**Weekly Cybersecurity Recap: OpenAI Scams, Amgen Data Theft, and More**
In the ever-evolving landscape of cybersecurity, staying informed is crucial. SecurityWeek’s weekly roundup provides a concise overview of significant developments that may not have warranted standalone articles but remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events from the past week.
### This Week’s Key Highlights
**OpenAI Disrupts Cambodia Scam Network Abusing ChatGPT**
OpenAI has banned a coordinated network of ChatGPT accounts linked to a Cambodia-based operation. The malicious actors used the AI model to create fake personas, translate messages, generate promotional images, and forge documents for investment, romance, gambling, and law enforcement impersonation scams.
**Amgen Confirms Data Theft from Cloud Environments**
In July 2026, Amgen detected unauthorized access to data stored in third-party cloud environments. The company later confirmed that proprietary information and patient protected health information were exfiltrated. Amgen stated there is no impact on products, manufacturing, financial systems, or patient care, and investigations into the full scope of accessed data are ongoing.
**Apple Caps Bug Bounty Reports Amid AI-Generated False Positives**
Apple has limited the number of vulnerability submissions researchers can make to its bug bounty program. This move comes after a surge of low-quality, AI-hallucinated reports buried legitimate findings. Cybersecurity firm Bynario hit the new cap after using ChatGPT to surface over 50 macOS issues. Apple is also using AI to help triage submissions, and researchers can request higher limits.
**Trump Administration Eyes Ban on Chinese Data Center Components**
The FCC is drafting rules to block imports of new Chinese optical transceivers used in data centers. The move aims to reduce risks of data theft, malware, or service disruption in AI infrastructure. US transceiver makers saw share gains on the news, though cloud operators could face higher costs as they shift suppliers.
**QuickFox VPN Supply Chain Attack Drops FDMTP Implant**
A long-running supply chain compromise of the QuickFox VPN and game-accelerator app delivered a trojanized Electron installer that executed a JavaScript loader and installed the FDMTP implant on Windows systems. The loader used process-based guardrails to avoid detection by Steam users and preferred endpoints running development, database, or crypto tools. QuickFox removed the malicious components after Fortinet’s disclosure.
**Zbtlink Routers Ship with Built-In Backdoor**
Multiple models of Zbtlink (and rebranded) cellular routers come pre-loaded with an implant based on the obscure Rctl tool. The backdoor, dubbed EndlessDoors, phones home at boot and accepts unauthenticated root commands. No inbound access is required, and anyone controlling the C2 endpoints can issue shell commands or open interactive root shells. Detection guidance has been published, and affected devices should be treated as untrusted.
**DoubleCup ClickFix Loader Delivers CountLoader and DeviceManager RATs**
A Russian Loader-as-a-Service called DoubleCup has been powering ClickFix campaigns since early June 2026. Using steganography and environmental keying, it delivers payloads including an updated CountLoader (Windows and macOS) that patches legitimate binaries for stealth, and a newly identified DeviceManager RAT that resolves C2 via Ethereum/Polygon smart contracts.
**IEH Corporation Employee Mailbox Breached via Phishing**
IEH Corporation, which provides high-reliability Hyperboloid connectors for defense, aerospace, and space applications, discovered on August 4 that a threat actor had gained unauthorized access to an employee’s Microsoft 365 mailbox. The phishing message impersonated a prospective business contact, leading the user to a fake login page. The actor could view emails, attachments, purchase orders, and engineering files, though there is no evidence of outbound emails or successful data exfiltration.
**Cyberattack Disrupts North Carolina Port Operations**
North Carolina Ports confirmed a cyberattack detected on August 4 that caused a systems-wide outage affecting the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. Gates reopened with expected delays the following day after the IT team activated its contingency plan and contained the breach. It remains unclear whether any sensitive data was taken.
**Vishing Wave Hits Major Hedge Funds**
Hackers conducted a series of voice-phishing attacks against several large hedge funds and private equity firms, using technology that mimics voices to trick employees into granting access or disclosing information. Impacted companies include Two Sigma and Point72, which said they blocked the attempts with no impact to data or systems. Citadel and others declined to comment.
### FAQ
**What should I do if I suspect my organization has been targeted by a supply chain attack?**
Immediately isolate affected systems, review logs for unusual activity, contact your incident response team or security vendor, and report the incident to relevant authorities. Ensure all software is updated and verify the integrity of third-party components.
**How can I protect against vishing attacks?**
Implement strict verification protocols for phone-based requests, use multi-factor authentication, educate employees about voice spoofing risks, and deploy advanced email and endpoint security solutions that detect phishing and social engineering attempts.
**Are AI-generated threats becoming more common?**
Yes. Attackers are increasingly using AI to generate convincing phishing content, automate vulnerability discovery, and create false security reports. Defenders are also adopting AI to improve threat detection and response.
**What are the risks of using unverified bug bounty submissions?**
Unverified submissions can overwhelm security teams with false positives, delay the discovery of legitimate vulnerabilities, and potentially expose sensitive information if malicious actors submit fake exploits.
**Should organizations be concerned about foreign components in their infrastructure?**
Yes. The use of components from certain regions may introduce supply chain risks, including hidden backdoors or malicious code. Organizations should conduct thorough risk assessments and consider diversification strategies.
### Conclusion
This week’s cybersecurity highlights demonstrate the diverse and evolving threats facing organizations today. From AI-powered scams and sophisticated supply chain attacks to insider phishing breaches and critical infrastructure disruptions, the threat landscape continues to expand in complexity. Staying informed, implementing robust security controls, and fostering a culture of vigilance are essential steps in mitigating these risks. As attackers become more innovative, defenders must adapt swiftly to protect their organizations and data.



