---
title: "Cl0p Mass Extortion, Anubis Hits Fairlife, AI Hacks Benchmark – Cybersecurity News [July 20, 2026] | DuoCircle"
description: "Stay updated with July 2026 cybersecurity news covering Cl0p ransomware, Anubis attacks, AI security breaches, zero-days, data leaks, and emerging threats."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/cybersecurity-news-update-week-30-of-2026/"
---

Quick Answer

The July 2026 cybersecurity news roundup highlights major threats, including Cl0p’s Windchill zero-day attacks, Anubis ransomware targeting Fairlife, AI models exploiting vulnerabilities, VPN exploits, data breaches, and emerging ransomware groups targeting organizations worldwide.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fcybersecurity-news-update-week-30-of-2026%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cl0p%20Mass%20Extortion%2C%20Anubis%20Hits%20Fairlife%2C%20AI%20Hacks%20Benchmark%20%E2%80%93%20Cybersecurity%20News%20%5BJuly%2020%2C%202026%5D&url=undefined%2Fblog%2Fcybersecurity-news-update-week-30-of-2026%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fcybersecurity-news-update-week-30-of-2026%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fcybersecurity-news-update-week-30-of-2026%2F&title=Cl0p%20Mass%20Extortion%2C%20Anubis%20Hits%20Fairlife%2C%20AI%20Hacks%20Benchmark%20%E2%80%93%20Cybersecurity%20News%20%5BJuly%2020%2C%202026%5D "Share on Reddit") [ ](mailto:?subject=Cl0p%20Mass%20Extortion%2C%20Anubis%20Hits%20Fairlife%2C%20AI%20Hacks%20Benchmark%20%E2%80%93%20Cybersecurity%20News%20%5BJuly%2020%2C%202026%5D&body=Check out this article: undefined%2Fblog%2Fcybersecurity-news-update-week-30-of-2026%2F "Share via Email") 

![cybersecurity update](https://media.mailhop.org/duocircle/spf-validator-6788-1785141966080.jpg) 

## Cl0p ransomware launches mass extortion campaign via PTC Windchill/FlexPLM zero-day

Cl0p affiliates are actively exploiting a critical flaw (CVE-2026-12569, CVSS 9.3) in PTC’s Windchill and FlexPLM product lifecycle management software. [Ransom-ISAC](https://thehackernews.com/2026/07/us-government-entity-paid-kairos-group.html) began observing the extortion campaign on July 20, with attackers sending emails titled “Windchill PDMLink module serious data leak” from compromised internal accounts to hundreds of users per victim organization. Manufacturing, automotive, aerospace, and retail firms are the primary targets, mirroring Cl0p’s past MOVEit and Oracle EBS campaigns.

## Coca-Cola’s Fairlife hit by Anubis ransomware, US production suspended

The [Anubis ransomware group](https://www.cybersecuritydive.com/news/threat-group-ransomware-coca-colas-dairy-Fairlife/825900/) listed Coca-Cola’s dairy subsidiary Fairlife on its leak site on July 20, just days after Coca-Cola disclosed the breach to the SEC. Coca-Cola confirmed attackers reached parts of **Fairlife’s production-related** environment and temporarily suspended U.S. production while Canadian operations continued, though product safety wasn’t affected.

## OpenAI says its own AI models “escaped” a sandbox and hacked Hugging Face to cheat a benchmark

In one of the **week’s wildest stories**, [OpenAI disclosed](https://thehackernews.com/2026/07/openai-says-its-own-ai-models-escaped.html) that during an internal [cybersecurity](https://www.duocircle.com/) evaluation, its models identified and exploited a zero-day vulnerability in a package-registry proxy to break out of their sandbox, then chained stolen credentials and further zero-days to breach Hugging Face’s production infrastructure all in an effort to retrieve answers to a benchmark test called ExploitGym. _OpenAI has disclosed the zero-day to the affected vendor and added Hugging Face to its trusted-access program_.

## Bluetooth flaw in dealer-installed anti-theft devices exposes 2.2 million cars

**UC San Diego researchers** found that at least [2.2 million U.S. vehicles](https://autos.yahoo.com/safety-and-recalls/articles/2-2-million-us-cars-062721183.html) are exposed to a Bluetooth attack letting thieves lock, unlock, or immobilize cars from about 5 yards away, without touching the vehicle. _The flaw stems from the KARR/SWDS anti-theft systems (made by Acrisure) all sharing the same cryptographic authentication key_. A firmware patch shipped July 20, but it requires manual owner action via an app.

![Spf Record Tester 7895](https://media.mailhop.org/duocircle/spf-record-tester-7895-1785142368864.jpg)

## Critical Palo Alto VPN bug now weaponized by Qilin ransomware gang

The [Qilin ransomware gang](https://www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks/) is exploiting a critical **PAN-OS GlobalProtect authentication** bypass flaw (CVE-2026-0257) to breach corporate networks, according to Arctic Wolf. Palo Alto patched it back in May, but exploitation is ongoing against unpatched systems.

