Ecopetrol Theft, Lidl Vendor Incident, Patch Tuesday – Cyber News
Quick Answer
This week's cyber news highlights ransomware, data breaches, Microsoft zero-days, and phishing threats. Reduce risk with timely patching, MFA, employee awareness, and SPF, DKIM, and DMARC to protect against email spoofing and credential theft.
Ecopetrol (Colombia) hit by attempted ransomware and data theft
Colombia’s state-controlled energy giant disclosed unauthorized access to certain digital resources by an external actor, along with an attempted ransomware attack that was blocked by its cybersecurity controls. The access affected cloud-based file storage environments of roughly 15 subsidiaries, resulting in the unauthorized download of data tied to about 3,300 user accounts, and the attacker made extortion demands threatening to publicly disclose the data.
Lidl discloses data breach at a third-party IT provider
Lidl notified customers in Germany, Belgium, and the Netherlands that customer data was stolen after attackers breached one of its IT service providers, warning of phishing and identity fraud risk. The stolen data includes customers’ names, phone numbers, email addresses, dates of birth, customer numbers, and salutations, though passwords and payment info weren’t confirmed impacted.
Microsoft ships largest-ever Patch Tuesday with two exploited zero-days
July’s Patch Tuesday arrived as the largest security update in Microsoft’s history at 622 CVEs, more than triple June’s prior record, including an unauthenticated SharePoint Server flaw and an Active Directory Federation Services bug that lets an attacker seize administrator control of the server that signs identity tokens-both actively exploited.

CISA adds actively exploited SharePoint RCE to its Known Exploited Vulnerabilities list
Beyond the Patch Tuesday zero-days, CISA warned of active exploitation of multiple SharePoint Server vulnerabilities that could let attackers gain unauthorized access to on-premises instances, steal IIS machine keys, and deploy malware for persistence.
Coca-Cola’s Fairlife dairy unit halted by ransomware
Coca-Cola disclosed that its Fairlife dairy subsidiary detected unauthorized third-party access to some of its systems, including production-related systems, in connection with a ransomware attack, and temporarily suspended US production operations (Canadian operations were unaffected).
Naval defense contractor TKMS/Atlas Elektronik claimed by ransomware group
The “TheGentlemen” ransomware gang claimed a breach isolated to a North American subsidiary of TKMS supporting U.S. military work, while the company said no security-relevant or sensitive military data was compromised; the attacker’s claim of over 1TB of stolen data remains unverified.

Spanish police dismantle €140 million cybercrime and BEC fraud ring
Spanish National Police, with Europol and Interpol, dismantled a network accused of stealing and laundering about €140 million through fake investment platforms, CEO fraud, invoice fraud, and man-in-the-middle attacks, arresting four people across Spain, Portugal, and Panama.
Japan’s largest taxi operator Nihon Kotsu knocked offline by ransomware
Nihon Kotsu confirmed its internal systems were subjected to unauthorized external access and malware infection, forcing it to disconnect systems and shut down its phone dispatch service; the AiLock ransomware group later claimed responsibility and threatened to leak stolen data.
D1R group claims theft from Synopsys and Bosch
The D1R cybercrime group claimed to have stolen valuable data from chipmaker Synopsys and industrial giant Bosch, threatening to leak it unless a ransom is paid.
Identity attacks overtake exploits as the top ransomware entry point
Dark Reading reported a shift in ransomware tactics, with compromised credentials and identity-based attacks now surpassing software exploitation as the leading way ransomware crews get in a trend worth flagging for readers focused on access controls and MFA.
ClickFix social-engineering technique keeps expanding
Security researchers highlighted how the “ClickFix” fake-error social engineering trick tricking users into pasting malicious commands themselves continues to spread across new campaigns, prompting calls for updated user-awareness training.

U.S. Treasury sanctions VPN provider and cryptor seller tied to ransomware
The U.S. sanctioned VPN provider 1VPNS and a cryptor seller for enabling ransomware gangs behind billions of dollars in losses to critical infrastructure.
Fake VPN and 7-Zip apps turn victims into residential proxy nodes
Researchers described a campaign using fake VPN and 7-Zip apps that turn victims’ devices into residential proxy nodes, letting criminals route their traffic through victims’ IP addresses without their knowledge.
Russian state-backed hackers breach cameras along NATO supply routes
Dutch intelligence reported that Russian state-backed hackers compromised internet-connected cameras along military logistics routes in the Netherlands to monitor equipment transfers to Ukraine-a geopolitical/OT-security story.
Strengthen email security with SPF, DKIM, and DMARC to block phishing and domain spoofing.
General Manager
General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.
Secure your email infrastructure
Protect, authenticate, and deliver. Contact our team to find the right solution.