
Arista fixes exploited VeloCloud Orchestrator zero-day
Arista released an emergency patch for a maximum-severity vulnerability in VeloCloud Orchestrator that attackers were already exploiting in the wild.
Incidents, vulnerabilities, abuse and certificates.

Arista released an emergency patch for a maximum-severity vulnerability in VeloCloud Orchestrator that attackers were already exploiting in the wild.

HSTS-Enforced inverts the current HTTPS opt-in model, making encrypted connections the default while requiring explicit, verifiable exceptions for HTTP. The change aims to eliminate downgrade attacks but must preserve compatibility with legacy systems still reliant on unencrypted transport.

The Russian hacking group Laundry Bear is exploiting a previously patched Zimbra Collaboration vulnerability alongside phishing to compromise email servers, according to a CISA advisory.

An ongoing outage affecting Microsoft Teams, SharePoint, Excel, and the Microsoft 365 Admin Center began earlier today, with no resolution timeline provided.

Security researchers discovered a vulnerability in OpenAI's ChatGPT workspace agents that allowed attackers to silently create and control malicious AI agents using a single link. The flaw, patched in June, enabled agents to act with the victim's permissions across connected corporate systems.

Check Point has issued a hotfix for a zero-day vulnerability in its SmartConsole GUI that attackers were already exploiting in the wild.

Iran's Revolutionary Guard claims to have struck an Amazon Web Services data center in Bahrain with cruise missiles, marking a potential escalation in targeting commercial cloud infrastructure during Middle Eastern hostilities. AWS has not confirmed the attack or damage.

The US government has filed a civil forfeiture action to seize the domain Egypt.com, claiming it was purchased with cryptocurrency linked to the now-defunct Abacus Market darknet marketplace. The complaint alleges the domain was acquired through a US brokerage and registrar using funds traced to drug trafficking operations.

OVH deployed emergency fixes for the Januscape guest-host escape vulnerability across its infrastructure, rebooting tens of thousands of hosts to protect roughly one million virtual machines after testing the process in Australia.

Cloudflare has activated Web Application Firewall protections for two high-severity WordPress vulnerabilities—an unauthenticated remote code execution flaw and a SQL injection issue—affecting versions 6.8 and later. The rules block attack attempts while sites apply patches released in WordPress 7.0.2 and backported versions.

Arelion's 2026 report identifies the Aisuru botnet as the source of 33% of DDoS traffic on its AS1299 backbone, highlighting the growing scale and economic impact of compromised consumer devices on global network defense.

Three Russian nationals face US federal charges for allegedly running a bulletproof hosting service used by ransomware gangs, causing over $62 million in damages worldwide.

SonicWall has released emergency fixes for two zero-day vulnerabilities in its SMA1000 secure access gateways after observing active exploitation. No customer impact details have been disclosed.

Cybersecurity agencies from the United States and eight partner countries have released a coordinated advisory detailing Russian state-sponsored attacks on critical infrastructure via vulnerable network routers. The alert provides mitigation guidance for operators.

Progress Software has instructed customers running on-premises ShareFile Storage Zone Controllers to power down servers immediately after identifying a credible security threat.

A critical authentication bypass vulnerability in the official Gitea Docker image is being actively exploited, allowing attackers to gain unauthorized access to self-hosted Git services by impersonating users, including administrators.

Zimbra has released a security update for its Classic Web Client after discovering a critical cross-site scripting vulnerability that could allow attackers to hijack user sessions. The company advises all customers to apply the patch without delay.

A China-linked threat group has exploited a vulnerability in Roundcube webmail servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware, according to security researchers.

BeyondTrust issued fixes for critical vulnerabilities in its Remote Support and Privileged Remote Access software that allowed authentication bypass, potentially exposing customer sessions to unauthorized access.

DigiCert has released a preview of Quantum Central, a tool designed to help enterprises identify cryptographic assets, assess quantum attack exposure, and manage migration to post-quantum algorithms without disrupting production systems.