<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Velocloud on CuraSec</title><link>https://curasec.metacog.co.kr/tags/velocloud/</link><description>Recent content in Velocloud on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 23 Sep 2026 15:27:03 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/velocloud/index.xml" rel="self" type="application/rss+xml"/><item><title>Arista patches actively exploited VeloCloud Orchestrator zero-day</title><link>https://curasec.metacog.co.kr/insights/2026-09-23-arista-patches-actively-exploited-velocloud-orchestrator-zer/</link><pubDate>Wed, 23 Sep 2026 15:27:03 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-23-arista-patches-actively-exploited-velocloud-orchestrator-zer/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> VeloCloud Orchestrator On-Prem is actively exploited network management infrastructure — apply Arista&amp;rsquo;s released patches immediately and treat all unpatched VCO instances as potentially compromised.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation means systems may have been compromised before patches were available — sweep VCO On-Prem hosts for anomalous admin activity, lateral movement, and configuration changes since the zero-day window opened.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Actively exploited zero-day in SD-WAN management infrastructure warrants same-week action — confirm whether VCO On-Prem is deployed, verify the patch has been applied or is on an emergency timeline, and brief IT leadership on exposure status.&lt;/li>
&lt;/ul></description></item></channel></rss>