<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Java on CuraSec</title><link>https://curasec.metacog.co.kr/tags/java/</link><description>Recent content in Java on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 28 Jul 2026 13:01:43 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/java/index.xml" rel="self" type="application/rss+xml"/><item><title>FastJson RCE zero-day actively exploited against US firms</title><link>https://curasec.metacog.co.kr/insights/2026-07-28-hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/</link><pubDate>Tue, 28 Jul 2026 13:01:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-28-hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> FastJson is widely used in Java applications; if your codebase or dependencies include it, audit immediately and apply any available patch or mitigations — if no patch exists, consider disabling unsafe deserialization features or replacing the library.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation is underway against US firms; hunt for anomalous outbound connections or process spawning from Java application servers since this week, and tune detections for RCE post-exploitation behavior (e.g., web shells, unexpected child processes).&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Active zero-day targeting US organizations warrants asking your engineering team this week whether FastJson is in use and what the mitigation timeline is — this may generate customer questions if it widens.&lt;/li>
&lt;/ul></description></item><item><title>Fastjson 1.x RCE (CVE-2026-16723) Actively Exploited, No Patch</title><link>https://curasec.metacog.co.kr/insights/2026-07-26-fastjson-1-x-rce-vulnerability-targeted-in-attacks-with-no-p/</link><pubDate>Sun, 26 Jul 2026 12:14:17 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-26-fastjson-1-x-rce-vulnerability-targeted-in-attacks-with-no-p/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Fastjson 1.x is embedded in many Spring Boot applications; unauthenticated RCE with a public PoC and confirmed active attacks means immediate action is required — audit all services for Fastjson 1.x dependencies, apply WAF rules to block the malicious JSON chain, and isolate or rate-limit exposed endpoints until a patch is available.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Multi-source confirmation of active exploitation gives a detection mandate now — hunt for anomalous JSON deserialization patterns in HTTP request logs to Spring Boot services and monitor for unexpected outbound connections or process spawning from Java app servers since the earliest confirmed attack date.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A critical, unpatched RCE in a widely-used Java library under active attack warrants commissioning an urgent Fastjson 1.x exposure inventory across development teams this week; if use is confirmed, allocate engineering time for compensating controls and track remediation until a vendor patch is released.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-16723 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub&lt;/li>
&lt;/ul></description></item></channel></rss>