Hackers Exploit Palo Alto PAN-OS Flaw to Deploy Qilin Ransomware
Arctic Wolf Labs linked multiple June 2026 intrusions to active exploitation of CVE-2026-0257, an authentication bypass flaw in Palo Alto Networks’ GlobalProtect portal and gateway, with attackers using it as an initial access point to deploy Qilin ransomware and, in some cases, steal data before encrypting networks. The flaw becomes exploitable when authentication override cookies are enabled alongside specific certificate configurations, letting unauthenticated attackers establish legitimate-looking VPN sessions and move from there to domain-wide encryption using PsExec-based lateral movement, credential dumping, and aggressive event log clearing. Organizations running affected PAN-OS versions should apply Palo Alto’s fixes immediately, terminate active GlobalProtect sessions post-patch, and watch for ransomware staging activity in the C:\PerfLogs\ directory — a recurring pattern across the incidents Arctic Wolf investigated.
New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2
Group-IB identified a new malware strain called HollowGraph that abuses Microsoft 365 calendars and the Microsoft Graph API as a stealthy command-and-control channel, using DNS tunneling to deliver and refresh the Entra ID credentials needed to authenticate to the Graph API, then securing that unencrypted channel with a hybrid RSA and AES-256-GCM encryption scheme. Researchers identified only 12 infected systems with earliest activity dating to June 3 and the most recent example found July 9, suggesting a highly targeted rather than opportunistic operation focused narrowly on Israeli entities. While Group-IB couldn’t confidently attribute the campaign to a known threat actor, they identified technical similarities to the Iranian-nexus group Lyceum and found command syntax matching the previously tracked Cavern framework, pointing to a capable, well-resourced adversary running a narrowly scoped espionage operation.
WP2Shell WordPress Vulnerabilities Exploited in the Wild
Two newly patched WordPress vulnerabilities dubbed WP2Shell — CVE-2026-60137, a high-severity SQL injection bug, and CVE-2026-63030, a critical arbitrary code execution flaw — are being actively exploited in the wild, with attacks beginning shortly after disclosure. Discovered by Searchlight Cyber, the flaws affect WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, and chaining them allows an anonymous attacker to achieve unauthenticated remote code execution on a stock WordPress install with no plugins required. Given the severity and confirmed in-the-wild exploitation, WordPress.org enabled forced auto-updates to the patched versions (6.9.5 and 7.0.2) for affected sites, though site owners should verify their installation has actually updated rather than assuming the forced update applied successfully.
Fairlife Pauses US Production After Cyberattack Breached Milk Brand’s Systems
Coca-Cola disclosed that its dairy subsidiary Fairlife identified unauthorized third-party access to a portion of its systems, including production-related systems, in connection with a ransomware event, forcing the company to temporarily suspend Fairlife’s U.S. manufacturing operations while Canadian production continues unaffected. Coca-Cola activated its incident response and business continuity protocols immediately upon detection, brought in outside cybersecurity advisors, and notified law enforcement, though the company says product quality and safety have not been impacted and the full scope of the incident remains under investigation. No ransomware group has yet claimed responsibility and Coca-Cola has not disclosed whether data was stolen or whether it has received an extortion demand, but the incident illustrates how ransomware targeting food and beverage manufacturing can translate directly into physical production shutdowns rather than just IT disruption.
Italy Fines WINDTRE €1.7 Million Over Security Flaws Behind Two Data Breaches
Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, fined telecom operator WINDTRE €1.7 million over “serious data security shortcomings” that allowed hackers to breach its systems twice and exfiltrate personal data belonging to more than 365,000 customers. The regulator opened its investigation after WINDTRE reported two separate breaches in February 2025, both of which relied on old-school social engineering rather than software exploitation — attackers posed as support technicians and convinced staff at two WINDTRE retail stores to grant them system access. The case underscores that even sophisticated telecom operators remain vulnerable to low-tech social engineering at the store or help-desk level, and that regulators are treating repeat breaches stemming from the same underlying control gaps as an aggravating factor in fine calculations.