- Fastjson 1.x RCE vulnerability
- browser impersonatorsUsed in exploitation attempts
- Ruby and Go toolsUsed in exploitation attempts
The cybersecurity landscape continues to evolve with critical developments across multiple fronts. Today's briefing covers significant advancements in supply chain defense mechanisms, active exploitation of unpatched vulnerabilities in widely-used libraries and enterprise software, and emerging proof-of-concept exploits that underscore the urgency of timely security patching.
GitHub and PyPI have deployed a time-based mechanism within the Dependabot dependency management tool designed to protect against supply-chain attacks and limit their potential impact. This defensive approach represents a strategic shift in how development platforms address the growing threat of compromised dependencies. Source: GitHub, PyPI add time-absed defenses against supply chain attacks
Security researchers at ThreatBook and Imperva have documented active attacks targeting a critical remote code execution vulnerability in Fastjson, Alibaba's JSON library for Java. The flaw, tracked as CVE-2026-16723 with a CVSS score of 9.0, allows attackers to execute arbitrary code without authentication in affected Spring Boot applications through malicious JSON requests. The vulnerability executes with the privileges of the Java process, creating a severe risk for organizations relying on vulnerable versions of the library. Notably, no patched version is currently available, leaving administrators with limited remediation options beyond application-level mitigations. Source: Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Threat actors affiliated with the Cl0p ransomware campaign, also known as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest, are actively exploiting vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments. The attackers chain a pre-authentication information disclosure vulnerability in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet to achieve unauthenticated remote code execution. This exploitation campaign targets manufacturing and engineering organizations as part of a data extortion operation, with CVE-2026-12569 identified as a key component of the attack chain. Source: Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Security researcher Yuhang Wu at depthfirst has released a working proof-of-concept exploit demonstrating remote code execution on unpatched GitLab 18.11.3 installations. The vulnerability allows ordinary authenticated users to execute commands as the git user by committing two specially crafted Jupyter notebooks and requesting their diff comparison. The attack chain requires no administrator privileges, continuous integration runner access, or victim interaction, making it a significant risk for self-managed GitLab deployments. Source: Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Organizations should prioritize immediate assessment of their exposure to these vulnerabilities, particularly those operating internet-facing instances of PTC software or self-managed GitLab servers. The combination of active exploitation, unavailable patches, and low barriers to attack execution makes today's threat landscape particularly challenging for security teams.
Source articles and extracted indicators (defanged where appropriate).
5.180.41.35216.152.148.54216.152.151.204104.243.35.63