Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2171+ Articles
156+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
NEWS

In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research

This week's security roundup covers a parcel delivery company breach at OnTrac, Adobe's latest security patches, AWS attribution of recent cloud attacks to North Korean threat actors, an OpenAI open source security tool release, and Mythos crypto research targeting DeFi protocols.

Dylan H.

News Desk

August 2, 2026
4 min read

Weekly Security Roundup

This week's roundup from SecurityWeek highlights several stories that may have slipped under the radar amid the week's bigger headlines. From a parcel delivery company breach to AWS attribution of cyberattacks to North Korean state actors, here's what you need to know.

OnTrac Hacked: Parcel Delivery Breach

OnTrac, a regional parcel delivery and logistics company operating in the western United States, disclosed that it was the victim of a cyberattack. The breach exposed customer data, though the full scope — including the number of individuals affected and the nature of the data compromised — was not fully detailed in initial reporting.

Logistics and shipping companies have become attractive targets for threat actors due to the volume of personally identifiable information (PII) they process, including delivery addresses, contact information, and in some cases payment details tied to delivery confirmation systems.

AWS Links Recent Cloud Attacks to North Korean Actors

Amazon Web Services (AWS) has attributed a series of recent cloud infrastructure attacks to North Korean-affiliated threat actors. The attacks are consistent with the operational tradecraft of groups such as Lazarus Group and affiliated units that have increasingly pivoted to targeting cloud environments for cryptocurrency theft and espionage operations.

North Korean state-sponsored hackers have escalated cloud targeting in recent years, using compromised AWS credentials obtained through phishing, supply chain attacks, and developer-targeted malware to:

  • Enumerate S3 buckets for sensitive data
  • Exfiltrate credentials and private keys stored in cloud configuration files
  • Establish persistence via IAM role abuse and lambda function backdoors
  • Fund state programs through cryptocurrency theft via DeFi protocol exploitation

AWS customers should review their IAM configurations, enable CloudTrail logging, and audit for unexpected cross-account access or unusual API call patterns consistent with credential abuse.

Adobe Security Patches

Adobe released a security update addressing vulnerabilities in multiple products. As is typical for Adobe's patch cadence, the updates addressed a range of severity levels across products in the Creative Cloud ecosystem. Adobe customers are advised to apply available updates through Creative Cloud's built-in update mechanism or the Adobe Enterprise Admin Console for managed deployments.

OpenAI Releases Open Source Security Tool

OpenAI published a new open source security tool aimed at helping developers and organizations better manage AI model security. While full details of the tool's capabilities were not available at the time of initial reporting, OpenAI has been increasingly focused on releasing security-oriented tooling alongside its model releases — including red-teaming frameworks, evaluation harnesses, and policy enforcement utilities.

The release reflects broader industry momentum toward treating AI system security as a distinct engineering discipline requiring dedicated tooling.

UK Department for Education Exposes 607,000 Records

The UK Department for Education (DfE) experienced a data exposure incident affecting approximately 607,000 records. The incident adds to a growing list of public sector data protection failures in the United Kingdom and is likely to attract scrutiny from the Information Commissioner's Office (ICO) given the scale of the exposure and the sensitivity of education-related data, which frequently involves records of minors.

Mythos Crypto Research

Security researchers published new findings on Mythos, a threat actor or research campaign targeting cryptocurrency and DeFi protocols. The research highlights ongoing risks in the DeFi ecosystem, where smart contract vulnerabilities, oracle manipulation, and flash loan attacks continue to enable significant fund drains from protocols with insufficient security review.

The Mythos research is consistent with a broader pattern of security work documenting how sophisticated actors — ranging from state-sponsored groups like North Korea's Lazarus Group to independent financially motivated criminals — have made DeFi protocol exploitation a primary revenue source.

Key Takeaways

  • Logistics companies handling PII remain high-value breach targets
  • AWS cloud environments face active targeting by North Korean threat actors — review IAM hygiene and enable comprehensive CloudTrail auditing
  • Adobe patching should be routine; verify Creative Cloud updates are applied across managed endpoints
  • AI security tooling from major labs like OpenAI is maturing — track open source releases for integration into your security programs
  • DeFi protocol risk remains elevated; the Mythos research underscores the need for rigorous smart contract audits before and after deployment

References

  • SecurityWeek: In Other News — OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
#North Korea#AWS#OpenAI#Breach#Crypto#Security Updates

Related Articles

Security Roundup: OpenAI Open Sources Codex Security CLI, AWS Pins NPM Attacks on North Korea, Anthropic Mythos Cracks Crypto

Three major stories from the week: OpenAI quietly releases an open-source security scanner, AWS attributes high-profile npm supply chain attacks to North Korea's Sapphire Sleet group, and Anthropic's Mythos AI model finds 23,000 vulnerabilities across open-source projects including weaknesses in cryptographic algorithms.

5 min read

In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum

This week's security roundup covers Apple's patch for a Beats headphones eavesdropping vulnerability, the DOT closing its investigation into Delta's...

5 min read

LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

Security researchers have disclosed three now-patched vulnerabilities in LangGraph — including a critical chain that enables remote code execution on...

4 min read
Back to all News