Date: Tuesday, July 28, 2026
Audience: Server admins, MSPs, infra leads, SOC/IR teams
Estimated reading time: 13 minutes
Executive Admin Summary
The day’s most urgent risk remains active exploitation of on-premises Arista VeloCloud Orchestrator. CVE-2026-16812 is an unauthenticated operating-system command-injection vulnerability in a management system that can influence downstream edge devices. Arista assigns CVSS 10.0, confirms exploitation, and identifies exposed web access as sufficient for attack. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on July 27 with a July 30 federal remediation deadline. Patching is necessary but insufficient where exposure existed: administrators must determine whether orchestrator credentials, certificates, databases, configurations, or managed Edge devices were compromised.
The second immediate issue is Fortinet CVE-2025-68686, newly added to KEV after Fortinet had originally reported no known exploitation. This is not a fresh initial-access mechanism. It allows an attacker who already obtained filesystem-level access to bypass remediation for an SSL-VPN symbolic-link persistence technique. Its presence should therefore be interpreted as potential evidence of an older FortiGate intrusion that survived incomplete cleanup—not simply as another medium-severity patch ticket.
Beyond those two exploited vulnerabilities, today’s broader pattern is the abuse of trusted administrative mechanisms and legitimate infrastructure. Research into Thailand’s Ministry of Finance describes an autonomous Hermes agent conducting post-exploitation work against government Hadoop, GlassFish, mail, and administrative systems. Cisco Talos separately documented ransomware operators directing command-and-control traffic through headless browsers and WebRTC rather than connecting from the implant itself. Fresh OpenAM and Budibase disclosures affect identity services, administrative applications, stored credentials, and backend databases. International advisories from Japan and Europe also reinforce that developer platforms, routers, and ordinary management protocols remain central pathways for espionage and potential infrastructure disruption.
Immediate Action Required
Actively exploited Arista VeloCloud Orchestrator can expose downstream network authority
Priority: Critical
Intelligence Update:
Arista published Security Advisory 0144 on July 27 for CVE-2026-16812, affecting on-premises VeloCloud Orchestrator. The vulnerability exposes functionality intended only for internal use and allows a remote attacker to execute operating-system commands without tenant or operator credentials. Arista confirms active exploitation and assigns CVSS 10.0 under both CVSS 3.1 and CVSS 4.0. Hosted and dedicated VCO services were patched before disclosure; the emergency applies primarily to customer-operated on-premises installations.
CISA added the vulnerability to KEV on July 27 and established a July 30 remediation deadline for affected federal systems. The public NVD record reports automatable exploitation and total technical impact.
Assessment:
VCO should be treated as effectively Tier 0 because downstream edge appliances accept its administrative instructions. Compromise may expose network topology, device inventory, databases, administrator records, credentials, certificates, private keys, configuration material, and the trusted relationship between the orchestrator and managed Edge devices.
A software upgrade does not establish environmental integrity. Attackers may preserve access through copied credentials, certificates, altered administrator accounts, exported databases, modified configurations, files placed on the VCO host, or unauthorized changes pushed to managed appliances. Arista explicitly advises credential rotation, administrator review, managed-device validation, and restoration or replacement from trusted sources where compromise is suspected.
Operational Impact:
Restrict every affected web interface to trusted administrative networks, preserve evidence, and deploy the appropriate fixed release. Internet-facing or suspicious systems should enter incident response before routine upgrade activity alters logs or filesystem evidence.
Where exploitation cannot be excluded, rebuild the orchestrator from trusted installation media, validate every managed Edge against an independently trusted configuration baseline, and revoke administrative credentials, API secrets, certificates, and private keys accessible through the VCO.
Operational Notes:
- Affected: VCO 5.2.x before 5.2.3.14.
- Affected: VCO 6.1.x before 6.1.3.4.
- Affected: VCO 6.4.x before 6.4.2.4.
- Affected: VCO 7.0.x before 7.0.0.1.
- Explicitly listed fixes: 5.2.3.14, 6.1.3.4, and 6.4.2.4 or later in their respective branches.
