Week in Brief: Google Security Cuts, AudiA6 Forum Axed, Coupang's $400M Fine

ICS exposure holds flat while the attack surface grows, IBM and AT&T face hack cover-up allegations, and Microsoft quietly drops an AI incident-response playbook.

ThreatVectr Newsdesk· 2 min read
Week in Brief: Google Security Cuts, AudiA6 Forum Axed, Coupang's $400M Fine
Share

A handful of stories moved quickly last week without getting the runway they deserved.

Google trims its security headcount. The cuts hit staff inside Google's security org — exact scope unconfirmed, but the timing lands as the company continues broader workforce restructuring. The practical effect on product security teams remains to be seen.

AudiA6 goes dark. The forum, a gathering point for threat actors trading stolen credentials and access, was taken down in what appears to be a coordinated law enforcement action. No arrests publicly announced yet. These takedowns rarely kill a community outright; they scatter it.

Coupang fined $400 million. The South Korean e-commerce giant faces a nine-figure penalty tied to data-handling violations. Coupang operates at scale — tens of millions of users across South Korea and a growing logistics footprint. Regulators have not detailed the exact breach or misuse at the center of the enforcement action, but the fine signals that Asian regulators are matching the posture of their European counterparts.

IBM and AT&T accused of cover-ups. Both companies face allegations that they concealed the true scope of security incidents from customers and regulators. Cover-up accusations are distinct from breach disclosures — they imply active concealment rather than delayed notification. No court has made findings yet.

ICS device exposure: flat, but worsening. Industrial control system devices visible on the public internet haven't grown dramatically in raw count, but the attack surface has widened as more of those devices run outdated firmware and sit behind thinner network controls. Flat numbers with deeper risk is not a neutral trend.

Microsoft releases an AI incident-response playbook. The document, aimed at enterprise defenders, outlines how security teams should triage and contain incidents involving AI systems — model poisoning, prompt injection abuse, data exfiltration through AI pipelines. Practical guidance in this space is sparse. The playbook fills a gap, even if it reflects Microsoft's own product assumptions throughout.

Six threads, none resolved. That's the week.

© 2026 Threat Vectr