Weekly threat intelligence roundup covering major incidents including an Ernst & Young data breach via a third-party IT support platform, a supply chain compromise of the Jscrambler npm package, and a ransomware attack on Coca-Cola's Fairlife subsidiary. AI-related threats include a China-linked campaign using Claude Code and DeepSeek to automate government intrusions, a data-exfiltration flaw in xAI's Grok Build, and a vulnerability in Anthropic's Claude for Chrome extension. On the vulnerability front, Microsoft's July Patch Tuesday addressed a record 622 CVEs, WordPress issued emergency patches for critical RCE flaws (wp2shell), and SonicWall patched two zero-days actively exploited by Inc ransomware. Threat intelligence reports cover ShinyHunters OAuth abuse targeting Salesforce, the CylindricalCanine Chinese cybercrime subgroup, and a new Rust-based ransomware family called Spirals.