Microsoft warns of surge in ACR Stealer attacks on customers

Microsoft Sounds Alarm on Surge in ACR Stealer Attacks, Warns Customers of Sensitive Data Theft A significant uptick in attacks using the ACR Stealer malware has been detected by Microsoft, with the threat actor targeting enterprise customers and stealing sensitive data such as browser-stored passwords, authentication tokens, and documents. Between late April and mid-June, the … Read more

WordPress Core “wp2shell” RCE flaws get public exploits, patch now

WordPress Users Urged to Patch Critical Vulnerabilities as Public Exploits Emerge A severe security threat has emerged for millions of WordPress users, with two critical vulnerabilities in the content management system’s core code allowing unauthenticated attackers to execute malicious code on affected sites. The flaws, known as wp2shell, have been publicly exploited and patched, but … Read more

Microsoft warns of surge in ACR Stealer attacks on customers

A Surge in ACR Stealer Attacks Leaves Microsoft Enterprise Customers Vulnerable Microsoft has sounded the alarm on a significant increase in attacks using the ACR Stealer malware, which targets sensitive data stored on browsers and enterprise systems. Between late April and mid-June, threat actors exploited ClickFix social engineering tactics, WebDAV servers, and MSHTA utility to … Read more

State officials, election experts pan Trump speech: ‘This is what desperation looks like’

State Officials and Experts Blast Trump’s Election Claims as “Desperation” In a scathing rebuke, state officials and election security experts have panned President Donald Trump’s latest claims about alleged voter fraud and foreign interference in US elections. The White House had teased explosive new evidence to support the President’s long-standing allegations, but experts say it … Read more

Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack

Coca-Cola’s Fairlife Dairy Unit Hit by Ransomware Attack, Production Suspended A major ransomware attack has forced Coca-Cola to temporarily suspend production at its US-based dairy subsidiary, Fairlife. The company disclosed the incident in a filing with the US Securities and Exchange Commission (SEC) on July 16, revealing that hackers had gained access to a portion … Read more

Fresh SharePoint Vulnerability Exploited Soon After Disclosure

A critical vulnerability in Microsoft SharePoint, disclosed just last week, is already being exploited by threat actors. The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to federal agencies, urging them to patch the flaw within three days. The vulnerability, tracked as CVE-2026-58644, allows an attacker with at least Site Owner privileges … Read more

ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th)

Cybersecurity Experts Sound Alarm on Widespread DNS Spoofing Attacks A wave of targeted DNS spoofing attacks has been sweeping across the globe, compromising sensitive information and crippling online services for unsuspecting users. Cybersecurity experts at SANS ISC have sounded the alarm on this emerging threat, urging organizations to take immediate action to protect themselves. The … Read more