Cybersecurity Headlines

Fairlife dairy cyberattack, ACR Stealer surge, Abbott Labs incidents

8 min
Jul 20, 20269 days ago
Listen to Episode
Summary

This episode covers major cybersecurity incidents including a Fairlife dairy cyberattack, a surge in ACR Stealer malware attacks, Abbott Labs breach investigations, and critical vulnerabilities in FortiSandbox, WordPress, and SharePoint. Additional coverage includes an Ernst Young data breach, AI spam filter evasion techniques, and active exploitation of multiple zero-day vulnerabilities.

Insights
  • Supply chain attacks continue to impact major corporations; Fairlife (Coca-Cola subsidiary) production halted despite parent company assurances of product safety
  • Malware-as-a-service operations like ACR Stealer (rebranded Amatera) are proliferating with sophisticated intrusion chains using WebDAV and HTML application exploits
  • Critical vulnerabilities with CVSS 9+ scores in widely-used enterprise software (FortiSandbox, SharePoint, WordPress) are being actively exploited in the wild
  • Traditional text-salting techniques are defeating modern AI-powered email security, indicating need for layered defense strategies beyond keyword detection
  • Extortion gangs like Shiny Hunters are operating with public deadlines and data leak sites, creating time-pressured incident response scenarios for enterprises
Trends
Increased targeting of healthcare and pharmaceutical companies (Abbott Labs) by organized extortion groupsMalware-as-a-service rebranding and evolution (Amatera to ACR Stealer) enabling broader attack distributionZero-day exploitation acceleration in enterprise infrastructure (SharePoint, FortiSandbox, WordPress core)AI security evasion techniques using established methods (text salting, CSS cropping, zero-font tricks) bypassing modern defensesThird-party software supply chain vulnerabilities (Ernst Young support ticket system compromise) affecting downstream customersCISA KEV catalog additions accelerating as evidence of active exploitation increases across critical infrastructureUnauthenticated remote code execution vulnerabilities becoming more prevalent in core enterprise softwareSocial engineering click-fix tactics remaining effective despite security awareness training
Companies
Fairlife
Coca-Cola subsidiary suffered cyberattack on Thursday forcing temporary U.S. production halt; scope unknown, no ranso...
Coca-Cola
Parent company of Fairlife; emphasized product quality and safety unimpacted; Canadian operations unaffected by cyber...
Microsoft
Warned of surge in ACR Stealer malware attacks targeting enterprise customers to steal passwords, tokens, and sensiti...
Abbott Labs
Pharmaceutical giant investigating two separate cyber incidents including unauthorized access to cancer diagnostics s...
Ernst Young
Auditing firm disclosing data breach from compromised third-party support ticket system affecting client tax information
Fortinet
FortiSandbox critical vulnerabilities (CVSS 9) with OS command injection flaws now actively exploited; affects 40 San...
WordPress
WP2Shell vulnerability in core versions 6.9 and 7.0 allows unauthenticated remote code execution; patched with forced...
Searchlight Cyber
AssetNote (attack surface management arm) discovered WP2Shell WordPress core vulnerability affecting bare installations
Barracuda
Cybersecurity firm identified text-salting techniques defeating AI-powered spam filters; recommends layered email sec...
CISA
Added FortiSandbox and SharePoint vulnerabilities to Known Exploited Vulnerabilities catalog; set federal agency upda...
People
Steve Prentiss
Hosted and reported the cybersecurity headlines episode covering major incidents and vulnerabilities
Quotes
"support tickets submitted through the platform may have included documents containing client tax information"
Ernst Young (quoted statement)Ernst Young breach segment
"an anonymous HTTP request can run code on a WordPress site"
AssetNote/Searchlight Cyber researchersWP2Shell vulnerability segment
"an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component"
Microsoft (SharePoint RCE description)SharePoint vulnerability segment
"fool an AI email scanning system into thinking the message is benign, something most human readers would latch onto"
Barracuda (text salting technique)AI spam filter evasion segment
Full Transcript
