Act
archived
FastJson RCE zero-day actively exploited against US firms
- Engineer — Act: FastJson is widely used in Java applications; if your codebase or dependencies include it, audit immediately and apply any available patch or mitigations — if no patch exists, consider disabling unsafe deserialization features or replacing the library.
- SOC/IR — Act: Active exploitation is underway against US firms; hunt for anomalous outbound connections or process spawning from Java application servers since this week, and tune detections for RCE post-exploitation behavior (e.g., web shells, unexpected child processes).
- Leader — Plan: Active zero-day targeting US organizations warrants asking your engineering team this week whether FastJson is in use and what the mitigation timeline is — this may generate customer questions if it widens.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.