Daily cybersecurity briefing

Top 10 Cybersecurity Stories for July 28, 2026

Immediate priority is patching the CVSS 10.0 Arista VeloCloud Orchestrator flaw and auditing for FastJson RCE, both of which are seeing active exploitation. We are also seeing a surge in high-impact identity risks via AD CS PoCs and cloud 'Confused Deputy' flaws. Additionally, the emergence of autonomous AI agents in real-world espionage underscores an urgent need to evaluate agentic browser security.

Compiled by the Slugnet Editorial System. Published Jul 29, 2026, 8:25 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

The audio edition is not available yet.

  1. 01
    The Hacker News

    Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

    What happened

    A critical OS command injection vulnerability (CVE-2026-16812) in on-premises Arista VeloCloud Orchestrator is under active exploitation. The flaw carries a CVSS score of 10.0 and allows attackers to execute arbitrary code.

    Why it ranks #1

    Highest priority due to confirmed active exploitation of a maximum-severity (CVSS 10.0) vulnerability in enterprise infrastructure.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Apply the Arista patch for VeloCloud Orchestrator immediately.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    BleepingComputer

    Hackers target US firms in FastJson RCE zero-day attacks

    What happened

    Attackers are actively exploiting a zero-day remote code execution vulnerability in the FastJson open-source Java library. The flaw allows unauthenticated RCE without user interaction under default configurations.

    Why it ranks #2

    Confirmed active exploitation of an unpatched, unauthenticated RCE in a widely used library constitutes immediate enterprise exposure.

    Who should care

    Application security teams, SOC and incident response teams

    What to do

    Audit Java applications for FastJson usage and monitor for unusual outbound traffic from affected servers.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    The Hacker News

    Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

    What happened

    JetBrains has released patches for a critical unauthenticated RCE vulnerability (CVE-2026-63077) affecting TeamCity On-Premises. The flaw allows attackers to run OS commands with a CVSS score of 9.8.

    Why it ranks #3

    Critical severity in CI/CD infrastructure, which is a high-value target for supply chain attacks, though not yet confirmed as actively exploited like the top two.

    Who should care

    Application security teams, IT and platform operations

    What to do

    Update TeamCity On-Premises to versions 2025.11.7 or 2026.1.3.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    BleepingComputer

    New Certighost PoC exploit lets attackers hijack Windows domains

    What happened

    A proof-of-concept exploit for 'Certighost,' a Windows Active Directory Certificate Services vulnerability, has been released. The exploit allows authenticated attackers to potentially hijack entire Windows domains.

    Why it ranks #4

    High-impact identity infrastructure vulnerability with a public PoC, enabling full domain compromise.

    Who should care

    Identity and access teams, SOC and incident response teams

    What to do

    Review AD CS configurations and apply relevant Microsoft security updates for certificate services.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    Dark Reading

    'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure

    What happened

    Researchers have identified persistent 'Confused Deputy' flaws within Google Cloud and Microsoft Azure. These vulnerabilities allow attackers to bypass access controls and acquire administrative-level permissions.

    Why it ranks #5

    Critical impact on cloud identity and access management across the two largest cloud providers.

    Who should care

    CISOs and security leaders, Cloud security teams

    What to do

    Review IAM policies for overly permissive service accounts and cross-tenant trust relationships.

    Impact
    high
    Urgency
    near-term
    Confidence
    medium
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    Dark Reading

    AI Agent Drives Espionage Attack on Thai Ministry of Finance

    What happened

    Attackers utilized the autonomous open-source tool Hermes in 'YOLO mode' to conduct an espionage campaign against Thailand's Ministry of Finance. This represents a practical application of AI agents for targeted attacks.

    Why it ranks #6

    Material evidence of AI agents being used in real-world state-level espionage, demonstrating operational consequence.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    Help Net Security

    Coca-Cola confirms hackers stole data in Fairlife ransomware attack

    What happened

    Coca-Cola confirmed that a ransomware attack on its subsidiary Fairlife resulted in the theft of company data. The incident previously caused temporary production halts at four US manufacturing facilities.

    Why it ranks #7

    Material breach and ransomware event involving a major global brand with operational disruption and data exfiltration.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    BleepingComputer

    New Dysphoria DDoS botnet spreads to 200k devices worldwide

    What happened

    The Dysphoria IoT botnet has expanded to approximately 200,000 devices worldwide. The network is being used for distributed denial of service (DDoS) attacks and traffic relay operations.

    Why it ranks #8

    Significant threat-actor operation with a large scale of compromised infrastructure capable of impacting availability.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Ensure IoT devices are segmented from critical enterprise networks and change default credentials.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    Dark Reading

    Agentic Browsers Rewind Web Security by 20 years

    What happened

    The 'PleaseFix' class of flaws allows attackers to socially engineer agentic browsers. These vulnerabilities highlight critical weaknesses in how AI-driven browsers handle cross-origin requests.

    Why it ranks #9

    Novel research into AI agent security with clear operational consequences for the emerging use of agentic web browsing.

    Who should care

    Application security teams, Cloud security teams

    Impact
    high
    Urgency
    near-term
    Confidence
    medium
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    Help Net Security

    AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

    What happened

    AWS is retiring Shield Advanced L7 automatic mitigation on January 1, 2027. Customers must migrate to the new Anti-DDoS managed rule group for application-layer protection.

    Why it ranks #10

    Direct impact on WAF/DDoS infrastructure management with a defined sunset date for a core security feature.

    Who should care

    Cloud security teams, IT and platform operations

    What to do

    Begin transitioning AWS Shield Advanced L7 mitigation to the Anti-DDoS managed rule group in Count mode.

    Impact
    low
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email