Cybersecurity Today

Wordpress RCE, New Windows 0-day and Coca-Cola's Fairline ransomed

13 min
Jul 20, 20269 days ago
Listen to Episode
Summary

This episode covers critical vulnerabilities across major platforms: Microsoft's Windows zero-day from Nightmare Eclipse, a WordPress core RCE affecting unauthenticated users, and significant ransomware attacks on Coca-Cola's Fairlife dairy unit and Abbott Laboratories. The episode highlights how attackers are timing exploits strategically and targeting essential infrastructure sectors.

Insights
  • Threat actors are deliberately timing zero-day releases immediately after Microsoft patches to maximize exploitation windows before fixes are available
  • Chaining multiple vulnerabilities together can escalate limited bugs into critical unauthenticated remote code execution, as demonstrated by WordPress WP2Shell
  • Food and agricultural sectors are increasingly targeted by ransomware gangs using automated scanning rather than targeted reconnaissance, creating indiscriminate damage risks
  • Leaked ransomware communications reveal internal disagreements about targeting healthcare, suggesting some operational constraints exist within criminal organizations
  • Open-source software patches create disclosure risks when release notes expose changed files, enabling rapid reverse-engineering of vulnerabilities
Trends
Coordinated timing of zero-day releases to maximize exploitation window after monthly patchesIncreased targeting of critical infrastructure sectors (food, agriculture, healthcare, medical devices)Vulnerability chaining as primary attack vector for achieving unauthenticated code executionAutomated, indiscriminate scanning of critical sectors followed by opportunistic targetingAI-assisted vulnerability discovery increasing patch volume and frequency across major platformsVishing attacks targeting SSO credentials as primary entry point for enterprise breachesRansomware gangs operating with internal ethical debates about targeting healthcareOpen-source software creating rapid vulnerability disclosure risks post-patchingRansomware extortion gangs maintaining leak sites with published deadlines for paymentMedical device sector becoming high-value target for ransomware operations
Companies
Microsoft
Released record 570 patches on Patch Tuesday; targeted by Nightmare Eclipse with Windows zero-day Legacy Hive vulnera...
Coca-Cola
Fairlife dairy unit suspended U.S. production following ransomware attack; Fairlife generates over $1B in annual reta...
Abbott Laboratories
Facing two simultaneous unrelated breaches: Shiny Hunters targeting legacy cancer diagnostics systems and Shadow Bite...
WordPress
Patched critical WP2Shell vulnerability in core affecting unauthenticated users; released forced updates via auto-upd...
Cloudflare
Shipped WAF rules alongside WordPress vulnerability disclosure to protect sites behind managed rules
Shiny Hunters
Ransomware extortion gang using vishing attacks on SSO credentials; claims 30M+ rows of Abbott customer data and 1M+ ...
Shadow Bites
Ransomware group claiming breach of Abbott's LabCentral portal via compromised credentials starting July 4th
Conti
Defunct ransomware gang that made $180M in 2021; leaked internal chats reveal debates about targeting healthcare faci...
Nightmare Eclipse
Threat actor group releasing Windows zero-days strategically timed after Microsoft patches; released Legacy Hive vuln...
