Analog Devices breach, Copilot AI worm, Teams ransomware vishing | #ransomware | #cybercrime


Today on CISO Series…


In today’s cybersecurity news…

Semiconductor firm Analog Devices discloses data breach

The Massachusetts-based company, which designs and manufactures analog, mixed-signal, and digital signal processing chips for the industrial, automotive, and communications sectors, announced, in a Wednesday filing with the SEC, that it had detected unauthorized access to certain of its systems on June 23. The attack resulted in the theft of certain files, but the nature of these files was not described. The company further stated that it is not aware of the files having being leaked, and the attack is “not expected to have a material impact on its business, operations, or financial condition.”

Copilot for Word POC copies hidden prompts into new documents

According to Norwegian AI and machine learning researcher

Håkon Måløy

, “hidden instructions in a Word document can make
Microsoft 365
Copilot rewrite figures in a report, then copy the same instructions into the finished file. This is an AI worm technique that Måløy disclosed on Tuesday, 144 days after reporting it to Microsoft, who confirmed it and deployed mitigations up to GPT-5.5. However the full chain works with modified instructions on GPT-5.6, and therefore remains exploitable. This attack is not a zero-click and does not execute malware. “It requires a Copilot drafting or editing operation, and the malicious document must enter the model’s context as an attachment or as a OneDrive source selected by Work IQ, the intelligence engine behind Microsoft 365 Copilot.” There is no evidence of this technique having been exploited in the wild as of yet. A link to a summary of the Måløy report is available in the show notes to this episode.

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Threat actors are once again impersonating IT support staff, this time in
Microsoft
Teams calls, to gain remote access to corporate devices and deploy Chaos ransomware.
Sophos
, who is tracking the campaign as STAC4749, says it has targeted dozens of North American organizations between February and June 2026, with at least three of these intrusions leading to the deployment of Chaos ransomware. One of these attacks went from initial access to encrypting files in less than 17 hours. The attacks begin with “external Microsoft Teams accounts impersonating IT helpdesk or support personnel in Teams chats and voice calls to targeted employees.

FTC sues Hims & Hers for allegedly sharing patients’ medical data with advertisers

The U.S.
Federal Trade Commission
has sued telehealth provider Hims & Hers, alleging it illegally shared customers’ sensitive health information with advertising and technology companies, including Meta, Snap, Microsoft, Pinterest, Reddit, and X, despite privacy promises to users. The FTC claims website tracking pixels collected data about users’ health-related activity and transmitted it to third parties, while also accusing the company of deceptive billing and making subscription cancellations unnecessarily difficult. Hims & Hers says its privacy policy allows users to control how their data is used and plans to fight the allegations.

Big thanks to our sponsor,
Pindrop


OpenAI Hugging Face attack a case of human error, not rogue AI

Following up on the OpenAI Hugging Face-Modal breach event that we have been covering these past two weeks, some cybersecurity experts are calling this a case of human error, in that the sandbox from which GPT-5.6 Sol and a more capable pre-release model escaped which should have been completely physically secluded from the internet, wasn’t. “Dan Guido, the founder of cybersecurity research startup
Trail of Bits
, called the mistake ‘a containment failure with the safeties turned off.’” In his blog, he describes that the sandbox was “a highly isolated environment, with network access constrained to the ability to install packages through an internally hosted third-party software that acts as a proxy and cache for package registries.” It appears that a zero-day vulnerability in the package-installation system became the a critical first step in the eventual hack on Hugging Face.

UK Department for Education reveals vulnerabilities and spurs industry reaction

Following up on a story we covered yesterday, regarding the theft of more than 740,000 records from the UK Department for Education and Police National Legal Database, a number of high profile members of the cybersecurity industry, spoke out, pointing to “the vulnerability of help desks and customer-facing portals as an entry point into otherwise well-defended government systems.” The richness of the data these departments hold, paired with data that shows education is currently one of the most targeted sectors globally, facing thousands of attacks per organization every week, led to an outpouring of frustration regarding the lack of defense focus this sector receives. A link to an article containing many comments is available in the show notes to this episode.

Senate confirms Clayton as intel chief after delays

The Senate on Tuesday confirmed Jay Clayton as the next Director of National Intelligence. Senators voted along party lines, 51-47. He is currently the U.S. attorney for the Southern District of New York, and will assume leadership of the organization that is “meant to oversee and coordinate the country’s nearly 20 intelligence agencies.”

Google develops new naming convention for threat actors

So long, Cozy Bear and Volt Typhoon.
Google
has created a new taxonomy for cybercrime outfits, leaving behind Microsoft’s earlier attempt at creating consistent names. Following its acquisition and absorption of Mandiant, it is announcing a two-word schema in which “the first word “is a unique and memorable term chosen to represent the specific actor.” The second word will “categorize threat clusters by motivation, attribution, or activity type based on which category we consider to be most important for defense and response strategies.” This means the following words will be applied:

CASTLE to describe crews from the People’s Republic of China

ION for threats from Iran

NEPTUNE for North Korean attackers

COMET for gangs not backed by a state


Subscribe to Cybersecurity Headlines podcast

Spotify, Apple Podcasts, YouTube, RSS link, Amazon Music, add as an Alexa Skill, or search “Cybersecurity Headlines” on your favorite podcast app.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW