View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Attackers Exploit Critical Command Injection Flaw in Arista VeloCloud

๐Ÿšจ ACTIVE EXPLOITATION

  • Attackers Exploit Critical Command Injection Flaw in Arista VeloCloud Orchestrator CVE-2026-16812
    CVE-2026-16812 (CVSS 9) allows remote OS command injection leading to arbitrary code execution in Arista VeloCloud Orchestrator.

    • Applies to on-premises Arista VeloCloud Orchestrator versions prior to 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1
    • Attackers exploit a flaw in internal functionality exposed remotely, compromising orchestrator confidentiality, integrity, and availability
    • Indicators of compromise include three malicious IPs: 8.19.75.217, 206.72.242.124, and 206.72.242.162
    • U.S. CISA added the flaw to its Known Exploited Vulnerabilities catalog with patch deadline July 30, 2026
      ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ“„ Original: thehackernews.com ยท ๐Ÿ‘ via The Hacker News
  • CISA Warns of Active Exploitation of Fortinet FortiOS Vulnerability CVE-2025-68686 CVE-2025-68686
    CVE-2025-68686 in Fortinet FortiOS is actively exploited to expose sensitive information via symbolic link persistence bypass.

    • Affects Fortinet FortiOS used in FortiGate firewalls and other Fortinet products
    • Exploitation requires prior filesystem-level access from a separate vulnerability
    • Attackers send crafted HTTP requests to bypass patch protections for persistence
    • CISA added CVE-2025-68686 to Known Exploited Vulnerabilities catalog with active attacks confirmed
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ’ฅ BREACHES & INCIDENTS

  • Origin Energy Data Breach Exposes Personal Data of 900,000 Australians
    Origin Energy suffered a data breach impacting 900,000 current and former customers.
    • Exposed data includes names, dates of birth, phone numbers, addresses, account info, and partial payment card or bank account numbers
    • Breach discovered in July 2026 after investigation of a potential security threat
    • Hacker claimed to have stolen data of 2 million customers and threatened to leak it unless paid ransom
    • Origin Energy has not confirmed any ransom payment; authorities are investigating
      ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via SecurityWeek

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Operation STANDOFF Uses GitHub Redirects to Mask Russian Cybercrime Campaign
    Operation STANDOFF is a Russian cybercrime campaign delivering multiple malware via GitHub redirects.

    • Targets include individual and enterprise systems infected via pay-per-install loaders
    • Delivers info stealers, loaders, cryptocurrency miner, and botnet components in one package
    • Uses HTTP 301 redirects to GitHub to hide command-and-control traffic and evade detection
    • Employs gaming-themed lures and automated outreach to spread malware
    • Operators use stolen credentials and proxy botnet for deeper network intrusion and traffic relay
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ“„ Original: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News
  • DCSync Attack Enables Silent Theft of Active Directory Password Hashes
    DCSync attacks let adversaries steal Active Directory password hashes without touching domain controllers directly.

    • Applies to enterprises using Active Directory with replication rights assigned
    • Attack targets password hashes of users, services, and machines via replication protocol
    • Works by impersonating a domain controller and requesting secrets over MS-DRSR RPC
    • Requires DS-Replication-Get-Changes and DS-Replication-Get-Changes-All rights, often held by privileged or misconfigured accounts
    • Commonly executed using tools like Mimikatz's lsadump::dcsync module
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ”“ CVEs & KEV

  • CVE-2026-17524 โ€” CVSS 7.5 โ€” Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal
  • CVE-2026-17528 โ€” CVSS 6.1 โ€” Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check