[SecurityIntel] 28 Jul | Active Zero-Day Exploitation of FastJson and Arista
SECURITYINTEL DAILY BRIEF ■ Threat Intel Brief Tuesday, July 28, 2026 INTEL CONFIDENCE 100% THREAT LEVEL CRITICAL THREAT OF THE DAY Active Zero-Day Exploitation of FastJson and Arista CRITICAL 5 C2 IPs 43 OTX IOCs 40 ARTICLES ■ ANALYST TLDR Active zero-day exploitation of unauthenticated remote code execution vulnerabilities in the FastJson Java library and command injection flaws in Arista VeloCloud Orchestrator present immediate perimeter threats to enterprises. Concurrently, attackers are exploiting an unsafe deserialization flaw in PTC Windchill to deploy ransomware, while the Dysphoria IoT botnet has expanded to 200,000 devices using blockchain-based C2. Security teams must also monitor the emergence of autonomous AI agents being utilized in cyber-espionage campaigns and secure shadow AI deployments. ■ CRITICAL STORIES CRITICAL #1 Hackers target US firms in FastJson RCE zero-day attacks A zero-day vulnerability in the widely used open-source FastJson Java library allows unauthenticated remote code execution without user interaction, posing an immediate threat of full system compromise to exposed enterprise applications. CRITICAL #2 Arista patches VeloCloud Orchestrator zero-day exploited in attacks Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in the wild to compromise software-defined WAN infrastructures. HIGH #3 Hackers used autonomous AI agent to spy on Thailand's finance ministry Cyber-espionage actors have deployed an autonomous AI agent to conduct target surveillance and data gathering against Thailand's Ministry of Finance, demonstrating a practical escalation in AI-driven offensive capabilities. HIGH #4 PTC Windchill Vulnerability Exploited in Ransomware Campaign Threat actors are actively exploiting an unauthenticated unsafe deserialization vulnerability in PTC Windchill PLM software to execute arbitrary code and deploy ransomware. ■ CVEs IDENTIFIED [CVE-TBD] FastJson Java Library — Remote Code Execution via unauthenticated input Critical [CVE-TBD] Arista VeloCloud Orchestrator — Command Injection in on-premises deployments Critical [CVE-TBD] PTC Windchill — Unsafe Deserialization leading to Remote Code Execution Critical [CVE-TBD] vBulletin Forum Software — Pre-Authentication Remote Code Execution via PHP eval() Critical ■ THREAT ACTORS ShinyHunters Extortion Group Claimed responsibility for an Ernst & Young data breach via supply-chain credentials; leaked data is being actively exploited by secondary sextortion scammers. Anubis Ransomware Group Claimed credit for a ransomware attack and data theft targeting Coca-Cola's dairy subsidiary, Fairlife. Dysphoria IoT Botnet Compromised 200,000 devices globally for DDoS and traffic relay, adopting blockchain-based name services and victim relays. ■ ATT&CK TTPs T1190 Exploit Public-Facing Application | Active exploitation of zero-days in FastJson, Arista VeloCloud Orchestrator, and PTC Windchill. T1566 Phishing | Targeted Telegram phishing against Belarusian activists and Microsoft Teams-themed lures in Operation BlueDash. T1068 Exploitation for Privilege Escalation | Use of the "Certighost" PoC to compromise Windows AD CS and hijack domains. T1584.005 Compromise Infrastructure: Botnet | Dysphoria botnet compromising 200,000 IoT devices. T1071.004 Application Layer Protocol: DNS | Dysphoria botnet utilizing blockchain-based name services for resilient C2. T1036 Masquerading | Fake Sparrow Wallet app on Apple App Store; fake Microsoft Teams updates. ■ PATCH PRIORITY [P1 PATCH NOW] ≤24h Arista VeloCloud Orchestrator — Actively exploited command injection zero-day — [BC] Arista patches VeloCloud Orchestrator zero-day exploited in attacks [P1 PATCH NOW] ≤24h FastJson Java Library — Actively exploited unauthenticated RCE zero-day — [BC] Hackers target US firms in FastJson RCE zero-day attacks [P1 PATCH NOW] ≤24h PTC Windchill — Unsafe deserialization vulnerability actively exploited in ransomware campaign — [SW] PTC Windchill Vulnerability Exploited in Ransomware Campaign [P1 PATCH NOW] ≤24h vBulletin Forum Software — Public pre-auth RCE exploit released — [THN] Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw ■ RECOMMENDED ACTIONS TODAY 1 [P1] Apply the emergency patch released by Arista for on-premises VeloCloud Orchestrator to mitigate the actively exploited command injection zero-day ([ CVE-TBD ]). 