Security news.
Today's security news features multiple high-impact data breaches, affecting millions of individuals, alongside new findings on sophisticated malware evasion techniques. Additionally, several tech giants have united to form an AI security alliance, aiming to bolster defenses for AI models.
Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack
Coca-Cola has confirmed a data breach following a ransomware attack by the Anubis cybercrime group on its subsidiary, Fairlife, with threats of data leakage.
DentaQuest Data Breach Potentially Impacts Over 23 Million People
Hackers stole personal and dental health information from DentaQuest’s network in May 2026, potentially affecting over 23 million individuals.
MCBS Data Breach Affects 1.2 Million Individuals
The PEAR ransomware group claimed responsibility for stealing 3 TB of information from medical business management company MCBS, impacting 1.2 million individuals.
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
A China-linked cybercrime group is using the sophisticated Cruciferra crypter, which employs Bring Your Own Vulnerable Driver (BYOVD) and process ghosting techniques, to deliver various malware to Indian taxpayers and finance teams.
MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection
The MedusaHVNC malware-as-a-service operates by launching legitimate browsers on an invisible Windows desktop, enabling covert and persistent remote access.
Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials
Threat actors are compromising public Wi-Fi gateways to target Microsoft 365 accounts of traveling corporate employees by redirecting them to fake login pages.
Nvidia and Tech Giants Launch AI Security Alliance
A new Nvidia-led coalition, including other major tech companies, aims to provide more open tools for testing, auditing, and protecting AI models and agents.
Java Spring Boot "heapdump" Scans Detected
Scans targeting the "/actuator/heapdump" endpoint in Spring Boot applications are being observed, which can expose sensitive debug information including a binary heapdump.