AI-POWERED THREAT INTELLIGENCE

Cyber Pulse

Daily AI-powered cybersecurity briefings, real-time critical CVE alerts, and curated security news.

Security FeedGet the Mobile App
THREAT INTELLIGENCE BRIEF·Tuesday, July 28, 2026·AI-Powered

The most urgent threat this week is the active exploitation of a critical zero-day vulnerability (CVE-2026-16812) in Arista's VeloCloud Orchestrator.

The most urgent threat this week is the active exploitation of a critical zero-day vulnerability (CVE-2026-16812) in Arista's VeloCloud Orchestrator. This vulnerability is listed on CISA's KEV list, confirming active attacks, and requires immediate patching by the specified due date. Additionally, a separate zero-day in the FastJson Java library is being actively exploited for remote code execution. Other significant threats include the use of a critical PTC Windchill flaw in ransomware campaigns and a major supply-chain data breach at Ernst & Young claimed by the ShinyHunters extortion gang.

45 articles analysed2 CVEs mentioned

Threat Categories

🐛Vulnerabilities3
📄Data Breach1
🔒Ransomware1

Article Analyses (5)

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

critical
KEV

Details

A maximum-severity (CVSS 10.0) OS command injection vulnerability in on-premises Arista VeloCloud Orchestrator (VCO) is being actively exploited as a zero-day. The flaw allows attackers to execute arbitrary commands with privileged access, potentially leading to a complete system compromise.

Affected Systems

On-premises versions of Arista VeloCloud Orchestrator.

Potential Impact

Full compromise of the network orchestration platform, enabling attackers to control network traffic, access sensitive data, and pivot to other systems within the corporate network.

Mitigations

Immediately apply patches provided by Arista. Per the CISA KEV directive, federal agencies must patch this vulnerability by 2026-07-30. All organizations using the affected product should prioritize this action.

Hackers target US firms in FastJson RCE zero-day attacks

critical

Details

A zero-day vulnerability in the widely-used FastJson open-source Java library is being actively exploited in the wild. The flaw allows for remote code execution (RCE) without any user interaction or elevated privileges, making it highly dangerous.

Affected Systems

Applications and services using the FastJson Java library.

Potential Impact

Remote code execution could lead to server compromise, data theft, deployment of malware or ransomware, and lateral movement across the network.

Mitigations

The source articles did not provide specific mitigation guidance. Organizations should monitor for security advisories from the FastJson project and apply patches when available.

PTC Windchill Vulnerability Exploited in Ransomware Campaign

high

Details

A critical unsafe deserialization vulnerability in PTC's Windchill product is being actively exploited to deploy ransomware. The flaw allows remote, unauthenticated attackers to execute arbitrary code on affected servers.

Affected Systems

PTC Windchill product lifecycle management (PLM) software.

Potential Impact

Severe business disruption from ransomware deployment, data encryption, and potential data exfiltration. Compromise of sensitive product lifecycle data.

Mitigations

The source articles did not provide specific mitigation guidance. Organizations using PTC Windchill should seek advisories from the vendor and apply all relevant security patches immediately.

Ernst & Young data breach claimed by ShinyHunters extortion gang

critical

Details

The ShinyHunters extortion gang has claimed responsibility for a data breach at professional services firm Ernst & Young. The attackers allege they gained access to company systems and exfiltrated data after obtaining credentials through a supply-chain attack.

Affected Systems

Ernst & Young internal systems and potentially client data.

Potential Impact

Reputational damage, financial loss from extortion demands, and potential exposure of sensitive corporate or client data. Highlights significant third-party and supply-chain risk.

Mitigations

This incident underscores the importance of robust supply-chain risk management, including vendor security assessments and enforcement of multi-factor authentication (MFA) for all third-party access.

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

medium
EPSS 8.6%

Details

A high-severity vulnerability (CVE-2026-27577) in the n8n workflow automation platform allows an authenticated user with workflow editor permissions to escape the expression sandbox. This enables them to execute arbitrary OS commands with the permissions of the n8n server process.

Affected Systems

n8n versions from 2.32.0 up to, but not including, 2.32.1.

Potential Impact

An authenticated user with workflow editor permissions could escalate privileges and execute code on the underlying server, leading to server compromise, data access, and lateral movement.

Mitigations

Upgrade n8n instances to patched versions 2.31.5 or 2.32.1 immediately. Restrict workflow editor permissions to only highly trusted users.

Everything a Security Pro Needs

Built for analysts, engineers, and defenders who need signal, not noise.

Daily Threat Briefings

AI-generated executive briefings synthesizing top CVEs, campaigns, and advisories every morning.

Critical CVE Alerts

Real-time push notifications for high-severity vulnerabilities with EPSS scores and KEV status.

Security News Feed

Curated articles from 15+ top security sources including CISA, NVD, Krebs, and Schneier.

Pro Intelligence

Evening debriefs, alerts history, AI analysis with PoC detection and mitigation guidance.

Free Account, Instant Access

Sign up free and get the morning brief, security feed, and critical alerts. Upgrade to Pro for advanced intelligence.

Create Free Account