This day 02:09 06:09 10:09 14:10 18:00 22:00
Info  2026-07-25 14:10Z · last 4h · 6 findings · glm-5.2:cloud

Threat Brief — 2026-07-25 — Zero-patch RCE and AI-tool worming

Executive summary: Attackers are actively exploiting a critical Fastjson 1.x RCE in Spring Boot apps with no fix available — patch or mitigate now if you have Java services using Fastjson. Separately, a new npm worm is spreading through AI coding assistants (Claude, Cursor, VS Code) via a malicious MCP server, stealing developer keys. Iranian-linked actors are targeting US ICS vendors (Rockwell, Schneider, Siemens), though some claimed "destruction" appears to have been a Microsoft outage rather than attacker success. JadeProx exposed itself by leaving a command-history server open.

Top items

Themes

===

[{"slug":"fastjson-1x-rce-no-patch","headline":"Fastjson 1.x unpatched RCE actively exploited in Spring Boot","findingIds":[4308],"status":"new"},

{"slug":"sandworm-mode-npm-mcp-worm","headline":"npm worm via fake MCP server steals developer keys from AI coding assistants","findingIds":[4307],"status":"new"},

{"slug":"iranian-ics-targeting-us-infrastructure","headline":"Iranian hackers target Rockwell, Schneider, Siemens ICS in US utilities","findingIds":[4304,4303],"status":"new"},

{"slug":"jadeprox-triback-loader","headline":"JadeProx exposed by open command-history server revealing Asia/LatAm targets","findingIds":[4306],"status":"developing","development":"Researchers found an exposed server with JadeProx command history, exposing full target scope after the group's new TriBack loader was first reported 2026-07-23"},

{"slug":"bahrain-fake-civil-defense-spyware","headline":"Fake anti-missile civil-defense app in Bahrain installs phone spyware","findingIds":[4305],"status":"new"}]

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb