Archive for July 2026
Certighost CVE-2026-54121 Active Directory Domain Takeover
Certighost CVE-2026-54121 Active Directory is a certificate-services flaw that turns any ordinary domain-user account into full control of your entire Windows domain — no admin rights, no malware, no phishing required. Microsoft patched it on July 14, 2026, but a full technical writeup and working proof-of-concept went public on July 24. If your Active Directory…
Read MoreTop 5 Cybersecurity News Stories July 31, 2026
The five stories in this week’s Cybersecurity News Stories July 31, 2026 each describe a different failure at the same architectural level: not the application layer, not the endpoint estate, not even the network perimeter as conventionally modelled — but the foundational infrastructure that the perimeter, the applications, and the endpoints depend on in order…
Read MoreArista VeloCloud Orchestrator CVE-2026-16812 Exploited
Arista VeloCloud Orchestrator CVE-2026-16812 is a maximum-severity, unauthenticated command injection flaw under active exploitation right now, and it hands an attacker control of an entire SD-WAN fabric from a single unpatched management console. CISA added it to the Known Exploited Vulnerabilities catalog on July 27, with a federal patch deadline of July 30. If your…
Read MoreStadler Rail Everest Ransomware: SFr10m Demand Refused
The Stadler Rail Everest ransomware incident shows what a mature extortion response looks like: the Swiss train manufacturer confirmed that the Everest group stole supplier technical data through a shared data-exchange platform and demanded roughly SFr10m (about $12.3M) — and Stadler refused outright, filing a criminal complaint instead of negotiating. What Happened Stadler Rail, an…
Read MoreRansomware in Germany: From IT Incident to Insolvency Risk
Ransomware in Germany is no longer an abstract IT concern — in 2026, it is one of the more concrete threats to whether a company survives at all. Two recent cases illustrate how differently this threat can play out. ZEGO Textilveredelungszentrum filed for insolvency following a cyberattack, without the attack type ever being publicly confirmed.…
Read More
