THREAT INTELLIGENCE BRIEFยทTuesday, July 28, 2026

The most urgent threat this week is the active exploitation of a critical zero-day vulnerability (CVE-2026-16812) in Arista's VeloCloud Orchestrator.

The most urgent threat this week is the active exploitation of a critical zero-day vulnerability (CVE-2026-16812) in Arista's VeloCloud Orchestrator. This vulnerability is listed on CISA's KEV list, confirming active attacks, and requires immediate patching by the specified due date. Additionally, a separate zero-day in the FastJson Java library is being actively exploited for remote code execution. Other significant threats include the use of a critical PTC Windchill flaw in ransomware campaigns and a major supply-chain data breach at Ernst & Young claimed by the ShinyHunters extortion gang.

45 articles analysed
2 CVEs mentioned
Email Brief

Threat Categories

๐Ÿ›Vulnerabilities3
๐Ÿ“„Data Breach1
๐Ÿ”’Ransomware1

Article Analyses (5)

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

critical
KEV

Details

A maximum-severity (CVSS 10.0) OS command injection vulnerability in on-premises Arista VeloCloud Orchestrator (VCO) is being actively exploited as a zero-day. The flaw allows attackers to execute arbitrary commands with privileged access, potentially leading to a complete system compromise.

Affected Systems

On-premises versions of Arista VeloCloud Orchestrator.

Potential Impact

Full compromise of the network orchestration platform, enabling attackers to control network traffic, access sensitive data, and pivot to other systems within the corporate network.

Mitigations

Immediately apply patches provided by Arista. Per the CISA KEV directive, federal agencies must patch this vulnerability by 2026-07-30. All organizations using the affected product should prioritize this action.

BleepingComputerDraft Post

Hackers target US firms in FastJson RCE zero-day attacks

critical

Details

A zero-day vulnerability in the widely-used FastJson open-source Java library is being actively exploited in the wild. The flaw allows for remote code execution (RCE) without any user interaction or elevated privileges, making it highly dangerous.

Affected Systems

Applications and services using the FastJson Java library.

Potential Impact

Remote code execution could lead to server compromise, data theft, deployment of malware or ransomware, and lateral movement across the network.

Mitigations

The source articles did not provide specific mitigation guidance. Organizations should monitor for security advisories from the FastJson project and apply patches when available.

BleepingComputerDraft Post

PTC Windchill Vulnerability Exploited in Ransomware Campaign

high

Details

A critical unsafe deserialization vulnerability in PTC's Windchill product is being actively exploited to deploy ransomware. The flaw allows remote, unauthenticated attackers to execute arbitrary code on affected servers.

Affected Systems

PTC Windchill product lifecycle management (PLM) software.

Potential Impact

Severe business disruption from ransomware deployment, data encryption, and potential data exfiltration. Compromise of sensitive product lifecycle data.

Mitigations

The source articles did not provide specific mitigation guidance. Organizations using PTC Windchill should seek advisories from the vendor and apply all relevant security patches immediately.

SecurityWeekDraft Post

Ernst & Young data breach claimed by ShinyHunters extortion gang

critical

Details

The ShinyHunters extortion gang has claimed responsibility for a data breach at professional services firm Ernst & Young. The attackers allege they gained access to company systems and exfiltrated data after obtaining credentials through a supply-chain attack.

Affected Systems

Ernst & Young internal systems and potentially client data.

Potential Impact

Reputational damage, financial loss from extortion demands, and potential exposure of sensitive corporate or client data. Highlights significant third-party and supply-chain risk.

Mitigations

This incident underscores the importance of robust supply-chain risk management, including vendor security assessments and enforcement of multi-factor authentication (MFA) for all third-party access.

BleepingComputerDraft Post

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

medium
CVE-2026-27577
EPSS 8.6%

Details

A high-severity vulnerability (CVE-2026-27577) in the n8n workflow automation platform allows an authenticated user with workflow editor permissions to escape the expression sandbox. This enables them to execute arbitrary OS commands with the permissions of the n8n server process.

Affected Systems

n8n versions from 2.32.0 up to, but not including, 2.32.1.

Potential Impact

An authenticated user with workflow editor permissions could escalate privileges and execute code on the underlying server, leading to server compromise, data access, and lateral movement.

Mitigations

Upgrade n8n instances to patched versions 2.31.5 or 2.32.1 immediately. Restrict workflow editor permissions to only highly trusted users.

The Hacker NewsDraft Post