MCS Tech Services Monthly Cyber Threat Briefing · August 2026
July was one of the busier months we’ve tracked this year: a household-name manufacturer had to halt US production because of ransomware, Microsoft’s flagship collaboration platform was hit with a wave of zero-days, and federal agencies issued back-to-back warnings about attackers scanning for weak network hardware. None of this is designed to alarm you — it’s meant to give you a clear picture of what happened last month and what it should change about how you think about IT security. Here are the five developments we think every Hudson Valley business owner and IT decision-maker should know about.
1. A ransomware attack stopped a $1 billion dairy brand cold
On July 16, Coca-Cola disclosed that its dairy subsidiary fairlife had suffered a ransomware attack serious enough to force a temporary shutdown of all US production facilities. The Anubis ransomware group later claimed responsibility, saying it had stolen roughly 1 terabyte of data, and by July 28 Coca-Cola confirmed data had in fact been taken. Production has since resumed, but the incident shows how a cyberattack on IT systems can ripple straight into physical operations — halting a manufacturing line, not just locking a database.
Why it matters: if your business has any dependency between IT systems and physical production or logistics, an attacker doesn’t need to touch your equipment directly to stop it. They just need to compromise the systems that support it.
2. Microsoft SharePoint had its worst month in years
July brought what researchers are calling SharePoint’s “fourth zero-day in a month.” CISA added multiple actively exploited SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog, including CVE-2026-58644, a critical flaw so severe that CISA gave federal agencies just three days to patch instead of the usual three weeks. Making matters worse, SharePoint Server 2016 and 2019 officially lost Microsoft’s extended support on July 14 — the same day the July patch batch shipped — meaning any new vulnerabilities found in those versions going forward may never get an official fix.
Why it matters: if your business still runs an on-premises SharePoint Server on one of those older versions, you’re now maintaining infrastructure the vendor has effectively stopped supporting, right as attackers are actively targeting the platform.
3. Healthcare ransomware is climbing, and the whole ecosystem is a target
A July report from Comparitech found ransomware attacks on healthcare organizations worldwide rose nearly 14% in the first half of 2026, with the United States recording more attacks than any other country. Notably, attacks on healthcare-adjacent businesses — medical billing companies, device makers, health tech vendors — rose even faster than attacks on hospitals themselves, up 35% and 11% respectively depending on the segment. HHS’s Health Sector Cybersecurity Coordination Center (HC3) continues to flag credential theft and identity-based attacks, including from state-linked groups, as a persistent driver of these incidents in its standing threat guidance for the health sector.
Why it matters for healthcare clients specifically: attackers are increasingly going after your vendors and billing partners, not just your front door. A billing company or device vendor breach can expose your patients’ data just as easily as a direct hit on your own network.
4. Russian state-sponsored hackers are scanning for weak routers
CISA, the NSA, FBI, and 17 allied international agencies issued a joint advisory (AA26-194A) warning that Russian state-sponsored group FSB Center 16 is actively scanning the internet for routers and network devices running outdated SNMP configurations or default credentials, then quietly maintaining access. The advisory specifically named energy, healthcare, government, financial services, and communications as the most targeted sectors.
Why it matters: this isn’t a sophisticated zero-day attack — it’s basic network hygiene that many businesses assume is “handled” without ever verifying it. Old router firmware and default settings are exactly what this campaign is built to find.
5. A widely used WordPress vulnerability is being actively exploited
Two new WordPress Core vulnerabilities, nicknamed “wp2shell” (CVE-2026-60137 and CVE-2026-63030), were disclosed and immediately exploited in the wild, allowing an anonymous attacker to chain the flaws into full remote code execution on a stock WordPress install with no plugins required. WordPress.org pushed forced automatic updates to affected sites, but security researchers note site owners should still verify their installation actually updated.
Why it matters: a huge share of small business websites run on WordPress. If yours does and marketing, lead generation, or e-commerce depends on it, this is worth a direct check rather than an assumption.
What this means for your business
Taken together, July’s headlines point to the same lesson from different directions: speed and hygiene matter more than sophistication. Most of these incidents didn’t require exotic techniques — they exploited unpatched software, outdated network settings, or vendors that hadn’t been vetted. That is exactly the kind of risk that’s manageable with the right ongoing process, but very hard to manage reactively while also running a business.
This is the gap MCS Tech Services closes for clients across the Hudson Valley. Our managed IT and cybersecurity services include proactive patch management (so a SharePoint or WordPress emergency doesn’t catch you off guard), 24/7 monitoring and endpoint detection, network and router hardening against exactly the kind of scanning campaigns CISA warned about this month, vendor risk awareness, backup and disaster recovery planning, and compliance support for healthcare, manufacturing, government, and professional services clients.
If July’s threat landscape left you wondering how exposed your own business might be, that’s worth a conversation. Reach out to MCS Tech Services for a no-pressure review of where you stand today — and where the gaps might be before an attacker finds them first.
Sources
Coca-Cola – Official announcement of fairlife ransomware event: https://investors.coca-colacompany.com/news-events/press-releases/detail/1166/the-coca-cola-company-announces-technology-disruption-involving-fairlife-operations
Help Net Security – Coca-Cola confirms hackers stole data in Fairlife ransomware attack: https://www.helpnetsecurity.com/2026/07/28/coca-cola-fairlife-dairy-subsidiary-ransomware-attack/
SecurityWeek – Ransomware group threatening to leak data stolen from Coca-Cola’s Fairlife: https://www.securityweek.com/ransomware-group-threatening-to-leak-data-stolen-from-coca-colas-fairlife/
Cloud Security Alliance – SharePoint zero-day CVE-2026-58644 joins CISA KEV under 3-day deadline: https://labs.cloudsecurityalliance.org/research/csa-research-note-sharepoint-cve-2026-58644-kev-20260717-csa/
Becker’s Hospital Review – Healthcare ransomware attacks up 14%: 5 things to know: https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/healthcare-ransomware-attacks-up-14-5-things-to-know/
HHS HC3 – Analyst Note: New Spear Phishing Campaign by Midnight Blizzard (standing healthcare-sector threat guidance): https://www.hhs.gov/sites/default/files/new-midnight-blizzard-campaign-analyst-note-tlpclear.pdf
Peter Bassill – The week in cyber, 13 to 17 July 2026 (CISA/NSA/FBI advisory AA26-194A on Russian router targeting): https://www.peterbassill.com/writing/the-week-in-cyber-13-to-17-july-2026
AboutDFIR – Infosec News Nuggets, July 21, 2026 (WordPress wp2shell exploitation): https://aboutdfir.com/infosec-news-nuggets-july-21-2026/