CISO Talk by James Azar
CyberHub Podcast
Fastjson Zero-Day Has No Patch, Windchill Becomes the Latest Ransomware Gateway, and a Hospital Cyberattack Diverts Patient Care
0:00
-16:11

Fastjson Zero-Day Has No Patch, Windchill Becomes the Latest Ransomware Gateway, and a Hospital Cyberattack Diverts Patient Care

Three actively exploited vulnerabilities, a healthcare system forced into patient diversion, and a stark reminder that cybersecurity failures ultimately impact people not just technology.

☕ Good Morning Security Gang,

Today’s show delivered one of those reminders that every cybersecurity practitioner eventually experiences: vulnerabilities aren’t just CVE numbers they eventually become real-world operational crises. Today we covered three actively exploited vulnerabilities disclosed on the same day, an enterprise software platform now fueling ransomware campaigns, a critical Java library under active attack with no patch available, and perhaps most importantly, a hospital system across Georgia and South Carolina forced to divert patients after a cyberattack disrupted clinical operations.

Underneath every headline today was the same message: speed matters, but consequences matter even more. Whether it’s ransomware targeting manufacturers, healthcare organizations scrambling to maintain patient care, or organizations waiting for patches that may never arrive, cybersecurity continues to demonstrate that operational resilience not simply technical excellence is what ultimately protects businesses and communities.

Double espresso in hand.

Coffee Cup Cheers, Security Gang.

🧭 Executive Summary

Today’s episode centered on a rapidly accelerating threat landscape where organizations are increasingly forced to defend against vulnerabilities that are either immediately weaponized or, in some cases, may never receive a security patch at all.

The show opened with active ransomware campaigns exploiting enterprise product lifecycle management software, moved through a perfect CVSS 10.0 vulnerability affecting Arista infrastructure, examined a dangerous Fastjson vulnerability without an available vendor fix, and concluded with a sobering reminder that cyberattacks against healthcare don’t simply disrupt technology, they disrupt patient care.

Cybersecurity is no longer measured solely by patch velocity.

It’s measured by operational readiness when patching alone isn’t enough.

📰 Top Stories

🚨 Windchill Vulnerability Becomes Active Ransomware Campaign

Today’s highest-priority story focused on PTC Windchill and FlexPLM, where a critical deserialization vulnerability has rapidly evolved into an active ransomware and extortion campaign. Originally patched in June, researchers from ReliaQuest and the Ransomware Information Sharing and Analysis Center (Ransom ISAC) now report that a Clop affiliate is actively exploiting the flaw against organizations across aerospace, automotive manufacturing, retail, and apparel sectors.

Attackers chain together multiple weaknesses to achieve unauthenticated remote code execution before deploying web shells, enumerating sensitive file systems, staging data for exfiltration, and sending extortion emails directly to hundreds of employees within affected organizations. Although Clop has not yet publicly listed victims, the operational methodology closely mirrors previous campaigns associated with the group.

Organizations running Windchill or FlexPLM should immediately deploy available updates while also performing comprehensive compromise assessments. Simply applying the patch is insufficient if attackers already established persistence through web shells or harvested sensitive information prior to remediation.

🔥 Arista Issues Critical CVSS 10.0 Patch Amid Active Exploitation

Arista Networks released emergency updates addressing a CVSS 10.0 vulnerability affecting its on-premises CloudVision Orchestrator (VCO) platform. The flaw, already under active exploitation, requires nothing more than network access to the web interface and allows attackers to compromise the management platform responsible for administering connected infrastructure.

CISA has already added the vulnerability to the Known Exploited Vulnerabilities catalog, issuing federal agencies an aggressive remediation deadline. Arista also published indicators of compromise, including attacker infrastructure, suspicious encoded requests, unexpected outbound connections, and unauthorized configuration changes.

Because compromise of the orchestrator may expose cryptographic material, credentials, and downstream infrastructure, organizations should assume that patching alone may not eliminate all risk. Full forensic review and credential validation should accompany every emergency deployment.

⚠️ Fastjson Zero-Day Under Active Attack Without a Patch

Perhaps the most concerning vulnerability discussed today is CVE-2026-16723, affecting Alibaba’s Fastjson Java library. The vulnerability enables attackers to achieve remote code execution through flaws in Fastjson’s type resolution logic, and organizations are already experiencing active attacks across financial services, healthcare, retail, and technology sectors throughout the United States.

Unlike most critical vulnerabilities, this one presents an additional challenge:

There is currently no vendor patch coming.

“Waiting for a patch isn’t a strategy when no patch is coming.” James Azar

Fastjson has effectively reached end-of-life maintenance for affected versions, leaving organizations responsible for implementing defensive workarounds, enabling safe mode where possible, migrating toward Fastjson 2, or replacing the library altogether.

The story serves as an important reminder that software lifecycle management is increasingly becoming a cybersecurity issue. Continuing to operate unsupported software significantly changes organizational risk regardless of current functionality.

