Thinking about hiring globally? Start with an EOR.
The best person for your next role might not live near your office—or even in the same country.
More companies are realizing they don't need to open entities everywhere just to access global talent. Instead, they're using EOR to hire internationally faster, stay compliant, and avoid building local infrastructure before they're ready.
Oyster's EOR helps companies hire, pay, and support employees in 180+ countries while Oyster handles payroll, compliance, taxes, and local employment requirements.

This week, the attackers are not just looking for software bugs. They are looking for systems that hold authority.
Let’s dive in.
Risk Level: Critical
Business Impact: Coordinated targeting of water utilities can create operational disruption, public safety risk, regulatory escalation, and executive-level incident pressure.
What You Need to Know
Minnesota officials disclosed that more than 30 community water systems were targeted between July 26 and July 27 in a coordinated cyberattack. Reuters’ reporting notes that unauthorized access with malicious intent was detected, the FBI is engaged, and officials are investigating similarities to prior attacks on U.S. water infrastructure.
Why This Matters
Water systems are critical infrastructure where cyber incidents can become public safety issues.
Coordinated targeting suggests attacker interest beyond opportunistic scanning.
Local utilities often lack the staffing, segmentation, and monitoring maturity of larger enterprises.
Executive Actions
🚰 Validate remote access controls for OT, water, facilities, and utility-like environments.
🔒 Require MFA, allowlisting, and logging for PLC, SCADA, and vendor access paths.
🔎 Hunt for abnormal remote sessions, configuration changes, and unauthorized access attempts.
🧯 Review continuity plans for utility disruption, manual operations, and public communication.
Risk Level: Critical
Business Impact: Unauthenticated RCE in a widely used Java library can expose application servers, internal services, credentials, and downstream enterprise systems.
What You Need to Know
A critical Fastjson vulnerability is being exploited in attacks before an official patch is available, creating immediate exposure for applications using default configurations. SecurityWeek’s Fastjson report notes that the issue can be exploited without authentication and that organizations may need to rely on mitigations while waiting for a vendor fix.
Why This Matters
Library-level vulnerabilities can hide deep inside applications and vendor products.
No-patch situations force compensating controls, monitoring, and exposure reduction immediately.
Unauthenticated RCE is exactly the type of condition attackers automate fast.
Executive Actions
🧾 Inventory applications and vendor products using Fastjson.
🧱 Apply recommended mitigations, WAF rules, or network restrictions while patching is unavailable.
🔎 Monitor Java applications for suspicious deserialization patterns, process spawning, and outbound callbacks.
🔐 Rotate secrets exposed to affected application environments if compromise is suspected.
Risk Level: Critical
Business Impact: SD-WAN orchestration compromise can expose privileged functionality, traffic control, network configuration, and broad enterprise connectivity paths.
What You Need to Know
Arista confirmed that a critical VeloCloud Orchestrator vulnerability was exploited as a zero-day against on-premises deployments. SecurityWeek’s Arista VeloCloud report describes the flaw as OS command injection that can allow attackers to access privileged internal functionality.
Why This Matters
SD-WAN orchestration sits at the control layer of distributed network access.
Command injection on a network controller can become configuration tampering and persistence.
On-prem management platforms are often exposed longer than teams realize.
Executive Actions
🩹 Patch or mitigate VeloCloud Orchestrator immediately where applicable.
🔒 Restrict orchestrator access to trusted admin networks only.
🔎 Hunt for unusual admin actions, command execution, configuration changes, and new users.
🧱 Treat SD-WAN orchestration as Tier 0 infrastructure with strict logging and segmentation.
Leadership Insight:
This week’s message is straightforward: attackers are targeting control planes.
Water systems control public infrastructure. Fastjson controls application behavior. VeloCloud controls network fabric. BMCs control servers below the OS. Check Point controls security policy. AI agents control automated action.
The executive takeaway is simple: if a system can make decisions, execute commands, route traffic, or authenticate access, it belongs inside your security boundary.
Stop typing what you could say in 10 seconds.
Wispr Flow turns your voice into clean, professional text inside any app. Emails, Slack, client updates — speak once, send without editing. 4x faster than typing.
