---
title: "Ecopetrol Theft, Lidl Vendor Incident, Patch Tuesday – Cyber News | DuoCircle"
description: "Stay ahead of cyber threats with this week"
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/cybersecurity-news-update-week-29-of-2026/"
---

Quick Answer

This week's cyber news highlights ransomware, data breaches, Microsoft zero-days, and phishing threats. Reduce risk with timely patching, MFA, employee awareness, and SPF, DKIM, and DMARC to protect against email spoofing and credential theft.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fcybersecurity-news-update-week-29-of-2026%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Ecopetrol%20Theft%2C%20Lidl%20Vendor%20Incident%2C%20Patch%20Tuesday%20%E2%80%93%20Cyber%20News&url=undefined%2Fblog%2Fcybersecurity-news-update-week-29-of-2026%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fcybersecurity-news-update-week-29-of-2026%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fcybersecurity-news-update-week-29-of-2026%2F&title=Ecopetrol%20Theft%2C%20Lidl%20Vendor%20Incident%2C%20Patch%20Tuesday%20%E2%80%93%20Cyber%20News "Share on Reddit") [ ](mailto:?subject=Ecopetrol%20Theft%2C%20Lidl%20Vendor%20Incident%2C%20Patch%20Tuesday%20%E2%80%93%20Cyber%20News&body=Check out this article: undefined%2Fblog%2Fcybersecurity-news-update-week-29-of-2026%2F "Share via Email") 

![Cybersecurity News update](https://media.mailhop.org/duocircle/spf-validator-6700-1784542861871.jpg) 

## Ecopetrol (Colombia) hit by attempted ransomware and data theft

[Colombia’s state-controlled energy](https://apnews.com/article/colombia-venezuela-gas-pipeline-ofac-license-trade-138a925f9d2aa4daf9ed0b5952417557) giant disclosed unauthorized access to certain digital resources by an external actor, along with an attempted ransomware attack that was blocked by its cybersecurity controls. The access affected cloud-based file storage environments of roughly 15 subsidiaries, resulting in the unauthorized download of data tied to **about 3,300 user accounts**, and the attacker made extortion demands threatening to publicly disclose the data.

## Lidl discloses data breach at a third-party IT provider

**Lidl notified customers** in Germany, Belgium, and the Netherlands that customer data was stolen after attackers breached one of its [IT service providers](https://www.helpnetsecurity.com/2026/07/13/lidl-data-breach-customer-data/), warning of phishing and identity fraud risk. The stolen data includes customers’ names, phone numbers, email addresses, dates of birth, customer numbers, and salutations, though passwords and payment info weren’t confirmed impacted.

## Microsoft ships largest-ever Patch Tuesday with two exploited zero-days

July’s Patch Tuesday arrived as the largest security update in [Microsoft’s history at 622 CVEs](https://www.techtimes.com/articles/320687/20260716/microsoft-patches-622-cves-active-sharepoint-ad-fs-zero-days-demand-first-action.htm), more than triple June’s prior record, including an unauthenticated SharePoint Server flaw and an **Active Directory Federation Services** bug that lets an attacker seize administrator control of the server that signs identity tokens-both actively exploited.

![DMARC Generator 2004](https://media.mailhop.org/duocircle/dmarc-generator-2004-1784542956246.jpg)

## CISA adds actively exploited SharePoint RCE to its Known Exploited Vulnerabilities list

Beyond the Patch Tuesday zero-days, [CISA warned](https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html) of active exploitation of multiple SharePoint Server vulnerabilities that could let attackers gain unauthorized access to on-premises instances, steal IIS machine keys, and deploy malware for persistence.

## Coca-Cola’s Fairlife dairy unit halted by ransomware

[Coca-Cola disclosed](https://www.bleepingcomputer.com/news/security/coca-cola-says-fairlife-ransomware-attack-halts-us-dairy-production/) that its Fairlife dairy subsidiary detected unauthorized third-party access to some of its systems, including **production-related systems**, in connection with a ransomware attack, and temporarily suspended US production operations (Canadian operations were unaffected).

## Naval defense contractor TKMS/Atlas Elektronik claimed by ransomware group

_The “TheGentlemen” ransomware gang claimed a breach isolated to a North American subsidiary of TKMS supporting U.S. military work, while the company said no security-relevant or sensitive military data was compromised; the attacker’s claim of over 1TB of stolen data remains unverified_.

![Smtp Relay 6766](https://media.mailhop.org/duocircle/smtp-relay-6766-1784543097234.jpg)

## Spanish police dismantle â‚¬140 million cybercrime and BEC fraud ring

Spanish National Police, with Europol and Interpol, dismantled a network accused of stealing and laundering about â‚¬140 million through fake investment platforms, [CEO fraud](https://abcnews.com/Business/startup-ceo-charged-175-million-fraud-case/story?id=98363900), invoice fraud, and man-in-the-middle attacks, arresting four people across Spain, Portugal, and Panama.

## Japan’s largest taxi operator Nihon Kotsu knocked offline by ransomware

Nihon Kotsu confirmed its **internal systems** were subjected to unauthorized external access and [malware infection](https://au.pcmag.com/security/118816/fbi-traces-malware-infected-steam-games-to-21-year-old-in-florida), forcing it to disconnect systems and shut down its phone dispatch service; the AiLock ransomware group later claimed responsibility and threatened to leak stolen data.

