SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefTuesday, July 28, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Active Zero-Day Exploitation of FastJson and Arista | CRITICAL |
|
5 C2 IPs | 43 OTX IOCs | 40 ARTICLES |
|
■ ANALYST TLDR Active zero-day exploitation of unauthenticated remote code execution vulnerabilities in the FastJson Java library and command injection flaws in Arista VeloCloud Orchestrator present immediate perimeter threats to enterprises. Concurrently, attackers are exploiting an unsafe deserialization flaw in PTC Windchill to deploy ransomware, while the Dysphoria IoT botnet has expanded to 200,000 devices using blockchain-based C2. Security teams must also monitor the emergence of autonomous AI agents being utilized in cyber-espionage campaigns and secure shadow AI deployments. |
|
■ CRITICAL STORIES Hackers target US firms in FastJson RCE zero-day attacks A zero-day vulnerability in the widely used open-source FastJson Java library allows unauthenticated remote code execution without user interaction, posing an immediate threat of full system compromise to exposed enterprise applications. |
Arista patches VeloCloud Orchestrator zero-day exploited in attacks Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in the wild to compromise software-defined WAN infrastructures. |
Hackers used autonomous AI agent to spy on Thailand's finance ministry Cyber-espionage actors have deployed an autonomous AI agent to conduct target surveillance and data gathering against Thailand's Ministry of Finance, demonstrating a practical escalation in AI-driven offensive capabilities. |
PTC Windchill Vulnerability Exploited in Ransomware Campaign Threat actors are actively exploiting an unauthenticated unsafe deserialization vulnerability in PTC Windchill PLM software to execute arbitrary code and deploy ransomware. |
|
■ CVEs IDENTIFIED [CVE-TBD] FastJson Java Library — Remote Code Execution via unauthenticated input |
[CVE-TBD] Arista VeloCloud Orchestrator — Command Injection in on-premises deployments |
[CVE-TBD] PTC Windchill — Unsafe Deserialization leading to Remote Code Execution |
[CVE-TBD] vBulletin Forum Software — Pre-Authentication Remote Code Execution via PHP eval() |
|
■ THREAT ACTORS ShinyHunters | Extortion Group |
Claimed responsibility for an Ernst & Young data breach via supply-chain credentials; leaked data is being actively exploited by secondary sextortion scammers. |
Claimed credit for a ransomware attack and data theft targeting Coca-Cola's dairy subsidiary, Fairlife. |
Compromised 200,000 devices globally for DDoS and traffic relay, adopting blockchain-based name services and victim relays. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Active exploitation of zero-days in FastJson, Arista VeloCloud Orchestrator, and PTC Windchill. |
| T1566 | | Phishing | Targeted Telegram phishing against Belarusian activists and Microsoft Teams-themed lures in Operation BlueDash. |
| T1068 | | Exploitation for Privilege Escalation | Use of the "Certighost" PoC to compromise Windows AD CS and hijack domains. |
| T1584.005 | | Compromise Infrastructure: Botnet | Dysphoria botnet compromising 200,000 IoT devices. |
| T1071.004 | | Application Layer Protocol: DNS | Dysphoria botnet utilizing blockchain-based name services for resilient C2. |
| T1036 | | Masquerading | Fake Sparrow Wallet app on Apple App Store; fake Microsoft Teams updates. |
|
■ PATCH PRIORITY Arista VeloCloud Orchestrator — Actively exploited command injection zero-day — [BC] Arista patches VeloCloud Orchestrator zero-day exploited in attacks |
FastJson Java Library — Actively exploited unauthenticated RCE zero-day — [BC] Hackers target US firms in FastJson RCE zero-day attacks |
PTC Windchill — Unsafe deserialization vulnerability actively exploited in ransomware campaign — [SW] PTC Windchill Vulnerability Exploited in Ransomware Campaign |
vBulletin Forum Software — Public pre-auth RCE exploit released — [THN] Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Apply the emergency patch released by Arista for on-premises VeloCloud Orchestrator to mitigate the actively exploited command injection zero-day ([CVE-TBD]). |
| 2 | [P1] Identify and update all instances of the FastJson Java library to the latest secure version to block active unauthenticated remote code execution zero-day attacks ([CVE-TBD]). |
| 3 | [P1] Immediately patch PTC Windchill deployments to remediate the unsafe deserialization vulnerability ([CVE-TBD]) currently being exploited in active ransomware campaigns. |
| 4 | [P2] Apply the security update released by n8n for the high-severity expression-sandbox escape ([CVE-TBD]) to prevent authenticated workflow editors from executing arbitrary OS commands. |
| 5 | [P2] Disable public access to the "/actuator/heapdump" endpoint in all Spring Boot applications to prevent unauthorized exposure of sensitive memory data. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |