Bg Shape
Image

JFrog Confirmed AI Attack, Minnesota Water Attack & Coca-Cola Refuse to Pay

Robert Kehoe
Chief Technology Officer
Published:
August 7, 2026

Three developments worth your attention this week: independent confirmation of the zero-day behind the Hugging Face breach, a ransomware leak affecting a Coca-Cola bottling operation, and a coordinated attack against municipal water infrastructure in Minnesota.

‍

JFrog Patches the Zero-Day Behind the Hugging Face Breach

An update this week on the Hugging Face and OpenAI breach we covered last week. JFrog, the company behind Artifactory, a platform widely used to host Windows binaries, container images, and AI images, has published a patch fixing the specific zero-day vulnerability the attacking agent used to gain internet access before pivoting to attack Hugging Face.

This is a useful third-party validation of the attack details originally reported, and it closes a gap that other organisations running Artifactory should not leave open.

What to do:
Update Artifactory to the latest patched release without delay. If you cannot patch immediately, review outbound internet access from your Artifactory instances and restrict it to what is strictly required.

Coca-Cola Bottler Fairlife Hit by Anubis Ransomware

One terabyte of data has been leaked on the dark web after a Coca-Cola-affiliated business refused to pay a ransomware demand. The Anubis ransomware group exploited Citrix Bleed 2, a vulnerability we have covered on this channel before, to encrypt infrastructure and exfiltrate more than a terabyte of data.

This is a known vulnerability. The fact that it is still being exploited months after disclosure is the real story.

What to do:
Confirm every NetScaler ADC and gateway appliance in your estate is patched to the latest version. Pair patching with active monitoring for exploitation attempts, since patching alone has not been enough to stop this vulnerability being used against organisations that were slow to act.

Coordinated Attack Disrupts Minnesota Water Systems

A large-scale coordinated attack has targeted more than 30 water systems across Minnesota, with at least four confirmed as compromised. One affected municipality has taken its entire water facility offline, leaving a gravity-fed tower system as the only water supply for its roughly 1,800 residents. As of this week, three days on, the system remains down.

What to do:
Any SCADA system, PLC, or other operational technology with internet-facing access should sit behind a firewall or equivalent perimeter defence. Unauthenticated internet exposure lets attackers discover and probe these systems before anyone notices.

Stay safe, and share this with your team.

Read Our Latest Blogs

Blog Image
Citrix NetScaler Mass Exploitation, Cisco's 9.8 CVE & Revolut Breached Again

Citrix NetScaler flaws face mass exploitation within a day of disclosure, Cisco's SD-WAN scores its eighth CVE of the year, and Revolut is breached again via a third-party supplier.

Blog Image
6 best MDR and XDR platforms for MSSPs in 2026

Compare six MDR and XDR platforms for MSSPs on multi-tenancy, compliance mapping and response speed, from CrowdStrike to Smarttech247 VisionX.

Blog Image
Microsoft Emergency Patch, Revolut Breach & Cisco's Second Perfect 10 CVSS

Microsoft rushes an emergency patch after last week's update broke Remote Desktop and hypervisor stability, Revolut discloses a process breach affecting 680+ high-net-worth clients, and Cisco scores another perfect 10 CVSS.

Bg ShapeBg Shape
BLOGS & INSIGHTS

JFrog Confirmed AI Attack, Minnesota Water Attack & Coca-Cola Refuse to Pay

Risk Radar
Vulnerabilities and Exposure
Threat Actors and Campaigns
Robert Kehoe
Chief Technology Officer
August 7, 2026

Three developments worth your attention this week: independent confirmation of the zero-day behind the Hugging Face breach, a ransomware leak affecting a Coca-Cola bottling operation, and a coordinated attack against municipal water infrastructure in Minnesota.

‍

JFrog Patches the Zero-Day Behind the Hugging Face Breach

An update this week on the Hugging Face and OpenAI breach we covered last week. JFrog, the company behind Artifactory, a platform widely used to host Windows binaries, container images, and AI images, has published a patch fixing the specific zero-day vulnerability the attacking agent used to gain internet access before pivoting to attack Hugging Face.

This is a useful third-party validation of the attack details originally reported, and it closes a gap that other organisations running Artifactory should not leave open.

What to do:
Update Artifactory to the latest patched release without delay. If you cannot patch immediately, review outbound internet access from your Artifactory instances and restrict it to what is strictly required.

Coca-Cola Bottler Fairlife Hit by Anubis Ransomware

One terabyte of data has been leaked on the dark web after a Coca-Cola-affiliated business refused to pay a ransomware demand. The Anubis ransomware group exploited Citrix Bleed 2, a vulnerability we have covered on this channel before, to encrypt infrastructure and exfiltrate more than a terabyte of data.

This is a known vulnerability. The fact that it is still being exploited months after disclosure is the real story.

What to do:
Confirm every NetScaler ADC and gateway appliance in your estate is patched to the latest version. Pair patching with active monitoring for exploitation attempts, since patching alone has not been enough to stop this vulnerability being used against organisations that were slow to act.

Coordinated Attack Disrupts Minnesota Water Systems

A large-scale coordinated attack has targeted more than 30 water systems across Minnesota, with at least four confirmed as compromised. One affected municipality has taken its entire water facility offline, leaving a gravity-fed tower system as the only water supply for its roughly 1,800 residents. As of this week, three days on, the system remains down.

What to do:
Any SCADA system, PLC, or other operational technology with internet-facing access should sit behind a firewall or equivalent perimeter defence. Unauthenticated internet exposure lets attackers discover and probe these systems before anyone notices.

Stay safe, and share this with your team.

Robert Kehoe

Chief Technology Officer

Robert is CTO at Smarttech247, leading engineering strategy and delivery across cybersecurity products and services. With over 15 years’ experience in software and security, and CISSP certified, he has led large-scale cloud and security initiatives, including Cloud Protection for Salesforce. Robert focuses on measurable customer outcomes and building empowered, high-performing engineering teams.

Contents:

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365