From the CISO series, it's Cybersecurity Headlines. These are the Cybersecurity Headlines for Monday, July 20th, 2026. I'm Steve Prentiss. Dairy company Fairlife suffers cyberattack. The company, a subsidiary of Coca-Cola, has been forced to temporarily halt production in the U.S. The intrusion occurred on Thursday and the full scope of the incident isn't yet known. Coca-Cola emphasized that product quality and safety had not been impacted and Fairlife's operations in Canada have not been affected. No mention of a ransomware group or any information about a breach has yet been made. Microsoft warns of surge in ACR Steeler attacks on customers. The observed surge in attacks using the ACR Steeler malware to steal browsers, stored passwords, authentication tokens, and sensitive documents from its enterprise customers appears to be yet another incident of click-fix social engineering. ACR Steeler is a malware-as-a-service operation believed to be a rebranding of the Amatera Steeler malware. This current alert highlights two different intrusion chains, one that executes a command to run a malicious DLL from a remote webdav share, and another that exploits Microsoft HTML application host. Abbott Labs investigates two cyber incidents amidst extortion claims. The pharmaceuticals giant is looking into two separate incidents One after, quote, confirming unauthorized access to internal legacy exact sciences systems In its cancer diagnostics business, end quote The other a separate claim that attackers breached its lab central portal and stole company data The shiny hunters extortion gang has already added Abbott to its data leak site and it has set a deadline of July 21st Ernst Young discloses data breach after support system intrusion The auditing and professional services provider is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. The company says, quote, support tickets submitted through the platform may have included documents containing client tax information, end quote. This announcement refers to anomalous activity detected on its networks on April 23rd. Investigations show that an unauthorized third party accessed the platform between March 28th and April 12th and downloaded multiple documents, which included personal and financial data used to prepare tax filings. The company has not shared the number of customers affected or the countries impacted. No ransomware or extortion groups have yet taken responsibility for the attack. Its decision engine evaluates the content, context and intent of every action before it completes. Alerts tell you later. Quiller AI decides now. Visit Quiller AI, that is Q-U-I-L-R dot A-I. Stay safe. Quiller it. 40 sandbox flaws now under active attack. Following up on a story we covered in June, a pair of critical FortiSandbox bugs are now confirmed as being actively exploited. Both of these bugs carry CVSS scores of 9 and affect 40 Sandbox 40 Sandbox Cloud and 40 Sandbox Platform as a Service They are OS command injection flaws that allow unauthenticated attackers to execute arbitrary commands via specially crafted HTTP requests, requiring neither valid credentials nor user interaction. The fact that CISA has now added both bugs to its KEV catalog means that the agency has evidence that the vulnerabilities are being actively exploited. New WP2 shell WordPress core flaw lets unauthenticated attackers run code. According to researchers at AssetNote, the attack surface management arm of Searchlight Cyber, quote, an anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. It has no preconditions and can be exploited by an anonymous user. Named WP2Shell, that is WP, the number 2, and then Shell, it is actually two bugs, each with CVE numbers. Every WordPress site based on versions 6.9 and 7.0 was a target, up until last Friday, at which point WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system. CISA adds SharePoint RCE Zero Day to KEV Catalog. This newly patched security flaw impacts Microsoft's SharePoint server. It has a score of 9.8 and is described as a critical deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute arbitrary code. Microsoft noted that the vulnerability is remotely exploitable over the internet and that an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component The flaw was entered into the KEV catalog last Thursday and federal agencies had until yesterday, Sunday, to update their instances to the latest supported versions. AI spam filters are getting fooled by old-fashioned text assaulting. According to the cybersecurity firm Barracuda, attackers are using a long-established technique known as text salting to enable phishing emails and spam to elude new AI-powered spam filters. The technique involves adding random, harmless-seeming words into the body of the message to, quote, fool an AI email scanning system into thinking the message is benign, something most human readers would latch onto, end quote. Techniques also used include CSS cropping, which sets the visible window small enough that a human won't see the hidden filler text, as well as zero font techniques to make these misleading words visible to the scanning software but not to a human reader. To counter this, Barracuda recommends a layered approach to email security rather than relying solely on keyword detection. This includes checking sender reputation, authentication results, embedded URLs, HTML rendering techniques, and differences between user-visible and hidden content. End quote. If you have some thoughts on the news from today or about this show in general, please be sure to reach out to us at feedback at CISOseries.com. We would love to hear from you. I'm Steve Prentice, reporting for the CISO Series. cybersecurity headlines are available every weekday. Head to CISOseries.com for the full stories behind the headlines.