CyberSecurity Events for this week: July 17, 2026

Jul 17, 2026Incognito CyberSecurity

By Nemuel Cruz, Incognito CyberSecurity™

Incognito CyberSecurity™ is a local Tucson, Arizona MSP company offering 24/7 services to small businesses across Southern Arizona. Here is what mattered in cybersecurity this week — and what it means if you run a business without a full-time security team.

1. Ransomware shuts down Coca-Cola’s Fairlife dairy production

On July 16, Coca-Cola disclosed that a ransomware attack hit its Fairlife dairy subsidiary and forced it to suspend production across the United States. Fairlife found unauthorized access to production systems, activated its incident response plan, and called in outside experts and law enforcement. Canadian operations were not affected, and the company says product quality and safety were not compromised. No ransomware gang has claimed the attack yet. The lesson for a small business: attackers do not just steal data — they stop you from operating, and a plant that cannot run is losing money every hour it is down.

What to do: Assume ransomware will eventually reach you and plan to recover fast. Keep tested, offline secure data backups that ransomware cannot encrypt, and write down exactly who does what in the first hour of an attack before you need it.

2. CISA warns of actively exploited Microsoft SharePoint flaws

On July 14, CISA urged organizations to harden their on-premises Microsoft SharePoint servers after confirming active exploitation of several flaws, including CVE-2026-45659, a remote code execution bug (CVSS 8.8) caused by deserialization of untrusted data. An attacker with even basic Site Member permissions can run code on an unpatched server. Researchers at Shadowserver counted roughly 10,000 internet-exposed SharePoint servers, with more than 800 still unpatched against these bugs. If you host SharePoint yourself, this is aimed squarely at you.

What to do: Apply Microsoft’s SharePoint updates now and follow CISA’s hardening guidance. If you are not sure whether your server is patched or even internet-exposed, that uncertainty is the problem — proactive server and workstation management keeps critical patches from slipping.

3. Fortinet FortiSandbox flaws added to CISA’s Known Exploited list

On July 16, CISA added Fortinet FortiSandbox vulnerabilities — including CVE-2026-25089, an unauthenticated OS command injection flaw rated as high as CVSS 9.8 — to its Known Exploited Vulnerabilities catalog, with a July 19 patch deadline for federal agencies. “Unauthenticated” means an attacker does not need a password or account; they can send a crafted request to an exposed device and run commands. Security appliances sitting at the edge of your network are prime targets because compromising one gives attackers a foothold inside everything it protects.

What to do: Update FortiSandbox to a fixed version (4.4.9+ or 5.0.6+) right away and make sure management interfaces are not exposed to the open internet. Treat firewalls, VPNs, and other edge gear as part of your core network solutions that need patching on the same schedule as your servers.

4. Auto insurer AssuranceAmerica breach exposes about 7 million people

U.S. auto insurer AssuranceAmerica disclosed a breach affecting roughly 7 million people. Attackers targeted an employee, used the stolen credentials to log in, and made off with names, contact details, driver’s license numbers, policy and account data, vehicle information, and claims records. Notice how the break-in started: not a zero-day exploit, but one worker’s login. That is the most common way small businesses get hit, and it does not take a sophisticated attacker to pull off.

What to do: Turn on multi-factor authentication everywhere — it stops most stolen-password attacks cold — and limit what any single account can reach. A layered set of small business cyber security solutions means one compromised login does not hand over the whole company.

5. Fake “IT support” calls hijack Microsoft 365 accounts

Security firm Okta and Palo Alto Networks’ Unit 42 detailed an extortion crew (tracked as O-UNC-066, also branded “Pink”) that cold-calls employees while pretending to be corporate IT support. On the phone, they walk the victim through what looks like a routine Microsoft Entra passkey setup — but the passkey being registered belongs to the attacker, handing them access to the victim’s Microsoft 365 account even when strong passwords and MFA are in place. The group has hit food and beverage, technology, healthcare, automotive, construction, and aviation firms, then extorts them with a data leak site and 72-hour deadlines.

What to do: Tell your team that real IT will never call and rush them through a security enrollment, and set a rule to verify any such request through a known internal channel first. Pair that human awareness with technical cybersecurity services that flag unusual logins and new device registrations.

6. Moody Bible Institute breach hits 2.3 million supporters

Moody Bible Institute disclosed a breach affecting more than 2.3 million donors, students, alumni, and supporters after the ShinyHunters extortion group published stolen records. The exposed data included names, dates of birth, home addresses, email addresses, and phone numbers — exactly the kind of information used to build convincing phishing and identity-theft scams against the people who trust you. Nonprofits and small organizations are frequent targets precisely because attackers expect their defenses to be thinner.

What to do: Know what personal data you hold, delete what you no longer need, and protect the rest. Encrypting sensitive files and communications through email encryption keeps stolen data far less useful if it ever leaves your walls.

The bottom line

This week’s news came down to the basics done consistently: patch fast, turn on MFA, verify who is really calling, and keep recoverable backups. None of it is exotic, but all of it takes time and attention most small business owners do not have to spare. Incognito CyberSecurity™ is a local Tucson, Arizona MSP company offering 24/7 services to businesses across Southern Arizona.

Want a second set of eyes on your defenses before the next headline is about you? Contact Incognito Cyber Security.

Related

Latest News