The Lyceum: Cyber Intelligence Daily — Jul 28, 2026
Photo: lyceumnews.com
Tuesday, July 28, 2026
The Big Picture
The freshest emergencies are hiding in infrastructure most employees never see: a Java library embedded inside business applications, an SD-WAN control plane, and an SSL-VPN gateway. The common lesson is less dramatic than a zero-day headline but more useful: when an edge system is actively exploited, installing the patch is the beginning of incident response—not the end.
What Just Dropped
- CVE-2026-16723 — Fastjson 1.2.68–1.2.83: no maintained Fastjson 1.x fix and actively exploited; no NVD score appears in the supplied CVE backbone; vulnerable Java applications may permit unauthenticated remote-code execution.
- CVE-2026-16812 — Arista VeloCloud Orchestrator On-Prem: patched and actively exploited; no NVD CVSS score is listed in the supplied backbone; attackers can inject operating-system commands and potentially reach managed Edge devices.
- CVE-2025-68686 — Fortinet FortiOS: patched and actively exploited; no NVD CVSS score is listed in the supplied backbone; the flaw can expose sensitive information and preserve access around affected SSL-VPN appliances.
Today's Stories
The Fastjson Flaw Has No Normal Patch—and Attackers Are Already Using It
Fastjson is the kind of dependency companies discover only after something catches fire. The Java library converts data between applications, and ThreatBook reported overnight that attackers are exploiting CVE-2026-16723 against vulnerable deployments. (Signal Validated: Fastjson Has No Patch, and Attackers Are Already Using It)
According to ThreatBook, the flaw affects Fastjson 1.2.68 through 1.2.83 under common Spring Boot packaging conditions and can lead to remote-code execution without authentication. Alibaba’s security advisory says Fastjson 1.x is no longer maintained, so there will be no conventional repaired release for administrators to install.
That forces a decision rather than a routine update. Alibaba recommends enabling SafeMode, moving temporarily to the restricted 1.2.83_noneautotype build, or migrating to Fastjson2. Organizations that successfully find and remove the dependency win back control of an invisible attack surface; organizations waiting for their vulnerability scanner to identify an installed application may never see it. (Signal Validated: Fastjson Has No Patch, and Attackers Are Already Using It)
The signal to watch is CISA’s Known Exploited Vulnerabilities catalog. An addition would independently validate the campaign and put federal systems on a formal remediation clock. (Signal Validated: Fastjson Has No Patch, and Attackers Are Already Using It)
Arista’s SD-WAN Control Tower Is Being Exploited Without Credentials
Arista disclosed Monday that attackers are exploiting CVE-2026-16812 in on-premises VeloCloud Orchestrator installations. The vulnerability lets an unauthenticated attacker inject operating-system commands into the software that centrally manages branch-network Edge devices. (Arista’s VeloCloud Orchestrator is being exploited without credentials)
Arista has released fixes for affected release trains, and CISA has set July 30 as the still-active federal remediation deadline. Arista says a successful intrusion may expose credentials, certificates, configuration databases, and managed devices—the difference between compromising one server and inheriting the keys to an organization’s branch network.
Fast remediation means patching, preserving logs, rotating exposed credentials, and checking whether managed Edge devices were altered. Failure looks like treating the orchestrator as an ordinary web server and closing the ticket after an upgrade.
Arista has published three observed attacking IP addresses, but attribution and the exploitation timeline remain undisclosed. Additional indicators—or evidence of configuration changes predating Monday’s advisory—would show whether defenders are facing isolated attacks or a broader campaign.
FortiOS Has Joined CISA’s Actively Exploited Edge Queue
Infosecurity Magazine reports that CISA added Fortinet FortiOS vulnerability CVE-2025-68686 to its Known Exploited Vulnerabilities catalog on Monday. The operative federal remediation deadline is August 10, not an expired date.
The vulnerability affects SSL-VPN infrastructure, which sits directly between remote users and internal networks. Current reporting describes it as a way around an earlier repair for a persistence technique involving symbolic links left on compromised FortiGate appliances. Fortinet’s fixed release trains include FortiOS 7.4.7 and 7.6.2 or later.
The organizations that handle this well will separate patch management from compromise assessment: update the appliance, then inspect administrator activity, configurations, accounts, and persistence artifacts. Non-adoption means an internet-facing security device may continue serving as both the front door and the spare key hidden under the mat.