2 [P1] Identify and update all instances of the FastJson Java library to the latest secure version to block active unauthenticated remote code execution zero-day attacks ([ CVE-TBD ]). 3 [P1] Immediately patch PTC Windchill deployments to remediate the unsafe deserialization vulnerability ([ CVE-TBD ]) currently being exploited in active ransomware campaigns. 4 [P2] Apply the security update released by n8n for the high-severity expression-sandbox escape ([ CVE-TBD ]) to prevent authenticated workflow editors from executing arbitrary OS commands. 5 [P2] Disable public access to the "/actuator/heapdump" endpoint in all Spring Boot applications to prevent unauthorized exposure of sensitive memory data. LIVE IOC FEED C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 PORT 8080 STATUS OFFLINE MALWARE Emotet COUNTRY US IP ADDRESS 50.16.16.211 PORT 443 STATUS ONLINE MALWARE QakBot COUNTRY US IP ADDRESS 34.204.119.63 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY US IP ADDRESS 178.62.3.223 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY GB IP ADDRESS 27.133.154.218 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY JP FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB
SECURITYINTEL DAILY BRIEF
Tuesday, July 28, 2026
INTEL CONFIDENCE 100%
Active Zero-Day Exploitation of FastJson and Arista
Active zero-day exploitation of unauthenticated remote code execution vulnerabilities in the FastJson Java library and command injection flaws in Arista VeloCloud Orchestrator present immediate perimeter threats to enterprises. Concurrently, attackers are exploiting an unsafe deserialization flaw in PTC Windchill to deploy ransomware, while the Dysphoria IoT botnet has expanded to 200,000 devices using blockchain-based C2. Security teams must also monitor the emergence of autonomous AI agents being utilized in cyber-espionage campaigns and secure shadow AI deployments.
Hackers target US firms in FastJson RCE zero-day attacks
A zero-day vulnerability in the widely used open-source FastJson Java library allows unauthenticated remote code execution without user interaction, posing an immediate threat of full system compromise to exposed enterprise applications.
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in the wild to compromise software-defined WAN infrastructures.
Hackers used autonomous AI agent to spy on Thailand's finance ministry
Cyber-espionage actors have deployed an autonomous AI agent to conduct target surveillance and data gathering against Thailand's Ministry of Finance, demonstrating a practical escalation in AI-driven offensive capabilities.
PTC Windchill Vulnerability Exploited in Ransomware Campaign
Threat actors are actively exploiting an unauthenticated unsafe deserialization vulnerability in PTC Windchill PLM software to execute arbitrary code and deploy ransomware.
FastJson Java Library — Remote Code Execution via unauthenticated input
Arista VeloCloud Orchestrator — Command Injection in on-premises deployments
PTC Windchill — Unsafe Deserialization leading to Remote Code Execution
vBulletin Forum Software — Pre-Authentication Remote Code Execution via PHP eval()
Claimed responsibility for an Ernst & Young data breach via supply-chain credentials; leaked data is being actively exploited by secondary sextortion scammers.
Claimed credit for a ransomware attack and data theft targeting Coca-Cola's dairy subsidiary, Fairlife.
Compromised 200,000 devices globally for DDoS and traffic relay, adopting blockchain-based name services and victim relays.
Arista VeloCloud Orchestrator — Actively exploited command injection zero-day — [BC] Arista patches VeloCloud Orchestrator zero-day exploited in attacks
FastJson Java Library — Actively exploited unauthenticated RCE zero-day — [BC] Hackers target US firms in FastJson RCE zero-day attacks
PTC Windchill — Unsafe deserialization vulnerability actively exploited in ransomware campaign — [SW] PTC Windchill Vulnerability Exploited in Ransomware Campaign
vBulletin Forum Software — Public pre-auth RCE exploit released — [THN] Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
■ RECOMMENDED ACTIONS TODAY
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5
FULL IOC EXPORT — GOOGLE SHEET
All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
