✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Real Estate/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Real Estate/Mortgage sector.
Explore Other Sectors
Real Estate/Mortgage Threat Reports
Microsoft, Europol Disrupt RedVDS Cybercrime Marketplace in Major Global Takedown (2025)
In June 2025, Microsoft, in collaboration with international law enforcement, dismantled the infrastructure powering the RedVDS cybercrime marketplace, a platform notorious for enabling large-scale cyber fraud. Since at least March 2025, RedVDS provided cybercriminals with access to disposable, unlicensed virtual Windows servers for as little as $24 per month, facilitating attacks such as phishing, credential theft, and business email compromise. The platform's operations are tied to over $40 million in U.S. fraud losses, including multi-million-dollar incidents targeting the pharmaceutical and real estate sectors. Over a month, attackers using RedVDS compromised more than 191,000 Microsoft email accounts, demonstrating the platform's operational scale and global reach. This takedown underscores the growing threat of Cybercrime-as-a-Service marketplaces, which lower barriers for cybercriminals and accelerate the pace and scale of attacks. Organizations across industries must prioritize modern security strategies as such platforms proliferate and regulatory bodies intensify their scrutiny of supply chain and email-based threats.
6 months ago
Kill Chain
YoSmart YoLink 2026: IoT Flaws Enable Remote Takeover and Data Exposure
In January 2026, YoSmart's YoLink Smart Hub platform was found vulnerable to a series of security flaws that placed smart home users at risk worldwide. Discovered and reported by Bishop Fox and disclosed via CISA, these issues included insufficient authorization in device communication, the use of predictable device identifiers, cleartext transmission of sensitive information over MQTT, and excessive session token lifetimes. Attackers could remotely control users' smart devices, intercept data, and hijack sessions without physical access, affecting both the hub and its mobile app ecosystem. The vulnerabilities were present in core server infrastructure, device APIs, and user-facing applications. While YoSmart resolved the vulnerabilities through server-side and over-the-air updates, this incident highlights critical and ongoing risks in the IoT and smart device sector. The attack methods exploited insecure-by-design communication and poor identity management—trends increasingly scrutinized by regulators and targeted by sophisticated threat actors worldwide.
6 months ago
Kill Chain
Flock Cloud Misconfiguration Exposes AI Camera Surveillance Feeds in 2026
In January 2026, Flock, a prominent provider of AI-enabled surveillance technologies, faced a significant cybersecurity incident due to a cloud misconfiguration. Unauthorized online access was discovered, revealing live video streams from Flock’s advanced Condor pan-tilt-zoom cameras deployed in public areas and private properties. These cameras, designed for AI-driven facial and movement tracking, unintentionally exposed high-resolution footage of civilians—including children—across multiple locations, highlighting considerable privacy and operational risks. No evidence suggests the exposure was caused by active exploitation; instead, the open access points were a direct result of insufficient cloud security controls and misapplied access permissions. The incident triggered regulatory and public concern around surveillance, data protection, and compliance obligations, emphasizing the criticality of proper cloud configurations in the era of AI-driven physical security systems. This breach is indicative of a broader rise in cloud infrastructure misconfigurations exposing sensitive, AI-powered surveillance data. Regulatory agencies and industry groups are increasing pressure on technology vendors to enforce robust controls, with cloud and IoT security now considered foundational to protecting physical as well as digital environments.
6 months ago
Kill Chain
Siemens Building X Firmware Supply Chain Flaw: Risks and Mitigation
In December 2025, Siemens disclosed a critical vulnerability in its Building X - Security Manager Edge Controller (ACC-AP), affecting all firmware versions. The flaw, tracked as CVE-2022-31807, is an improper verification of cryptographic signature that enables a local—or, in some cases, remote—attacker to upload maliciously altered firmware to the device. This could be exploited by an individual with physical access or by intercepting firmware updates, introducing risks to device integrity and broadening the attack surface in critical manufacturing environments. Siemens has issued operational mitigations but no permanent patch is planned. This incident highlights increasing attention on firmware supply chain vulnerabilities across operational technology (OT) in critical infrastructure. Insecure update mechanisms are a prime target for actors seeking persistent access or sabotage, echoing a trend that is prompting regulators and organizations to strengthen controls—especially amid rising regulatory scrutiny and high-profile supply chain breaches.
6 months ago
Kill Chain
Inside the 2024 Korea IP Camera Mass-Hack: A Wake-Up Call for IoT Security
In early 2024, South Korean authorities arrested four suspects for hacking into more than 120,000 IP cameras nationwide, exfiltrating sensitive video footage, and distributing it through a foreign adult website. Attackers exploited insecure and poorly configured IoT camera devices lacking adequate network segmentation or encrypted traffic, allowing for remote access and large-scale unauthorized surveillance. The breach exposed thousands of individuals to privacy violations and highlighted severe weaknesses in the deployment and security of IoT devices within residential and business environments. This incident underscores a rising trend of IoT device exploitation for privacy invasions, raising alarms globally about insufficient network protections and the urgency for robust segmentation, encrypted communications, and egress security policies as IoT adoption grows.
6 months ago
Kill Chain
SitusAMC Breach Exposes Sensitive Data in Real-Estate Finance Supply Chain
In June 2024, SitusAMC, a leading provider of real-estate finance back-end services, identified unauthorized access to systems containing client data. Attackers exploited a vulnerability in the company’s network infrastructure, resulting in the exposure of sensitive information related to financial institutions and their customers. SitusAMC promptly launched an investigation and notified impacted clients after confirming that personal and business data—including names, contact details, financial records, and transaction information—had been compromised. The breach triggered operational reviews and regulatory notification obligations, highlighting the company’s broad reach in the U.S. finance sector. This incident spotlights a worrisome trend of threat actors targeting managed services and supply chains in critical industries. With rising attacks focusing on lateral movement and data exfiltration, organizations face growing pressure from regulators and industry groups to prioritize segmentation, monitoring, and encryption across their digital estates.
6 months ago
Kill Chain
Researchers Reveal Tuoni C2’s Role in 2025 Real-Estate Cyber Attack
In early November 2025, a prominent U.S.-based real-estate company was targeted in a sophisticated cyber attack utilizing the Tuoni command-and-control (C2) framework, a new red-teaming tool known for implementing stealthy, in-memory payload delivery. The attackers exploited Tuoni C2’s advanced capabilities to infiltrate the network while evading traditional security controls, demonstrating lateral movement and attempting data collection within internal segments. Although swift detection halted major exfiltration, the intrusion highlighted gaps in east-west traffic visibility and segmentation, causing temporary disruption to key business systems and prompting an urgent review of internal controls. This attack underscores the growing trend of adversaries adopting novel, freely available C2 tools to bypass existing enterprise defenses. It reflects broader industry concern as C2 frameworks like Tuoni fuel increased attack sophistication, especially in sectors handling large volumes of sensitive data such as real estate and finance.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports