LogoLogo

Podcasts

Newsletters

Videos

Catalog

People

About

Search

Risky Bulletin Newsletter

July 27, 2026

Risky Bulletin: A JSON RCE bug is about to rock the Java world

Written by

Catalin Cimpanu
Catalin Cimpanu

News Editor

This newsletter is brought to you by application allow-listing software maker Airlock Digital. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.

Threat actors are exploiting a vulnerability in Alibaba's Fastjson, one of the Java ecosystem's most popular libraries for working with JSON-formatted data.

Active exploitation began last week, a day after details about the security flaw were revealed by cybersecurity firm FearsOff.

The attacks, first spotted and documented by Imperva and ThreatBook, target CVE-2026-16723, a vulnerability that can enable unauthenticated remote code execution attacks against Java projects that use the Fastjson library as a component.

The vulnerability works in the library's default configuration and in its most common deployment model, as a Spring Boot executable component.

The only positive news is that the bug only impacts only the older 1.x branch and not the current 2.x releases.

Despite the public disclosure, Alibaba has not released a patch and urged developers to either turn the library's SafeMode on or move to the newer 2.x branch.

Fastjson 1.2.83, the last version of the 1.x branch, was released in May 2022. It might be an old release, but if I know my Java world, this is still probably in every bank and government network you know.

Imperva says it detected exploits targeting its customers across several industry verticals, such as finances, healthcare, computing, and retail. Most of the attacks targeted US orgs.

Risky Business Podcasts

The main Risky Business podcast is now on YouTube with video versions of our recent episodes. Below is our latest weekly show with Pat, James, and special guest co-host Chris Krebs at the helm!


Breaches, hacks, and security incidents

RubyGems leak: The RubyGems package repository has patched a CDN caching bug that exposed a user's API key to other users signing in. RubyGems believes 18% of logins were affected by the leak. The team also reviewed logs and found no sign of API keys being used maliciously. [RubyGems]

OpenAI didn't notice it hacked Hugging Face for days: AI company OpenAI didn't notice for almost a week that two of its cyber models hacked AI platform Hugging Face. The company's models spent a full two days inside Hugging Face's servers before being evicted on July 13. OpenAI engineers didn't notice that their models had escaped containment until July 16 when Hugging Face published a blog post about the hack, blaming it on an autonomous AI system. [Reuters]

Hugging Face hack: Hacktron's Mohan Pedhapati tried to reconstruct how OpenAI's models hacked AI platform Hugging Face. It's one of the multiple theories going around. Another major one is that OpenAI's models exploited some sort of Redis bug. [Hacktron]

AI, general tech, and privacy

Kimi lags behind Western cyber models: Moonshot's Kimi K3 AI model performs significantly below the cyber capabilities of AI models released by US frontier labs. According to a joint evaluation by UK and US cyber institutes, Kimi K3 is China's most advanced model in terms of cyber capabilities, but has yet to catch up with US alternatives. Tests also showed that Kimi guardrails failed to prevent Kimi users from developing exploits. [UK AISI]

Dependabot gets a cooldown: GitHub has added a three-day cooldown for its Dependabot service. Dependabot will now wait three days before opening a pull request and prompting developers to install dependency updates. The delay is meant to allow security tools time to detect malicious packages. The cooldown will not apply to security updates and Dependabot will continue to open pull requests as soon as a security fix is released in a dependency. [GitHub]

Signal disappearing messages now cover calls too: The Signal disappearing messages feature will now delete data about taken or missed calls. Previously the feature only covered text messages and media exchanged by two users or a group. [Signal]

This is a very significant/helpful tool for journalist-source opsec.

