20th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, […] The post 20th July – Threat Intelligence Report appeared first on Check Point Research .
AI Analysis
Technical Summary
The 20th July 2026 Threat Intelligence Report details multiple cyber threats and incidents observed during the week. Ernst & Young disclosed a data breach caused by a compromised third-party IT support platform, exposing sensitive support tickets containing client documents and tax information. Jscrambler suffered a supply chain attack distributing malicious JavaScript packages after npm credential theft. Coca-Cola's Fairlife subsidiary experienced a ransomware attack disrupting production, though data exfiltration remains unconfirmed. Japan's Nihon Kotsu faced a malware attack causing operational disruption without confirmed data theft. AI-enabled attacks were identified targeting government and financial sectors in Thailand, Afghanistan, and Taiwan, including automated exploit generation and credential harvesting. Vulnerabilities patched include Microsoft SharePoint and Active Directory Federation Services flaws under active exploitation, critical WordPress Core remote code execution bugs (wp2shell), and SonicWall SMA 1000 Series command execution vulnerabilities linked to ransomware. The report also covers advanced threat actor campaigns abusing OAuth in Salesforce, stolen DigiCert code-signing certificates, and a fast-moving Rust-based ransomware family. Vendor advisories provide patches for known vulnerabilities; however, no direct remediation information is available for the Ernst & Young breach or supply chain compromise.
Potential Impact
The Ernst & Young breach potentially exposed sensitive client and employee data through compromised third-party IT support tickets, risking confidentiality and privacy. The Jscrambler supply chain compromise distributed malware targeting developer and cloud credentials, threatening software supply chain integrity. Coca-Cola's Fairlife ransomware attack caused operational disruption, impacting manufacturing continuity. Nihon Kotsu's malware incident disrupted critical taxi services, affecting business operations. AI-driven attacks compromised government and financial organizations in multiple countries, exposing sensitive systems. Critical vulnerabilities in Microsoft, WordPress, and SonicWall products allow privilege escalation, remote code execution, and system command execution, with some under active exploitation, posing significant risks to affected systems. The abuse of OAuth in Salesforce environments and stolen code-signing certificates further elevate threat levels by enabling persistent access and malware distribution.
Mitigation Recommendations
For disclosed vulnerabilities in Microsoft SharePoint Server (CVE-2026-56164), Active Directory Federation Services (CVE-2026-56155), WordPress Core (CVE-2026-63030, CVE-2026-60137), and SonicWall SMA 1000 Series (CVE-2026-15409, CVE-2026-15410), official patches and hotfixes have been released and should be applied promptly. Check Point IPS provides protection against these threats. For the Ernst & Young breach and Jscrambler supply chain compromise, no direct remediation is stated; affected organizations should follow incident response best practices and monitor vendor advisories for updates. Coca-Cola and Nihon Kotsu have activated incident response and business continuity measures. AI-related threat mitigations include applying vendor fixes for Anthropic's Claude extension and monitoring for suspicious OAuth application approvals. Organizations should verify the revocation status of DigiCert certificates and ensure secure code-signing practices. Patch status for the breaches and supply chain attacks is not explicitly confirmed; users should consult vendor advisories for current guidance.
20th July – Threat Intelligence Report
Description
For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, […] The post 20th July – Threat Intelligence Report appeared first on Check Point Research .
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 20th July 2026 Threat Intelligence Report details multiple cyber threats and incidents observed during the week. Ernst & Young disclosed a data breach caused by a compromised third-party IT support platform, exposing sensitive support tickets containing client documents and tax information. Jscrambler suffered a supply chain attack distributing malicious JavaScript packages after npm credential theft. Coca-Cola's Fairlife subsidiary experienced a ransomware attack disrupting production, though data exfiltration remains unconfirmed. Japan's Nihon Kotsu faced a malware attack causing operational disruption without confirmed data theft. AI-enabled attacks were identified targeting government and financial sectors in Thailand, Afghanistan, and Taiwan, including automated exploit generation and credential harvesting. Vulnerabilities patched include Microsoft SharePoint and Active Directory Federation Services flaws under active exploitation, critical WordPress Core remote code execution bugs (wp2shell), and SonicWall SMA 1000 Series command execution vulnerabilities linked to ransomware. The report also covers advanced threat actor campaigns abusing OAuth in Salesforce, stolen DigiCert code-signing certificates, and a fast-moving Rust-based ransomware family. Vendor advisories provide patches for known vulnerabilities; however, no direct remediation information is available for the Ernst & Young breach or supply chain compromise.
Potential Impact
The Ernst & Young breach potentially exposed sensitive client and employee data through compromised third-party IT support tickets, risking confidentiality and privacy. The Jscrambler supply chain compromise distributed malware targeting developer and cloud credentials, threatening software supply chain integrity. Coca-Cola's Fairlife ransomware attack caused operational disruption, impacting manufacturing continuity. Nihon Kotsu's malware incident disrupted critical taxi services, affecting business operations. AI-driven attacks compromised government and financial organizations in multiple countries, exposing sensitive systems. Critical vulnerabilities in Microsoft, WordPress, and SonicWall products allow privilege escalation, remote code execution, and system command execution, with some under active exploitation, posing significant risks to affected systems. The abuse of OAuth in Salesforce environments and stolen code-signing certificates further elevate threat levels by enabling persistent access and malware distribution.
Mitigation Recommendations
For disclosed vulnerabilities in Microsoft SharePoint Server (CVE-2026-56164), Active Directory Federation Services (CVE-2026-56155), WordPress Core (CVE-2026-63030, CVE-2026-60137), and SonicWall SMA 1000 Series (CVE-2026-15409, CVE-2026-15410), official patches and hotfixes have been released and should be applied promptly. Check Point IPS provides protection against these threats. For the Ernst & Young breach and Jscrambler supply chain compromise, no direct remediation is stated; affected organizations should follow incident response best practices and monitor vendor advisories for updates. Coca-Cola and Nihon Kotsu have activated incident response and business continuity measures. AI-related threat mitigations include applying vendor fixes for Anthropic's Claude extension and monitoring for suspicious OAuth application approvals. Organizations should verify the revocation status of DigiCert certificates and ensure secure code-signing practices. Patch status for the breaches and supply chain attacks is not explicitly confirmed; users should consult vendor advisories for current guidance.
Technical Details
- Article Source
- {"url":"https://research.checkpoint.com/2026/20th-july-threat-intelligence-report/","fetched":true,"fetchedAt":"2026-07-20T12:22:17.846Z","wordCount":912}
Threat ID: 6a5e12f92a4a8d59890630e1
Added to database: 07/20/2026, 12:22:17 UTC
Last enriched: 07/20/2026, 12:22:30 UTC
Last updated: 07/21/2026, 02:30:35 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.