Security news.
Today's security brief highlights critical vulnerabilities under active exploitation, significant data breaches impacting millions, and the ongoing evolution of AI in both defensive and offensive cybersecurity. Patching remains crucial, with several zero-days reported, while nation-state actors continue sophisticated campaigns.
Fastjson RCE Zero-Day Actively Exploited
Hackers are actively exploiting a critical remote code execution vulnerability in the Fastjson open-source Java library, allowing unauthenticated RCE.
Arista VeloCloud Orchestrator Zero-Day Exploited
A maximum-severity OS command injection vulnerability (CVE-2026-16812) in on-premises Arista VeloCloud Orchestrator deployments is being actively exploited, with CISA adding it to its KEV catalog.
Critical TeamCity Flaw Allows OS Command Execution
JetBrains has patched a critical security vulnerability (CVE-2026-63077, CVSS 9.8) in on-premise TeamCity versions that could lead to arbitrary code execution without authentication.
24,000+ Servers Expose Password Hashes via Old BMC Flaw
Over 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface.
Origin Energy Data Breach Affects 900,000 Australians
Origin Energy confirmed a data breach claimed by hackers, potentially impacting up to 2 million customers, with details of 900,000 Australians confirmed stolen.
Medical Billing Firm MCBS Breach Affects 1.26 Million
Medical Computer Business Services (MCBS) disclosed a network breach from 2025 that exposed the sensitive information of over 1.2 million individuals.
Iranian APT Nimbus Manticore Uses New Backdoor
The Iranian state-backed group Nimbus Manticore (aka GalaxyGato) is using a new Windows backdoor, NightLedger, and custom WebSocket tunnelers in attacks targeting the Middle East, Africa, and South Asia.
AI Agent Used in Espionage Attack on Thai Ministry of Finance
Attackers leveraged Hermes, an autonomous open-source AI tool in "YOLO mode," to conduct espionage against Thailand's Ministry of Finance.