20th July – Threat Intelligence Report
This week saw multiple major cybersecurity incidents and patches. Ernst & Young disclosed a data breach via a compromised third-party IT support platform, potentially exposing sensitive client and employee data. Jscrambler suffered a supply chain attack where stolen credentials led to the distribution of malicious npm packages. Meanwhile, Coca-Cola's subsidiary Fairlife confirmed a ransomware attack that disrupted U.S. dairy production. In terms of vulnerabilities, Microsoft addressed 622 flaws in its largest-ever Patch Tuesday update, including two actively exploited issues (CVE-2026-56164 and CVE-2026-56155). WordPress issued emergency fixes for two critical RCE flaws (CVE-2026-63030 and CVE-2026-60137), while SonicWall released hotfixes for two zero-day vulnerabilities (CVE-2026-15409 and CVE-2026-15410) being exploited by ransomware groups.
For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
- Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, employee details, and other sensitive information submitted while requesting technical assistance.
- Jscrambler, a JavaScript code-protection package with more than 15,000 weekly downloads, has experienced a supply chain compromise after stolen npm publishing credentials distributed malicious releases. The packages deployed malware targeting developers’, cloud, browser, cryptocurrency, and messaging credentials. Jscrambler removed the affected versions.
- Coca-Cola’s US dairy subsidiary Fairlife has confirmed a ransomware attack that temporarily halted production across the United States. Attackers accessed systems supporting manufacturing operations, prompting the company to activate incident response and business continuity procedures. Coca-Cola has not confirmed whether data was exfiltrated in the attack.
- Nihon Kotsu, Japan’s largest taxi operator, has suffered a malware attack following unauthorized access to its internal network. The company shut down affected systems, disrupting taxi dispatches, telephone services, bookings, reservations, and car rentals from July 11. No theft of customer or corporate information has been confirmed.…