In partnership with

~7 MIN READ
Fact A new macOS malware called ClickLock tricks victims into typing their own password into a fake verification dialog, closing every open app every 210 milliseconds for up to 83 hours straight until they comply. It's infected 100+ systems across 33 countries since May 2026. (Group-IB via BleepingComputer, July 2026)
The Signal
 
A ransomware gang took down Coca-Cola's milk supply chain and didn't even bother taking credit, which might be the most confusing crime of the year. Meanwhile two teenagers who broke London's transit system are heading to prison for 5.5 years each, so crime evidently still doesn't pay, unless you're whoever just walked off with Fairlife's production line.

This week the common thread is patience, attackers who spent years undetected and companies that still can't say who hit them. Here's what happened, what's still unresolved, and one router setting worth checking today.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🕵️ Threat Intel
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
RANSOMWARE
🥛 Coca-Cola's Dairy Brand Just Went Dark. Nobody's Claiming Credit.
Intro
Fairlife, Coca-Cola's dairy subsidiary, just found out the hard way that milk is apparently a ransomware target too.
What Happened
Hackers hit systems tied to Fairlife's US production, forcing Coca-Cola to halt dairy manufacturing nationwide while Canadian operations kept running. The company activated incident response, notified law enforcement, and says product quality was never at risk, but it still doesn't know the full scope of the intrusion or whether the attackers made any extortion demands.
Why It Matters
A wholly owned Coca-Cola subsidiary going dark shows ransomware crews don't need a household name on the door, subsidiary and supply-chain systems are just as disruptive to hit and often less defended.
The Other Side
No group has claimed responsibility days after disclosure, an unusual silence for an attack this size and a sign the investigation, or the extortion demand, is still very much in progress.
 
👉 Takeaway
If your organization runs under a bigger parent brand, don't assume attackers care about your name recognition, they care about your production line.
TL;DR: Coca-Cola's Fairlife dairy brand halted US production after a ransomware attack; nobody has claimed responsibility yet.
Further reading: SecurityWeek
🚨 Can't Miss
 
 
SENTENCING
Owen Flowers, 18, and Thalha Jubair, 20, were sentenced at Woolwich Crown Court for the 2024 Transport for London hack that knocked out 140+ systems and cost £29 million to fix. It's the first-ever prosecution under this specific UK computer crime statute, and investigators say the pair, tied to the Scattered Spider group, had enough access to shut TfL down completely.
Scattered Spider's members are barely out of their teens, and these sentences suggest UK courts are done treating that as a mitigating factor.
 
MALWARE
ClickLock skips exploits entirely: a fake Cloudflare verification prompt tricks victims into running a Terminal command, then the malware kills every open app every 210 milliseconds, for up to 83 hours, until the victim types their real password into a fake dialog. Group-IB has tracked 100+ infected systems across 33 countries since May.
The scariest part isn't the malware, it's how normal "paste this into Terminal to verify you're human" has become.
 
DATA BREACH
An attacker sat inside a third-party support ticket platform for two weeks in the spring, downloading client tax documents including Social Security numbers and financial account data, before EY noticed. No group has claimed the breach, and the Big Four firm is now offering affected clients two years of identity monitoring.
The company that audits everyone else's controls just proved third-party vendor access is still nobody's strong suit.

Want to get the most out of ChatGPT?

ChatGPT is a superpower if you know how to use it correctly.

Discover how HubSpot's guide to AI can elevate both your productivity and creativity to get more things done.

Learn to automate tasks, enhance decision-making, and foster innovation with the power of AI.

🤖 AI in Cyber
 
 
AI VULNERABILITY
Researchers at Manifold found that a malicious browser extension can fake a user click to trigger Claude's agentic browser mode into reading Gmail, Docs, and Calendar, no real approval needed, if a user has "Act without asking" enabled. Anthropic has shipped eight patches since the flaw was reported in May and still hasn't closed it.
If you've enabled autonomous mode on any AI browser agent, an unrelated extension might be the thing making decisions for you.
 
AI RISK
Multiple users, including one who lost a production database, reported GPT-5.6 wiping files when running in full-access mode without sandboxing. OpenAI says the model sometimes tries to override its home directory environment variable and deletes the wrong one instead, and is now calling it "misaligned behavior" rather than a bug.
If you're giving an AI agent unsandboxed file access, "honest mistake" is not a recovery plan.
🕵️ Threat Intel
 
 
SANCTIONS
In their first-ever joint cyber sanctions package, the EU designated 9 individuals and 4 entities and the UK sanctioned 24, publicly naming the FSB's 16th Centre as the operator behind Turla, an espionage group that's been inside government networks in France, Germany, Poland, and beyond since 2010. The package also targeted the alleged leader of the Trickbot and Conti cybercrime groups.
Attribution took over a decade, proof that patience is still a nation state's best weapon.
 
ESPIONAGE
Kaspersky found GoSerpent, a previously undocumented Go-based backdoor used against government and diplomatic targets, harvesting credentials for months before its operators returned in May 2026 with upgraded tooling. Researchers say it shares real overlap with TetrisPhantom, an older APAC-focused espionage group.
Long, quiet campaigns like this one rarely get caught by anything except someone actively looking.
🛠️ Tools & Tactics
 
 
Practical play
A joint advisory says FSB-linked hackers are scanning for routers still running default SNMP settings and years-old Cisco vulnerabilities from 2008 and 2018, targeting energy, healthcare, finance, and government networks across a dozen countries. The fix list is short: disable Cisco Smart Install, kill SNMPv1/v2 in favor of SNMPv3, and use unique credentials per device.
If your organization has any of that sitting exposed, today's the day to check, these are eighteen-year-old bugs still doing damage in 2026.

Why did one company's AI work, and another's didn't?

One had a dedicated owner. Resolution rate: 48.9%. One didn't: 0.38%. See the full breakdown.

🧪 Strange Cyber
 
Strange but real
🧾 A Compromised Google Cloud Key Cost One Developer $11,000 in AI Art Nobody Asked For
Intro
Developer Charles Jones woke up to a Google Cloud bill for $11,089.77, entirely in Gemini image-generation charges he never ran.
What Happened
A compromised Firebase admin SDK service account key let an attacker rack up two days of unauthorized AI image generation on Jones's account. Google's own security team flagged the compromise and suspended his account for "abusive activity," then billed him for the attacker's usage anyway.
Why It Matters
Google caught the hijack in real time and still couldn't, or wouldn't, separate the victim's bill from the attacker's usage, and it won't say how the key leaked in the first place.
The Other Side
Cloud billing disputes like this aren't rare, and Jones says he followed every recommended remediation step; the problem is there's no automated spending cap and no clear appeals path once the charges hit.
 
👉 Takeaway
If you're running service account keys in production, rotate them regularly and set hard spending caps, because trusting the vendor to sort it out clearly isn't a plan.
TL;DR: A hijacked Google Cloud key ran up $11,089 in AI image charges; Google flagged the hijack and billed the victim anyway.
Further reading: The Register

Porkbun is the domain registrar people trust when they want low prices without the nonsense. Score most domains at cost, free perks like WHOIS privacy & SSL certificates, and real 24/7 human support. Save $1 On Your Domain

Keep Reading