[image or embed]

— Kevin Collier (@kevincollier.bsky.social) July 25, 2026 at 2:30 AM

Tracking in the banking sector: A Jscrambler report found that banks and financial institutions in the EU and USroutinely send sensitive customer data to third-party advertising and analytics platforms, sometimes before users can refuse cookies or tracking, and sometimes after, despite a rejection. [Jscrambler]

Facebook to tiktokify itself: Meta plans to turn Facebook's main timeline into a fullscreen video experience, a-la TikTok, later this year. [Meta // Neowin]

EU says TikTok broke child protection rules: A preliminary EU investigation has found that TikTok likely broke child protection and safety rules mandated through the EU DSA, which opens the door for a formal investigation and a likely ginormous fine for the platform. [EU]

Social media networks are hiding their data: Despite obligations to provide their data to researchers and academics under the EU DSA, social media networks are blatantly refusing to share their data with anyone, hindering efforts to study political influence campaigns, scams, and dis/misinformation. [WIRED]

2️⃣ Platforms like #TikTok, X, and #Meta use strict quotas, high fees, and onerous security demands to stall requests. In Romania and Germany, scholars were forced into legal battles or denied data altogether while covert bot networks manipulated voters. 📊

— Daboo 🧐 (@daboo23.eurosky.social) July 25, 2026 at 5:12 PM

Government, politics, and policy

AI Kill Switch Act: US lawmakers have proposed a bill that would force AI companies to build killswitches to shut down or throttle powerful AI models. The AI Kill Switch Act would also require companies to report security incidents to authorities. The bill was proposed a week after OpenAI admitted to losing control of two models that ended up hacking AI platform Hugging Face. [Rep. Ted Lieu // Politico]

FedRAMP boss wants to ban slow vendors: Software vendors who are slow to patch dangerous bugs should expect to lose US government work. Companies should patch bugs within days of a notice. FedRAMP Director Pete Waterman says vendors who can't react in time should get out of the federal marketplace. [NextGov]

South Korea changes diplomat emails after hack: The South Korean government will change the emails of all diplomatic officials after a hack of its diplomat training system. The Ministry of Foreign Affairs is concerned the leaked addresses could be used for spear-phishing and the targeting of certain diplomats. Unidentified hackers breached the Korean National Diplomatic Academy between April 2025 and February this year. [The Strait Times]

Global Public Security Cooperation Forum: China expects more than 40 countries to participate in the Global Public Security Cooperation Forum, an international alliance to fight against online and telecom fraud. [China Daily]

ACSC's AI guide: Australia's cybersecurity agency has published a guide on the proper adoption of AI toolkits for cyber defense tasks. The guide calls human oversight of any AI tools as "essential." [ACSC]

TikTok is "legal" again: After a group of US investors bought TikTok's US operations, the DOJ said federal employees can download the app on government devices again. [Reuters]

Sponsor section

In this Risky Business sponsor interview, James Wilson chats with Airlock Digital co-founders David Cottingham and Daniel Schell about how attackers are using LLMs to enumerate EDR detections.

LLMs dramatically reduce the time and specialist labour needed to extract rulesets out of EDR products. What once might have taken months of manual reversing can now be accelerated by “burning tokens”. The takeaway is that defenders increasingly need to assume attackers have visibility into how their endpoint security products work.

Arrests, cybercrime, and threat intel

US charges gift card fraudster: The US has indicted a Chinese national for his role in an international gift card fraud conspiracy. Jinbin Ren received gift cards stolen from victims through romance fraud, elder fraud, hacking, theft, and other scams. He allegedly used the cards to purchase high-value electronics and then reshipped them to China, where they'd be resold for a profit. Ren ran a warehouse in Salem, New Hampshire, and coordinated with other group members in a WeChat group. [DOJ]

US tries to prosecute protester who used a duress password: The US Justice Department is prosecuting a man who used a so-called "duress password." Samuel Tunick allegedly provided the US Customs and Border Protection a password that wiped his smartphone. The phone was running GrapheneOS, which includes such a security feature. Tunick protested against building the Cop City campus in Atlanta. He had his device seized by border agents last year when he returned to the US from a travel trip. [The Guardian]

Smisher detained in Rotterdam: Dutch authorities have arrested a 22-year-old man from Rotterdam for a massive smishing campaign that impersonated government entities. [Dutch Police]

Scam compounds expand in Myanmar: Cyber scam compounds in Myanmar have expanded despite a highly public purported government crackdown. Criminal groups have built smaller compounds in the jungle, away from large population centres and moved away from running large multi-building complexes. The ruling military made a show last year of blowing up buildings from the country's largest scam compound, KK Park. [ABC // WIRED]

