
HSTS-Enforced Wants to Close the Web’s Oldest Backdoor — Plain HTTP Is Asked to Leave the Building First
A proposal discussed on the APNIC Blog would invert the web’s old assumption that sites start on HTTP unless they say otherwise, pushing secure-by-default closer to reality.
July 28, 2026

A New DDoS Botnet Has Reached 200,000 Devices — The Internet of Things Remains a Volunteer Artillery Program
The Dysphoria botnet has reportedly compromised around 200,000 devices for DDoS and traffic relay operations, proving once again that default-hardening is cheaper than incident response theatre.
July 28, 2026

Arista Patches a Maximum-Severity VeloCloud Orchestrator Zero-Day — Managed Edge Devices Get a Calendar Invitation From CISA
Arista has patched an actively exploited command-injection bug in on-premises VeloCloud Orchestrator deployments, and administrators have been told to move quickly.
July 28, 2026

More Than 24,000 Exposed Server BMCs Are Leaking Password Hashes — The Management Port Has Become the Breach Department
BleepingComputer reports that internet-exposed server management controllers are leaking password hashes through a decades-old flaw, which is precisely why out-of-band management belongs out of band.
July 28, 2026