LIVE · cybersecurity feed
Live wire
patch

In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research

Noteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records. The post In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research appeared first on SecurityWeek.

zeroday.news · 1d ago

A recent report highlighted several security incidents and developments that may have received less widespread attention. Among these were a reported hack impacting the parcel delivery company OnTrac, a series of patches released by Adobe, and a data loss incident at the UK Department for Education involving a significant number of records.

The incident involving OnTrac, a parcel delivery company, was presented as a hack. While specific technical details of the compromise were not provided, such incidents in the logistics sector often involve unauthorized access to systems that manage package tracking, customer data, or operational logistics. The potential impact of a hack on a delivery service can range from disruption of services to the compromise of sensitive customer information, including names, addresses, and potentially payment details if stored within affected systems.

Adobe released a set of patches, indicating the remediation of vulnerabilities within its product suite. Adobe’s software, widely used across various industries for creative design, document management, and web content, is a frequent target for attackers dueating to its pervasive deployment. These patches typically address security flaws that could lead to arbitrary code execution, information disclosure, or privilege escalation, which, if exploited, could allow attackers to gain control over affected systems or access sensitive data. Users are generally advised to apply such updates promptly to mitigate potential risks.

The UK Department for Education reported the loss of 607,000 records. While the nature of the "loss" was not detailed, such incidents in government agencies often involve data breaches, misconfigurations leading to public exposure, or accidental deletion or corruption of data. The scale of the reported record loss suggests a significant incident, potentially impacting a large number of individuals. The specific type of records lost would determine the severity of the privacy implications, but educational data can include highly sensitive personal information.

Data loss incidents in government sectors frequently stem from a variety of causes, including sophisticated cyberattacks, insider threats, or human error in data handling and system administration. The sheer volume of records involved in this particular incident underscores the critical need for robust data governance, access controls, and comprehensive data protection strategies within public sector organizations.

Mitigation strategies for the types of incidents reported typically include maintaining up-to-date software and security patches, implementing strong access controls and multi-factor authentication, regular security audits, and comprehensive employee training on data handling best practices. For organizations managing sensitive data, robust data encryption, both in transit and at rest, is also a critical component of a defense-in-depth strategy.

These incidents collectively underscore the persistent and varied threat landscape faced by both private enterprises and public sector entities. From supply chain vulnerabilities affecting logistics to widespread software flaws and significant government data losses, the reports highlight the ongoing challenges in maintaining robust cybersecurity postures against a backdrop of evolving threats and increasing data volumes.

patchaicloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

breach

CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks

After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water utilities across the state, according to Minnesota IT Services (MNIT). “A coordinated cyberattack targeted operational technology [

security

Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)

Introduction

vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]