AI and IT News Recap: July 17, 2026: Ransomware Curdles Coca-Cola's Fairlife, Moonshot's Kimi K3 Undercuts Fable, and Claude for Chrome Springs a Leak

By Noah Smith, Owner & Consultant, KeyChange Technologies · July 17, 2026

Pen-and-ink editorial illustration of a dairy bottling line at a standstill: a giant wrench jams the machine's gears, milk bottles are backed up on a stopped conveyor, milk spills onto the floor, and a worker in an apron stands helplessly with hands on head.

Your daily scan of the AI and IT news that actually touches how you run a business. Six stories today, from a household-name ransomware shutdown to a new open model that undercuts the frontier on price.

📌 The AI and IT news at a glance

  • 🥛 Ransomware halts Coca-Cola's Fairlife: A cyberattack forced Coca-Cola to suspend all US production at its $4 billion Fairlife dairy brand.
  • 🤖 Moonshot's Kimi K3 undercuts Fable: China's Moonshot AI shipped a 2.8-trillion-parameter open model that claims near-Fable performance at a third of the price.
  • 🛡️ Claude for Chrome springs a leak: Researchers say two unpatched flaws let rogue browser extensions silently trigger Claude to read your Gmail, Docs, and Calendar.
  • ⏰ CISA sets a Saturday deadline on Oracle: Federal agencies must patch an actively exploited Oracle E-Business Suite takeover bug by July 18.
  • ⚖️ Scattered Spider duo jailed over TfL: Two young hackers got five and a half years each for the 2024 Transport for London attack.
  • 🧰 Anthropic reworks Claude Code and memory: A broad Claude Code update and a new categorized memory system landed for developers and everyday users.

🔝 Top story: Ransomware forces Coca-Cola to halt Fairlife production

Coca-Cola disclosed on July 16 that its dairy subsidiary Fairlife was hit by a ransomware attack that reached production-related systems, and as a result the company has temporarily suspended all US production of the brand. Fairlife, which posted roughly $4 billion in sales in 2024, makes ultra-filtered milk and the popular Core Power protein shakes, so a full US production stop is a serious supply disruption for a fast-growing part of Coca-Cola's portfolio. The company said it activated its incident response and business continuity plans, brought in outside cybersecurity experts, and notified law enforcement. Canadian production was not affected, and Coca-Cola stressed that product quality and safety were not impacted.

The disclosure came through an SEC 8-K filing, which is notable in itself: a material-event filing signals that a beverage giant now treats a factory-floor ransomware hit as a shareholder-level event. Attackers increasingly go after operational technology and production systems, not just office data, because halting a physical line creates maximum pressure to pay. As of the disclosure, Coca-Cola had not named the threat actor or said whether a ransom was demanded.

In short: A ransomware attack on Coca-Cola's Fairlife dairy has suspended all US production of a $4 billion brand while the company investigates.

What it means for your business: If a company Coca-Cola's size can have a production line frozen by ransomware, any operation with connected machinery or logistics is exposed. Segmenting production systems from office networks and rehearsing a "we lost the plant" continuity plan is no longer optional.

My take: The scary part here is not the data, it is the shutdown. Ransomware crews have figured out that stopping the physical thing you sell is far more coercive than leaking a spreadsheet. If your business depends on machines that talk to a network, assume that network is a target and ask your IT team one blunt question: what happens to the shop floor if the servers go dark tomorrow?

Source: TechCrunch


🤖 AI

Moonshot's Kimi K3 undercuts the frontier on price

China's Moonshot AI released Kimi K3 on July 16, a new-architecture Mixture-of-Experts model with roughly 2.8 trillion total parameters and a 1-million-token context window, making it one of the largest open-weight models available. Two variants shipped at launch, K3 Max for chat and agent tasks and K3 Swarm Max for large-scale parallel work, initially through Kimi Code and the Kimi app. Moonshot says the model performs competitively with Anthropic's Fable 5, currently among the most capable models on the market, and it is aimed squarely at long-horizon coding and agent workloads.

The headline for buyers is price. Kimi K3 runs about

5 per million output tokens, versus roughly $50 for the comparable Fable tier, and Moonshot has said it will release the full model weights publicly on July 27. That combination of a claimed frontier-class model, aggressive pricing, and open weights continues the pattern of Chinese labs pressuring US incumbents on cost rather than raw capability alone.

In short: Moonshot AI launched Kimi K3, a 2.8-trillion-parameter open model that claims near-Fable performance at roughly a third of the output-token price.

What it means for your business: Cheaper capable models mean the cost of building AI features into your products keeps falling. If you are pricing an AI project around today's frontier API rates, the ground is shifting under you every few weeks.

My take: Benchmark claims from any lab, US or Chinese, deserve a healthy squint until independent testers weigh in. But the pricing pressure is real and it is good for you as a buyer. Do not lock into a single model provider for anything you can keep portable. The most valuable position right now is being able to swap the engine underneath your AI features when a cheaper, equally good one shows up, and one just did.

Source: Fortune

On the watch: Google's Gemini 3.5 Pro has been widely reported to target a July 17 launch after a full architectural rebuild, but as of this writing Google has not officially confirmed a date, pricing, or specs. We will cover it properly once it is real. (TechTimes)


🛡️ IT and security

Unpatched Claude for Chrome flaw lets rogue extensions read your Gmail

Researchers at Manifold Security say two vulnerabilities in Anthropic's Claude for Chrome extension let a malicious browser extension silently trigger Claude to perform sensitive actions, using as little as six lines of JavaScript. The core issue is in Claude's content script, which listens for a click on an onboarding button but never verifies that the click was genuinely user-initiated. Any other extension with script access on claude.ai, a common permission, can forge that click and set off one of nine hardcoded prompts, which include reading recent Gmail messages, opening the user's most recent Google Doc, checking calendar availability, and creating meetings, all without the user knowing.

