[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fmp3Xnuss3v7Y12qXA0_T7PhdpRl-7NjCIyiUCitJwVQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"b382ab25-0c05-46f9-9487-61358e4402f1","fastjson-zero-day-rce-exploited-against-us-organizations","f624bc70-d608-4c92-90a5-9754a44252e4","FastJson Zero-Day RCE Exploited Against U.S. Organizations","A critical zero-day vulnerability in the widely-used FastJson Java library (CVE-2026-16723) is being actively exploited against U.S. organizations, enabling unauthenticated remote code execution with no user interaction required. The root problem lies in reliance on an end-of-life open-source component that no longer receives active security maintenance, leaving affected organizations with no vendor-issued patch. This highlights the compounding risk of unmanaged third-party library dependencies — when a popular library reaches end-of-life, any newly discovered flaw becomes an indefinite exposure. Organizations that lack a software bill of materials (SBOM) or automated dependency tracking are especially blind to where FastJson exists in their environments, delaying detection and response.","**Immediate Actions:**\n- Enable FastJson's SafeMode feature as a temporary mitigation to restrict unsafe deserialization until a full migration is possible.\n- Conduct an emergency audit of all applications and services using FastJson versions 1.2.68–1.2.83 using SBOM tooling or dependency scanners (e.g., OWASP Dependency-Check).\n- Implement WAF rules and network-level controls to detect or block exploit payloads targeting FastJson deserialization endpoints.\n\n**Long-Term Improvements:**\n- Migrate all affected applications from FastJson 1.x to the actively maintained fastjson2 library on a prioritized remediation schedule.\n- Establish a formal end-of-life (EOL) library policy that mandates migration planning before a dependency loses active maintenance.\n- Maintain a continuously updated Software Bill of Materials (SBOM) for all applications to enable rapid identification of vulnerable components during future zero-day events.\n\n**Detection Measures:**\n- Deploy runtime application self-protection (RASP) or Java agent-based monitoring to detect anomalous deserialization behavior in real time.\n- Configure SIEM alerts for indicators of compromise (IOCs) associated with FastJson RCE exploit patterns, including unusual outbound connections from Java application servers.\n- Increase logging verbosity on affected application tiers and route logs to a centralized platform for threat hunting.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 7: Continuous Vulnerability Management","NIST SP 800-161: Supply Chain Risk Management (C-SCRM)","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 SA-12: Supply Chain Protection","NIST CSF ID.AM-2: Software platforms and applications inventoried","OWASP A08:2021 – Software and Data Integrity Failures","NIST SP 800-218 (SSDF) PW.4: Reuse Existing, Well-Secured Software","GDPR Article 32: Security of Processing (for EU-linked data exposure risk)","published","2026-07-28T00:20:25.000493+00:00","2026-07-28T00:20:24.702+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-target-us-firms-in-fastjson-rce-zero-day-attacks\u002F","hackers-target-us-firms-in-fastjson-rce-zero-day-attacks-acea04","Hackers target US firms in FastJson RCE zero-day attacks",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[42],{"id":43,"date":44,"edition":45,"title":46,"audio_url":47},"06ee55fa-efec-4281-b3e2-6223debddb32","2026-07-28","morning","ThreatNoir Morning Brief — July 28","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-28\u002Fthreatnoir-morning-brief-2026-07-28.mp3"]