Incident-Response
Ransomware Halts US Production at Coca-Cola's Fairlife Dairy Unit
A ransomware intrusion at Coca-Cola-owned Fairlife forced a shutdown of US dairy production lines, disclosed via SEC 8-K filing — no gang has claimed the attack and no ransom demand has been confirmed publicly.
AssuranceAmerica Breach Exposes 7 Million Driver's Licenses After a Single Phished Employee Account
A single compromised employee credential at auto insurer AssuranceAmerica led to the theft of driver's license numbers, SSNs, and policy data for nearly 7 million people — one of the largest driver's-license breaches disclosed in the US this year.
Progress Tells ShareFile Customers to Power Down Storage Zone Controllers Over 'Credible' Threat
Progress Software is telling on-prem ShareFile Storage Zone Controller admins to physically shut down their Windows servers over an unnamed 'credible external security threat' — no CVE, no patch, no explanation.
DHS Confirms Breach of HSIN, the Federal-State-Local Information-Sharing Backbone
DHS confirms an unattributed threat actor breached HSIN and a connected SharePoint environment used by fusion centers and law enforcement nationwide, with the intrusion window overlapping World Cup security planning.
Trellix Confirms Source Code Repository Breach: Security Vendor's Internal Code Accessed by Unknown Attackers
Trellix confirms unauthorized access to a portion of its internal source code repository, with forensic experts and law enforcement engaged. The blast radius for a security vendor going public with a code breach is its customer base — every defender running its EDR agents.
The Ransomware Dwell Time Collapse: When the Entire Kill Chain Fits Inside an Hour
Akira is encrypting domains 60 minutes after a VPN login. Storm-1175 is going from zero-day to domain-wide Medusa deployment in under 24 hours. The industry's average detection time is still measured in days. The math no longer works.
Anubis Ransomware Gang Claims 2TB Exfiltration from Signature Healthcare as Brockton Hospital Diverts Ambulances
Anubis RaaS group claims theft of 2TB of patient data from Signature Healthcare while Brockton Hospital diverts ambulances, cancels chemo, and operates on paper charts a week after the attack.
Akira Ransomware Now Encrypts in Under an Hour: SonicWall VPNs Are the Front Door
Akira ransomware operators are completing full attack chains from initial VPN access to encryption in under 60 minutes, targeting SonicWall SSL VPNs even on patched devices.