A zero-day vulnerability in the FastJson Java library is being exploited by hackers to launch remote code execution (RCE) attacks on US firms, allowing attackers to execute arbitrary code without user interaction or elevated privileges. The vulnerability is particularly severe as it is being exploited before any patches have been released, putting defenders at a significant disadvantage. The FastJson library is widely used in many applications, making it a prime target for attackers. Hackers are taking advantage of this exploit to gain unauthorized access to sensitive systems and data. The fact that these attacks are happening before patches exist means that defenders are already behind in mitigating the vulnerability1. This matters to security practitioners because it highlights the importance of proactive measures, such as monitoring for suspicious activity and implementing temporary workarounds, to stay ahead of emerging threats.