Coca-Cola Fairlife Confirms Data Theft in Ransomware Attack
Coca-Cola Fairlife Confirms Data Theft in Ransomware Attack
Coca-Cola confirmed data was stolen from its subsidiary Fairlife during a recent ransomware attack. The Anubis ransomware group claimed responsibility, targeting Fairlife’s Nutanix systems and threatening to leak 1 TB of stolen files after Coca-Cola refused to negotiate. While the attackers’ countdown timer expired and the data was leaked online, Coca-Cola reported that U.S. production has mostly resumed and product safety was never compromised.
Source: Bleeping Computer
Claude AI Attacks Post-Quantum
Anthropic announced that its Claude Mythos Preview AI derived an end-to-end key-recovery attack against HAWK-256, a challenge parameter in NIST’s post-quantum standardization process, and sped up a meet-in-the-middle attack on 7-round AES-128 by 200 to 800 times using a new “Möbius Bridge” fingerprint. Neither finding impacts production systems or full AES-128, as the attacks target simplified variants and remain computationally impractical for real-world production cryptography.
Source: The Hacker News
Penta Security Now Available Through AWS Marketplace Storefront
Penta Security has launched an AWS Marketplace Storefront, allowing customers to discover, evaluate, and purchase its Cloudbric SaaS security solutions directly through Cloudbric’s website. The platform streamlines procurement, offers free trials and custom quotes, and simplifies AWS WAF security management. Clients can leverage existing AWS accounts for consolidated billing, reducing operational overhead while securing web, API, and cloud environments.
Source: EIN Presswire
Origin Data Breach Exposes Client Data
Australian energy retailer Origin Energy confirmed a cyber incident exposing customer personally identifiable information, including names, contact details, dates of birth, and partial financial information. While Origin assesses the impact across its 4.8 million customers, a threat actor named “John Doe” claims to hold data for 2 million clients and is threatening a leak within two weeks unless negotiations occur. Origin has alerted law enforcement and cyber authorities.
Source: Bleeping Computer
New HTTP/2 Vulnerability Crash Servers
A newly disclosed HTTP/2 flaw enables unauthenticated attackers to remotely crash servers through memory exhaustion attacks. By manipulating flow-control parameters, attackers stall outbound response transmission while forcing servers to process incoming requests. This causes un-sent response data to accumulate in memory buffers, triggering out-of-memory conditions, system crashes, or connection pool exhaustion.
Source: Cyber Security News
Click here to subscribe our Newsletter
