Hackers target US firms in FastJson RCE zero-day attacks (2026-07-27 23:49 UTC)
Kurz: Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. […]
Kurz: Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. […]
New Dysphoria DDoS botnet spreads to 200k devices worldwide (2026-07-27 21:08 UTC)
Kurz: A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. […]
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost (2026-07-28 06:07 UTC)
Kurz: Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It als…
Kurz: A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating s…
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework (2026-07-27 18:10 UTC)
Kurz: NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security…