- Arista lists pre-7.0.0.1 releases as affected but does not enumerate a 7.0 release in the advisory’s fixed-release section. Confirm the supported 7.0 remediation path with Arista Technical Assistance Center.
- End-of-support releases have not been assessed.
- Exploitation requires network access to the VCO web interface; credentials and user interaction are not required.
- Preserve web-access, backend-application, system, database, and filesystem-timestamp evidence.
- Investigate unusual encoded paths, references to local services, unexpected command execution, archives, database exports, outbound HTTP or HTTPS activity, and unexplained configuration or maintenance actions.
- Arista observed attacks from
8.19.75.217,206.72.242.124, and206.72.242.162. - Treat those addresses as investigative pivots, not a complete blocklist or proof of compromise.
- Compare downstream Edge configurations for unauthorized accounts, tunnels, routes, DNS changes, firewall policy changes, and altered remote-management settings.
- Do not restore unverified databases or configuration backups into a clean replacement.
- Federal remediation deadline: July 30, 2026.
Assessment Confidence: High — Arista confirms exploitation, publishes affected versions and observed attack infrastructure, and provides post-compromise guidance; CISA independently placed the vulnerability in KEV.
Sources:
Arista Networks — Security Advisory 0144: VeloCloud Orchestrator On-Prem CVE-2026-16812.
NIST National Vulnerability Database — CVE-2026-16812 Detail and CISA KEV Update.
FortiOS persistence bypass requires investigation of the preceding intrusion
Priority: High
Intelligence Update:
Fortinet published FG-IR-25-934 on February 10, 2026, and updated it on March 12. The advisory covers CVE-2025-68686, which can bypass remediation for an SSL-VPN symbolic-link persistence mechanism observed in some post-exploitation cases. Fortinet originally reported no known exploitation. CISA added the vulnerability to KEV on July 27 after receiving evidence of active exploitation and set an August 10 federal remediation deadline.
Assessment:
The crafted HTTP request is unauthenticated, but the vulnerability is not an independent gateway takeover path. The attacker must first have compromised the appliance through another vulnerability and obtained filesystem-level access.
That prerequisite is the central operational fact. Exposure to CVE-2025-68686 should trigger investigation of how the earlier compromise occurred, what the attacker accessed, and whether other persistence or downstream access remains. Updating only the affected code may remove the symbolic-link path while leaving stolen VPN credentials, certificates, API secrets, policy information, internal reconnaissance, or unrelated persistence intact.
Fortinet states that products which never had SSL-VPN enabled are not affected.
Operational Impact:
Update affected branches using Fortinet’s supported upgrade path and conduct a historical compromise assessment. Examine earlier FortiOS exposure, filesystem changes, symbolic links, administrators, API accounts, VPN activity, policy revisions, and unexplained configuration changes.
Where appliance integrity cannot be demonstrated, isolate it, preserve evidence, rebuild from trusted firmware and a verified configuration, and rotate credentials and cryptographic material that resided on or traversed the appliance.
Operational Notes:
- Affected: FortiOS 7.6.0 through 7.6.1; upgrade to 7.6.2 or later.
- Affected: FortiOS 7.4.0 through 7.4.6; upgrade to 7.4.7 or later.
- All FortiOS 7.2, 7.0, and 6.4 releases require migration to a fixed supported branch.
- Products that never had SSL-VPN enabled are not affected.
- Exploitation requires an earlier compromise providing filesystem-level access.
- Review symbolic links, startup behavior, filesystem integrity, local administrators, API users, certificates, authentication settings, SSL-VPN configuration, firewall policies, and configuration history.
- Correlate findings with identity-provider, VPN, DNS, endpoint, internal-authentication, and network-flow logs.
- Determine whether the appliance was exposed to earlier FortiOS vulnerabilities before its last upgrade or cleanup.
- Contain and remove persistence before revoking credentials, sessions, certificates, and API secrets.
- Federal remediation deadline: August 10, 2026.
Assessment Confidence: High — Fortinet clearly defines the prerequisite and affected versions, while CISA’s later KEV entry establishes active exploitation. Public reporting does not establish the number or identity of compromised organizations.
