Google Security Layoffs, Audi A6 Recall, Coupang Fined $400 Million

0
29

Key Takeaways

  • Former IBM exec sues IBM and AT&T for allegedly concealing foreign‑government hacks to win federal contracts.
  • University of Oxford’s CareerConnect service suffered a breach exposing names, emails and encrypted passwords of alumni, staff and employers.
  • Google Cloud is cutting staff from Mandiant and the Google Threat Intelligence Group, though exact numbers are unconfirmed.
  • Microsoft released an AI‑focused incident‑response playbook for Microsoft 365 Copilot and Azure AI Services.
  • CISA added a critical LiteLLM command‑injection flaw (CVE‑2026‑42271) to its Known Exploited Vulnerabilities catalog.
  • South Korean regulators fined Coupang a record $400 million for massive data‑handling failures affecting 30 million customers.
  • Nokia launched Deepfield Genome Shield, an automated edge‑defense platform targeting residential‑proxy‑botnet DDoS attacks.
  • Bitsight’s 2026 ICS/OT report shows flat internet‑facing device exposure but a widening attack surface due to new protocols.
  • ENISA’s Cyber Europe 2026 exercise will stress collective EU resilience against large‑scale cyber incidents.
  • An international law‑enforcement takedown dismantled the AudiA6 crypto‑laundering network, seizing $388 million and shutting down the Dark2Web forum.

IBM and AT&T Accused of Hack Cover‑Ups
A former IBM cybersecurity executive has filed a lawsuit alleging that IBM and AT&T deliberately concealed repeated foreign‑government‑linked intrusions on their systems. According to the whistleblower, the companies failed to disclose multiple breaches to the U.S. government over several years and instead provided false assurances about their security posture to retain lucrative federal contracts. The suit claims these actions violate federal contracting laws that require timely and accurate reporting of cyber incidents. If proven, the allegations could trigger significant financial penalties and reputational damage for both technology giants.

University of Oxford Impacted by CareerConnect Data Breach
The University of Oxford disclosed that its CareerConnect careers platform was compromised, allowing hackers to access names, email addresses, and encrypted passwords. The breach affected alumni, research staff, and employer accounts but did not reach students, who log in via the university’s Single Sign‑On (SSO) system. Oxford has notified affected users, reset passwords, and is working with forensic investigators to determine the scope of the intrusion. The incident underscores the continued risk posed by third‑party career‑services platforms that aggregate sensitive personal data.

Google Threat Intelligence Group and Mandiant Layoffs
Google Cloud has reportedly begun a round of layoffs targeting members of its Mandiant team and the Google Threat Intelligence Group (GTIG). While Google has not released an exact headcount, sources indicate the cuts are part of a broader effort to streamline its cybersecurity offerings amid shifting market demands. The company declined to comment on the specifics when approached by SecurityWeek. The move raises concerns about the potential impact on threat‑intelligence capabilities that many enterprises rely on for proactive defense.

Microsoft Issues Incident Response Playbook for AI
Microsoft has published a practitioner’s playbook aimed at helping security teams investigate incidents involving Microsoft 365 Copilot and Azure AI Services. The document outlines structured methodologies for collecting telemetry, analyzing anomalous behavior, and coordinating response efforts within AI‑centric environments. By adapting traditional incident‑response workflows to the unique data streams generated by large‑language models and AI services, Microsoft seeks to shorten detection‑to‑remediation timelines and improve overall resilience against AI‑targeted threats.

CISA Mandates Patching for Actively Exploited LiteLLM Flaw
The Cybersecurity and Infrastructure Security Agency (CISA) added CVE‑2026‑42271—a critical command‑injection vulnerability in the BerriAI LiteLLM AI gateway—to its Known Exploited Vulnerabilities (KEV) catalog after observing active exploitation in the wild. Although details of the attacks remain scarce, CISA’s inclusion signals that federal agencies must prioritize patching or mitigating the flaw to prevent potential compromise. Organizations using LiteLLM are urged to apply vendor‑provided updates or implement temporary workarounds immediately.

Regulators Issue $400 Million Penalty Over Coupang Data Leak
South Korea’s Personal Information Protection Commission (PIPC) levied a record‑setting $400 million fine against e‑commerce giant Coupang for widespread security failures that exposed the personal data of more than 30 million customers. Investigators found deficient access controls, poor authentication‑key management, and inadequate monitoring practices. Coupang has announced its intention to appeal the penalty, arguing that the fine is disproportionate to the remedial actions already undertaken. The case highlights the growing financial stakes of data‑protection non‑compliance in Asia’s fast‑growing digital markets.

Nokia Debuts Automated Edge Defense for Proxy Botnets
Nokia introduced Deepfield Genome Shield, an automated security platform designed to thwart massive DDoS attacks launched from residential proxy botnets. Operating at the network edge, the solution identifies and disrupts command‑and‑control traffic emanating from an estimated 200 million compromised devices, thereby neutralizing attack traffic before it reaches customer infrastructure. By leveraging real‑time telemetry and machine‑learning‑based anomaly detection, Nokia aims to provide carriers and enterprises with a scalable defense against increasingly botnet‑driven volumetric threats.

ICS Device Exposure Remains Flat as Attack Surface Widens
Bitsight’s 2026 Global State of ICS/OT Exposure report shows that the number of internet‑facing industrial control systems has plateaued at roughly 170,000 monthly exposures. Despite this stability in raw counts, the overall risk landscape is expanding because modern ICS environments now support non‑traditional protocols such as SSH, HTTP, and MQTT alongside legacy fieldbus standards. This protocol diversification enlarges the attack surface, complicating monitoring efforts and requiring defenders to adopt more comprehensive, protocol‑agnostic security strategies.

ENISA Shifts Focus to Collective EU Resilience
The European Union Agency for Cybersecurity (ENISA) announced that its Cyber Europe 2026 exercise will emphasize enhancing collective response capabilities across member states. The initiative seeks to evaluate and strengthen cooperative resilience against large‑scale, transnational cyber incidents that could disrupt critical infrastructure throughout the bloc. By fostering joint exercises, information sharing, and coordinated incident‑handling procedures, ENISA aims to ensure that European infrastructure can withstand and rapidly recover from sophisticated, multi‑nation cyber threats.

Global Operation Takes Down Crypto Laundering Service
An international law‑enforcement coalition led by Europol and Eurojust dismantled AudiA6, a prominent cryptocurrency‑laundering network that processed over $388 million for ransomware actors between 2022 and 2025. The operation exposed an industrial‑scale scheme that funneled illicit digital assets through thousands of fake exchange accounts created with stolen identities. Authorities also seized the platform’s web infrastructure and shut down Dark2Web, an underground cybercrime forum used by the same operators to connect threat actors globally. The takedown illustrates the growing effectiveness of cross‑border cooperation in combating crypto‑enabled crime.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here