A rundown of this week’s security stories that deserve more attention than they got.
Russia used Cellebrite to hack an activist’s phone. Citizen Lab confirmed that Russian authorities used Cellebrite software to break into opposition activist Andrey Pivovarov’s iPhone. Even though Cellebrite canceled its Russian contracts in 2021, legacy setups were still operational. Data harvested from Telegram and WhatsApp was reportedly weaponized by the ColdRiver threat group for targeted phishing against the activist’s contacts.
Scattered Spider members plead guilty. Two British men connected to the Scattered Spider group changed their pleas to guilty for the 2024 Transport for London hack. The breach disrupted fare refund systems and admin networks, costing millions. All 28,000 TfL employees had to reset passwords in person.
Tata Electronics breach exposes Apple and Tesla secrets. A massive 630 GB data leak from India’s Tata Electronics hit the dark web, published by extortion group World Leaks. The trove reportedly includes manufacturing specs, component schematics, and confidential drawings for Apple and Tesla.
Five Eyes issues AI threat warning. The intelligence coalition says AI has compressed the threat timeline from years to months. Automated vulnerability research and exploit development are democratizing high-end offensive tools for lower-skilled attackers. The advisory pushes zero-trust architectures and faster patching as immediate priorities.
macOS.Gaslight backdoor targets analysts. A Rust-based North Korean backdoor embeds adversarial prompt injection to disrupt LLM-assisted triage tools. Dozens of fake system error messages trick AI analysis into stopping investigations. It also features an interactive shell and data harvesting capabilities.
White House wants to restrict OpenAI’s GPT-5.6 rollout. Federal officials asked OpenAI to delay and tightly control deployment of its next model. Preview access will be vetted client-by-client by government agencies. This follows similar restrictions placed on Anthropic’s advanced AI models.
Qihoo 360 announces Mythos-like AI. The blacklisted Chinese cybersecurity firm’s CEO unveiled Tulongfeng, an AI system the company claims can match Western frontier models for vulnerability discovery. The exec admitted it may not be as powerful as Mythos, but combined with other Qihoo tools, the capability is reportedly similar.
Snyk layoffs. The security vendor cut staff as part of a restructuring that consolidates R&D around four areas and flattens leadership for faster decisions. Israeli media reports suggest around 90 employees affected.
