Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack

2026-07-22T19:23:29Zdfde96c5c8be8bb07066e8c482f5bfb6129096f015c325757a9f40c83979b340
AnubisCISAEverestExchange EOLGenAI riskInfraTrustKratosLangflowOpenAIPhaaSRCESharePointSmartLoaderWordPresscredential stuffingextortionmalwarephishingransomwaresupply chainvulnerabilitieswp2shell

What happened

Batch of high-impact security news: Swiss rail manufacturer Stadler refused a ~$12.3M ransom demand from the Everest ransomware gang after a supplier data-exchange breach; Anubis claims a ransomware attack on Coca‑Cola’s Fairlife; Chick‑fil‑A disclosed credential‑stuffing account breaches. Multiple actively exploited critical vulnerabilities were reported — Microsoft SharePoint (CVE-2026-50522) and the wp2shell WordPress issues (CVE-2026-63030, CVE-2026-60137) — and CISA ordered urgent patching for an actively exploited Langflow RCE. Large-scale abuse and takedowns: the FakeGit operation used

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
dfde96c5c8be8bb07066e8c482f5bfb6129096f015c325757a9f40c83979b340
Enrichment time
2026-07-22T19:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack · Baitaphish