- FastJson RCE zero-day vulnerability
ThreatNoir Morning Brief — July 28
Morning Review in IT Security — July 28, 2026
The threat landscape continues to accelerate on multiple fronts as attackers exploit zero-day vulnerabilities in critical infrastructure components and cloud environments. Today's security briefing covers active exploitation campaigns targeting widely-deployed systems, newly released proof-of-concept exploits, and emerging attack patterns that compress compromise timelines to mere minutes.
Hackers Target US Firms in FastJson RCE Zero-Day Attacks
A critical remote code execution vulnerability in the FastJson open-source Java library is being actively exploited by threat actors against United States organizations. The vulnerability, tracked as CVE-2026-16723, allows attackers to execute arbitrary code without requiring user interaction or elevated privileges, making it particularly dangerous for organizations relying on FastJson in their infrastructure. Source: Hackers target US firms in FastJson RCE zero-day attacks
The exploitation of this vulnerability represents a significant risk to any organization using FastJson in production environments. The absence of user interaction requirements means that compromises can occur silently and at scale across affected deployments.
Arista Patches VeloCloud Orchestrator Zero-Day Exploited in Attacks
Arista has released patches for a maximum-severity command injection vulnerability affecting on-premises VeloCloud Orchestrator deployments that is currently being exploited in active attacks. The vulnerability, identified as CVE-2026-16812, allows attackers to execute arbitrary commands on affected systems. Source: Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Organizations operating VeloCloud Orchestrator instances should prioritize patching immediately, as threat actors are already leveraging this vulnerability in real-world attacks. The associated indicators of compromise include the IP addresses 206.72.242.124, 206.72.242.162, and 8.19.75.217.
New Certighost PoC Exploit Lets Attackers Hijack Windows Domains
A proof-of-concept exploit has been released for Certighost, a Windows Active Directory Certificate Services vulnerability tracked as CVE-2026-54121. The exploit enables authenticated attackers to potentially compromise entire Windows domains through forged certificates. Source: New Certighost PoC exploit lets attackers hijack Windows domains
The availability of working exploit code significantly elevates the risk profile for organizations running vulnerable Active Directory Certificate Services infrastructure. Administrators should assess their certificate services deployments and apply available mitigations to prevent domain-level compromise.
The Sub-10-Minute Cloud Takeover: Exposed IAM Keys and AI-Accelerated Attacks
Recent analysis reveals that real-world cloud attacks are achieving meaningful impact in under ten minutes through combinations of exposed IAM keys, misconfigurations, and AI-powered reconnaissance. Attackers increasingly treat cloud environments as connected systems, leveraging existing permissions and relationships to expand their reach rapidly across infrastructure. Source: The Sub-10-Minute Cloud Takeover: How Exposed IAM Keys, Misconfiguration and AI Are Rewriting the Rules of Cloud Breaches
The compression of attack timelines from hours to minutes fundamentally changes incident response requirements and emphasizes the critical importance of preventative controls. Organizations must prioritize IAM hygiene, eliminate exposed credentials, and implement continuous monitoring to detect and respond to cloud compromises before attackers establish persistent access or deploy crypto-mining infrastructure.
The convergence of zero-day exploits, proof-of-concept releases, and accelerated cloud attack timelines underscores the need for immediate patching cycles, comprehensive vulnerability management, and robust cloud security postures across all organizational environments.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- VeloCloud Orchestrator command injection vulnerability
8.19.75.217IP address seen exploiting the vulnerability206.72.242.124IP address seen exploiting the vulnerability206.72.242.162IP address seen exploiting the vulnerability
- Certighost vulnerability in Windows AD CS
- Crypto-mining infrastructureDeployed across AWS EC2 and ECS resources in November 2025 attack