⚠️ Region Alert: UAE/Middle East
This week's cyber research highlights significant security events and emerging threats. Ernst & Young is investigating a data breach involving a compromised third-party IT support platform that may have exposed sensitive client and employee information. Jscrambler experienced a supply chain attack where stolen npm credentials led to malicious releases of their JavaScript code-protection package, distributing malware that targeted various credentials.
Fairlife, Coca-Cola's US dairy subsidiary, confirmed a ransomware attack that halted production, while Japan's largest taxi operator, Nihon Kotsu, suffered a malware attack disrupting services. In the realm of AI threats, researchers observed China-linked campaigns using AI tools like Claude Code and DeepSeek to automate attacks against government and financial organizations. Additionally, a vulnerability in xAI's Grok Build could expose Git repositories, and a flaw in the Claude for Chrome extension allowed rogue extensions to access user Gmail accounts.
Microsoft released a record-breaking 622 patches for July's Patch Tuesday, including two actively exploited vulnerabilities in SharePoint Server and Active Directory Federation Services. WordPress issued emergency updates for critical 'wp2shell' vulnerabilities, and SonicWall released a hotfix for zero-day flaws in their SMA 1000 Series gateways, associated with Inc ransomware. Check Point Research also released its 2026 AI Security Report, noting AI's evolution into an active operator in cyber intrusions, with a doubling of high-risk GenAI prompts.
Top comments (0)