The Containment Era is here. →Explore

Industry Category

Commercial Real Estate

Breach intelligence, attack campaigns, and threat reports targeting the Commercial Real Estate sector.

26 threat reports
Page 2 of 3

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Commercial Real Estate Threat Reports

Showing 1324 / 26 reports
Critical Unauthenticated API Vulnerability in Honeywell CCTV Products (CVE-2026-1670)
Impact· CRITICAL

Critical Unauthenticated API Vulnerability in Honeywell CCTV Products (CVE-2026-1670)

In February 2026, a critical vulnerability (CVE-2026-1670) was identified in Honeywell CCTV products, allowing unauthenticated attackers to remotely modify the 'forgot password' recovery email address via an exposed API endpoint. This flaw could lead to unauthorized access to camera feeds and potential network compromise. Affected models include I-HIB2PI-UL 2MP IP (version 6.1.22.1216), SMB NDAA MVO-3 WDR_2MP_32M_PTZ_v2.0, PTZ WDR 2MP 32M WDR_2MP_32M_PTZ_v2.0, and 25M IPC WDR_2MP_32M_PTZ_v2.0. ([cvedetails.com](https://www.cvedetails.com/cve/CVE-2026-1670/?utm_source=openai)) The vulnerability underscores the importance of securing IoT devices, especially in critical infrastructure sectors. Organizations are urged to apply patches promptly and implement robust access controls to mitigate such risks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in TP-Link VIGI Cameras: Authentication Bypass Exploit (CVE-2026-0629)
Impact· HIGH

Critical Vulnerability in TP-Link VIGI Cameras: Authentication Bypass Exploit (CVE-2026-0629)

In January 2026, a critical vulnerability (CVE-2026-0629) was discovered in TP-Link's VIGI series surveillance cameras, affecting over 32 models. This flaw allowed attackers on the same local network to bypass authentication by exploiting the password recovery feature in the cameras' local web interface. By manipulating client-side state, attackers could reset the administrator password without verification, granting them full administrative access to the device. This access enabled potential compromise of device configurations, network security, and unauthorized viewing of live and recorded video feeds. ([tp-link.com](https://www.tp-link.com/us/support/faq/4899/?utm_source=openai)) The incident underscores the growing risks associated with IoT devices in corporate environments. As surveillance systems become increasingly integrated into business operations, vulnerabilities like this highlight the necessity for robust security measures, regular firmware updates, and network segmentation to prevent unauthorized access and potential data breaches.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in Avation Light Engine Pro Exposes Systems to Unauthorized Access
Impact· CRITICAL

Critical Vulnerability in Avation Light Engine Pro Exposes Systems to Unauthorized Access

In February 2026, a critical vulnerability (CVE-2026-1341) was identified in Avation's Light Engine Pro devices, which are widely deployed in commercial facilities worldwide. The flaw involves the exposure of the device's configuration and control interface without any authentication or access control, potentially allowing unauthorized users to gain full control over the device. This vulnerability poses significant risks, including unauthorized access, data manipulation, and potential disruption of operations. ([itsecuritynews.info](https://www.itsecuritynews.info/avation-light-engine-pro/?utm_source=openai)) The absence of authentication mechanisms in critical infrastructure devices underscores the urgent need for robust security measures. Organizations must prioritize the implementation of authentication protocols and access controls to safeguard against such vulnerabilities, especially in devices integral to operational technology environments.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Johnson Controls Metasys Vulnerability: 2026 SQL Exposure Threatens Critical Infrastructure
Impact· HIGH

Johnson Controls Metasys Vulnerability: 2026 SQL Exposure Threatens Critical Infrastructure

In January 2026, Johnson Controls disclosed a critical vulnerability (CVE-2025-26385) affecting multiple Metasys products including the Application and Data Server (ADS), Extended Application and Data Server (ADX), LCS8500, NAE8500, System Configuration Tool (SCT), and Controller Configuration Tool (CCT). The flaw, stemming from improper neutralization of special elements used in a command, could allow remote, unauthenticated attackers to execute arbitrary SQL statements, leading to potential alteration or loss of critical data. Attackers could exploit the issue remotely over network-exposed ports, causing high impact to confidentiality, integrity, and availability across critical infrastructure sectors worldwide. This incident underscores the increasing risks posed by vulnerabilities in operational technology and industrial control systems. As attackers continue to target widely deployed OT/ICS solutions, organizations must accelerate patch deployment, network segmentation, and adopt hardened security practices to protect essential services and meet evolving regulatory expectations.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Johnson Controls iSTAR ICU Tool Faces Critical Stack Buffer Overflow Vulnerability
Impact· high

