Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Infosec News Nuggets — July 29, 2026 – AboutDFIR

    July 29, 2026

    Some thoughts about Anthropic’s new cryptanalysis results – A Few Thoughts on Cryptographic Engineering

    July 29, 2026

    “Clapping Is a First Amendment Right:” An Interview With the Person Arrested for Clapping at a Data Center Meeting

    July 29, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Infosec News Nuggets — July 29, 2026 – AboutDFIR
    News

    Infosec News Nuggets — July 29, 2026 – AboutDFIR

    adminBy adminJuly 29, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Arista patches VeloCloud Orchestrator zero-day exploited in attacks

    Arista has shipped patches for a maximum-severity command injection flaw in on-premises VeloCloud Orchestrator deployments after confirming it is being actively exploited. The bug allows unauthenticated attackers with only network access to the web interface to reach privileged internal functionality, potentially compromising the confidentiality, integrity, and availability of the orchestrator and the SD-WAN edge devices it manages. Three attacker IP addresses have been identified, and the flaw has been added to the federal Known Exploited Vulnerabilities catalog with a three-day remediation deadline.

     

    Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

    OpenWrt has released version 24.10.8 to fix a critical stack overflow in its odhcpd DHCPv6 service that can be triggered by a single crafted, unauthenticated network request. Because odhcpd runs as root and many embedded routers lack stack canaries or ASLR, successful exploitation could hand an attacker full control of the device rather than just crashing it. The release also patches a separate set of pre-authentication weaknesses uncovered through an AI-assisted security audit, though related fixes for optional web-interface components remained under review as of publication.

     

    Hackers Exploiting FastJson RCE 0-Day in the Wild to Attack US-based Organizations

    Attackers are actively exploiting an unpatched deserialization flaw in FastJson 1.x, a widely used Java library for converting between Java objects and JSON, to gain remote code execution on Spring Boot applications packaged as executable JAR files. The bypass works without valid credentials, user interaction, or third-party gadget classes, letting a single malicious JSON payload trigger arbitrary command execution. Exploitation has concentrated on US financial, healthcare, retail, and business services organizations, with smaller campaigns spotted in Singapore and Canada; since the affected release line is no longer maintained, defenders are advised to enable the library’s safe mode immediately and plan a migration to FastJson 2.x.

     

    Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)

    Researchers observed active exploitation of a critical unauthenticated remote code execution flaw in on-premises Microsoft SharePoint within hours of a proof-of-concept exploit going public, with attackers stealing IIS machine keys to maintain long-term access even after patching. Threat intelligence suggests exploitation may have actually begun days earlier, before the PoC surfaced. Because forged authentication tokens built from stolen keys let attackers impersonate legitimate users, organizations that already applied the underlying patch are being urged to also rotate credentials and hunt for intrusion artifacts rather than treating patching alone as sufficient remediation.

     

    Clop exploits vulnerability in PTC Windchill and FlexPLM

    A Clop-affiliated group is chaining a pre-authentication information leak with a remote code execution flaw in the login servlet of PTC’s Windchill and FlexPLM product lifecycle management software to deploy webshells and steal sensitive engineering and design data from manufacturing, automotive, aerospace, and retail companies. Researchers believe the underlying vulnerability was exploited as a zero-day starting in early June before being publicly disclosed and patched, and the group has since launched a mass email extortion campaign targeting hundreds of employees per victim organization, mirroring tactics used in last year’s Oracle E-Business Suite campaign.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSome thoughts about Anthropic’s new cryptanalysis results – A Few Thoughts on Cryptographic Engineering
    admin
    • Website

    Related Posts

    News

    Some thoughts about Anthropic’s new cryptanalysis results – A Few Thoughts on Cryptographic Engineering

    July 29, 2026
    News

    “Clapping Is a First Amendment Right:” An Interview With the Person Arrested for Clapping at a Data Center Meeting

    July 29, 2026
    News

    Making forensic observability the norm for network devices

    July 29, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Our Picks

    Infosec News Nuggets — July 29, 2026 – AboutDFIR

    July 29, 2026

    Some thoughts about Anthropic’s new cryptanalysis results – A Few Thoughts on Cryptographic Engineering

    July 29, 2026

    “Clapping Is a First Amendment Right:” An Interview With the Person Arrested for Clapping at a Data Center Meeting

    July 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.