Attackers Exploit Arista VeloCloud Orchestrators Without Credentials
On-premises VCO is exposed by default. Arista says defenders must inspect web activity and managed Edge state after patching.
Read article →Reader view
Choose the default article length.
Threat actors, malware campaigns, phishing, exploitation, and incident activity.
On-premises VCO is exposed by default. Arista says defenders must inspect web activity and managed Edge state after patching.
Read article →A misconfigured evaluation harness let three Claude models reach production systems, exposing a control gap that prompts and model safeguards could not contain.
Read article →Every on-prem Secure FMC configuration is affected. Cisco published hot fixes, a shared license.tmp indicator, and credential-rotation guidance.
Read article →Talos tied QR-code PDFs to credential theft, inbox-rule changes, SharePoint staging and new phishing sent from compromised Microsoft 365 mailboxes.
Read article →Kaspersky found BridgeHead using Windows SSO to cross corporate proxies before relaying server-selected TCP traffic through compromised hosts.
Read article →Five recovered task logs record service discovery, privilege checks and file enumeration after an operator enabled Hermes's unattended mode.
Read article →Hugging Face traced 17,600 actions from an Artifactory escape through two malicious-dataset vectors and into its clusters, network and source control.
Read article →The botnet spread through developer extensions and packages, then used stolen credentials to force-push malicious code into default branches.
Read article →Push Security traced paid search ads to shared ChatGPT and Claude pages that handed visitors to fake desktop-app downloads.
Read article →A civil lawsuit targets a Telegram-based phishing-kit operation that Google links to 2.5 million texts and more than one million fraudulent URLs.
Read article →A Teams lure installed a headless Edge extension and a Python native-messaging host, giving a ransomware access broker a quiet route to local command execution.
Read article →A stolen npm publisher account added a malicious dependency to more than 140 Mastra packages, giving Sapphire Sleet an install-time path into developer and CI systems.
Read article →A forgotten Klue credential led to customer OAuth token theft and direct access to Salesforce CRM data across several companies.
Read article →