Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Anthropic’s Dario Amodei responds: doesn’t oppose open-weight models, but fears Chinese AI

    July 28, 2026

    Adversaries Don’t Need a Zero-Day — They Read Your Rulebook

    July 28, 2026

    Coinbase’s Chief Policy Officers Praises Clarity Act Draft

    July 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Anthropic’s Dario Amodei responds: doesn’t oppose open-weight models, but fears Chinese AI
    • Adversaries Don’t Need a Zero-Day — They Read Your Rulebook
    • Coinbase’s Chief Policy Officers Praises Clarity Act Draft
    • NASA Astronaut Chris Williams to Discuss Space Station Mission
    • Pat Lowe spent decades describing and defending the Kimberley
    • No, Centrica, customers don’t prefer bots to humans | Centrica
    • US diplomats walk out as France addresses UN Security Council | Conflict News
    • New technical education routes to be offered at 14 in England
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, July 28
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers target US firms in FastJson RCE zero-day attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 28, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges.

    The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S.

    The malicious activity was observed last week by the agentic security company ThreatBook, and researchers at the business protection company Imperva confirmed that it was “targeting a wide range of organizations, across Financial Services, Healthcare, Computing, Retail, Business, and other industries.”

    image

    “Attacks are currently almost entirely targeting US-based organizations, with a few attacks in Singapore and Canada, although this will likely continue to expand globally,” Imperva says.

    Industries targeted
    Industries targeted
    Source: Imperva

    FastJson is an open-source Java library developed by Alibaba, used for serializing Java objects to JSON, and vice versa.

    The project has 25,600 stars and 6,400 forks on GitHub, and is especially prevalent in Chinese enterprise software and projects built on Alibaba’s platform.

    CVE-2026-16723 was discovered by FearsOff, an offensive security company, which published a technical write-up earlier this month.

    The researchers explain that the flaw stems from the library’s type-resolution logic, which performs attacker-controlled resource lookups before enforcing AutoType restrictions. This creates a path for executing code remotely in Spring Boot fat-JAR deployments.

    By abusing @type processing, the researchers were able to load and execute malicious classes without AutoType enabled or requiring third-party gadget chains.

    No fix available

    In its security bulletin, Alibaba confirmed the critical severity of the vulnerability and warned that it is exploitable on “the most common Spring Boot deployment model.”

    “The only deployment prerequisite is that the target runs as a Spring Boot executable fat-jar (i.e., launched via java -jar xxx.jar),” reads Alibaba’s security advisory.

    The vendor notes that specifying a target class during deserialization does not mitigate CVE-2026-16723, as attackers can embed malicious payloads within ‘Object’ or ‘Map’ fields.

    The vulnerable type-resolution logic is not present in fastjson2, which uses an allowlist-first model for polymorphic deserialization and doesn’t rely on the @JSONType annotation as a trust signal.

    Also, FastJson versions 1.2.60 and earlier, and any non-fat-JAR deployments, aren’t affected either.

    Developers using a version within the affected spectrum are urged to immediately enable SafeMode or switch to a non-impacted build.

    Currently, there’s no fix issued for CVE-2026-16723. Imperva has also noted that FastJson 1.x is no longer actively maintained, so it’s unlikely it will receive a security update.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    attacks Fastjson firms hackers RCE Target ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Adversaries Don’t Need a Zero-Day — They Read Your Rulebook

    What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out

    Confused Deputy Flaws Persist in Google Cloud, Microsoft Azure

    The containment paradox: Why your ransomware playbook has the wrong people in charge

    Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin

    Compromised owner contract just let hackers print 5.2 million WEMIX stablecoins out of thin air, forcing a complete network freeze

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Anthropic’s Dario Amodei responds: doesn’t oppose open-weight models, but fears Chinese AI

    July 28, 2026

    Adversaries Don’t Need a Zero-Day — They Read Your Rulebook

    July 28, 2026

    Coinbase’s Chief Policy Officers Praises Clarity Act Draft

    July 28, 2026

    NASA Astronaut Chris Williams to Discuss Space Station Mission

    July 28, 2026
    Latest Posts

    The Western Myth of Russian Greatness – Foreign Policy

    July 21, 2026

    Defence stocks rally as John Healey appointed chancellor; UK borrows less than expected in June – business live | Business

    July 21, 2026

    You Pay for Internet Service in Empty Buildings on Alaska’s Adak Island — ProPublica

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Anthropic’s Dario Amodei responds: doesn’t oppose open-weight models, but fears Chinese AI

    July 28, 2026

    Adversaries Don’t Need a Zero-Day — They Read Your Rulebook

    July 28, 2026

    Coinbase’s Chief Policy Officers Praises Clarity Act Draft

    July 28, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.