Microsoft Patch Records, Ransomware Hits Fairlife, Spirals Moves Fast
Quick Answer
This week's cybersecurity roundup covers Microsoft's record-breaking July Patch Tuesday, the Fairlife ransomware attack, Spirals' rapid ransomware operations, active phishing campaigns, AI-powered cyber threats, CISA KEV updates, and the latest DMARC, DKIM, and SPF email security developments.
Microsoft’s July Patch Tuesday breaks records
Microsoft’s July 2026 Patch Tuesday addressed roughly 570 vulnerabilities, including two actively exploited zero-days — CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services — plus a publicly disclosed BitLocker bypass bug. One of the largest single-month patch batches on record.
Coca-Cola’s Fairlife dairy unit hit by ransomware
The Coca-Cola Company disclosed that a ransomware attack impacting its Fairlife dairy subsidiary disrupted operations, temporarily suspending production of Fairlife products across the United States.
New ransomware crew “Spirals” moves at record speed
A new ransomware actor called Spirals completed a corporate intrusion — from initial access to data theft and encryption — in less than 24 hours.

Scattered Spider hackers finally jailed
Thalha Jubair, 20, and Owen Flowers, 18, were each sentenced to five years and six months in prison for the 2024 cyberattack on Transport for London, in what UK authorities called the largest cybercrime prosecution ever brought before a UK court, with damages estimated at £29 million. The attack originated through social engineering targeting the organization’s helpdesk.
LastPass warns of active phishing campaign
LastPass alerted customers to an active phishing campaign identified on July 13, with emails sent from a lookalike domain directing recipients to a fraudulent site designed to steal LastPass master passwords. LastPass’s own systems were not affected.
CISA adds actively exploited plugin flaws to its KEV catalog
CISA added unrestricted file-upload vulnerabilities affecting iCagenda and Balbooa Forms to its Known Exploited Vulnerabilities catalog.
Lidl customer data stolen via third-party vendor
Hackers stole Lidl customer data from an external service provider.
Wrongful detention in REvil manhunt

Armenia detained a Russian tourist on a US extradition request tied to a REvil ransomware suspect, though his lawyers say authorities have the wrong man.
AWS billing bug shows trillion-dollar charges
An AWS Cost Explorer error displayed inaccurate estimated charges reaching trillions of dollars, although customers were not actually billed those amounts.
IIS server compromise leads to same-week ransomware
Attackers used a compromised Microsoft IIS server as an initial foothold before deploying ransomware throughout the victim’s network the next day.
Nation-state hackers weaponize AI coding tools
China-linked hackers weaponized Claude Code and DeepSeek against government networks, while researchers detailed an exploit chain combining GPT-5/6-era AI models with Chrome browser vulnerabilities to illustrate emerging AI-assisted attack techniques.
New “GhostCommit” AI-prompt-hiding technique
A novel technique dubbed GhostCommit was found hiding malicious AI instructions inside images and code commits, part of a growing trend of attackers targeting AI-integrated developer workflows.

DPRK-aligned hackers target developers for crypto theft
Cybersecurity researchers uncovered a campaign, tracked as REF9403, targeting software developers with North Korean state-sponsored hackers aiming to steal sensitive data and plunder cryptocurrency wallets.
Bandcamp phishing campaign hits musicians and developers
A phishing campaign began targeting musicians and developers on Bandcamp, abusing legitimate contact forms and spoofed “noreply@bandcamp.com” emails to bypass spam filters — bearing a striking resemblance to a 2025 Pixiv phishing scam.

Independence-Day-themed scams targeted mobile users
Bitdefender flagged a wave of holiday-lure scams spreading via WhatsApp and SMS, impersonating major retailers with fake gift offers — roughly 90% coming from contacts already saved in victims’ phones, making them unusually convincing.
Stay informed about the latest cybersecurity threats, ransomware attacks, phishing campaigns, and DMARC, DKIM, and SPF email security updates.
General Manager
Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.
LinkedIn Profile →Take control of your DMARC reports
Turn raw XML into actionable dashboards. Start free - no credit card required.