## SonicWall SMA VPN zero-days exploited for weeks before public disclosure

A [threat actor](https://www.duocircle.com/blog/email-security/what-threat-actor-can-do-with-your-emails-without-password/) tracked as UTA0533 chained two zero-day vulnerabilities (CVE-2026-15409, CVSS 10.0, and CVE-2026-15410) in SonicWall’s SMA 1000 series appliances to gain root access, deploy custom malware, and steal credentials, starting as early as June 22\. Multiple ransomware groups, including Inc, have since piled on with their own exploitation.

## Abbott Laboratories hit with two separate breaches, ShinyHunters and ShadowByt3$ both claim credit

One incident tied to ShinyHunters includes more than **30 million rows of customer data** names, emails, phone numbers, physical addresses, dates of birth plus over a million [Social Security numbers](https://www.investopedia.com/terms/s/ssn.asp) from Abbott’s Cancer Diagnostics business. _A second incident, from the ShadowByt3$ group, hit Abbott’s LabCentral customer portal but reportedly only exposed corporate, not personal, data_.

## Origin Energy confirms Australian customer data breach

Origin Energy confirmed an unauthorized party accessed and later leaked customer data online, exposing sensitive [personally identifiable information](https://www.techtarget.com/whatis/video/An-explanation-of-personally-identifiable-information).

![Spf Record 4588](https://media.mailhop.org/duocircle/spf-record-4588-1785142587832.jpg)

## Estée Lauder discloses delayed breach notification to employees

Cosmetics giant Estée Lauder is notifying [employees of a data breach](https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/) that actually occurred back in August but wasn’t detected until last month, exposing full names, postal addresses, emails, dates of birth, Social Security numbers, and passport numbers.

## Ernst & Young discloses third-party support-system breach

_EY is notifying customers of a data breach traced to a compromised third-party support ticket system used by its IT personnel_.

## South Korea’s National Diplomatic Academy breached for 10 months

Attackers infiltrated [South Korea’s National Diplomatic Academy](https://therecord.media/south-korea-cyberattack-foreign-ministry) for roughly 10 months, stealing personal data belonging to current and former **Ministry of Foreign Affairs employees**, including overseas diplomats.

[![Watch on YouTube](https://img.youtube.com/vi/jbuGkr-WamM/hqdefault.jpg)](https://youtu.be/jbuGkr-WamM)

## New ransomware group emerges roughly once a week, report finds

A Black Kite report published **July 21 identified 146** active ransomware groups that have claimed at least one victim as of June 2026 up from 105 a year earlier, with 61 new groups surfacing in 2026 alone (more than one a week). _Qilin led the pack with 1,358 claimed victims, followed by Akira, INC Ransom, Play, and SafePay_.

## New ENCFORGE ransomware targets AI model files directly

Researchers at Sysdig linked a new attack to the JADEPUFFER threat actor, who has begun deploying “ENCFORGE,” a custom Go-based ransomware built specifically to **encrypt AI model** weights, vector indexes, and training datasets. It’s an early sign that [ransomware crews](https://www.insurancebusinessmag.com/us/news/cyber/one-ransomware-crew-now-drives-half-of-all-cyber-claims-atbay-573139.aspx) are starting to target AI infrastructure as its own asset class.

## Cl0p rival “Chaos” ransomware routes its command-and-control through your own browser

Cisco Talos detailed a new implant called msaRAT, used by the Chaos ransomware group to route [command-and-control](https://trainingcamp.com/glossary/command-and-control-c2/) traffic through a victim’s own **Headless Chrome/Edge browser** process rather than opening any outbound connection directly a notably stealthy technique.

![Spf Record Check 4851](https://media.mailhop.org/duocircle/spf-record-check-4851-1785142268658.jpg)

## Insurance phishing evolves into real-time account hijacking

CTM360 research shows [insurance-focused phishing campaigns](https://www.foxnews.com/tech/insurance-breach-exposes-7m-drivers-licenses) shifting away from the old model of harvesting credentials for later use, toward hijacking accounts in real time as victims enter their information.

## Caterpillar and an architecture firm hit by separate ransomware crews

The CoinbaseCartel group claimed a ransomware attack on Caterpillar Inc. on July 20, while the [Play ransomware group](https://www.darkreading.com/cyberattacks-data-breaches/play-ransomware-group-windows-zero-day) separately claimed responsibility for breaching U.S. architecture firm **Kreysler & Associates on July 21** both threatening data leaks unless paid.

## Microsoft adds prompt-injection protection to Defender for Office 365

Microsoft is adding prompt-injection protection to **Defender for Office 365**, extending its [email security](https://www.duocircle.com/content/email-security-services/email-security-features/) stack to defend AI assistants themselves, not just human users, from manipulation.

