Threat Brief — 2026-07-25 — Zero-patch RCE and AI-tool worming
Executive summary: Attackers are actively exploiting a critical Fastjson 1.x RCE in Spring Boot apps with no fix available — patch or mitigate now if you have Java services using Fastjson. Separately, a new npm worm is spreading through AI coding assistants (Claude, Cursor, VS Code) via a malicious MCP server, stealing developer keys. Iranian-linked actors are targeting US ICS vendors (Rockwell, Schneider, Siemens), though some claimed "destruction" appears to have been a Microsoft outage rather than attacker success. JadeProx exposed itself by leaving a command-history server open.
Top items
- Fastjson 1.x unpatched RCE under active attack. ThreatBook and Imperva confirm attackers are exploiting a critical remote code execution flaw in Alibaba's Fastjson 1.x within Spring Boot applications. A malicious unauthenticated JSON request triggers code execution. No patch is available — if your Java services use Fastjson 1.x, consider disabling autotype or removing the dependency immediately. (src: thehackernews)
- npm worm spreads via fake MCP server, steals developer keys from Claude, Cursor, and VS Code. A self-propagating npm package dubbed SANDWORM_MODE infects AI coding assistants through a malicious Model Context Protocol server, exfiltrating developer API keys and tokens and spreading laterally across project dependencies. Any team using AI-assisted coding tooling with MCP integration should audit installed MCP servers and rotate keys. (src: securitylab-ru)
- Iranian hackers target Rockwell, Schneider, and Siemens ICS across US energy, water, and wastewater. A new campaign attributed to Iranian cyber units is probing and attempting intrusions against US critical infrastructure, specifically industrial control systems from three major vendors. Some claimed attacks — where groups asserted "we destroyed everything" — are being assessed by analysts as potentially linked to a routine Microsoft outage rather than genuine destructive success, though the targeting pattern itself is confirmed. (src: securitylab-ru, securitylab-ru)
- JadeProx group exposed by open command-history server. Researchers discovered an exposed server containing the full command history of the JadeProx hacking group, revealing targets across Asia (Vietnamese hospitals, Malaysia's Foreign Ministry, Hong Kong universities) and Latin America. This builds on prior reporting of JadeProx's new TriBack loader (first reported 2026-07-23 by thehackernews), now with operational-security failure exposing their full target scope. (src: securitylab-ru)
- Fake civil-defense app in Bahrain turns phones into spyware. A trojanised "anti-missile" civil-defense application distributed in Bahrain exploits citizen fear during security incidents, installing full surveillance capabilities on smartphones. This is a textbook crisis-exploitation social-engineering pattern relevant to any organisation with staff in the Gulf region. (src: securitylab-ru)
Themes
- Crisis-exploitation social engineering is scaling. The Bahrain fake civil-defense app mirrors patterns seen in conflict zones — attackers weaponize public fear to distribute spyware. Organisations with personnel in volatile regions should warn staff to only install official government apps from verified stores.
- AI tooling as an attack surface is maturing. The SANDWORM_MODE npm worm targeting MCP servers in Claude/Cursor/VS Code is a notable escalation — it turns AI coding assistants into both target and propagation vector. Combined with recent fake-Claude malvertising and Claude jailbreak-as-a-service stories, AI assistant security is a recurring thread this week.
- ICS targeting persists with disputed impact. Iranian ICS campaigns against US infrastructure continue, but the gap between attacker claims and verified impact remains wide — some "successful" attacks may be coincidental outages. Treat all ICS vendor alerts seriously but verify before attributing.
===
[{"slug":"fastjson-1x-rce-no-patch","headline":"Fastjson 1.x unpatched RCE actively exploited in Spring Boot","findingIds":[4308],"status":"new"},
{"slug":"sandworm-mode-npm-mcp-worm","headline":"npm worm via fake MCP server steals developer keys from AI coding assistants","findingIds":[4307],"status":"new"},
{"slug":"iranian-ics-targeting-us-infrastructure","headline":"Iranian hackers target Rockwell, Schneider, Siemens ICS in US utilities","findingIds":[4304,4303],"status":"new"},
{"slug":"jadeprox-triback-loader","headline":"JadeProx exposed by open command-history server revealing Asia/LatAm targets","findingIds":[4306],"status":"developing","development":"Researchers found an exposed server with JadeProx command history, exposing full target scope after the group's new TriBack loader was first reported 2026-07-23"},
{"slug":"bahrain-fake-civil-defense-spyware","headline":"Fake anti-missile civil-defense app in Bahrain installs phone spyware","findingIds":[4305],"status":"new"}]
