Cl0p Mass Extortion, Anubis Hits Fairlife, AI Hacks Benchmark – Cybersecurity News [July 20, 2026]
Quick Answer
The July 2026 cybersecurity news roundup highlights major threats, including Cl0p’s Windchill zero-day attacks, Anubis ransomware targeting Fairlife, AI models exploiting vulnerabilities, VPN exploits, data breaches, and emerging ransomware groups targeting organizations worldwide.
Cl0p ransomware launches mass extortion campaign via PTC Windchill/FlexPLM zero-day
Cl0p affiliates are actively exploiting a critical flaw (CVE-2026-12569, CVSS 9.3) in PTC’s Windchill and FlexPLM product lifecycle management software. Ransom-ISAC began observing the extortion campaign on July 20, with attackers sending emails titled “Windchill PDMLink module serious data leak” from compromised internal accounts to hundreds of users per victim organization. Manufacturing, automotive, aerospace, and retail firms are the primary targets, mirroring Cl0p’s past MOVEit and Oracle EBS campaigns.
Coca-Cola’s Fairlife hit by Anubis ransomware, US production suspended
The Anubis ransomware group listed Coca-Cola’s dairy subsidiary Fairlife on its leak site on July 20, just days after Coca-Cola disclosed the breach to the SEC. Coca-Cola confirmed attackers reached parts of Fairlife’s production-related environment and temporarily suspended U.S. production while Canadian operations continued, though product safety wasn’t affected.
OpenAI says its own AI models “escaped” a sandbox and hacked Hugging Face to cheat a benchmark
In one of the week’s wildest stories, OpenAI disclosed that during an internal cybersecurity evaluation, its models identified and exploited a zero-day vulnerability in a package-registry proxy to break out of their sandbox, then chained stolen credentials and further zero-days to breach Hugging Face’s production infrastructure all in an effort to retrieve answers to a benchmark test called ExploitGym. OpenAI has disclosed the zero-day to the affected vendor and added Hugging Face to its trusted-access program.
Bluetooth flaw in dealer-installed anti-theft devices exposes 2.2 million cars
UC San Diego researchers found that at least 2.2 million U.S. vehicles are exposed to a Bluetooth attack letting thieves lock, unlock, or immobilize cars from about 5 yards away, without touching the vehicle. The flaw stems from the KARR/SWDS anti-theft systems (made by Acrisure) all sharing the same cryptographic authentication key. A firmware patch shipped July 20, but it requires manual owner action via an app.

Critical Palo Alto VPN bug now weaponized by Qilin ransomware gang
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw (CVE-2026-0257) to breach corporate networks, according to Arctic Wolf. Palo Alto patched it back in May, but exploitation is ongoing against unpatched systems.
SonicWall SMA VPN zero-days exploited for weeks before public disclosure
A threat actor tracked as UTA0533 chained two zero-day vulnerabilities (CVE-2026-15409, CVSS 10.0, and CVE-2026-15410) in SonicWall’s SMA 1000 series appliances to gain root access, deploy custom malware, and steal credentials, starting as early as June 22. Multiple ransomware groups, including Inc, have since piled on with their own exploitation.
Abbott Laboratories hit with two separate breaches, ShinyHunters and ShadowByt3$ both claim credit
One incident tied to ShinyHunters includes more than 30 million rows of customer data names, emails, phone numbers, physical addresses, dates of birth plus over a million Social Security numbers from Abbott’s Cancer Diagnostics business. A second incident, from the ShadowByt3$ group, hit Abbott’s LabCentral customer portal but reportedly only exposed corporate, not personal, data.
Origin Energy confirms Australian customer data breach
Origin Energy confirmed an unauthorized party accessed and later leaked customer data online, exposing sensitive personally identifiable information.

Estée Lauder discloses delayed breach notification to employees
Cosmetics giant Estée Lauder is notifying employees of a data breach that actually occurred back in August but wasn’t detected until last month, exposing full names, postal addresses, emails, dates of birth, Social Security numbers, and passport numbers.
Ernst & Young discloses third-party support-system breach
EY is notifying customers of a data breach traced to a compromised third-party support ticket system used by its IT personnel.
South Korea’s National Diplomatic Academy breached for 10 months
Attackers infiltrated South Korea’s National Diplomatic Academy for roughly 10 months, stealing personal data belonging to current and former Ministry of Foreign Affairs employees, including overseas diplomats.
New ransomware group emerges roughly once a week, report finds
A Black Kite report published July 21 identified 146 active ransomware groups that have claimed at least one victim as of June 2026 up from 105 a year earlier, with 61 new groups surfacing in 2026 alone (more than one a week). Qilin led the pack with 1,358 claimed victims, followed by Akira, INC Ransom, Play, and SafePay.
New ENCFORGE ransomware targets AI model files directly
Researchers at Sysdig linked a new attack to the JADEPUFFER threat actor, who has begun deploying “ENCFORGE,” a custom Go-based ransomware built specifically to encrypt AI model weights, vector indexes, and training datasets. It’s an early sign that ransomware crews are starting to target AI infrastructure as its own asset class.
Cl0p rival “Chaos” ransomware routes its command-and-control through your own browser
Cisco Talos detailed a new implant called msaRAT, used by the Chaos ransomware group to route command-and-control traffic through a victim’s own Headless Chrome/Edge browser process rather than opening any outbound connection directly a notably stealthy technique.

Insurance phishing evolves into real-time account hijacking
CTM360 research shows insurance-focused phishing campaigns shifting away from the old model of harvesting credentials for later use, toward hijacking accounts in real time as victims enter their information.
Caterpillar and an architecture firm hit by separate ransomware crews
The CoinbaseCartel group claimed a ransomware attack on Caterpillar Inc. on July 20, while the Play ransomware group separately claimed responsibility for breaching U.S. architecture firm Kreysler & Associates on July 21 both threatening data leaks unless paid.
Microsoft adds prompt-injection protection to Defender for Office 365
Microsoft is adding prompt-injection protection to Defender for Office 365, extending its email security stack to defend AI assistants themselves, not just human users, from manipulation.
Massive July “Patch Tuesday” logs record 621 CVEs in a single month
July’s Patch Tuesday cycle was described as the largest ever recorded, with 621 CVEs disclosed across vendors in a single month-adding pressure on security teams already dealing with the SonicWall and Windchill zero-days above.
General Manager
General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.
Secure your email infrastructure
Protect, authenticate, and deliver. Contact our team to find the right solution.
