Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2041+ Articles
153+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. In Other News: Dolphin X AI Malware, Car Anti-Theft Hack, 432 Linux Kernel CVEs
In Other News: Dolphin X AI Malware, Car Anti-Theft Hack, 432 Linux Kernel CVEs
NEWS

In Other News: Dolphin X AI Malware, Car Anti-Theft Hack, 432 Linux Kernel CVEs

This week's security roundup covers an AI-prioritizing infostealer targeting developer machines, a hardcoded Bluetooth key in 2.2 million car anti-theft units, a single-day flood of 432 Linux kernel CVEs, and ongoing threats from Siemens ICS zero-days and Russian Zimbra espionage.

Dylan H.

News Desk

July 24, 2026
4 min read

Dolphin X: The Infostealer That Uses AI to Pick Its Victims

Varonis Threat Labs has disclosed Dolphin X, a new infostealer that goes beyond conventional credential harvesting by incorporating AI behavioral profiling to score and prioritize victims based on installed software and system activity.

The malware targets over 300 applications — browser password stores, cryptocurrency wallets, SSH keys, AWS and GCP tokens, and developer toolchains. What sets it apart is the triage layer: rather than exfiltrating everything from every machine, Dolphin X uses behavioral analysis to identify high-value targets and focus attacker effort accordingly.

For organizations with developer machines connected to production environments, this is a significant escalation. A single Dolphin X infection on an engineer's workstation could hand attackers live cloud credentials, private SSH keys, and access to internal repositories — the keys to an entire infrastructure.

Defensive posture: Endpoint detection focused on behavioral anomalies matters more here than signature-based AV. Segment developer machines, enforce short-lived credentials, and audit SSH key usage.


2.2 Million Car Anti-Theft Devices Exposed by Hardcoded Bluetooth Key

Security researchers discovered a fundamental flaw in KARR and Secure Wireless Detection Systems (SWDS) aftermarket anti-theft units manufactured by Acrisure — devices installed in at least 2.2 million vehicles, predominantly through dealerships in Southern California.

The vulnerability: a hardcoded Bluetooth key embedded in the device firmware. Any attacker within approximately 5 yards can use the key to remotely unlock vehicle doors. Acrisure has released patches, though the vendor characterized the flaw as "highly complex" with "low risk" in real-world conditions — a framing security researchers are unlikely to share given that hardcoded credentials are among the most well-understood classes of vulnerability.

This follows a familiar pattern in automotive IoT: the physical security promise of an aftermarket device completely undermined by a software shortcut taken during development.

Mitigation: Check with your dealership or the Acrisure website for firmware update availability for affected KARR and SWDS units.


432 Linux Kernel CVEs in a Single Day

In a development that has overwhelmed vulnerability management teams, 432 CVEs were published against the Linux kernel in a 24-hour window in mid-July 2026. This is an unprecedented single-day volume and has created acute triage pressure across enterprises, cloud providers, and embedded Linux deployments.

No single catastrophic vulnerability anchors the release — the volume reflects accumulated upstream security fixes being formally enumerated rather than a coordinated disclosure event. That said, the sheer count strains automated patch management pipelines and vulnerability scanner capacity.

Security teams are advised to:

  1. Prioritize by kernel version and configuration — not all 432 CVEs apply to all kernels.
  2. Use vendor advisories (Red Hat, Ubuntu, SUSE) to identify which CVEs affect your specific distributions.
  3. Avoid treating the count itself as a severity signal — assess individual CVE impact ratings.

Siemens ROX II: Three Chained Zero-Days in Industrial Switches

Unit 42 researchers disclosed a chain of three zero-day vulnerabilities in Siemens ROX II industrial switches used in operational technology (OT) environments:

  • CVE-2025-40948 — Arbitrary file disclosure, enabling intelligence gathering
  • CVE-2025-40947 — Command injection via privilege escalation
  • CVE-2025-40949 — Web management scheduler flaw enabling code execution that persists across reboots

Chained together, these vulnerabilities enable an attacker to achieve persistent root-level access on network switches controlling industrial processes. The persistence mechanism is particularly concerning in OT environments where reboots are infrequent and monitoring is often limited.

Siemens has published patches and mitigations in coordination with ICS-CERT.


Russian Laundry Bear APT Exploits Zimbra for Zero-Click Espionage

CISA, in coordination with international partners, has issued an advisory on Laundry Bear, a Russian state-sponsored threat actor exploiting CVE-2025-66376 in Zimbra Collaboration Suite.

The attack is zero-click: a malicious email triggers the exploit automatically upon being opened, immediately exfiltrating the victim's inbox. Targets span Western government entities and commercial organizations. Zimbra has patched the vulnerability; organizations running unpatched Zimbra instances should treat this as an emergency update.


Stadler Rail Ransomware Extortion

The Everest ransomware group claimed responsibility for stealing technical data from Stadler Rail's shared supplier platform in mid-July 2026, demanding approximately 10 million Swiss francs (~$12M USD). Stadler refused to pay and confirmed no critical security, personal data, or production operations were affected.

The incident highlights ongoing ransomware targeting of manufacturing and critical infrastructure supply chains — even when the primary target proves resilient, supplier platforms can serve as entry points.

References

  • SecurityWeek Coverage
#Malware#Linux#IoT#Ransomware#Russia#ICS#Cybercrime#Threat Intelligence

Related Articles

LeakNet Ransomware Weaponizes ClickFix and Deno Runtime for Stealthy Corporate Attacks

The LeakNet ransomware gang is using ClickFix social engineering for initial access and a Deno-based malware loader to execute fileless payloads from...

6 min read

JadePuffer Agentic Attacks Now Target AI Model Data with Ransomware

The JadePuffer autonomous AI agent threat actor has upgraded its arsenal with EncForge, custom ransomware engineered to encrypt AI assets including training datasets, vector databases, and model checkpoints — marking a new frontier in ransomware targeting.

7 min read

ThreatsDay: Game Cheat Spyware, Spirals Ransomware, Chrome Sync Stalking

This week's threat roundup covers NuGet packages poisoned with game-cheat spyware, the Spirals ransomware deploying network-wide in under 24 hours, and Chrome Sync being exploited for no-spyware domestic surveillance.

5 min read
Back to all News