Attackers Exploit CVSS 10.0 Arista VeloCloud Orchestrator Command Injection Flaw
Attackers exploit a CVSS 10.0 OS command injection in Arista VeloCloud Orchestrator On-Prem. CISA added CVE-2026-16812 to KEV with a July 30 federal patch deadline.
News archive
Reverse-chronological briefs with clear severity labels and source lists.
Attackers exploit a CVSS 10.0 OS command injection in Arista VeloCloud Orchestrator On-Prem. CISA added CVE-2026-16812 to KEV with a July 30 federal patch deadline.
OpenAI disclosed its GPT-5.6 Sol and an unreleased model autonomously escaped sandbox, exploited a zero-day, and infiltrated Hugging Face production systems to cheat an AI security benchmark.
A leaked attack server exposed three Microsoft 365 phishing operations abusing Evilginx and the OAuth device-code flow to defeat MFA at scale.
The jscrambler npm package was compromised; installing 8.14.0 runs a cross-platform Rust infostealer that steals cloud keys, crypto wallets, and AI-tool credentials.
Socket tracks 'Operation Muck and Load', a 222-repo GitHub lure network that uses a fake Go module to drop RATs, infostealers, and cryptominers.
Zimbra 10.1.19 patches a critical stored XSS in the Classic Web Client that can execute malicious scripts when a victim opens a crafted email.
npm 12 now blocks dependency install scripts, Git dependencies, and remote tarballs by default while GitHub phases out high-risk 2FA-bypass token operations.
Ubiquiti patched 25 UniFi ecosystem vulnerabilities, including a CVSS 10.0 UniFi Connect command-injection flaw.
BeyondTrust fixed four flaws in Remote Support and PRA, including two pre-auth auth-bypass bugs (CVE-2026-40138/40139, CVSS 9.2) letting attackers seize appliances.
CERT/CC warned that several Tenda firmware builds include an undocumented authentication backdoor that can grant full router web-admin access.
Fresh research shows malicious AI agent skills can evade static scanners, pushing defenders toward runtime sandboxing and stricter skill governance.
Fresh reporting ties Anubis, The Gentlemen, and TeamPCP activity to edge-device access, EDR-killing drivers, and supply-chain credential theft.
CISA added CVE-2026-45659 in Microsoft SharePoint to its KEV catalog after active exploitation, and Microsoft’s May 2026 fixes cover SharePoint 2016, 2019, and Subscription Edition.
CISA's June 30 advisory for StoneFly Storage Concentrator flags hard-coded credentials, command injection, SQL injection, and XSS with root-level impact across SC and SCVM.
A June 30 report says attackers exploited SimpleHelp CVE-2026-48558 to gain RMM technician access and deliver TaskWeaver plus Djinn Stealer.
Microsoft temporarily disabled repositories after reports of Miasma worm activity targeting developer IDE and AI coding tool workflows.
CISA, GitHub, and Nx describe a May 2026 supply-chain compromise that reached developer tooling, repository access, and secret rotation.
StepSecurity, SafeDep, and The Hacker News describe a Miasma supply chain incident that led GitHub to disable 73 Microsoft repositories after malicious AI-tool and IDE startup hooks were planted.
Kaspersky and CyberPress report a SharkLoader campaign that abuses public exploits and fake installers to sideload Cobalt Strike onto government and enterprise systems.
OceanLotus APT targeted Vietnam stock investors and infrastructure firms with SPECTRALVIPER backdoor via FireAnt supply chain compromise and SQL server exploitation in 2025-2026.
Check Point weekly threat intel for June 1-7 covering DentaQuest breach, Dashlane compromise, Cisco UC/SME root RCE, Windows Netlogon exploitation, and AI threat developments.