In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.
This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment.
Here are this week’s highlights:
Government AI platform deal sparks outrage
The Defense Department’s recent award of an $821 million contract to Accenture Federal Services for its War Data Platform (WDP) is drawing criticism for allegedly undermining goals to rapidly adopt commercial AI. Sources claim the task order prioritizes a traditional consulting model over integrating best-of-breed commercial technologies. The WDP contract is a restructuring of the former Advana program and aims to provide standardized data access for AI-enabled military operations.
North Korean IT worker breaches federal agency
The FBI is investigating how a North Korean IT worker successfully gained employment at an unnamed US federal government agency. North Korea places thousands of remote IT workers in Western organizations using fraudulent identities to earn wages for the regime and steal intellectual property. It’s likely that the individual was working at the federal agency via a contract job rather than being hired directly.
Hacking a Boeing 737
A group of academic researchers demonstrated [paywalled Wired article] how a concealed, coin-sized hardware device can successfully compromise systems on a Boeing 737. Malicious actors who have access to a plane can attach the hacking device to an external port, giving them remote access. While safety systems on an aircraft are likely to prevent direct harm, an attacker could spoof data such as air temperature readings and the aircraft weight, and even change a plane’s flight plan and divert it from its intended route.
LexisNexis probing another potential hack
LexisNexis took its Diligence, Metabase API, and Newsdesk services offline last week after identifying unusual activity on servers managed by a third-party vendor. The company stated it disconnected the systems to contain the threat. LexisNexis clarified that its Metabase API product is not connected to Metabase Cloud, which recently disclosed a zero-day vulnerability. This would be the third data breach suffered by LexisNexis in recent years.
Hacking commercial refrigeration systems
Claroty’s Team82 found vulnerabilities in two widely used commercial refrigeration systems. The researchers discovered 23 vulnerabilities in Copeland XWEB Pro controllers, including ones that can be chained to bypass security controls and achieve root-level RCE. A demonstration showed that a compromised controller could remotely manipulate refrigeration equipment, including cooling fans and compressors, and conceal the resulting temperature increase while food spoils. Team82 also identified multiple vulnerabilities in Danfoss AK-SM 800A refrigeration controllers, including RCE flaws. Both vendors patched the vulnerabilities discovered by Claroty.
DEF CON attendee blamed for Delta flight disruption
A passenger on a Delta flight from Las Vegas to Atlanta is suspected of broadcasting an unauthorized Wi-Fi network. Delta said the aircraft and its systems were never at risk and that no Delta system was hacked, while confirming that the unauthorized network was active briefly and that the crew disabled in-flight Wi-Fi for about 30 minutes during the incident. Reports suggest that someone who had attended the DEF CON conference set up the fake Wi-Fi network, but the identity of the individual currently remains unknown.
Uber Freight probes cyber intrusion
Uber Freight is investigating unauthorized access to part of its systems and repositories following claims by hackers. The company said its operations have not been disrupted and that its systems remain secure and fully operational while the investigation continues. The probe was launched after a group named Helix claimed to have stolen nearly 1 million Uber Freight files. Helix, whose activities were detailed recently by Google, is also believed to be behind a recent campaign targeting major Wall Street companies.
Rapid7 lays off 12% of workforce
Rapid7 is cutting 314 jobs, or 12% of its workforce, as new CEO Wael Mohamed restructures the cybersecurity vendor around efficiency and its core platform. The company expects to spend up to $11 million on severance and benefits while redirecting resources toward product modernization and AI-driven capabilities, with the restructuring also intended to help lift its non-GAAP operating margin to 20% in Q4 2026.
CISA warns of Gunra ransomware
CISA has issued a new #StopRansomware advisory focused on Gunra ransomware, providing organizations with information intended to help identify and defend against the threat. The advisory adds Gunra to the growing body of ransomware intelligence being made available to defenders by the agency.
Industrial ransomware attacks climb 12%
Dragos identified 1,140 ransomware incidents affecting industrial organizations worldwide in Q2 2026, a 12% increase from the previous quarter, with manufacturing accounting for 747 incidents. While ransomware continued to disrupt operations through IT, ERP and virtualization systems, Dragos found no cases in which attackers directly manipulated industrial control systems.
Related: In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.