Cybersecurity Today is brought to you by NordLayer. Teams today work across multiple tools and devices, but security often remains fragmented. And this is exactly what NordLayer can help you address. NordLayer gives your company centralized control over access by individuals and teams and keeps connection secure from anywhere with no additional hardware required. Visit nordlayer.com slash cybersecurity today and use the discount code NLSUMMER26 for a special discount on your purchase. Microsoft's Serial Tormentor drops another zero day. A ransomware attack shuts down Coca-Cola's Fair Life milk lines. Abbott is fighting two breaches at once. Leaked ransomware chats reveal heartless attacks on healthcare. And a WordPress flaw that turns an anonymous web request into code execution. This is Cybersecurity Today, and I'm your host, David Shipley. Let's get started. Microsoft's most persistent tormentor is back. Nightmare Eclipse dropped another Windows Zero Day on Tuesday, and true to form, they timed it to land right after Microsoft shipped its monthly patches, maximizing the window before Redmond can write and distribute any fixes. This one's called Legacy Hive. It's a local privilege escalation flaw in the Windows User Profile Service, and it abuses the way Windows loads registry hives. Windows hives are the files on the disk that store the registry, the database Windows uses to hold configuration for the system, installed applications, and individual user profiles. Each user gets their own hive, holding their personal settings. In practice, a standard user can mount another user's hive, including an administrator's, into their own class's root. For an attacker who's already inside a network, that's quite useful. But it's not the haymaker Nightmare Eclipse promised. Back in June, they teased a quote bone-shattering end quote drop that would deliver full system compromise. What actually shipped is much more modest. Matei Badenow at Pentest Tools told the register the distance between the public proof of concept and a real full compromise is pretty wide. Bundling this with credential access and persistence into full compromise, he said, is more ambition than release code at this point. And this time the code is deliberately stripped back. There's no fully working proof of concept code shipping with this vulnerability. The public version needs extra credentials and only reaches one hive. Nightmare Eclipse says the original, the one that they say they held back, needs no credentials and goes further, but you'll need, in their words, some brain cells to get there. That restraint is a shift. Earlier drops like Blue Hammer and Red Sun went from proof of concept to widespread exploitation within days. And that prompted some pretty harsh words from Microsoft Cybersecurity experts believe capable actors will be able to reverse engineer the missing pieces and stand up weaponized versions of this vulnerability in short order Nightmare Eclipse claims Legacy Hive works against machines fully patched as of July. Microsoft says it's aware of the reports and is investigating the validity of the claims. This month's Patch Tuesday sets a record for Microsoft. Redmond shipped 570 fixes, according to Krebson Security. That's the largest single release the company has ever put out on a patch Tuesday. At least two of the vulnerabilities were zero days already under active exploitation. One in Windows Server that escalates a limited user straight to system administrator, and one in SharePoint that CISA flagged as being used in the wild to compromise organizations. Microsoft said last week the company is now using AI to hunt for vulnerability in its code, much of which dates back decades, and that as AI helps defenders surface more issues, customers should expect heavier patch loads every month. Coca-Cola has suspended U.S. production at its Fairlife Dairy Unit following a ransomware attack. The company disclosed the attack in a filing with the SEC late last week. Coca-Cola says it's still working to determine the full scope of the attack, but that the attack hadn't affected the quality or safety of Fairlife products. Fairlife makes ultra-filtered milk, protein shakes, and nutritional drinks. And Fairlife is no small piece of Coca-Cola's business. It crossed a billion dollars in annual retail sales back in 2022, and Coca-Cola committed $650 million in March to expand its Coopersville, Michigan facilities. No group has yet claimed responsibility for the attack, and researchers haven't tied it to a known crew. Law enforcement has been notified, and outside cybersecurity advisors are working to restore systems. Food and agricultural industries keep drawing more and more unhealthy cyber attention. The Food and Ag ISAC says the sector has absorbed roughly 205 attacks so far this year. They noted adversaries scan for exposed, vulnerable systems at machine speed and then sort out who the victim is only after they're already in and potentially causing damage. It's doubtful they'll care much about impacting human safety and well-being when it comes to major food and agricultural hacks. Massive healthcare and medical device maker Abbott Laboratories is juggling two separate breach investigations at the same time that don't appear to be connected. The first surfaced when the extortion gang Shiny Hunters added Abbott to its leak site, threatening to publish stolen data unless the company paid up. Abbott has confirmed unauthorized access to a limited number of internal legacy exact Sciences systems inside its cancer diagnostics business. The company says those legacy systems are separate from Abbott's own and that no other operations, products, or lab work were affected, and that it doesn expect a material financial hit from the hack Shiny Hunters claims it got through on a vishing attack on avid employees in mid compromising a Microsoft Entra single sign account and pivoting from there That's the same playbook the gang has run for over a year. Phish an SSO login, then drain connected apps like Salesforce, Microsoft 365, and Slack. In this case, Shiny Hunters claim to have taken more than 30 million rows of customer data, over a million social security numbers, and 22 million client notes containing doctor-patient conversations. Bleeping Computer hasn't verified any of these claims. The second incident involves a different actor calling itself Shadow Bites, which claims it breached Abbott's core laboratory business through the LabCentral customer portal using compromised credentials, then quietly pulled files through API endpoints starting July 4th. It says it grabbed manufacturing certificates, technical specs, and regulatory documentation. Abbott confirms it's aware of the potential incident, but disputes the characterization. A spokesperson says LabCentral is an externally facing portal holding publicly available product reference material, not sensitive or proprietary data. Neither group has published anything yet. Shiny Hunter's latest deadline lands on Tuesday. Abbott is the second major US-based medical device maker to be hit this year, though it doesn't look like, as of now, these attacks will disrupt the medical supply chain the way the striker attack did earlier this year. Jeff White's BBC Cyberhack podcast has been mining the Conti leaks, and the picture it paints of one of ransomware's biggest gangs is well worth a listen. Conti made an estimated $180 million in 2021 alone, hitting more than 1,000 organizations. Then, in early 2022, after the gang posted support for Russia's invasion of Ukraine, a member turned on them and leaked over 300,000 internal messages. The chats showed hackers arguing over targeting hospitals during the pandemic. One member wrote, quote, let them die, end quote, and wanted to hit hundreds of U.S. health care facilities, while the others insisted the medical sector was off limits. When Conti breached jeweler graph and leaked client data, they realized too late they'd exposed Gulf Royals and issued a rare public apology promising to scrub the leak. Conti's boss, known as Stern, was later identified by German police as Russian national Vitaly Kovalev. The BBC traced him through social media to a life of Bentleys, Louis Vuitton, and holidays at a resort where a villa runs £22,000 a week. White's books and podcasts dig deep into stories exactly like this one and are highly recommended summer reading or listening. There's a new WordPress vulnerability and what makes it dangerous is where it lives. This one's in the core. A bare install with zero plugins is exploitable. An anonymous HTTP request can run code on the site no login required It called WP2Shell and it actually two bugs chained together Adam Cues at AssetNote Searchlight Cyber attack surface arm found a confusion flaw in WordPress's batch rest routine and reported it through the HackerOne bug bounty program. Separately, three researchers, TF1T, Ditro, and Hango, reported a SQL injection in core. On their own, each vulnerability was fairly limited. Chained, they carry an anonymous request all the way to remote code execution. Both now have CVE IDs. The SQL injection reaches back to version 6.8, but the batch route bug, the half that turns a bounded injection into full unauthenticated RCE, only exists from version 6.9 onward, which shipped in December. WordPress says it patched the vulnerability Friday in 6.9.5 and 7.0.2 and pushed forced updates through the auto update system. Searchlight had held back its own technical write-up, but WordPress's core is open source and the release notes named the files that changed. Within a day, other researchers had read the patch, published the full mechanism, and put a working proof of concept on GitHub. There's one narrowing condition to this vulnerability. The code execution path only works when the site isn't running a persistent object cache like Redis or Memcached. Cloudflare shipped WAF rules alongside the disclosure and says sites behind its managed rules are covered. And that's Cybersecurity Today for Monday, July 20th. Thanks for listening. I've been your host, David Shipley, and I'll be back on Wednesday with the latest headlines. If you missed our show on Saturday, I did an interview about the last six months worth of AI cybersecurity issues, what it all means for CISOs, and how the browser is the new battleground for both humans and AI. We appreciate all of your feedback. Feel free to drop us a line at technewsday.com or .ca, or you can leave a comment under the YouTube video. Stay safe and stay secure. Once again, we'd like to thank NordLayer for their support in sponsoring this show. Teams today work across multiple tools and devices, but security often remains fragmented. This is exactly what NordLayer can help you address. It provides a network security platform with easy-to-manage network access monitoring and control, and without additional hardware or complex infrastructure. NordLayer helps businesses of all sizes manage and secure access to company resources going beyond what traditional VPNs can offer. And it provides encrypted connectivity with visibility across your entire network environment. And did we mention no new hardware required? Visit nordlayer.com slash cybersecurity today and use the code NLSUMMER26 for a special discount during their summer sale.