Security news.
Today's security brief highlights a range of critical vulnerabilities and ongoing cyberattack campaigns. Attackers are actively exploiting flaws in Fastjson and PTC Windchill/FlexPLM, while new malvertising techniques are building malware directly in browsers. CISA also added two more actively exploited vulnerabilities to its KEV catalog.
Fastjson 1.x RCE Vulnerability Under Active Attack
Threat actors are exploiting a critical remote code execution flaw, CVE-2026-16723 (CVSS 9.0), in Alibaba's Fastjson library for Java, impacting Spring Boot applications without available patches.
Cl0p Affiliates Exploit PTC Windchill and FlexPLM for Data Extortion
Threat actors linked to the Cl0p ransomware group are targeting internet-exposed PTC Windchill and FlexPLM deployments by chaining information disclosure and server-side flaws for unauthenticated RCE.
Malvertising Builds Malware in Browser Memory
A significant malvertising campaign, dubbed SourTrade, is using malicious JavaScript on fake Solana, Luno, and TradingView sites to instruct browsers to assemble Windows executables directly in memory.
CISA Adds Two Exploited Vulnerabilities to KEV Catalog
CISA has added CVE-2026-16232 (Check Point SmartConsole Improper Authentication) and CVE-2026-50522 (Microsoft SharePoint Deserialization of Untrusted Data) to its Known Exploited Vulnerabilities catalog.
GitLab RCE PoC Published for Unpatched Servers
A researcher published working exploit code for a GitLab flaw patched in June, allowing authenticated users to run commands as git on self-managed 18.11.3 servers that have not applied the update.
GitHub, PyPI Enhance Supply Chain Defenses
GitHub and PyPI have integrated a time-based mechanism into Dependabot to bolster protection against supply chain attacks and limit their potential impact.
Scans for ESAFENET CDG 3 Document Management System Weak Logins
SANS ISC reports scans targeting ESAFENET's CDG 3 Content Data Guard, a document management system primarily for the Chinese market, which has known basic security vulnerabilities like SQL Injection.
Steam Forum "ClickFix" Attacks Infect Gamers with Cryptominers
Malicious actors are abusing Steam discussion forums with "ClickFix" attacks, disguising cryptominer infections as fixes for game and computer issues.