Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIAttackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A critical command injection vulnerability (CVE-2026-16812) with a maximum CVSS score of 10.0 has been discovered in on-premises versions of Arista VeloCloud Orchestrator and is being actively exploited. The flaw allows attackers to execute arbitrary code through operating system command injection, posing severe security risks to affected enterprise deployments.
AIMicrosoft Exchange Flaw Lets Attackers Spoof Any Email Address
A vulnerability dubbed 'Ghost-Sender' has been discovered in Microsoft Exchange that allows attackers to spoof any email address. The flaw specifically affects Exchange Online or on-premises deployments running in hybrid mode when configured with third-party mail servers or spam filters, enabling sophisticated email impersonation attacks.
AIClaude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories
A critical vulnerability was discovered in Anthropic's Claude Code GitHub Action that allowed attackers to hijack public repositories through a single malicious GitHub issue. The flaw was particularly severe because Anthropic's own action repository used the vulnerable workflow, potentially enabling supply chain attacks affecting all downstream projects using the action.
