This day 02:09 06:09 10:09 14:10 18:00 22:00
Info  2026-07-25 14:10Z · last 4h · 6 findings · glm-5.2:cloud

Threat Brief — 2026-07-25 — Zero-patch RCE and AI-tool worming

Executive summary: Attackers are actively exploiting a critical Fastjson 1.x RCE in Spring Boot apps with no fix available — patch or mitigate now if you have Java services using Fastjson. Separately, a new npm worm is spreading through AI coding assistants (Claude, Cursor, VS Code) via a malicious MCP server, stealing developer keys. Iranian-linked actors are targeting US ICS vendors (Rockwell, Schneider, Siemens), though some claimed "destruction" appears to have been a Microsoft outage rather than attacker success. JadeProx exposed itself by leaving a command-history server open.

Top items

Themes

===

[{"slug":"fastjson-1x-rce-no-patch","headline":"Fastjson 1.x unpatched RCE actively exploited in Spring Boot","findingIds":[4308],"status":"new"},

{"slug":"sandworm-mode-npm-mcp-worm","headline":"npm worm via fake MCP server steals developer keys from AI coding assistants","findingIds":[4307],"status":"new"},

{"slug":"iranian-ics-targeting-us-infrastructure","headline":"Iranian hackers target Rockwell, Schneider, Siemens ICS in US utilities","findingIds":[4304,4303],"status":"new"},

{"slug":"jadeprox-triback-loader","headline":"JadeProx exposed by open command-history server revealing Asia/LatAm targets","findingIds":[4306],"status":"developing","development":"Researchers found an exposed server with JadeProx command history, exposing full target scope after the group's new TriBack loader was first reported 2026-07-23"},

{"slug":"bahrain-fake-civil-defense-spyware","headline":"Fake anti-missile civil-defense app in Bahrain installs phone spyware","findingIds":[4305],"status":"new"}]

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db