Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

2026-07-27T01:23:59Z6c0083e12be6a48300e79ee078a4750d73a60bedcc7fb0606e46f66dd1a7737b
CVE-2026-16723CVE-2026-32194CVE-2026-64600AI securityActive DirectoryBingChina-nexusFastjsonGitLabJavaLinuxNodeBBPTC WindchillRedisRussia-alignedWindowsZimbraactive exploitationcredential theftidentity compromisemalvertisingphishingprivilege escalationransomwareremote code executionsandbox escapestate-sponsoredzero-day

What happened

The feed highlights active exploitation and disclosure of critical vulnerabilities, ransomware and malware campaigns, phishing operations, AI-agent security flaws, and targeted state-sponsored activity. Highest-impact items include unauthenticated RCE in Fastjson and PTC Windchill/FlexPLM, Bing server command execution as SYSTEM/root, AD domain-controller impersonation, Redis authenticated RCE, Linux local privilege escalation, and espionage exploiting a Zimbra zero-day. Multiple reports include public exploit code or confirmed exploitation, creating elevated patching and threat-hunting risk.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
6c0083e12be6a48300e79ee078a4750d73a60bedcc7fb0606e46f66dd1a7737b
Enrichment time
2026-07-27T01:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.