The important downstream signal is ransomware casework. If incident responders begin finding this vulnerability or its persistence artifacts in extortion intrusions, FortiOS access has become a reusable criminal commodity rather than an isolated exploitation technique.
MCP’s Stateless Security Rewrite Has Reached Release-Candidate Form
The Model Context Protocol project published a July 28 release candidate that moves the protocol used to connect AI agents with tools and data toward stateless HTTP. In plain English: servers should rely less on long-lived sessions that can be stolen, confused, or silently reused.
The revision also tightens authorization around OAuth and OpenID Connect. Production SDKs are beginning to support the architecture, but a release candidate is not a finished ecosystem migration—and several protections still depend on developers enabling and configuring them correctly.
If adoption succeeds, MCP servers become easier to isolate, route, and scale without preserving dangerous session state. If it stalls, enterprises will accumulate a mixture of old clients, new servers, optional safeguards, and compatibility exceptions—the traditional ingredients of an authentication mess.
Watch conformance testing and downgrade behavior. Clients quietly falling back to older protocol versions, or SDKs shipping without the newer authorization controls enabled, would show that the specification improved faster than the deployments it is supposed to protect.
⚡ What Most People Missed
- Origin Energy’s breach reached 900,000 people: Origin Energy said Tuesday that exposed records may include names, addresses, birth dates, contact details, account information, and partial financial numbers. The immediate risk is not direct withdrawals; it is extraordinarily convincing billing, refund, and account-verification fraud.
- Fairlife’s ransomware incident included data theft: BleepingComputer reports that Coca-Cola confirmed files were taken from Fairlife, although Coca-Cola has not identified the record types. Anubis claims it stole one terabyte, but that volume remains the ransomware group’s claim rather than a confirmed company figure.
- Dysphoria has compromised roughly 200,000 devices: BleepingComputer attributes that estimate to QiAnXin XLab, which says Dysphoria uses blockchain naming systems and infected-device relays to make command infrastructure harder to remove. Weak Telnet and SSH credentials remain the botnet’s decidedly low-tech doorway.
- Steam support threads are becoming ClickFix traps: Xakep reports that malicious replies are offering fake PowerShell repairs that install the XMRig cryptocurrency miner, create a Microsoft Defender exclusion, and establish a privileged scheduled task. Anyone who followed one should inspect
C:\Windows\Backgroundand tasks beginning withXMRig-. [Source: Xakep — Russian] - The January Office patch is not a fresh emergency: Microsoft released the CVE-2026-21509 Office update on January 26; CISA’s Langflow action arrived July 21 with a July 24 deadline, while the circulating CL0P headline is a June retrospective. All remain relevant to unpatched systems, but none qualifies as a new event within this edition’s 24-hour window.
📅 What to Watch
- If CISA adds Fastjson CVE-2026-16723 to KEV, it means an obscure application dependency has become a government-validated exploitation priority rather than a vendor-observed campaign.
- If Arista finds pre-disclosure configuration changes on managed Edge devices, the orchestrator flaw was likely used for durable network access rather than quick server compromise.
- If CVE-2025-68686 artifacts appear in ransomware investigations, compromised FortiGate appliances are becoming traded access inventory for criminal affiliates.
- If MCP clients silently downgrade to older protocol versions, interoperability pressure will be defeating the security benefits of the stateless rewrite.
- If Origin Energy customers report tailored refund or billing calls, the stolen dataset has moved from the original intruder into a wider fraud ecosystem.
The Closer
A forgotten Java parser grew teeth, an SD-WAN control tower started handing out shell access, and an AI protocol tried to improve security by forgetting everyone on purpose.
Meanwhile, Steam support has discovered the timeless troubleshooting method of “paste this into PowerShell and accidentally mine cryptocurrency for a stranger.”
Keep the logs; distrust the fix.
Forward this to whoever still thinks dependencies are someone else’s problem.
⚡ EDGE Signals
The following signals appeared in the adversarial edge sweep but were not carried forward in the primary synthesis:
- This effectively turns widely‑deployed VPN and SD‑WAN control planes into high‑priority incident surfaces rather than routine patch jobs[2][3][4][6]. The catch is that Fortinet’s robust fix is only available on newer 7.6.2+ and 7.4.7+ trains, and appliances that ever had SSL‑VPN enabled can be e