Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
2026-07-22T07:24:17Z•b7aac276fb4dbd6bd773d8be4ff86373fcba33ac665009664a2cb0fcb77bad68
7-zipactive-exploitationai-agent-abusecalendar-c2github-malwarehoneypot/telemetry-evasionmodel-theftnugetpalo-alto-pan-osphishing-toolkitprompt-injectionransomwareremote-code-executionrubygemssandbox-escapeservicenowsharepointsnmp-command-injectionsupply-chainwordPress
What happened
This feed highlights a spike in high-impact supply-chain and AI-related attacks alongside multiple critical RCEs now being actively exploited. Notable items: a trojanized NuGet package (Newtonsoftt.Json.Net) and malicious RubyGems/GitHub repos (SleeperGem, FakeGit) delivering loaders; WordPress wp2shell (CVE-2026-63030, CVE-2026-60137) and SharePoint deserialization RCE (CVE-2026-50522) under active exploitation; ServiceNow sandbox escape (CVE-2026-6875) in the wild; a 7-Zip XZ extraction RCE (CVE-2026-14266); and a PAN-OS authentication bypass (CVE-2026-0257) used to plant Qilin ransomware. A
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- b7aac276fb4dbd6bd773d8be4ff86373fcba33ac665009664a2cb0fcb77bad68
- Enrichment time
- 2026-07-22T07:24:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.