Weekly Cybersecurity Roundup: Aviation, Refrigeration, Ransomware and Industry Developments
This week’s security developments include concerns over a major defense technology contract, suspected North Korean insider activity, vulnerabilities in aircraft and refrigeration equipment, and a ris...
This week’s security developments include concerns over a major defense technology contract, suspected North Korean insider activity, vulnerabilities in aircraft and refrigeration equipment, and a rise in ransomware incidents affecting industrial organizations.
Government and transportation concerns
The Defense Department’s $821 million award to Accenture Federal Services for the War Data Platform has drawn criticism from sources who argue that the deal favors a conventional consulting approach over faster adoption of commercial artificial-intelligence technologies. The platform is intended to replace or restructure the Advana program and provide standardized data for military AI applications.
The FBI is also investigating how an alleged North Korean information-technology worker obtained a position at an unidentified U.S. federal agency. North Korea is known to use fraudulent identities and remote workers to generate revenue and obtain sensitive information, often through contractor roles.
Researchers reportedly demonstrated that a small hardware device attached to an external port on a Boeing 737 could provide remote access to certain aircraft systems. Safety controls would likely limit the ability to cause direct harm, but potential effects could include falsifying sensor readings or altering flight-plan information.
Separately, Delta temporarily disabled onboard Wi-Fi after an unauthorized wireless network appeared during a flight from Las Vegas to Atlanta. The airline said neither the aircraft nor its systems were compromised. The person responsible has not been identified.
Industrial and enterprise security
LexisNexis took several services offline after detecting suspicious activity on infrastructure operated by a third-party provider. The company said the action was precautionary and clarified that its Metabase API is separate from Metabase Cloud, which recently disclosed a zero-day issue.
Claroty researchers reported 23 vulnerabilities in Copeland XWEB Pro refrigeration controllers, including flaws that could enable security bypasses and root-level remote code execution. Similar remote-code-execution vulnerabilities were found in Danfoss AK-SM 800A controllers. Successful exploitation could allow attackers to manipulate cooling equipment and disguise temperature changes. Both vendors have released fixes.
Uber Freight is investigating claims that attackers accessed portions of its systems and repositories. The group Helix alleges it obtained nearly one million files, while the company says operations remain available and unaffected.
Threat activity and business news
Rapid7 plans to eliminate 314 positions, representing about 12% of its workforce, as it prioritizes efficiency, platform modernization and AI-related capabilities. CISA issued a new advisory on Gunra ransomware, and Dragos recorded 1,140 ransomware incidents involving industrial organizations during the second quarter of 2026—a 12% quarterly increase. Manufacturing accounted for 747 cases, although Dragos reported no incidents involving direct manipulation of industrial control systems.
