La semana en noticias sobre filtraciones

This week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned organizations about several Microsoft SharePoint vulnerabilities that are actively being exploited in the wild. Meanwhile, cyberattacks continue to disrupt organizations across multiple industries, with major incidents affecting Coca-Cola’s dairy subsidiary fairlife, U.K.-based health care technology firm Craneware, Latin American energy producer Ecopetrol and Japan’s largest cold-chain operator, Nichirei Logistics Group.

Norteamérica

Microsoft SharePoint

Sector: Tecnología Vulnerabilidad: Vulnerabilidad de día cero

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned organizations about several Microsoft SharePoint vulnerabilities that are actively being exploited or pose significant security risks. The advisory highlights the need for organizations using on-premises SharePoint Server to promptly assess their exposure and apply available security updates.

CISA stated that it is aware of active exploitation of the following vulnerabilities, which enable threat actors to gain unauthorized access to on-premises SharePoint Server instances.

  • CVE-2026-32201: An improper input validation vulnerability that allows an attacker to perform spoofing over a network.
  • CVE-2026-45659: A remote code execution vulnerability involving the deserialization of untrusted data that allows an authorized attacker to execute code over a network.
  • CVE-2026-56164: A missing authentication for a critical function vulnerability in Microsoft Office SharePoint that allows an attacker to elevate privileges over a network.
  • CVE-2026-58644: A remote code execution vulnerability that allows an unauthorized attacker to execute code over a network.
  • CISA has also identified CVE-2026-55040, a newly disclosed vulnerability that is not yet known to have been exploited but poses a potential risk if left unpatched. The weakness involves improper authentication in Microsoft Office SharePoint, allowing an unauthorized attacker to bypass a network security feature.

The latest advisory reflects a steady stream of new SharePoint vulnerabilities, including both pre-disclosure zero-day exploitation and longer-tail n-day exploitation.

Fuente

Cómo puede afectar a su empresa

The continued discovery and exploitation of these flaws underscore the importance of timely patching and ongoing monitoring for organizations that rely on on-premises SharePoint environments. CISA advises security teams to rotate Internet Information Services (IIS) machine keys and check for signs of compromise, including machine key harvesters. Organizations should also avoid exposing SharePoint directly to the internet and block external access to SharePoint Central Administration. Here’s a SharePoint hardening guide from Microsoft to strengthen your SharePoint security posture.

Estados Unidos

fairlife

Sector: Agricultura y alimentación Explotación: Ransomware y malware

On July 16, Coca-Cola disclosed a ransomware attack on its dairy subsidiary, fairlife, that disrupted operations and temporarily halted production of fairlife products across the U.S.

In a filing with the U.S. Securities and Exchange Commission (SEC), Coca-Cola said fairlife detected unauthorized access to some of its systems, including production-related systems, in connection with the ransomware attack. The company confirmed that production at fairlife’s U.S. facilities has been temporarily suspended while it responds to the incident and restores impacted systems. However, Coca-Cola said the ransomware attack has not affected product quality or safety.

Meanwhile, the Anubis ransomware gang has listed fairlife on its dark web leak site and is threatening to publish data, adding pressure on the company as it continues its response and recovery efforts.

Fuente

Cómo puede afectar a su empresa

Ransomware attacks can have consequences far beyond data theft. As this incident demonstrates, they can disrupt production, interrupt business operations and delay the delivery of products and services, resulting in financial losses and operational downtime. To reduce the impact of these attacks, organizations should combine proactive monitoring with a robust business continuity and disaster recovery (BCDR) strategy. Maintaining ransomware-resilient backups and regularly testing recovery processes can help organizations restore critical systems quickly and continue business operations with minimal disruption following a ransomware attack.

Estados Unidos

Craneware

Industry: Health care Exploit: Hacking

On July 20, U.K.-based health care technology firm Craneware disclosed that it is responding to a cyberattack that may have exposed a significant volume of customer data.

Craneware develops health care billing and revenue cycle management software used by thousands of clinics, hospitals and pharmacies across the U.S. The company’s software helps health care providers bill patients for services and processes large volumes of medical records and patient data on behalf of its customers. In a statement filed with the London Stock Exchange, Craneware said the attackers appear to have been removed from its systems, but its investigation into the incident remains ongoing.

