Hackers target US firms in FastJson RCE zero-day attacks

A critical zero-day vulnerability in the FastJson Java library is being actively exploited by hackers to achieve remote code execution. The flaw affects versions 1.2.68 through 1.2.83 and primarily targets US-based organizations using Spring Boot deployments.
Why it matters
FastJson is widely used in enterprise software, making this vulnerability a significant security risk for a broad range of industries.
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges.
The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S.
The malicious activity was observed last week by the agentic security company ThreatBook, and researchers at the business protection company Imperva confirmed that it was "targeting a wide range of organizations, across Financial Services, Healthcare, Computing, Retail, Business, and other industries."
"Attacks are currently almost entirely targeting US-based organizations, with a few attacks in Singapore and Canada, although this will likely continue to expand globally," Imperva says .
FastJson is an open-source Java library developed by Alibaba, used for serializing Java objects to JSON, and vice versa.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in