Coca-Cola confirms data theft in Fairlife ransomware attack

Coca-Cola Confirms Data Theft in Fairlife Ransomware Attack, Production Mostly Resumed A ransomware attack on Coca-Cola’s dairy subsidiary, Fairlife, has resulted in the theft of sensitive data, the company confirmed yesterday. The cyberattack, which was first disclosed by the global beverages giant earlier this month, disrupted production operations at Fairlife’s four US facilities, but most … Read more

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Cybersecurity Threats Escalate as Operation BlueDash Exploits Remote Management Tools A sophisticated cyberattack campaign, dubbed Operation BlueDash, has been uncovered, targeting organizations with fake software updates that compromise remote management tools. This malware-driven operation leverages a combination of Level RMM (Remote Monitoring and Management) and ScreenConnect to gain unauthorized access to corporate networks. At its … Read more

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

A critical vulnerability has been discovered in the popular workflow automation tool n8n, allowing unauthorized access to sensitive system resources. The flaw, known as an “out-of-sandbox” escape, allows malicious actors to execute arbitrary operating system commands with elevated privileges, posing a significant risk to organizations that rely on the platform. The issue stems from a … Read more

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

As AI-generated malware continues to evolve and become increasingly sophisticated, security teams are being outsmarted by rogue agents designed to exploit software vulnerabilities. In a disturbing trend, researchers have discovered that these AI models can identify previously unknown flaws in code, making it easier for attackers to breach even the most secure systems. The vulnerability … Read more

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

A freshly disclosed exploit for a pre-authentication code execution vulnerability in vBulletin, a popular online forum software, is wreaking havoc on unsuspecting users. The bug, first patched by vBulletin’s developers several months ago, has been exploited by attackers to inject malicious code and steal sensitive data from compromised websites. The vulnerable software, widely used by … Read more

Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack

Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack A devastating cyberattack has left one of the world’s largest beverage companies reeling. Coca-Cola has confirmed that its dairy products subsidiary, Fairlife, was hit by a ransomware attack from the Anubis group. The cybercriminals claim to have stolen over 1 terabyte (TB) of confidential data, including files … Read more

Nvidia and Tech Giants Launch AI Security Alliance

A group of tech giants, led by Nvidia, has launched a new initiative to develop and share open-source tools for securing artificial intelligence (AI) systems. The Open Secure AI Alliance brings together companies like Adobe, Cisco, IBM, Microsoft, and many others to create a collective defense against the growing threats in the AI security landscape. … Read more

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection

A Stealthy RAT Hides in Plain Sight: MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection A sophisticated remote access trojan (RAT) has been discovered using a legitimate Windows feature to evade detection and remain hidden from users. MedusaHVNC, sold as malware-as-a-service (MaaS), is promoted through its own website and Telegram channel, and was analyzed … Read more

PTC Windchill Vulnerability Exploited in Ransomware Campaign

A Cl0p Ransomware Affiliate Exploits Critical PTC Windchill Vulnerability, Targeting Multiple Industries A critical remote code execution (RCE) vulnerability in PTC’s product lifecycle management (PLM) platforms Windchill and FlexPLM has been exploited by a Cl0p ransomware affiliate. The bug, tracked as CVE-2026-12569 with a CVSS score of 9.3, allows attackers to execute code on vulnerable … Read more

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

A sophisticated malware campaign, dubbed “Cruciferra Crypter,” has been uncovered, leveraging advanced techniques to evade detection and remain hidden on infected Windows systems. The malicious software employs two key tactics: Bring Your Own Vulnerability Disclosure (BYOVD) and process ghosting, making it a particularly challenging foe for cybersecurity teams. The Cruciferra Crypter malware operates by exploiting … Read more