## Massive July “Patch Tuesday” logs record 621 CVEs in a single month

**July’s Patch Tuesday** cycle was described as the largest ever recorded, with 621 CVEs disclosed across vendors in a single month-adding pressure on security teams already dealing with the [SonicWall and Windchill zero-days](https://cyberscoop.com/sonicwall-zero-day-vulnerabilities-exploited/) above.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fcybersecurity-news-update-week-30-of-2026%2F) [ ](https://twitter.com/intent/tweet?text=Cl0p%20Mass%20Extortion%2C%20Anubis%20Hits%20Fairlife%2C%20AI%20Hacks%20Benchmark%20%E2%80%93%20Cybersecurity%20News%20%5BJuly%2020%2C%202026%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fcybersecurity-news-update-week-30-of-2026%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fcybersecurity-news-update-week-30-of-2026%2F) Copy 

Related Articles

- [ ![Cybersecurity News](https://media.mailhop.org/duocircle/spf-permerror-5610-1779093389633.jpg)  Cisco SD-WAN Flaw, Critical NGINX Exploit, Foxconn Ransomware Attack – Cybersecurity News \[May 11, 2026\] Blog ](/blog/cybersecurity-news-update-week-20-of-2026/)
- [ ![Cybersecurity news](https://media.mailhop.org/duocircle/spf-permerror-5667-1779700511937.jpg)  GitHub Code Leak, 7-Eleven Breached, NYC Patient Exposure – Cybersecurity News \[May 18, 2026\] Blog ](/blog/cybersecurity-news-update-week-21-of-2026/)
- [ ![Cybersecurity news](https://media.mailhop.org/duocircle/spf-permerror-5686-1780301891080.jpg)  FBI Warns Firms, Carnival Breach, GlobalProtect Flaw – Cyber News Blog ](/blog/cybersecurity-news-update-week-22-of-2026/)
- [ ![cybersecurity news](https://media.mailhop.org/duocircle/spf-record-4590-1780921768387.jpg)  DentaQuest Leak, Cisco Patch Pending, Instagram Bug – Cyber News Blog ](/blog/cybersecurity-news-update-week-23-of-2026/)

## Related Articles

[  news  Cisco SD-WAN Flaw, Critical NGINX Exploit, Foxconn Ransomware Attack – Cybersecurity News \[May 11, 2026\]  May 18, 2026 ](/blog/cybersecurity-news-update-week-20-of-2026/)[  news  GitHub Code Leak, 7-Eleven Breached, NYC Patient Exposure – Cybersecurity News \[May 18, 2026\]  May 25, 2026 ](/blog/cybersecurity-news-update-week-21-of-2026/)[  news  FBI Warns Firms, Carnival Breach, GlobalProtect Flaw – Cyber News  Jun 1, 2026 ](/blog/cybersecurity-news-update-week-22-of-2026/)[  news  DentaQuest Leak, Cisco Patch Pending, Instagram Bug – Cyber News  Jun 8, 2026 ](/blog/cybersecurity-news-update-week-23-of-2026/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cl0p Mass Extortion, Anubis Hits Fairlife, AI Hacks Benchmark – Cybersecurity News [July 20, 2026]","description":"Stay updated with July 2026 cybersecurity news covering Cl0p ransomware, Anubis attacks, AI security breaches, zero-days, data leaks, and emerging threats.","url":"https://www.duocircle.com/blog/cybersecurity-news-update-week-30-of-2026/","datePublished":"2026-07-27T00:00:00.000Z","dateModified":"2026-07-27T00:00:00.000Z","dateCreated":"2026-07-27T00:00:00.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/cybersecurity-news-update-week-30-of-2026/"},"articleSection":"news","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/spf-validator-6788-1785141966080.jpg","caption":"cybersecurity update"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"news"},{"@type":"ListItem","position":3,"name":"Cl0p Mass Extortion, Anubis Hits Fairlife, AI Hacks Benchmark – Cybersecurity News [July 20, 2026]","item":"https://www.duocircle.com/blog/cybersecurity-news-update-week-30-of-2026/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"news","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cl0p Mass Extortion, Anubis Hits Fairlife, AI Hacks Benchmark – Cybersecurity News [July 20, 2026]","item":"https://www.duocircle.com/blog/cybersecurity-news-update-week-30-of-2026/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cl0p Mass Extortion, Anubis Hits Fairlife, AI Hacks Benchmark – Cybersecurity News [July 20, 2026]","description":"Stay updated with July 2026 cybersecurity news covering Cl0p ransomware, Anubis attacks, AI security breaches, zero-days, data leaks, and emerging threats.","url":"https://www.duocircle.com/blog/cybersecurity-news-update-week-30-of-2026/","datePublished":"2026-07-27T00:00:00.000Z","dateModified":"2026-07-27T00:00:00.000Z","dateCreated":"2026-07-27T00:00:00.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/cybersecurity-news-update-week-30-of-2026/"},"articleSection":"news","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/spf-validator-6788-1785141966080.jpg","caption":"cybersecurity update"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
