Monday, July 27, 2026 | Jonathan Lockhart
Fastjson Exploitation Arrives Without a Patch for the 1.x Branch
The Fastjson project disclosed a remote code execution flaw in versions 1.2.68 through 1.2.83. Under the project’s verified conditions, a vulnerable Spring Boot application packaged as an executable fat JAR can be exploited with Fastjson’s stock defaults. AutoType does not need to be enabled, and the attacker does not need a suitable gadget class already present on the server.
ThreatBook says its platform has captured in-the-wild exploitation and that public proof-of-concept code is available. That claim should be read with the project’s narrower scope in mind: the Fastjson advisory identifies the affected range and fat-JAR prerequisite, while ThreatBook’s own testing reproduced full code execution in a Spring Boot fat-JAR environment and only server-side request forgery in one embedded-Tomcat scenario.
There will be no repaired Fastjson 1.x release. The branch is no longer maintained. Immediate options are to enable SafeMode or move to the 1.2.83_noneautotype build; the durable fix is migration to Fastjson 2. Inventory matters first, because an application team may not realize the parser is embedded inside a deployable Java package.
Watch for: Fastjson 1.2.68 through 1.2.83 inside Spring Boot fat JARs, SafeMode left disabled, JSON requests containing suspicious @type values, jar:http retrieval attempts and Java processes spawning shells or download utilities.
Sources: Alibaba Fastjson project, “Security Advisory: Remote Code Execution in fastjson 1.2.68–1.2.83,” July 21, 2026; ThreatBook, “Fastjson RCE: Active Exploitation Detected—Detection & Mitigation,” July 22, 2026.
Check Point Management Servers Were Exploited Through the Front Door
Check Point has confirmed exploitation of CVE-2026-16232, an improper-authentication vulnerability affecting SmartConsole and security-management environments. The company said the activity reached a handful of customers whose management systems were directly exposed to the internet without source-address restrictions.
Check Point published its advisory, indicators and latest Jumbo Hotfix on July 22, the same day the Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog. CISA gave U.S. federal agencies a July 25 remediation deadline. Check Point privately notified known targets, but the actor and the full post-compromise activity remain undisclosed.
This is a management-plane problem, not merely another edge-device bug. A compromised security console can expose policy, objects, credentials and administrative trust that govern the devices defenders rely on to contain an intrusion. Patch status matters, but so does proving that the management interface was never broadly reachable—or investigating it as a potential compromise if it was.
Watch for: Internet-reachable Check Point management services, SmartConsole connections from unfamiliar addresses, unexpected administrator creation, unexplained policy changes, unusual management-server exports and evidence of access before the hotfix was installed.
Sources: Check Point, “Security Advisory—Action Required—July 2026 Security Update,” July 22, 2026; Check Point SecureKnowledge article sk185169, “CVE-2026-16232—Authentication Bypass with SmartConsole Login Process Using Application Token,” July 2026; CISA Known Exploited Vulnerabilities Catalog, added July 22, 2026, remediation due July 25, 2026.
A Notebook Diff Can Become Code Execution on GitLab
Depthfirst released a public proof of concept on July 24 for a command-execution chain in self-managed GitLab. A normal authenticated user who can push to a project and view its commit diff can place crafted JSON in a Jupyter Notebook file and trigger the vulnerable parser when GitLab renders the notebook’s changes.
The chain combines an out-of-bounds write and a heap-address disclosure in the native C code of the Oj Ruby JSON parser. Successful exploitation runs commands as the git account inside a Puma application worker. It does not require administrator rights, access to a runner, another victim’s project or an additional user to open the diff.
GitLab shipped the repaired Oj version in GitLab 18.10.8, 18.11.5 and 19.0.2 on June 10; GitLab.com was already patched. No in-the-wild exploitation has been reported. The publication of working code changes the urgency for self-managed installations that deferred the earlier update without knowing what the dependency bump prevented.
Watch for: Self-managed GitLab below the fixed releases, malformed or unusual .ipynb commits, Puma crashes involving Oj, the git account spawning shells or system utilities and unexpected outbound traffic from GitLab application workers.
Sources: Depthfirst, “Going Depthfirst: Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities,” July 24, 2026; GitLab, “Patch Release: 19.0.2, 18.11.5, 18.10.8,” June 10, 2026.
One Compromised Mailbox Reached Bank of Baroda Customer Data
India’s state-run Bank of Baroda said today that a compromised employee email account led to unauthorized access to certain data. The bank has contained the initial access, started a forensic investigation and is working with authorities. It said its core banking systems were not accessed and remain secure.
Cybersecurity researcher Srikanth L told Reuters that the leaked material includes customer details, identification documents, loan papers and internal audit records. He said the dark-web listing advertised more than 700 gigabytes, based on his analysis of the site’s metadata. The bank has not confirmed the volume, and the number of affected customers remains unknown.
The useful distinction is between transaction processing and the information orbiting it. A core banking platform can remain intact while mail, shared repositories and workflow documents expose enough identity and loan data for fraud and highly credible social engineering. Containment should therefore extend beyond the mailbox password to sessions, application grants, forwarding rules and every repository the account could reach.
Watch for: Legacy mailbox sessions, suspicious forwarding or inbox rules, new OAuth grants, bulk access to loan and audit repositories, downloads by the compromised identity and phishing that uses genuine customer or loan details.
Sources: Reuters, “Customer Data From India’s Bank of Baroda Leaked Online, Source and Researcher Say,” July 27, 2026, incorporating Bank of Baroda’s statement and Srikanth L’s metadata analysis.
Malware at AnMed Is Changing Where Patients Can Receive Care
South Carolina health system AnMed says malware is disrupting its network today. AnMed Medical Group offices and Imaging Services are closed for Monday, July 27, and patients with scheduled elective procedures are being contacted directly. Emergency departments continue to see patients, while urgent care, pediatric care, integrated therapy and laboratory locations are operating on their published schedules.
AnMed is coordinating procedures, transfers and diversions with emergency medical services, nearby hospitals and public-safety partners. It has not identified an actor, called the incident ransomware or confirmed that patient data was taken. The scope and restoration timeline remain under investigation.
This is the immediate healthcare impact that breach totals can obscure: unavailable communications and clinical systems force care-routing decisions before anyone knows whether information was stolen. The priority is safe continuity—reliable downtime records, medication and allergy checks, controlled restoration, and clear handoffs between facilities.
Watch for: Lateral movement between business and clinical networks, loss of electronic health record or identity services, unauthorized remote-management tools, unusual privileged-account activity, failures in backup communications and restoration pressure that bypasses validation.
Sources: AnMed, “AnMed Systems Disruption,” July 26, 2026; AnMed, “Service, Practice Openings and Closings for Monday, July 27, 2026,” July 26, 2026.
Fairlife Restarted Production Before the Data Story Was Finished
Coca-Cola says its Fairlife dairy subsidiary has resumed a majority of production at four U.S. facilities after a ransomware event forced operations offline on July 16. Existing inventory largely preserved retail availability, and the company says product quality and safety were not affected.
Today’s update also confirms that the intruder took certain data, although Coca-Cola has not described the information or its owners. The Anubis group claims it stole one terabyte, but that figure remains an attacker assertion. Coca-Cola currently believes the incident has not had, and is not reasonably likely to have, a material financial impact.
Operational recovery and breach scoping run on different clocks. A plant can restart safely while investigators are still determining which documents left the network and whose notification obligations follow. The cleanest recovery test is therefore not “Are the lines moving?” but whether production, identity and administrative systems were restored from trusted states and the attacker’s access paths were removed.
Watch for: Reintroduced credentials during plant restoration, suspicious access between enterprise and production networks, compromised supplier or maintenance accounts, delayed evidence of data staging and extortion disclosures that reveal the contents of the stolen material.
Sources: The Coca-Cola Company, Fairlife technology-disruption update, July 27, 2026; Reuters, “Coca-Cola Says Fairlife Resumes Production at Four U.S. Plants After Cyberattack,” July 27, 2026; SecurityWeek, “Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack,” July 27, 2026.
A Simulation File Can Execute Code on an Engineering Workstation
Rockwell Automation has patched four high-severity memory-corruption flaws in Arena Simulation. CVE-2026-8085, CVE-2026-8312, CVE-2026-8313 and CVE-2026-8314 affect separate model, experiment, linker and simulation components. A crafted Arena file can trigger an out-of-bounds write and execute code in the context of the current process.
This is not an unauthenticated remote takeover. An attacker must persuade a user to open the malicious file, and there is no public evidence of exploitation. Arena 17.00.00 and earlier are affected; Rockwell fixed the flaws in version 17.00.01.
Arena is simulation software rather than a plant controller, but its files carry operational trust. Engineering workstations may hold process models, production assumptions and access to adjacent industrial environments. Treat externally supplied models and experiments as active content, isolate analysis where possible and do not let the absence of direct controller impact reduce workstation protections.
