A Max-Severity Arista Zero-Day Is Exploited & an AI Agent Runs an Espionage Op (07/27/2026)
- › A maximum-severity command-injection flaw in on-prem Arista VeloCloud Orchestrator, CVE-2026-16812 (CVSS 10.0), is under active exploitation in the wild.
- › Attackers used Hermes, an autonomous open-source tool run in unrestricted YOLO mode, to conduct espionage against Thailand's Ministry of Finance.
- › A public exploit released July 27 shows how an unauthenticated request reaches PHP's eval() inside vBulletin to run code on an unpatched forum server.
- › Researchers warn that Confused Deputy flaws persist in Google Cloud and Microsoft Azure, letting an attacker acquire admin-level permissions and bypass access controls.
- › Microsoft launched MAI-Cyber-1-Flash inside its MDASH harness, claiming a 95.95% CyberGym score at half the cost of its prior configuration.
Today’s lead is a perfect-score flaw already being exploited on an appliance that sits at the center of enterprise networks. Behind it, the autonomous-AI-as-attacker story took another step from theory to incident, and an old forum platform got a fresh public exploit. The theme is unchanged from last week: the reach and speed of attacks keep growing, and the fixes are the unglamorous ones.
Top 5 Critical Security Alerts
1. A Max-Severity Arista VeloCloud Flaw Is Under Active Attack
A maximum-severity command-injection vulnerability in on-premises Arista VeloCloud Orchestrator, CVE-2026-16812 (CVSS 10.0), is being actively exploited, allowing arbitrary command execution (The Hacker News, BleepingComputer). VeloCloud Orchestrator manages an organization’s SD-WAN, so it sits at the center of the network with reach into every branch it connects, which makes a perfect-score flaw in it a route to the whole estate rather than a single box.
Operator Note: If you run VeloCloud Orchestrator on-prem, patch it now and treat it as possibly already compromised. Pull its management interface off the public internet, and review it for signs of command execution, because a CVSS 10.0 under active attack does not wait for your maintenance window.
2. An AI Agent Ran an Espionage Operation Against a Finance Ministry
Attackers used Hermes, an autonomous open-source tool run in unrestricted “YOLO mode,” to conduct an espionage operation against Thailand’s Ministry of Finance (Dark Reading). This is the same capability class that broke out of a lab and hit a third party last week, now pointed at a government target on purpose. An agent running without safety limits does the reconnaissance, decision-making, and action of a human operator at machine speed, which compresses the timeline a defender has to notice and respond.
3. A vBulletin Pre-Auth RCE Exploit Goes Public
A public exploit released July 27 shows how an unauthenticated request can reach PHP’s eval() function inside vBulletin and execute code on an unpatched forum server, with no account or user interaction required (The Hacker News). A public forum is internet-facing by definition, and a pre-auth flaw that reaches eval() is the cleanest kind of takeover, so unpatched vBulletin servers are on a short clock now that the exploit is out.
4. Confused Deputy Flaws Persist in Google Cloud and Azure
Researchers warn that a class of Confused Deputy vulnerabilities still exists in Google Cloud and Microsoft Azure, letting an attacker acquire administrative permissions and bypass the cloud providers’ access controls (Dark Reading). A confused deputy is a trusted service tricked into using its own privileges on an attacker’s behalf, and in a cloud that means your access controls can hold perfectly while a legitimate service quietly does the attacker’s work for it.
5. Microsoft Launches a Cybersecurity-Specific AI Model
Microsoft launched MAI-Cyber-1-Flash inside MDASH, its vulnerability identification and remediation harness, claiming a 95.95% score on the CyberGym benchmark at half the cost of its prior configuration (The Hacker News). Vendor benchmark claims deserve a skeptical read, and the signal worth noting is that the same AI capability being weaponized in the espionage story above is being productized for defense, so both sides of the fight are scaling on the same curve.
Additional Security Alerts
Government & Policy
- Senator Pushes to Purge Outdated VPNs From Federal Agencies: Senator Ron Wyden asked CISA, OMB, and NIST to lead a federal effort to remove obsolete VPNs from US government networks. The Record
- FBI Details How Breaking Affiliate Trust Took Down LockBit: An FBI agent explained how Operation Cronos disrupted the LockBit ransomware group by eroding trust between its operators and affiliates. Dark Reading
Privacy & Exposure
- Claude Shared Chats May Have Been Indexed by Google: Links created through Claude’s share-chat feature may have become publicly discoverable in Google search, exposing conversation and project contents. TechCrunch
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.