Supply Chain Attack
Cyberattack on Nichirei Logistics Disrupts KFC Japan and Cold-Chain Deliveries
A cold-chain cyberattack ripples into KFC Japan and supermarket supplies — supply-chain sector-advisory coverage this week.
Supply Chain Attack
A cold-chain cyberattack ripples into KFC Japan and supermarket supplies — supply-chain sector-advisory coverage this week.
Data Breaches
A scale-significant airline-industry disclosure traced to a tech-support scam — sector-advisory coverage this week, based on early single-source reporting that Qantas has yet to fully detail.
Nation-State Cyber Threats
Another Sandworm-attributed technique lands from CERT-UA — end-user awareness and defender posture review this week for Ukraine-adjacent organizations.
Vulnerabilities
F5's July patch cycle continues — defender verification across NGINX and BIG-IP deployments this week.
Malware
A novel macOS stealer technique with credential-and-crypto targeting — defender posture review for Mac-issuing organizations this week.
Vulnerabilities
A CVSS 9.8 Zoom Windows flaw and companion Splunk patches — defender teams verify across enterprise deployments this week.
Policy & Government
The biggest cybercrime conviction in UK history — Scattered Spider's TfL attackers face five-and-a-half years, and the £29M cost lands as a defender-team reminder this week.
Policy & Government
A US indictment against Russian bulletproof hosting operators — law-enforcement continuation coverage this week.
Vulnerabilities
CISA raises the SharePoint patch stakes — three actively exploited flaws, two of them zero-days, and defender teams accelerate verification this week.
Vulnerabilities
A three-week pre-disclosure exposure window for the SonicWall SMA zero-days — defender teams review the timeline this week.
Vulnerabilities
A Windows User Profile Service PoC drops the same day as Patch Tuesday — the researcher's fourth CyberSignal-tracked disclosure this cycle, and a defender review for this week.
Supply Chain Attack
Another JavaScript-ecosystem supply-chain compromise, confirmed by four vendors: four @asyncapi npm packages were observed distributing a multi-stage botnet loader, and all five malicious versions have since been pulled from npm — defender inventory work this week.