Johnson Controls iSTAR ICU Tool Faces Critical Stack Buffer Overflow Vulnerability

In January 2026, Johnson Controls Inc. disclosed a significant vulnerability (CVE-2025-26386) affecting its iSTAR Configuration Utility (ICU) tool, versions up to 6.9.7. The issue, a stack-based buffer overflow, could be exploited by a remote attacker, potentially causing a failure in the operating system hosting the ICU tool. Although there have been no reported cases of active exploitation as of the disclosure, the vulnerability poses a risk to critical infrastructure sectors—including commercial facilities, energy, and government services—where the affected product is widely deployed. Security researchers at Tenable responsibly reported the flaw to CISA, who published the advisory. This incident rolls out against the backdrop of increasing attention to the cybersecurity of operational technology (OT) in industrial and critical infrastructure, with regulators and operators emphasizing timely patching and network segmentation practices to prevent lateral movement and operational disruption.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Axis Communications 2025: Critical Camera System Vulnerabilities Threaten OT Security
Impact· low

Axis Communications 2025: Critical Camera System Vulnerabilities Threaten OT Security

In December 2025, Axis Communications disclosed multiple critical vulnerabilities affecting their Camera Station Pro, Camera Station, and Device Manager products. The issues, discovered by cybersecurity researchers from Claroty Team82, include flaws such as deserialization of untrusted data, improper certificate validation, authentication bypass, and local privilege escalation. These vulnerabilities could allow an attacker to remotely execute arbitrary code, intercept communications via man-in-the-middle attacks, or bypass authentication mechanisms, significantly compromising the security posture of organizations using these systems globally. Patches are now available and users are urged to upgrade immediately. This incident highlights a growing trend in targeting surveillance and control infrastructure, reflecting the increased attention threat actors are placing on operational technology and critical manufacturing environments. The convergence of IT and OT risks, as well as heightened regulatory expectations, make robust security controls for IoT and camera systems more critical than ever.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Johnson Controls IoT Devices Exposed: 2025 Encryption Vulnerabilities in PowerG, IQPanel & IQHub
Impact· medium

Johnson Controls IoT Devices Exposed: 2025 Encryption Vulnerabilities in PowerG, IQPanel & IQHub

In December 2025, security researchers at NCC Group identified and responsibly disclosed four cryptographic vulnerabilities (CVE-2025-61738, CVE-2025-61739, CVE-2025-26379, CVE-2025-61740) impacting Johnson Controls’ PowerG, IQPanel, and IQHub products. The flaws included cleartext transmission of sensitive information, nonce reuse, weak pseudo-random number generation, and inadequate origin validation. Threat actors could exploit these issues to intercept, decrypt, or manipulate encrypted wireless traffic, potentially altering system behavior or disrupting services in commercial facilities globally. Johnson Controls issued advisories and firmware updates, especially urging customers to migrate to IQPanel 4 with firmware 4.6.1 or later. The incident highlights the continued importance of secure-by-design principles in IoT and OT devices, as attacks increasingly pivot toward embedded and building automation systems. Heightened regulatory focus and attacker sophistication underscore the need for proactive vulnerability management and segmenting critical infrastructure networks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Johnson Controls iSTAR Ultra Vulnerabilities: 2025 Exposure of OT Systems
Impact· medium

Johnson Controls iSTAR Ultra Vulnerabilities: 2025 Exposure of OT Systems

In December 2025, Johnson Controls publicly disclosed critical vulnerabilities (CVE-2025-43873 and CVE-2025-43874) affecting several versions of its iSTAR Ultra and Edge G2 door controllers used in building automation across critical infrastructure sectors worldwide. These OS Command Injection flaws, exploitable remotely with low attack complexity and minimal user interaction, could allow attackers to gain full control of vulnerable devices, modify firmware, and potentially disrupt or compromise secure building environments. The vulnerabilities were responsibly reported by Reid Wightman of Dragos, and patches have been made available for affected products. This incident highlights increasing threats targeting operational technology (OT) in critical sectors, as cybercriminals and nation-state actors leverage software supply chain and device-level weaknesses for initial access. The prevalence of command injection vulnerabilities, coupled with rising demands for segmentation and zero trust architectures, elevates the urgency for organizations to update OT and IoT assets and enforce proactive defense strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Critical Flaw in India-Based CCTV Cameras Exposes Credentials via Missing Authentication
Impact· medium

