๐จ ACTIVE EXPLOITATION
-
Critical Zero-Day OS Command Injection in Arista VeloCloud Orchestrator Exploited
CVE-2026-16812
Arista VeloCloud Orchestrator on-premises deployments are actively exploited via a critical OS command injection zero-day.- Applies to Arista VeloCloud Orchestrator on-premises versions before 5.2.3.145, 6.1.3.46, 6.4.2.4, and 7.0.0.1
- Vulnerability allows remote OS command injection without authentication or user interaction
- Attackers gain privileged internal functionality access, compromising confidentiality, integrity, and availability
- Exploitation requires only network access to the VCO web interface; no credentials or special config needed
- Observed attacker IPs include 8.19.75.217, 206.72.242.124, and 206.72.242.162
๐ Coverage: securityweek.com ยท ๐ Original: securityweek.com ยท ๐ via SecurityWeek, Cyber Security News
-
Unpatched Fastjson RCE Vulnerability Exploited in Attacks Targeting Multiple Sectors
Attackers are exploiting an unauthenticated remote code execution flaw in Fastjson 1.x.- Applies to Fastjson versions 1.2.68 to 1.2.83 used in Spring Boot fat-jar deployments
- Vulnerability allows remote code execution without authentication or external gadget libraries
- Exploitation involves crafted JSON with malicious @type values bypassing AutoType restrictions
- Attacks observed across business, financial, healthcare, retail sectors in US, Singapore, and Canada
- Attack origins include browser impersonators and tools written in Ruby and Go
๐ Coverage: securityweek.com ยท ๐ Original: securityweek.com ยท ๐ via SecurityWeek
๐ CVEs & KEV
- Other: 20 CVEs (worst 9.8)
๐ต๏ธ RESEARCH & DEEP DIVES
-
Dysphoria Botnet Infects 200,000 IoT Devices Using Blockchain-Based C2 Infrastructure
Dysphoria botnet has infected 200,000 IoT devices and uses blockchain domains for command-and-control.- Targets routers, cameras, gateways, and embedded Linux IoT devices globally
- Spreads via weak Telnet/SSH passwords and exploits known IoT vulnerabilities
- Uses Ethereum and Solana blockchain domains to hide and update C2 infrastructure
- New variants create relay nodes to route traffic and evade detection
- Estimated DDoS capacity up to 4 Tbps with around 200,000 infected devices
๐ Coverage: cybersecuritynews.com ยท ๐ Original: cybersecuritynews.com ยท ๐ via Cyber Security News
-
Multiple High-Severity Vulnerabilities Found in FFmpeg Allow Memory Corruption
Multiple vulnerabilities in FFmpeg enable memory corruption and potential code execution via malicious media files.- Affects FFmpeg versions 7.0 through 8.1, impacting media parsing, decoding, filtering, and encoding components
- Vulnerabilities include heap memory corruption, integer overflow, buffer overflow, uncontrolled resource consumption, and uninitialized memory exposure
- Attack vectors involve crafted video files, subtitle files, audio files, PNG images, and malformed streams
- Notable CVEs: CVE-2026-66036, CVE-2026-66037, CVE-2026-66038, CVE-2026-66039, CVE-2026-66040, CVE-2026-66041
- Exploitation can cause crashes, denial-of-service, information disclosure, or arbitrary code execution
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
-
Mirage Kitten APT Deploys NightLedger Backdoor and WebSocket Tunnelers in Middle East
Mirage Kitten APT uses new NightLedger backdoor and tunneling tools in targeted Middle East attacks.- Targets aerospace, aviation, defense, and telecom sectors in Middle East and Africa
- New malware includes NightLedger Windows backdoor and two WebSocket tunnelers: ArcBridge and BridgeHead
- NightLedger uses DLL hijacking via SspiCli.dll alongside AppVShNotify.exe for stealthy execution
- Malware communicates with C2 servers over HTTPS using custom endpoints and payload tokenization
- Initial access via spear-phishing with recruitment-themed lures and fake videoconferencing pages
๐ Coverage: securelist.com ยท ๐ Original: securelist.com ยท ๐ via Securelist (Kaspersky)
๐ ADVISORIES
- Five Critical Vulnerabilities Found in Progress LoadMaster Appliances Allow Root Access
CVE-2026-59686CVE-2026-59687CVE-2026-59688CVE-2026-59689CVE-2026-59690
Progress LoadMaster appliances have five vulnerabilities allowing authenticated users to gain root access.- Affects Progress Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale appliances
- Includes CVE-2026-59686 to CVE-2026-59690 impacting versions 7.2.63.27 and earlier, plus LTSF and Multi-Tenant variants
- Three command injection flaws allow execution of arbitrary OS commands via management interfaces and backup functions
- Two broken access control issues enable low-privilege authenticated users to escalate to root and perform unauthorized admin actions
- Exploitation requires authentication; no active exploitation or indicators of compromise reported yet
๐ Coverage: cybersecuritynews.com ยท ๐ Original: cybersecuritynews.com ยท ๐ via Cyber Security News