🏥 Cyberattack Forces Hospital System to Divert Patients

The day’s most impactful story involved AnMed Health, a nonprofit healthcare provider serving northeastern Georgia and South Carolina. Following a malware attack believed to involve extortion, multiple hospitals and more than sixty physician practices experienced widespread operational disruption affecting telecommunications, internet connectivity, outpatient services, oncology, imaging, surgeries, and physician offices. Patients requiring treatment were diverted to neighboring healthcare facilities while recovery efforts continue.

“A hospital-wide ransomware outage isn’t simply an IT incident, it’s a patient care event.” James Azar

Although emergency departments remained operational, delayed treatments, interrupted oncology services, postponed procedures, and regional patient diversion illustrate why healthcare cyberattacks carry uniquely serious consequences.

Unlike attacks against retail or manufacturing organizations, ransomware impacting healthcare directly influences patient outcomes. This incident reinforces why healthcare cybersecurity must increasingly prepare for operational continuity not simply data recovery.

⚡ Need to Know

🤖 Claude Shared Conversations Indexed by Google

Users discovered publicly shared Claude AI conversations including health information, internal business discussions, and personal information appearing within Google search results after publicly accessible sharing links became indexed. Organizations should review AI collaboration settings and assume any publicly shared content may eventually become searchable.

💼 ShinyHunters Claims Ernst & Young Breach

The ShinyHunters extortion group claimed responsibility for Ernst & Young’s previously disclosed third-party support platform compromise, alleging broader access into Jira, GitHub, and Azure environments. EY has not independently confirmed those claims.

🥛 Coca-Cola Confirms Data Theft

Coca-Cola acknowledged that the ransomware attack impacting its Fairlife subsidiary involved theft of corporate information, although the company maintains the incident is not expected to materially impact financial performance and that product safety remained unaffected throughout the event.

🏥 MCBS Healthcare Breach Affects 1.2 Million Patients

Atlanta-based medical billing provider MCBS disclosed that a previous ransomware attack exposed medical and personal information associated with more than 1.2 million individuals spanning multiple healthcare organizations.

🛡️ NVIDIA Launches Open Secure AI Alliance

NVIDIA joined thirty-six technology organizations including Microsoft, Cisco, CrowdStrike, and Hugging Face, to launch the Open Secure AI Alliance, focused on building open frameworks for securing AI agents and autonomous systems. Notably absent were OpenAI, Google, Anthropic, and Meta.

⚖️ UK Court Rejects Bahrain Sovereign Immunity Claim

The United Kingdom’s Supreme Court ruled that Bahrain cannot invoke sovereign immunity in litigation involving alleged deployment of commercial spyware against dissidents located within the United Kingdom.

🎯 Key Takeaway

Today’s show wasn’t really about three vulnerabilities.

It wasn’t about ransomware.

It wasn’t even about healthcare.

It was about consequences.

Every vulnerability eventually reaches someone beyond the security operations center.

Sometimes it’s a manufacturing line.

Sometimes it’s a customer.

And sometimes it’s a patient waiting for treatment.

Leave a comment

🧠 James Azar’s CISOs Take

Today’s stories reinforced something I’ve believed for a long time: cybersecurity is ultimately measured by operational outcomes, not technical achievements. We often celebrate how quickly vulnerabilities are patched or how efficiently incidents are contained, but today’s healthcare story reminds us that every disruption eventually affects someone outside the security team. When patients are diverted, surgeries are postponed, or treatments are delayed, cybersecurity becomes far more than protecting systems or data, it becomes part of protecting human lives. That perspective should fundamentally shape how organizations prepare, practice, and prioritize resilience.

The Fastjson story also highlights another growing challenge for security leaders. Increasingly, organizations are discovering vulnerabilities where the traditional expectation of “wait for the vendor patch” no longer applies. Unsupported software, abandoned open-source components, and aging dependencies require security teams to make difficult architectural decisions rather than simply applying updates. Going forward, software lifecycle management, third-party dependency governance, and modernization efforts will become just as important as vulnerability management itself because sometimes the safest patch is replacing the technology altogether.

🛠️ Action Items

  • Immediately patch all PTC Windchill and FlexPLM environments.

  • Hunt for published indicators of compromise before assuming remediation is complete.

  • Apply Arista CloudVision Orchestrator emergency updates immediately.

  • Restrict Arista management interfaces to trusted administrative networks only.

  • Audit environments for unsupported Fastjson implementations and begin migration planning.

  • Enable Fastjson Safe Mode where migration cannot occur immediately.

  • Review healthcare business continuity and patient diversion procedures.

  • Audit publicly shared AI conversations and collaboration links.

  • Monitor Ernst & Young supplier-related third-party risk developments.

  • Review ransomware preparedness across healthcare, manufacturing, and critical infrastructure environments.

  • Treat unsupported software libraries as strategic cybersecurity risks requiring executive attention.

Stay Cyber Safe.

Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.

Share

Discussion about this episode

User's avatar

Ready for more?