Chuyển đến nội dung
Cybersecurity

Bản tin bảo mật ngày 28/07/2026: các điểm nóng cần chú ý

cybersecurity briefing 2026 07 28

Cập nhật nhanh các tin an ninh mạng đáng chú ý trong ngày 28/07/2026, được biên tập tự động cho độc giả gocdulieu.com từ các nguồn bảo mật công khai. Bài viết tập trung vào rủi ro có thể ảnh hưởng tới quản trị viên hệ thống, đội vận hành bảo mật và doanh nghiệp.

Điểm nóng bảo mật

  • Arista patches VeloCloud Orchestrator zero-day exploited in attacks — Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. […] Nguồn: BleepingComputer (28/07 05:49).
  • Hackers target US firms in FastJson RCE zero-day attacks — Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. […] Nguồn: BleepingComputer (28/07 06:49).
  • PTC Windchill Vulnerability Exploited in Ransomware Campaign — The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The post PTC Windchill Vulnerability Exploited in Ransomware Campaign appeared first on SecurityWeek . Nguồn: SecurityWeek (27/07 20:19).
  • PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) — Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and techni Nguồn: Help Net Security (27/07 19:04).
  • AI Agent Drives Espionage Attack on Thai Ministry of Finance — Attackers used Hermes, an autonomous open source tool, in unrestricted "YOLO mode" to conduct espionage against Thailand's Ministry of Finance. Nguồn: Dark Reading (28/07 08:00).
  • FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown — An FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time. Nguồn: Dark Reading (28/07 03:33).

Ưu tiên xử lý trong 24–48 giờ

  1. Kiểm kê các dịch vụ public-facing: VPN, gateway, IAM/NAC, remote support, dashboard quản trị và hệ thống có quyền cao.
  2. Đối chiếu phiên bản với advisory chính thức; ưu tiên vá lỗ hổng đang bị khai thác, có PoC công khai hoặc ảnh hưởng thiết bị biên.
  3. Rà soát log đăng nhập, thay đổi cấu hình, session/token bất thường và dấu hiệu truy cập từ hạ tầng lạ.
  4. Với AI agent/plugin/extension, áp dụng quyền tối thiểu, bật logging cho tool-call/API call và tách dữ liệu nhạy cảm khỏi môi trường thử nghiệm.

CISA KEV / lỗ hổng cần theo dõi

  • CISA KEV chưa truy cập được từ môi trường tự động (HTTPError: HTTP Error 403: Forbidden); cần đối chiếu thủ công nếu đang xử lý hệ thống trọng yếu.

Nguồn tham khảo

Lưu ý: Bản tin được biên tập theo hướng thực hành; trước khi áp dụng thay đổi trên hệ thống production, anh/chị nên đối chiếu với advisory chính thức của nhà cung cấp và quy trình change management nội bộ.

Tham gia thảo luận

Your email address will not be published. Required fields are marked *