
Loading summary
Host
From the CISO series, it's Cybersecurity Headlines
Steve Prentiss
these are the cybersecurity headlines for Monday, July 20, 2026. I'm Steve Prentiss. Dairy company Fairlife suffers cyberattack the company, a subsidiary of Coca Cola, has been
News Reporter
forced to temporarily halt production in the
Steve Prentiss
US the intrusion occurred on Thursday and
News Reporter
the full scope of the incident isn't yet known. Coca Cola emphasized that product quality and safety had not been impacted and Fairlife's
Steve Prentiss
operations in Canada have not been affected.
News Reporter
No mention of a ransomware group or any information about a breach has yet been made. Microsoft warns of surge in ACR Stealer
Steve Prentiss
attacks on Customers the observed surge in attacks using the ACR Stealer malware to
News Reporter
steal browser stored passwords, authentication tokens and sensitive documents from its enterprise customers appears to be yet another incident of click fix social engineering. ACR Stealer is a malware is a
Steve Prentiss
service operation believed to be a rebranding
News Reporter
of the Amatera Stealer malware. This current alert highlights two different intrusion chains, one that executes a command to run a malicious DLL from a remote webdav share and another that exploits Microsoft HTML application host Abbott Labs investigates two
Steve Prentiss
cyber incidents amidst extortion claims the pharmaceuticals
News Reporter
giant is looking into two separate incidents, one after confirming unauthorized access to internal legacy Exact Sciences systems in its cancer diagnostics business, end quote. The other a separate claim that attackers breached its lab central portal and stole company data. The Shiny Hunters extortion gang has already added Abbott to its data leak site and it has set a deadline of July 21st. Ernst and Young discloses data breach after
Steve Prentiss
support system Intrusion the auditing and professional
News Reporter
services provider is notifying customers of a data breach caused by the compromise of a third party support ticket system used by its IT personnel. The company says support tickets submitted through the platform may have included documents containing client tax information. This announcement refers to anomalous activity detected on ITS networks on April 23. Investigations show that an unauthorized third party accessed the platform between March 28 and April 12 and downloaded multiple documents, which included personal and financial data used to prepare tax filings. The company has not shared the number of customers affected or the countries impacted. No ransomware or extortion groups have yet
Steve Prentiss
taken responsibility for the attack.
News Reporter
Huge thanks to our sponsor, Quiller AI. AI agents don't ask permission, they act, moving data, triggering workflows, changing systems. Quiller AI is the permission layer they never had. Its decision engine evaluates the content, context and intent of every action before it completes alerts. Tell you later. Quiller AI decides now visit quillerai that is q u I l r AI
Steve Prentiss
stay safe quiller it
News Reporter
40 sandbox floors
Steve Prentiss
now under active attack following up on
News Reporter
a story we covered in June, a pair of critical fortisandbox bugs are now
Steve Prentiss
confirmed as being actively exploited.
News Reporter
Both of these bugs carry CVSS scores of 9.1 and affect 40 sandbox, 40 sandbox cloud and 40 sandbox platform as a service. They are OS command injection flaws that allow unauthenticated attackers to execute arbitrary commands via specially crafted HTTP requests requiring neither valid credentials nor user interaction. The fact that CISA has now added both bugs to its Kev catalog means that the agency has evidence that the
Steve Prentiss
vulnerabilities are being actively exploited.
News Reporter
New WP2 shell WordPress core flaw lets unauthenticated attackers run code According to researchers at Asset Note, the Attack Surface management arm of Searchlight Cyber, an anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. It has no preconditions and can be exploited by an Anonymous user named wp2shell that is wp the number 2 and then shell it is actually two bugs, each with CVE numbers. Every WordPress site based on versions 6.9 and 7.0 was a target up until last Friday, at which point WordPress shipped 6 and 7.0.2 and enabled what it
Steve Prentiss
calls forced updates through its Auto update system.
News Reporter
CISA adds SharePoint RCE Zero Day to
Steve Prentiss
kev catalog this newly patched security flaw
News Reporter
impacts Microsoft's SharePoint server. It has a score of 9.8 and is described as a critical deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute arbitrary code, end quote. Microsoft noted that the vulnerability is remotely exploitable over the Internet and that an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component. The flaw was entered into the Kev catalog last Thursday, and federal agencies had until yesterday Sunday to update their instances
Steve Prentiss
to the latest supported versions.
News Reporter
AI spam filters are getting fooled by
Steve Prentiss
old fashioned text salting According to the
News Reporter
cybersecurity firm Barracuda, attackers are using a long established technique known as text salting to enable phishing, emails and spam to elude new AI powered spam filters. The technique involves adding random, harmless seeming words into the body of the message to fool an AI email scanning system into thinking the message is benign, something most human readers would latch onto. Techniques also used include CSS cropping, which sets the visible window small enough that a human won't see the hidden filler text as well as zero font techniques to make these misleading words visible to the scanning software, but not to a human reader. To counter this, Barracuda recommends a layered approach to email security. Rather than relying solely on keyword detection, this includes checking sender reputation authentication results, embedded URLs, HTML rendering techniques, and differences between user visible and hidden content. If you have some thoughts on the news from today, or about this show in general, please be sure to reach out to us@feedbackisoseries.com we would love to hear from you.
Steve Prentiss
Steve I'm Steve Prentiss, reporting for the CISO series.
Host
Cybersecurity headlines are available every weekday. Head to CISoseries.com for the full stories behind the headlines.
Host: Steve Prentiss, CISO Series
Episode Focus: Fairlife Dairy Cyberattack, ACR Stealer Surge, Abbott Labs Incidents, and Other Major Security Stories
This episode delivers a concise roundup of the day’s most notable cybersecurity events, ranging from impactful data breaches at major corporations to critical vulnerabilities exploited in the wild. Hosted by Steve Prentiss, the episode emphasizes recent attacks impacting the food, healthcare, and finance sectors, malware trends, and evolving technical vulnerabilities affecting global enterprises.
[00:06–00:41]
“The full scope of the incident isn't yet known... No mention of a ransomware group or any information about a breach has yet been made.”
(Steve Prentiss, 00:29–00:41)
[00:50–01:17]
“The observed surge in attacks... to steal browser stored passwords, authentication tokens, and sensitive documents from its enterprise customers...”
(Steve Prentiss, 00:50–00:57)
[01:31–02:07]
“The Shiny Hunters extortion gang has already added Abbott to its data leak site and it has set a deadline of July 21st.”
(News Reporter, 01:36–02:07)
[02:07–02:57]
“Support tickets submitted through the platform may have included documents containing client tax information.”
(News Reporter, 02:11–02:23)
[03:43–04:25]
“They are OS command injection flaws that allow unauthenticated attackers to execute arbitrary commands via specially crafted HTTP requests requiring neither valid credentials nor user interaction.”
(News Reporter, 03:55–04:13)
[04:30–05:22]
“A bare install with zero plugins is exploitable... It has no preconditions and can be exploited by an anonymous user.”
(News Reporter, 04:35–05:04)
[05:27–06:13]
“Microsoft noted that the vulnerability is remotely exploitable over the Internet and that an attacker does not require significant prior knowledge of the system.”
(News Reporter, 05:35–05:53)
[06:17–07:39]
“Attackers are using a long established technique known as text salting to enable phishing emails and spam to elude new AI powered spam filters.”
(News Reporter, 06:23–06:34)
As a rapid-fire headline briefing, the tone stays factual, succinct, and focused on actionable intelligence for security professionals. The delivery underscores urgency and the need for ongoing vigilance against emerging threats.
For more in-depth coverage, visit CISOseries.com.