Sources:
Fortinet PSIRT — FG-IR-25-934: SSL-VPN Symlink Persistence Patch Bypass.
NIST National Vulnerability Database — CVE-2025-68686 Detail and CISA KEV Update.
Patch / Upgrade Watch
OpenAM 16.1.2 closes pre-authentication RCE and a broader identity-server vulnerability cluster
OpenIdentityPlatform released OpenAM 16.1.2 with fixes for multiple security defects, including CVE-2026-62379, a CVSS 9.8 pre-authentication remote-code-execution vulnerability. The /authservice endpoint accepts an XML element naming a Java class and, in vulnerable versions, loads and instantiates it without adequate validation. The route is reachable without authentication under default configuration. All releases before 16.1.2 are affected.
The same release also lists a WebAuthn Java-deserialization RCE bypass, an authenticated Groovy sandbox escape, multiple server-side request forgery paths, LDAP injection, XACML policy-import code execution, and other identity-server flaws. Administrators should treat 16.1.2 as a security rollup rather than patching only the headline CVE.
Prioritize internet-facing and federation-critical OpenAM systems. Restrict /authservice and management interfaces while upgrading, preserve access and application logs, and inspect vulnerable systems for unusual XML callbacks, Java class loading, child-process execution, unexpected outbound connections, policy imports, and unauthorized identity or federation changes.
Source: OpenIdentityPlatform — OpenAM Release 16.1.2.
Source: GitLab Advisory Database — CVE-2026-62379: OpenAM Unauthenticated Remote Code Execution via Class.forName.
Additional VeloCloud flaws should be closed during the emergency upgrade window
Arista’s separate July 27 Advisory 0145 covers CVE-2026-17191, a CVSS 9.1 SQL-injection path that can enable server-side request forgery, and CVE-2026-17192, a second server-side request forgery vulnerability. Both require authenticated tenant access; the first can be exercised by the lowest built-in Enterprise Read Only role, while the second requires Enterprise Standard Admin. Arista reports no known malicious use.
The same 5.2.3.14, 6.1.3.4, and 6.4.2.4 releases used for the exploited command-injection flaw close these additional paths. Administrators should therefore complete the upgrade even where web exposure has already been restricted and should review low-privilege tenant accounts and unexplained outbound requests from the VCO.
Source: Arista Networks — Security Advisory 0145: SQL Injection and Server-Side Request Forgery in VeloCloud Orchestrator.
Budibase critical advisories affect stored credentials, single sign-on, and backend databases
Three GitHub-reviewed Budibase advisories published or updated July 24 deserve attention in self-hosted enterprise environments:
- A public query can redirect a REST datasource request to an attacker-controlled host while retaining stored Bearer, Basic, or static-header credentials. The advisory describes a one-request, unauthenticated theft path where a vulnerable query is published with the PUBLIC role.
- OpenID Connect account linking can match an incoming identity to an existing account by email without verifying
email_verified, potentially granting the victim’s roles—including global administrator—when a trusted identity provider will issue an unverified attacker-controlled email claim. - The MySQL integration enables multiple SQL statements, permitting arbitrary SQL injection through affected application input paths.
The advisories list versions through 3.38.1 as affected but leave their structured “patched versions” fields blank while linking corrective commits and releases 3.39.30, 3.40.0, and 3.40.1. Administrators should deploy a current release containing all relevant corrections rather than assuming one intermediate build resolves the entire cluster.
After updating, rotate credentials stored in REST datasources that were reachable through public queries; audit OIDC account links and active sessions; require verified email claims at every trusted identity provider; and restrict MySQL integration accounts to the minimum schemas and privileges required. Disable exposed integrations until remediation where an immediate upgrade is not possible.
Sources:
GitHub Advisory Database — Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak.
GitHub Advisory Database — Budibase: OIDC SSO Account Takeover Through Unverified Email Linking.
GitHub Advisory Database — Budibase: SQL Injection via multipleStatements.
Microsoft-hosted Azure disclosures require tenant review, not local package deployment
Microsoft published three exclusively hosted-service CVE records on July 24:
- CVE-2026-56163 affects Azure Kubernetes Service and allows unauthenticated privilege elevation over the network; Microsoft assigns CVSS 10.0.
