Security News

Cybersecurity news aggregator

CRITICAL Attacks SC Media

Hackers exploit FastJson vulnerability for remote code execution

A critical vulnerability (CVE-2026-16723, CVSS 9.0) in the FastJson Java library allows for unauthenticated remote code execution via its type-resolution logic, particularly targeting Spring Boot fat-JAR deployments. The flaw affects FastJson versions 1.2.68 through 1.2.83, and no official patch is available as the 1.x branch is no longer maintained. As a workaround, developers should enable SafeMode or migrate to a non-impacted build like fastjson2.
Read Full Article →

Threat Management , Threat Intelligence Hackers exploit FastJson vulnerability for remote code execution July 28, 2026 Share By SC Staff Bleeping Computer disclosed that hackers are actively exploiting a critical vulnerability in the FastJson open-source Java library, enabling remote code execution without requiring user interaction or elevated privileges. The security flaw, identified as CVE-2026-16723, affects FastJson versions 1.2.68 through 1.2.83. ThreatBook researchers observed the malicious activity last week, with Imperva confirming that a wide range of organizations across Financial Services, Healthcare, Computing, Retail, and Business industries are being targeted. Attacks are primarily focused on U.S. organizations, with some instances in Singapore and Canada. The vulnerability stems from the library's type-resolution logic, which allows attackers to execute malicious code remotely, particularly in Spring Boot fat-JAR deployments. Alibaba confirmed the critical severity and noted that the issue is exploitable on the most common Spring Boot deployment model. A fix is not available, and FastJson 1.x is no longer actively maintained, making it unlikely to receive an update. Developers are advised to enable SafeMode or switch to a non-impacted build, such as fastjson2, which uses a more secure allowlist-first model. Source: Bleeping Computer SC Staff Related Data Security Arista patches critical command injection flaw in VeloCloud Orchestrator exploited in attacks SC Staff July 28, 2026 As reported by Bleeping Computer, Arista released a patch for a critical command injection vulnerability affecting on-premises VeloCloud Orchestrator (VCO) deployments. Ransomware Operation Cronos dismantled LockBit ransomware group by undermining affiliate trust SC Staff July 28, 2026 As reported by Dark Reading, Operation Cronos, a significant international law enforcement effort, successfully dismantled LockBit, once one of the most dominant ransomware-as-a-service (RaaS) operations globally. Identity German government report details Windows Hello for Business biometric security limitations SC Staff July 28, 2026 Germany’s Federal Office for Information Security (BSI) published a technical analysis of Windows Hello for Business, detailing how the system performs biometric identification and highlighting potential security vulnerabilities. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Cybercast RSAC Preview: Exposure management takes center stage On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Botnet DNS Spoofing Deauthentication Attack Defacement Dictionary Attack Distributed Scans DumpSec Information Warfare Password Cracking Reconnaissance You can skip this ad in 5 seconds

Share this article