# Today's Top Stories

July 26, 2026

  1. 1
    0
    The Hacker News general Jul 25
    Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

    CVE-2026-16723, a critical unauthenticated RCE vulnerability in Alibaba's Fastjson 1.x Java library (CVSS 9.0), is being actively exploited in the wild with no patch currently available. ThreatBook and Imperva confirmed that attackers can execute arbitrary code without authentication in affected Spring Boot applications by sending a malicious JSON request. Security practitioners running Spring Boot with Fastjson 1.x should treat this as an emergency given active exploitation and the absence of a vendor fix.

  2. 2
    0
    The Hacker News general Jul 25
    Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

    Cl0p ransomware affiliates (tracked as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) are actively exploiting chained unauthenticated RCE vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments in a new data extortion campaign. The attack chain combines a pre-authentication information disclosure flaw in the FlexPLM WSDL endpoint with a server-side vulnerability in the Windchill login servlet. Industrial organizations using these PLM platforms should immediately audit external exposure and apply available patches.

  3. 3
    0
    The Hacker News general Jul 25
    Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

    Security researcher Yuhang Wu published a working RCE proof-of-concept for GitLab 18.11.3 self-managed instances that allows any authenticated user — with no admin or CI runner privileges — to execute commands as the git system user. The exploit is triggered by committing two specially crafted Jupyter notebooks and requesting their diff, requiring no victim interaction beyond standard authentication. Organizations running unpatched self-managed GitLab instances should treat this as critical given the low privilege bar and publicly available exploit code.

  4. 4
    0
    The Hacker News general Jul 24
    BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

    North Korean threat group BlueNoroff has operationalized a phishing kit that impersonates Zoom and Microsoft Teams via typosquatted domains, profiling cryptocurrency wallet contents before selectively deploying malware. The kit combines compromised industry contacts with social engineering to abuse trust relationships, targeting crypto wallet holders with tailored payloads. This represents a significant operational maturity step for BlueNoroff beyond standard ClickFix-style lure campaigns.

  5. 5
    0
    Dark Reading general Jul 24
    Default Azure Automation Setting Enables Cross-Tenant Identity Takeover

    Microsoft patched a public-by-default misconfiguration in Azure Automation combined with code-level flaws that could have allowed attackers to perform cross-tenant identity takeover, gaining access to other tenants' data, credentials, and cloud workloads. The issue stemmed from Azure Automation's default configuration exposing managed identity capabilities beyond intended scope. Cloud security teams should audit Azure Automation configurations and managed identity permissions as a priority remediation action.

  6. 6
    0
    The Hacker News general Jul 25
    Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

    The SourTrade malvertising campaign, active since late 2024 and detailed by Confiant on July 23, 2026, has victims' browsers assemble the final Windows malware executable in memory using a legitimate Bun JavaScript runtime — avoiding delivery of a single detectable malicious file from a fixed URL. The operation impersonated TradingView, Solana, and Luno to target retail traders and crypto users. This browser-side assembly technique presents a significant challenge for traditional network-based malware detection controls.

  7. 7
    0
    BleepingComputer general Jul 24
    Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

    Threat actors are hijacking DNS settings on Wi-Fi routers at hotels and conference centers to redirect guests to spoofed Microsoft 365 login pages designed to steal credentials. The attack targets transient, high-value business users who are unlikely to scrutinize connection details on unfamiliar networks. Security teams should advise employees to use VPNs on untrusted networks and enable phishing-resistant MFA such as FIDO2 for M365 accounts.

  8. 8
    0
    The Hacker News general Jul 24
    Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

    CERT-UA has attributed a new campaign to Russia-aligned threat cluster UAC-0099, which is now delivering the MATCHBOIL.V2 malware disguised as a legitimate Notepad++ plugin to compromise Windows systems. UAC-0099 previously weaponized WinRAR vulnerabilities and continues to evolve its delivery mechanisms against Ukrainian targets. Defenders should treat unsolicited Notepad++ plugins as high-risk and implement application allowlisting to block unauthorized plugin execution.

  9. 9
    0
    The Hacker News general Jul 24
    Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

    The Golden Chickens malware-as-a-service ecosystem has resurfaced with four new malware families: TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and a modified browser credential stealer, indicating continued operational resilience despite extensive prior public disclosure. The new modular implant architecture suggests the operators are deliberately compartmentalizing capabilities to evade detection and attribution. Threat hunters should update detection rules to cover these new family signatures across endpoint and network telemetry.

  10. 10
    0
    BleepingComputer general Jul 24
    Hermes AI agent used to automate attack on Thai Finance Ministry

    A threat actor deployed the open-source Hermes AI agent in autonomous 'YOLO' mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance, marking one of the first documented cases of an AI agent being used hands-off for attack automation against a government target. The use of Hermes in unattended mode allowed the actor to conduct reconnaissance and lateral movement without direct operator involvement. This incident signals a practical escalation in AI-assisted offensive operations that defenders need to account for in incident response playbooks.