Infosec News Nuggets — July 29, 2026

Arista patches VeloCloud Orchestrator zero-day exploited in attacks Arista has shipped patches for a maximum-severity command injection flaw in on-premises VeloCloud Orchestrator deployments after confirming it is being actively exploited. The bug allows unauthenticated attackers with only network access to the web interface to reach privileged internal functionality, potentially compromising the confidentiality, integrity, and availability of the orchestrator and the SD-WAN edge devices it manages. Three attacker IP addresses have been identified, and the flaw…
Read More

InfoSec News Nuggets 07/13/2023

Financial Industry Faces Soaring Ransomware Threat  The financial industry has been facing a surge in ransomware attacks over the past few years, said cybersecurity provider SOCRadar in a threat analysis post published on July 12, 2023. This trend started in the first half of 2021, when Trend Micro saw a staggering 1318% increase in ransomware attacks targeting banks and financial institutions compared to the same period in 2020. Sophos also found that over half (55%) of financial service firms fell victim…
Read More

InfoSec News Nuggets 02/07/2023

French Authorities Capture Finland’s Most-Wanted Hacker  Julius "Zeekill" Kivimäki, a notorious hacker long on the run from Finnish authorities, was arrested this week in France. The capture occurred during a domestic violence call on a residence in France, and Kivimäki likely faces extradition to Finland. The 25-year-old is one of the most wanted cybercriminals in Finland, with a lengthy list of cybercrimes that includes extorting an online psychotherapy practice and leaking sensitive info on more than…
Read More

InfoSec News Nuggets 12/12/2022

Samsung Galaxy S22 gets hacked in 55 seconds at Pwn2Own Toronto On the third day of Pwn2Own, contestants hacked the Samsung Galaxy S22 a fourth time since the start of the competition, and this time they did it in just 55 seconds. Security researchers representing penetration test provider Pentest Limited pulled this off after demoing a zero-day bug part of a successful Improper Input Validation attack against Samsung's flagship device on Thursday. This earned them $25,000, 50%…
Read More