- CVE-2026-58630 affects Azure App Service for Linux and allows unauthenticated privilege elevation; Microsoft assigns CVSS 10.0.
- CVE-2026-62835 affects Azure Portal and permits unauthorized information disclosure; Microsoft assigns CVSS 9.3.
The public records report no known exploitation and identify all three as automatable. Because these are provider-hosted services, administrators should not search for a conventional server patch package. Confirm remediation status and tenant-specific instructions through Microsoft Security Response Center, then review Azure Activity Logs, Kubernetes audit data, role assignments, service-principal activity, App Service changes, and unusual Portal access during the relevant exposure period.
Sources:
Microsoft Corporation and NIST NVD — CVE-2026-56163: Azure Kubernetes Service Privilege Elevation.
Microsoft Corporation and NIST NVD — CVE-2026-58630: Azure App Service for Linux Privilege Elevation.
Microsoft Corporation and NIST NVD — CVE-2026-62835: Azure Portal Information Disclosure.
Detection / Monitoring Watch
Hermes-assisted intrusion targeted Thai government application and data infrastructure
Hunt.io and researcher Bob Diachenko reported finding exposed attacker staging directories from July 9 through July 13 containing 585 files and approximately 470 MB of exploit code, stolen credentials, web shells, implants, and autonomous-agent logs. The material was tailored to Thailand’s Ministry of Finance and included active session material, internal host references, web-shell deployments, and tooling for ministry Hadoop, HiveServer2, Ambari, GlassFish, mail, and administrative systems. Thailand’s national CERT and National Cyber Security Agency were notified July 15 and acknowledged receipt; the research does not establish the initial-access path or confirm the full extent of data exfiltration.
The operator used the Hermes agent in unattended “YOLO” mode, allowing it to enumerate hosts, traverse files, process privilege-escalation results, and execute commands without per-action approval. A separate Windows and Linux Go implant called Hades provided interactive shell, persistence, proxying, file transfer, and—in the Windows build—process hollowing and screenshot capability.
Defenders responsible for government, tax, treasury, state-owned-enterprise, or large data-platform environments should review:
- HiveServer2 on port 10000 for weak or permissive SASL configuration, unauthorized sessions, malicious user-defined functions, and unexpected WebHDFS access.
- Ambari for unauthorized command payloads and changes to managed Hadoop nodes.
- GlassFish for unexplained WAR deployment, undeployment, headless-browser automation, and default or weak administrative credentials.
- Windows Run keys and scheduled tasks, Linux cron persistence, and Go binaries masquerading as
ctfmon,csrss,conhost,kworker,multipathd, oraccounts-daemon. - HTTPS traffic using Hades paths
/assets/app.min.js,/assets/vendor.js, or/assets/main.js. - Connections involving
43.246.208.207and202.181.27.115, while accounting for the source’s caveats regarding unrelated historical infrastructure on the same hosts. - Web shells,
suo5HTTP tunnels, LinPEAS output, session-cookie files, and unexpected access to internal administrative panels.
Assessment Confidence: Moderate — The research contains detailed captured infrastructure, malware, scripts, credentials, and logs, and Thai authorities acknowledged notification. It remains a third-party reconstruction without a public Thai government incident confirmation or a verified initial-access account.
Source: Hunt.io and Bob Diachenko — Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged.
Chaos ransomware hides remote-access traffic inside a controlled browser
Cisco Talos documented msaRAT, a Rust remote-access Trojan used after initial compromise and before Chaos ransomware deployment. The implant does not connect directly to its command server. It launches Chrome or Edge in headless mode with remote debugging enabled, controls the browser through the Chrome DevTools Protocol, uses a Cloudflare Workers endpoint for WebRTC signalling, and establishes a WebRTC DataChannel through Twilio TURN infrastructure. Once the channel is established, the signalling service leaves the traffic path.
Talos observed the attacker downloading update_ms.msi into C:\ProgramData using plain HTTP over destination port 443, then executing it to load the RAT DLL in memory. Firewall policy based only on port number could misclassify that traffic as encrypted HTTPS.