Watch for: Arena versions at or below 17.00.00, model or experiment files arriving through email and shared portals, Arena child processes, crashes in Siman components and engineering workstations with unnecessary access to production networks.
Sources: CISA Industrial Control Systems Advisory ICSA-26-197-01, “Rockwell Automation Arena,” July 16, 2026; Rockwell Automation Security Advisory SD1784, July 2026; SecurityWeek, “Rockwell Patches Code Execution Flaws in Arena Simulation Software,” July 25, 2026.
HollowGraph Hid Commands and Stolen Files in a Calendar
Group-IB identified HollowGraph, Windows malware that turns a compromised Microsoft 365 mailbox calendar into a two-way command-and-control channel. Operators place encrypted instructions in event attachments, and the implant creates its own events to return stolen files. The appointments are dated May 13, 2050 so they stay away from the user’s normal calendar view.
A second channel uses IPv6 Domain Name System queries to refresh the Microsoft Entra ID credentials needed for Graph access. Group-IB found the implant on 12 systems, about three of which were actively communicating at the time of analysis, and assessed that the observed activity was focused on Israeli targets. It linked the malware to the Cavern framework with high confidence.
This is not a Microsoft 365 vulnerability. The attacker already needs a usable cloud identity and application credentials. The defensive shift is to inspect what trusted software identities do inside collaboration services—not merely whether traffic goes to a trusted Microsoft domain.
Watch for: Calendar events dated May 13, 2050, application-created events with attachments, unusual Graph calendar operations, the file logAzure.txt, repeated IPv6 AAAA queries for cloudlanecdn[.]com and mailbox access by unfamiliar applications.
Sources: Group-IB, “HollowGraph: Turning Microsoft 365 Calendars Into Covert Command-and-Control Channels,” July 20, 2026; Broadcom, “HollowGraph Malware Leverages Microsoft 365 Calendar Events for C2 Communication,” July 2026.
MedusaHVNC Gives Criminals a Browser Session the Victim Cannot See
BlackFog analyzed MedusaHVNC, a remote-access trojan sold as malware-as-a-service. Its hidden-desktop module launches a legitimate browser on a separate Windows desktop that is invisible to the user. By loading an existing browser profile, an operator can work inside authenticated sessions from the victim’s own device and network location.
The analyzed chain starts with obfuscated JavaScript executed by Windows Script Host, uses AutoIt, establishes persistence with a batch file in the Startup folder and injects the final payload into charmap.exe. The sample used a custom Transmission Control Protocol channel to a hard-coded command server.
The evidence supports the capabilities of the sample, not claims of a large deployed campaign. The important detection idea is behavioral: a second browser desktop, profile access and interactive activity can reveal session abuse that password-reset telemetry may miss.
Watch for: wscript.exe launching AutoIt or unusual installers, Startup-folder batch files, code injection into charmap.exe, browsers attached to hidden desktops, new processes reading browser-profile data and outbound traffic to 51.89.204[.]28 on port 4444.
Sources: BlackFog, “MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions,” July 27, 2026; SecurityWeek, “MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection,” July 27, 2026.
SourTrade Makes the Victim’s Browser Assemble the Malware
Confiant has documented SourTrade, a malvertising operation that impersonates TradingView, Solana and Luno across 12 countries and 25 languages. Its landing pages fingerprint visitors, showing convincing download sites to selected targets while serving blank or harmless pages to bots and analysts.
Instead of sending one finished malicious executable, the site gives the browser a build recipe. A SharedWorker retrieves instructions, the browser downloads a clean Bun runtime, locally generates additional bytes and combines them with attacker-supplied material. A ServiceWorker then delivers the completed Windows executable through a same-origin download path. The resulting file can vary by victim or session.
This is not a browser exploit; the victim still has to download and run the file. The innovation is delivery. A network sensor that sees only a clean runtime or a file scanner looking for one stable hash can miss the assembled result. Detection has to connect the advertisement, landing-page workers, component retrieval, final download and execution.
Watch for: Trading or cryptocurrency software obtained through ads, landing pages that register SharedWorkers and ServiceWorkers before a download, /config responses containing build templates, clean Bun runtimes followed by newly assembled executables and same-origin downloads from newly registered domains.
Sources: Confiant Threat Intelligence, “SourTrade: Browser-Assembled Malware Delivered Through Malvertising,” July 23, 2026.
Jonathan Lockhart is a cybersecurity researcher and investigative journalist at bordercybergroup.com.
If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.
Member discussion: