Security news.
Today's security landscape is marked by active exploitation of critical vulnerabilities, sophisticated phishing campaigns, and data breaches. Threat actors are leveraging new techniques, including in-browser malware assembly and AI-powered automation, underscoring the need for vigilant patching and robust security measures.
Fastjson 1.x RCE Vulnerability Under Active Attack
Attackers are targeting CVE-2026-16723, a critical remote code execution flaw in Alibaba's Fastjson library (CVSS 9.0), affecting unpatched Spring Boot applications.
Cl0p Affiliates Exploit PTC Windchill and FlexPLM for RCE
Threat actors linked to the Cl0p ransomware group are exploiting pre-authentication information disclosure and server-side flaws in internet-exposed PTC Windchill and FlexPLM to achieve unauthenticated remote code execution.
Malvertising Campaign Builds Malware in Browser Memory
A large-scale malvertising campaign is using malicious JavaScript on fake Solana, Luno, and TradingView sites to assemble malware directly in browser memory, avoiding traditional detection.
GitLab RCE PoC Released for Unpatched Servers
A working exploit (CVE-2026-16723) has been published for a GitLab flaw, allowing authenticated users to run commands as 'git' on self-managed servers not updated to version 18.11.3 or higher.
CISA Adds Two Vulnerabilities to KEV Catalog
CISA has added CVE-2026-16232 (Check Point SmartConsole Improper Authentication) and CVE-2026-50522 (Microsoft SharePoint Deserialization of Untrusted Data) to its Known Exploited Vulnerabilities Catalog, urging immediate patching.
ShinyHunters Data Leaks Fuel $2,000 Sextortion Scams
Email addresses exposed in data breaches by the ShinyHunters group are being used by threat actors to send sextortion emails demanding $2,000 in Bitcoin.
OnTrac Notifies Customers of Data Breach
The parcel delivery company OnTrac is informing customers that hackers breached its corporate network, potentially accessing personal details.
Hackers Hijack Hotel Wi-Fi DNS for Microsoft 365 Account Theft
Threat actors are manipulating DNS settings on Wi-Fi devices in hotels and conference centers to redirect users to fake Microsoft 365 login pages and steal credentials.