Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

2026-07-26T19:24:12Zeb43a40e5ad27f24e4fce3d22b721c9d402b0a5900d00a8b661703e115ff0f4f
CVE-2026-16723CVE-2026-32194CVE-2026-64600active-directoryai-agent-exploitcloud-exposuredata-exfiltrationmalvertisingphishingprivilege-escalationransomwareransomware-as-a-servicercesupply-chainzero-day

What happened

A collection of high-impact security reports: an ongoing malvertising campaign (SourTrade) assembles Windows executables in-browser; Fastjson 1.x RCE (CVE-2026-16723) is being actively exploited against Spring Boot apps; working GitLab and Redis RCE proofs-of-concept and other zero-days were published; Cl0p affiliates and other ransomware groups (Chaos, DevMan RaaS) are exploiting internet-exposed enterprise software and centralizing payload builds; AI/agent platforms (OpenAI ChatGPT Workspace AgentForger, Anthropic Claude Cowork) and image-processing (Bing SVG, CVE-2026-32194) reveal sandbox/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
eb43a40e5ad27f24e4fce3d22b721c9d402b0a5900d00a8b661703e115ff0f4f
Enrichment time
2026-07-26T19:24:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.