| ~7 MIN READ |
|
A ransomware gang took down Coca-Cola's milk supply chain and didn't even bother taking credit, which might be the most confusing crime of the year. Meanwhile two teenagers who broke London's transit system are heading to prison for 5.5 years each, so crime evidently still doesn't pay, unless you're whoever just walked off with Fairlife's production line.
This week the common thread is patience, attackers who spent years undetected and companies that still can't say who hit them. Here's what happened, what's still unresolved, and one router setting worth checking today. PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe → |
|
In this edition
|
RANSOMWARE
🥛 Coca-Cola's Dairy Brand Just Went Dark. Nobody's Claiming Credit.
Intro
Fairlife, Coca-Cola's dairy subsidiary, just found out the hard way that milk is apparently a ransomware target too.
What Happened
Hackers hit systems tied to Fairlife's US production, forcing Coca-Cola to halt dairy manufacturing nationwide while Canadian operations kept running. The company activated incident response, notified law enforcement, and says product quality was never at risk, but it still doesn't know the full scope of the intrusion or whether the attackers made any extortion demands.
Why It Matters
A wholly owned Coca-Cola subsidiary going dark shows ransomware crews don't need a household name on the door, subsidiary and supply-chain systems are just as disruptive to hit and often less defended.
The Other Side
No group has claimed responsibility days after disclosure, an unusual silence for an attack this size and a sign the investigation, or the extortion demand, is still very much in progress.
TL;DR: Coca-Cola's Fairlife dairy brand halted US production after a ransomware attack; nobody has claimed responsibility yet.
Further reading: SecurityWeek
|
|
Want to get the most out of ChatGPT?
ChatGPT is a superpower if you know how to use it correctly.
Discover how HubSpot's guide to AI can elevate both your productivity and creativity to get more things done.
Learn to automate tasks, enhance decision-making, and foster innovation with the power of AI.
|
|
|
Why did one company's AI work, and another's didn't?
One had a dedicated owner. Resolution rate: 48.9%. One didn't: 0.38%. See the full breakdown.
Strange but real
🧾 A Compromised Google Cloud Key Cost One Developer $11,000 in AI Art Nobody Asked For
Intro
Developer Charles Jones woke up to a Google Cloud bill for $11,089.77, entirely in Gemini image-generation charges he never ran.
What Happened
A compromised Firebase admin SDK service account key let an attacker rack up two days of unauthorized AI image generation on Jones's account. Google's own security team flagged the compromise and suspended his account for "abusive activity," then billed him for the attacker's usage anyway.
Why It Matters
Google caught the hijack in real time and still couldn't, or wouldn't, separate the victim's bill from the attacker's usage, and it won't say how the key leaked in the first place.
The Other Side
Cloud billing disputes like this aren't rare, and Jones says he followed every recommended remediation step; the problem is there's no automated spending cap and no clear appeals path once the charges hit.
TL;DR: A hijacked Google Cloud key ran up $11,089 in AI image charges; Google flagged the hijack and billed the victim anyway.
Further reading: The Register
|
Porkbun is the domain registrar people trust when they want low prices without the nonsense. Score most domains at cost, free perks like WHOIS privacy & SSL certificates, and real 24/7 human support. Save $1 On Your Domain


