# Archive
Browse past daily curated stories
Tuesday, July 28, 2026
-
1BleepingComputer generalCoca-Cola confirms data theft in Fairlife ransomware attack
Coca-Cola confirmed that ransomware attackers stole data from its dairy subsidiary Fairlife during an attack earlier this month. The Anubis cybercrime group has claimed responsibility and is threatening to leak the exfiltrated data, making this a significant corporate breach affecting a major consumer brand's subsidiary.
-
2BleepingComputer generalErnst & Young data breach claimed by ShinyHunters extortion gang
ShinyHunters has claimed responsibility for the Ernst & Young data breach, stating they obtained credentials via a supply-chain attack against one of EY's systems. ShinyHunters is a prolific extortion gang with a history of high-profile breaches, making this a notable supply-chain compromise of a Big Four accounting firm.
-
3BleepingComputer generalArista patches VeloCloud Orchestrator zero-day exploited in attacks
Arista patched a maximum-severity (CVSS 10.0) command injection zero-day in on-premises VeloCloud Orchestrator deployments that is actively being exploited in the wild. Network administrators running on-prem VeloCloud Orchestrator instances should apply the patch immediately given active exploitation and the critical severity rating.
-
4SecurityWeek generalDentaQuest Data Breach Potentially Impacts Over 23 Million People
A May 2026 breach of DentaQuest's computer network resulted in theft of personal and dental health information potentially affecting over 23 million individuals. This ranks among the largest healthcare data breaches of 2026, with dental health records carrying significant sensitivity for affected patients.
-
5BleepingComputer generalNew Certighost PoC exploit lets attackers hijack Windows domains
A proof-of-concept exploit dubbed 'Certighost' has been publicly released for a Windows Active Directory Certificate Services vulnerability that allows authenticated attackers to potentially compromise an entire Windows domain. The PoC release significantly raises exploitation risk for organizations that have not yet patched their AD CS infrastructure.
-
6BleepingComputer generalHackers target US firms in FastJson RCE zero-day attacks
Threat actors are actively exploiting a zero-day remote code execution vulnerability in FastJson, a widely-used open-source Java JSON parsing library, targeting US firms without requiring user interaction or elevated privileges. The unauthenticated RCE nature of the flaw makes it particularly dangerous for any Java application using FastJson for input parsing.
-
7Dark Reading generalAI Agent Drives Espionage Attack on Thai Ministry of Finance
Attackers deployed Hermes, an open-source autonomous AI agent running in unrestricted 'YOLO mode,' to conduct a cyber-espionage campaign against Thailand's Ministry of Finance. This represents one of the first documented cases of an AI agent being weaponized autonomously for nation-state-level espionage, signaling a new threat vector for government targets.
-
8SecurityWeek generalPTC Windchill Vulnerability Exploited in Ransomware Campaign
A critical unsafe deserialization vulnerability in PTC Windchill, a widely deployed product lifecycle management platform, is being actively exploited in ransomware campaigns, allowing unauthenticated remote code execution. ICS/OT security teams running Windchill should treat this as an urgent patch priority given active ransomware exploitation.
-
9The Hacker News generalPublic Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
A public exploit was released on July 27 demonstrating how an unauthenticated HTTP request can reach PHP's eval() function in vBulletin versions 6.2.1 and earlier and 6.1.6 and earlier, enabling pre-authentication remote code execution with no user interaction required. Forum administrators on unpatched vBulletin instances are at immediate risk given the public availability of working exploit code.
-
10SecurityWeek generalHacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials
A threat actor has been compromising public Wi-Fi gateway appliances and using them to intercept and harvest Microsoft 365 credentials from traveling corporate employees. The attack targets the captive portal or authentication flow of public hotspot infrastructure, turning a trusted connectivity resource into a credential-harvesting trap for business travelers.