Cybersecurity Roundup: AI Defense Calls, Data Breaches, and Global Threats
This week’s cybersecurity landscape saw significant developments, from industry-wide calls for AI defense collaboration to high-profile breaches and geopolitical cyber threats.
OpenAI Leads Push for Collective Cyber Defense
OpenAI, alongside 116 signatories including tech giants like Microsoft, Google, AWS, and cybersecurity firms such as Palo Alto Networks and Cloudflare published an open letter urging governments and organizations to adopt a collective cyber defense strategy for AI systems. The letter outlines three core principles:
- Acknowledging that current security measures are insufficient against evolving threats.
- Empowering defenders with AI-driven tools to counter attacks.
- Mobilizing a coordinated response across governments, critical infrastructure, and private sector partners.
The initiative emphasizes accelerating security investments, fixing high-risk vulnerabilities, and leveraging AI to bolster defenses particularly for resource-constrained organizations.
OpenAI Bans Russian-Linked Disinformation Campaign
OpenAI terminated multiple ChatGPT accounts linked to a Russian-operated influence campaign orchestrated by the International Burke Institute, a self-described "expert community" based in Israel. The group used VPNs to bypass regional restrictions and generated AI-written social media posts in English, targeting platforms like X, Facebook, and Telegram with anti-Ukraine, anti-EU, and anti-German narratives.
The campaign relied on machine-translated content from Slavic languages, fake academic articles, and stolen identities to lend credibility. While OpenAI noted the operation had limited reach, it highlighted how AI can be exploited to manufacture authority and scale disinformation over time.
Critical Gitea Flaw Exploited in the Wild
Attackers are actively exploiting CVE-2026-60004, a 9.8-severity vulnerability in the open-source Git hosting platform Gitea, to execute arbitrary commands on vulnerable servers. The flaw allows attackers with repository write access to plant malicious Git hooks, enabling shell command execution under the Gitea service account.
Affected versions (1.17.0–1.27.0) were patched in Gitea 1.27.1 (July 27), but CISA added the bug to its Known Exploited Vulnerabilities catalog after observing in-the-wild attacks. One incident involved a cryptocurrency miner deployed via the exploit, which terminated competing processes and self-deleted post-execution. The risk is amplified by Gitea’s default open-registration setting, which attackers can abuse to gain write access.
8.7 Million UK Airport Passengers’ Data Stolen
Hackers breached systems belonging to Manchester Airports Group (MAG), stealing records of 8.7 million passengers who used services at Manchester, London Stansted, and East Midlands airports. The compromised data includes email addresses, phone numbers, vehicle registrations, and postcodes but no payment or operational systems were affected.
MAG confirmed the breach involved car park, lounge, Fast Track, and Wi-Fi booking systems, urging passengers to watch for phishing attempts. The incident underscores the persistent targeting of travel-related data, with the three airports serving 54 million passengers annually.
North Korean Remote Workers Infiltrate Global Firms
Cybersecurity firm Huntress uncovered five suspected North Korean operatives working remotely for organizations in IT, healthcare, finance, and marketing in 2026. The workers used stolen identities, fraudulent documents, and VPN/proxy tools (e.g., Astrill VPN, IPRoyal) to conceal their locations, with activity peaking around 9 AM Pyongyang time.
In one case, three healthcare workers in Australia were found using fake Chinese IDs with near-identical metadata. Another investigation revealed a PiKVM device allowing pre-boot remote access connected to a corporate laptop, alongside a Guermok USB capture tool and altered GitHub profile photos. The findings align with North Korea’s long-standing tactic of infiltrating foreign companies to fund state operations.
Barcelona Police Data Leak Exposes Officers’ Routines
A data leak exposed the names, ID numbers, work locations, and shift schedules of 568 Barcelona Urban Guard officers, raising concerns amid Catalonia’s Level 4 antiterrorism alert. The information, accessible via simple online searches, could enable attackers to track officers’ movements or target them and their families.
While Barcelona officials claimed the data stemmed from transparency initiatives rather than a breach, pro-independence politician Jordi Martí i Galbis called it a "security failure of the first order." Efforts are underway to remove the exposed details from public platforms.
Norway Hit by Prolonged DDoS Attack
A 30-hour distributed denial-of-service (DDoS) attack disrupted 10 Norwegian government services, including ID-porten, the country’s digital identity gateway used by 4.5 million citizens for access to healthcare, prescriptions, and public records. The attack, targeting IT provider Vivicta, was 2–3 times larger than previous incidents in June.