Manifold first reported the problems in May 2026 and says they remained reproducible in version 1.0.80, released July 7, with the vulnerable code effectively unchanged across several releases. The takeaway is bigger than one extension: as AI agents get standing permission to act inside your email and documents, a flaw that lets someone else pull the trigger turns a productivity tool into a data-exfiltration path.

In short: Manifold researchers say two still-unpatched Claude for Chrome flaws let any rogue browser extension silently make Claude read a victim's Gmail, Docs, and Calendar.

What it means for your business: AI browser assistants inherit access to everything you are logged into. If your team uses agentic extensions, treat their permissions like admin credentials and be strict about what else you let run in the same browser.

My take: This is the double edge of handing an AI agent the keys to your inbox. The convenience is real, but so is the blast radius when something goes wrong. Until agentic browser tools mature, I would keep them in a dedicated browser profile that is not signed into your most sensitive accounts, and I would keep the extension roster in that profile ruthlessly short. Fewer tenants, fewer ways for one to abuse another.

Source: The Hacker News

CISA orders federal agencies to patch an Oracle takeover bug by Saturday

CISA has told US federal civilian agencies to patch an actively exploited Oracle E-Business Suite vulnerability by Saturday, July 18. The flaw, tracked as CVE-2026-46817, sits in the File Transmission component of Oracle Payments and lets an unauthenticated attacker with HTTP network access take over the system in a low-complexity attack. CISA added it to its Known Exploited Vulnerabilities catalog on July 15 and is enforcing the deadline under Binding Operational Directive 26-04.

The exposure is not trivial. Shadowserver is tracking more than 1,000 internet-exposed Oracle EBS instances, over half of them in the United States. Oracle E-Business Suite runs core financial, procurement, and payments processes at large organizations, so a takeover of the Payments module is close to a worst case for the businesses that rely on it.

In short: CISA is forcing federal agencies to patch an actively exploited Oracle E-Business Suite flaw (CVE-2026-46817) that allows full system takeover by July 18.

What it means for your business: If you run Oracle EBS, especially anything internet-facing, treat this as an emergency patch, not a routine one. Attackers are already exploiting it, and a compromise here reaches your payments and financial data directly.

My take: CISA deadlines are aimed at federal agencies, but they are the closest thing the private sector gets to a free "drop everything" alarm. When CISA gives its own agencies days rather than weeks, that is your cue too. If Oracle EBS touches your money, ask whoever owns it to confirm the patch is on today, then verify it themselves rather than take a shrug for an answer.

Source: BleepingComputer

Two Scattered Spider hackers jailed over the Transport for London attack

Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on July 16 for the 2024 cyberattack on Transport for London. The pair, linked to the Scattered Spider collective, broke into TfL's systems in late August and early September 2024, leaving 148 systems inoperable and forcing all 27,000 TfL employees to reset their passwords in person. Prosecutors put the losses and recovery costs at £29 million.

Both had pleaded guilty last month under Section 3ZA of the UK's Computer Misuse Act, the law's most serious offense, admitting they were reckless as to whether they created a significant risk of serious damage to human welfare. The CPS says they are believed to be the first hackers successfully prosecuted under that provision, a signal that courts are starting to treat attacks on critical public infrastructure as more than white-collar crime.

In short: Two Scattered Spider-linked hackers received five and a half years each for the 2024 Transport for London attack that cost an estimated £29 million.

What it means for your business: The people behind Scattered Spider-style attacks favor social engineering, tricking help desks and employees, over exotic exploits. The defense that keeps working is boring: strong identity verification and staff who know not to reset a password on a convincing phone call.

My take: Real prison time for young social engineers is a shift worth noting, but do not let it lull you. Scattered Spider's whole method is talking their way past your people, not hacking your firewall. Sentences deter some, but the fix that protects you is on your side of the phone: verify who is actually calling before anyone resets a credential or approves an MFA prompt.

Source: The Record


🧰 New tools and tooling

Anthropic reworks Claude Code and gives Claude a smarter memory

Anthropic shipped a broad Claude Code update on July 16 aimed at developers, with smarter navigation and login flows, new /doctor and gateway support, stronger safety prompts, and a batch of performance fixes. Two are quietly meaningful for anyone running long agent sessions: returning to a Claude agent no longer silently kills its running subagents and restarts from scratch, so in-progress work now carries over, and auto-update downloads stream to disk instead of buffering in memory, cutting the updater's peak memory use by roughly 400 MB.

On the consumer side, Claude's memory was also reworked the same day. Instead of a single daily summary, Claude now keeps a set of individual, categorized entries that it reads and updates during conversations, which should make it recall context more precisely across sessions. Together the two updates point at the same goal: making AI assistants steadier and more reliable over long, ongoing work rather than just impressive in a one-off chat.

In short: Anthropic released a wide Claude Code update for developers and replaced Claude's daily memory summary with richer categorized memory entries.

What it means for your business: These are the unglamorous reliability improvements that decide whether AI tools actually stick in a team's workflow. Better memory and steadier long-running sessions mean less babysitting and more real work getting finished.

My take: The interesting trend in AI tooling right now is not flashier demos, it is durability. Fixing a bug where an agent throws away its own work, or trimming memory use so the tool does not choke, is what moves AI from "fun to try" to "safe to depend on." When you evaluate AI tools for your team, weight reliability over the highlight reel. The tool that finishes the job unattended beats the one that dazzles for five minutes.

Source: Anthropic release notes


Yesterday's edition: AI and IT News Recap: July 16, 2026.