Hackers Target US Firms in FastJson RCE Zero-Day Attacks
Attackers are actively exploiting a critical remote code execution flaw in the open-source FastJson Java library, a widely used component in Alibaba-linked enterprise software, without needing user interaction or elevated privileges. Tracked as CVE-2026-16723, the bug affects versions 1.2.68 through 1.2.83 under common Spring Boot fat-JAR deployments and stems from type-resolution logic that allows malicious classes to load before AutoType restrictions kick in. Attacks are currently concentrated on organizations in financial services, healthcare, computing, and retail across the US, with some spillover into Singapore and Canada. Since FastJson 1.x is no longer actively maintained, no patch is expected, leaving affected users to enable SafeMode or migrate to a non-vulnerable build as their only real options.
FBI: Breaking Affiliate Trust Sped Along LockBit’s Takedown
An FBI cyber division official is offering new detail on why Operation Cronos succeeded in dismantling LockBit, once the most prolific ransomware-as-a-service operation, responsible for a quarter of all ransomware attacks and more than 2,500 victims across 120 countries. Rather than relying purely on technical takedowns, investigators focused on eroding the trust between the group’s operators and its roughly 200 affiliates, using the seized leak site to publicly “out” affiliates and expose broken promises about deleted victim data and working decryptors. Officials say that centralized infrastructure, while efficient for running a criminal enterprise, was equally efficient to target, and that treating an affiliate network’s reputation as an operational asset worth attacking has become a broader lesson for future takedowns. More than two years later, ransom payments tied to the group have fallen roughly 79% in the US, even as some remnants of the brand persist.
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
A newly published proof-of-concept shows how an unauthenticated attacker can reach PHP’s eval() function inside vBulletin forum software and execute arbitrary code without any account or user interaction. The flaw, CVE-2026-61511, lives in the template engine’s handling of inline math expressions, where a visitor-supplied value in the public pagenav route gets passed to eval() after only partial filtering, an approach the researcher’s advisory nicknames “phpfuck” for its use of digits and operators to rebuild function calls without letters. vBulletin actually patched the underlying bug nearly four weeks before the exploit went public, shipping fixed builds in late June and July 1, so the real risk falls on self-hosted, internet-facing forums that haven’t updated, while vBulletin’s own Cloud installations are already protected. No in-the-wild exploitation has been confirmed so far, and the flaw isn’t yet in CISA’s Known Exploited Vulnerabilities catalog.
DentaQuest Data Breach Potentially Impacts Over 23 Million People
Dental and vision benefits administrator DentaQuest is notifying millions of people that hackers accessed its network for several days in May and made off with sensitive personal and health information, including Social Security numbers, Medicaid and Medicare numbers, and treatment and billing details. The extortion group ShinyHunters has claimed responsibility and leaked roughly 234 GB of stolen data, which reportedly also included email addresses, phone numbers, and government-issued IDs. Based on state attorney general filings, DentaQuest is sending written notices to at least 4.5 million people, while outside reporting puts the confirmed impacted total north of 15 million and potential exposure as high as 23.4 million. The company, a Sun Life subsidiary serving 35 million people nationwide, is offering affected individuals two years of free credit monitoring and identity theft restoration.
Australian Energy Giant Origin Confirms Data Breach Exposes Customer Data
Origin Energy, one of Australia’s largest energy providers, has confirmed that threat actors gained unauthorized access to and exfiltrated portions of its customer database after first detecting the incident on July 22. Compromised information includes names, addresses, dates of birth, phone numbers, account details, and partial financial data such as the last four digits of credit card numbers, though the company says this fragmented payment data can’t be used directly for fraud. Origin’s CEO has publicly apologized and the company has looped in the Australian Cyber Security Centre, the Australian Federal Police, and outside cybersecurity specialists to investigate what looks like a fairly deep intrusion. The incident adds to a string of recent breaches at critical infrastructure and utility operators, sectors that remain attractive targets given the volume of customer data and operational stakes involved.