The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States.
A flaw in Anthropic’s Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude’s access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce.
A new malicious framework called OkoBot is delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data.
Traditional security workflows were built for environments that changed at human speed. Token Security explains why AI agents require a new approach: building on a live identity foundation while giving security teams the flexibility to create workflows tailored to their own environments.
Genetic testing company 23andMe has agreed to pay $18 million to settle claims from a coalition of 43 attorneys general that it failed to protect customers’ genetic data.
Two leading members of the Scattered Spider cybercrime collective were sentenced to five years and six months in prison each for hacking Transport for London (TfL) in 2024.
AutomationDirect’s Productivity Suite versions up to 4.6.2.2 are vulnerable to several critical issues that could allow local attackers to cause memory corruption, system instability, or denial-of-service conditions. Key vulnerabilities include out-of-bounds reads/writes, and a divide-by-zero error. Users are advised to update to version 4.7.0.47 or later. If immediate updates aren’t possible, AutomationDirect recommends various compensating measures, such as network isolation, access restrictions, and stringent monitoring practices to mitigate risks. CISA encourages organizations to maintain robust cybersecurity practices and to report any anomalies.
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, reflecting active exploitation: two CVEs related to Fortinet FortiSandbox OS Command Injection and one from Microsoft SharePoint concerning Deserialization of Untrusted Data. These vulnerabilities are significant risks for federal agencies, driving the need for prompt remediation as outlined in Binding Operational Directive 26-04. While this directive specifically affects Federal Civilian Executive Branch agencies, CISA advises all organizations to adopt similar risk-based vulnerability management practices. CISA welcomes submissions for new vulnerabilities to the KEV Catalog through its nomination process.
A vulnerability in NASA’s Core Flight System (cFS) Health & Safety (HS) Application could lead to denial-of-service conditions. The issue stems from a null pointer dereference, causing a segmentation fault when handling a Housekeeping Telemetry request. This flaw affects the cFS Health & Safety application, with critical implications for transportation systems globally. The vendor, NASA, provides a CVSS score of 7.5 for this vulnerability, indicating its severity.
A denial-of-service vulnerability (CVE-2026-9653) has been identified in Rockwell Automation’s 1756-EN2, 1756-EN3, and 1756-ENBT communication modules due to improper validation of connection packets. The affected versions can allow attackers on the network to disrupt device connections, although these connections will resume immediately after. Users are advised to upgrade the affected devices to version 12.002, as the 1756-ENBT is discontinued and has no available fix. CISA recommends enhancing network security, including using firewalls and VPNs, to mitigate risks.
Rockwell Automation’s Arena software versions up to V17.00.00 are vulnerable to multiple memory corruption issues, identified as CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, and CVE-2026-8314. Attackers could exploit these vulnerabilities to execute arbitrary code by convincing users to open malicious files. Users are urged to update to V17.00.01 to mitigate these risks. CISA recommends enhancing network security and implementing cybersecurity best practices to protect against such threats.