Daily cybersecurity briefing

Top 10 Cybersecurity Stories for July 26, 2026

Immediate priority must be given to patching Fastjson, ServiceNow, and PTC Windchill/FlexPLM due to confirmed active exploitation of unauthenticated RCEs. We are also seeing a shift toward AI-automated post-exploitation and sophisticated browser-based malware assembly that bypasses traditional file scanning. Ensure Active Directory auditing is tightened against the Certighost impersonation technique.

Compiled by the Slugnet Editorial System. Published Jul 26, 2026, 8:03 AM EDT Updated Jul 26, 2026, 10:11 AM EDT

This legacy edition is awaiting expanded Slugnet analysis and is not yet indexed.

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

The audio edition is not available yet.

  1. 01
    The Hacker News

    Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

    What happened

    Attackers are actively exploiting CVE-2026-16723, a critical unauthenticated remote code execution flaw in Alibaba's Fastjson library for Java. In affected Spring Boot applications, malicious JSON requests can execute code with the privileges of the Java process.

    This legacy edition predates Slugnet’s expanded analytical assessment.

    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    The Hacker News

    Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

    What happened

    Cl0p ransomware affiliates are exploiting a chain of vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments. The attack combines an information disclosure flaw in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet to achieve unauthenticated remote code execution.

    This legacy edition predates Slugnet’s expanded analytical assessment.

    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
  4. 04
    The Hacker News

    Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

    What happened

    The Certighost exploit allows low-privileged Active Directory users to obtain a certificate for a Domain Controller and authenticate as that machine. This enables attackers to retrieve the krbtgt secret through DCSync, leading to full domain compromise.

    This legacy edition predates Slugnet’s expanded analytical assessment.

    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    The Hacker News

    Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

    What happened

    Working exploit code has been released for a GitLab vulnerability that allows authenticated users to execute commands as the git user on unpatched self-managed 18.11.3 servers. The attack involves committing a crafted Jupyter notebook to leak heap memory.

    This legacy edition predates Slugnet’s expanded analytical assessment.

    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    BleepingComputer

    Hermes AI agent used to automate attack on Thai Finance Ministry

    What happened

    Threat actors utilized the open-source Hermes AI agent in unattended mode to automate post-exploitation activities during a breach of Thailand's Ministry of Finance. This demonstrates the operational use of AI agents to accelerate lateral movement and data collection.

    This legacy edition predates Slugnet’s expanded analytical assessment.

    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    The Hacker News

    Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

    What happened

    The SourTrade malvertising campaign uses a legitimate Bun runtime to instruct browsers to assemble Windows executables directly in memory. By avoiding the delivery of a complete malicious file from a single URL, the operation bypasses traditional file-based detection.

    This legacy edition predates Slugnet’s expanded analytical assessment.

    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
  9. 09
    The Hacker News

    DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

    What happened

    The DevMan ransomware-as-a-service operation uses a centralized web portal to manage affiliate payouts and automate payload generation. This infrastructure allows the group to scale its operations through a streamlined management interface.

    This legacy edition predates Slugnet’s expanded analytical assessment.

    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10