SecurityWeek weekly newspaper overview of cybersecurity news offers a brief overview of important developments that may not receive full stand-alone coverage but remain relevant to the broader threat landscape.
This curated summary highlights key vulnerability disclosure stories, emerging attack methods, policy updates, industry reports, and other notable events to help readers stay fully informed of the evolving cybersecurity landscape.
Here are this week’s highlights:
Government deal for AI platform sparks outrage
The recent DoD awarding of an $821 million contract to Accenture Federal Services for its Military Data Platform (WDP) is criticizing for allegedly undermining the goals of rapid adoption of commercial AI. Sources say the order prioritizes the traditional consulting model over the integration of best-in-class commercial technology. The WDP contract is a restructuring of the previous Advana program and aims to provide standardized access to data for AI-enabled military operations.
North Korean IT worker breaches federal agency
The FBI is investigating how a North Korean IT worker successfully got a job at an unnamed agency of the US federal government. North Korea places thousands of remote IT workers in Western organizations using fake identities to earn salaries for the regime and steal intellectual property. The individual likely worked for the federal agency on a contract basis rather than being directly employed.
Boeing 737 Hacking
A group of academic researchers demonstrated (paywalled Wired article) how a hidden coin-sized hardware device can successfully compromise systems on a Boeing 737. Malicious actors with access to an aircraft can attach the hacking device to an external port, giving them remote access. Although an aircraft’s safety systems are likely to prevent direct harm, an attacker could tamper with data such as air temperature readings and the aircraft’s weight, and even alter the aircraft’s flight plan and divert it from its intended route.
LexisNexis is investigating another potential hack
LexisNexis took its Diligence, Metabase API and Newsdesk services offline last week after identifying unusual activity on servers operated by a third-party provider. The company said it had shut down systems to contain the threat. LexisNexis clarified that its Metabase API product is not related to Metabase Cloud, which recently disclosed a zero-day vulnerability. This would be the third data breach suffered by LexisNexis in recent years.
Hacking Commercial Refrigeration Systems
Claroty’s team82 found vulnerabilities in two widely used commercial refrigeration systems. Researchers found 23 vulnerabilities in Copeland XWEB Pro controllers, including those that can be chained together to bypass security controls and achieve root-level RCE. A demonstration showed that a compromised controller could remotely manipulate refrigeration equipment, including cooling fans and compressors, and mask the resulting temperature rise as food spoils. Team82 also identified multiple vulnerabilities in the Danfoss AK-SM 800A refrigeration controllers including RCE deficiencies. Both vendors patched the vulnerabilities discovered by Claroty.
DEF CON attendee blamed for Delta flight disruption
A passenger on a Delta flight from Las Vegas to Atlanta is suspected of broadcasting the unauthorized Wi-Fi network. Delta said the plane and its systems were never at risk and that no Delta systems were hacked, while confirming that the unauthorized network was briefly active and that the crew disabled in-flight Wi-Fi for about 30 minutes during the incident. Reports indicate that someone who attended the DEF CON conference created the fake Wi-Fi network, but the person’s identity remains unknown at this time.
Uber Freight is investigating a cyber breach
Uber Freight is investigating unauthorized access to some of its systems and storage following claims by hackers. The company said its operations have not been disrupted and that its systems remain secure and fully operational while the investigation continues. The investigation began after a group called Helix claimed to have stolen nearly 1 million Uber Freight files. Helix, whose activities were recently detailed by Google, is also believed to be behind a recent campaign targeting major Wall Street companies.
Rapid7 cuts 12% of workforce
Rapid7 cuts 314 jobs, or 12% of the workforce, as new CEO Wael Mohammed restructures the cybersecurity provider around efficiency and its core platform. The company expects to spend up to $11 million on compensation and benefits while refocusing resources on product modernization and AI-driven capabilities, with the restructuring also intended to help lift its non-GAAP operating margin to 20% in the fourth quarter of 2026.
CISA warns of Gunra ransomware
CISA has issued a new #StopRansomware advisory focused on Gunra ransomware, providing organizations with information designed to help identify and protect against the threat. The recommendation adds Gunra to a growing body of ransomware intelligence provided to defenders by the agency.
Industrial ransomware attacks rise 12%
Dragos identified 1,140 ransomware incidents affecting industrial organizations worldwide in the second quarter of 2026, a 12% increase from the previous quarter, with manufacturing accounting for 747 incidents. Although the ransomware continues to disrupt operations through IT, ERP and virtualization systems, Dragos has not found instances where attackers directly manipulate industrial control systems.
Connected: In other news: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Wall Street Hackers
Connected: Other news: OpenAI open source tool, AWS links hacks to North Korea, Mythos Crypto Research