Code Defender
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution.
“VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue
Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost
The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already
Adversaries Don’t Need a Zero-Day — They Read Your Rulebook
FBI: Breaking Affiliate Trust Sped Along LockBit’s Takedown
‘Confused Deputy’ Flaws Persist in Google Cloud, Microsoft Azure
MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection
The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems.
The post MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection appeared first on SecurityWeek.
PTC Windchill Vulnerability Exploited in Ransomware Campaign
The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication.
The post PTC Windchill Vulnerability Exploited in Ransomware Campaign appeared first on SecurityWeek.
Recent Comments