SecurityWeek’s weekly roundup covers major cybersecurity developments, including the OnTrac breach, Adobe vulnerability patches, SonicWall credential stuffing, and a North Korea-linked supply-chain campaign against popular NPM packages. It also highlights data exposure at the UK Department for Education, flaws in VE Commercial Vehicles’ My Eicher platform, and AI-assisted cryptanalysis research from Anthropic. #OnTrac #Adobe #SonicWall #SapphireSleet #DepartmentforEducation #MyEicher #Anthropic
Keypoints
- OnTrac notified customers after attackers accessed its corporate network and files.
- Adobe patched critical flaws in Bridge, Campaign Classic, and Format Plugins.
- SonicWall VPN and firewall accounts were hit by a widespread credential stuffing campaign.
- Amazon linked Axios, Debug, and Chalk package compromises to North Korea’s Sapphire Sleet.
- A researcher exposed serious flaws in VE Commercial Vehicles’ My Eicher platform, and Anthropic reported AI-assisted cryptanalysis advances.