Top stories
// 5 stories cyclingCisco Secure Firewall ASA & FTD — CVE-2026-20349
Actively exploited zero-day lets an unauthenticated attacker crash Cisco ASA and FTD firewalls with a crafted request to the Remote Access SSL VPN service.
Amgen — third-party cloud breach, patient PHI and proprietary data exfiltrated, SEC 8-K
Amgen filed an SEC Item 1.05 8-K confirming attackers exfiltrated patient protected health information and proprietary data from third-party cloud environments; scale undisclosed.
Minnesota water utilities — coordinated OT attack on 30+ community systems
A coordinated cyberattack disrupted more than 30 Minnesota water utilities over one weekend, knocking a treatment plant offline via unpatchable internet-exposed PLC flaws.
PTC Windchill / FlexPLM — Cl0p mass exploitation (CVE-2026-12569)
Cl0p is exploiting an unauthenticated remote-code-execution flaw in PTC's Windchill and FlexPLM product-lifecycle software to plant webshells, steal engineering data and run double-extortion.
Nichirei — RansomHouse ransomware halts Japan's largest frozen-food cold-chain network
RansomHouse-claimed ransomware disrupted Nichirei, Japan's largest frozen-food and cold-chain logistics group, for over a week, curtailing shipments and triggering KFC Japan and Glico supply shortages.
Profiles and interviews with the people behind the keyboard. Some made the news. Some made the millions. Some did the time. Some came back with something to say.
Open the profiles →fairlife (The Coca-Cola Company) — ransomware halts US dairy production, Item 8.01 8-K
Coca-Cola filed an Item 8.01 8-K on 16 July confirming a ransomware event at dairy subsidiary fairlife that suspended all US production; Canada unaffected.
Deutsche Bank — third-party platform breach, Unsafe extortion claim
Extortion group Unsafe listed Deutsche Bank and leaked alleged employee records; the bank attributes the breach to a German third-party marketing platform, not its network.
US Department of Homeland Security — HSIN information-sharing platform breach
DHS confirmed hackers breached HSIN, its unclassified information-sharing platform and a linked SharePoint system, weeks before disclosure during live World Cup security coordination.
Aflac Japan — policyholder-portal breach, 4.38M records, SEC 8-K
Aflac Japan disclosed via SEC 8-K that intruders repeatedly accessed its policyholder portal over ten days, exfiltrating personal data on 4.38 million customers and agents.
River Financial Corporation — ransomware attack, Item 1.05 8-K
River Financial, parent of Alabama's River Bank & Trust, filed an Item 1.05 8-K on 25 June confirming ransomware across its servers after a 16 June intrusion.