A curated dispatch from GajShield

The GajShield Gazette

Lead story

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

The exploited Arista VeloCloud Orchestrator zero-day highlights the serious risk created when SD-WAN management platforms are exposed and vulnerable.VeloCloud Orchestrator is used to centrally manage SD-WAN environments, including edges, gateways, policies, routing, config…

Also today
In brief

Coca-Cola confirms data theft in Fairlife ransomware attack

The Coca-Cola Fairlife ransomware incident highlights how cyberattacks against manufacturing and food-production businesses can create both…

Jul 27, 2026

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

The TELESHIM campaign highlights a growing problem in modern malware operations: attackers are abusing legitimate cloud and messaging platf…

Jul 27, 2026

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

The Cl0p-linked targeting of internet-exposed PTC Windchill and FlexPLM systems highlights the growing risk around enterprise product lifec…

Jul 26, 2026

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

The active exploitation of the Fastjson 1.x remote code execution vulnerability highlights the serious risk created when widely used applic…

Jul 26, 2026

ShinyHunters data leaks fuel $2,000 sextortion email scam

The ShinyHunters-linked sextortion scam shows how stolen breach data can be reused long after the original incident to frighten victims int…

Jul 26, 2026

Malicious sites use JavaScript to build malware in browser memory

The campaign using JavaScript to build malware in browser memory highlights a dangerous shift in web-based malware delivery.Traditionally, …

Jul 26, 2026

Chick-fil-A data breach affects more than 13,000 customers

The Chick-fil-A data breach is another reminder that credential stuffing remains one of the most common and effective ways attackers compro…

Jul 25, 2026

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

The Certighost exploit highlights one of the most dangerous areas in enterprise identity security: Active Directory Certificate Services.Ac…

Jul 25, 2026

OnTrac notifies customers of data breach after network hack

The OnTrac data breach highlights the growing risk around logistics and delivery companies, where customer data can become highly valuable …

Jul 25, 2026

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

The hotel Wi-Fi DNS hijacking campaign highlights a serious risk for business travelers: the network you connect to can become part of the …

Jul 25, 2026

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

The Claude Cowork flaw highlights a serious and growing security issue around AI agents: once an agent can execute code, access files, conn…

Jul 24, 2026