Artificial Intelligence & Machine Learning
,
Cybercrime
,
Fraud Management & Cybercrime
Also, Russian Hackers Exploit Outlook Flaw, Coca-Cola Restarts Fairlife Production
Every week, ISMG rounds up cybersecurity incidents and breaches around the world. This week: “I’m mean there could be, yeah,” is what OpenAI’s Sam Altman said when asked about more model hacking. A Russian nation-state hacking group revived with an Outlook web access exploit, Coca-Cola restarted Fairlife milk production after a ransomware attack, a U.K. Education Department breach, an attack took down an Angola mobile operator. A SonicWall credential stuffing campaign, a Russian arrest warrant for Telegram’s Pavel Durov and researchers highlighted how hidden prompts could spread through Microsoft Copilot.
See Also: Scattered Spider Exposed: Critical Takeaways for Cyber Defenders
OpenAI Models on a Hacking Tear
OpenAI CEO Sam Altman said the company’s artificial intelligence models may have also accessed other companies’ systems, days after OpenAI revealed they had breached code repository Hugging Face.
Answering reporters on Capitol Hill whether the models had hacked other systems, Altman said, “I mean there could be, yeah.”
His comment comes after OpenAI updated its blog post about the Hugging Face incident. The company said it has “been finding a small number of cases where the models identified and used publicly exposed credentials at the account-level on other publicly available services.”
OpenAI’s post said this includes four accounts on four unnamed services as part of the Hugging Face breach. They said one of the accounts “was used as an outbound relay and staging path, a second for data storage, and the remaining two accounts were accessed only “in a read-only manner” and did not help in attacking Hugging Face.
“We’ll continue to notify service owners directly and have not seen evidence of broader impact on these providers or other accounts on their services,” OpenAI said in its post.
Reuters reported that one of the companies not named by OpenAI is Modal Labs. The company’s CTO Akshat Bubna told Reuters that the models exploited code written by a Modal customer that was hosted on Modal’s cloud infrastructure.
Russian Spy Group Revives Campaign With Outlook Web Access Exploit
A Russia nation-state cyberespionage group resurfaced after months of inactivity, using a newly patched Microsoft Outlook Web Access vulnerability to compromise organizations and maintain long-term access to email systems, found to Proofpoint.
The campaign, attributed to TA488 – also known as Void Blizzard and Laundry Bear, began on July 22 and targeted government agencies in the United States and Europe, as well as organizations in the telecommunications, financial services, hospitality and aerospace sectors.
The attackers exploited CVE-2026-42897, a cross-site scripting flaw affecting on-premises Microsoft Exchange Server. Simply opening a malicious email in a vulnerable OWA client was enough to trigger the attack, requiring no links, attachments or additional user interaction.
Proofpoint said the group used ordinary-looking emails with subjects related to supply chains, gas markets and tourism to avoid attracting attention.
The attack deployed a previously unknown JavaScript implant dubbed OWAReaper, which operated entirely within the OWA reading pane without leaving files on disk. The malware harvested credentials, modified the original email to remove evidence of the exploit and stored an encrypted copy of itself in the browser for continued execution.
The implant established server-side persistence by abusing Exchange mailbox permissions, allowing attackers to retain access even after passwords were changed or infected devices were reimaged.
Proofpoint said the malware received commands through GitHub commit messages or email and exfiltrated stolen data over HTTPS, with DNS tunneling as a fallback. Microsoft has since released patches for the vulnerability and organizations are urged to apply the updates and review Exchange permissions.
Coca-Cola Restarts Fairlife Production After Ransomware Disruption
The milk production division of beverage giant Coca-Cola mostly resumed production after a ransomware attack disrupted operations at four U.S. plants earlier this month.
The company said Monday Fairlife ultra-filtered milk brand has made “significant progress” in restoring affected systems and restarted the majority of production at the impacted facilities.
Coca-Cola disclosed on July 16 that an unauthorized third party had accessed parts of Fairlife’s technology environment in a ransomware attack. The company temporarily suspended production at Fairlife plants while responding to the incident although it said that product quality and safety were never affected (see: Anubis Ransomware Halts Fairlife Milk Production in the US).
The company said the disruption is not expected to have a material impact on sales, stating that existing inventory has kept Fairlife products widely available at retail. Coca-Cola acquired Fairlife from Select Milk Producers in 2020 for about $7 billion.
UK Education Department Confirms Breach of 607K Records
The U.K. Department for Education said a cyberattack exposed about 607,000 records, the BBC reported.
