SecurityWeek’s weekly cybersecurity information roundup presents a concise overview of vital developments that will not obtain full standalone protection but stay related to the broader menace panorama.
This curated abstract highlights key tales throughout vulnerability disclosures, rising assault strategies, coverage updates, business stories, and different noteworthy occasions to assist readers keep a well-rounded consciousness of the evolving cybersecurity atmosphere.
Listed here are this week’s highlights:
OpenAI disrupts Cambodia rip-off community abusing ChatGPT
OpenAI banned a coordinated set of ChatGPT accounts linked to a Cambodia-based operation that used the mannequin to run funding, romance, playing, and regulation enforcement impersonation scams. The community generated pretend personas, translated messages, created promotional pictures, and solid paperwork.
Amgen confirms knowledge theft from cloud environments
Amgen detected unauthorized entry to knowledge saved in third-party cloud environments in July 2026 and later decided that proprietary data and affected person protected well being data had been exfiltrated. The corporate has seen no impression on merchandise, manufacturing, monetary methods, or affected person care. Investigation continues into the total scope of accessed knowledge, and required notifications will comply with.
Apple caps bug bounty stories amid AI-generated false positives
Apple has restricted [gated article from Financial Times] the variety of vulnerability submissions researchers can have in its bug bounty program after a surge of low-quality, AI-hallucinated stories that bury actual findings. Cybersecurity agency Bynario hit the brand new cap after utilizing ChatGPT to floor greater than 50 macOS points, together with a privilege-escalation exploit it couldn’t instantly report. Researchers can request greater limits, and Apple itself has begun utilizing AI to assist triage submissions.
Trump administration eyes ban on Chinese language knowledge middle parts
The FCC is drafting guidelines that might block imports of recent Chinese language optical transceivers used inside knowledge facilities, aiming to scale back dangers of information theft, malware, or service disruption in AI infrastructure. Officers hope to finalize the measure this yr. US transceiver makers noticed share positive aspects on the information, although cloud operators may face greater prices as they shift suppliers.
QuickFox VPN provide chain assault drops FDMTP implant
A long-running provide chain compromise of the QuickFox VPN and game-accelerator app delivered a trojanized Electron installer that executed a JavaScript loader and in the end put in the FDMTP implant on Home windows methods. The loader used process-based guardrails to keep away from Steam customers and like endpoints operating improvement, database, or crypto instruments earlier than downloading the following stage. QuickFox eliminated the malicious parts after Fortinet’s disclosure.
Zbtlink routers ship with built-in backdoor
A number of fashions of Zbtlink (and rebranded) mobile routers come pre-loaded with an implant based mostly on the obscure Rctl software that telephones residence at boot and accepts unauthenticated root instructions. The backdoor, dubbed EndlessDoors, requires no inbound entry and any social gathering controlling the C2 endpoints can concern shell instructions or open interactive root shells. VulnCheck revealed detection steerage and suggested treating affected units as untrusted.
DoubleCup ClickFix loader delivers CountLoader and DeviceManager RATs
A Russian Loader-as-a-Service referred to as DoubleCup has been powering ClickFix campaigns since early June 2026, utilizing steganography and environmental keying to ship payloads. Noticed second-stage malware contains an up to date CountLoader (Home windows and macOS) that patches professional binaries for stealth, and a newly recognized DeviceManager RAT that resolves C2 through Ethereum/Polygon sensible contracts.
IEH Company worker mailbox breached through phishing
IEH Company, which gives high-reliability Hyperboloid connectors for protection, aerospace, and area functions, found on August 4 {that a} menace actor had gained unauthorized entry to an worker’s Microsoft 365 mailbox. The compromise started with a phishing message impersonating a potential enterprise contact that led the person to enter credentials on a pretend login web page. The actor may view emails, attachments, buy orders, and engineering information in the course of the interval of entry, although the corporate has discovered no proof of outbound emails or profitable knowledge exfiltration.
Cyberattack disrupts North Carolina port operations
North Carolina Ports confirmed a cyberattack detected August 4 that brought on a systems-wide outage affecting the Port of Wilmington, Port of Morehead Metropolis, and Charlotte Inland Port. Gates reopened with anticipated delays the next day after the IT crew activated its contingency plan and contained the breach. It stays unclear whether or not any delicate knowledge was taken.
Vishing wave hits main hedge funds
Hackers carried out a sequence of voice-phishing assaults towards a number of giant hedge funds and personal fairness companies, utilizing know-how that mimics voices to trick staff into granting entry or disclosing data. Impacted firms [gated] embody Two Sigma, which stated it blocked the try with no impression to knowledge or methods, and Point72, which informed buyers it was reviewing an incident with no preliminary proof of shopper knowledge theft. Citadel and others declined to touch upon the extent of any compromise.








