July 17, 2026 by sig9
Hacker Wars - July 17, 2026
Your daily dose of infosec chaos
Ransomware hit your protein shake, CISA is yelling about Fortinet again, macOS malware is getting creative with social engineering, and AI browser extensions are the new attack surface. Just another Thursday in infosec.
Fairlife Ransomware Attack Brings US Dairy Production to a Halt
Coca-Cola’s Fairlife subsidiary got hit by ransomware hard enough to suspend dairy production across the entire United States. The company confirmed the attack disrupted operations and temporarily halted manufacturing of its ultra-filtered milk products. When ransomware stops your supply chain from producing actual food, you know the attackers aren’t messing around.
What to do: Review your OT/IT network segmentation and ensure your incident response plan covers production-line shutdowns, not just data encryption.
CISA Sounds the Alarm on Actively Exploited Fortinet FortiSandbox Flaws
CISA dropped an emergency directive ordering federal agencies to patch two actively exploited vulnerabilities in Fortinet’s FortiSandbox platform by Sunday. The flaws allow attackers to escape the sandbox and potentially compromise the host system. If CISA is setting weekend deadlines, you know it’s serious.
What to do: Patch FortiSandbox immediately. If you can’t patch before the weekend, isolate the management interface and monitor for suspicious sandbox escape attempts.
ClickLock macOS Malware Uses Process Kill Trick to Steal Your Password
A new macOS stealer called ClickLock takes a novel approach to credential theft: it terminates all visible applications, triggering macOS to demand the system password for recovery. The user dutifully types it in, and ClickLock captures it. No zero-day exploits needed, just weaponizing the OS’s own security prompts.
What to do: Be suspicious when your Mac suddenly asks for your password after apps crash unexpectedly. Enable FileVault and consider using a hardware security key for sensitive operations.
Claude Chrome Extension Bug Lets Other Extensions Hijack Your AI
A flaw in Anthropic’s Claude for Chrome extension allows malicious browser extensions to simulate clicks and trigger AI actions without user consent. The attacker could potentially abuse Claude’s access to Gmail, Google Docs, Calendar, and Salesforce. Your AI assistant just became an insider threat with legitimate access to everything.
What to do: Audit your Chrome extensions and remove anything you don’t actively use. Keep the Claude extension updated and review what services it’s connected to.
Until next time, may your logs be clean and your alerts be false positives.
Brought to you by sig9 - sig9.ch | Protecting the unseen, securing the unknown
This bulletin is provided for informational purposes. Contact us for tailored security analysis.