📡 Tech & Security Digest — 2026-07-28
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks — Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploit…
- Hackers target US firms in FastJson RCE zero-day attacks — Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or e…
- New Certighost PoC exploit lets attackers hijack Windows domains — A proof-of-concept exploit for “Certighost,” a Windows Active Directory Certificate Services vulnerability, has been released that can allow authentic…
- Coca-Cola confirms data theft in Fairlife ransomware attack — The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. […]…
- OnTrac notifies customers of data breach after network hack — OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its custom…
- Hermes AI agent used to automate attack on Thai Finance Ministry — A threat actor used the open-source Hermes AI agent in unattended “YOLO” mode to automate post-exploitation activity during an alleged breach of Thail…
Hacker News
- Exploiting Volvo/Eicher’s fleet platform to gain control over all users/vehicles (148 pts)
- Removing React.js from the codebase and adapting Htmx for UI interactivity (2023) (241 pts)
- Self-contained highly-portable Python distributions (141 pts)
- Netflix employee fired for sharing personal details in retreat trust exercise (283 pts)
Krebs on Security
- Microsoft Patches a Record 570 Security Flaws — Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple…
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication — A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.
The vu…
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw — A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild….
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available — Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boo…
- Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access — Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) product…
- Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data — Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million …
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link — Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link …
- NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats — Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and say…
- Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say — Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.
…
- Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs — Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can…
- Why Modern SOCs Need Multi-Layered Detections — The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today…