Malvertising Makes the Browser Build Its Own Malware & Cl0p Hits PTC Windchill (07/24/2026)

July 24, 2026
Malvertising Makes the Browser Build Its Own Malware & Cl0p Hits PTC Windchill (07/24/2026)
Key Intel / TL;DR
  • A malvertising operation dubbed SourTrade ships malware in pieces and has the victim's own browser assemble the final Windows executable, using the legitimate Bun runtime as its base.
  • Cl0p affiliates are exploiting internet-exposed PTC Windchill and FlexPLM deployments through an unauthenticated remote code execution chain for data extortion.
  • Attackers are exploiting a critical unauthenticated RCE in Fastjson 1.x (CVE-2026-16723) in Spring Boot applications, with no patch available for the 1.x line.
  • A researcher published a working RCE exploit for a GitLab flaw patched on June 10 that still runs commands as git on unpatched self-managed 18.11.3 servers.
  • CTM360 reports that insurance phishing has shifted from harvesting credentials for later use to hijacking accounts in real time as the victim types.

Today’s lead is a technique built to defeat the scanner at the perimeter. A malvertising crew ships its malware in fragments and lets the victim’s own browser assemble the working executable, so nothing that crosses the wire looks like a complete threat. Alongside it, Cl0p is back on a familiar playbook against enterprise software, and two unauthenticated flaws are under active exploitation.

Top 5 Critical Security Alerts

1. Malvertising Makes the Browser Build the Malware

A malvertising operation dubbed SourTrade is making victims’ browsers assemble the final Windows executable themselves, using the legitimate Bun JavaScript runtime as its base instead of serving one complete malicious file from a fixed URL, per Confiant (The Hacker News, BleepingComputer). Splitting the payload so it is stitched together in browser memory means the malicious file never travels the network as one piece, which is precisely how it slips past tools that scan what crosses the wire.

Operator Note: Detection that inspects files in transit will not catch a payload assembled on the endpoint. Lean on endpoint behavioral detection and application controls that flag an unexpected runtime like Bun spawning and writing an executable, and treat the browser as an execution environment, not just a viewer.

2. Cl0p Exploits PTC Windchill and FlexPLM

Threat actors linked to Cl0p (also tracked as FIN11 and Lace Tempest) are exploiting internet-exposed PTC Windchill and FlexPLM deployments, chaining a pre-authentication information disclosure into unauthenticated remote code execution for a data extortion campaign (The Hacker News). Cl0p built its reputation on mass-exploiting a single enterprise product to breach hundreds of victims at once, and product lifecycle management systems hold exactly the engineering and design data that makes extortion pay.

Operator Note: If you run Windchill or FlexPLM exposed to the internet, treat it as a current Cl0p target. Get it off the public internet or behind strong access control today, and check for the pre-auth information disclosure that opens the chain.

3. An Unpatched Fastjson Flaw Is Under Attack

Attackers are exploiting CVE-2026-16723, a critical unauthenticated RCE in Fastjson, Alibaba’s JSON library for Java, where a malicious JSON request executes code with the privileges of the Java process in affected Spring Boot applications (The Hacker News). The 1.x line has no patch, so anyone still on it cannot simply update their way out, and a JSON parser is the kind of dependency that sits quietly in the stack until it becomes the way in.

4. A GitLab RCE Exploit Goes Public

Researchers at depthfirst published working exploit code for a GitLab flaw that GitLab patched on June 10, and it still runs commands as git on any self-managed 18.11.3 server that has not taken the update (The Hacker News). Any authenticated user who can push to a project can run it, and a source control server is a high-value target because it holds the code and the pipelines that reach everything downstream. Six weeks after a patch is plenty of time for a public exploit to find the servers that skipped it.

5. Insurance Phishing Becomes Real-Time Hijacking

CTM360 reports that phishing against insurance customers has shifted from the old model of harvesting credentials for later use to hijacking accounts in real time, capturing what the victim types and using it immediately to take the session (The Hacker News). Real-time relay defeats the assumption that a stolen password is useless without the second factor, because the attacker walks through the login and the prompt alongside the victim as it happens.

Additional Security Alerts

Threat Intelligence

  • DevMan RaaS Runs a Full Affiliate Portal: PRODAFT is tracking DevMan, a ransomware-as-a-service operation running a dedicated web platform where affiliates build payloads, manage victims, and track payouts. The Hacker News
  • ShinyHunters Leaks Fuel a Sextortion Wave: Attackers are using email addresses exposed in ShinyHunters breach leaks to send sextortion emails demanding $2,000 in Bitcoin. BleepingComputer

Law Enforcement

  • Europol Flags 4,340 URLs Tied to The Com: Europol identified thousands of URLs linked to the online network known as The Com, used for recruiting and propaganda aimed at minors. The Register

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)