
Loading summary
A
Cybersecurity Today is brought to you by nordlayer. Teams today work across multiple tools and devices, but security often remains fragmented, and this is exactly what Nord layer can help you address. Nord layer gives your company centralized control over access by individuals and teams and keeps connection secure from anywhere with no additional hardware required. Visit nordlayer.com cybersecurity today and use the discount code NLSUMMER26 for a special discount on your purchase.
B
Microsoft's serial tormentor drops another zero day A ransomware attack shuts down Coca Cola's fairlife milk lines. Abbott is fighting two breaches at once. Leaked ransomware chats reveal heartless attacks on healthcare and a WordPress flaw that turns an anonymous web request into code execution. This is Cybersecurity Today, and I'm your host David Shipley. Let's get started. Microsoft's most persistent tormentor is back Nightmare Eclipse dropped another Windows zero day on Tuesday, and true to form, they timed it to land right after Microsoft shipped its monthly patches, maximizing the window before Redmond can write and distribute any fixes. This one's called Legacy Hive. It's a local privilege escalation flaw in the Windows user profile service, and it abuses the way Windows loads Registry hives. Windows hives are the files on the disk that store the registry, the database Windows uses to hold configuration for the system, installed applications, and individual user profiles. Each user gets their own hive, holding their personal settings. In practice, a standard user can mount another user's hive, including an administrator's, into their own classes route for an attacker who's already inside a network. That's quite useful, but it's not the haymaker nightmare Eclipse promised back in June. They teased a bone shattering drop that would deliver full system compromise. What actually shipped is much more modest, matei Badenow at Pentest Tools told the Register. The distance between the public proof of concept and a real full compromise is pretty wide. Bundling this with credential access and persistence into full compromise, he said, is more ambition than release code at this point, and this time the code is deliberately stripped back. There's no fully working proof of concept code shipping with this vulnerability. The public version needs extra credentials and only reaches one hive nightmare, Eclipse says. The original, the one that they say they held back, needs no credentials and goes further. But you'll need, in their words, some brain cells to get there. That restraint is a shift. Earlier drops like Blue Hammer and Red sun went from proof of concept to widespread exploitation within days, and that prompted some pretty harsh words from Microsoft Cybersecurity experts believe capable actors will be able to reverse engineer the missing pieces and stand up weaponized versions of this vulnerability in short order. Nightmare Eclipse claims Legacy Hive works against machines fully patched as of July. Microsoft says it's aware of the reports and is investigating the validity of the claims. This month's patch Tuesday sets a record for Microsoft. Redmond shipped 570 fixes, according to Krebs on security. That's the largest single release the company has ever put out on a patch Tuesday. At least two of the vulnerabilities were zero days already under active exploitation, one in Windows Server that escalates a limited user straight to system administrator, and one in SharePoint that CISA flagged as being used in the wild to compromise organizations. Microsoft said last week the company is now using AI to hunt for vulnerability in its code, much of which dates back decades. And that as AI helps defenders surface more issues, customers should expect heavier patch loads every month. Coca Cola has suspended US Production at its Fairlife dairy unit following a ransomware attack. The company disclosed the attack in a filing with the SEC late last week. Coca Cola says it's still working to determine the full scope of the attack, but that the attack hadn't affected the quality or safety of Fairlife products. Fairlife makes ultra filtered milk protein shakes and nutritional drinks, and Fairlife is no small piece of Coca Cola's business. It crossed a billion dollars in annual retail sales back in 2022, and Coca Cola committed $650 million in March and to expand its Coopersville, Michigan facilities. No group has yet claimed responsibility for the attack, and researchers haven't tied it to a known crew. Law enforcement has been notified and outside cybersecurity advisors are working to restore systems. Food and agricultural industries keep drawing more and more unhealthy cyber attention. The Food and Ag ISAC says the sector has absorbed roughly 205 attacks so far this year. They noted adversaries scan for exposed vulnerable systems at machine speed and then sort out who the victim is only after they're already in and potentially causing damage. It's doubtful they'll care much about impacting human safety and well being when it comes to major food and agricultural hacks. Massive healthcare and medical device maker Abbott Laboratories is juggling two separate breach investigations and at the same time that don't appear to be connected. The first surfaced when the extortion gang Shiny Hunters added Abbott to its leak site, threatening to publish stolen data unless the company paid up. Abbott has confirmed unauthorized access to a limited number of internal legacy exact sciences systems inside its cancer diagnostics business. The company says those legacy systems are separate from Abbott's own and that no other operations, products or lab work were affected, and that it doesn't expect a material financial hit from the hack. Shiny Hunters claims it got through on a vishing attack on Abbott employees in mid June, compromising a Microsoft Entre single sign on account and pivoting from there. That's the same playbook the gang has run for over a year. Phish and SSO login then drain connected apps like Salesforce, Microsoft 365 and Slack. In this case, Shiny Hunters claim to have taken more than 30 million rows of customer data, over a million Social Security numbers and 22 million client notes containing doctor patient conversations. Bleeping computer hasn't verified any of these claims. The second incident involves a different actor calling itself Shadow Bytes, which claims it breached Abbott's core laboratory business through the Lab Central customer portal using compromised credentials, then quietly pulled files through API endpoints starting July 4th. It says it grabbed manufacturing certificates, technical specs and regulatory documentation. Abbott confirms it's aware of the potential incident, but disputes the characterization. A spokesperson says Lab Central is an externally facing portal holding publicly