securitylab_nJuly 14, 2026🇷🇺Translated from Russian

Six Weeks of Inactivity and 37 Years of History Lost: Cyberattack Forces German Textile Firm ZEGO into Bankruptcy

A devastating cyberattack has forced the long-established German textile company ZEGO Textilveredelungszentrum into bankruptcy proceedings after nearly six weeks without production, effectively ending 37 years of operations.

The Bavarian firm, which specialized in the finishing and processing of fabrics for the automotive industry, manufacturers of workwear, and producers of technical textiles, was unable to withstand the financial consequences of the prolonged shutdown.

The attack occurred on 29 March 2026 and brought production to a near-complete halt for almost six weeks. Company leadership explored multiple avenues to offset losses and keep the business afloat, but the extended downtime created an overwhelming financial burden that proved impossible to overcome.

Managing Director Johannes Zenglein described the move to seek creditor protection as one of the most painful decisions in the company’s history, stating that the attack had so severely damaged ZEGO’s financial position that continuing operations without insolvency proceedings was no longer viable.

The company has not disclosed the nature of the attack. It remains unknown whether the perpetrators used ransomware, who was responsible, or whether any customer or employee data was accessed. Management has only confirmed that the production stoppage itself placed the enterprise on the verge of closure.

The initiation of bankruptcy proceedings does not necessarily mean the final liquidation of ZEGO. The company intends to maintain production activities while insolvency administrators search for ways to restructure the business, protect jobs, and retain clients and suppliers.

Cyberattacks have previously disrupted factories and production lines, yet companies rarely acknowledge that operational downtime was the direct cause of their collapse. One of the most prominent examples is the bankruptcy of British logistics provider KNP Logistics, which operated for 158 years until attackers gained access via an employee password, encrypted systems, and left more than 700 people without work. Payment of the ransom failed to save the enterprise.

Related articles

BoletimSecRansomware & Extortion

Cl0p Exploits Critical Windchill Vulnerability CVE-2026-12569 to Steal Industrial Designs

The Cl0p extortion group is actively targeting internet-exposed PTC Windchill and FlexPLM servers to exfiltrate engineering projects, technical specifications, and other sensitive data. The campaign focuses on organizations in the industrial, automotive, aerospace, defense, and retail sectors. Attackers leverage the critical remote code execution vulnerability CVE-2026-12569, which stems from unsafe deserialization and carries a CVSS score of 9.8, allowing unauthenticated exploitation over the network. The intrusion chain also combines a WSDL endpoint information disclosure in FlexPLM with a login mechanism weakness in Windchill to gain initial access and execute commands without valid credentials. After compromise, operators deploy JSP web shells to maintain persistence, explore files, and prepare data for exfiltration. Affected systems often contain unreleased product designs, engineering drawings, and strategic manufacturing documents. The activity began in early June 2026, with extortion emails sent to hundreds of employees starting July 20 to increase internal pressure ahead of potential data leaks.

BoletimSecRansomware & Extortion

Chaos Ransomware Group Uses msaRAT Trojan to Hide C2 Traffic Through Invisible Chrome and Edge Browsers

The Chaos ransomware group has adopted a new Rust-based trojan called msaRAT to conceal its command-and-control communications inside legitimate browser sessions. The malware launches Chrome or Edge in invisible mode and controls it via the Chrome DevTools Protocol, keeping all outbound traffic restricted to localhost. It then injects JavaScript to negotiate a WebRTC connection through Cloudflare Workers before routing data over Twilio TURN servers, preventing the attackers' real infrastructure from appearing in network logs. Commands are executed through cmd.exe, and the implant includes queuing mechanisms that support reliable transfer of files, screenshots, and larger data volumes. In the analyzed incident, operators delivered the malware via an MSI installer disguised as a Windows update that loaded the msaRAT DLL directly into memory. The technique does not exploit any vulnerabilities in Chrome or Edge and is designed to blend malicious traffic with normal corporate browser activity.

BoletimSecRansomware & Extortion

Qilin Ransomware Operators Exploit Palo Alto PAN-OS VPN Flaw CVE-2026-0257

Operators linked to the Qilin ransomware group have been actively exploiting an authentication bypass vulnerability in Palo Alto Networks PAN-OS to gain initial access to corporate networks. The attacks, observed in June 2026, targeted the GlobalProtect VPN service running on Palo Alto firewalls and were tracked under CVE-2026-0257. Attackers used specially crafted authentication cookies to establish unauthorized VPN sessions, after which they harvested credentials from Windows LSASS processes and Active Directory NTDS databases. Lateral movement relied heavily on PsExec and administrative shares, supplemented by tools such as AnyDesk, Ngrok, LogMeIn, and NetExec. Before deploying the ransomware binary stored as win.exe in C:\PerfLogs\, the threat actors disabled Microsoft Defender real-time protection and cleared event logs. The vulnerability affects PAN-OS versions 10.2, 11.1, 11.2, and 12.1 as well as certain Prisma Access editions, while Panorama and Cloud NGFW remain unaffected.

BoletimSecRansomware & Extortion

Ransomware Attack Hits Coca-Cola Subsidiary Fairlife, Temporarily Halting US Production Systems

Fairlife, a company owned by Coca-Cola, temporarily suspended production operations in the United States after detecting unauthorized access to parts of its systems in a ransomware incident. The breach, publicly disclosed by Coca-Cola on July 16, 2026, affected environments directly linked to industrial production, prompting an immediate shutdown while investigations and recovery efforts continue. Fairlife manufactures milk, protein beverages, and other dairy products sold across the North American market, making the incident potentially disruptive to product availability, logistics, and internal processes. The company activated its incident response and business continuity protocols and engaged external cybersecurity specialists and consultants to assist with containment, investigation, and system restoration. No information has yet been released regarding data exfiltration, file encryption, or ransom demands, and the full scope of the attack remains under assessment. Coca-Cola has notified law enforcement authorities about the incident, while operations at Fairlife facilities in Canada were confirmed to be unaffected.