Infosec News Nuggets — July 29, 2026
Arista patches VeloCloud Orchestrator zero-day exploited in attacks Arista has shipped patches for a maximum-severity command injection flaw in on-premises VeloCloud Orchestrator deployments after confirming it is being actively exploited. The bug allows unauthenticated attackers with only network access to the web interface to reach privileged internal functionality, potentially compromising the confidentiality, integrity, and availability of the orchestrator and the SD-WAN edge devices it manages. Three attacker IP addresses have been identified, and the flaw…