Cập nhật nhanh các tin an ninh mạng đáng chú ý trong ngày 29/07/2026, được biên tập tự động cho độc giả gocdulieu.com từ các nguồn bảo mật công khai. Bài viết tập trung vào rủi ro có thể ảnh hưởng tới quản trị viên hệ thống, đội vận hành bảo mật và doanh nghiệp.
Điểm nóng bảo mật
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks — Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. […] Nguồn: BleepingComputer (28/07 05:49).
- Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day — Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared first on SecurityWeek . Nguồn: SecurityWeek (28/07 13:40).
- Ghost Credentials Expose Cloud Systems to Hidden Identity Risks — Dormant nonhuman identities can create security blind spots, says security researcher Aleksandr Krasnov, who has released an open source tool to sniff out trust paths. Nguồn: Dark Reading (29/07 04:33).
- JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077) — JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible. “For those who are unable to do so, we have released a security patch plug Nguồn: Help Net Security (28/07 18:04).
- Unpatched Fastjson Vulnerability Exploited in Attacks — The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched Fastjson Vulnerability Exploited in Attacks appeared first on SecurityWeek . Nguồn: SecurityWeek (28/07 14:27).
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw — A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating s Nguồn: The Hacker News (28/07 11:43).
Ưu tiên xử lý trong 24–48 giờ
- Kiểm kê các dịch vụ public-facing: VPN, gateway, IAM/NAC, remote support, dashboard quản trị và hệ thống có quyền cao.
- Đối chiếu phiên bản với advisory chính thức; ưu tiên vá lỗ hổng đang bị khai thác, có PoC công khai hoặc ảnh hưởng thiết bị biên.
- Rà soát log đăng nhập, thay đổi cấu hình, session/token bất thường và dấu hiệu truy cập từ hạ tầng lạ.
- Với AI agent/plugin/extension, áp dụng quyền tối thiểu, bật logging cho tool-call/API call và tách dữ liệu nhạy cảm khỏi môi trường thử nghiệm.
CISA KEV / lỗ hổng cần theo dõi
- CISA KEV chưa truy cập được từ môi trường tự động (HTTPError: HTTP Error 403: Forbidden); cần đối chiếu thủ công nếu đang xử lý hệ thống trọng yếu.
Nguồn tham khảo
- BleepingComputer — Arista patches VeloCloud Orchestrator zero-day exploited in attacks
- SecurityWeek — Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
- Dark Reading — Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
- Help Net Security — JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)
- SecurityWeek — Unpatched Fastjson Vulnerability Exploited in Attacks
- The Hacker News — Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
Lưu ý: Bản tin được biên tập theo hướng thực hành; trước khi áp dụng thay đổi trên hệ thống production, anh/chị nên đối chiếu với advisory chính thức của nhà cung cấp và quy trình change management nội bộ.
