Coca-Cola says Fairlife ransomware attack halts US dairy production
Coca-Cola disclosed in an SEC filing that its Fairlife dairy subsidiary detected unauthorized access to systems tied to production as part of a ransomware attack, forcing a temporary suspension of Fairlife manufacturing across the United States while Canadian operations continue unaffected. The company activated incident response and business continuity protocols, notified law enforcement, and said product quality and safety were not compromised, though it has not disclosed whether data was stolen, whether it received an extortion demand, or which group is responsible.
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
North Korean threat actors tied to the Contagious Interview campaign have been found hiding a four-stage malware payload inside SVG flag images distributed through fake job offers and coding assessments, a technique researchers say sidesteps detection tools built to catch pixel-level tampering rather than semantic content in image comment blocks. The payload, aligned with the OtterCookie family, steals browser credentials and crypto wallets, exfiltrates files, and installs a Socket.IO-based remote access trojan, with the campaign first surfacing after operators targeted a security firm’s own community Slack workspace with a bogus e-commerce developer role.
Medical giant Abbott investigates two cyber incidents as ShinyHunters claims breach
Abbott Laboratories is investigating two apparently unrelated cyber incidents, one involving unauthorized access to legacy systems in its Cancer Diagnostics business and another involving claims that a separate group breached its LabCentral customer portal. The extortion gang ShinyHunters says it used a vishing attack to compromise an employee’s Microsoft Entra single sign-on account and stole tens of millions of medical orders and patient notes along with Social Security numbers, while Abbott maintains neither incident has affected its operations, finances, or customers and that no stolen data has yet been published.
Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets
Ernst & Young disclosed that an unauthorized third party accessed a third-party IT support ticket platform between late March and mid-April and downloaded documents belonging to multiple clients, some containing tax filings and financial data such as Social Security numbers and investment holdings. The firm says it has since secured the platform, confirmed the intrusion was contained, notified federal authorities, and is offering affected clients two years of identity monitoring, though it has found no evidence yet that the stolen files have been misused.
OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes
Researchers disclosed a flaw called HollowByte that lets an unauthenticated attacker crash OpenSSL-backed servers by sending an 11-byte TLS handshake payload that tricks vulnerable versions into pre-allocating massive memory buffers before any real data arrives. Repeated connections cause memory fragmentation that steadily climbs a server’s resident memory until it is killed by the operating system, a risk affecting web servers, language runtimes, and databases that rely on OpenSSL; the issue was quietly fixed in OpenSSL 4.0.1 with backports to several older branches rather than through a formal CVE advisory.