Cyber News Bytes: What’s Happening in Cybersecurity This Week

This week's latest cybersecurity news and industry updates

Hey all! This week’s cyber news is full of interesting stories that I’m excited to get into.

But before we dive into the news, I want to talk about the part of the job search that quietly decides everything.

If you are sending out fifty applications and finally landing one interview, that single conversation is carrying an enormous amount of weight, and Googling "top 10 cybersecurity interview questions" the night before is not going to be enough to carry it.

That is exactly why I built my Cybersecurity Interview Prep Mastery course.

It is seven modules covering technical interview prep, security design interviews, behavioral questions and the STAR method, plus a full 30 minute mock interview you actually work through yourself instead of just watching.

You also get 100+ sample interview questions, my resume and cover letter guidance, my job search process, and a module on negotiating your offer, because getting the yes is only half of it.

It is built for anyone targeting Security Analyst, SOC Analyst, Security Engineer, Junior Pentester, Compliance, GRC, or ISSO roles, and it is $65 with installment options.

If you have an interview on the calendar, or you are hoping to have one soon, this is the prep I wish someone had handed me early on.

Enroll here and walk in ready. Now, on to this week's stories. →

1. Coca-Cola halts fairlife production across the US after a ransomware attack

Coca-Cola disclosed in a Form 8-K filing with the SEC that a ransomware attack hit its fairlife dairy brand, forcing a temporary suspension of fairlife production across the United States.

Canadian operations were not affected, and the company says product quality and safety were not impacted.

Coca-Cola activated its incident response and business continuity plans, brought in outside cybersecurity advisors, and notified law enforcement.

No ransomware group had publicly claimed responsibility at the time of disclosure.

Why it matters: This is a perfect example of ransomware causing physical business disruption without ever touching the machinery. Food and beverage manufacturers run on perishable inventory and fixed production schedules, so knocking out ordering, labeling, or quality-control systems can stop a plant cold. If you want to work in OT or manufacturing security, this is the exact scenario hiring managers will ask you about.

Read more at Reuters

2. Microsoft ships its largest Patch Tuesday ever with 622 CVEs and two exploited zero-days

Microsoft addressed 622 vulnerabilities in its July security update release, roughly triple the number from June and almost five times the number from May.

Two zero-days are being exploited in the wild: CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint Server.

A third, CVE-2026-50661 in Windows BitLocker, was publicly disclosed but has no confirmed in-the-wild exploitation.

CISA added both exploited flaws to its Known Exploited Vulnerabilities Catalog, giving federal agencies a July 17 deadline for the SharePoint bug and July 28 for the AD FS bug.

Microsoft says the growing patch volume reflects AI models finding more issues across more code, not Windows getting less secure.

Why it matters: AD FS handles enterprise sign-on and SharePoint stores sensitive business data, so a single compromise can hand attackers admin rights or a lasting foothold. Patch volumes like this are the new normal, which means prioritization skills matter more than ever. Knowing how to triage 600 CVEs down to the handful that actually threaten your environment is a genuinely hireable skill.

Read more at BleepingComputer

3. Google and Microsoft pull a popular browser extension with 1.6 million installs

Researchers at Stripe OLT found a hidden, dormant browsing-history collector built into the official, store-signed version of ModHeader, a header-editing extension with roughly 1.6 million combined installs on Chrome and Edge.

The collector could encrypt and exfiltrate visited domains along with full HTTP headers, including any API keys, bearer tokens, or session cookies users pasted into the tool.

No evidence emerged that it had actually been activated.

Microsoft pulled the extension from Edge, Google removed it from the Chrome Web Store, and researchers urged anyone who used it to uninstall and rotate any secrets they entered.

Why it matters: A store signature proves where software came from, not what it does. ModHeader is a developer tool, which means the people most likely to have pasted production API keys into it are the ones with the most access. If you use this one, uninstall it today and rotate anything sensitive.

Read more at The Hacker News

4. Blueprints from India's largest nuclear plant leak through a contractor

The ransomware group World Leaks posted a large cache of files tied to the Kudankulam nuclear power plant, including purported facility blueprints and supplier details.

The data reportedly came from a partial breach at Reliance Group, a plant contractor, on a server hosted by third-party data center provider Yotta.

Nearly 19,000 sensitive files were posted as part of a larger 858,000-file leak, including blueprints, inspection records, equipment reviews, and insurance policies.

Yotta says it spotted suspicious activity on May 29 and believed it had prevented ransomware execution, only learning of the data breach claims weeks later.

Why it matters: Critical infrastructure security is only as strong as the weakest contractor in the supply chain. This one also shows why "we contained it" is not the same as "nothing left the building." Third-party risk management is one of the fastest-growing GRC specialties right now, and stories like this are exactly why.

Read more at Reuters

That's a wrap for this week.

Four very different incidents, and three of them trace back to something outside the victim's own network: a contractor, a hosting provider, a browser extension somebody trusted because it had a signature on it.

The perimeter keeps moving further away from the things you actually control, and the people who can map that sprawl are the ones companies are hiring.

- Sandra