Dolphin X AI stealer, 2.2M cars open, 432 Linux CVEs

Dolphin X uses AI to profile victims and steal passwords, wallets, keys and tokens. A hardcoded Bluetooth key left 2.2M dealer-installed car devices open. Linux saw 432 kernel CVEs in 24 hours.

Varonis Threat Labs identified a new information-stealing program called Dolphin X that uses an AI behavioral profiler to score and rank infected users by activity and installed software. The malware targets more than 300 applications and is designed to exfiltrate browser passwords, cryptocurrency wallets, SSH keys and cloud tokens. Varonis warned that an infection on a developer’s machine could expose build systems and cloud environments and allow attackers to reach production infrastructure.

Researchers at the University of California San Diego found a hardcoded Bluetooth key in dealer-installed Acrisure anti-theft devices, including KARR and SWDS models. The flaw affected at least 2.2 million vehicles and could be exploited from roughly five yards to unlock doors on affected units. Acrisure issued firmware updates for the devices. KARR described the vulnerability as “highly complex” and argued it presented low risk to customers under real-world conditions.

Security teams recorded an unusually large disclosure of 432 CVEs tied to the Linux kernel within a 24-hour period. The mass release requires administrators to triage kernel versions, assess exploitability and schedule patches and reboots where necessary.

Medical device maker Abbott disclosed unauthorized access to a limited number of systems in its Cancer Diagnostics business and said operations, manufacturing and patient care were not disrupted. The hacking group ShinyHunters claimed responsibility for the intrusion.

A cyberattack on a regional telecommunications provider in Maine caused internet outages across 23 towns, affecting municipal networks and some local government services that rely on the provider’s infrastructure.

Palo Alto Networks’ Unit 42 published findings on three zero-day vulnerabilities in Siemens ROX II operational switches that can be chained to achieve persistent root-level access. The chain starts with an arbitrary file disclosure (CVE-2025-40948) that reveals system information, continues with a command injection for privilege escalation (CVE-2025-40947) and ends with abuse of a web management task scheduler to retain code execution across reboots (CVE-2025-40949). Siemens has released patches and guidance for affected customers.

A joint advisory from CISA and international partners reported that the Russian-linked group known as Laundry Bear is exploiting a patched Zimbra Collaboration Suite flaw (CVE-2025-66376). The exploit uses a view-based technique that can exfiltrate a user’s inbox when a malicious email is opened. The campaign has targeted Western government and commercial organizations.

Ransomware actor Everest demanded 10 million Swiss francs from train builder Stadler Rail after stealing technical data from a shared supplier platform; Stadler refused the demand and said production and core IT systems were not impacted and no critical security or personal data were compromised. German authorities announced the dismantling of the Kratos phishing group, disrupting an organized operation focused on credential theft and large-scale phishing.

Vendors and researchers released mitigations and tools in response. Google previewed CodeMender, a service to integrate vulnerability detection and remediation into developer workflows. Acrisure issued firmware updates for KARR and SWDS devices, and Siemens provided patches and guidance for ROX II switch customers.

Articles by this author