Daily cybersecurity briefing

Top 10 Cybersecurity Stories for July 27, 2026

Immediate priority must be given to the unpatched Fastjson RCE and active ServiceNow exploits, both of which provide high-impact entry points for attackers. We are also seeing a trend in sophisticated evasion techniques, including browser-based malware assembly and BYOVD crypters, alongside continued supply chain risks that GitHub is attempting to mitigate via Dependabot cooldowns.

Compiled by the Slugnet Editorial System. Published Jul 27, 2026, 8:01 AM EDT

This legacy edition is awaiting expanded Slugnet analysis and is not yet indexed.

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

The audio edition is not available yet.

  1. 01
    The Hacker News

    Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

    What happened

    Attackers are actively exploiting a critical unauthenticated remote code execution vulnerability (CVE-2026-16723) in Alibaba's Fastjson 1.x Java library. The flaw allows malicious JSON requests to execute code with the privileges of the Java process, and no patch is currently available.

    This legacy edition predates Slugnet’s expanded analytical assessment.

    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
  3. 03
    The Hacker News

    Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

    What happened

    A China-linked threat group is using the Cruciferra crypter service to deliver remote access trojans via income tax-themed phishing lures. The malware employs Bring Your Own Vulnerable Driver (BYOVD) and process ghosting techniques to evade detection on Windows systems.

    This legacy edition predates Slugnet’s expanded analytical assessment.

    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
  5. 05
  6. 06
    The Hacker News

    Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

    What happened

    The SourTrade malvertising campaign uses malicious JavaScript to instruct browsers to assemble Windows executables directly in memory using a legitimate Bun runtime. This technique bypasses traditional file-based detection by avoiding the delivery of a complete malicious binary.

    This legacy edition predates Slugnet’s expanded analytical assessment.

    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
  8. 08
  9. 09
  10. 10