TechCrunch · Jul 16
Coca-Cola halted all US Fairlife production after ransomware hit OT systems
Coca-Cola disclosed in an SEC filing that a ransomware attack reached production-related systems at its Fairlife subsidiary, temporarily suspending all US output of the roughly $4 billion dairy brand while Canadian operations continued. No threat group was named and no restoration timeline was given.
▸ The MSP Angle
Can ransomware actually stop a company from making its product?
It just stopped a multibillion-dollar brand's entire US line. For clients with any operational technology, plant floors, logistics, physical processes, the breach is not an IT inconvenience, it is lost revenue by the hour. Segment OT from IT, test restores against a production-down scenario, and price business-continuity work against the number this makes concrete.
Read at TechCrunch ↗
BleepingComputer · Jul 17
Ernst & Young breach traces back to a third-party IT support platform
EY disclosed that an unauthorized party accessed a third-party ITSM support-ticket platform used by its tax practice between March 28 and April 12, downloading attachments with client tax and financial data. EY is offering 24 months of credit monitoring, underscoring how much sensitive data pools in support systems.
▸ The MSP Angle
Am I exposed when a vendor or tool I rely on gets breached?
A support-ticket system took down data security at one of the largest accounting firms on earth, and MSPs run ticketing systems for a living. Your PSA, your documentation tool, your RMM: each holds client secrets and each is a target. Inventory what lives in every third-party platform you touch, and make vendor breach response part of the service you sell, not an afterthought.
Read at BleepingComputer ↗
BleepingComputer · Jul 14
SonicWall VPN zero-days rated CVSS 10 were exploited before disclosure
SonicWall patched two actively exploited SMA 1000 flaws, an SSRF rated CVSS 10.0 and a post-auth command injection, on models 6210, 7210, and 8200v. Volexity tracked attackers stealing credentials, session databases, and TOTP MFA seeds, and CISA ordered federal agencies to remediate by July 17.
▸ The MSP Angle
Why do VPN appliances keep getting hit first?
Because they sit at the edge holding the keys, and this crew walked off with MFA seeds, which means stolen second factors too. Edge appliances need their own patch SLA, out-of-band, faster than the rest of the fleet. After a credential-and-seed theft like this, rotating passwords is not enough; MFA re-enrollment is the real cleanup.
Read at BleepingComputer ↗
BleepingComputer · Jul 16
CISA orders emergency patching of an exploited Oracle E-Business Suite flaw
CISA gave federal agencies until July 18 to patch CVE-2026-46817, an unauthenticated Oracle EBS Payments flaw rated CVSS 9.8 and exploited since June 29. Shadowserver counts more than 1,000 exposed instances, over half in the US, with the fix shipped in Oracle's May update that many customers never applied.
▸ The MSP Angle
How do critical patches sit unapplied for months?
The fix existed in May; attackers had it since June; and 1,000-plus instances are still open in July. That gap is the whole problem, and it is a service. Clients running big ERP and finance systems rarely patch on their own cadence. A managed patch program with proof of what was applied and when is exactly what turns this headline into a retainer.
Read at BleepingComputer ↗
Socket · Jul 11
A hijacked npm package pushed an infostealer that hunts AI-tool credentials
Attackers used stolen publishing credentials to ship malicious jscrambler releases with an install hook that deployed a Rust infostealer targeting AWS, GCP, and Azure credentials, CI tokens, crypto wallets, and API keys stored by Claude Desktop, Cursor, and VS Code. Socket flagged it within six minutes, but 1,479 malicious downloads landed first.
▸ The MSP Angle
Can a software dependency steal my AI tools' credentials?
This one specifically raided the API keys that AI coding tools leave on developer machines, a new prize in an old attack. If your team or your clients build anything, the developer laptop is now a credential vault worth stealing. Lock down build pipelines, pin dependencies, and keep AI-tool keys out of plaintext config where a preinstall script can grab them.
Read at Socket ↗
TechCrunch · Jul 15
Mira Murati's Thinking Machines ships its first open model, Inkling
Thinking Machines Lab released Inkling, an open-weight 975-billion-parameter mixture-of-experts model with about 41 billion active parameters, claiming roughly a third of the token usage of a rival model on coding. The startup monetizes through its Tinker customization platform rather than the model itself.
▸ The MSP Angle
Do new open models change what MSPs can offer?
Every capable open model widens the menu you can run for clients without locking them to one vendor's pricing or terms. The catch is that open weights are ingredients, not a service; the value is in hosting, governing, and supporting them safely. Model-agnostic delivery means a launch like this is an option to add, not a platform to rebuild.
Read at TechCrunch ↗
SecurityWeek · Jul 21
Empirical Security raises $25M to predict which CVEs attackers will exploit
Empirical Security, founded by Kenna Security veterans and an EPSS co-creator, raised a $25 million Series A ($37 million total) for AI exploit-prediction products that track more than 18,000 exploited CVEs to help teams prioritize which flaws to fix first as vulnerability volume climbs.
▸ The MSP Angle
How do I prioritize patching when everything is critical?
You cannot patch it all, so the win is patching what will actually be attacked. Exploit-prediction is where remediation is heading: rank by real-world exploitation likelihood, not raw CVSS. Whether you buy a tool or build the discipline, a defensible prioritization method is what lets a lean team credibly promise patch coverage across many clients.
Read at SecurityWeek ↗
Crunchbase News · Jul 17
AI and cyber take most of the week's biggest venture rounds
Machine-identity vendor Keyfactor took $1 billion from Summit Partners and AI-chip maker SambaNova raised a $1 billion Series F, with AI claiming five of the week's ten largest US venture rounds. Capital keeps concentrating in AI infrastructure and identity security.
▸ The MSP Angle
Where is the smart money going in AI and security?
A billion dollars into machine identity is a tell: as agents proliferate, the hard problem becomes proving who and what is allowed to act. That is a client conversation you can start now, because agent identity and access will land on your desk long before the funded products mature. Watch what gets built here; it becomes your toolset in 18 months.
Read at Crunchbase News ↗
Google Workspace Updates · Jul 16
Gmail's AI writing tool adds free-form custom editing prompts
Google replaced Gmail's preset Help me write refinements with a prompt bar that accepts custom natural-language editing instructions, plus undo and redo, rolling out to rapid-release Workspace domains from July 16 with completion targeted around July 20.
▸ The MSP Angle
Should I worry about new AI writing features in my clients' email?
Not alarm, but oversight. Every new free-form AI prompt in a client tool is another place company data flows into a model, often switched on by default and invisible to the admin who should be deciding. Know which AI features are live in each tenant you manage, decide per client whether they belong on, and put that decision in writing rather than discovering it after the fact.
Read at Google Workspace Updates ↗