SecurityWeek weekly newspaper overview of cybersecurity news offers a brief overview of important developments that may not receive full stand-alone coverage but remain relevant to the broader threat landscape.
This curated digest highlights key vulnerability disclosure stories, emerging attack methods, policy updates, industry reports, and other notable events to help readers stay fully informed of the evolving cybersecurity landscape.
Here are this week’s highlights:
Developers say Log4j vulnerability warning is exaggerated
This week, the Apache Log4j 2 vulnerability raised concerns in the cybersecurity community. Reports began circulating for a critical remote code execution vulnerability. The developers of Log4j, however appeased fearsdescribing the issue as “a known security bug”. They confirmed its potential for remote code execution, but pointed out the specific circumstances required for exploitation and noted that volunteers’ limited time could be spent on more useful things. Log4j vulnerabilities can have a serious impact, as demonstrated by the Log4Shell breach a few years ago.
Bank of America responds to ransomware gang’s claims
US Bancorp says the ransomware allegations involving its name actually stem from a potential incident at 4th party supplieroutside the bank environment. The bank says there is currently no evidence that its systems, networks or data stores have been compromised, although LockBit has threatened to publish allegedly stolen data.
Cybersecurity firm Minimus is shutting down
Container stable imaging provider Minimus is shutting down after raising $51 million in 2025, saying the business and investment climate made it too difficult to continue. The suspension comes less than a month after the company appeared at the Black Hat conference. Shortly after Minimus announced it was going out of business, Echo said so acquired the company and its technology.
Credential Leak Investigation
Security with truffles study found over 700 still-active corporate AWS keys that gave full control over their accounts. The discovery was made during the review of 10,616 AWS keys exposed between 2022 and 2026. Separately, Intruder found 28,000 Git repositories exposed while scanning 3.5 million active hosts, revealing more than 400 AWS keys, 107 Stripe keys, 123 OpenAI keys, 80 Telegram tokens, and 17 GitHub PATs. Some credentials were still active and could provide access to cloud environments, private source code, and other sensitive systems.
Mobile banking malware is expanding its reach
Cimperium found 30 mobile malware families actively targeting more than 800 banking and fintech applications in 44 EMEA countries. The research also shows that attackers are increasingly using AI in the attack chain, from localized decoys and exploit scripts to more convincing phishing pages and overlays.
Carhartt’s breakthrough data is partly false
Troy Hunt found that much of the data attributed to Carhartt’s alleged breach was actually synthetic TPC-DS benchmark data mixed with real customer information. His analysis suggests that roughly half of the 24.8 million email addresses were spam records, meaning ShinyHunters’ original breach claims vastly overstated the amount of actual customer data involved.
Paylogix breach exposes sensitive records
Paylogix says attackers stolen files from its network over several days in November, revealing Social Security numbers, financial and health insurance information, medical records, passport numbers and taxpayer identification numbers. At least 67,789 people were reported affected in South Carolina, New Hampshire and Vermont. The Akira ransomware group claimed responsibility for the attack.
Russian Cyber Learning Pipeline Exposed
Expired Bowman University records reveal a long-running program that has trained approximately 250 career and reserve students in Russian military intelligence and cyber operations. The material covers offensive and defensive cyber techniques, malware analysis, intelligence work and military assignments, with graduates linked to units linked to Russian threat groups APT28 and Sandworm.
Manchester Airports Group cyber attack
Access by hackers personal data belonging to approximately 8.7 million Manchester Airports Group customers, including email addresses, telephone numbers, vehicle registrations and postcodes. The attackers demanded a ransom for the return of the data, but MAG refused to pay. The company said airport operations, passenger safety and aviation security were not affected.
US imposes sanctions on Iranian hackers
US Treasury Department sanctioned Iranian cyber actors linked to MOIS accuse the group of compromising critical infrastructure and committing financially motivated cyber theft. The Treasury Department said Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh and Mohammad Reza Kadkhoda’i carried out the data compromises and theft, while four of the 17 Iranian cyber actors indicted by the FBI were named in the action.
Connected: Other news: Rapid7 layoffs, Boeing 737 hack, refrigeration vulnerabilities
Connected: In other news: zombie map attack, T-Mobile cuts cord to stop hackers, GitHub denies AI-caused bug