CISA
Flagged SharePoint vulnerability as being actively exploited in the wild to compromise organizations
People
David Shipley
Host of the Cybersecurity Today podcast episode
Matei Badenow
Analyzed Legacy Hive zero-day, noting gap between PoC and full system compromise
Jeff White
Analyzed Conti ransomware gang leaks revealing internal ethical debates about targeting healthcare
Adam Cues
Discovered confusion flaw in WordPress batch REST routine reported through HackerOne
Vitaly Kovalev
Identified by German police as Conti boss 'Stern'; traced through social media to luxury lifestyle
Quotes
"bone-shattering end drop that would deliver full system compromise"
Nightmare EclipseEarly segment
"the distance between the public proof of concept and a real full compromise is pretty wide"
Matei BadenowMicrosoft zero-day segment
"let them die"
Conti gang memberRansomware chats segment
"adversaries scan for exposed, vulnerable systems at machine speed and then sort out who the victim is only after they're already in"
Food and Ag ISACFood sector attacks segment
"some brain cells to get there"
Nightmare EclipseLegacy Hive vulnerability segment
Full Transcript
Cybersecurity Today is brought to you by NordLayer. Teams today work across multiple tools and devices, but security often remains fragmented. And this is exactly what NordLayer can help you address. NordLayer gives your company centralized control over access by individuals and teams and keeps connection secure from anywhere with no additional hardware required. Visit nordlayer.com slash cybersecurity today and use the discount code NLSUMMER26 for a special discount on your purchase. Microsoft's Serial Tormentor drops another zero day. A ransomware attack shuts down Coca-Cola's Fair Life milk lines. Abbott is fighting two breaches at once. Leaked ransomware chats reveal heartless attacks on healthcare. And a WordPress flaw that turns an anonymous web request into code execution. This is Cybersecurity Today, and I'm your host, David Shipley. Let's get started. Microsoft's most persistent tormentor is back. Nightmare Eclipse dropped another Windows Zero Day on Tuesday, and true to form, they timed it to land right after Microsoft shipped its monthly patches, maximizing the window before Redmond can write and distribute any fixes. This one's called Legacy Hive. It's a local privilege escalation flaw in the Windows User Profile Service, and it abuses the way Windows loads registry hives. Windows hives are the files on the disk that store the registry, the database Windows uses to hold configuration for the system, installed applications, and individual user profiles. Each user gets their own hive, holding their personal settings. In practice, a standard user can mount another user's hive, including an administrator's, into their own class's root. For an attacker who's already inside a network, that's quite useful. But it's not the haymaker Nightmare Eclipse promised. Back in June, they teased a quote bone-shattering end quote drop that would deliver full system compromise. What actually shipped is much more modest. Matei Badenow at Pentest Tools told the register the distance between the public proof of concept and a real full compromise is pretty wide. Bundling this with credential access and persistence into full compromise, he said, is more ambition than release code at this point. And this time the code is deliberately stripped back. There's no fully working proof of concept code shipping with this vulnerability. The public version needs extra credentials and only reaches one hive. Nightmare Eclipse says the original, the one that they say they held back, needs no credentials and goes further, but you'll need, in their words, some brain cells to get there. That restraint is a shift. Earlier drops like Blue Hammer and Red Sun went from proof of concept to widespread exploitation within days. And that prompted some pretty harsh words from Microsoft Cybersecurity experts believe capable actors will be able to reverse engineer the missing pieces and stand up weaponized versions of this vulnerability in short order Nightmare Eclipse claims Legacy Hive works against machines fully patched as of July. Microsoft says it's aware of the reports and is investigating the validity of the claims. This month's Patch Tuesday sets a record for Microsoft. Redmond shipped 570 fixes, according to Krebson Security. That's the largest single release the company has ever put out on a patch Tuesday. At least two of the vulnerabilities were zero days already under active exploitation. One in Windows Server that escalates a limited user straight to system administrator, and one in SharePoint that CISA flagged as being used in the wild to compromise organizations. Microsoft said last week the company is now using AI to hunt for vulnerability in its code, much of which dates back decades, and that as AI helps defenders surface more issues, customers should expect heavier patch loads every month. Coca-Cola has suspended U.S. production at its Fairlife Dairy Unit following a ransomware attack. The company disclosed the attack in a filing with the SEC late last week. Coca-Cola says it's still working to determine the full scope of the attack, but that the attack hadn't affected the quality or safety of Fairlife products. Fairlife makes ultra-filtered milk, protein shakes, and nutritional drinks. And Fairlife is no small piece of Coca-Cola's business. It crossed a billion dollars in annual retail sales back in 2022, and Coca-Cola committed $650 million in March to expand its Coopersville, Michigan facilities. No group has yet claimed responsibility for the attack, and researchers haven't tied it to a known crew. Law enforcement has been notified, and outside cybersecurity advisors are working to restore systems. Food and agricultural industries keep drawing more and more unhealthy cyber attention. The Food and Ag ISAC says the sector has absorbed roughly 205 attacks so far this year. They noted adversaries scan for exposed, vulnerable systems at machine speed and then sort out who the victim is only after they're already in and potentially causing damage. It's doubtful they'll care much about impacting human safety and well-being when it comes to major food and agricultural hacks. Massive healthcare and medical device maker Abbott Laboratories is juggling two separate breach investigations at the same time that don't appear to be connected. The first surfaced when the extortion gang Shiny Hunters added Abbott to its leak site, threatening to publish stolen data unless the company paid up. Abbott has confirmed unauthorized access to a limited number of internal legacy exact Sciences systems inside its cancer diagnostics business. The company says those legacy systems are separate from Abbott's own and that no other operations, products, or lab work were affected, and that it doesn expect a material financial hit from the hack Shiny Hunters claims it got through on a vishing attack on avid employees in mid compromising a Microsoft Entra single sign account and pivoting from there That's the same playbook the gang has run for over a year. Phish an SSO login, then drain connected apps like Salesforce, Microsoft 365, and Slack. In this case, Shiny Hunters claim to have taken more than 30 million rows of customer data, over a million social security numbers, and 22 million client notes containing doctor-patient conversations. Bleeping Computer hasn't verified any of these claims. The second incident involves a different actor calling itself Shadow Bites, which claims it breached Abbott's core laboratory business through the LabCentral customer portal using compromised credentials, then quietly pulled files through API endpoints starting July 4th. It says it grabbed manufacturing certificates, technical specs, and regulatory documentation. Abbott confirms it's aware of the potential incident, but disputes the characterization. A spokesperson says LabCentral is an externally facing portal holding publicly available product reference material, not sensitive or proprietary data. Neither group has published anything yet. Shiny Hunter's latest deadline lands on Tuesday. Abbott is the second major US-based medical device maker to be hit this year, though it doesn't look like, as of now, these attacks will disrupt the medical supply chain the way the striker attack did earlier this year. Jeff White's BBC Cyberhack podcast has been mining the Conti leaks, and the picture it paints of one of ransomware's biggest gangs is well worth a listen. Conti made an estimated $180 million in 2021 alone, hitting more than 1,000 organizations. Then, in early 2022, after the gang posted support for Russia's invasion of Ukraine, a member turned on them and leaked over 300,000 internal messages. The chats showed hackers arguing over targeting hospitals during the pandemic. One member wrote, quote, let them die, end quote, and wanted to hit hundreds of U.S. health care facilities, while the others insisted the medical sector was off limits. When Conti breached jeweler graph and leaked client data, they realized too late they'd exposed Gulf Royals and issued a rare public apology promising to scrub the leak. Conti's boss, known as Stern, was later identified by German police as Russian national Vitaly Kovalev. The BBC traced him through social media to a life of Bentleys, Louis Vuitton, and holidays at a resort where a villa runs £22,000 a week. White's books and podcasts dig deep into stories exactly like this one and are highly recommended summer reading or listening. There's a new WordPress vulnerability and what makes it dangerous is where it lives. This one's in the core. A bare install with zero plugins is exploitable. An anonymous HTTP request can run code on the site no login required It called WP2Shell and it actually two bugs chained together Adam Cues at AssetNote Searchlight Cyber attack surface arm found a confusion flaw in WordPress's batch rest routine and reported it through the HackerOne bug bounty program. Separately, three researchers, TF1T, Ditro, and Hango, reported a SQL injection in core. On their own, each vulnerability was fairly limited. Chained, they carry an anonymous request all the way to remote code execution. Both now have CVE IDs. The SQL injection reaches back to version 6.8, but the batch route bug, the half that turns a bounded injection into full unauthenticated RCE, only exists from version 6.9 onward, which shipped in December. WordPress says it patched the vulnerability Friday in 6.9.5 and 7.0.2 and pushed forced updates through the auto update system. Searchlight had held back its own technical write-up, but WordPress's core is open source and the release notes named the files that changed. Within a day, other researchers had read the patch, published the full mechanism, and put a working proof of concept on GitHub. There's one narrowing condition to this vulnerability. The code execution path only works when the site isn't running a persistent object cache like Redis or Memcached. Cloudflare shipped WAF rules alongside the disclosure and says sites behind its managed rules are covered. And that's Cybersecurity Today for Monday, July 20th. Thanks for listening. I've been your host, David Shipley, and I'll be back on Wednesday with the latest headlines. If you missed our show on Saturday, I did an interview about the last six months worth of AI cybersecurity issues, what it all means for CISOs, and how the browser is the new battleground for both humans and AI. We appreciate all of your feedback. Feel free to drop us a line at technewsday.com or .ca, or you can leave a comment under the YouTube video. Stay safe and stay secure. Once again, we'd like to thank NordLayer for their support in sponsoring this show. Teams today work across multiple tools and devices, but security often remains fragmented. This is exactly what NordLayer can help you address. It provides a network security platform with easy-to-manage network access monitoring and control, and without additional hardware or complex infrastructure. NordLayer helps businesses of all sizes manage and secure access to company resources going beyond what traditional VPNs can offer. And it provides encrypted connectivity with visibility across your entire network environment. And did we mention no new hardware required? Visit nordlayer.com slash cybersecurity today and use the code NLSUMMER26 for a special discount during their summer sale.