Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks.
Independent cybersecurity / privacy / AI risk journal
A restrained field journal for cybersecurity, privacy, and AI risk signals worth keeping.
Lead briefing
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks.
Latest
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges.
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations.
Yet another Israeli mass surveillance company: Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops to keep tabs on any phones in the vicini…
Topics
318 entries
Cybersecurity briefings on breaches, exploited vulnerabilities, ransomware, incident response, and systemic security failures.
41 entries
Privacy briefings on data misuse, tracking changes, surveillance harms, regulator action, and data rights enforcement.
112 entries
AI risk briefings on model misuse, deployment failures, safety regressions, governance gaps, and synthetic-media harms.
22 entries
Governance briefings on enforcement, standards, court action, regulator opinions, institutional accountability, and policy shifts.
7 entries
Infrastructure briefings on cloud, telecoms, public systems, network edge, and critical infrastructure risk developments.
3 entries
Surveillance briefings on biometrics, monitoring systems, identity correlation, tracking technology, and public or private observation systems.