Risk Level: High
Business Impact: Baseboard management controller compromise can enable server takeover, credential theft, hardware-level persistence, and disruption of critical compute infrastructure.
What You Need to Know
Researchers warned that thousands of internet-exposed data center controllers are vulnerable to offline password-cracking and takeover risks. Dark Reading’s data center controller report explains that exposed remote hardware management processors give attackers a path toward low-level server control if credentials are weak or protections are misconfigured.
Why This Matters
BMCs sit below the operating system and can control power, console access, and server management.
Compromise at this layer can survive normal endpoint remediation assumptions.
Internet exposure of hardware management interfaces is a preventable high-impact risk.
Executive Actions
🧯 Remove BMC/iDRAC/iLO-style interfaces from public exposure immediately.
🔐 Enforce strong unique credentials and MFA where supported.
🧱 Segment management networks away from user, server, and production traffic.
🔎 Monitor for abnormal console logins, power events, firmware changes, and unknown management IPs.
Risk Level: High
Business Impact: Security management compromise can allow attackers to alter firewall policies, weaken controls, create access paths, and hide malicious activity.
What You Need to Know
Researchers released a public proof-of-concept for an exploited Check Point SmartConsole authentication bypass affecting Security Management Server and Multi-Domain Security Management Server. The Hacker News’ Check Point coverage notes that the flaw had already been exploited in the wild, and the release of technical details raises the urgency for patching and verification.
Why This Matters
Security management systems define what the network allows and denies.
Auth bypass at this layer can turn defensive infrastructure into attacker-controlled infrastructure.
Public PoC release increases copycat exploitation risk.
Executive Actions
🩹 Patch Check Point management systems immediately and validate fixed versions.
🔒 Restrict SmartConsole access to admin networks and approved jump hosts.
🔎 Review policy changes, admin logins, object modifications, and unexpected rule updates.
🧾 Require change review for recent firewall policy activity during the exposure window.
Risk Level: High
Business Impact: AI agent abuse can accelerate credential misuse, tool chaining, and unauthorized actions across developer and research environments.
What You Need to Know
Hugging Face reported that an OpenAI-powered autonomous agent used exposed credentials during a multi-day intrusion attempt involving roughly 17,600 recovered attacker actions. The Hacker News’ AI agent incident report says the activity targeted ExploitGym infrastructure and demonstrates how agentic tooling can operate at scale once credentials are exposed.
Why This Matters
Exposed credentials remain the root problem, but AI agents can amplify speed and persistence.
Agentic workflows can perform long chains of actions faster than human attackers.
Research, dev, and benchmark environments often contain useful tokens, cloud access, and internal tooling.
Executive Actions
🔑 Rotate exposed credentials immediately and shorten token lifetimes where possible.
🤖 Treat AI agents as privileged actors with scoped permissions, logging, and rate limits.
🔎 Monitor for high-volume tool actions, unusual API sequences, and automated credential use.
🧱 Segment research and benchmark environments from production systems and sensitive secrets.
🩹 Patch or mitigate Fastjson, Arista VeloCloud, Check Point SmartConsole, and exposed management systems immediately
🚰 Review critical infrastructure and utility-like remote access paths for MFA, logging, and vendor restrictions
🔒 Remove public exposure from BMCs, SD-WAN orchestrators, security consoles, and admin interfaces
🔑 Rotate credentials exposed to AI agents, research environments, application servers, and management planes
🔎 Hunt for command injection, abnormal admin changes, BMC access, unauthorized policy changes, and agent-driven activity
📊 Require proof of running fixed versions and configuration validation, not just ticket closure
💡 If your water systems, network fabric, data center controllers, firewall console, and AI agents all need supervision this week, that is not chaos. That is the control plane asking for a seat at the risk committee. 💡
J.W.
(P.S. Check out our partners! It goes a long way to support this newsletter!)
What is an EOR—and why are companies using it?
Opening entities in every country can be slow, expensive, and hard to scale.
That's why more companies are using EOR to hire globally faster.
See how Oyster helps teams hire, pay, and support talent in 180+ countries while staying compliant along the way.