While no data was compromised, the outage affected employee access, government data exchanges, and online pharmacies. Authorities have not attributed the attack, which follows a pattern of increasing DDoS activity against Nordic infrastructure.
Taiwan Charges Nine in AI Server Smuggling Scheme
Taiwanese prosecutors charged nine individuals, including an Nvidia employee and two former Super Micro staff, with illegally exporting 74 high-end AI servers (Nvidia B300s) to China in violation of U.S. and Taiwanese export controls. The servers were routed through Indonesia, China, and Japan-Hong Kong, while a second shipment of 56 servers was intercepted.
The case highlights the escalating tech war between Washington and Beijing, with the U.S. restricting AI chip exports since 2022. Prosecutors allege the suspects falsified documents, set up a Japanese shell company, and evaded inspections a scheme that could result in five-year prison sentences for four defendants. Nvidia and Super Micro pledged cooperation with authorities.
Nigeria Advances Sovereign Cloud Initiative
Nigeria launched a National Sovereign Cloud Initiative, aiming to reduce reliance on foreign cloud providers and bolster data security, AI, and digital sovereignty. The government established a Joint Technical Committee to develop domestic cloud infrastructure, enforce data-security certifications, and attract $750 million in investment over two years.
Led by NITDA Director General Kashifu Inuwa, the initiative promotes a cloud-first policy to support government services, finance, and the digital economy. The move aligns with a global trend of nations including the EU, India, and Saudi Arabia seeking greater control over data and critical infrastructure.
Source: https://www.bankinfosecurity.com/breach-roundup-call-for-cyber-defense-collective-action-a-32673
SuperCom (NASDAQ: SPCB) cybersecurity rating report: https://www.rankiteo.com/company/supercom
NVIDIA cybersecurity rating report: https://www.rankiteo.com/company/nvidia
"id": "SUPNVI1787870586",
"linkid": "supercom, nvidia",
"type": "Cyber Attack",
"date": "2/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '8.7 million passengers',
'industry': 'Transportation/Aviation',
'location': 'United Kingdom',
'name': 'Manchester Airports Group (MAG)',
'size': 'Large (54 million passengers annually)',
'type': 'Airport Operator'},
{'industry': 'Government/Public Safety',
'location': 'Spain',
'name': 'Barcelona Urban Guard',
'size': '568 officers exposed',
'type': 'Law Enforcement'},
{'customers_affected': '4.5 million citizens',
'industry': 'Public Services',
'location': 'Norway',
'name': 'Norwegian Government (ID-porten)',
'size': '4.5 million citizens affected',
'type': 'Government'},
{'industry': 'Technology/Software',
'location': 'Global',
'name': 'Gitea',
'type': 'Open-Source Git Hosting Platform'},
{'industry': ['IT',
'Healthcare',
'Finance',
'Marketing'],
'location': 'Global (suspected North Korean '
'infiltration)',
'name': 'Global Firms (IT, Healthcare, Finance, '
'Marketing)',
'type': 'Corporations'},
{'industry': 'Semiconductors/AI',
'location': 'United States',
'name': 'Nvidia',
'size': 'Large',
'type': 'Technology Company'},
{'industry': 'Hardware/Server Manufacturing',
'location': 'United States',
'name': 'Super Micro',
'size': 'Large',
'type': 'Technology Company'}],
'attack_vector': ['Git Hook Exploitation',
'Stolen Identities',
'VPN/Proxy Tools',
'Phishing',
'DDoS',
'Fraudulent Documents'],
'customer_advisories': ['MAG passengers (phishing risks)',
'Norwegian citizens (service disruptions)'],
'data_breach': {'number_of_records_exposed': ['8.7 million (MAG)',
'568 (Barcelona Urban Guard)'],
'personally_identifiable_information': ['Yes (email, phone, '
'vehicle reg, '
'postcodes, names, '
'IDs, shifts)'],
'sensitivity_of_data': ['High (personal identifiers, work '
'routines)'],
'type_of_data_compromised': ['Passenger records (email, '
'phone, vehicle reg, postcodes)',
"Officers' personal/work details "
'(names, IDs, shifts)',
'Corporate identities (fake IDs, '
'GitHub profiles)']},
'description': 'This week’s cybersecurity landscape saw significant '
'developments, including industry-wide calls for AI defense '
