Weekly Cybersecurity Roundup: KDDI Breach, Zero-Day Drops, PamStealer
A Canadian hacker linked to Anonymous has been sentenced to 18 months in prison for a September 2021 cyberattack on the Texas Republican Party's website. Aubrey Cottle, 39, of Oshawa, Ontario, pleaded guilty to defacing the site, exfiltrating data from a Texas GOP server, and publishing the stolen information online. In a separate disclosure, Japanese telecoms provider KDDI revealed a data breach likely impacting the email addresses and passwords of 14.22 million customers. The incident affected five ISP operators under KDDI's umbrella, including BIGLOBE, Chubu Telecommunications, JCOM Co., NIFTY Corporation, and STNet. Users can verify exposure using an email breach checker and rotate any reused credentials via a password checker to ensure stronger replacements.
Push Security was targeted in a poisoned tenant attack three years after first documenting the technique, with attackers abusing OpenAI's organization invitation feature. Multiple employees received invitations to join a malicious Push Security Inc. tenant; once accepted, the attacker could monitor user activity and stage further social engineering. Jamf separately detailed PamStealer, a Rust-based macOS information stealer that validates harvested credentials through Pluggable Authentication Modules (PAM) before exploitation. The malware is distributed as a compiled AppleScript impersonating the legitimate open-source clipboard manager Maccy, highlighting the ongoing trend of supply-chain-style impersonation against macOS users.
Russian threat actors were responsible for the September 2025 cyberattack that severely disrupted Jaguar Land Rover's manufacturing operations, according to The New York Times. Microsoft reportedly notified the automaker of the intrusion, with Mandiant, Palo Alto Networks, and US and UK law enforcement agencies assisting in the investigation. In parallel, Citizen Lab revealed that former European Parliament member Stelios Kouloglou was hacked with NSO Group's Pegasus spyware while serving on the PEGA committee investigating Pegasus abuse, though no specific government has been attributed. Rounding out the week, a researcher using the handle "Bikini" published proof-of-concept exploit code for dozens of zero-day vulnerabilities across multiple open-source projects, a disclosure pattern that underscores the urgent need for maintainers to audit dependencies and run a comprehensive privacy checkup across exposed development environments.