Detection should include:
- Chrome or Edge launched headlessly on servers or administrative workstations.
- Browser command lines enabling a remote-debugging port.
- Local WebSocket connections to Chrome DevTools endpoints and requests to
/json/list/. - Unexpected WebRTC or TURN sessions from systems that do not require browser-based real-time communications.
- Plain HTTP on TCP 443, especially downloads of
update_ms.msi. curl.exewriting executables or MSI files intoC:\ProgramData.- Browser processes functioning without an interactive user session.
- Ransomware precursor activity where endpoint telemetry shows browser traffic but no direct network activity from the suspected implant.
Source: Cisco Talos — Chaos Ransomware’s msaRAT: Living Off the Browser to Build a Covert C2 Channel.
Russian FSB Centre 16 continues exploiting weakly managed routers across critical sectors
New to this feed, but not a new July 28 disclosure: the UK National Cyber Security Centre and partners warned on July 13 that Russia’s FSB Centre 16 is exploiting vulnerable and poorly configured routers while opportunistically targeting communications, defence, energy, government, healthcare, and other critical networks worldwide. The actor scans for default or weak Simple Network Management Protocol credentials and community strings and has also exploited known Cisco vulnerabilities, Smart Install, and web-management flaws.
The UK and European Union also attributed the December 2025 attempted attack against Poland’s energy grid to Centre 16. The NCSC assessed that a successful attack could have deprived approximately 500,000 civilians of electricity.
Administrators should:
- Replace SNMPv1 and SNMPv2c with authenticated and encrypted SNMPv3.
- Remove default, shared, or weak community strings and management credentials.
- Restrict SNMP, SSH, Telnet, HTTP, HTTPS, and vendor-management protocols to designated management networks.
- Disable Cisco Smart Install where it is not explicitly required.
- Review configuration archives, firmware state, local users, startup configuration, access-control lists, routing, DNS, and unexplained tunnelling or port-forwarding.
- Preserve NetFlow, authentication, configuration-change, and management-plane logs for historical review.
Source: UK National Cyber Security Centre and international partners — Improve Router Hygiene and Defend Against Russian Intelligence Targeting.
APT-C-60 abuses Proton Drive and trusted development infrastructure against Japan
JPCERT/CC continues to observe APT-C-60 attacks against Japanese organizations. The 2026 chain uses Proton Drive or direct attachments to deliver RAR archives containing LNK files. Opening the shortcut invokes mshta.exe to execute embedded JavaScript, after which the attacker uses legitimate git.exe and services including GitHub, GitLab, jsDelivr, and Codeberg to retrieve SpyGlace payloads.
This activity is primarily an endpoint intrusion, but it has server and administrative relevance because developer-oriented services and content-delivery networks are often broadly permitted from engineering, build, and management networks. Blocking those domains wholesale is rarely practical.
Defenders should monitor archive extraction followed by LNK execution, mshta.exe launching script or network activity, unusual git.exe execution outside development workflows, and newly created files sourced from public code-hosting or content-delivery services. JPCERT/CC’s published command-and-control addresses and file hashes should be incorporated as time-bounded hunting pivots rather than permanent reputation judgements.
Source: JPCERT/CC — Update on Attacks by Threat Group APT-C-60 in 2026.
Lower-Priority Server-Risk Notes
Nichirei’s cyberattack disrupted refrigerated-warehouse inbound and outbound operations and frozen-food shipment activity in Japan, demonstrating the continuity consequences of compromising logistics systems that support food distribution. Nichirei reported on July 24 that ordering restrictions had been removed and all affected locations had returned to normal operation. The company has not publicly disclosed a technical entry vector or operational indicators, so the incident does not yet support a product-specific patch or hunt directive.
Research presented ahead of Black Hat concerning “confused deputy” relationships in Azure and Google Cloud remains worth tracking, but it was not promoted. Some Azure Backup and Kubernetes claims are disputed, the providers have not published corresponding broad vulnerability advisories, and CERT/CC clarified that intake of one report did not constitute independent validation. Pre-conference research should not be treated as a confirmed cross-cloud vulnerability class until technical conditions and provider responses are available.
