Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (27 July 2026)
Published: Loading…
At a Glance
- Cl0p-linked attackers chain a pre-authentication flaw in PTC FlexPLM with a Windchill login servlet bug for unauthenticated RCE.
- A published proof-of-concept exploit lets authenticated users run commands as git on unpatched self-managed GitLab 18.11.3 servers.
- Attackers actively exploit unpatched Fastjson CVE-2026-16723, letting malicious JSON requests execute code in Spring Boot applications without authentication.
- GitHub's Dependabot now applies a 72-hour cooldown and PyPI blocks release file uploads after 14 days to curb supply-chain attacks.
- The SourTrade malvertising campaign impersonates TradingView, Solana and Luno, instructing browsers to assemble Windows malware in memory.
- DevMan ransomware-as-a-service, tracked as Funky Mantis, centralizes payload builds, victim management, and affiliate payouts on one portal.
Editorial Analysis
Several incidents today show how quickly exposed enterprise software can become an entry point for attackers, from Cl0p campaigns targeting PTC systems to an actively exploited Fastjson vulnerability affecting Spring Boot deployments. A public GitLab exploit further demonstrated how rapidly technical research can translate into usable attack methods.
These cases differ technically, but share a common pattern: security assumptions around widely deployed software continue to break at points that were considered protected. Legacy components, overlooked code paths, and exposed functionality can all create new entry points despite previous hardening efforts.
Malvertising is also evolving beyond static payload delivery. The SourTrade campaign no longer serves a finished malicious file; instead, it provides legitimate-looking components and instructions that allow the browser to construct the final executable in memory. This shifts the compromise point away from a downloadable payload towards behaviour generated locally on the victim's machine, making detection based only on static artefacts less effective.
Highlights of the Day
Fake Steam Forum Fixes Infect Gamers With Cryptominers
Threat actors are posting fake troubleshooting replies on Steam discussion forums, urging users to run malicious PowerShell commands. The script poses as a Windows optimisation tool called "msf utility \ PC Opt" while secretly disabling Defender protections and downloading an XMRig cryptominer. The malware installs itself as a persistent scheduled task running with SYSTEM privileges.
Malvertising Campaign Assembles Malware Inside Victims' Browsers
Confiant detailed "SourTrade," a malvertising operation active since late 2024 that impersonates TradingView, Solana and Luno to target traders across multiple countries. Rather than delivering finished malware, landing pages instruct the browser to fetch a clean Bun runtime and assemble a malicious executable locally using AES-CTR generated bytes. This technique evades file-fingerprinting detection, since network logs only show clean components being downloaded.
Fastjson's "Safe" 1.2.83 Release Found Vulnerable to RCE
Researchers at FearsOff discovered CVE-2026-16723, a remote code execution flaw in fastjson 1.2.83, previously considered secure with AutoType disabled. The bug chains a blind SSRF in the class-lookup function with a technique that reads still-open temporary jar files via /proc/self/fd, bypassing Java 9's stricter class-name restrictions. The flaw affects Spring Boot fat-jar deployments and impacts fastjson versions 1.2.68 through 1.2.83, according to Alibaba's advisory.
Researchers Chain Two Ruby Bugs for GitLab RCE
DepthFirst researchers combined two memory-corruption flaws in Oj, a native JSON parser used by GitLab's notebook-diff feature, to achieve remote code execution. An unchecked nesting stack enabled a heap write primitive, while a key-length truncation bug leaked a heap pointer, together defeating ASLR to hijack execution. The chain affects GitLab CE and EE versions 15.2.0 through 19.0.1, exploitable by any authenticated user able to push a commit.
GitHub and PyPI Add Time Delays to Curb Supply-Chain Attacks
GitHub's Dependabot now applies a default 72-hour cooldown before adopting new package updates, reducing exposure to newly published malicious code. PyPI separately blocks maintainers from adding new files to a release more than 14 days after publication, preventing poisoning of trusted older releases. Both measures follow a string of recent supply-chain incidents including the Shai-Hulud and GhostAction campaigns.
Daily Coverage