VYPR
advisoryPublished Jul 24, 2026· 1 source

Weekly Cybersecurity Roundup: AI Malware, Siemens Switch Flaws, and Linux Kernel Vulnerabilities

This week's cybersecurity news includes the discovery of AI-powered malware, critical vulnerabilities in Siemens industrial switches, a surge in Linux kernel flaws, and a ransomware attack on a train manufacturer.

SecurityWeek's latest roundup covers a diverse range of cybersecurity developments, from novel malware tactics to critical infrastructure vulnerabilities. A new infostealer named Dolphin X has emerged, distinguished by its use of an AI behavioral profiler to assess and prioritize targets based on user activity and installed software. This sophisticated malware aims to exfiltrate a wide array of sensitive data, including browser passwords, cryptocurrency wallets, SSH keys, and cloud tokens, posing a significant threat, especially if it compromises a developer's machine.

In the realm of industrial control systems, researchers have detailed a chain of three zero-day vulnerabilities affecting Siemens ROX II OT switches. These flaws, when exploited together, allow attackers to achieve persistent root-level access. The exploit chain begins with an arbitrary file disclosure, followed by privilege escalation via command injection, and is cemented by a third vulnerability that enables malicious code execution to survive system reboots, presenting a serious risk to operational technology environments.

The cybersecurity community also witnessed an unprecedented influx of vulnerabilities affecting the Linux kernel, with 432 CVEs disclosed within a single 24-hour period. This massive disclosure requires security teams to rapidly triage affected systems and prioritize patching efforts, highlighting the ongoing challenges in maintaining the security of widely used operating systems.

In the financial sector, Swiss train manufacturer Stadler Rail has been targeted by the Everest ransomware group. The attackers reportedly breached a data exchange platform shared with a supplier, stealing technical information. Stadler has refused to pay the 10 million Swiss franc ($12 million) ransom demand, stating that no critical security or personal data was compromised and that global production operations remain unaffected.

Further underscoring the evolving threat landscape, a joint advisory from CISA and international partners warns of a Russian state-sponsored threat group, known as Laundry Bear, actively exploiting a patched vulnerability in the Zimbra Collaboration Suite. This zero-click exploit, triggered by opening a malicious email, allows for the silent exfiltration of victim inboxes, targeting Western government and commercial entities for intelligence gathering.

In other news, Varonis Threat Labs identified the new Dolphin X infostealer, which uses AI to profile victims. Abbott is investigating a breach attributed to the ShinyHunters group, and a cyberattack disrupted internet services across 23 towns in Maine. German authorities have dismantled the Kratos phishing group, and researchers have uncovered a vulnerability in aftermarket anti-theft devices from Acrisure, potentially exposing millions of vehicles to Bluetooth hijacking. Google has also launched a preview of CodeMender, a new service aimed at helping developers identify and remediate software vulnerabilities more efficiently.

Synthesized by Vypr AI