- Cybersecurity Docket
- Posts
- Analog Devices Assessing New Cyber Breach Claim from Hackers
Analog Devices Assessing New Cyber Breach Claim from Hackers
Plus, Cybernews researchers expose ransomware campaign against V-Silicon.

Good morning! Here’s what’s up.

People
Frances Mosley has joined Cooley as a partner in the emerging companies and venture capital (ECVC) practice, based in the firm’s Palo Alto office. She brings to Cooley experience in the medical device, digital health and life sciences sectors, complemented by a robust portfolio of work with artificial intelligence and tech-driven ventures. Mosley joins Cooley from DLA Piper, where she was a partner representing tech and life sciences emerging growth companies and venture investors.
Justin Webb has joined Netflix as principal counsel, cybersecurity legal. In this role, he will help navigate the complex legal issues surrounding cybersecurity and artificial intelligence. Webb joins Netflix after nearly five years at SNAP Inc, where he most recently was associate general counsel of cybersecurity, privacy, and AI.

Clips ✂️
Analog Devices Assessing Latest Cyber Breach Claim From Hackers
Analog Devices Inc. is assessing a new claim by a group of hackers who say they’ve stolen hundreds of files containing information on customers of the computer chips maker.
A hacking group known as ExfilSquad has claimed to have breached Analog Devices and is threatening to release sensitive customer data unless its demands are met, according to the cybersecurity firm DeXpose. Analog Devices said in a filing Wednesday that it was made aware of reports and is assessing “validity, scope, and any potential impact.”
👉 In its July 29 regulatory filing, Analog Devices reported that on June 23 it had “identified unauthorized access to certain company systems,” and that “certain files were exfiltrated.” The company disclosed that it “immediately activated its incident response protocols and engaged external cybersecurity experts to assist with containment and investigation activities.” It also said it has “notified and is coordinating with law enforcement authorities.”
Exposed hacker server reveals an attack on V-Silicon semiconductor company
Cybernews researchers uncovered an active ransomware campaign against multinational semiconductor company V-Silicon after discovering an exposed hacker server.
Cybercriminals are not immune to human errors. A simple security mistake made by an attacker can sometimes expose ongoing ransomware operations and how they function.
Recently, Cybernews researchers discovered an exposed web directory that functioned as a staging server for a ransomware attack.
A subsequent investigation linked the discovered infrastructure to an attack against V-Silicon, a multinational semiconductor company that develops chips used in smart TVs and display devices.
The campaign was attributed to INC Ransomware, a ransomware-as-a-service (RaaS) operation that has been active since 2023.
Our researchers say the exposed server contained hacking tools built specifically for the campaign. The evidence found on the server allowed the team to reconstruct the attack chain before it hit the public.
After years of prioritizing rapid AI adoption and widespread experimentation, senior executives are shifting their strategies. The latest research from EY reveals that senior leaders are pivoting to sharply balance cost against value, driven by mounting operational expenses and the rise of autonomous agentic workflows.
The new EY US AI Pulse Survey, the fifth in a series of polls of at least 500 US-employed decision-makers (senior vice presidents and above) from a broad range of sectors, uncovers the impacts of agentic vibe coding on organizations, with 82% of senior leaders whose organization is investing in AI saying their organization is concerned about AI token usage (units of data AI models use to process the amount of inputs and generate outputs) and related costs.
Furthermore, an overwhelming 98% of those investing in AI and using tools that require AI tokens say AI token usage and related costs have caused their organization to reconsider their approach.
Microsoft’s Nadella: trusting AI too much can bankrupt a business
Microsoft CEO Satya Nadella has previously criticized a small group of leading AI companies for dominating the conversation with either hype overload or gloom. Now, he’s warning businesses that they shouldn’t trust AI too much.
By now, businesses large and small already know that using too much AI can be extremely costly if you’re not careful with token usage.
…
A month ago, Nadella already spoke in an interview with The Wall Street Journal, saying AI models should be cheaper and pointing out that the public wouldn’t tolerate just a few models and companies “doing all of the learning for the world.”
Now, the Microsoft CEO has another warning. On an episode of CNN’s Fareed Zakaria GPS, Nadella said businesses shouldn’t share too much information – including proprietary data and the prompts entered – with third-party AI models they’re using.
EY Says Its 'Invisible' Router Has Helped Cut Token Consumption by up to 60%
EY does not let every employee query go straight to the smartest AI model in the room.
The Big Four firm has introduced an "invisible" router to help manage its internal AI spending, Dan Diasio, EY's global consulting AI leader, told Business Insider.
Rolled out globally in April, the router sits behind some of EY's specialized AI tools and acts as an intermediary to direct employees towards the best AI model for the task at hand.
"To the users, it makes no apparent change," said Diasio. They open the frontier model, enter their prompt, and get a response. But behind the scenes, the router is deciding where their query should go.
"Many times, it's faster than the frontier models, because to use the heavier models means there's more thinking that gets put in place, and it takes longer to be able to get back to the answer," Diasio added.
Token costs have become a growing concern for companies as AI providers increasingly charge based on usage.
Exposed credentials are giving attackers a head start many organizations don’t see
Compromised credentials can remain active long after passwords are created, leaving organizations trying to identify exposed accounts before attackers can use them. The 2026 Credential Risk Report from Enzoic shows growing awareness of the problem, but monitoring and response capabilities continue to lag.
The growing risk of exposed credentials
73% of organizations identified employee or contractor credentials in breach data, dark web sources, or infostealer logs during the past year, while nearly one in five lack visibility into whether their credentials have been exposed. More than seven in 10 companies experienced an authentication-related incident during the past year, and two-thirds of the most recent incidents involved attackers signing in with valid credentials.
Exposed credentials often stay active long enough to be exploited, making early identification a key part of reducing credential-based risk.
