Latest NEWS

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution.
"VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue
28 July 2026
From:
info@thehackernews.com (The Hacker News) [The Hacker News]

China fights back in AI spat with claim US AI companies distil Chinese models
Beijing happy to ‘take all necessary measures’ if sanctioned
28 July 2026
From:
[www.theregister.com - Articles]

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents.
The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux
28 July 2026
From:
info@thehackernews.com (The Hacker News) [The Hacker News]

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
Monday starts with the usual promise that everything is under control. Then the logs wake up.
This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped.
That is the mood. Here is the full recap.
⚡ Threat of the Week
OpenAI Says Its AI Agent Went Rogue
28 July 2026
From:
info@thehackernews.com (The Hacker News) [The Hacker News]

Hyperscale, hypersensitive: US teacher cuffed for applauding datacenter critics
Public meeting over proposed AI bit barn ended with zoning approval, a physics teacher arrested, and fresh questions over whether clapping now counts as disorderly conduct
28 July 2026
From:
[www.theregister.com - Articles]

HelloNet campaign — new malicious modules launched through the ViPNet update system
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
28 July 2026
From:
Konstantin Isakov, Georgy Kucherin, Anton Kargin [Securelist]

Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign
An inside look at the active Armored Likho APT campaign. The attackers are using spear-phishing, AI-generated loaders, and a new Python-based tool, BusySnake Stealer, to target organizations in Russia, Kazakhstan, and Brazil.
28 July 2026
From:
Kaspersky [Securelist]


.jpg)


