FASTJSON ZERO-DAY PUTS US FIRMS AT RISK
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
Hackers are actively exploiting a remote code execution vulnerability in FastJson, a widely-used Java library. The zero-day requires no user interaction or elevated privileges to trigger.
■ MORE FROM THE SECURITY DESK
A threat actor compromised BdThemes' infrastructure and modified a remote JSON feed to create unauthorized admin accounts on affected WordPress sites. The attack leveraged the company's premium web-design plugin distribution system.
HackerOne, the bug bounty platform, has come under criticism following recent policy shifts and operational decisions that have impacted its security researcher community.
Simply deleting files from old USB drives before disposal provides minimal data protection. Experts warn that deleted data can be recovered with basic tools, making proper wiping essential.
CISA has confirmed that ransomware groups are actively exploiting two recently patched vulnerabilities in SonicWall SMA1000 devices, including a critical server-side request forgery flaw.