Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
2026-07-27T01:23:59Z•6c0083e12be6a48300e79ee078a4750d73a60bedcc7fb0606e46f66dd1a7737b
CVE-2026-16723CVE-2026-32194CVE-2026-64600AI securityActive DirectoryBingChina-nexusFastjsonGitLabJavaLinuxNodeBBPTC WindchillRedisRussia-alignedWindowsZimbraactive exploitationcredential theftidentity compromisemalvertisingphishingprivilege escalationransomwareremote code executionsandbox escapestate-sponsoredzero-day
What happened
The feed highlights active exploitation and disclosure of critical vulnerabilities, ransomware and malware campaigns, phishing operations, AI-agent security flaws, and targeted state-sponsored activity. Highest-impact items include unauthenticated RCE in Fastjson and PTC Windchill/FlexPLM, Bing server command execution as SYSTEM/root, AD domain-controller impersonation, Redis authenticated RCE, Linux local privilege escalation, and espionage exploiting a Zimbra zero-day. Multiple reports include public exploit code or confirmed exploitation, creating elevated patching and threat-hunting risk.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 6c0083e12be6a48300e79ee078a4750d73a60bedcc7fb0606e46f66dd1a7737b
- Enrichment time
- 2026-07-27T01:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.