# Archive

Browse past daily curated stories

Jul 28 Jul 27 Jul 26 Jul 25 Jul 24 Jul 23 Jul 22 Jul 21 Jul 19 Jul 18 Jul 17 Jul 16 Jul 15 Jul 14 Jul 12 Jul 11 Jul 10 Jul 09 Jul 08 Jul 07 Jul 05 Jul 04 Jul 03 Jul 02 Jul 01 Jun 30 Jun 27 Jun 26 Jun 25 Jun 24

Tuesday, July 28, 2026

  1. 1
    0
    BleepingComputer general
    Coca-Cola confirms data theft in Fairlife ransomware attack

    Coca-Cola confirmed that ransomware attackers stole data from its dairy subsidiary Fairlife during an attack earlier this month. The Anubis cybercrime group has claimed responsibility and is threatening to leak the exfiltrated data, making this a significant corporate breach affecting a major consumer brand's subsidiary.

  2. 2
    0
    BleepingComputer general
    Ernst & Young data breach claimed by ShinyHunters extortion gang

    ShinyHunters has claimed responsibility for the Ernst & Young data breach, stating they obtained credentials via a supply-chain attack against one of EY's systems. ShinyHunters is a prolific extortion gang with a history of high-profile breaches, making this a notable supply-chain compromise of a Big Four accounting firm.

  3. 3
    0
    BleepingComputer general
    Arista patches VeloCloud Orchestrator zero-day exploited in attacks

    Arista patched a maximum-severity (CVSS 10.0) command injection zero-day in on-premises VeloCloud Orchestrator deployments that is actively being exploited in the wild. Network administrators running on-prem VeloCloud Orchestrator instances should apply the patch immediately given active exploitation and the critical severity rating.

  4. 4
    0
    SecurityWeek general
    DentaQuest Data Breach Potentially Impacts Over 23 Million People

    A May 2026 breach of DentaQuest's computer network resulted in theft of personal and dental health information potentially affecting over 23 million individuals. This ranks among the largest healthcare data breaches of 2026, with dental health records carrying significant sensitivity for affected patients.

  5. 5
    0
    BleepingComputer general
    New Certighost PoC exploit lets attackers hijack Windows domains

    A proof-of-concept exploit dubbed 'Certighost' has been publicly released for a Windows Active Directory Certificate Services vulnerability that allows authenticated attackers to potentially compromise an entire Windows domain. The PoC release significantly raises exploitation risk for organizations that have not yet patched their AD CS infrastructure.

  6. 6
    0
    BleepingComputer general
    Hackers target US firms in FastJson RCE zero-day attacks

    Threat actors are actively exploiting a zero-day remote code execution vulnerability in FastJson, a widely-used open-source Java JSON parsing library, targeting US firms without requiring user interaction or elevated privileges. The unauthenticated RCE nature of the flaw makes it particularly dangerous for any Java application using FastJson for input parsing.

  7. 7
    0
    Dark Reading general
    AI Agent Drives Espionage Attack on Thai Ministry of Finance

    Attackers deployed Hermes, an open-source autonomous AI agent running in unrestricted 'YOLO mode,' to conduct a cyber-espionage campaign against Thailand's Ministry of Finance. This represents one of the first documented cases of an AI agent being weaponized autonomously for nation-state-level espionage, signaling a new threat vector for government targets.

  8. 8
    0
    SecurityWeek general
    PTC Windchill Vulnerability Exploited in Ransomware Campaign

    A critical unsafe deserialization vulnerability in PTC Windchill, a widely deployed product lifecycle management platform, is being actively exploited in ransomware campaigns, allowing unauthenticated remote code execution. ICS/OT security teams running Windchill should treat this as an urgent patch priority given active ransomware exploitation.

  9. 9
    0
    The Hacker News general
    Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

    A public exploit was released on July 27 demonstrating how an unauthenticated HTTP request can reach PHP's eval() function in vBulletin versions 6.2.1 and earlier and 6.1.6 and earlier, enabling pre-authentication remote code execution with no user interaction required. Forum administrators on unpatched vBulletin instances are at immediate risk given the public availability of working exploit code.

  10. 10
    0
    SecurityWeek general
    Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials

    A threat actor has been compromising public Wi-Fi gateway appliances and using them to intercept and harvest Microsoft 365 credentials from traveling corporate employees. The attack targets the captive portal or authentication flow of public hotspot infrastructure, turning a trusted connectivity resource into a credential-harvesting trap for business travelers.