Current Threat
Landscape

Active threats, critical vulnerabilities, and emerging attack patterns -- monitored continuously and summarized for security practitioners and business leaders.

LIVE FEED
UPDATED: July 27, 2026 at 7:01 PM
THREATS: 7
The past 24 to 48 hours have brought several significant developments that security teams must act on immediately. Most urgently, Coca-Cola confirmed today that the Anubis ransomware attack on its Fairlife dairy subsidiary resulted in a confirmed data breach, with the threat group claiming to hold 1 TB of exfiltrated data and a ransom deadline that expired this morning. Separately, ShinyHunters surfaced today claiming credit for the Ernst and Young breach via a supply-chain attack, alleging access to EY's Jira, GitHub, and Azure environments and threatening to release stolen client tax data by July 31. Both events reinforce that ransomware and extortion actors are accelerating pressure timelines, giving security teams very little runway to respond before data is weaponized publicly. On the vulnerability front, the unpatched Fastjson 1.x RCE flaw (CVE-2026-16723, CVSS 9.0) continues to see active exploitation with no patch available from Alibaba as of today. Imperva and ThreatBook have both confirmed in-the-wild attacks targeting financial services, healthcare, and retail organizations running Spring Boot fat-JAR deployments. If your Java environment inventory has not been checked for Fastjson 1.2.68 through 1.2.83 with SafeMode disabled, that audit should begin immediately. Additionally, the Clop ransomware gang's ongoing campaign against PTC Windchill and FlexPLM (CVE-2026-12569, CVSS 9.8) is actively extracting engineering and product lifecycle data from manufacturing, aerospace, and automotive sector victims, with extortion emails now being distributed at scale to compromised organizations. At the macro level, this week's threat landscape is defined by three converging trends every CISO should brief their board on: AI-accelerated vulnerability discovery is dramatically expanding patch volume, with Microsoft's record 570-flaw Patch Tuesday and Oracle's 1,449-patch quarterly update both attributed in part to AI-assisted research; ransomware operators are integrating AI automation into attack pipelines, as evidenced by the JadePuffer LLM-driven ransomware campaign; and supply-chain attacks through third-party SaaS and IT service management platforms are emerging as the preferred initial access vector for sophisticated extortion groups. Boards should expect these trends to intensify, not abate, through the remainder of 2026.
FILTER:
CRITICAL
CVE-2026-12569: Clop Ransomware Actively Exploiting PTC Windchill and FlexPLM RCE
The Clop ransomware group is actively exploiting CVE-2026-12569, a critical unsafe deserialization vulnerability (CVSS 9.8) in PTC Windchill PDMLink and FlexPLM, enabling unauthenticated remote code execution and deployment of persistent JSP web shells. Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with the RCE to exfiltrate engineering, design, and product lifecycle data before initiating double-extortion campaigns. CISA added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch; German authorities (BSI) have also conducted emergency outreach to PTC customers overnight.
AFFECTS: PTC Windchill PDMLink and FlexPLM prior to release 11.0 M030; over 30,000 organizations in manufacturing, aerospace, defense, automotive, retail, and medical technology sectors SOURCE: BleepingComputer 2026-07-24
Ransomware
CRITICAL
CVE-2026-16723: Fastjson 1.x Zero-Day RCE Under Active Exploitation with No Patch Available
A critical remote code execution vulnerability (CVSS 9.0) in Alibaba's Fastjson library affects all versions 1.2.68 through 1.2.83 running in Spring Boot fat-JAR deployments with SafeMode disabled, which is the default configuration. An unauthenticated attacker can send a specially crafted JSON payload to execute arbitrary code with the privileges of the Java process, requiring no AutoType enablement and no classpath gadgets. As of July 25, 2026, Alibaba has not released a patched 1.x version; ThreatBook and Imperva have both confirmed active in-the-wild exploitation targeting financial services, healthcare, and retail organizations primarily in the United States.
AFFECTS: Java applications using Fastjson versions 1.2.68 to 1.2.83 in Spring Boot fat-JAR deployments; financial services, healthcare, computing, and retail sectors SOURCE: SecurityWeek 2026-07-25
Vulnerability
CRITICAL
CVE-2026-15409 / CVE-2026-15410: SonicWall SMA1000 Zero-Days Exploited by INC Ransomware for Root Access
Two chained zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 Series appliances, including a CVSS 10.0 unauthenticated SSRF (CVE-2026-15409) and a code injection privilege escalation (CVE-2026-15410), have been under active exploitation since at least June 22, 2026, three weeks before SonicWall's July 14 hotfix release. Rapid7 confirmed that INC ransomware affiliates are using the exploit chain to sweep credentials and stage ransomware deployments. The attack gives threat actors root-level control of the VPN appliance that serves as the network's trusted remote-access perimeter.
