Fastjson RCE under attack, no patch; GitLab exploit public; PTC manufacturing targeted
ID: dea2bd70-acfd-5168-84ca-059f9e78027d
STIX ID: report--dea2bd70-acfd-5168-84ca-059f9e78027d
Feed Name: defend.network
This briefing reports multiple high-risk active threats: a critical, actively exploited Fastjson RCE (CVE-2026-16723) with no vendor patch; a published GitLab RCE PoC affecting unpatched self-managed servers; a SourTrade malvertising campaign that assembles Windows malware in-browser to evade detections; Cl0p affiliates exploiting PTC Windchill/FlexPLM for data extortion; and finance-sector phishing that conducts real-time account hijacking. Immediate actions recommended include inventorying and segmenting vulnerable Spring Boot apps, patching/updating GitLab, implementing browser isolation, restricting internet exposure of PTC systems, and enforcing stronger MFA and transaction controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
