Ticker feed
Coca-Cola has confirmed a data breach tied to a ransomware attack on its dairy subsidiary Fairlife. The company initially disclosed the intrusion on July 16, suspending production at four U.S. Fairlife facilities. Most production has since resumed, and Fairlife product availability remains largely unaffected thanks to existing inventory.
The Anubis ransomware group claimed responsibility on July 20, alleging it stole 1 TB of confidential data — a figure Coca-Cola has not confirmed. The company acknowledges data was taken but hasn't said what, and says the incident won't materially affect its financial condition or results of operations.
Anubis has been active since December 2024, runs a double-extortion model, and unusually also carries a wiper mode for permanently destroying files. It has threatened to publish the stolen Fairlife data if no ransom is paid.
Source: SecurityWeek
Coca-Cola has confirmed a data breach tied to a ransomware attack on its dairy subsidiary Fairlife. The company initially disclosed the intrusion on July 16, suspending production at four U.S. Fairlife facilities. Most production has since resumed, and Fairlife product availability remains largely unaffected thanks to existing inventory.
The Anubis ransomware group claimed responsibility on July 20, alleging it stole 1 TB of confidential data — a figure Coca-Cola has not confirmed. The company acknowledges data was taken but hasn't said what, and says the incident won't materially affect its financial condition or results of operations.
Anubis has been active since December 2024, runs a double-extortion model, and unusually also carries a wiper mode for permanently destroying files. It has threatened to publish the stolen Fairlife data if no ransom is paid.
Source: SecurityWeek
CISA added six actively exploited Microsoft zero-days to its Known Exploited Vulnerabilities Catalog on 10 February 2026: CVE-2026-21510 (Windows Shell), CVE-2026-21513 (MSHTML), CVE-2026-21514 (Office Word), CVE-2026-21519 (Desktop Window Manager), CVE-2026-21525 (Remote Access Connection Manager) and CVE-2026-21533 (Remote Desktop Services).
Between them they cover privilege escalation, security feature bypasses and denial of service. Microsoft shipped fixes in its February 2026 Patch Tuesday, so anyone current on updates is covered — the risk sits with organisations that deferred that cycle.
Federal remediation deadlines have since changed. CISA replaced Binding Operational Directive 22-01 with BOD 26-04 on 10 June 2026, swapping flat timelines for a tiered model running from three days to 60 days depending on risk.
Nation-state groups, including China's Salt Typhoon, are among those exploiting similar flaws. All organisations should confirm the February patches are applied and audit exposure across Office, RDS and remote access tools.
Source: Cybersecurity News
CISA added six actively exploited Microsoft zero-days to its Known Exploited Vulnerabilities Catalog on 10 February 2026: CVE-2026-21510 (Windows Shell), CVE-2026-21513 (MSHTML), CVE-2026-21514 (Office Word), CVE-2026-21519 (Desktop Window Manager), CVE-2026-21525 (Remote Access Connection Manager) and CVE-2026-21533 (Remote Desktop Services).
Between them they cover privilege escalation, security feature bypasses and denial of service. Microsoft shipped fixes in its February 2026 Patch Tuesday, so anyone current on updates is covered — the risk sits with organisations that deferred that cycle.
Federal remediation deadlines have since changed. CISA replaced Binding Operational Directive 22-01 with BOD 26-04 on 10 June 2026, swapping flat timelines for a tiered model running from three days to 60 days depending on risk.
Nation-state groups, including China's Salt Typhoon, are among those exploiting similar flaws. All organisations should confirm the February patches are applied and audit exposure across Office, RDS and remote access tools.
Source: Cybersecurity News
A supply chain attack hit Jscrambler's popular NPM package on July 11, after a threat actor used a compromised publishing credential to push malicious versions containing hidden malware. Jscrambler versions 8.16, 8.17, 8.18 and 8.20 were affected — 8.19 was not — along with jscrambler-webpack-plugin 8.6.2, gulp-jscrambler 8.6.2, grunt-jscrambler 8.5.2 and jscrambler-metro-plugin 9.0.2. The tainted versions were downloaded 1,479 times before being deprecated.
The malware, written in Rust, steals credentials, crypto wallet seed phrases, browser data and cloud API keys — and reaches further than most, pulling in AI coding assistant and MCP configurations, OS keyrings, messaging apps and Steam sessions. It exfiltrates everything over TLS and tries stolen credentials against cloud APIs.
Jscrambler has deprecated the malicious versions and released clean version 8.22. If you installed any affected version, remove it immediately, scan for malware, and rotate all secrets and API keys.
Source: SecurityWeek
A supply chain attack hit Jscrambler's popular NPM package on July 11, after a threat actor used a compromised publishing credential to push malicious versions containing hidden malware. Jscrambler versions 8.16, 8.17, 8.18 and 8.20 were affected — 8.19 was not — along with jscrambler-webpack-plugin 8.6.2, gulp-jscrambler 8.6.2, grunt-jscrambler 8.5.2 and jscrambler-metro-plugin 9.0.2. The tainted versions were downloaded 1,479 times before being deprecated.
The malware, written in Rust, steals credentials, crypto wallet seed phrases, browser data and cloud API keys — and reaches further than most, pulling in AI coding assistant and MCP configurations, OS keyrings, messaging apps and Steam sessions. It exfiltrates everything over TLS and tries stolen credentials against cloud APIs.
Jscrambler has deprecated the malicious versions and released clean version 8.22. If you installed any affected version, remove it immediately, scan for malware, and rotate all secrets and API keys.
Source: SecurityWeek
A misconfigured Python HTTP server in Budapest with directory listing enabled handed researchers a full look inside three active phishing campaigns. The exposed server at 185.163.204.7 contained credential logs, phishing configs, RMM installers, combolists, and even the operator's own Telegram session files.
Three distinct threat actors were identified: codemado, an Egyptian operator whose Microsoft 365 AiTM campaign ran from January to May 2026; mail-argenta, a Nigerian operator undone by his own reused password, hardcoded in a public GitHub repo and later found in infostealer logs; and saroula01, whose Device Code Flow campaign quietly accumulated 218 victims across 12 countries over a year — 94% of them corporate accounts.
All three built their MFA-bypassing infrastructure from customised Evilginx forks pulled straight off public GitHub repositories, with minimal modification. The barrier to running these attacks is effectively zero.
Source: Lexfo Security Blog
A misconfigured Python HTTP server in Budapest with directory listing enabled handed researchers a full look inside three active phishing campaigns. The exposed server at 185.163.204.7 contained credential logs, phishing configs, RMM installers, combolists, and even the operator's own Telegram session files.
Three distinct threat actors were identified: codemado, an Egyptian operator whose Microsoft 365 AiTM campaign ran from January to May 2026; mail-argenta, a Nigerian operator undone by his own reused password, hardcoded in a public GitHub repo and later found in infostealer logs; and saroula01, whose Device Code Flow campaign quietly accumulated 218 victims across 12 countries over a year — 94% of them corporate accounts.
All three built their MFA-bypassing infrastructure from customised Evilginx forks pulled straight off public GitHub repositories, with minimal modification. The barrier to running these attacks is effectively zero.
Source: Lexfo Security Blog
Security firm Socket has uncovered "Operation Muck and Load" — a campaign using 222 GitHub repositories across 190 accounts to distribute Windows malware. Active since January 24, 2026, the threat actor published over 1,200 package versions, 700 of which are malicious.
The attack disguises a Go module as a legitimate DNS scanning tool, impersonating the real open source project dnsub. Hidden PowerShell code then pulls encrypted payloads from dead-drop platforms including Pastebin, YouTube, Instagram, Telegram, and Google Docs — making it harder to shut down.
Final payloads include AsyncRAT, Quasar RAT, Vidar infostealer, and XMRig cryptominers. Anyone who has pulled a DNS or subdomain scanning module from GitHub should check what they actually installed — go.mod and go.sum are the place to start.
Source: SecurityWeek
Security firm Socket has uncovered "Operation Muck and Load" — a campaign using 222 GitHub repositories across 190 accounts to distribute Windows malware. Active since January 24, 2026, the threat actor published over 1,200 package versions, 700 of which are malicious.
The attack disguises a Go module as a legitimate DNS scanning tool, impersonating the real open source project dnsub. Hidden PowerShell code then pulls encrypted payloads from dead-drop platforms including Pastebin, YouTube, Instagram, Telegram, and Google Docs — making it harder to shut down.
Final payloads include AsyncRAT, Quasar RAT, Vidar infostealer, and XMRig cryptominers. Anyone who has pulled a DNS or subdomain scanning module from GitHub should check what they actually installed — go.mod and go.sum are the place to start.
Source: SecurityWeek
Accenture has confirmed a security incident after a hacker posted on PwnForums claiming to have stolen 35 gigabytes of internal data — including Azure access keys, tokens, SSH and RSA keys, configuration files, and source code. The threat actor posted a screenshot of a private Azure DevOps repository on an accenture.com domain as proof, and listed the data for sale.
Accenture called it "this isolated matter," said it had "remediated its source," and reported no impact to operations or service delivery. It did not confirm what was taken, whether personal or client data was involved, or how the attacker got in.
Ross Filipek, CISO at Corsica Technologies, warns the stolen data could serve as "a playbook for future attacks" — exposing code vulnerabilities, credentials and infrastructure detail. Consulting firms make attractive targets precisely because of how deep their access runs into client systems.
Source: SecurityWeek
Accenture has confirmed a security incident after a hacker posted on PwnForums claiming to have stolen 35 gigabytes of internal data — including Azure access keys, tokens, SSH and RSA keys, configuration files, and source code. The threat actor posted a screenshot of a private Azure DevOps repository on an accenture.com domain as proof, and listed the data for sale.
Accenture called it "this isolated matter," said it had "remediated its source," and reported no impact to operations or service delivery. It did not confirm what was taken, whether personal or client data was involved, or how the attacker got in.
Ross Filipek, CISO at Corsica Technologies, warns the stolen data could serve as "a playbook for future attacks" — exposing code vulnerabilities, credentials and infrastructure detail. Consulting firms make attractive targets precisely because of how deep their access runs into client systems.
Source: SecurityWeek
A massive global cybercrime sweep has wrapped up with 5,811 arrests and $293 million in intercepted illicit assets. Operation First Light 2026 ran from January 15 to April 30, 2026, pulling in law enforcement from 97 countries under Interpol's coordination — with funding from China's Ministry of Public Security.
The operation targeted social engineering scams like romance fraud and business email compromise schemes. Authorities blocked or froze 31,014 bank accounts, seized cryptocurrency wallets, identified 15,606 suspects, and uncovered more than 142,000 victims worldwide.
One standout bust in Eswatini took down a network posing as Brazilian Federal Police over video calls, talking victims into transferring money for "safekeeping." Officers seized 240 electronic devices and a full replica Brazilian police station — fake uniforms, signage and all.
Source: Infosecurity Magazine
A massive global cybercrime sweep has wrapped up with 5,811 arrests and $293 million in intercepted illicit assets. Operation First Light 2026 ran from January 15 to April 30, 2026, pulling in law enforcement from 97 countries under Interpol's coordination — with funding from China's Ministry of Public Security.
The operation targeted social engineering scams like romance fraud and business email compromise schemes. Authorities blocked or froze 31,014 bank accounts, seized cryptocurrency wallets, identified 15,606 suspects, and uncovered more than 142,000 victims worldwide.
One standout bust in Eswatini took down a network posing as Brazilian Federal Police over video calls, talking victims into transferring money for "safekeeping." Officers seized 240 electronic devices and a full replica Brazilian police station — fake uniforms, signage and all.
Source: Infosecurity Magazine
A sophisticated phishing campaign is targeting marketing professionals by impersonating major brands including Coca-Cola, Netflix, OpenAI, McKinsey & Company, Louis Vuitton and FIFA. First spotted by Team Cymru's Will Thomas, the attackers send personalized job recruitment emails via legitimate HR platform PeopleForce, then route victims through nested redirects — bouncing through Salesforce's ExactTarget and real estate CRM Wise Agent — before landing on a fake Google sign-in page hosted on Netlify.
The multi-hop redirect chain bypasses basic email filters and builds false trust. Over 30 malicious domains have been identified, on convincing addresses like mckinsey-careers[.]com.
The final page uses a browser-in-the-browser trick: the Google login window is drawn inside the web page rather than being a real browser window. That's the tell — a genuine login window can be dragged outside the page, and a fake one can't. Password managers help too, since they won't autofill on a spoofed domain. Advanced web filtering and social engineering training round out the defenses.
Source: Dark Reading
A sophisticated phishing campaign is targeting marketing professionals by impersonating major brands including Coca-Cola, Netflix, OpenAI, McKinsey & Company, Louis Vuitton and FIFA. First spotted by Team Cymru's Will Thomas, the attackers send personalized job recruitment emails via legitimate HR platform PeopleForce, then route victims through nested redirects — bouncing through Salesforce's ExactTarget and real estate CRM Wise Agent — before landing on a fake Google sign-in page hosted on Netlify.
The multi-hop redirect chain bypasses basic email filters and builds false trust. Over 30 malicious domains have been identified, on convincing addresses like mckinsey-careers[.]com.
The final page uses a browser-in-the-browser trick: the Google login window is drawn inside the web page rather than being a real browser window. That's the tell — a genuine login window can be dragged outside the page, and a fake one can't. Password managers help too, since they won't autofill on a spoofed domain. Advanced web filtering and social engineering training round out the defenses.
Source: Dark Reading
Cybersecurity firm Sysdig has documented what it calls the first agentic ransomware attack — where an AI agent autonomously ran an entire extortion operation, from reconnaissance and credential theft through lateral movement, encryption, data destruction and the ransom note. The late June 2026 attack, attributed to a financially motivated group called JadePuffer, exploited Langflow flaw CVE-2025-3248 to reach a MySQL and Alibaba Nacos production server.
The agent ran over 600 payloads, self-corrected an error in 31 seconds, and tapped models from OpenAI, Anthropic, DeepSeek and Gemini.
The autonomy had limits worth noting. A human provisioned the infrastructure, configured the command-and-control server, picked the victim, and supplied root credentials obtained in an earlier compromise — the agent took it from there.
"The skill floor for running a full ransomware operation just dropped to whatever it costs to run an agent," warned Michael Clark, Sysdig's senior director of threat research. Anyone running Langflow should confirm CVE-2025-3248 is patched.
Source: CyberScoop
Cybersecurity firm Sysdig has documented what it calls the first agentic ransomware attack — where an AI agent autonomously ran an entire extortion operation, from reconnaissance and credential theft through lateral movement, encryption, data destruction and the ransom note. The late June 2026 attack, attributed to a financially motivated group called JadePuffer, exploited Langflow flaw CVE-2025-3248 to reach a MySQL and Alibaba Nacos production server.
The agent ran over 600 payloads, self-corrected an error in 31 seconds, and tapped models from OpenAI, Anthropic, DeepSeek and Gemini.
The autonomy had limits worth noting. A human provisioned the infrastructure, configured the command-and-control server, picked the victim, and supplied root credentials obtained in an earlier compromise — the agent took it from there.
"The skill floor for running a full ransomware operation just dropped to whatever it costs to run an agent," warned Michael Clark, Sysdig's senior director of threat research. Anyone running Langflow should confirm CVE-2025-3248 is patched.
Source: CyberScoop
Security researchers at Push Security have uncovered a "poisoned tenant" attack where hackers create fake OpenAI organizations — impersonating real companies — and send employees legitimate-looking invitations straight from OpenAI's own notification system, noreply@tm.openai.com. One click joins the victim to an attacker-controlled tenant with zero additional verification.
Once inside, anything the employee does — prompts, uploaded files, API calls — is visible to the attacker. The fake orgs go to some lengths to look real: executive impersonation, Owner-level privileges for everyone, even a credit card attached to avoid friction on paid features. Push found the technique when it saw itself impersonated, and the invites observed so far have targeted cybersecurity and tech firms.
No spoofed domains, no malicious links. Just a trusted platform being weaponized against its own users. The one visible tell is a small domain mismatch warning on the invite. Beyond that, defences are organizational: restrict who can join external tenants, enforce domain verification, and get visibility into which SaaS orgs staff are actually joining.
Source: Cybersecurity News
Security researchers at Push Security have uncovered a "poisoned tenant" attack where hackers create fake OpenAI organizations — impersonating real companies — and send employees legitimate-looking invitations straight from OpenAI's own notification system, noreply@tm.openai.com. One click joins the victim to an attacker-controlled tenant with zero additional verification.
Once inside, anything the employee does — prompts, uploaded files, API calls — is visible to the attacker. The fake orgs go to some lengths to look real: executive impersonation, Owner-level privileges for everyone, even a credit card attached to avoid friction on paid features. Push found the technique when it saw itself impersonated, and the invites observed so far have targeted cybersecurity and tech firms.
No spoofed domains, no malicious links. Just a trusted platform being weaponized against its own users. The one visible tell is a small domain mismatch warning on the invite. Beyond that, defences are organizational: restrict who can join external tenants, enforce domain verification, and get visibility into which SaaS orgs staff are actually joining.
Source: Cybersecurity News