Microsoft Teams Vishing Ransomware Hits in 17 Hours

A Microsoft Teams vishing ransomware campaign, STAC4749, breached dozens of firms via fake IT-helpdesk calls, encrypting networks within 17 hours.

A Microsoft Teams vishing ransomware campaign has hit dozens of North American organizations since February 2026, using two-minute fake IT-helpdesk phone calls to gain a foothold that, in the fastest confirmed case, ended in full Chaos ransomware encryption within 17 hours of first contact. What Happened Security vendor Sophos tracked the campaign to a financially…

Read More

Cisco Secure FMC CVE-2026-20316 Exploited

Cisco Secure FMC CVE-2026-20316 is under active attack via hardcoded credentials that chain into a CVSS 10.0 root bypass. Patch now.

Cisco Secure FMC CVE-2026-20316 is under confirmed active exploitation: a hardcoded, low-privilege account built into every on-premises Secure Firewall Management Center gives an unauthenticated attacker a foothold — and in the same advisory cycle, Cisco quietly reactivated a five-month-old, maximum-severity root-level bypass in the same product, sharing an identical indicator of compromise. CISA added the…

Read More

Certighost CVE-2026-54121 Active Directory Domain Takeover

Certighost CVE-2026-54121 Active Directory flaw lets any standard user impersonate a Domain Controller and take over the entire domain via DCSync.

Certighost CVE-2026-54121 Active Directory is a certificate-services flaw that turns any ordinary domain-user account into full control of your entire Windows domain — no admin rights, no malware, no phishing required. Microsoft patched it on July 14, 2026, but a full technical writeup and working proof-of-concept went public on July 24. If your Active Directory…

Read More

Top 5 Cybersecurity News Stories July 31, 2026

Cybersecurity News Stories July 31, 2026: Minnesota water OT attack, TeamCity CVSS 9.8 RCE, Certighost AD CS domain takeover, NGINX chain RCE, Cisco FMC KEV.

The five stories in this week’s Cybersecurity News Stories July 31, 2026 each describe a different failure at the same architectural level: not the application layer, not the endpoint estate, not even the network perimeter as conventionally modelled — but the foundational infrastructure that the perimeter, the applications, and the endpoints depend on in order…

Read More

Arista VeloCloud Orchestrator CVE-2026-16812 Exploited

Arista VeloCloud Orchestrator CVE-2026-16812 (CVSS 10.0) is under active attack. Unauthenticated command injection lets attackers seize full SD-WAN control.

Arista VeloCloud Orchestrator CVE-2026-16812 is a maximum-severity, unauthenticated command injection flaw under active exploitation right now, and it hands an attacker control of an entire SD-WAN fabric from a single unpatched management console. CISA added it to the Known Exploited Vulnerabilities catalog on July 27, with a federal patch deadline of July 30. If your…

Read More