Security news.
Today's security brief highlights active exploitation of critical vulnerabilities, sophisticated malvertising campaigns, and continued concerns around AI security. Threat actors are leveraging new techniques to deliver malware and bypass traditional defenses, emphasizing the need for robust patching and awareness.
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Attackers are actively exploiting CVE-2026-16723, a critical RCE flaw in Alibaba's Fastjson library (CVSS 9.0), affecting Spring Boot applications without available patches.
Cl0p Affiliates Target PTC Windchill and FlexPLM with Unauthenticated RCE
Threat actors linked to the Cl0p ransomware are exploiting vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments for data extortion.
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
Steam discussion forums are being abused in "ClickFix" social engineering campaigns that lead users to download cryptominers under the guise of game or computer fixes.
Malvertising Makes Browsers Build Malware Executables
The "SourTrade" malvertising operation is delivering malware in pieces, instructing victims' browsers to assemble the final Windows executable using a legitimate Bun runtime.
Researcher Publishes GitLab RCE PoC for Authenticated Users
A working exploit (CVE-2026-16723) has been published for a GitLab flaw (patched June 10) that allows any authenticated user to run commands as 'git' on unpatched self-managed 18.11.3 servers.
ShinyHunters data leaks fuel $2,000 sextortion email scam
Threat actors are using email addresses exposed in ShinyHunters data breaches to send sextortion emails demanding $2,000 in Bitcoin.
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
CISA warns that Russian state-supported actors have been targeting Western government and commercial organizations using Zimbra Collaboration Suite since at least July 2025.
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
Microsoft addressed a public-by-default configuration in Azure Automation that could have allowed attackers to seize another tenant's identity and access data and cloud workloads.