safety and security by scanning code repositories, tracking security findings, verifying fixes, and integrating security checks into CI/CD pipelines. The early release is available on npm and GitHub, with OpenAI actively seeking user feedback for further development.
On the data breach front, the UK Department for Education has reported that approximately 607,000 records containing phone numbers and email addresses were accessed by hackers. The department has stated that no sensitive financial information was compromised, and the incident was contained swiftly with a low perceived risk to individuals.
In a notable security research development, a researcher discovered unauthenticated internal APIs within VE Commercial Vehicles' My Eicher platform, a joint venture between Volvo Group and Eicher Motors. These flaws exposed customer, user, and vehicle data, and allowed for account takeover, potentially granting full control over commercial vehicle fleets in India. The vulnerabilities were addressed after disclosure.
Finally, researchers at Anthropic, using their Claude Mythos Preview, have demonstrated AI-assisted progress in cryptanalysis. They developed an improved attack on the post-quantum signature scheme HAWK, effectively halving its security level, and a faster meet-in-the-middle attack on a reduced-round variant of AES. While these findings do not impact currently deployed systems, they underscore the growing capability of AI in uncovering cryptographic weaknesses.