SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.
This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment.
Here are this week’s highlights:
OpenAI disrupts Cambodia scam network abusing ChatGPT
OpenAI banned a coordinated set of ChatGPT accounts linked to a Cambodia-based operation that used the model to run investment, romance, gambling, and law enforcement impersonation scams. The network generated fake personas, translated messages, created promotional images, and forged documents.
Amgen confirms data theft from cloud environments
Amgen detected unauthorized access to data stored in third-party cloud environments in July 2026 and later determined that proprietary information and patient protected health information had been exfiltrated. The company has seen no impact on products, manufacturing, financial systems, or patient care. Investigation continues into the full scope of accessed data, and required notifications will follow.
Apple caps bug bounty reports amid AI-generated false positives
Apple has limited [gated article from Financial Times] the number of vulnerability submissions researchers can have in its bug bounty program after a surge of low-quality, AI-hallucinated reports that bury real findings. Cybersecurity firm Bynario hit the new cap after using ChatGPT to surface more than 50 macOS issues, including a privilege-escalation exploit it could not immediately report. Researchers can request higher limits, and Apple itself has begun using AI to help triage submissions.
Trump administration eyes ban on Chinese data center components
The FCC is drafting rules that would block imports of new Chinese optical transceivers used inside data centers, aiming to reduce risks of data theft, malware, or service disruption in AI infrastructure. Officials hope to finalize the measure this year. US transceiver makers saw share gains on the news, though cloud operators could face higher costs as they shift suppliers.
QuickFox VPN supply chain attack drops FDMTP implant
A long-running supply chain compromise of the QuickFox VPN and game-accelerator app delivered a trojanized Electron installer that executed a JavaScript loader and ultimately installed the FDMTP implant on Windows systems. The loader used process-based guardrails to avoid Steam users and prefer endpoints running development, database, or crypto tools before downloading the next stage. QuickFox removed the malicious components after Fortinet’s disclosure.
Zbtlink routers ship with built-in backdoor
Multiple models of Zbtlink (and rebranded) cellular routers come pre-loaded with an implant based on the obscure Rctl tool that phones home at boot and accepts unauthenticated root commands. The backdoor, dubbed EndlessDoors, requires no inbound access and any party controlling the C2 endpoints can issue shell commands or open interactive root shells. VulnCheck published detection guidance and advised treating affected devices as untrusted.
DoubleCup ClickFix loader delivers CountLoader and DeviceManager RATs
A Russian Loader-as-a-Service called DoubleCup has been powering ClickFix campaigns since early June 2026, using steganography and environmental keying to deliver payloads. Observed second-stage malware includes an updated CountLoader (Windows and macOS) that patches legitimate binaries for stealth, and a newly identified DeviceManager RAT that resolves C2 via Ethereum/Polygon smart contracts.
IEH Corporation employee mailbox breached via phishing
IEH Corporation, which provides high-reliability Hyperboloid connectors for defense, aerospace, and space applications, discovered on August 4 that a threat actor had gained unauthorized access to an employee’s Microsoft 365 mailbox. The compromise began with a phishing message impersonating a prospective business contact that led the user to enter credentials on a fake login page. The actor could view emails, attachments, purchase orders, and engineering files during the period of access, though the company has found no evidence of outbound emails or successful data exfiltration.
Cyberattack disrupts North Carolina port operations
North Carolina Ports confirmed a cyberattack detected August 4 that caused a systems-wide outage affecting the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. Gates reopened with expected delays the following day after the IT team activated its contingency plan and contained the breach. It remains unclear whether any sensitive data was taken.
Vishing wave hits major hedge funds
Hackers conducted a series of voice-phishing attacks against several large hedge funds and private equity firms, using technology that mimics voices to trick employees into granting access or disclosing information. Impacted companies [gated] include Two Sigma, which said it blocked the attempt with no impact to data or systems, and Point72, which told investors it was reviewing an incident with no initial evidence of client data theft. Citadel and others declined to comment on the extent of any compromise.
Related: In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
Related: In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
