Hackers target US firms in FastJson RCE zero-day attacks

2026-07-28T07:23:20Z5d8dbf99471801cfcab8587c1d24d1b25fe25447bef8fbfada680d7965e07309
AD-CSAI-assisted-operationsActive-DirectoryCertighostClickFixDDoSDysphoria-botnetFastJsonShinyHuntersVeloCloud-OrchestratorXMRigactive-exploitationcommand-injectioncryptominingdata-breachin-memory-malwaremalvertisingransomwareremote-code-executionsextortionshadow-AIsupply-chain-securityzero-day

What happened

BleepingComputer security news roundup covering active exploitation of FastJson and VeloCloud Orchestrator zero-days, a large Dysphoria DDoS botnet, Certighost Active Directory Certificate Services exploitation, ransomware and data breaches, supply-chain defenses, ClickFix cryptomining campaigns, browser-based malware delivery, sextortion, shadow AI risks, and AI-assisted cyber operations. No CVE identifiers are provided in the supplied content.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
5d8dbf99471801cfcab8587c1d24d1b25fe25447bef8fbfada680d7965e07309
Enrichment time
2026-07-28T07:23:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Hackers target US firms in FastJson RCE zero-day attacks · Baitaphish