## D1R group claims theft from Synopsys and Bosch

The D1R cybercrime group claimed to have stolen valuable data from chipmaker Synopsys and industrial giant Bosch, threatening to leak it unless a ransom is paid.

## Identity attacks overtake exploits as the top ransomware entry point

Dark Reading reported a shift in ransomware tactics, with [compromised credentials](https://www.infosecurity-magazine.com/news/compromised-logins-ransomware-entry/) and identity-based attacks now surpassing software exploitation as the leading way ransomware crews get in a trend worth flagging for readers focused on **access controls and MFA**.

## ClickFix social-engineering technique keeps expanding

Security researchers highlighted how the “[ClickFix” fake-error social engineering trick](https://www.whitecloudsecurity.com/news/2026/March/ClickFix-Social-Engineering-Zero-Trust-Defense/) tricking users into pasting malicious commands themselves continues to spread across new campaigns, prompting calls for **updated user-awareness training**.

![DMARC Report Service 2001](https://media.mailhop.org/duocircle/dmarc-report-service-2001-1784543055842.jpg)

## U.S. Treasury sanctions VPN provider and cryptor seller tied to ransomware

The [U.S. sanctioned VPN provider](https://www.scworld.com/brief/u-s-sanctions-vpn-provider-and-cryptor-seller-for-aiding-ransomware-gangs) 1VPNS and a cryptor seller for enabling ransomware gangs behind billions of dollars in losses to critical infrastructure.

## Fake VPN and 7-Zip apps turn victims into residential proxy nodes

Researchers described a campaign using [fake VPN and 7-Zip apps](https://www.malwarebytes.com/blog/threat-intel/2026/02/fake-7-zip-downloads-are-turning-home-pcs-into-proxy-nodes) that turn victims’ devices into residential proxy nodes, letting criminals route their traffic through **victims’ IP addresses** without their knowledge.

## Russian state-backed hackers breach cameras along NATO supply routes

Dutch intelligence reported that [Russian state-backed hackers](https://edition.cnn.com/2026/07/14/politics/us-indicts-russia-cybercrime) compromised internet-connected cameras along military logistics routes in the Netherlands to monitor equipment transfers to Ukraine-a **geopolitical/OT-security story**.

Strengthen [email security](https://www.duocircle.com/) with SPF, [DKIM](https://www.duocircle.com/blog/email-hosting/what-is-dkim-and-why-you-should-use-it-to-secure-your-email/), and [DMARC](https://www.duocircle.com/email/dmarc/) to block phishing and domain spoofing.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

## Related Articles

[  news  Cisco SD-WAN Flaw, Critical NGINX Exploit, Foxconn Ransomware Attack – Cybersecurity News \[May 11, 2026\]  May 18, 2026 ](/blog/cybersecurity-news-update-week-20-of-2026/)[  news  GitHub Code Leak, 7-Eleven Breached, NYC Patient Exposure – Cybersecurity News \[May 18, 2026\]  May 25, 2026 ](/blog/cybersecurity-news-update-week-21-of-2026/)[  news  FBI Warns Firms, Carnival Breach, GlobalProtect Flaw – Cyber News  Jun 1, 2026 ](/blog/cybersecurity-news-update-week-22-of-2026/)[  news  DentaQuest Leak, Cisco Patch Pending, Instagram Bug – Cyber News  Jun 8, 2026 ](/blog/cybersecurity-news-update-week-23-of-2026/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Ecopetrol Theft, Lidl Vendor Incident, Patch Tuesday – Cyber News","description":"Stay ahead of cyber threats with this week's top security news, from ransomware and data breaches to zero-days, plus why SPF, DKIM, and DMARC remain essential.","url":"https://www.duocircle.com/blog/cybersecurity-news-update-week-29-of-2026/","datePublished":"2026-07-20T00:00:00.000Z","dateModified":"2026-07-20T00:00:00.000Z","dateCreated":"2026-07-20T00:00:00.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/cybersecurity-news-update-week-29-of-2026/"},"articleSection":"news","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/spf-validator-6700-1784542861871.jpg","caption":"Cybersecurity News update"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"news"},{"@type":"ListItem","position":3,"name":"Ecopetrol Theft, Lidl Vendor Incident, Patch Tuesday – Cyber News","item":"https://www.duocircle.com/blog/cybersecurity-news-update-week-29-of-2026/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"news","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Ecopetrol Theft, Lidl Vendor Incident, Patch Tuesday – Cyber News","item":"https://www.duocircle.com/blog/cybersecurity-news-update-week-29-of-2026/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Ecopetrol Theft, Lidl Vendor Incident, Patch Tuesday – Cyber News","description":"Stay ahead of cyber threats with this week's top security news, from ransomware and data breaches to zero-days, plus why SPF, DKIM, and DMARC remain essential.","url":"https://www.duocircle.com/blog/cybersecurity-news-update-week-29-of-2026/","datePublished":"2026-07-20T00:00:00.000Z","dateModified":"2026-07-20T00:00:00.000Z","dateCreated":"2026-07-20T00:00:00.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/cybersecurity-news-update-week-29-of-2026/"},"articleSection":"news","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/spf-validator-6700-1784542861871.jpg","caption":"Cybersecurity News update"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
