🚨 ACTIVE EXPLOITS & INCIDENTS
-
Coca-Cola Fairlife Subsidiary Hit by Ransomware — BleepingComputer
A ransomware attack has disrupted production at Coca-Cola’s Fairlife dairy operations across the US, causing temporary suspension of product manufacturing. This incident raises concerns over supply chain impacts and potential product shortages. Monitor for related IOCs and ransomware strain details as they emerge. -
ClickLock macOS Malware Forces Password Disclosure — BleepingComputer
New macOS malware named ClickLock kills all visible processes to coerce users into re-entering their system login password, enabling credential theft. This novel social engineering tactic targets macOS endpoints and could bypass typical user vigilance. Immediate endpoint detection and user awareness recommended.
🔓 VULNERABILITIES & CVEs
-
CVE-2026-53410: Zoom Clients for Windows TOCTOU Race Condition — CVE ThreatInt
A time-of-check to time-of-use (TOCTOU) race condition in Zoom Clients’ install/uninstall processes allows authenticated local users to escalate privileges. Affects Windows versions prior to latest patch. CVSS score pending but likely high due to local privilege escalation vector. Immediate patching advised. -
CVE-2026-53409: Zoom Rooms for Windows Improper Privilege Management — CVE ThreatInt
Improper privilege management vulnerability in Zoom Rooms for Windows before version 7.1.0 permits authenticated local users to escalate privileges. Organizations using Zoom Rooms should prioritize upgrading to 7.1.0 or later to mitigate risk. -
CVE-2026-44023: Docling Core Unsafe Remote Filename Resolution — CVE ThreatInt
Docling Core versions 1.5.0 through 2.74.0 inadequately restrict remote filename resolution, potentially enabling remote code execution or file manipulation. Users of Docling document processing should update to 2.74.1 or later immediately. -
CVE-2026-44019: Docling Core Insufficient Validation of Image Reference URIs — CVE ThreatInt
Versions 2.5.0 through 2.74.0 of Docling Core allow local file:// image references without proper validation, risking local file disclosure or injection attacks. Patch to 2.74.1+ to remediate.
🕵️ THREAT RESEARCH & DEEP DIVES
- Anubis Ransomware: Emerging RaaS Threat Targeting Healthcare — Graham Cluley / Fortra
Anubis ransomware-as-a-service (RaaS) campaigns have recently targeted healthcare organizations, employing new TTPs that increase operational impact. While healthcare is a primary victim, other sectors are at risk. Recommended to review detection rules and incident response playbooks for Anubis indicators.
📰 LESSER-KNOWN / UNDER-REPORTED
- None.