Security.io Intelligence DeskFriday, 7 August 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
Actively exploited Arista flaw exposes the SD-WAN control planeOrigin Energy says approximately 900,000 customers were affectedFairlife confirms data theft while restoring US productionMCBS breach extends healthcare exposure through seven clients
Tuesday, 28 July 2026 · 06:00 America/New_York · Executive decision brief

Actively exploited Arista flaw exposes the SD-WAN control plane

Unauthenticated command injection in on-premises VeloCloud Orchestrator is under active exploitation, carries a three-day federal remediation deadline and requires compromise assessment beyond installing the fixed release.

Executive consequence

Arista disclosed CVE-2026-16812 on 27 July, confirmed active exploitation and published three observed attack-source IP addresses.

Decision today

Inventory every on-premises VCO instance and record its version and web-interface exposure.

Decision intelligence, not a headline feed.Every edition ranks what security leaders should read first, assign today and monitor next.
Six-minute executive briefing

Security.io Daily Headlines

Five equally weighted stories: what happened and the leadership decision each creates.

Read today’s headlines

Today’s decision ledger

What changed · Why it matters · What to do
02
Application and Software Supply Chain Security

Fastjson 1.x exploitation turns dependency discovery into an emergency

Why it matters

CVE-2026-16723 affects Fastjson 1.2.68 through 1.2.83 in Spring Boot executable fat-JAR deployments. Imperva reports attacks across multiple sectors, while maintainers recommend SafeMode, a noneautotype build or migration to Fastjson2.

Do today

Search source, build and runtime inventories for Fastjson 1.x.

Read the briefing →
03
Incident Response and Resilience

Fairlife confirms data theft while restoring US production

Why it matters

A 27 July company update confirms both production recovery and data theft following the Fairlife ransomware event disclosed on 16 July. Product safety and quality were unaffected, but the categories and population of data taken remain undisclosed.

Do today

Confirm whether Fairlife disruption creates material supplier or inventory dependencies.

Read the briefing →
05
Data Protection and Critical Services

Origin Energy says approximately 900,000 customers were affected

Why it matters

Origin Energy's 28 July update says information belonging to approximately 900,000 current and former customers was accessed. The company is notifying affected customers and warns that criminals may exploit the incident through impersonation and scams.

Do today

Check fraud controls for impersonation using breached utility-account information.

Read the briefing →

Signal desk

Evidence that changes prioritisation
Security.io editorial score, 0–100

Executive decision priority across today's edition

Security.io scores each selected development from 0–100 using a weighted editorial assessment of Exposure at 35%, Urgency at 35% and Business Consequence at 30%. Scores compare leadership decisions, not technical severity or CVSS ratings. Source: Security.io editorial scoring derived from the selected primary, regulatory and original-research sources.

Appointments, dinners & sponsored intelligence

Current paid placements · clearly separated
Registration open
Sponsor's Notice · Information Security Network

Security.io Executive Roundtable: The 2027 CISO Agenda

CISO Roundtables & Executive events

View roundtables →
Invitation only
Sponsor's Notice · NoBrowser

Security.io CISO Dinner: The Secure Browser Decision

Virtual PC's & Secure Browsers in the Cloud

Request an invitation →
Black Hat week
Paid Placement · HackerFX

Security.io at Black Hat: Daily Intelligence Briefing

Catch the Daily News Where it Happens First

Follow the Black Hat desk →