SourTrade assembles malware in a victim's browser: A novel malvertising operation is using clean websites that load multiple pieces of benign-looking JavaScript code that assemble and run malware inside a user's browser. The malicious code runs in-memory and is designed to work as an infostealer. According to security firm Confiant, the novel technique defeats file fingerprinting as security tools only see the clean JavaScript files but not their output. [Confiant]

ClickFix on Steam: Threat actors are sharing ClickFix-like malicious instructions on Steam forum topics asking for technical assistance. In observed cases, users were tricked into running malicious PowerShell commands that installed cryptominers. [BleepingComputer]

Hotel WiFi attacks: Hackers are breaching WiFi gateways at hotels to intercept DNS traffic and redirect victims to Microsoft 365 phishing sites. Since June, security firm ReliaQuest has discovered compromised WiFi systems at hotels in multiple US cities and across India and Saudi Arabia. Researchers believe the campaign might be the work of Russian state hackers. Earlier this year, the US disrupted a Russian botnet made up of hacked routers that also hijacked traffic for M365 login pages. [ReliaQuest]

Proxy ecosystem expands: Despite recent law enforcement takedowns, malicious residential proxy botnets are expanding and growing. According to Lumen, almost 20 million IP addresses are now part of 30 residential proxy botnets. Almost half of the botnets are of Chinese origin. Many botnets are also renting each others' infected bots in an attempt to look bigger than they are. [Lumen Black Lotus Labs]

Malware technical reports

The Gentlemen RaaS: Threat intel researchers look at how offshoots from two RaaS operations, ArmCorp and Qilin, have built and grown The Gentleman ransomware operation into the second most prolific RaaS platform on the market today. Researchers believe the gang's leader, a hacker going by Zeta88, is based in Izhevsk, in the Udmurt Republic of Russia. His possible real name might be Alexandr Yapaev. [Ctrl-Alt-Intel]

The INC RaaS: Threat intel analyst Rakesh Krishnan has uncovered the real IP address of the INC ransomware's backend systems, but unfortunately it's hosted in Russia, meaning to takedown anytime soon. [The Raven File]

Sponsor section

In this product demo of the Airlock Digital application control and allowlisting solution, Patrick Gray speaks with Airlock Digital co-founders David Cottingham and Daniel Schell.

APTs, cyber-espionage, and info-ops

Telegram spear-phishing targeting dissidents: A Telegram spear-phishing campaign is targeting exiled activists and dissidents in Belarus, Russia, and Kazakhstan. The campaign attempted to trick targets into handing over Telegram one-time passcodes so the attackers could log into their accounts. Attacks have been traced back to at least 2024. Researchers at RESIDENT.NGO have not attributed the campaign to any threat actor. [RESIDENT.NGO // RESIDENT.NGO]

DPRK's ClickFix campaigns: In a report last week, SOCRadar researchers spotted North Korean hackers using ClickFix techniques for their fake job interview lures. Jumpsec now takes a more in-depth look at how ClickFix fits into the broader social engineering steps the hackers use. [Jumpsec]

APT-C-00: Vietnam's OceanLotus espionage group, aka APT32 or APT-C-00, is still active in China, carrying out campaigns involving IMG disc files delivered via email, like it's 2005. [Qihoo 360]

Google has a new APT naming scheme: Google is rolling out a new naming scheme for threat actors. The new scheme will merge the naming schemes of Google's own Threat Analysis Group with Mandiant, which Google acquired in 2022. Chinese groups will be tracked under the codename of Castle, Iranians as Ion, North Korea as Neptune, and Russia as Relic. E-crime groups will be tracked as Comet, while uncategorized groups will continue to be tracked as UNC. [Google]

RELIC for Russia is iconic

— Dell R. "Dell" Adams (@dell-adams.bsky.social) July 25, 2026 at 3:41 AM

Vulnerabilities, security research, and bug bounty

Security updates: Atlassian, Chrome, Ericsson, HP, HPE, MongoDB, Moodle, Progress, Ubuntu.

