Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Attackers are targeting a critical unauthenticated RCE vulnerability (CVE-2026-16723, CVSS 9.0) in Fastjson 1.x, Alibaba's JSON library for Java. In Spring Boot applications, a malicious JSON request can execute code with Java process privileges without authentication.
Security researchers published working exploit code for a GitLab RCE vulnerability (patched June 10, 2026) that lets any authenticated user who can push to a project run commands as the git user on self-managed GitLab 18.11.3 servers. The exploit uses crafted Jupyter notebooks to leak heap pointers via commit diffs, then fires payloads through memory corruption bugs in the Oj Ruby JSON parser.
CTM360 research reveals that insurance-focused phishing has evolved from credential harvesting to real-time account hijacking. Attackers now synchronize their activity with victims in real-time, authenticating against legitimate insurance portals as victims unknowingly complete the login process, all within a single browsing session.
Cl0p ransomware affiliates are exploiting flaws in internet-exposed PTC Windchill and FlexPLM deployments in a new data extortion campaign. Attackers chain a pre-authentication information disclosure in FlexPLM's WSDL endpoint with a server-side flaw in Windchill's login servlet to achieve unauthenticated RCE and deploy JSP web shells.
The DevMan ransomware-as-a-service operation, tracked as Funky Mantis by PRODAFT, maintains a dedicated web platform offering affiliates payload building, earnings oversight, victim management, and payout functions. First emerging in April 2025 as an affiliate for Qilin, DragonForce, Apos, and RansomHub, DevMan later shifted to its own RaaS operation.
Escalating threats are forcing boards to prioritize security, but communication gaps persist.