Dutch Cybersecurity Act: is your organisation secure online? →

Loki Intelligence — Security Briefs · Published

Daily Security Brief: Java RCEs, Cl0p Targeting, and Browser-Built Malware

Attackers are moving quickly against exposed enterprise software, including Java libraries, GitLab, and PTC platforms used in product lifecycle workflows. Separately, criminal groups are refining delivery and operations through ransomware portals, ClickFix lures, and browser-based malware assembly.

Signal 01 · The Hacker News

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Threat researchers report active attacks against a critical Fastjson 1.x issue affecting some Java and Spring Boot applications. The risk is heightened because exploitation may not require authentication and no vendor patch is currently available.

Why it matters: Inventory Fastjson usage immediately, restrict exposure of affected services, add compensating controls, and monitor Java application processes for unusual child activity or outbound connections.

Source: The Hacker News

Signal 02 · The Hacker News

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Cl0p-linked actors are reportedly targeting internet-facing PTC Windchill and FlexPLM environments in a data extortion campaign. The activity focuses on enterprise systems that often store sensitive product, supplier, and design information.

Why it matters: Product and engineering teams should treat PLM systems as high-value assets: reduce internet exposure, validate patch status, enforce strong access controls, and review logs for suspicious data access.

Source: The Hacker News

Signal 03 · The Hacker News

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Public proof-of-concept code is now available for a GitLab remote code execution flaw patched in June. Self-managed GitLab instances that missed the update face increased risk as working details circulate.

Why it matters: Prioritize GitLab patch verification, especially for self-hosted deployments, and review runner, repository, and system activity for signs of unauthorized command execution.

Source: The Hacker News

Signal 04 · The Hacker News

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

Researchers describe DevMan as a ransomware-as-a-service operation with a centralized portal for affiliate management, victim tracking, and payment workflows. The model lowers operational friction for criminal partners.

Why it matters: Ransomware defense should assume scalable, repeatable attacks: harden identity, test backups, segment critical systems, and monitor for early-stage intrusion patterns before encryption or extortion.

Source: The Hacker News

Signal 05 · BleepingComputer

Steam forum ClickFix attacks infect gamers with XMRig cryptominers

Attackers are abusing Steam discussion forums with fake troubleshooting posts that lead users into ClickFix-style malware infection. Reported payloads include cryptomining malware that consumes victim device resources.

Why it matters: Organizations should block unsafe script execution patterns, educate users about fake support fixes, and monitor endpoints for unexplained CPU spikes or mining-related network traffic.

Source: BleepingComputer

Signal 06 · The Hacker News

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A malvertising campaign known as SourTrade is delivering malware in fragments and relying on the victim browser environment to assemble the final executable. This approach can complicate static detection and URL-based blocking.

Why it matters: Defenders should pair web filtering with behavior-based endpoint detection, restrict risky ad traffic where possible, and watch for unexpected runtime use or file creation from browsers.

Source: The Hacker News

Signal 07 · BleepingComputer

Malicious sites use JavaScript to build malware in browser memory

Malicious pages imitating cryptocurrency and trading brands are using JavaScript-heavy delivery to assemble malware during browsing sessions. The campaign shows continued abuse of trusted-looking financial themes to lure victims.

Why it matters: Security teams should strengthen brand impersonation detection, isolate browsing for high-risk users, and tune controls for suspicious script behavior rather than relying only on downloaded-file signatures.

Source: BleepingComputer

Brief sources

Related briefs

Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.