
Daily DefSec Brief - Cyber Security News for July 28 2026
Show notes
1. Arista VeloCloud Orchestrator zero-day exploited, added to CISA KEV — CVE-2026-16812 — SecurityWeek — https://www.securityweek.com/critical-arista-velocloud-orchestrator-vulnerability-exploited-as-zero-day/
2. Critical TeamCity auth-bypass RCE, patch on-prem now — CVE-2026-63077 — The Hacker News — https://thehackernews.com/2026/07/critical-teamcity-flaw-could-let.html
3. Fortinet FortiOS info-exposure flaw added to KEV — CVE-2025-68686 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
4. FastJson RCE zero-day, active US targeting confirmed — CVE-2026-16723 — SecurityWeek — https://www.securityweek.com/unpatched-fastjson-vulnerability-exploited-in-attacks/
5. Windows LegacyHive logon-time PoC bypasses July patches — no CVE — Cyber Security News — https://cybersecuritynews.com/legacyhive-exploitation-chain/
6. Progress LoadMaster: five flaws, command injection to root — CVE-2026-59686 through CVE-2026-59690 — Cyber Security News — https://cybersecuritynews.com/five-progress-loadmaster-vulnerabilities/
7. Operation BlueDash: fake Teams update installs Level RMM and ScreenConnect — no CVE — The Hacker News — https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html
8. Mirage Kitten deploys NightLedger backdoor and WebSocket tunnelers — no CVE — Securelist — https://securelist.com/mirage-kitten-new-tools/120811/
9. libssh2 flaws let a malicious SSH server corrupt client memory — CVE-2026-66032 through CVE-2026-66035 — Cyber Security News — https://cybersecuritynews.com/libssh2-vulnerabilities/
10. vBulletin pre-auth RCE now has a public exploit — CVE-2026-61511 (also CVE-2025-48827, CVE-2025-48828) — The Hacker News — https://thehackernews.com/2026/07/public-exploit-released-for-patched.html
11. n8n sandbox escape lets workflow editors run OS commands — GHSA-gv7g-jm28-cr3m — The Hacker News — https://thehackernews.com/2026/07/n8n-sandbox-escape-lets-workflow.html
12. AutoIT payload injector delivered via fake bank emails — no CVE — SANS ISC — https://isc.sans.edu/diary/rss/33192