The previously covered SharePoint, Zimbra, and Iranian PLC stories remain serious unresolved risks for organizations that have not completed remediation. They are not repeated today because this review found no material July 28 change sufficient to justify another full operational section. Their absence does not rescind earlier patching, hunting, credential-rotation, or process-validation guidance.
Routine AI-risk surveys, generic agentic-security marketing, ransomware takedown retrospectives, and consumer-oriented credential theft reporting were excluded because they did not provide new server exposure conditions, patches, verified indicators, or defensive actions.
Admin Action Checklist
- Restrict every on-premises VeloCloud Orchestrator to trusted management networks, preserve evidence, and deploy the appropriate fixed release.
- For exposed or suspicious VCO systems, rebuild from trusted sources, validate every managed Edge, and revoke credentials, certificates, API secrets, and private keys accessible through the orchestrator.
- Patch CVE-2025-68686-affected FortiGate appliances and investigate the earlier filesystem compromise required to exploit it; rebuild appliances whose integrity cannot be demonstrated.
- Upgrade OpenAM to 16.1.2 or later and investigate vulnerable identity servers for unauthorized class loading, child processes, policy imports, LDAP manipulation, and unexpected outbound traffic.
- Update self-hosted Budibase deployments using a release containing all current corrections; rotate exposed REST datasource credentials and audit OIDC identity links, administrator sessions, and MySQL access.
- Verify Microsoft’s remediation status for the July 24 Azure Kubernetes Service, App Service for Linux, and Azure Portal disclosures; review control-plane logs and privileged changes during the relevant period.
- Hunt government and large-data environments for Hermes/Hades activity, malicious Hive user-defined functions, unauthorized Ambari commands, GlassFish WAR deployment, web shells, and compromised session material.
- Detect headless Chrome or Edge with remote debugging, unexpected Chrome DevTools Protocol sessions, WebRTC or TURN traffic from servers, and plain HTTP transfers over port 443 associated with msaRAT.
- Replace legacy SNMP with SNMPv3, restrict network-device management planes, disable unnecessary Cisco Smart Install, and review router configuration integrity.
- Monitor Japanese and multinational environments for APT-C-60’s RAR/LNK,
mshta.exe,git.exe, and public-development-platform delivery chain. - Maintain earlier SharePoint, Zimbra, and PLC remediation as open work only where local evidence shows it remains incomplete; do not republish unchanged risk as though it were a new daily development.
BCG Assessment
Today’s strongest items are connected by a single architectural weakness: systems are routinely trusted to act on behalf of other systems. VeloCloud Orchestrator can alter downstream network devices. FortiGate decides which users and networks may cross a security boundary. OpenAM issues identity decisions consumed by applications. Budibase holds credentials for external datasources and databases. Azure control planes assign authority across hosted workloads. The value of each target is therefore measured not by the files stored on the server alone, but by the actions other infrastructure will accept from it.
The international campaign reporting adds a second dimension. The Thai operation used an autonomous agent to accelerate work after access was already obtained; the dangerous capability was not intelligence in the abstract, but unattended access to shells, credentials, Hadoop administration, application servers, and implants. Chaos ransomware similarly delegated communications to a browser so the malicious binary itself would not appear to use the network. APT-C-60 hid delivery behind ordinary development platforms, while Russia’s Centre 16 exploited neglected router-management practices. In each case, the adversary used something defenders ordinarily trust—an agent, browser, source platform, management protocol, or network appliance—to conceal or amplify malicious authority.
The correct sequence remains exposure control, evidence preservation, remediation, compromise assessment, trust revocation, downstream validation, and rebuilding where integrity cannot be demonstrated. Patch status answers whether vulnerable software has been replaced. It does not answer whether the identities, credentials, configurations, managed devices, databases, or physical operations that trusted the compromised system remain safe.
A recurring pre-publication watch can flag new KEV entries and international CERT developments before each edition; say the word and I’ll schedule it.
Jonathan Lockhart is a cybersecurity researcher and investigative journalist at bordercybergroup.com.
If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.
Member discussion: