🚨 ACTIVE EXPLOITATION
- Critical Fastjson 1.x RCE Vulnerability CVE-2026-16723 Exploited in the Wild — The Hacker News
Attackers are exploiting a critical remote code execution flaw in Fastjson 1.x with no patch available.- Applies to Fastjson versions 1.2.68 through 1.2.83 used in Spring Boot fat-JAR applications
- Vulnerability allows unauthenticated remote code execution via malicious JSON requests with Java process privileges
- Exploit leverages attacker-controlled @type values and nested JAR paths in fat-JAR loaders without requiring AutoType or classpath gadgets
- Observed exploitation activity targets sectors including financial services, healthcare, retail, mainly in the US, Singapore, and Canada
- No official patch released as of July 25, 2026; mitigations include enabling SafeMode or migrating to Fastjson2
🕵️ RESEARCH & DEEP DIVES
- ShinyHunters data leaks exploited in $2,000 sextortion email scam — BleepingComputer
Threat actors use ShinyHunters leaked emails to send sextortion scams demanding $2,000.- Targets include email addresses from breaches of Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill
- Emails claim device compromise and access to personal data to coerce $2,000 Bitcoin payments
- Scam uses leaked breach data to appear credible but no actual device compromise or malware infection detected
- Emails impersonate ShinyHunters group but the extortion gang denies involvement
- Campaign started in April 2026 and uses threats of exposing intimate videos to extort victims