available product reference material, not sensitive or proprietary data. Neither group has published anything yet. Shiny Hunter's latest deadline lands on Tuesday. Abbott is the second major US based medical device maker to be hit this year, though it doesn't look like as of now, these attacks will disrupt the medical supply chain the way the Stryker attack did earlier this year. Jeff White's BBC Cyberhack podcast has been mining the Conti leaks, and the picture it paints of one of ransomware's biggest gangs is is well worth a listen. Conti made an estimated 180 million in 2021 alone, hitting more than 1,000 organizations. Then in early 2022, after the gang posted support for Russia's invasion of Ukraine, a member turned on them and leaked over 300,000 internal messages. The chats showed hackers arguing over targeting hospitals during the pandemic. One member wrote, quote, let them die, end quote, and wanted to hit hundreds of US Healthcare facilities, while the others insisted the medical sector was off limits. When Conti breached Jeweler Graph and leaked client data, they realized too late they'd exposed Gulf royals and issued a rare public apology, promising to scrub the leak. Conti's boss, known as Stern, was later identified by German police as Russian national Vitaly Kovalev. The BBC traced him through social media to a life of Bentleys, Louis Vuitton and holidays at a resort where a Villa runs 22,000 pounds a week. White's books and podcasts dig deep into stories exactly like this one and are highly recommended summer reading or listening there's a new WordPress vulnerability, and what makes it dangerous is where it lives. This one's in the Core. A bare install with zero plugins is exploitable. An anonymous HTTP request can run code on the site, no login required. It's called WP2SHELL, and it's actually two bugs chained together. Adam Cues at AssetNote Searchlight Cyber's attack surface arm found a confusion flaw in WordPress's batch rest routine and reported it through the HackerOne bug bounty program. Separately, three researchers, TF1, T, D, Ditro and Hango, reported a SQL injection in core on their own. Each vulnerability was fairly limited. Chained, they carry an anonymous request all the way to remote code execution. Both now have CVE IDs. The SQL injection reaches back to version 6.8, but the batch route bug, the half that turns a bounded injection into full unauthenticated RCE, only exists from version 6.9 onward, to which shipped in December. WordPress says it patched the vulnerability Friday in 6.9.5 and 7.0.2 and pushed forced updates through the auto update system. Searchlight had held back its own technical write up, but WordPress's core is open source and the release notes named the files that changed within a day. Other researchers had read the patch, published the full mechanism, and put a working proof of concept on GitHub. There's one narrowing condition to this vulnerability. The code execution path only works when the site isn't running a persistent object cache like Redis or memcached. Cloudflare shipped WAF rules alongside the disclosure and says sites behind its managed rules are covered. And that's Cybersecurity today for Monday, July 20th. Thanks for listening. I've been your host David Shipley, and I'll be back on Wednesday with the latest headlines. If you missed our show on Saturday, I did an interview about the last six months worth of AI cybersecurity issues, what it all means for CISOs, and how the browser is the new battleground for both humans and AI. We appreciate all of your feedback. Feel free to drop us a line@technewsday.com or CA, or you can leave a comment under the YouTube video Stay safe and stay secure.
A
Once again, we'd like to thank nordlayer for their support in sponsoring this show. Teams today work across multiple tools and devices, but security often remains fragmented. This is exactly what NORD Layer can help you address it provides a network security platform with easy to manage network access, monitoring and control, and without additional hardware or complex infrastructure. Nordlayer helps businesses of all sizes manage and secure access to company resources going beyond what traditional VPNs can offer. And it provides encrypted connectivity with visibility across your entire network environment. And did we mention no new hardware required? Visit nord layer.com cybersecurity today and use the code NL Summer 26 for a special discount during their summer sale.
Episode: Wordpress RCE, New Windows 0-day and Coca-Cola's Fairlife Ransomed
Host: David Shipley
Date: July 20, 2026
Main Theme:
This episode delivers an incisive update on major cybersecurity threats, including Windows zero-day vulnerabilities, a ransomware strike disrupting Coca-Cola’s Fairlife production, double breach investigations at Abbott, heartless tactics adopted by ransomware gangs, and a critical, core-level WordPress remote code execution (RCE) flaw.
[00:40–03:40]
Overview:
Nightmare Eclipse, a persistent and notorious threat actor, unveiled a fresh Windows zero-day vulnerability dubbed “Legacy Hive.” It is a local privilege escalation flaw targeting the Windows user profile service.
Technical Exploit:
Expert Commentary:
"The distance between the public proof of concept and a real full compromise is pretty wide. Bundling this with credential access and persistence into full compromise... is more ambition than release code at this point." [02:11]
Microsoft’s Response:
[03:40–06:00]
Incident Breakdown:
No Attacker Attribution Yet:
Industry Trend Points:
"The Food and Ag ISAC says the sector has absorbed roughly 205 attacks so far this year." [05:27]
[06:00–08:30]
Incident 1:
Incident 2:
Industry Context:
[08:30–09:55]
Conti's Internal Conflicts & Ruthlessness:
"Let them die," [Conti member’s chilling quote, discussing attacks on US healthcare facilities] [09:14]
Operational Blunders & Fallout:
Referenced Resource:
[09:55–11:30]
Nature of the Vulnerability:
Discovery & Patch:
Limitations/Conditions:
On the new Windows RCE restraint:
"There's no fully working proof of concept code shipping with this vulnerability. The public version needs extra credentials and only reaches one hive… you’ll need, in their words, 'some brain cells' to get there." – David Shipley [02:34]
On food & ag ransomware strategy:
“…adversaries scan for exposed, vulnerable systems at machine speed and then sort out who the victim is only after they're already in and potentially causing damage.” – David Shipley [05:27]
On the ethics crisis within Conti:
"Let them die." — Conti gang member arguing for targeting hospitals during the pandemic [09:14]
Host’s Closing Reminder:
Stay safe, stay secure – with news and context to prepare your business for today’s evolving threats.
Summary compiled for listeners seeking an in-depth and practical breakdown of the episode’s cybersecurity coverage.