'collaboration, high-profile breaches, geopolitical cyber '
'threats, and exploitation of critical vulnerabilities.',
'impact': {'brand_reputation_impact': ['Manchester Airports Group (MAG)',
'Barcelona Urban Guard',
'Norwegian government'],
'data_compromised': ["8.7 million passengers' data (email "
'addresses, phone numbers, vehicle '
'registrations, postcodes)',
"568 Barcelona Urban Guard officers' personal "
'and work details',
'AI server smuggling details'],
'downtime': '30 hours (Norwegian government services)',
'identity_theft_risk': ['8.7 million MAG passengers',
'Barcelona officers'],
'legal_liabilities': ['Taiwanese AI server smuggling case '
'(potential 5-year prison sentences)',
'Regulatory violations for data exposure'],
'operational_impact': ['Disrupted government services in Norway',
'Potential tracking of Barcelona officers',
'Cryptocurrency miner deployment via Gitea '
'exploit'],
'systems_affected': ['Gitea servers',
'Manchester Airports Group (MAG) booking '
'systems',
'Norwegian government services (ID-porten)',
'Corporate systems infiltrated by North '
'Korean operatives']},
'initial_access_broker': {'backdoors_established': ['PiKVM device (North '
'Korean operatives)'],
'entry_point': ['Stolen identities (North Korean '
'operatives)',
'Git hooks (Gitea exploit)'],
'high_value_targets': ['Healthcare, finance, IT '
'firms (North Korean '
'operatives)']},
'investigation_status': ['Ongoing (North Korean infiltration)',
'Resolved (Gitea patch)',
'Ongoing (Barcelona data removal)'],
'lessons_learned': ['Need for collective AI defense strategies',
'Risks of open-registration in Git platforms',
'Vulnerability of travel-related data',
'North Korean tactics for remote work infiltration',
'Importance of data transparency vs. security trade-offs'],
'motivation': ['Disinformation',
'Financial Gain',
'Espionage',
'Geopolitical Influence',
'Data Theft'],
'post_incident_analysis': {'corrective_actions': ['Patch management for '
'critical vulnerabilities',
'Stricter remote work '
'identity verification',
'Sovereign cloud '
'initiatives (Nigeria)',
'Collective AI defense '
'strategies'],
'root_causes': ['Insufficient AI security measures '
'(OpenAI letter)',
'Unpatched Gitea vulnerability '
'(CVE-2026-60004)',
'Open-registration in Git '
'platforms',
'Stolen identities for remote work '
'infiltration',
'Data transparency without '
'security safeguards (Barcelona)']},
'recommendations': ['Accelerate AI-driven security investments',
'Patch critical vulnerabilities (e.g., Gitea '
'CVE-2026-60004) immediately',
'Enhance monitoring for stolen identity use in remote '
'work',
'Implement stricter export controls for AI hardware',
'Adopt sovereign cloud initiatives for data security'],
'references': [{'source': 'OpenAI Open Letter'},
{'source': 'CISA Known Exploited Vulnerabilities Catalog'},
{'source': 'Huntress Report on North Korean Operatives'},
{'source': "Taiwanese Prosecutors' Charges"}],
'regulatory_compliance': {'legal_actions': ['Taiwanese charges against 9 '
'individuals (AI server '
'smuggling)'],
'regulations_violated': ['U.S. and Taiwanese export '
'controls (AI server '
'smuggling)',
'EU GDPR (Barcelona data '
'leak)']},
'response': {'communication_strategy': ['MAG passenger advisories',
'Norwegian government updates on DDoS '
'attack'],
'containment_measures': ['OpenAI terminated '
'disinformation-linked ChatGPT accounts',
'Gitea patched CVE-2026-60004'],
'law_enforcement_notified': ['Taiwanese prosecutors (AI server '
'smuggling case)'],
'remediation_measures': ['MAG urged passengers to watch for '
'phishing',
'Barcelona officials removing exposed '
'data']},
'stakeholder_advisories': ['OpenAI collective defense initiative',
'MAG passenger phishing warnings',
'Norwegian government DDoS updates'],
'threat_actor': ['Russian-linked Disinformation Campaign (International Burke '
'Institute)',
'North Korean Operatives',
'Unknown (DDoS Attackers)',
'Unknown (Barcelona Police Data Leak)'],
'title': 'Cybersecurity Roundup: AI Defense Calls, Data Breaches, and Global '
'Threats',
'type': ['Data Breach',
'Disinformation Campaign',
'Vulnerability Exploitation',
'DDoS Attack',
'Insider Threat',
'Supply Chain Attack'],
'vulnerability_exploited': ['CVE-2026-60004 (Gitea)']}