Breaking
SecurityDeveloping Story

Security Roundup: Pentagon AI Deal Draws Fire

A weekly summary of key cybersecurity events, from a Boeing 737 hack demo to refrigeration flaws and Rapid7 layoffs.

··3 hours ago·4 min read
black and red laptop computer
Photo by FlyD on Unsplash

This week's security landscape is marked by a controversial Pentagon AI contract, a hardware-based attack on a Boeing 737, and a surge in industrial ransomware, among other incidents. From the FBI probing a North Korean IT worker inside a federal agency to LexisNexis shutting down services after suspicious activity, the threats are diverse and evolving.

Pentagon AI Contract Under Fire

The Defense Department’s award of an $821 million contract to Accenture Federal Services for its War Data Platform (WDP) is drawing criticism for allegedly undermining goals to rapidly adopt commercial AI. Sources claim the task order prioritizes a traditional consulting model over integrating best-of-breed commercial technologies. The WDP contract is a restructuring of the former Advana program and aims to provide standardized data access for AI-enabled military operations.

North Korean IT Worker in US Agency

The FBI is investigating how a North Korean IT worker successfully gained employment at an unnamed US federal government agency. North Korea places thousands of remote IT workers in Western organizations using fraudulent identities to earn wages for the regime and steal intellectual property. It’s likely that the individual was working at the federal agency via a contract job rather than being hired directly.

Coin-Sized Device Hacks Boeing 737

A group of academic researchers demonstrated how a concealed, coin-sized hardware device can successfully compromise systems on a Boeing 737. Malicious actors who have access to a plane can attach the hacking device to an external port, giving them remote access. While safety systems on an aircraft are likely to prevent direct harm, an attacker could spoof data such as air temperature readings and the aircraft weight, and even change a plane’s flight plan and divert it from its intended route.

LexisNexis Probes Potential Third Breach

LexisNexis took its Diligence, Metabase API, and Newsdesk services offline last week after identifying unusual activity on servers managed by a third-party vendor. The company stated it disconnected the systems to contain the threat. LexisNexis clarified that its Metabase API product is not connected to Metabase Cloud, which recently disclosed a zero-day vulnerability. This would be the third data breach suffered by LexisNexis in recent years.

Refrigeration Systems Flawed by Design

Claroty’s Team82 found vulnerabilities in two widely used commercial refrigeration systems. The researchers discovered 23 vulnerabilities in Copeland XWEB Pro controllers, including ones that can be chained to bypass security controls and achieve root-level RCE. A demonstration showed that a compromised controller could remotely manipulate refrigeration equipment, including cooling fans and compressors, and conceal the resulting temperature increase while food spoils. Team82 also identified multiple vulnerabilities in Danfoss AK-SM 800A refrigeration controllers, including RCE flaws. Both vendors patched the vulnerabilities discovered by Claroty.

Delta Flight Wi-Fi Interference

A passenger on a Delta flight from Las Vegas to Atlanta is suspected of broadcasting an unauthorized Wi-Fi network. Delta said the aircraft and its systems were never at risk and that no Delta system was hacked, while confirming that the unauthorized network was active briefly and that the crew disabled in-flight Wi-Fi for about 30 minutes during the incident. Reports suggest that someone who had attended the DEF CON conference set up the fake Wi-Fi network, but the identity of the individual currently remains unknown.

Uber Freight Investigates Unauthorized Access

Uber Freight is investigating unauthorized access to part of its systems and repositories following claims by hackers. The company said its operations have not been disrupted and that its systems remain secure and fully operational while the investigation continues. The probe was launched after a group named Helix claimed to have stolen nearly 1 million Uber Freight files. Helix, whose activities were detailed recently by Google, is also believed to be behind a recent campaign targeting major Wall Street companies.

Rapid7 Lays Off 12% of Workforce

Rapid7 is cutting 314 jobs, or 12% of its workforce, as new CEO Wael Mohamed restructures the cybersecurity vendor around efficiency and its core platform. The company expects to spend up to $11 million on severance and benefits while redirecting resources toward product modernization and AI-driven capabilities, with the restructuring also intended to help lift its non-GAAP operating margin to 20% in Q4 2026.

Gunra Ransomware Advisory

CISA has issued a new #StopRansomware advisory focused on Gunra ransomware, providing organizations with information intended to help identify and defend against the threat. The advisory adds Gunra to the growing body of ransomware intelligence being made available to defenders by the agency.

Industrial Ransomware Incidents Climb

Dragos identified 1,140 ransomware incidents affecting industrial organizations worldwide in Q2 2026, a 12% increase from the previous quarter, with manufacturing accounting for 747 incidents. While ransomware continued to disrupt operations through IT, ERP and virtualization systems, Dragos found no cases in which attackers directly manipulated industrial control systems.

Why It Matters

The breadth of incidents this week underscores the need for constant vigilance, from physical supply chains to software dependencies. The Boeing hack and refrigeration flaws show that security must extend beyond traditional IT, while the rapid spread of ransomware highlights the importance of robust backup and response plans. As threat actors exploit new avenues, organizations must adapt their defenses to protect both data and physical assets.

#pentagon#boeing#ransomware#industrial#rapid7#lexisnexis

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories