✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Commercial Real Estate
Breach intelligence, attack campaigns, and threat reports targeting the Commercial Real Estate sector.
Explore Other Sectors
Commercial Real Estate Threat Reports
2024 Smart Building Zero-Day: Global Infrastructure Exposed
In early 2024, cybersecurity researcher Gjoko Krstic uncovered hundreds of zero-day vulnerabilities within legacy building automation systems still widely deployed in hospitals, schools, and commercial facilities globally. The investigation, codenamed "Project Brainfog," revealed that outdated codebases, some as old as 18 years, exposed critical physical infrastructure to remote compromise by unauthenticated attackers. Exploitable weaknesses in authentication, encryption, and access controls allowed for the manipulation of HVAC, security, and energy systems, putting sensitive environments such as medical and educational facilities at operational risk, and making them potential targets for ransomware and espionage. This incident highlights the growing threat of unpatched operational technology in critical sectors, as attackers increasingly target IoT and building control systems for both sabotage and lateral movement. As digital-physical convergence accelerates, organizations must rapidly modernize and secure these legacy environments to mitigate cascading risks.
6 months ago
Kill Chain
CloudEdge Camera Flaw Exposes Millions: MQTT Wildcard and Credentials Risk
In October 2025, security researchers disclosed a critical vulnerability (CVE-2025-11757) affecting CloudEdge IoT cameras and their mobile application. The flaw, caused by improper sanitization of MQTT topic inputs and the use of hard-coded credentials, allowed remote attackers to subscribe to wildcard topics and intercept sensitive messages. This gave unauthorized access to camera feeds and controls globally for any device running the vulnerable CloudEdge App v4.4.2. Neither CloudEdge nor Meari Technologies responded to official disclosure requests, leaving millions of devices worldwide potentially exposed to attack. This incident exemplifies ongoing risks in consumer IoT, highlighting weaknesses in MQTT implementations and credential management. Similar vulnerabilities are increasingly leveraged by attackers to gain unauthorized access, disrupt operations, and compromise privacy, underscoring the pressing need for stronger IoT security regulation and vendor accountability.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports