# Today's Top Stories

July 28, 2026

  1. 1
    0
    BleepingComputer general Jul 27
    Coca-Cola confirms data theft in Fairlife ransomware attack

    Coca-Cola confirmed that ransomware attackers stole data from its dairy subsidiary Fairlife during an attack earlier this month. The Anubis cybercrime group has claimed responsibility and is threatening to leak the exfiltrated data, making this a significant corporate breach affecting a major consumer brand's subsidiary.

  2. 2
    0
    BleepingComputer general Jul 27
    Ernst & Young data breach claimed by ShinyHunters extortion gang

    ShinyHunters has claimed responsibility for the Ernst & Young data breach, stating they obtained credentials via a supply-chain attack against one of EY's systems. ShinyHunters is a prolific extortion gang with a history of high-profile breaches, making this a notable supply-chain compromise of a Big Four accounting firm.

  3. 3
    0
    BleepingComputer general Jul 27
    Arista patches VeloCloud Orchestrator zero-day exploited in attacks

    Arista patched a maximum-severity (CVSS 10.0) command injection zero-day in on-premises VeloCloud Orchestrator deployments that is actively being exploited in the wild. Network administrators running on-prem VeloCloud Orchestrator instances should apply the patch immediately given active exploitation and the critical severity rating.

  4. 4
    0
    SecurityWeek general Jul 27
    DentaQuest Data Breach Potentially Impacts Over 23 Million People

    A May 2026 breach of DentaQuest's computer network resulted in theft of personal and dental health information potentially affecting over 23 million individuals. This ranks among the largest healthcare data breaches of 2026, with dental health records carrying significant sensitivity for affected patients.

  5. 5
    0
    BleepingComputer general Jul 27
    New Certighost PoC exploit lets attackers hijack Windows domains

    A proof-of-concept exploit dubbed 'Certighost' has been publicly released for a Windows Active Directory Certificate Services vulnerability that allows authenticated attackers to potentially compromise an entire Windows domain. The PoC release significantly raises exploitation risk for organizations that have not yet patched their AD CS infrastructure.

  6. 6
    0
    BleepingComputer general Jul 27
    Hackers target US firms in FastJson RCE zero-day attacks

    Threat actors are actively exploiting a zero-day remote code execution vulnerability in FastJson, a widely-used open-source Java JSON parsing library, targeting US firms without requiring user interaction or elevated privileges. The unauthenticated RCE nature of the flaw makes it particularly dangerous for any Java application using FastJson for input parsing.

  7. 7
    0
    Dark Reading general Jul 28
    AI Agent Drives Espionage Attack on Thai Ministry of Finance

    Attackers deployed Hermes, an open-source autonomous AI agent running in unrestricted 'YOLO mode,' to conduct a cyber-espionage campaign against Thailand's Ministry of Finance. This represents one of the first documented cases of an AI agent being weaponized autonomously for nation-state-level espionage, signaling a new threat vector for government targets.

  8. 8
    0
    SecurityWeek general Jul 27
    PTC Windchill Vulnerability Exploited in Ransomware Campaign

    A critical unsafe deserialization vulnerability in PTC Windchill, a widely deployed product lifecycle management platform, is being actively exploited in ransomware campaigns, allowing unauthenticated remote code execution. ICS/OT security teams running Windchill should treat this as an urgent patch priority given active ransomware exploitation.

  9. 9
    0
    The Hacker News general Jul 27
    Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

    A public exploit was released on July 27 demonstrating how an unauthenticated HTTP request can reach PHP's eval() function in vBulletin versions 6.2.1 and earlier and 6.1.6 and earlier, enabling pre-authentication remote code execution with no user interaction required. Forum administrators on unpatched vBulletin instances are at immediate risk given the public availability of working exploit code.

  10. 10
    0
    SecurityWeek general Jul 27
    Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials

    A threat actor has been compromising public Wi-Fi gateway appliances and using them to intercept and harvest Microsoft 365 credentials from traveling corporate employees. The attack targets the captive portal or authentication flow of public hotspot infrastructure, turning a trusted connectivity resource into a credential-harvesting trap for business travelers.