Daily Security Intel

Archives
Log in
Subscribe
July 28, 2026

[SecurityIntel] 28 Jul | Active Zero-Day Exploitation of FastJson and Arista

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Tuesday, July 28, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Active Zero-Day Exploitation of FastJson and Arista

CRITICAL

5

C2 IPs

43

OTX IOCs

40

ARTICLES

■ ANALYST TLDR

Active zero-day exploitation of unauthenticated remote code execution vulnerabilities in the FastJson Java library and command injection flaws in Arista VeloCloud Orchestrator present immediate perimeter threats to enterprises. Concurrently, attackers are exploiting an unsafe deserialization flaw in PTC Windchill to deploy ransomware, while the Dysphoria IoT botnet has expanded to 200,000 devices using blockchain-based C2. Security teams must also monitor the emergence of autonomous AI agents being utilized in cyber-espionage campaigns and secure shadow AI deployments.

■ CRITICAL STORIES

CRITICAL#1

Hackers target US firms in FastJson RCE zero-day attacks

A zero-day vulnerability in the widely used open-source FastJson Java library allows unauthenticated remote code execution without user interaction, posing an immediate threat of full system compromise to exposed enterprise applications.

CRITICAL#2

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in the wild to compromise software-defined WAN infrastructures.

HIGH#3

Hackers used autonomous AI agent to spy on Thailand's finance ministry

Cyber-espionage actors have deployed an autonomous AI agent to conduct target surveillance and data gathering against Thailand's Ministry of Finance, demonstrating a practical escalation in AI-driven offensive capabilities.

HIGH#4

PTC Windchill Vulnerability Exploited in Ransomware Campaign

Threat actors are actively exploiting an unauthenticated unsafe deserialization vulnerability in PTC Windchill PLM software to execute arbitrary code and deploy ransomware.

■ CVEs IDENTIFIED

[CVE-TBD]

FastJson Java Library — Remote Code Execution via unauthenticated input

Critical

[CVE-TBD]

Arista VeloCloud Orchestrator — Command Injection in on-premises deployments

Critical

[CVE-TBD]

PTC Windchill — Unsafe Deserialization leading to Remote Code Execution

Critical

[CVE-TBD]

vBulletin Forum Software — Pre-Authentication Remote Code Execution via PHP eval()

Critical

■ THREAT ACTORS

ShinyHunters

Extortion Group

Claimed responsibility for an Ernst & Young data breach via supply-chain credentials; leaked data is being actively exploited by secondary sextortion scammers.

Anubis

Ransomware Group

Claimed credit for a ransomware attack and data theft targeting Coca-Cola's dairy subsidiary, Fairlife.

Dysphoria

IoT Botnet

Compromised 200,000 devices globally for DDoS and traffic relay, adopting blockchain-based name services and victim relays.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Active exploitation of zero-days in FastJson, Arista VeloCloud Orchestrator, and PTC Windchill.
T1566
Phishing | Targeted Telegram phishing against Belarusian activists and Microsoft Teams-themed lures in Operation BlueDash.
T1068
Exploitation for Privilege Escalation | Use of the "Certighost" PoC to compromise Windows AD CS and hijack domains.
T1584.005
Compromise Infrastructure: Botnet | Dysphoria botnet compromising 200,000 IoT devices.
T1071.004
Application Layer Protocol: DNS | Dysphoria botnet utilizing blockchain-based name services for resilient C2.
T1036
Masquerading | Fake Sparrow Wallet app on Apple App Store; fake Microsoft Teams updates.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Arista VeloCloud Orchestrator — Actively exploited command injection zero-day — [BC] Arista patches VeloCloud Orchestrator zero-day exploited in attacks

[P1 PATCH NOW]≤24h

FastJson Java Library — Actively exploited unauthenticated RCE zero-day — [BC] Hackers target US firms in FastJson RCE zero-day attacks

[P1 PATCH NOW]≤24h

PTC Windchill — Unsafe deserialization vulnerability actively exploited in ransomware campaign — [SW] PTC Windchill Vulnerability Exploited in Ransomware Campaign

[P1 PATCH NOW]≤24h

vBulletin Forum Software — Public pre-auth RCE exploit released — [THN] Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

■ RECOMMENDED ACTIONS TODAY

1[P1] Apply the emergency patch released by Arista for on-premises VeloCloud Orchestrator to mitigate the actively exploited command injection zero-day ([CVE-TBD]).
2[P1] Identify and update all instances of the FastJson Java library to the latest secure version to block active unauthenticated remote code execution zero-day attacks ([CVE-TBD]).
3[P1] Immediately patch PTC Windchill deployments to remediate the unsafe deserialization vulnerability ([CVE-TBD]) currently being exploited in active ransomware campaigns.
4[P2] Apply the security update released by n8n for the high-severity expression-sandbox escape ([CVE-TBD]) to prevent authenticated workflow editors from executing arbitrary OS commands.
5[P2] Disable public access to the "/actuator/heapdump" endpoint in all Spring Boot applications to prevent unauthorized exposure of sensitive memory data.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 29 Jul | AI Models Exploit Artifactory Zero-Days to Escape Older → [SecurityIntel] 27 Jul | Active scans target ESAFENET CDG weak logins
Powered by Buttondown, the easiest way to start and grow your newsletter.