WEEKLY TOP TEN: July 20, 2026, 16:00 GMT
- Ernst And Young Discloses Data Breach After Support System Hack
Ernst & Young is notifying customers of a data breach traced to a compromised third-party support ticket system used by its IT personnel. Attackers gained access to the platform and were able to view information tied to customer support interactions handled through the tool. The professional services and consulting giant has not disclosed the exact number of individuals or clients affected, but the incident highlights the growing risk posed by third-party helpdesk and ticketing tools that hold sensitive customer communications. EY says it is investigating the scope of the exposure and notifying affected parties as required.. - Coca-Cola Suspends Fairlife Production After Ransomware Attack
The Coca-Cola Company confirmed that a ransomware attack against its Fairlife dairy subsidiary has disrupted operations, forcing a temporary suspension of Fairlife product manufacturing across the United States. The beverage giant said it has not yet determined the full scope, nature, and impact of the incident, and it is working to restore systems while investigating the intrusion. The disruption illustrates how ransomware against a single subsidiary can halt physical production lines for a major consumer packaged goods manufacturer, raising supply chain concerns for retailers and distributors that depend on consistent dairy output. - New Windows LegacyHive Zero-Day Gives Hackers Admin Privileges
A security researcher using the handle “Nightmare Eclipse” publicly released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges to administrator level on fully patched Windows systems. Because the flaw affects up-to-date machines with no official fix yet available, security teams face an active exposure window with limited mitigation options. Privilege escalation vulnerabilities of this kind are especially dangerous when combined with initial-access malware, since they let attackers move from a foothold to full system control. Microsoft has not yet issued a patch. - HollowByte DDoS Flaw Bloats OpenSSL Server Memory
Researchers disclosed a denial-of-service vulnerability dubbed HollowByte that allows unauthenticated attackers to crash OpenSSL-based servers using a malicious payload of just 11 bytes. The flaw triggers excessive memory consumption on vulnerable servers, potentially taking critical services offline with minimal attacker effort or bandwidth. Given OpenSSL’s widespread use across web servers, VPNs, and enterprise applications, the low complexity required to trigger the crash makes this a high-priority patch for any organization running affected versions, particularly those exposing OpenSSL-dependent services directly to the internet. - Russian Hackers Trojanize WebEx And Zoom Apps
A financially motivated Russian threat actor tracked as UAT-11795 is distributing trojanized versions of WebEx and Zoom software to steal credentials and cryptocurrency through a newly identified backdoor called Starland RAT. Victims who download the tampered installers unknowingly grant attackers persistent access to their systems, enabling credential theft and further compromise. The campaign highlights the risk of trojanized software distribution targeting widely used collaboration tools, a technique that can bypass user suspicion because the applications appear to function normally after installation. - CISA Adds SonicWall And Microsoft AD FS Flaws To Exploited Catalog
Microsoft fixed RoguePlanet, a Defender privilege-escalation flaw tracked as CVE-2026-50656. The bug exploits a race condition in Microsoft Defender to spawn a command prompt with SYSTEM privileges, granting an attacker complete control of the local machine if the timing is right. The vulnerability was addressed through an update to the Microsoft Malware Protection Engine rather than a monthly Patch Tuesday bundle, so customers should ensure they run the latest engine version. The flaw surfaced in June when researcher Nightmare Eclipse published technical details and proof-of-concept code claiming it worked against fully patched Windows 10 and Windows 11 systems. - Cyberattack Disrupts Operations At Japanese Frozen Food Giant Nichirei
Nichirei, a major Japanese frozen food manufacturer, disconnected its systems on July 13 after detecting a cyberattack, and has since begun gradually restoring operations. The company has not disclosed the specific nature of the intrusion or whether ransomware was involved, but the shutdown of internal systems points to a disruptive incident affecting production or logistics. Attacks against food and beverage manufacturers continue to raise concerns about critical infrastructure resilience, given the operational and supply chain consequences when a major producer is forced offline. - PromptFiction Flaw Auto-Submitted Hidden Prompts In Claude Desktop
Security researchers at Oasis Security disclosed a vulnerability named PromptFiction affecting Anthropic’s Claude Desktop application, which exploited the app’s custom claude:// URL scheme. A single click on a crafted link could cause Claude Desktop to execute attacker-written instructions without prompting the user to review or approve the action, potentially allowing an attacker to direct the AI agent to access sensitive information or perform tasks through connected tools. The flaw underscores emerging risks tied to AI desktop agents and custom URL handlers, an increasingly relevant category of vulnerability as enterprises adopt agentic AI tools. - CISA Orders Feds To Patch Exploited Oracle Flaw
CISA directed federal agencies to secure their systems against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite financial application, setting a strict deadline for remediation. The flaw is being actively targeted in the wild, and Oracle E-Business Suite’s role in core financial operations for many government agencies and large enterprises raises the stakes of delayed patching. The order follows a pattern of aggressive exploitation against Oracle’s enterprise applications this year, reinforcing the need for organizations running E-Business Suite to treat this as an urgent priority. - Abbott Laboratories Probes Two Cyber Incidents Amid Extortion Claims
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems tied to its Cancer Diagnostics business. The healthcare and medical device maker is also examining a separate claim that attackers breached its LabCentral portal and stole company data. Extortion actors have surfaced claiming responsibility for the intrusions, though Abbott has not confirmed the scale of data taken. The dual incidents underscore the risk healthcare and diagnostics companies face from both legacy system exposure and third-party portal compromise.
Our Threat Operations and Intelligence team compiles a daily digest of the most recent online cybersecurity risks. The previous 10 stories were determined to be most significant during the course of the week, ranked by highest risk, and using multiple sources when available.