AFFECTS: SonicWall SMA 1000 Series appliances (models 6210, 7210, 8200v); government agencies, MSSPs, and medium to multinational enterprises using SonicWall remote access solutions SOURCE: Dark Reading 2026-07-17
Ransomware
CRITICAL
CVE-2026-50522: Microsoft SharePoint Critical Deserialization RCE Under Active Exploitation Post-PoC
A critical deserialization of untrusted data vulnerability in Microsoft Office SharePoint (CVE-2026-50522, CVSS 9.8) has come under active exploitation following the public release of proof-of-concept exploit code. The flaw allows an unauthenticated attacker to execute arbitrary code over the network and is the third SharePoint Server vulnerability from the July 2026 Patch Tuesday release to be weaponized in attacks. CISA has ordered federal agencies to remediate affected SharePoint servers under Binding Operational Directive BOD 26-04, with CISA having now flagged 11 total Microsoft SharePoint vulnerabilities exploited in attacks since 2021, seven of which have been used in ransomware campaigns.
AFFECTS: Microsoft SharePoint Server (Subscription Edition, 2019, and 2016) on-premises deployments; government and enterprise organizations globally SOURCE: CISA 2026-07-21
Vulnerability
HIGH
Anubis Ransomware: Fairlife (Coca-Cola) Ransomware Attack Results in Confirmed Data Breach
The Anubis ransomware group carried out an attack on Fairlife, LLC, Coca-Cola's wholly owned U.S. dairy subsidiary, first detected on July 16, 2026, resulting in unauthorized access to production systems and a complete suspension of U.S. dairy operations. Coca-Cola confirmed on July 27 that the incident resulted in a confirmed data breach involving the theft of certain data, disclosed via an SEC Form 8-K filing. Anubis claims to have encrypted systems and stolen 1 TB of confidential data, with the group's extortion deadline expiring today.
AFFECTS: Fairlife, LLC (Coca-Cola subsidiary); food and beverage manufacturing sector; U.S. dairy production and supply chain operations SOURCE: SecurityWeek 2026-07-27
Ransomware
HIGH
ShinyHunters Claims Ernst and Young Breach via Supply-Chain Attack on Third-Party IT Platform
The ShinyHunters extortion gang has claimed responsibility for the Ernst and Young data breach, alleging it obtained credentials through a supply-chain attack on EY's third-party IT service management platform and used them to access EY's Jira, GitHub, and Azure environments. EY previously disclosed the breach affected a third-party support ticket system used by its IT staff for tax-related client work, with attackers exfiltrating documents containing client names, addresses, Social Security numbers, and financial information between March 28 and April 12, 2026. ShinyHunters has set a July 31 deadline for EY to make contact before releasing the allegedly stolen data.
AFFECTS: Ernst and Young (EY) and its global tax and professional services clients; third-party IT service management and support ticketing infrastructure SOURCE: BleepingComputer 2026-07-27
Data Breach
HIGH
Microsoft July 2026 Patch Tuesday: Record 570 Flaws Including 3 Zero-Days and 59 Critical RCEs
Microsoft's July 2026 Patch Tuesday addressed a record-breaking 570 security vulnerabilities, nearly triple the previous record set in June, with Microsoft attributing the surge to AI-assisted vulnerability discovery. The release includes fixes for three zero-day vulnerabilities, two of which are actively exploited in the wild: CVE-2026-56164, an unauthenticated privilege escalation in on-premises SharePoint Server, and CVE-2026-56155, an authenticated privilege escalation in Active Directory Federation Services, both discovered by Microsoft's own DART incident response unit. An additional critical RDP Remote Code Execution flaw (CVE-2026-56190) requires no authentication and no user interaction, making internet-exposed RDP servers a high-priority remediation target.
AFFECTS: Microsoft Windows (all supported versions), SharePoint Server, Active Directory Federation Services, Remote Desktop Protocol, Exchange Server (OWA), and BitLocker across enterprise and government environments globally SOURCE: KrebsOnSecurity 2026-07-14
Vulnerability