In partnership with

Speak naturally. Send without fixing.

Wispr Flow turns your voice into clean, professional text you can send the moment you stop talking. Not rough transcription you have to clean up. Actual polished text โ€” ready for email, Slack, or any app.

Speak the way you think. Go on tangents. Change your mind mid-sentence. Flow strips the filler, fixes the grammar, and gives you text that reads like you spent five minutes writing it.

89% of messages sent with zero edits. Millions of professionals use Flow daily, including teams at OpenAI, Vercel, and Clay. Works on Mac, Windows, and iPhone.

Cyber Disruption
Coca-Cola says Fairlife ransomware attack halts US dairy production

The beverage giant found that hackers gained entry to systems that control the actual factory equipment.

Operation Stoppage

To control the damage, the company shut down its main digital systems.

This move immediately paused the manufacturing lines across the United States, though the factories located in Canada remain open and working normally.

The safety and quality of the drinks were not harmed during the incident.

Business Impact and Investigation

Company leaders shared the news in an official form with government regulators at the Securities and Exchange Commission.

Experts do not know yet if this shutdown will cause huge financial losses for the business.

Fairlife is a major part of the parent company, bringing in billions of dollars in sales recently.

Security teams brought in outside helpers and told law enforcement about the attack.

Scott Algeier from the Food and Agriculture Information Sharing and Analysis Center noted that the farming and food sector faces many similar threats now.

Cybersecurity researcher Joseph Perry warned that every hour the systems stay offline could cost the company a lot of money.

No hacker group has claimed responsibility for the incident so far.

This incident highlights how digital attacks can quickly freeze real-world factory lines and disrupt everyday supply chains.

Third-Party Risk
Lidl discloses online shop breach after service provider hack

The supermarket giant, which belongs to the Schwarz Group, confirmed that the main online store computers were not broken into directly.

Instead, bad actors found a way into a separate file kept by a helper company.

Stolen Information

Here is a look at what the intruders managed to grab from the system:

  • Customer names and email addresses were taken during the incident.

  • Phone numbers and dates of birth were also part of the stolen records.

  • Customer identification numbers were exposed to the intruders as well.

Lidl explicitly stated that critical details like passwords and bank account numbers are completely safe.

Response Actions

Company leaders quickly shared details about the event with the Dutch Data Protection Authority to follow privacy laws.

At the same time, the technology provider brought in security experts and filed an official report with the police.

The grocery chain is now warning people in Germany, Belgium, and the Netherlands to look out for fake emails or phone scams.

This incident shows that businesses must watch their outside partners closely because a weak partner down the line can expose customer details to digital scams.

๐Ÿ“บ๏ธ Podcast
Building an AI-pilled, solo vibe-coded, Clickhouse-based SIEM

The Origins of Nano SIEM

Longtime security operations expert Dan Lussier created a fully functioning Security Information and Event Management (SIEM) platform called Nano in just two weeks using AI code assistance. Driven by a desire to build a cost-effective, high-scale platform tailored precisely to his ideal design specifications, Lussier initially experimented with Postgres before pivoting to a modern stack built on Rust and ClickHouse. The entire project was bootstrapped out-of-pocket for roughly seven thousand dollars in token and cloud infrastructure costs.

Architectural Strategy and Speed

The platform prioritizes sub-second search speeds and tight resource efficiency, allowing it to run leanly on minimal infrastructure while ingesting substantial daily data volumes. Choosing ClickHouse as the core database engine enables the system to maintain rapid query responses even after absorbing over a hundred terabytes of telemetry data. While initially designed as a tightly coupled, full-stack package, the architecture has since evolved to allow specific components, like the ingestion pipeline, to be decoupled to accommodate air-gapped environments and regional data sovereignty requirements.

Cautious AI-Driven Triage

The system features an integrated AI assistant named Pivot that automates contextual searches and handles initial alert triage using lower-cost language models to preserve budget. It references historical cases and maps identities to endpoint detection and response (EDR) data to streamline investigations for analysts. However, Lussier maintains a cautious stance on automated response, emphasizing that human verification remains absolutely critical for compliance and accountability since AI should not autonomously close cases.

PII Exposure
6.9 million driverโ€™s license numbers stolen from AssuranceAmerica

The major vehicle insurance provider operates across fourteen states through a large network of separate business agents.

The Internal Investigation

Company leaders first spotted the digital intruders inside their corporate computer systems back in March.

A full security review wrapped up in June and showed that the digital thieves successfully copied highly sensitive customer folders.

The stolen files contained the full names, private contact details, and driver license numbers of up to 6.9 million individuals.

The Exposed Data

Beyond basic identity details, the bad actors also took paperwork related to specific vehicle insurance policies and accounts.

The taken files held detailed information about customer cars, active drivers, and individual insurance claims.

Security researchers noted that the entire incident started when a hacker used a targeted trick email to fool a single company worker.

The business has not named a specific hacker group or shared any details about money demands yet.

This incident shows that even a single tricked worker can lead to massive data theft and leave millions of customer records exposed to identity fraud.

Social Engineering
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

Security teams at Elastic Security Labs caught the group trying to drop harmful code inside their own public communication spaces.

Deceptive Coding Tests

The threat actors created fake job postings to trick developers into downloading a mock project for a technical test.

Hidden inside the test folder were ordinary-looking country flag images using the Scalable Vector Graphics format.

The hackers hid broken pieces of encoded code inside the hidden text comments of each image file.

When the developer ran the test application, a script put the hidden image pieces together in alphabetical order to create the real threat.

The Stolen Data

The final payload matches a known tool named OtterCookie that quietly takes control of a computer.

Once active, this tool steals saved internet passwords, grabs local files, and drains digital cryptocurrency wallets.

Not a single antivirus engine detected the hidden code during the initial tests.

This campaign highlights the growing need for companies to isolate test environments for new job candidates to prevent stealthy network intrusions.

Wallet Exploitation
Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets

Security researchers at the firm Coinspect discovered the weakness and named the security flaw Ill Bloom.

The Software Weakness

The problem lies in how older or lesser-known wallet software builds the secret recovery phrases used to back up accounts.

When these applications generate the required list of words, they use weak mathematical randomness that follows a predictable pattern.

Bad actors figured out this pattern, allowing them to calculate the exact secret phrases and unlock the accounts from anywhere.

The Financial Losses

A single organized digital sweep successfully cleared out over three million dollars from hundreds of separate wallets.

Shortly after, the attackers located another exposed wallet and took an additional two million dollars in digital funds.

The total confirmed losses from this specific digital weakness have now passed five million dollars.

Hardware storage devices that keep keys completely offline are not affected by this problem.

This incident highlights the extreme danger of weak security patterns in basic code, proving that poor digital randomness can allow hackers to completely empty financial accounts without breaking into a central network.

โ

Stay safe!

Eyal Estrin, Author @ CSec Weekly