AI-Powered Dolphin X Malware, Siemens Zero-Days, Stadler Ransomware: Weekly News
Varonis Threat Labs has uncovered a sophisticated infostealer dubbed Dolphin X that leverages an AI behavioral profiler to score and prioritize infected hosts based on user activity and installed software. The malware targets more than 300 applications, harvesting browser passwords, cryptocurrency wallets, SSH keys, and cloud tokens. Security teams should alert developers to this threat, as a single compromised workstation could expose an entire production environment through stolen credentials. Users worried about exposed credentials can verify their status with an email breach checker and strengthen any compromised logins using a reliable password checker.
Unit 42 researchers at Palo Alto Networks have detailed a three-vulnerability exploit chain in Siemens ROX II OT switches that enables persistent root-level access. Attackers chain an arbitrary file disclosure flaw (CVE-2025-40948) with a command injection privilege escalation (CVE-2025-40947), then cement the compromise via a web management task scheduler flaw (CVE-2025-40949) that survives reboots. Organizations running industrial control infrastructure should patch immediately and audit the integrity of their management interfaces, including verifying TLS configurations with an SSL/TLS checker.
Swiss train manufacturer Stadler Rail has refused to pay a 10 million Swiss franc (approximately $12 million) extortion demand from the Everest ransomware group following a targeted data theft incident. The attackers breached a data exchange platform shared with a supplier in mid-July, stealing technical schematics without impacting Stadler's IT systems or production. Separately, Abbott has disclosed a cybersecurity incident affecting its Cancer Diagnostics business, with the ShinyHunters group claiming responsibility, though operations and patient care remain unaffected. A cyberattack on a Maine telecommunications provider also disrupted internet services across 23 towns, affecting municipal networks and local government operations.
German law enforcement has successfully dismantled the Kratos phishing group, a network responsible for widespread credential-harvesting campaigns. The takedown marks a significant win against phishing infrastructure operators targeting European users. The week's developments underscore the growing convergence of AI-driven malware, unpatched OT vulnerabilities, and financially motivated ransomware, highlighting the need for organizations to maintain layered defenses, monitor for exposed credentials, and conduct regular security assessments across both IT and operational environments.