Critical Flaw in India-Based CCTV Cameras Exposes Credentials via Missing Authentication

In December 2025, a critical vulnerability (CVE-2025-13607) was discovered in multiple India-based CCTV camera systems, particularly impacting D-Link's DCS-F5614-L1 model up to version v1.03.038, with other vendors like Sparsh Securitech and Securus CCTV also implicated. The flaw allowed remote attackers to access sensitive camera configuration information and steal account credentials without any authentication, dramatically raising the risk of unauthorized surveillance, data breaches, or lateral movement across commercial facility networks. Security researchers reported this issue to CISA, who validated the high-severity risk with a CVSS v4 score of 9.3. This incident highlights the persistent risk posed by insecure IoT devices in critical sectors. Vulnerabilities in widely deployed camera models remain a prime target for opportunistic attackers and serve as a cautionary signal amidst the global increase in attacks exploiting exposed IoT endpoints.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
iCam365 CCTV Camera Vulnerabilities Expose Video Streams and Configuration Data in 2025
Impact· medium

iCam365 CCTV Camera Vulnerabilities Expose Video Streams and Configuration Data in 2025

In November 2025, critical vulnerabilities were disclosed affecting iCam365 CCTV camera models P201 and QC021 (versions 43.4.0.0 and prior), allowing unauthorized access to video streams and configuration data via missing authentication controls. CVE-2025-64770 and CVE-2025-62674 enable attackers present on the same network segment to exploit unauthenticated access to ONVIF and RTSP services, potentially exposing sensitive surveillance footage and device configurations across commercial facilities globally. The vulnerabilities were reported by researcher Truong Nguyen Long and published by CISA after vendor non-responsiveness. This exposure highlights the persistent risk of IoT and security camera devices with weak or missing access controls, coinciding with broader trends of exploitation in internet-connected infrastructure. As remote surveillance soars and IoT devices proliferate, such lapses in device security increase the attack surface for organizations across industries.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Ubia Ubox IoT Cameras Exposed: 2025 Credential Vulnerability Risks
Impact· medium

Ubia Ubox IoT Cameras Exposed: 2025 Credential Vulnerability Risks

In November 2025, a critical vulnerability (CVE-2025-12636) was disclosed in Ubia's Ubox smart camera platform, affecting version 1.1.124. The issue—insufficiently protected credentials—enables a remote attacker with low complexity to exploit API credential weaknesses, providing unauthorized access to live camera feeds and the ability to modify device settings. No public exploitation has yet been reported, but the vulnerability impacts commercial facilities worldwide, especially enterprises deploying these IoT cameras without network segmentation or backend isolation. Ubia did not engage with CISA coordination efforts. This incident exemplifies the ongoing risks associated with insecure IoT/ICS deployments and the lack of vendor responsiveness. With increased regulatory scrutiny and attacker interest in operational technology, ensuring proper credential management and network segmentation is an urgent priority for organizations using connected surveillance systems.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Survision LPR Cameras: Unauthenticated Access Vulnerability (CVE-2025-12108)
Impact· medium

Survision LPR Cameras: Unauthenticated Access Vulnerability (CVE-2025-12108)

In November 2025, a critical vulnerability (CVE-2025-12108) was disclosed in Survision License Plate Recognition (LPR) cameras, affecting all product versions globally. The flaw stems from missing authentication safeguards, allowing threat actors to remotely access device configuration wizards without credentials. This enables full system compromise—enabling attackers to alter settings, exfiltrate data, or use compromised cameras as entry points for broader attacks on commercial infrastructure. Researchers at Microsec identified the issue and notified stakeholders, prompting immediate remediation efforts and a firmware update (v3.5) from Survision. No confirmed active exploitation has been reported so far. With physical security increasingly integrated with digital management systems, unauthenticated access to surveillance infrastructure exposes environments to cyber-physical risks. The urgency of this disclosure reflects a broader industry trend: attackers actively seek exposed IoT and operational tech lacking basic authentication, prompting rising regulatory scrutiny and heightened compliance mandates.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports