Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
2026-07-26T19:24:12Z•eb43a40e5ad27f24e4fce3d22b721c9d402b0a5900d00a8b661703e115ff0f4f
CVE-2026-16723CVE-2026-32194CVE-2026-64600active-directoryai-agent-exploitcloud-exposuredata-exfiltrationmalvertisingphishingprivilege-escalationransomwareransomware-as-a-servicercesupply-chainzero-day
What happened
A collection of high-impact security reports: an ongoing malvertising campaign (SourTrade) assembles Windows executables in-browser; Fastjson 1.x RCE (CVE-2026-16723) is being actively exploited against Spring Boot apps; working GitLab and Redis RCE proofs-of-concept and other zero-days were published; Cl0p affiliates and other ransomware groups (Chaos, DevMan RaaS) are exploiting internet-exposed enterprise software and centralizing payload builds; AI/agent platforms (OpenAI ChatGPT Workspace AgentForger, Anthropic Claude Cowork) and image-processing (Bing SVG, CVE-2026-32194) reveal sandbox/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- eb43a40e5ad27f24e4fce3d22b721c9d402b0a5900d00a8b661703e115ff0f4f
- Enrichment time
- 2026-07-26T19:24:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.