Origin Energy Data Breach Affects 900,000 Australians

Origin Energy Data Breach Exposes 900,000 Australians to Cyber Threats A major data breach at Australian energy giant Origin Energy has compromised sensitive information for nearly a million customers. The incident highlights the growing threat of cyber attacks against critical infrastructure and the importance of vigilance in protecting personal data. The breach, which was discovered … Read more

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

A Critical Vulnerability in Arista’s VeloCloud Orchestrator Platform Has Been Exploited in the Wild In a stark reminder of the ongoing threat landscape, Arista Networks has released patches for a critical-severity vulnerability affecting its VeloCloud Orchestrator (VCO) centralized management platform. The security flaw, tracked as CVE-2026-16812, has already been exploited by attackers as a zero-day, … Read more

Unpatched Fastjson Vulnerability Exploited in Attacks

A critical vulnerability in the popular Fastjson library is being exploited by threat actors to execute arbitrary code on vulnerable servers, posing a significant risk to data confidentiality, integrity, and availability. The issue affects all deployments running as Spring Boot executable fat-jars, which are widely used in various sectors, including business, computing, financial services, healthcare, … Read more

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

Cybersecurity researchers have identified a critical vulnerability in the Arista VeloCloud Orchestrator, a software tool used for network management and orchestration. Attackers have been exploiting this flaw to inject malicious commands, potentially leading to unauthorized access and data breaches. The issue arises from a command injection bug that allows attackers to bypass security measures and … Read more

Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost

A significant breakthrough in artificial intelligence-powered cybersecurity has been announced by Microsoft, with the company claiming that its new AI model has achieved an impressive 95.95% accuracy rate in detecting and mitigating software vulnerabilities – all while reducing costs by half. This development is set to have far-reaching implications for organizations worldwide, highlighting the critical … Read more

Origin Energy Data Breach Affects 900,000 Australians

A massive data breach has affected over 900,000 current and former customers of Origin Energy Limited, one of Australia’s largest electricity and gas retailers. The incident highlights the growing threat of cyber attacks on critical infrastructure and the importance of robust security measures to protect sensitive information. Origin Energy, which serves approximately 4.8 million customers … Read more

Adversaries Don’t Need a Zero-Day — They Read Your Rulebook

Cybersecurity’s Biggest Weakness: Your Own Rulebook A disturbing trend has emerged in the world of cybersecurity, where adversaries are exploiting not the technical vulnerabilities of systems, but rather the rules and governance designed to protect them. Autonomous security tools, once hailed as a game-changer in the fight against cyber threats, are now being outsmarted by … Read more

FBI: Breaking Affiliate Trust Sped Along LockBit’s Takedown

The takedown of LockBit, one of the most successful ransomware-as-a-service (RaaS) groups in history, was a major milestone for law enforcement. The group’s operations were disrupted by Operation Cronos, a multinational effort that targeted its infrastructure and severed ties with its network of affiliates. This article will explore how the FBI and its international partners … Read more

‘Confused Deputy’ Flaws Persist in Google Cloud, Microsoft Azure

Significant security flaws have been discovered in Google Cloud and Microsoft Azure, allowing attackers to easily acquire administrative-level permissions and bypass access controls. These “confused deputy” vulnerabilities, also known as CWE-114, are a type of weakness that has persisted for nearly 40 years since their discovery by computer scientist Norm Hardy in the late 1980s. … Read more

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

A Critical Flaw Exposes VeloCloud Orchestrator Systems to Command Injection Attacks A significant security vulnerability has been discovered in Arista’s VeloCloud Orchestrator, an essential component of many businesses’ network management infrastructure. The flaw, which allows attackers to inject malicious commands, poses a substantial risk to organizations relying on these systems for network orchestration and automation. … Read more