Cybersecurity Radar — 2026-07-29
Arista VeloCloud Orchestrator faces active zero-day exploitation with critical OS injection vulnerability; Microsoft's historic July patch addresses 622 CVEs including three zero-days; Japanese frozen-food supplier Nichirei hit by ransomware disrupting logistics operations.
Cybersecurity Radar — 2026-07-29
🔴 Critical Alerts
Arista VeloCloud Orchestrator Zero-Day Under Active Attack A maximum-severity OS command injection vulnerability in Arista VeloCloud Orchestrator on-premises deployments is being actively exploited in the wild. The flaw allows unauthenticated remote code execution. Arista has released patches; organizations should prioritize immediate deployment on all exposed instances. As of July 27, 2026, no CISA Known Exploited Vulnerabilities listing had been published, but active exploitation confirms imminent widespread attacks.
Microsoft Patch Tuesday: Record 622 CVEs Including Three Zero-Days Microsoft released patches for a historic 622 vulnerabilities in July 2026, including three zero-day flaws—two actively exploited in attacks (SharePoint and AD FS) and one publicly disclosed. This represents the largest single patch release in company history. Organizations must prioritize critical and exploited patches immediately, particularly for SharePoint and Active Directory Federation Services. Notably, a Kerberos RC4 change may impact service account authentication configurations.

Threat Landscape
Nichirei Ransomware Attack Disrupts Japan Food Supply Chain Nichirei, a major Japan-based frozen-food supplier and logistics company, suffered a ransomware attack that disrupted shipping operations. The incident highlights ongoing targeting of supply chain and logistics sectors. No ransom demand amount or data exposure details were disclosed as of July 27.

Dysphoria Botnet Compromises ~200,000 Devices Globally A botnet designated Dysphoria has compromised approximately 200,000 devices worldwide and is actively using them for distributed denial-of-service (DDoS) attacks and traffic relay operations. The large-scale compromise suggests ongoing infrastructure reconnaissance and preparation for coordinated attack campaigns.
CVE-2026-61511 vBulletin Pre-Auth Code Execution Exploit Now Public Public exploit code has been released for CVE-2026-61511, a pre-authentication remote code execution flaw in vBulletin forums. The vulnerability allows attackers to reach PHP eval() functions through visitor-controlled template parameters. As of July 27, no in-the-wild exploitation had been confirmed, but public disclosure significantly raises attack risk for unpatched installations.
Vulnerabilities & Patches
Windows ProfSvc Privilege Escalation (LegacyHive PoC) A researcher released proof-of-concept code for a Windows privilege escalation flaw affecting the Profile Service (ProfSvc) that remains exploitable after July 2026 patches. The public PoC accelerates weaponization risk; defenders should monitor for exploitation attempts targeting local privilege escalation chains.
Microsoft Patch Tuesday CVE Breakdown Of the 622 Microsoft CVEs patched, 57 were marked as critical severity. Key affected products include Windows, Exchange Server, SharePoint, and Azure services. The three zero-days (two in-the-wild, one publicly disclosed) require emergency prioritization.
Breaches & Incidents
Incident Response Status: Nichirei Ransomware Nichirei confirmed the ransomware attack and disclosed operational disruption to shipping. Status of data exfiltration, ransom negotiation, and recovery timeline remain undisclosed as of July 27.
Industry & Policy
SMB Targeting Intensifies Amid Ransomware Competition Rising competition among top-tier ransomware groups is driving increased targeting of small and medium-sized businesses alongside continued attacks on larger organizations. The NSA and CISA have issued joint advisories addressing this trend and recommending security posture hardening for organizations lacking enterprise-scale defenses.
What to Watch
- Arista VeloCloud patch deployment deadline: Organizations with on-premises deployments should complete patching within 48 hours given active exploitation
- Microsoft July patches rollout window: Plan testing and deployment across critical systems (Exchange, SharePoint, AD FS) before end of week
- Botnet infrastructure expansion: Monitor for signs of Dysphoria botnet growth and potential use in coordinated attacks targeting specific sectors
Reader Action Items
- Immediate (Today): Check your network for Arista VeloCloud Orchestrator instances and apply patches; verify your SharePoint and AD FS versions are current or schedule urgent updates for Monday
- This Week: Review your vBulletin forum infrastructure; if running unpatched versions, isolate from internet-facing access or apply CVE-2026-61511 patches immediately
- Ongoing: Subscribe to CISA Known Exploited Vulnerabilities catalog and monitor Check Point/SecurityWeek advisories for emerging exploitation patterns in the Dysphoria botnet campaign
Data freshness note: This report covers cybersecurity intelligence published or updated after July 27, 2026. Vulnerability details, patch information, and threat actor activity are current as of July 29, 2026 at publication time.
This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.