View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Critical Zero-Day OS Command Injection in Arista VeloCloud

๐Ÿšจ ACTIVE EXPLOITATION

  • Critical Zero-Day OS Command Injection in Arista VeloCloud Orchestrator Exploited CVE-2026-16812
    Arista VeloCloud Orchestrator on-premises deployments are actively exploited via a critical OS command injection zero-day.

    • Applies to Arista VeloCloud Orchestrator on-premises versions before 5.2.3.145, 6.1.3.46, 6.4.2.4, and 7.0.0.1
    • Vulnerability allows remote OS command injection without authentication or user interaction
    • Attackers gain privileged internal functionality access, compromising confidentiality, integrity, and availability
    • Exploitation requires only network access to the VCO web interface; no credentials or special config needed
    • Observed attacker IPs include 8.19.75.217, 206.72.242.124, and 206.72.242.162
      ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ“„ Original: securityweek.com ยท ๐Ÿ‘ via SecurityWeek, Cyber Security News
  • Unpatched Fastjson RCE Vulnerability Exploited in Attacks Targeting Multiple Sectors
    Attackers are exploiting an unauthenticated remote code execution flaw in Fastjson 1.x.

    • Applies to Fastjson versions 1.2.68 to 1.2.83 used in Spring Boot fat-jar deployments
    • Vulnerability allows remote code execution without authentication or external gadget libraries
    • Exploitation involves crafted JSON with malicious @type values bypassing AutoType restrictions
    • Attacks observed across business, financial, healthcare, retail sectors in US, Singapore, and Canada
    • Attack origins include browser impersonators and tools written in Ruby and Go
      ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ“„ Original: securityweek.com ยท ๐Ÿ‘ via SecurityWeek

๐Ÿ”“ CVEs & KEV

  • Other: 20 CVEs (worst 9.8)

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Dysphoria Botnet Infects 200,000 IoT Devices Using Blockchain-Based C2 Infrastructure
    Dysphoria botnet has infected 200,000 IoT devices and uses blockchain domains for command-and-control.

    • Targets routers, cameras, gateways, and embedded Linux IoT devices globally
    • Spreads via weak Telnet/SSH passwords and exploits known IoT vulnerabilities
    • Uses Ethereum and Solana blockchain domains to hide and update C2 infrastructure
    • New variants create relay nodes to route traffic and evade detection
    • Estimated DDoS capacity up to 4 Tbps with around 200,000 infected devices
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ“„ Original: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News
  • Multiple High-Severity Vulnerabilities Found in FFmpeg Allow Memory Corruption
    Multiple vulnerabilities in FFmpeg enable memory corruption and potential code execution via malicious media files.

    • Affects FFmpeg versions 7.0 through 8.1, impacting media parsing, decoding, filtering, and encoding components
    • Vulnerabilities include heap memory corruption, integer overflow, buffer overflow, uncontrolled resource consumption, and uninitialized memory exposure
    • Attack vectors involve crafted video files, subtitle files, audio files, PNG images, and malformed streams
    • Notable CVEs: CVE-2026-66036, CVE-2026-66037, CVE-2026-66038, CVE-2026-66039, CVE-2026-66040, CVE-2026-66041
    • Exploitation can cause crashes, denial-of-service, information disclosure, or arbitrary code execution
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News
  • Mirage Kitten APT Deploys NightLedger Backdoor and WebSocket Tunnelers in Middle East
    Mirage Kitten APT uses new NightLedger backdoor and tunneling tools in targeted Middle East attacks.

    • Targets aerospace, aviation, defense, and telecom sectors in Middle East and Africa
    • New malware includes NightLedger Windows backdoor and two WebSocket tunnelers: ArcBridge and BridgeHead
    • NightLedger uses DLL hijacking via SspiCli.dll alongside AppVShNotify.exe for stealthy execution
    • Malware communicates with C2 servers over HTTPS using custom endpoints and payload tokenization
    • Initial access via spear-phishing with recruitment-themed lures and fake videoconferencing pages
      ๐Ÿ“Ž Coverage: securelist.com ยท ๐Ÿ“„ Original: securelist.com ยท ๐Ÿ‘ via Securelist (Kaspersky)
  • microsoft-teams-vishing-gogrpc-backdoor

  • edr-killers-byovd-vulnerable-drivers

๐Ÿ“‹ ADVISORIES

  • Five Critical Vulnerabilities Found in Progress LoadMaster Appliances Allow Root Access CVE-2026-59686 CVE-2026-59687 CVE-2026-59688 CVE-2026-59689 CVE-2026-59690
    Progress LoadMaster appliances have five vulnerabilities allowing authenticated users to gain root access.
    • Affects Progress Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale appliances
    • Includes CVE-2026-59686 to CVE-2026-59690 impacting versions 7.2.63.27 and earlier, plus LTSF and Multi-Tenant variants
    • Three command injection flaws allow execution of arbitrary OS commands via management interfaces and backup functions
    • Two broken access control issues enable low-privilege authenticated users to escalate to root and perform unauthorized admin actions
    • Exploitation requires authentication; no active exploitation or indicators of compromise reported yet
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ“„ Original: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check