VYPR
advisoryPublished Jul 20, 2026· 1 source

Check Point Research Details July's Cyber Threats: Supply Chain Attacks, Ransomware, and AI-Driven Exploits

Check Point Research's latest bulletin covers a wide array of threats including a Jscrambler supply chain attack, Fairlife ransomware incident, and AI-powered exploits targeting government and financial sectors.

Check Point Research has released its latest threat intelligence report for the week of July 20th, detailing a broad spectrum of cyber threats that have emerged or continued to impact organizations globally. The report highlights significant incidents ranging from supply chain compromises and ransomware attacks to sophisticated AI-driven campaigns and critical software vulnerabilities.

A notable supply chain attack targeted Jscrambler, a popular JavaScript code-protection package downloaded by over 15,000 developers weekly. Malicious releases were distributed after attackers stole npm publishing credentials. These compromised packages deployed malware designed to steal credentials for developers' tools, cloud environments, browsers, cryptocurrencies, and messaging applications. Jscrambler has since removed the affected versions, but the incident underscores the persistent risks within software supply chains.

In the realm of ransomware, Coca-Cola's US dairy subsidiary, Fairlife, confirmed an attack that temporarily halted its production facilities across the United States. Threat actors gained access to systems critical for manufacturing operations, prompting the company to initiate incident response and business continuity protocols. While Fairlife has not confirmed data exfiltration, the disruption to production highlights the significant operational impact of such attacks.

Japan's largest taxi operator, Nihon Kotsu, also fell victim to a malware attack following unauthorized access to its internal network. The company was forced to shut down affected systems, leading to disruptions in taxi dispatches, telephone services, bookings, reservations, and car rentals. As with the Fairlife incident, no theft of customer or corporate information has been confirmed at this time.

The report also sheds light on the evolving use of Artificial Intelligence in cyberattacks. Researchers identified a China-linked campaign that leveraged AI tools like Claude Code and DeepSeek to automate attack processes. These tools were used to generate malicious scripts, adapt failed exploits, create credential-harvesting pages, and execute commands. Confirmed compromises linked to this campaign affected government systems in Thailand and Afghanistan, as well as organizations in Taiwan, demonstrating the growing threat of AI-augmented cyber operations.

Furthermore, the report details several critical vulnerabilities that have been addressed. Microsoft's July Patch Tuesday included the largest monthly release on record, patching 622 vulnerabilities, with two actively exploited: CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services, both allowing privilege escalation. WordPress issued emergency updates for CVE-2026-63030 and CVE-2026-60137 (wp2shell), critical vulnerabilities enabling unauthenticated remote code execution and website takeover. SonicWall also released a hotfix for two critical vulnerabilities (CVE-2026-15409 and CVE-2026-15410) in its SMA 1000 Series gateways, which allow unauthenticated command execution and have been associated with Inc ransomware.

Additional research highlighted in the bulletin includes findings on the xAI Grok Build coding assistant's potential to upload entire Git repositories, a weakness in Anthropic's Claude for Chrome extension that allowed impersonation, and the ShinyHunters group's abuse of OAuth application approvals to access Salesforce environments. The report also analyzed CylindricalCanine, a subgroup linked to the DigiCert compromise, and documented Spirals, a Rust-based ransomware family used in a rapid attack against an IT services company.

Check Point Research's "2026 AI Security Report" is also highlighted, indicating a shift in AI's role from an attack aid to an active operator in intrusions and malware development. The report notes an increase in high-risk GenAI prompts and various AI-related security concerns, including indirect prompt injection and enterprise data exposure.

Synthesized by Vypr AI