Top 5 Cybersecurity News Stories July 31, 2026

Cybersecurity News Stories July 31, 2026: Minnesota water OT attack, TeamCity CVSS 9.8 RCE, Certighost AD CS domain takeover, NGINX chain RCE, Cisco FMC KEV.

The five stories in this week’s Cybersecurity News Stories July 31, 2026 each describe a different failure at the same architectural level: not the application layer, not the endpoint estate, not even the network perimeter as conventionally modelled — but the foundational infrastructure that the perimeter, the applications, and the endpoints depend on in order…

Read More

Arista VeloCloud Orchestrator CVE-2026-16812 Exploited

Arista VeloCloud Orchestrator CVE-2026-16812 (CVSS 10.0) is under active attack. Unauthenticated command injection lets attackers seize full SD-WAN control.

Arista VeloCloud Orchestrator CVE-2026-16812 is a maximum-severity, unauthenticated command injection flaw under active exploitation right now, and it hands an attacker control of an entire SD-WAN fabric from a single unpatched management console. CISA added it to the Known Exploited Vulnerabilities catalog on July 27, with a federal patch deadline of July 30. If your…

Read More

Check Point SmartConsole CVE-2026-16232: Admin Bypass

Check Point SmartConsole CVE-2026-16232: Admin Bypass

Check Point SmartConsole CVE-2026-16232 is now on CISA’s Known Exploited Vulnerabilities list: an unauthenticated attacker can forge a login token and get full administrator access to the console that manages an organization’s entire firewall fleet. Check Point patched it on July 22 and confirmed a handful of customers were already targeted. The federal remediation deadline…

Read More

wp2shell WordPress RCE: Patch Now

wp2shell WordPress RCE

wp2shell WordPress RCE is now a two-CVE chain in CISA’s Known Exploited Vulnerabilities catalog — and it lets a completely unauthenticated attacker execute code on a default WordPress install with no plugins involved. If you run self-hosted WordPress and haven’t confirmed the July 17 auto-update landed, check today. What Happened wp2shell WordPress RCE combines two…

Read More

Top 5 Cybersecurity News Stories July 24, 2026

Cybersecurity News Stories July 24, 2026 — DIESEC editorial header showing five cybersecurity threat icons: OT control panel, firewall UI, server key, workflow dashboard, helpdesk document

The five stories in this week’s Cybersecurity News Stories July 24, 2026 share a structural feature that distinguishes them from the opportunistic exploitation patterns that dominate most news cycles: in each case, the component that was compromised, configured, or exposed was not the primary IT system the organisation considers its attack surface. It was the…

Read More