Security teams faced a mixed July 25 queue: active targeting of a Fastjson 1.x remote code execution flaw, public GitLab exploit code for unpatched…
Fastjson and GitLab Flaws Draw Patch Push (7.25)
Overview
- Fastjson 1.x drew the highest patch priority after feeds.feedburner.com reported active targeting of CVE-2026-16723, an unauthenticated remote code execution flaw with an Alibaba-assigned CVSS score of 9.0.
- GitLab administrators faced a narrower but immediate exposure window after researchers published PoC code for a flaw already patched on June 10, affecting unupdated self-managed 18.11.3 servers.
- CTM360 described a shift in insurance phishing from delayed credential harvesting to faster account hijacking workflows that try to act while victims are still engaged.
- PRODAFT’s reporting on DevMan showed how ransomware-as-a-service groups are using portal-style operations to manage payloads, victims, finance, and affiliate activity.
Details
Fastjson 1.x RCE Draws Active Targeting With CVSS 9.0
feeds.feedburner.com reported on July 25 that security firms ThreatBook and Imperva observed attacks targeting Fastjson 1.x, Alibaba’s JSON library for Java. The issue is tracked as CVE-2026-16723 and carries an Alibaba-assigned CVSS score of 9.0, putting it in the Critical range by ordinary operational triage standards.
The reported risk centers on affected Spring Boot applications. In those cases, a malicious JSON request can lead to remote code execution(RCE) without authentication, running with the privileges of the Java process. That combination matters because internet-facing Java services often process JSON by default, and unauthenticated RCE shortens the path from scanning to compromise.
The source material says no patch was available at publication time. That makes mitigation more important than a normal update cycle. Teams using Fastjson 1.x should first identify exposed applications, restrict inbound access where possible, review application logs for unusual JSON payload handling, and reduce process privileges so a successful exploit has less reach.
Key takeaway: CVE-2026-16723 should be treated as an urgent exposure-management issue, not just a library bug. Until a patch is available, access controls, dependency inventory, and process hardening carry the response.
GitLab PoC Raises Risk for Unpatched Self-Managed 18.11.3 Servers
feeds.feedburner.com reported that researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched on June 10. The reported exposure applies to self-managed GitLab 18.11.3 servers that have not taken the update.
The flaw lets an authenticated user who can push to a project run commands as the git user. That is not the same as unauthenticated internet compromise, but it remains serious in organizations where many developers, contractors, automation accounts, or compromised credentials can push code.
The timing changes the risk calculus. A patch had already existed for about six weeks when the PoC appeared, so the defensive question is no longer whether a fix exists. It is whether self-managed instances actually applied it, and whether any lower-trust users had push access during the gap.
Key takeaway: The GitLab issue is most urgent for self-managed servers that skipped the June 10 patch. Public PoC code makes access review and post-patch log inspection part of the response, not optional cleanup.
CTM360 Says Insurance Phishing Is Moving Toward Real-Time Hijacking
feeds.feedburner.com reported that CTM360 research found insurance-focused phishing operations adopting a more immediate account-takeover model. Older campaigns often collected usernames and passwords for later use. The newer pattern tries to act while the victim is still in the session.
That shift matters because many defensive controls assume time exists between credential theft and account abuse. Password resets, suspicious-login review, and manual fraud checks work best when attackers wait. Real-time workflows compress that window and can force defenders to rely more on session controls, transaction checks, and phishing-resistant authentication.
The source data does not name a CVE because this is campaign research rather than a software vulnerability. The affected surface is the human login path around insurance and financial services accounts. The mitigation is therefore procedural and architectural: reduce reliance on passwords, monitor account changes in-session, and challenge high-risk actions with stronger proof.
Key takeaway: CTM360’s finding points to a faster phishing model aimed at using access immediately. Insurers and financial services teams should protect sensitive account actions, not only the initial sign-in screen.
DevMan Portal Shows RaaS Operations Becoming More Centralized
feeds.feedburner.com reported that the operators of DevMan ransomware-as-a-service maintain a dedicated web platform for affiliates. The portal reportedly supports payload building, earnings oversight, victim management, and related operational functions.
Swiss cybersecurity company PRODAFT tracks the centrally administered operation under the name Funky Mantis. The reporting describes a service model rather than a single intrusion. That distinction matters because a portal can make ransomware operations more repeatable for affiliates who do not build every tool themselves.
There is no CVE tied to this item in the supplied data. The immediate relevance for defenders is threat operations: ransomware groups continue to professionalize the business layer around intrusions, extortion, payments, and affiliate coordination. That means prevention still depends on basic controls, but response planning must account for faster handoffs after initial access.
Key takeaway: DevMan’s portal model shows ransomware operations continuing to standardize affiliate work. Defenders should focus on slowing the intrusion chain and rehearsing decisions before extortion pressure begins.
Morning Breaking Updates
- feeds.feedburner.com: Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable - A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving o
At a glance
| Fact | Publisher | Source |
|---|---|---|
| Fastjson 1.x flaw is tracked as CVE-2026-16723 with CVSS 9.0. | feeds.feedburner.com | thehackernews.com |
| Affected Spring Boot apps may allow unauthenticated remote code execution. | feeds.feedburner.com | thehackernews.com |
| GitLab patched the reported flaw on June 10; PoC code appeared July 24. | feeds.feedburner.com | thehackernews.com |
| Self-managed GitLab 18.11.3 servers are exposed if they missed the update. | feeds.feedburner.com | thehackernews.com |
| CTM360 described insurance phishing that moves toward real-time account takeover. | feeds.feedburner.com | thehackernews.com |
| PRODAFT tracks the DevMan RaaS operation under the name Funky Mantis. | feeds.feedburner.com | thehackernews.com |
FAQ
Sources
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available - feeds.feedburner.com
- Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git - feeds.feedburner.com
- CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking - feeds.feedburner.com
- Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE - feeds.feedburner.com
- DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts - feeds.feedburner.com
- BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery - feeds.feedburner.com
- CISA Cybersecurity Advisories - CISA
- National Vulnerability Database - NIST
- Microsoft Security Response Center - Microsoft
- Google Online Security Blog - Google
- Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable - feeds.feedburner.com
Last updated: 2026-07-26T04:20:08.308Z
댓글
댓글 쓰기