20th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, employee details, and other sensitive information submitted while requesting technical assistance. Jscrambler, a JavaScript code-protection package with more than 15,000 weekly downloads, has experienced a supply chain compromise after stolen npm publishing credentials distributed malicious releases. The packages deployed malware targeting developers’, cloud, browser, cryptocurrency, and messaging credentials. Jscrambler removed the affected versions. Coca-Cola’s US dairy subsidiary Fairlife has confirmed a ransomware attack that temporarily halted production across the United States. Attackers accessed systems supporting manufacturing operations, prompting the company to activate incident response and business continuity procedures. Coca-Cola has not confirmed whether data was exfiltrated in the attack. Nihon Kotsu, Japan’s largest taxi operator, has suffered a malware attack following unauthorized access to its internal network. The company shut down affected systems, disrupting taxi dispatches, telephone services, bookings, reservations, and car rentals from July 11. No theft of customer or corporate information has been confirmed. AI THREATS Researchers identified a China-linked campaign that used Claude Code and DeepSeek to automate attacks against government and financial organizations. The tools generated scripts, adapted failed exploits, created credential-harvesting pages, and executed commands. Confirmed compromises affected government systems in Thailand and Afghanistan and organizations in Taiwan. Researchers found that xAI’s Grok Build coding assistant could upload entire Git repositories while processing debugging requests. Transferred information included unopened files and complete commit histories, potentially exposing API keys, credentials, and proprietary source code. Initial privacy controls did not prevent uploads until a server-side restriction was introduced. Researchers verified a weakness in Anthropic’s Claude for Chrome extension that allowed malicious browser extensions to impersonate Claude and act through authenticated user sessions. Successful exploitation could expose Gmail, Google Drive, or GitHub information through Claude’s permissions. Anthropic released fixes, although researchers reported that a bypass remained possible. VULNERABILITIES AND PATCHES Microsoft released patches for 622 vulnerabilities in July’s Patch Tuesday, the largest monthly release recorded by the company. Two vulnerabilities were under active exploitation, including CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services. Both vulnerabilities could allow attackers to elevate privileges. Check Point IPS provides protection against these threats (Microsoft SharePoint Authentication Bypass (CVE-2026-56164)) WordPress has issued emergency updates for CVE-2026-63030 and CVE-2026-60137, collectively called wp2shell. The critical WordPress Core vulnerabilities allow unauthenticated remote code execution and website takeover. Affected releases include versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. Fixed versions include 6.9.5 and 7.0.2. Check Point IPS provides protection against these threats (WordPress Authentication Bypass (CVE-2026-63030)), WordPress SQL Injection (CVE-2026-60137)) SonicWall has released a hotfix for CVE-2026-15409 and CVE-2026-15410, two critical vulnerabilities affecting SMA 1000 Series gateways. The flaws allow unauthenticated attackers to execute system commands on vulnerable appliances. Active exploitation has been associated with Inc ransomware. Check Point IPS provides protection…
AI Analysis
Technical Summary
The report covers a range of cybersecurity threats and vulnerabilities identified in July 2026. It details a data breach at Ernst & Young due to a compromised third-party IT support platform exposing sensitive client and employee data. Jscrambler suffered a supply chain attack distributing malicious npm packages targeting developer and cloud credentials. Coca-Cola's Fairlife experienced a ransomware attack disrupting US production, while Nihon Kotsu faced a malware attack causing operational disruptions without confirmed data theft. AI threats include automated attack tools linked to China and privacy issues in AI coding assistants like xAI's Grok Build and Anthropic's Claude for Chrome extension, with fixes partially applied. Microsoft patched 622 vulnerabilities including two actively exploited privilege escalation flaws (CVE-2026-56164 and CVE-2026-56155). WordPress addressed critical unauthenticated remote code execution vulnerabilities (CVE-2026-63030 and CVE-2026-60137) affecting versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1, fixed in 6.9.5 and 7.0.2. SonicWall released hotfixes for critical command injection vulnerabilities (CVE-2026-15409 and CVE-2026-15410) in SMA 1000 Series gateways, linked to active exploitation by Inc ransomware. Check Point IPS signatures are available for protection against several of these threats.
Potential Impact
The impact includes exposure of sensitive client and employee data from Ernst & Young's breach, potential credential theft from Jscrambler's supply chain compromise, operational disruption and possible data exposure from ransomware at Fairlife, and service disruption at Nihon Kotsu without confirmed data loss. AI-related threats risk exposure of credentials and proprietary code due to privacy weaknesses. Microsoft vulnerabilities allow privilege escalation with active exploitation. WordPress vulnerabilities enable unauthenticated remote code execution and website takeover, posing critical risk to affected sites. SonicWall vulnerabilities permit unauthenticated system command execution, facilitating ransomware attacks. These combined threats affect a wide range of organizations and software environments.
Mitigation Recommendations
Microsoft has released official patches for the identified vulnerabilities, including those under active exploitation; organizations should apply these updates promptly. WordPress has issued emergency updates fixing the critical RCE vulnerabilities; affected sites running versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 should upgrade immediately to 6.9.5 or 7.0.2. SonicWall has provided hotfixes for critical SMA 1000 Series gateway vulnerabilities; affected users must apply these hotfixes. Check Point IPS signatures are available to protect against several of the mentioned threats and should be deployed where applicable. For the AI-related privacy issues, vendor fixes and server-side restrictions have been introduced; users should ensure these updates are applied. Organizations impacted by breaches or ransomware should follow incident response and business continuity procedures as appropriate. Patch status for other vulnerabilities should be confirmed via vendor advisories. No generic mitigations beyond these specific actions are recommended.
20th July – Threat Intelligence Report
Description
For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, employee details, and other sensitive information submitted while requesting technical assistance. Jscrambler, a JavaScript code-protection package with more than 15,000 weekly downloads, has experienced a supply chain compromise after stolen npm publishing credentials distributed malicious releases. The packages deployed malware targeting developers’, cloud, browser, cryptocurrency, and messaging credentials. Jscrambler removed the affected versions. Coca-Cola’s US dairy subsidiary Fairlife has confirmed a ransomware attack that temporarily halted production across the United States. Attackers accessed systems supporting manufacturing operations, prompting the company to activate incident response and business continuity procedures. Coca-Cola has not confirmed whether data was exfiltrated in the attack. Nihon Kotsu, Japan’s largest taxi operator, has suffered a malware attack following unauthorized access to its internal network. The company shut down affected systems, disrupting taxi dispatches, telephone services, bookings, reservations, and car rentals from July 11. No theft of customer or corporate information has been confirmed. AI THREATS Researchers identified a China-linked campaign that used Claude Code and DeepSeek to automate attacks against government and financial organizations. The tools generated scripts, adapted failed exploits, created credential-harvesting pages, and executed commands. Confirmed compromises affected government systems in Thailand and Afghanistan and organizations in Taiwan. Researchers found that xAI’s Grok Build coding assistant could upload entire Git repositories while processing debugging requests. Transferred information included unopened files and complete commit histories, potentially exposing API keys, credentials, and proprietary source code. Initial privacy controls did not prevent uploads until a server-side restriction was introduced. Researchers verified a weakness in Anthropic’s Claude for Chrome extension that allowed malicious browser extensions to impersonate Claude and act through authenticated user sessions. Successful exploitation could expose Gmail, Google Drive, or GitHub information through Claude’s permissions. Anthropic released fixes, although researchers reported that a bypass remained possible. VULNERABILITIES AND PATCHES Microsoft released patches for 622 vulnerabilities in July’s Patch Tuesday, the largest monthly release recorded by the company. Two vulnerabilities were under active exploitation, including CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services. Both vulnerabilities could allow attackers to elevate privileges. Check Point IPS provides protection against these