The stolen data is linked to its customer helpdesk and the Turing Scheme, an international education funding program. The department said the compromised data was limited to customer service contact details for individuals and organizations and that no other systems or data were accessed.
The Times reported that the leaked information includes names and email addresses of head teachers, university staff and government officials. A cybercrime group calling itself ExfilSquad has claimed responsibility, saying it stole about 600,000 records from the help portal and another 7,000 from the Turing portal, including names, email addresses, phone numbers and job titles.
Cyberattack Hits Angola’s Largest Telecom Before IPO
A cyberattack against Angola’s largest telecommunications operator disrupted mobile voice, data and internet services nationwide. It occurred just hours before the Angolan government sold on the national stock market a 15% stake in the firm, a large chunk of the quarter stake in the telecom the government seized in 2020.
The company said it detected the incident shortly after 2 a.m. local time. Technical and cybersecurity teams are working to restore services, although Unitel has not disclosed the nature of the attack or when operations will fully resume.
Network data reviewed by The Record suggests the disruption stemmed from an internal systems failure rather than an external connectivity outage or distributed denial-of-service attack. Cloudflare Radar also showed a sharp drop in Unitel’s traffic beginning around the time the attack was detected, while other Angolan telecom networks were unaffected.
The outage also disrupted point-of-sale payment terminals operating on Unitel’s network, affecting businesses and digital services, according to Angolan publication Expansão.
TechAfrica News reported Thursday that service has been partially restored.
Credential Stuffing Campaign Compromises SonicWall Accounts Across 30 Organizations
A large-scale credential stuffing campaign targeting SonicWall VPN and firewall accounts compromised 92 user accounts across 30 organizations in less than two days, said a Huntress threat advisory.
The attacks began on Saturday and continued for about 41 hours before abruptly stopping on Monday. Huntress researchers said the campaign appeared broad and opportunistic, targeting any internet-facing SonicWall device rather than specific industries or organizations.
Researchers observed no post-compromise activity, suggesting attackers may be pre-positioning access for future operations rather than launching immediate attacks.
The attackers are unidentified and the root cause is still under investigation. Huntress said the intrusions began with successful, authorized logins, indicating attackers likely used previously stolen credentials. Possible sources include infostealer malware logs, compromised SonicWall configuration files or credentials harvested during earlier breaches.
SonicWall has not issued a security advisory, saying it is continuing to investigate the activity.
The campaign follows years of attacks against SonicWall products. In 2025, a suspected state-sponsored actor breached SonicWall’s cloud environment and stole customer firewall configurations. The company has also faced repeated exploitation of zero-day vulnerabilities, while 17 SonicWall flaws have been added to CISA’s Known Exploited Vulnerabilities catalog since late 2021, including 10 linked to ransomware campaigns.
Russia Seeks Arrest of Telegram Founder Pavel Durov on Terrorism Charges
Russia issued an arrest warrant for Telegram founder Pavel Durov, accusing him of facilitating terrorist activities through the messaging platform in a dramatic escalation of its long-running conflict with the tech billionaire.
Russia’s Federal Security Service alleges Telegram failed to remove content used by Ukrainian intelligence services and extremist groups to coordinate sabotage, cyber fraud and armed attacks inside Russia. Authorities claim the platform enabled the recruitment of Russians for terrorist activities and have charged Durov with aiding terrorism, an offense that carries a potential life sentence if convicted.
Telegram responded to the charges by posting an image of Durov making an obscene gesture.
The latest charges add to Durov’s legal troubles following his 2024 arrest in France over separate allegations related to Telegram’s content moderation practices.
Hidden Prompt Turns Microsoft Copilot Into Self-Spreading AI Worm
Security researchers demonstrated a proof-of-concept attack that can turn Microsoft Copilot for Word into a self-propagating “AI worm” by embedding hidden prompts inside Word documents.
The attack uses prompt injection, concealing malicious instructions as white text on a white background or in hidden document elements. While invisible to users, Microsoft Copilot can read and execute the instructions when processing the document. The hidden prompt then instructs Copilot to insert the same malicious payload into newly created or edited documents, allowing the attack to spread as users share files.
Unlike traditional malware, the technique does not exploit a software vulnerability or require users to run malicious code. Instead, it abuses how generative AI systems interpret document content.
The researchers said the attack could be adapted to manipulate AI-generated content, exfiltrate sensitive information or spread malicious prompts across organizations that rely heavily on AI-assisted document creation. However, they stressed that the work is a proof of concept and there is no evidence the technique has been used in real-world attacks.
Other Stories From This Week
With reporting by ISMG’s Emilia David in Manhattan.
Click Here For The Original Source.
