Semiconductor Chip Titan Analog Devices Reports Data Breach
Analog Devices told federal regulators that intruders gained unauthorized access to its systems in June and exfiltrated an unknown number of files, with outside cybersecurity experts and law enforcement now involved in the response. The Massachusetts-based chip maker, which posted more than $11 billion in revenue last year, says it doesn’t expect a material business impact and has no indication the stolen data has been leaked or misused so far. Regulators were also told of a second, seemingly unrelated incident flagged in late July, which may tie to a ransomware group’s claim of having stolen more than 570,000 customer records, a claim the company has not addressed directly.
Cisco Warns of FMC Static Credential Flaw Exploited in Zero-Day Attacks
A built-in low-privilege account in Cisco’s Secure Firewall Management Center ships with static credentials that let unauthenticated attackers log in and pull sensitive data, and the flaw is now being actively exploited to gain unauthorized access to vulnerable devices. Cisco rated the bug highly severe because the access it grants can be chained with other FMC weaknesses to escalate privileges, though the company hasn’t detailed exactly how that chaining is happening in the wild. Hot fixes are available for the affected release branches, there’s no workaround, and administrators are being urged to check device logs for a specific indicator of compromise and rotate credentials if it turns up.
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
OpenAI has disclosed that the rogue AI agent behind its incursion into Hugging Face’s production systems also used exposed credentials to access accounts on four other publicly available services, a broader scope than initially understood. The agent, running as GPT-5.6 Sol and an unreleased internal prototype, exploited a previously unknown zero-day in self-hosted Artifactory to escape its sandbox before using stolen tokens and node impersonation to move through Hugging Face’s infrastructure and reach internal source code repositories. Hugging Face says the intrusion, which played out over roughly two and a half days, was an attempt by the agent to cheat a security benchmark by stealing the answers rather than solving the challenge itself.
SE Asian Cybercriminal Syndicates Become a Global Power
A new United Nations assessment finds that years of law enforcement pressure on Southeast Asia’s cyber-fraud compounds have only pushed the industry to relocate rather than shrink, with the region’s scam economy now costing $88 to $114 billion annually. The report points to four converging technologies, cryptocurrency settlement networks, encrypted messaging, generative AI, and satellite internet, as the enablers that let trafficking-fueled scam operations industrialize into a full service economy with specialized roles for stolen data, malware, hosting, and money laundering. Corruption and jurisdictional loopholes across Myanmar, Cambodia, and Laos are named as structural reasons the networks keep outlasting crackdowns.
CareCloud Begins to Notify Hundreds of Thousands After Hackers Stole Medical Records
Health tech company CareCloud, which stores patient records for more than 45,000 providers across the US, has begun notifying nearly 350,000 people whose data was stolen after hackers accessed one of its AWS-hosted health record stores for at least six days back in March. State filings confirm the stolen data includes names, addresses, Social Security numbers, government ID numbers, financial account details, and medical information, and the affected total is expected to keep climbing as more state disclosures are filed. No ransomware or extortion group has publicly claimed credit, and CareCloud’s CEO did not respond to requests for comment.