The incident has raised concerns across the U.S. health care sector because of the potential scale of patient data that could be affected. To put that into perspective, when Craneware acquired Florida-based pharmacy software provider Sentry in 2021, the company said it gained access to Sentry’s 147 million patient records collected over two decades.

Fuente

Cómo puede afectar a su empresa

Cybercriminals are increasingly targeting technology companies that provide software and services to the health care sector. By compromising these providers, attackers can gain access to vast amounts of sensitive medical and health-related data and use the threat of public disclosure to extort organizations. Companies that develop software or provide services to the health care industry should strengthen their cyber defenses with continuous monitoring, strong access controls, regular vulnerability management and a well-tested incident response plan to reduce the risk and impact of these attacks.

América Latina y el Caribe

Ecopetrol

Sector: Energía y recursos naturales Vulnerabilidad: ransomware y malware

Colombian energy giant Ecopetrol disclosed that thousands of user accounts were affected by a ransomware attack.

The Latin American energy producer said a ransomware attack resulted in the theft of data from 3,300 user accounts. However, the attackers were unable to deploy ransomware or disrupt the company’s day-to-day operations due to its existing security controls. Ecopetrol also said the stolen files were pseudonymized, suggesting the information may have limited value to the attackers.

Meanwhile, reports indicate that an unidentified threat actor contacted Ecopetrol and demanded a ransom payment. However, no details have been disclosed about the amount demanded or whether any of the stolen data has been released publicly.

Fuente

Cómo puede afectar a su empresa

This incident demonstrates how robust security controls can limit the impact of a ransomware attack. Although attackers stole data, security measures prevented ransomware from encrypting the company’s systems, allowing it to maintain normal operations. Some of the measures organizations can take to strengthen their resilience against ransomware include implementing continuous security monitoring, enforcing multifactor authentication, applying security patches promptly, segmenting critical systems, maintaining ransomware-resilient backups and regularly testing incident response and recovery plans.

Asia y Pacífico

Nichirei Logistics Group

Industry: Agriculture & Food Exploit: Hacking

A cyberattack on Japan’s largest cold-chain operator, Nichirei, has had a ripple effect across the country’s food supply chain, disrupting the distribution of frozen and refrigerated products.

On July 13, Nichirei Logistics Group, which transports frozen and refrigerated food for about 5,000 customers across Japan, experienced a system outage. On July 16, the company confirmed that hackers had breached its servers. To contain the attack and protect customer data, Nichirei disconnected key systems, bringing parts of its logistics network to a standstill. The attack disrupted warehouse operations and frozen food shipments.

The disruption quickly spread across the restaurant industry, with more than 1,300 KFC restaurants and other major restaurant chains facing ingredient shortages and struggling to keep up with deliveries.

Fuente

Cómo puede afectar a su empresa

Cyberattacks on critical supply chain providers can have far-reaching consequences across multiple industries. A single attack on a logistics provider can disrupt operations for thousands of customers, interrupt the delivery of essential goods and create cascading operational and financial impacts throughout the supply chain. Organizations should strengthen supply chain security by assessing third-party cyber risks, continuously monitoring critical vendors, implementing strong security controls across interconnected systems and ensuring business continuity plans account for disruptions affecting key suppliers and service providers.

¿Te gusta lo que lees?

Suscríbete ahora para recibir cada semana noticias e información sobre seguridad en tu bandeja de entrada

Próximos webinars y eventos

Participa en nuestros próximos eventos y seminarios web para conocer las opiniones de los expertos, estrategias prácticas y las últimas tendencias en ciberseguridad.

INKY Tech Jam: From flagged to fixed – mastering email analysis & threat response

August 20, 2026 11:00 AM EDT

Learn how to investigate, analyze and resolve suspicious emails with confidence in this INKY Tech Jam. Discover how to use the Observations page, understand mail flow architecture and manage quarantine effectively to diagnose issues faster and strengthen email security for your clients or corporate users.

Regístrese ahora

Kaseya Security quarterly product innovation update

August 25, 2026 11:00 AM EDT

Discover the latest innovations across Kaseya’s integrated security portfolio in this exclusive quarterly product update. Learn how new AI-powered capabilities, deeper platform integrations and enhanced detection, response, visibility and protection features are helping MSPs and corporate IT teams strengthen security while reducing operational complexity.

Regístrese ahora