View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Anubis ransomware hits Coca-Cola's Fairlife, threatens 1TB data leak

💥 BREACHES & INCIDENTS

  • Anubis ransomware claims attack on Coca-Cola's Fairlife, threatens data leak — bleepingcomputer.com
    Anubis ransomware gang attacked Coca-Cola's Fairlife dairy subsidiary, disrupting operations and encrypting Nutanix infrastructure.
    • Targets Coca-Cola's Fairlife dairy subsidiary operating US production facilities
    • Attack disrupted operations and encrypted Nutanix infrastructure
    • Ransomware gang claims to have stolen about 1 TB of corporate data
    • Threatens to publish stolen data unless ransom negotiations begin
    • Anubis ransomware active since Dec 2024, uses data theft and encryption

🕵️ RESEARCH & DEEP DIVES

  • CrowdStrike details SANDWORM_MODE AI toolchain supply chain attacks targeting CI/CD pipelines — CrowdStrike Blog
    CrowdStrike uncovered SANDWORM_MODE, a multi-stage AI toolchain supply chain attack on npm packages targeting AI-augmented CI/CD pipelines.

    • Targets AI-augmented development workflows in modern CI/CD pipelines using AI coding assistants and LLM toolchains
    • Involves 19 malicious npm packages published under two aliases, exploiting runtime behaviors rather than static build outputs
    • Attack evades detection by mimicking legitimate operations within AI-driven CI automation environments
    • Detection engineering efforts developed indicators of attack now protecting CrowdStrike customers
  • WP2Shell: Pre-Authentication RCE in WordPress Core Affects Version 7.0.1 — learn.uphack.io
    A pre-authentication remote code execution vulnerability affects WordPress core version 7.0.1 via a read-only SQL injection combined with WordPress features.

    • Vulnerabilities identified as CVE-2026-63030 and CVE-2026-60137
    • Exploitation chain involves a read-only SQL injection combined with WordPress features to achieve code execution
    • Attack requires no authentication and leverages legitimate WordPress internals

📌 LESSER-KNOWN / UNDER-REPORTED

  • NJ software bug wrongly registered 6,600 non-citizens to vote, 400 voted — nj.gov
    A software bug in New Jersey's motor vehicle system mistakenly registered approximately 6,600 non-citizens to vote, with around 400 casting ballots.
    • Bug ignored users' 'no' responses to U.S. citizenship question during license/ID applications
    • Issue discovered under previous administration; current governor ordered investigation and voter roll cleanup

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check