Loki Intelligence — Security Briefs · Published
Daily Security Brief: Java RCEs, Cl0p Targeting, and Browser-Built Malware
Attackers are moving quickly against exposed enterprise software, including Java libraries, GitLab, and PTC platforms used in product lifecycle workflows. Separately, criminal groups are refining delivery and operations through ransomware portals, ClickFix lures, and browser-based malware assembly.
Signal 01 · The Hacker News
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Threat researchers report active attacks against a critical Fastjson 1.x issue affecting some Java and Spring Boot applications. The risk is heightened because exploitation may not require authentication and no vendor patch is currently available.
Why it matters: Inventory Fastjson usage immediately, restrict exposure of affected services, add compensating controls, and monitor Java application processes for unusual child activity or outbound connections.
Source: The Hacker News
Signal 02 · The Hacker News
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Cl0p-linked actors are reportedly targeting internet-facing PTC Windchill and FlexPLM environments in a data extortion campaign. The activity focuses on enterprise systems that often store sensitive product, supplier, and design information.
Why it matters: Product and engineering teams should treat PLM systems as high-value assets: reduce internet exposure, validate patch status, enforce strong access controls, and review logs for suspicious data access.
Source: The Hacker News
Signal 03 · The Hacker News
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Public proof-of-concept code is now available for a GitLab remote code execution flaw patched in June. Self-managed GitLab instances that missed the update face increased risk as working details circulate.
Why it matters: Prioritize GitLab patch verification, especially for self-hosted deployments, and review runner, repository, and system activity for signs of unauthorized command execution.
Source: The Hacker News
Signal 04 · The Hacker News
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
Researchers describe DevMan as a ransomware-as-a-service operation with a centralized portal for affiliate management, victim tracking, and payment workflows. The model lowers operational friction for criminal partners.
Why it matters: Ransomware defense should assume scalable, repeatable attacks: harden identity, test backups, segment critical systems, and monitor for early-stage intrusion patterns before encryption or extortion.
Source: The Hacker News
Signal 05 · BleepingComputer
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
Attackers are abusing Steam discussion forums with fake troubleshooting posts that lead users into ClickFix-style malware infection. Reported payloads include cryptomining malware that consumes victim device resources.
Why it matters: Organizations should block unsafe script execution patterns, educate users about fake support fixes, and monitor endpoints for unexplained CPU spikes or mining-related network traffic.
Source: BleepingComputer
Signal 06 · The Hacker News
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
A malvertising campaign known as SourTrade is delivering malware in fragments and relying on the victim browser environment to assemble the final executable. This approach can complicate static detection and URL-based blocking.
Why it matters: Defenders should pair web filtering with behavior-based endpoint detection, restrict risky ad traffic where possible, and watch for unexpected runtime use or file creation from browsers.
Source: The Hacker News
Signal 07 · BleepingComputer
Malicious sites use JavaScript to build malware in browser memory
Malicious pages imitating cryptocurrency and trading brands are using JavaScript-heavy delivery to assemble malware during browsing sessions. The campaign shows continued abuse of trusted-looking financial themes to lure victims.
Why it matters: Security teams should strengthen brand impersonation detection, isolate browsing for high-risk users, and tune controls for suspicious script behavior rather than relying only on downloaded-file signatures.
Source: BleepingComputer
Brief sources
Related briefs
- How to Evaluate an AI Security Testing Provider
- What Is AI Agent Security Testing?
- AI Red Teaming vs Traditional Pentesting
Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.