threats (Microsoft SharePoint Authentication Bypass (CVE-2026-56164)) WordPress has issued emergency updates for CVE-2026-63030 and CVE-2026-60137, collectively called wp2shell. The critical WordPress Core vulnerabilities allow unauthenticated remote code execution and website takeover. Affected releases include versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. Fixed versions include 6.9.5 and 7.0.2. Check Point IPS provides protection against these threats (WordPress Authentication Bypass (CVE-2026-63030)), WordPress SQL Injection (CVE-2026-60137)) SonicWall has released a hotfix for CVE-2026-15409 and CVE-2026-15410, two critical vulnerabilities affecting SMA 1000 Series gateways. The flaws allow unauthenticated attackers to execute system commands on vulnerable appliances. Active exploitation has been associated with Inc ransomware. Check Point IPS provides protection…
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The report covers a range of cybersecurity threats and vulnerabilities identified in July 2026. It details a data breach at Ernst & Young due to a compromised third-party IT support platform exposing sensitive client and employee data. Jscrambler suffered a supply chain attack distributing malicious npm packages targeting developer and cloud credentials. Coca-Cola's Fairlife experienced a ransomware attack disrupting US production, while Nihon Kotsu faced a malware attack causing operational disruptions without confirmed data theft. AI threats include automated attack tools linked to China and privacy issues in AI coding assistants like xAI's Grok Build and Anthropic's Claude for Chrome extension, with fixes partially applied. Microsoft patched 622 vulnerabilities including two actively exploited privilege escalation flaws (CVE-2026-56164 and CVE-2026-56155). WordPress addressed critical unauthenticated remote code execution vulnerabilities (CVE-2026-63030 and CVE-2026-60137) affecting versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1, fixed in 6.9.5 and 7.0.2. SonicWall released hotfixes for critical command injection vulnerabilities (CVE-2026-15409 and CVE-2026-15410) in SMA 1000 Series gateways, linked to active exploitation by Inc ransomware. Check Point IPS signatures are available for protection against several of these threats.
Potential Impact
The impact includes exposure of sensitive client and employee data from Ernst & Young's breach, potential credential theft from Jscrambler's supply chain compromise, operational disruption and possible data exposure from ransomware at Fairlife, and service disruption at Nihon Kotsu without confirmed data loss. AI-related threats risk exposure of credentials and proprietary code due to privacy weaknesses. Microsoft vulnerabilities allow privilege escalation with active exploitation. WordPress vulnerabilities enable unauthenticated remote code execution and website takeover, posing critical risk to affected sites. SonicWall vulnerabilities permit unauthenticated system command execution, facilitating ransomware attacks. These combined threats affect a wide range of organizations and software environments.
Defensive Guidance
Microsoft has released official patches for the identified vulnerabilities, including those under active exploitation; organizations should apply these updates promptly. WordPress has issued emergency updates fixing the critical RCE vulnerabilities; affected sites running versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 should upgrade immediately to 6.9.5 or 7.0.2. SonicWall has provided hotfixes for critical SMA 1000 Series gateway vulnerabilities; affected users must apply these hotfixes. Check Point IPS signatures are available to protect against several of the mentioned threats and should be deployed where applicable. For the AI-related privacy issues, vendor fixes and server-side restrictions have been introduced; users should ensure these updates are applied. Organizations impacted by breaches or ransomware should follow incident response and business continuity procedures as appropriate. Patch status for other vulnerabilities should be confirmed via vendor advisories. No generic mitigations beyond these specific actions are recommended.
Technical Details
- Article Source
- {"url":"https://research.checkpoint.com/2026/20th-july-threat-intelligence-report/","fetched":true,"fetchedAt":"2026-07-20T12:22:17.846Z","wordCount":912}
- Classification
- {"confidence":0.79,"severitySource":"heuristic","classifier":"rss-v2"}
Threat ID: 6a5e12f92a4a8d59890630e1
Added to database: 07/20/2026, 12:22:17 UTC
Last enriched: 08/15/2026, 05:04:57 UTC
Last updated: 09/02/2026, 22:19:15 UTC
Views: 204
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.