Bug lets attackers replace app executables on macOS: A vulnerability in macOS allows attackers to silently replace an app's executable with a malicious version. The vulnerability only impacts apps downloaded from the internet. Exploiting the bug requires archiving and restoring the target app. No elevated privileges are required. Apple did not patch the bug because it did not consider it a security issue. [Mysk]

ERPNext RCE: Researchers have found a stored XSS bug in the ERPNext open-source enterprise resource planning platform that could be exploited for remote attacks. It  is one of four issues they discovered in the platform. [Armadin]

XCharge EV charging stations can be hacked via the charging port: A vulnerability in XCharge EV charging stations can allow hackers to take over the devices. According to security firm Sailflow, the charging stations are exposing a misconfigured SSH service on the connector when a car is plugged in. The SSH server uses a default username and password of root/root. Attackers can exploit the bug for free recharges, physical damage, or move inside the provider's network. [Sailflow // CVE-2026-9039]

Certighost vulnerability: Security researchers Muhammad Ali and Aniq Fakhrul have published a technical write-up of Certighost, or CVE-2026-54121, a Windows bug that they found and reported to Microsoft. The bug lets low-privilege AD users impersonate the Domain Controller and access other resources on the network. This was patched in this month's Patch Tuesday. [GitHub // CVE-2026-54121]

AgentForger vulnerability: A Cross-Site Request Forgery (CSRF) vulnerability in OpenAI's Workspace Agents can allow malicious actors to forge an entire (malicious) autonomous agent that lives and exfiltrates data from your organization. [Zenity]

Infosec industry

Threat/trend reports: Censys, Check Point, Group-IB, Health-ISAC, LevelBlue, Lumen, and Positive Technologies have recently published reports and summaries covering various threats and infosec industry trends.

via Censys

New tool—Project ORBITAL: Team Cymru researcher Will Thomas has released Project ORBITAL, a tool for r mapping, fingerprinting, and hunting China-nexus Operational Relay Box (ORB) networks and malicious edge-devices.

New tool—Mantis: Google has released Mantis, a modular, stack-agnostic toolkit of security review skills for AI coding agents to autonomously find, reproduce, and patch vulnerabilities. 

Risky Business podcasts

In this edition of Seriously Risky Business, Tom Uren and James Wilson talk about the future of open-weight models. For different reasons, both the Chinese and American governments have reasons to crack down on them.

Recent Newsletters

  • Risky Bulletin: A JSON RCE bug is about to rock the Java world
  • Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers
  • Srsly Risky Biz: Knives Are Out For Open-Weight AI Models
  • Risky Bulletin: Linux kernel discloses 442 CVEs as AI bugpocalypse settles in
  • Risky Bulletin: Hacker wipes Romania's entire land registry database

Recent Videos

  • Srsly Risky Biz: Knives are out for open-weight AI models
  • Risky Business (845): OpenAI's Skynet moment
  • Between Two Nerds: What China gets wrong about cyber war in Ukraine
  • Srsly Risky Biz: Ransomware uses AI to amp up negotiations
  • Between Two Nerds: Exploits are not cyber power

Recent Podcasts

  • Risky Bulletin: A JSON RCE bug is about to rock the Java world
  • Sponsored: How AI is putting pressure on EDR
  • Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers
  • Srsly Risky Biz: Knives are out for open-weight AI models
  • Risky Bulletin: Rogue OpenAI models were behind the Hugging Face breach
Risky Business Media

Risky Business

  • Home
  • Podcasts
  • Newsletters
  • Video
  • Sitemap

Risky Business Media

  • About
  • People
  • Advertising
  • Sponsor Enquiries: sales@risky.biz

Risky Connections

  • Risky Business on Apple Podcasts
  • Risky Business on Spotify
  • Risky Bulletin on Apple Podcasts
  • Risky Bulletin on Spotify
  • Risky Business Features on Apple Podcasts
  • Risky Business Features on Spotify
  • Risky Business Stories on Apple Podcasts
  • Risky Business Stories on Spotify
  • YouTube
  • LinkedIn

Risky Contacts

Risky Business Media Pty Ltd
PO Box 774
Byron Bay NSW 2481
General Email: editorial@risky.biz

© Risky Business Media 2007–2026. All rights reserved.
ABN 73 618 465 517