๐จ ACTIVE EXPLOITATION
-
Attackers Exploit Critical Command Injection Flaw in Arista VeloCloud Orchestrator
CVE-2026-16812
CVE-2026-16812 (CVSS 9) allows remote OS command injection leading to arbitrary code execution in Arista VeloCloud Orchestrator.- Applies to on-premises Arista VeloCloud Orchestrator versions prior to 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1
- Attackers exploit a flaw in internal functionality exposed remotely, compromising orchestrator confidentiality, integrity, and availability
- Indicators of compromise include three malicious IPs: 8.19.75.217, 206.72.242.124, and 206.72.242.162
- U.S. CISA added the flaw to its Known Exploited Vulnerabilities catalog with patch deadline July 30, 2026
๐ Coverage: thehackernews.com ยท ๐ Original: thehackernews.com ยท ๐ via The Hacker News
-
CISA Warns of Active Exploitation of Fortinet FortiOS Vulnerability CVE-2025-68686
CVE-2025-68686
CVE-2025-68686 in Fortinet FortiOS is actively exploited to expose sensitive information via symbolic link persistence bypass.- Affects Fortinet FortiOS used in FortiGate firewalls and other Fortinet products
- Exploitation requires prior filesystem-level access from a separate vulnerability
- Attackers send crafted HTTP requests to bypass patch protections for persistence
- CISA added CVE-2025-68686 to Known Exploited Vulnerabilities catalog with active attacks confirmed
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ฅ BREACHES & INCIDENTS
- Origin Energy Data Breach Exposes Personal Data of 900,000 Australians
Origin Energy suffered a data breach impacting 900,000 current and former customers.- Exposed data includes names, dates of birth, phone numbers, addresses, account info, and partial payment card or bank account numbers
- Breach discovered in July 2026 after investigation of a potential security threat
- Hacker claimed to have stolen data of 2 million customers and threatened to leak it unless paid ransom
- Origin Energy has not confirmed any ransom payment; authorities are investigating
๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
๐ต๏ธ RESEARCH & DEEP DIVES
-
Operation STANDOFF Uses GitHub Redirects to Mask Russian Cybercrime Campaign
Operation STANDOFF is a Russian cybercrime campaign delivering multiple malware via GitHub redirects.- Targets include individual and enterprise systems infected via pay-per-install loaders
- Delivers info stealers, loaders, cryptocurrency miner, and botnet components in one package
- Uses HTTP 301 redirects to GitHub to hide command-and-control traffic and evade detection
- Employs gaming-themed lures and automated outreach to spread malware
- Operators use stolen credentials and proxy botnet for deeper network intrusion and traffic relay
๐ Coverage: cybersecuritynews.com ยท ๐ Original: cybersecuritynews.com ยท ๐ via Cyber Security News
-
DCSync Attack Enables Silent Theft of Active Directory Password Hashes
DCSync attacks let adversaries steal Active Directory password hashes without touching domain controllers directly.- Applies to enterprises using Active Directory with replication rights assigned
- Attack targets password hashes of users, services, and machines via replication protocol
- Works by impersonating a domain controller and requesting secrets over MS-DRSR RPC
- Requires DS-Replication-Get-Changes and DS-Replication-Get-Changes-All rights, often held by privileged or misconfigured accounts
- Commonly executed using tools like Mimikatz's lsadump::dcsync module
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ CVEs & KEV
- CVE-2026-17524 โ CVSS 7.5 โ Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal
- CVE-2026-17528 โ CVSS 6.1 โ Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting