Tuesday, July 28, 2026 | Jonathan Lockhart
Attackers Were Already Inside VeloCloud Orchestrators When Arista Published the Fix
Arista Networks disclosed on July 27 that attackers are exploiting CVE-2026-16812, an operating-system command-injection flaw in on-premises VeloCloud Orchestrator. Arista assigned the vulnerability a 10.0 base score under both CVSS 3.1 and CVSS 4.0. A remote attacker needs network access to the web interface but no tenant or operator credentials. Arista says the vulnerable functionality is exposed by default and cannot be disabled through a product configuration.
The flaw affects the on-premises product formerly owned by Broadcom. Hosted and dedicated VeloCloud Orchestrator services were patched before disclosure. Fixed releases are 5.2.3.14, 6.1.3.4, 6.4.2.4 and 7.0.0.1. The Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on July 27, with a July 30 federal remediation deadline.
Arista has published three source addresses observed in the attacks, but it has not identified the actor, victim count or exploitation start date. Those addresses are useful hunting pivots, not a complete boundary around the campaign. Because the orchestrator stores configuration, inventory, credentials, certificates and key material for software-defined wide-area networking, patching a previously exposed system is not enough. Suspected compromises require log preservation, credential rotation, validation of managed edge-device state and, where trust cannot be re-established, restoration or replacement from a known-good source.
Watch for: Additional exploitation infrastructure, confirmed victim scope or evidence that compromised orchestrators were used to alter configurations or reach managed VeloCloud Edge devices.
Sources: Arista Networks Security Advisory 0144, “VeloCloud Orchestrator On-Prem OS Command Injection,” July 27, 2026; CISA, “CISA Adds Two Known Exploited Vulnerabilities to Catalog,” July 27, 2026.
Every On-Premises TeamCity Server Needed a Fix at Once
JetBrains warned on July 27 that every version of TeamCity On-Premises is affected by CVE-2026-63077. An unauthenticated attacker who can reach the server over HTTP or HTTPS can abuse the TeamCity agent-polling protocol to bypass authentication and execute operating-system commands with the privileges of the TeamCity server process.
JetBrains fixed the flaw in TeamCity 2025.11.7 and 2026.1.3. Its advisory explicitly says that a security-patch plugin is available for installations running version 2017.1 or later when an immediate full upgrade is not possible. Versions 2017.1 through 2018.1 require a server restart after installation; version 2018.2 and later can enable the plugin without one. The plugin addresses only this vulnerability, not the other security debt carried by an old TeamCity release. TeamCity Cloud has already been protected and requires no customer action. JetBrains said it knew of no active exploitation when it published the advisory, and no public proof of concept was identified during this review.
The risk extends beyond control of one application server. TeamCity may hold repository tokens, signing material, deployment credentials, build configurations and access paths into downstream environments. Successful compromise could therefore alter source-derived artifacts or turn a continuous-integration server into a bridge toward production. Organizations that exposed TeamCity to the internet should patch promptly, review server and agent activity, and be prepared to rotate stored secrets if suspicious access is found.
Watch for: Public exploit code, scanning of TeamCity login and agent-polling endpoints, or the first confirmed case in which the flaw is used to tamper with builds or steal pipeline credentials.
Sources: JetBrains, “Critical Security Issue Affecting TeamCity On-Premises (CVE-2026-63077)—Update to 2025.11.7 or 2026.1.3 Now,” July 27, 2026.
CISA Says Attackers Are Exploiting a FortiOS Flaw That Matters Only After the First Breach
CISA added CVE-2025-68686 to its Known Exploited Vulnerabilities catalog on July 27, reversing the practical assessment of a FortiOS issue that Fortinet disclosed in February. CISA has set an August 10 remediation deadline for federal agencies. Public reporting does not yet identify the actor, initial-access vulnerability or number of affected appliances.
This is not a fresh way into a FortiGate. An attacker must already have filesystem-level access obtained through another vulnerability. CVE-2025-68686 then permits crafted HTTP requests to bypass a repair Fortinet developed for malicious symbolic links left behind after exploitation of older SSL-VPN flaws. In other words, the weakness can preserve access or sensitive-file exposure after a defender believes the original vulnerability has been patched.
That distinction is operationally decisive. A current firmware version does not prove that an appliance exploited before the update is trustworthy. Organizations with historically exposed or previously vulnerable FortiGate devices should follow Fortinet’s branch-specific upgrade guidance, but also inspect for unauthorized symbolic links and configuration changes, rotate credentials and certificates reachable from the appliance, and rebuild questionable devices from trusted images.
Watch for: CISA or Fortinet publishing the initial-access chain, affected symlink paths, campaign indicators or evidence connecting the persistence bypass to a named espionage or ransomware operation.
Sources: CISA, “CISA Adds Two Known Exploited Vulnerabilities to Catalog,” July 27, 2026; Fortinet PSIRT Advisory FG-IR-25-934, “SSL-VPN Symlink Persistence Patch Bypass,” February 10, 2026.
A Cyberattack Disrupted Mobile and Internet Service Across Angola
Angola’s largest telecommunications operator, Unitel, said a cyberattack detected at 2:20 a.m. local time on July 28 disrupted voice, mobile-data and internet services nationwide. Unitel serves more than 21 million customers in a country of roughly 39 million people. Services remained affected when the company issued its initial statement, and restoration work was continuing.
Unitel has not described the intrusion method, identified an actor, reported data theft or called the incident ransomware. The timing is conspicuous—the state-controlled company is due to begin public share trading on July 29—but timing alone is not evidence of motive. Sabotage, extortion, opportunistic intrusion and an attack intended to embarrass the company before its listing all remain possibilities.
The immediate consequence is availability, not attribution. A national mobile outage interferes with business transactions, healthcare coordination, transport applications, emergency communication and any service that treats the cellular network as its fallback channel. Continuity plans that depend on a single national carrier can fail together even when the organizations relying on it have not themselves been breached.
Watch for: The restoration timeline, emergency-service effects, evidence of destructive activity or data theft, a ransom demand, or a credible claim that explains whether the stock-market listing influenced the attack.
Sources: Unitel statement on the July 28 cyberattack, July 28, 2026, as reported by Reuters and Lusa; Reuters, “Angola’s Unitel Hit by Cyberattack Ahead of Stock Market Debut,” July 28, 2026.
Origin Energy Now Places Its Breach at About 900,000 Customers
Origin Energy said on July 28 that information linked to approximately 900,000 current and former customers may have been accessed in its recent security incident. The major Australian energy retailer began reviewing a threat in early July but initially assessed it as not credible. New information received on July 22 changed that judgment and prompted customer and market notifications.
The potentially exposed records include names, addresses, dates of birth, phone numbers, Origin account information and partial financial details such as the last digits of a credit card or bank account. Origin says the incomplete payment data cannot by itself be used to make transactions. It has not disclosed the access route, duration of unauthorized access or whether the actor moved beyond customer-information systems. No disruption to electricity or gas delivery has been reported.
The confirmed estimate is materially below an attacker’s earlier claim of two million records, but 900,000 is still a large and useful social-engineering dataset. Former customers are especially easy to overlook in response planning because they may no longer monitor Origin communications closely. Scam detection should focus on messages that combine genuine account details with requests to “verify” payment, identity or service information.
Watch for: A confirmed intrusion path, a regulator’s account of the disclosure timeline, evidence that operational systems were reached, or publication of data that tests Origin’s current estimate and description of the exposed fields.
Sources: Origin Energy, “Customer Data Security Incident,” updated July 28, 2026; Reuters, “Australia’s Origin Energy Flags Possible Data Exposure of About 900,000 Customers,” July 28, 2026; ABC News Australia, “Origin Energy Believes 900,000 Customers’ Data Accessed in Breach,” July 28, 2026.
Dysphoria Turned 200,000 Compromised Devices into Both a Botnet and a Relay Network
QiAnXin XLab and China’s national computer emergency response center published an analysis of Dysphoria, a rapidly changing botnet they estimate has infected more than 200,000 devices. XLab first observed the family in March and recorded repeated redesigns through July, including separate variants for distributed denial-of-service attacks and for turning victims into traffic relays.
Dysphoria spreads through weak Telnet and SSH credentials and exploits known flaws in routers, cameras and other internet-connected devices. Its newer versions retrieve command infrastructure through Ethereum and Solana naming records, conceal server addresses inside strings that resemble IPv6 data and use compromised systems as intermediate relays. One proxy-focused variant abuses Universal Plug and Play to create 155 port-forwarding rules, potentially exposing internal services to inbound connections.
The 200,000-device figure is XLab’s estimate, not an independently verified census. The operators’ advertised four-terabit-per-second attack capacity is also a marketing claim. The more defensible finding is architectural: blockchain-based resolution and victim relays make command infrastructure harder to remove, while the proxy variant gives customers access to residential or small-office network positions that can support intrusions beyond denial of service.
Watch for: Independent measurement of the bot count, attacks demonstrating the claimed capacity, new exploitation modules or evidence that Dysphoria’s relay nodes are being sold for credential attacks and enterprise intrusion.
Sources: QiAnXin XLab and CNCERT, “Dysphoria Botnet Evolution and In-Depth Technical Analysis,” July 25, 2026; BleepingComputer, “New Dysphoria DDoS Botnet Spreads to 200K Devices Worldwide,” July 27, 2026.
Cruciferra Sells Defense Evasion as Reusable Cybercrime Infrastructure
Proofpoint has documented Cruciferra, a crypter service used by multiple unrelated criminal groups to conceal remote-access trojans and information stealers. The service has been advertised since late 2025 at prices ranging from $450 to $2,000 per month. Proofpoint observed dozens of campaigns delivering payloads including AsyncRAT, XWorm, Remcos, FormBook, XLoader and Agent Tesla.
Cruciferra is more than a simple packer. Its variants use vulnerable kernel drivers to interfere with endpoint detection, indirect system calls and API unhooking to avoid monitoring, privilege escalation, registry persistence and a modified form of Process Ghosting designed to leave fewer useful disk artifacts. Proofpoint identified more than 90 changing combinations of cryptographic routines used to protect payloads, with new builds appearing frequently.
The service illustrates why malware families should not be treated as self-contained adversaries. Different actors can buy the same evasion layer, place different payloads behind it and create campaigns that look unrelated at the email or command-server level. Defenders gain more durable coverage by detecting vulnerable-driver loading, security-process termination, abnormal memory-backed execution and other shared behaviors rather than relying on one packed-file hash.
Watch for: Wider adoption by ransomware affiliates, new vulnerable drivers, changes that defeat current behavioral detections or a stable infrastructure pattern that allows campaigns using different payloads to be clustered reliably.
Sources: Proofpoint Threat Research, “Unpacking ‘Cruciferra’: An Analysis of a Sophisticated Crypter Service,” July 20, 2026.
GitHub and PyPI Added Time as a Software-Supply-Chain Control
GitHub has made a three-day package cooldown the default for Dependabot version updates. A newly published dependency must now remain available in its registry for at least three days before Dependabot opens a routine version-update pull request. Security updates are exempt and can still move immediately, so the delay does not hold back a known vulnerability fix.
The Python Package Index has adopted a different time barrier. Since July 22, PyPI has rejected attempts to add files to releases more than 14 days old. The change prevents an attacker who steals a maintainer token from quietly adding a malicious build for a new platform to an old, trusted version. PyPI says it is not aware of that technique having been abused in the wild; the control closes a plausible path before it becomes routine.
Together, the changes target opposite ends of package poisoning. GitHub slows the automatic uptake of a dangerously fresh release, while PyPI prevents the resurrection of an old release as a delivery vehicle. Neither replaces version pinning, provenance verification, protected publisher identities or review of dependency changes, but both reduce the advantage attackers gain from moving faster than maintainers and scanners.
Watch for: Other registries adopting minimum-age or release-freeze policies, evidence that the controls prevented a live poisoning attempt, or attackers shifting toward theft of existing build workflows and signing identities.
Sources: GitHub, “Dependabot Version Updates Introduce Default Package Cooldown,” July 14, 2026; GitHub, “The Case for a Cooldown: Why Dependabot Now Waits Before Issuing Version Updates,” July 23, 2026; PyPI, “Releases Now Reject New Files After 14 Days,” July 22, 2026.
Apple’s Patch Count Is Huge, but This Is Not an Active-Zero-Day Alert
Apple’s July 27 security releases address 87 vulnerabilities in iOS and iPadOS 26.6 and 155 in macOS Tahoe 26.6. SecurityWeek counted 138 fixes in macOS Sequoia 15.7.8 and 127 in Sonoma 14.8.8, with many vulnerabilities shared across platforms. Apple also issued substantial updates for Safari, watchOS, tvOS and visionOS.
The advisories include flaws that can permit arbitrary code execution, kernel-memory corruption, sandbox escape, root privilege escalation, code-signing or Gatekeeper bypass and access to protected data. On iOS and iPadOS, CVE-2026-64747 can allow an application to execute code with kernel privileges, while CVE-2026-43810 may allow a remote user to terminate a system or corrupt kernel memory. The practical prerequisites differ across the long list, and the count alone does not measure exploitability.
Neither Apple nor the public advisories reviewed for this edition reported in-the-wild exploitation. That makes this a broad maintenance event rather than an emergency zero-day notice. Managed fleets should still avoid treating mobile and desktop Apple devices as self-updating by assumption: verify deployment, confirm that older supported operating-system branches received the intended fixes and identify devices unable to move to a protected release.
Watch for: Apple revising an advisory to acknowledge exploitation, exploit chains combining a remote-content flaw with kernel privilege escalation, or important gaps between the current and older supported operating-system branches.
Sources: Apple, “About the Security Content of iOS 26.6 and iPadOS 26.6,” July 27, 2026; Apple, “About the Security Content of macOS Tahoe 26.6,” July 27, 2026; SecurityWeek, “Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe,” July 28, 2026.
Bit2Watt Asks Whether a Legitimate GPU Tenant Could Disturb the Power Grid
Researchers from Zhejiang University have described Bit2Watt, a cyber-physical attack concept in which a legitimate cloud customer rapidly changes GPU workloads to create controlled oscillations in electrical demand. It requires no compromise of a utility network and no software vulnerability in the conventional sense. The tenant alternates computation-intensive and low-load states, turning authorized use of rented hardware into a deliberately unstable power profile.
The researchers measured high-frequency power modulation on real GPUs and grid-connected photovoltaic inverters, then modeled the larger electrical consequences. In their synchronized worst-case simulation, 1,000 GPUs operating against a one-megawatt local system with 90 percent distributed energy resources produced 46.8 percent current harmonic distortion and a negative damping ratio. Those are serious modeled conditions, but they are not evidence that anyone has caused a real grid failure this way. Coordinating that many cloud GPUs with the required timing also remains an important practical constraint.
The value of the paper is the boundary it exposes. Cloud schedulers see legitimate workloads; facilities teams see electrical behavior; grid operators see aggregate demand. An attack can live in the gaps between those views. Plausible defenses include correlating tenant scheduling with high-frequency power telemetry, limiting tightly synchronized load transitions, distributing workloads across power domains and adding buffering or controls at the facility layer.
Watch for: Reproduction at meaningful facility scale, cloud-provider mitigations, evidence that synchronization is practical across rented infrastructure or a real incident showing deliberate workload-driven power disturbance.
Sources: Zhouhao Ji, Kaikai Pan and Wenyuan Xu, “Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures,” arXiv, July 7, 2026; The Hacker News, “New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit,” July 21, 2026.
Jonathan Lockhart is a cybersecurity researcher and investigative journalist at bordercybergroup.com.
If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.
Member discussion: