Ransomware Stops the Milk, Windows Has a New Unfixed Hole
Friday, July 17, 2026 · 5-minute read
The European Commission just handed Google a hard deadline. Under the Digital Markets Act, Google must let competing AI assistants access Android's camera, microphone, screen content, and wake-word activation — the same powers its own Gemini assistant already has. The order kicks in with Android 18, due no later than August 1, 2027. Google must also share anonymised Search data with rival search engines and AI chatbots at a cost-based fee.
About 60% of European mobile users run Android. This means someone could soon set a non-Google AI as their default assistant and have it work just as deeply as Gemini does today. These are binding requirements, not fines — but separate penalty proceedings are still possible if Google drags its feet.
↗ The Hacker NewsArmenia has held a Russian tourist named Aleksandr Ermakov since June 28, after U.S. authorities flagged him at Yerevan's airport as a wanted ransomware suspect. The problem: his lawyers say the U.S. wants a different Aleksandr Ermakov — one sanctioned by Australia, the U.S., and the UK in 2024 for stealing nearly 10 million records from Australian insurer Medibank Private and leaking them on the dark web. That suspect is reportedly already serving a sentence inside Russia and is barred from leaving. The man in the Armenian cell is from Omsk and shares only his name.
↗ The Hacker NewsTwo key members of the Scattered Spider cybercrime collective have each been sentenced to five years and six months in prison. Their crime: hacking Transport for London in 2024, disrupting the city's transit systems and stealing customer data. The sentencing is one of the more significant outcomes in a string of prosecutions targeting this group, which has also been linked to attacks on MGM Resorts and other large organizations.
↗ BleepingComputerA piece of infostealer malware called ACR Stealer is making the rounds in a particularly sneaky way. It uses a technique called ClickFix: you see what looks like a system error, you're told to paste a fix into Windows' Run box, and the moment you press Enter, you've handed the attacker the keys. Once in, ACR Stealer grabs your saved browser passwords, active login session tokens (which let attackers log in as you without needing your password), plus PDFs and Microsoft 365 documents — including files synced from OneDrive and SharePoint. Microsoft's security team watched this campaign grow across customer networks from late April to mid-June 2026. One variant runs almost entirely in memory, leaving very few traces for security tools to catch.
Researchers at Kaspersky have uncovered a previously unknown malware called GoSerpent, actively targeting government agencies and diplomatic missions across Southeast Asia since late 2025. The malware is built for long-term, quiet access — it phones home to an external server, drops additional tools over time, and focuses on harvesting sensitive files and login credentials without raising alarms. In May 2026, the attackers upgraded their toolkit with new tools that helped them secretly move collected data off compromised networks through shared network folders. The goal appears to be ongoing espionage rather than financial theft.
A security researcher going by "Nightmare Eclipse" published a working zero-day exploit called LegacyHive this week. It lets an attacker take full admin control of a Windows machine — even one that's fully up to date. The flaw involves Windows' registry system (a core settings database), and the researcher released working exploit code publicly, meaning anyone with moderate skills can now use it.
Status: No patch available yet. Microsoft has not issued a fix as of this publication. Avoid running untrusted software and ensure your account does not have local administrator privileges for day-to-day use — that limits what an attacker can do even if they get in.
Progress Software confirmed that a zero-day vulnerability in its ShareFile product is what forced the company to shut down its Storage Zone service. ShareFile is widely used by businesses and law firms to share large sensitive files. CISA also issued a separate alert urging organisations to harden their SharePoint environments following new exploitations this week — a reminder that file-sharing platforms are prime targets.
Status: Progress has shut down the affected Storage Zone service. If your organisation uses ShareFile on-premises, apply any available patches immediately and check CISA's SharePoint hardening guidance.
CISA ordered U.S. government agencies to patch two vulnerabilities in Fortinet's FortiSandbox platform on an urgent timeline. FortiSandbox is used to analyse potentially dangerous files — ironically, the tool meant to catch threats now has active flaws being exploited against it. Both vulnerabilities are confirmed as actively targeted in the wild.
Status: Patches are available from Fortinet. If your organisation runs FortiSandbox, update immediately. Federal agencies have a mandatory deadline to comply.
Microsoft's monthly security update — known as Patch Tuesday — is a big one this month. The company pushed out fixes for 570 vulnerabilities across Windows, Office, and other products, including patches for three zero-days that were already being exploited before today. This is one of the largest single-month patch releases Microsoft has ever issued. If you have Windows automatic updates turned on, your machine will grab these on its own. If you manage systems manually — check now.
A newly discovered malware for Mac computers called ClickLock takes an unusual approach. Instead of hiding quietly in the background, it deliberately crashes every visible app on your screen, forcing a situation where you feel compelled to enter your Mac login password to "fix" things — and then steals that password the moment you do. It's a social engineering trick baked right into the malware itself. Mac users should be suspicious any time all their apps suddenly close and they're prompted to authenticate.
You might have noticed Fairlife products — the high-protein milk and shakes owned by Coca-Cola — disappearing from store shelves this week. The reason isn't a supply chain issue or ingredient shortage. A ransomware attack hit the Fairlife dairy subsidiary and forced it to temporarily halt all U.S. production. Coca-Cola confirmed the attack publicly on Thursday.
Here's how these attacks typically work: criminals break into a company's computer network, move quietly through it for days or weeks, and then simultaneously lock up the computers that run the business — in this case, likely the systems controlling production scheduling, inventory, and logistics at Fairlife's facilities. Without those systems, you can't run a modern dairy operation. It's the digital equivalent of someone stealing every key in the building and changing all the locks overnight.
For regular people, this is a reminder that ransomware isn't just a problem for banks and hospitals. It hits food production, water treatment, shipping, and any other industry that now runs on computers — which is all of them. The ripple effect reaches your grocery cart. Fairlife is one of the most popular protein milk brands in the U.S., and production disruptions like this can take weeks to recover from even after systems are restored, because physical manufacturing lines don't restart at the push of a button.
Watch for Coca-Cola to say more about whether data was stolen (ransomware gangs often steal data before locking systems, to use as additional leverage for payment). Also watch whether this attack is claimed by a known group — attribution could point to a broader campaign targeting the food and beverage sector, which CISA has flagged as an increasingly attractive target for criminal ransomware operators.