Weekly Cybersecurity Roundup: AI-Driven Bounty Noise, Port Disruption and Financial-Sector Vishing

A series of smaller cybersecurity developments this week highlighted risks spanning artificial intelligence abuse, software supply chains, cloud data exposure and targeted social engineering.AI misuse...

A series of smaller cybersecurity developments this week highlighted risks spanning artificial intelligence abuse, software supply chains, cloud data exposure and targeted social engineering.

AI misuse and defensive challenges

OpenAI said it disrupted a Cambodia-based network that used ChatGPT to support investment, romance, gambling and impersonation scams. The operation reportedly generated fake identities, translated outreach, produced promotional materials and created forged documents.

Separately, Apple has introduced limits on the number of vulnerability reports some researchers can submit to its bug bounty program. The move follows a rise in low-quality reports generated with AI tools, which security teams say can make legitimate findings harder to identify. Researchers may request increased submission allowances, while Apple is also using AI to assist with triage.

Attacks and exposed infrastructure

Amgen confirmed that attackers accessed data held in third-party cloud environments during July. The company said proprietary information and protected health information were taken, although its products, manufacturing operations, financial systems and patient care were not affected. An investigation is continuing.

A supply-chain compromise involving the QuickFox VPN and game-acceleration application distributed a modified Electron installer that ultimately deployed the FDMTP implant on Windows devices. Fortinet reported the activity, after which QuickFox removed the malicious components. Researchers also warned that several Zbtlink and rebranded cellular routers contain a backdoor capable of contacting an external command-and-control server and accepting unauthenticated root commands.

North Carolina Ports reported that a cyberattack caused a systems outage affecting the Port of Wilmington, Port of Morehead City and Charlotte Inland Port. Operations resumed with delays after contingency measures were activated, but officials have not said whether data was stolen.

Phishing reaches corporate targets

IEH Corporation disclosed a Microsoft 365 mailbox compromise that began with a phishing message and a counterfeit login page. The intruder could access messages, attachments, purchase orders and engineering documents; the company said it has found no evidence of data exfiltration.

Voice-phishing campaigns using synthetic or mimicked voices also targeted major hedge funds and private-equity firms. Two Sigma said it stopped an attempted intrusion, while Point72 was reviewing an incident and reported no initial evidence of client data theft. Other firms did not provide details.