Cover art for Wordpress RCE, New Windows 0-day and Coca-Cola's Fairline ransomed
Cybersecurity Today

Wordpress RCE, New Windows 0-day and Coca-Cola's Fairline ransomed

1mo ago13m
New Windows zero-day, Coca-Cola's Fairlife hit by ransomware, and a core WordPress RCE
David Shipley covers a new Windows zero-day disclosure from "Nightmare Eclipse" called LegacyHive, a local privilege escalation flaw in the Windows User Profile Service that could be weaponized despite a stripped-back public release, as Microsoft investigates and sets a Patch Tuesday record with 570 fixes including two exploited zero-days.
Coca-Cola suspended U.S. production at its Fairlife dairy unit after a ransomware attack, with scope still being assessed and the Food and Ag ISAC warning the sector has seen about 205 attacks this year.
Abbott faces two separate breach claims: ShinyHunters alleges vishing-led SSO compromise and massive data theft from legacy systems, while Shadowbytes claims access via LabCentral credentials, which Abbott disputes as non-sensitive.
The episode also highlights Conti leak revelations about healthcare targeting and details a core WordPress bug chain (WP_2Shell) enabling unauthenticated RCE, now patched in 6.9.5 and 7.0.2.
00:00 Sponsor NordLayer
00:36 Headlines Preview
01:05 Windows Zero Day LegacyHive
03:35 Record Patch Tuesday
04:22 Fairlife Ransomware Shutdown
05:49 Abbott Dual Breach Probes
08:09 Conti Leaks Healthcare Cruelty
09:33 WordPress Core RCE WP 2Shell
11:29 Wrap Up And Listener Notes
12:06 Sponsor Message NordLayer
Loading content...

Read the full transcript

Matterfact has every podcast on Apple Podcasts and Spotify: 700K+ channels, 120M+ episodes.

Already have access? Sign in

Want podcast transcripts in Claude? Subscribe, then follow this guide.Read the guide

The candid version is on a podcast, not the earnings call.

Matterfact turns the conversations your coverage is already having into a searchable, citable record — across every episode, not just this one.