Illustrative image generated with AI
Threats of the Week: AI-Powered Infostealer, Zero-Day on Industrial Switches, and Flood of CVEs in the Linux Kernel
Explore this week's top cyber threats: AI infostealer, Siemens ROX II zero-days, 432 Linux kernel CVEs, and Zimbra APT exploits.
Text generated by artificial intelligence, published without human review. AI transparency
Introduction
The past week has put security teams under immense pressure with a wave of threats ranging from AI-enhanced infostealers to exploit chains targeting critical infrastructure, along with a record release of Linux kernel vulnerabilities. Among the most notable events are the discovery of Dolphin X by Varonis, a triple zero-day vulnerability in Siemens ROX II switches identified by Palo Alto Networks, the active exploitation of a flaw in Zimbra by the Russian APT group Laundry Bear, and the publication of a staggering 432 kernel CVEs in a single day. Rounding out the picture are warnings about Acrisure car anti-theft devices and other breach and law enforcement operations. Below is an in-depth analysis.
Technical Analysis
Dolphin X: The Infostealer That Chooses Its Victims With AI
Researchers at Varonis Threat Labs have isolated a new malware, dubbed Dolphin X, which introduces a dangerous innovation: a behavioral profiling module based on artificial intelligence. The code primarily infects Windows systems and analyzes over 300 installed applications (from productivity suites to IDEs and cryptocurrency wallets). Based on the activity and the presence of sensitive tools, it assigns a “value score” to the machine, deciding whether and which credentials to exfiltrate: browser passwords, SSH keys, cloud tokens, wallet seed phrases. Particularly insidious is its ability to target development workstations: a single infection in a CI/CD environment can open the door to the entire production ecosystem.
Siemens ROX II: Three Zero-Days for Persistent Root Control
Palo Alto Networks Unit 42 has documented a chain of three zero-day vulnerabilities in Siemens ROX II industrial switches, widely used in OT environments. The flaws – CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949 – allow an attacker, once they have network access, to read arbitrary files, inject commands with elevated privileges, and ultimately abuse the web management scheduler to maintain persistence even after a reboot. The exploit guarantees persistent root access, providing total control over the device and the process traffic that flows through it.
Deluge of CVEs in the Linux Kernel
In an unprecedented day, 432 vulnerabilities affecting the Linux kernel were published. The record number puts pressure on security teams, who are forced into emergency triage to identify the flaws that affect their distributions and infrastructures. The types range from local privilege escalation to denial of service and arbitrary code execution, with risk proportional to the exposure of the systems.
Laundry Bear and Espionage via Zimbra (CVE-2025-66376)
A joint advisory from CISA and international partners warns of the active exploitation of CVE-2025-66376 in Zimbra Collaboration Suite by the Russian APT group Laundry Bear. The vulnerability is “view-based”: simply viewing a malicious email (without any click) is enough to trigger the exfiltration of the victim’s entire mailbox. The silent, targeted campaign focuses on Western government and commercial entities for espionage purposes.
Cars at Risk: Hardcoded Bluetooth Key in Acrisure Devices
A team from UC San Diego discovered a fixed, immutable Bluetooth pairing key in the aftermarket KARR and SWDS devices manufactured by Acrisure, installed in over 2.2 million vehicles (primarily in California). An attacker within a 4–5 meter range can exploit it to unlock the doors. Although the company has released a patch, the risk of car theft or theft of items inside the vehicle remains tangible for those who have not yet updated the system.
Other Events
Brief notes: the ShinyHunters group claimed unauthorized access to Abbott’s Cancer Diagnostics systems (with no operational impact); Stadler Rail refused a multi-million ransom demand after a breach at a supplier platform; the German Kratos phishing gang was dismantled; Google launched the preview of CodeMender for vulnerability detection in code; an attack on a provider caused internet outages in several towns in Maine.
Impact
The overall picture paints a high-risk scenario:
- Dolphin X threatens the targeted theft of digital secrets and credentials, with possible pivots to production environments and supply chain attacks.
- The Siemens ROX II exploit jeopardizes industrial networks: process disruption, manipulation of operational data, industrial espionage.
- The 432 Linux kernel CVEs expand the attack surface for servers, IoT, and workstations, making patch management critical.
- The Zimbra attack exposes entire email archives of government and corporate organizations, fostering prolonged espionage.
- The car vulnerability facilitates physical theft and erodes trust in aftermarket security devices.
Mitigation
The following are the main defensive actions recommended:
- Siemens ROX II: immediately apply the patches released by Siemens; segment OT/IT networks and restrict access to management interfaces.
- Linux kernel: perform rapid triage with inventory tools, prioritizing exposed systems; monitor distribution bulletins and automate patching.
- Zimbra: promptly install the patch for CVE-2025-66376; disable automatic HTML preview in webmail; check IMAP/POP3 logs for past exfiltrations.
- Dolphin X: strengthen endpoint defense with behavioral analysis; limit privileges on development machines and segment CI/CD environments.
- Acrisure: request and apply the software update for KARR/SWDS devices from installation centers.
- General: maintain continuous visibility over your assets, raise user awareness (where necessary), and test the resilience of response plans.
FAQ
1. What is the most urgent threat for businesses this week?
It depends on the organization’s profile. For those operating in the industrial sector, the absolute priority is patching Siemens ROX II switches (critical zero-days). For most IT companies, the two emergencies are the immediate update of Zimbra (if in use) and the accelerated triage of Linux kernel vulnerabilities, which could affect exposed servers and devices.
2. What makes Dolphin X different from common infostealers?
Dolphin X uses an AI-based profiler to assess the “profitability” of a victim. Instead of collecting data indiscriminately, it analyzes installed software and user activity to focus on high-value targets (developers, administrators, wallet holders), increasing the effectiveness of the theft and reducing background noise.
3. How can I manage 432 new kernel vulnerabilities in a single day?
The winning approach is triage based on real exposure, not just CVE severity. Use asset management tools to identify which systems are actually affected, then prioritize critical systems and those reachable from outside. Automate patching as soon as updated distribution packages (Red Hat, Ubuntu, Debian, SUSE) become available, and monitor official channels for any out-of-band fixes.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2025-40949Critical9.1A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCOM ROX RX1501 (All versions < V2.17.1), RUGGEDCOM ROX RX1510 (Al
- CVE-2025-40947High7.5A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCOM ROX RX1501 (All versions < V2.17.1), RUGGEDCOM ROX RX1510 (Al
- CVE-2025-66376High7.2Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
- CVE-2025-40948Medium6.8A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCOM ROX RX1501 (All versions < V2.17.1), RUGGEDCOM ROX RX1510 (Al
