SecurityWeek’s weekly roundup covers stories that might have slipped under your radar. Here’s what happened this week.
Canadian hacker sentenced. Aubrey Cottle, a 39-year-old Anonymous-linked hacker from Oshawa, Ontario, got 18 months in prison for the 2021 cyberattack on the Texas Republican Party’s website. He pleaded guilty to defacing the site and publishing stolen data.
KDDI data breach. Japanese telecom KDDI disclosed a breach affecting 14.22 million people — email addresses and passwords. The incident hit five ISP operators including BIGLOBE and NIFTY Corporation.
Open source zero-days. A researcher named Bikini published PoC code targeting dozens of zero-day vulnerabilities in popular open source projects — FFmpeg, Gogs, Gitea, Ghidra, 7-Zip, OpenVPN, and VLC. Nine of them have CVEs assigned. The researcher says they were found via LLM fuzzing.
ATM jackpotting sentencing. Two Venezuelan nationals, Carlos Javier Padron and Arnoldo Cabrera Torrealba, were sentenced to 78 months in US prison for ATM jackpotting. They built and deployed Ploutus malware on ATMs across the US and were ordered to pay $1.5 million in restitution.
Other notable items: Pegasus spyware hit a European Parliament member who was investigating Pegasus abuse. Russian hackers were behind the 2025 Jaguar Land Rover attack. Cisco patched seven ClamAV flaws, and Synology fixed two critical bugs in MailPlus Server.
