Wordpress RCE, New Windows 0-day and Coca-Cola's Fairline ransomed

Wordpress RCE, New Windows 0-day and Coca-Cola's Fairline ransomed

July 19, 2026 · 13 min

About this episode

The episode discusses a new Windows zero-day, a ransomware attack on Coca-Cola's Fairlife, and a critical WordPress vulnerability.

New Windows zero-day, Coca-Cola's Fairlife hit by ransomware, and a core WordPress RCE David Shipley covers a new Windows zero-day disclosure from "Nightmare Eclipse" called LegacyHive, a local privilege escalation flaw in the Windows User Profile Service that could be weaponized despite a stripped-back public release, as Microsoft investigates and sets a Patch Tuesday record with 570 fixes including two exploited zero-days. Coca-Cola suspended U.S. production at its Fairlife dairy unit after a ransomware attack, with scope still being assessed and the Food and Ag ISAC warning the sector has seen about 205 attacks this year. Abbott faces two separate breach claims: ShinyHunters alleges vishing-led SSO compromise and massive data theft from legacy systems, while Shadowbytes claims access via LabCentral credentials, which Abbott disputes as non-sensitive. The episode also highlights Conti leak revelations about healthcare targeting and details a core WordPress bug chain (WP_2Shell) enabling unauthenticated RCE, now patched in 6.9.5 and 7.0.2. 00:00 Sponsor NordLayer 00:36 Headlines Preview 01:05 Windows Zero Day LegacyHive 03:35 Record Patch Tuesday 04:22 Fairlife Ransomware…

Sponsors

NordLayer

More episodes of Cybersecurity Today

Explore listener stats, chart rankings, contacts and more on the Cybersecurity Today podcast page.