|
Here is the most recent Cybersecurity news for the past week:
⚡ Arista Patches Maximum-Severity VeloCloud Orchestrator Zero-Day Under Active Exploitation
Arista released emergency security updates to address a maximum-severity OS command injection vulnerability (CVE-2026-16812, CVSS 10.0) in on-premises VeloCloud Orchestrator deployments. Threat actors are actively exploiting the bug in the wild to execute arbitrary system commands with elevated privileges without requiring prior authentication.
https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/
🔓 Australian Energy Giant Origin Energy Confirms Customer Data Breach
Origin Energy Limited, one of Australia’s primary electricity and natural gas providers, confirmed a cybersecurity intrusion impacting customer data.A threat actor claims to have exfiltrated sensitive information belonging to two million customers, including names, dates of birth, phone numbers, and partial financial details.
https://www.securityweek.com/data-breach-confirmed-after-australian-energy-giant-origin-is-hacked/
🛠️ Critical JetBrains TeamCity RCE Vulnerability Threatens On-Premises Servers
JetBrains issued urgent patches for a maximum-severity vulnerability (CVE-2026-63077, CVSS 9.8) affecting all on-premises versions of TeamCity CI/CD software. The flaw enables unauthenticated remote attackers with network access to bypass authentication mechanisms and execute arbitrary OS commands on vulnerable servers.
https://thehackernews.com/2026/07/critical-teamcity-flaw-could-let.html
🏥 DentaQuest Data Breach Potentially Affects Over 23 Million Individuals
US dental benefits administrator DentaQuest disclosed a major data breach following a network intrusion linked to the ShinyHunters extortion group.The incident potentially compromised protected health and personal information—including Social Security numbers, Medicare IDs, treatment records, and billing data—for tens of millions of individuals.
https://www.securityweek.com/dentaquest-data-breach-potentially-impacts-over-23-million-people/
🎵 Massive Data Breaches at Suno and Paidwork Expose 78 Million User Records
Data breach notification service Have I Been Pwned revealed significant data leaks affecting AI music generation service Suno (55.3 million accounts) and gig platform Paidwork (23.3 million accounts). The exfiltrated datasets include email addresses, hashed passwords, physical locations, phone numbers, and partial payment details.
https://www.securityweek.com/suno-paidwork-data-breaches-affect-tens-of-millions-of-accounts/
|