Actively exploited Arista flaw exposes the SD-WAN control planeOrigin Energy says approximately 900,000 customers were affectedFairlife confirms data theft while restoring US productionMCBS breach extends healthcare exposure through seven clients
Actively exploited Arista flaw exposes the SD-WAN control plane
Unauthenticated command injection in on-premises VeloCloud Orchestrator is under active exploitation, carries a three-day federal remediation deadline and requires compromise assessment beyond installing the fixed release.
Security.io Intelligence Desk · Tuesday, 28 July 2026
Executive consequence
Arista disclosed CVE-2026-16812 on 27 July, confirmed active exploitation and published three observed attack-source IP addresses.
Decision today
Inventory every on-premises VCO instance and record its version and web-interface exposure.
Read the full decision briefPrimary reporting: Arista Security Advisory 0144 · CISA Known Exploited Vulnerabilities Catalog · NIST National Vulnerability Database · BleepingComputer · Arista Security Advisory 0144
Decision intelligence, not a headline feed.Every edition ranks what security leaders should read first, assign today and monitor next.
Six-minute executive briefing
Security.io Daily Headlines
Five equally weighted stories: what happened and the leadership decision each creates.
CVE-2026-16723 affects Fastjson 1.2.68 through 1.2.83 in Spring Boot executable fat-JAR deployments. Imperva reports attacks across multiple sectors, while maintainers recommend SafeMode, a noneautotype build or migration to Fastjson2.
Do today
Search source, build and runtime inventories for Fastjson 1.x.
A 27 July company update confirms both production recovery and data theft following the Fairlife ransomware event disclosed on 16 July. Product safety and quality were unaffected, but the categories and population of data taken remain undisclosed.
Do today
Confirm whether Fairlife disruption creates material supplier or inventory dependencies.
Origin Energy's 28 July update says information belonging to approximately 900,000 current and former customers was accessed. The company is notifying affected customers and warns that criminals may exploit the incident through impersonation and scams.
Do today
Check fraud controls for impersonation using breached utility-account information.