logo

Fastjson RCE under attack, no patch; GitLab exploit public; PTC manufacturing targeted

ID: dea2bd70-acfd-5168-84ca-059f9e78027d

STIX ID: report--dea2bd70-acfd-5168-84ca-059f9e78027d

Feed Name: defend.network

Threat Score
88/100

Date Published: 2026-07-26

Date Updated: 2026-07-26

Author: defend.network

...
...

This briefing reports multiple high-risk active threats: a critical, actively exploited Fastjson RCE (CVE-2026-16723) with no vendor patch; a published GitLab RCE PoC affecting unpatched self-managed servers; a SourTrade malvertising campaign that assembles Windows malware in-browser to evade detections; Cl0p affiliates exploiting PTC Windchill/FlexPLM for data extortion; and finance-sector phishing that conducts real-time account hijacking. Immediate actions recommended include inventorying and segmenting vulnerable Spring Boot apps, patching/updating GitLab, implementing browser isolation, restricting internet exposure of PTC systems, and enforcing stronger MFA and transaction controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.