Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 10 (Critical). Affects Arista VeloCloud Orchestrator.
This analysis highlights how behavioral detection exposed attacker activity using legitimate tools and infrastructure, providing multiple opportunities for early intervention and containment.
HackTheBox - Fries
IppSec·11K views · 1 month ago
00:00 - Introduction
01:00 - Start of nmap
05:00 - Discovering PWM, then failing to find exploits/release date
08:45 - Doing a Virtual Host Brute Force, discovering a gitea instance, logging in and finding a new VHOST and credential
13:45 - Logged into PGAdmin playing with queries, shell the database but not much is gathered here
20:10 - Finding a CVE in PGAdmin which lets us run code on this container
31:45 - Some weird oddities with networking, got me to use the DB Shell as a Pivot Point (not needed)
36:50 - Running hydra to bruteforce SSH with credentials we have found so far
39:00 - Finding NFS running, getting a port forward then using NetExec to download the shadow file (doesn't get us much)
44:20 - Mounting the NFS Share then using setpriv to change our UID/GID so we can browse the NFS Share, download SSL Certs and generate our own to auth against docker
55:20 - Can auth against docker, start a new container mounting the root FS to the container, grabbing the ssh key and logging in as root
01:02:00 - Editing PWM Ldap config to point it at our server and stealing the credential it uses to bind to LDAP, then running Rusthound/Bloodhound
01:08:00 - Using ReadGMSA to get gMSA_CA_Prod$'s account, running Certipy running ESC7 but getting a denied
01:15:30 - We can modify ADCS Configuration, using Certify to make it vulnerable to ESC6 but still run into an issue
01:26:00 - The conflicting SAN/Security Extension give us an issue, enable ESC16 to disable this check and then getting a root shell
A compromised AI gateway connected to Amazon Bedrock services was found communicating with cryptomining infrastructure, highlighting emerging risks in AI infrastructure security. The incident, investigated by Darktrace, underscores how AI platforms can become vectors for attacks when inadequately secured, potentially allowing attackers to redirect computational resources for illicit purposes.
Researchers at ReliaQuest have identified a cyber espionage campaign exploiting hotel Wi-Fi infrastructure through DNS poisoning attacks to intercept corporate login credentials from business travelers. The widespread nature of these attacks against the hospitality sector suggests attackers are strategically targeting hotels to harvest credentials from corporate visitors. This threat demonstrates how network-level compromises in public accommodations can serve as effective platforms for credential theft targeting enterprise users.
The Gentlemen ransomware has driven a significant increase in ransomware attacks targeting universities during the first half of 2026, according to analysis by Comparitech. Higher education institutions appear to be facing elevated threat levels as this emerging ransomware variant gains prominence in the threat landscape.
A Russian espionage group has exploited a previously unknown vulnerability in Zimbra to intercept email communications and two-factor authentication codes from targeted organizations. The zero-day flaw allowed the threat actors to access sensitive messages and compromise multi-factor authentication, potentially enabling further unauthorized access to victim systems.
Russian state-backed hackers are conducting a coordinated campaign against Western organizations through a zero-click vulnerability in Zimbra Collaboration Suite, prompting a joint alert from international agencies. The attack requires no user interaction, making it a particularly dangerous threat to enterprise email infrastructure and communications systems.
You can't have failed to hear the news headlines about "rogue" OpenAI models hacking into another AI organisation, Hugging Face. But what has actually happened, who is to blame, and is it as serious as some of the reports suggest? Find out in my article on the Hot for Security blog.
Unit 42 has documented a Russian cyberespionage campaign that exploits Zimbra webmail servers through JavaScript injection attacks designed to harvest user credentials. The threat actors leverage this technique to gain unauthorized access to email accounts on a global scale, representing a significant risk to organizations relying on Zimbra infrastructure.
US government agencies have warned that Iranian cyber actors are actively targeting industrial equipment from Siemens and Schneider used in US-based operations. CISA's alert highlights the continued threat to critical infrastructure from state-sponsored Iranian threat actors focusing on widely-deployed industrial control systems.