The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Security/Investigations
Breach intelligence, attack campaigns, and threat reports targeting the Security/Investigations sector.
Explore Other Sectors
Security/Investigations Threat Reports
Six Critical Vulnerabilities Expose Digital Watchdog Surveillance Systems to Complete Compromise
In September 2026, CISA disclosed six critical vulnerabilities in Digital Watchdog VMAX DVR and NVR surveillance systems affecting all product versions worldwide. The vulnerabilities include authentication bypass (CVE-2026-68953), hard-coded credentials (CVE-2026-66890, CVE-2026-68950), missing authentication for critical functions (CVE-2026-68070), missing authorization (CVE-2026-66887), and predictable session tokens (CVE-2026-66372). Successful exploitation grants full administrative control, allowing attackers to view surveillance footage, alter configurations, and use devices as network pivot points with root-level access. This disclosure highlights the growing security risks in IoT surveillance infrastructure, particularly as organizations increasingly deploy connected security devices without proper hardening. The vulnerabilities demonstrate classic IoT security failures that enable lateral movement within critical infrastructure networks.
1 week ago
Kill Chain
Critical Vulnerability in Siemens Siveillance Video Management Servers: CVE-2026-3014
In August 2026, Siemens disclosed a critical vulnerability (CVE-2026-3014) in its Siveillance Video Management Servers, which could allow authenticated users with edit permissions to execute arbitrary code within the Management Server Service. This vulnerability affects versions V2023 R3 prior to V23.3.27, V2024 R1 prior to V24.1.16, and V2025 prior to V25.1.15. Siemens has released patches to address this issue and strongly recommends users update to the latest versions to mitigate potential risks. This incident underscores the ongoing challenges in securing critical infrastructure software, highlighting the importance of timely vulnerability management and the need for organizations to stay vigilant against potential exploitation of such vulnerabilities.
1 month ago
Kill Chain
Critical Bluetooth Vulnerability in Acrisure's KARR Security Systems Exposes Millions of Vehicles
In July 2026, researchers from the University of California, San Diego, identified a critical vulnerability in the KARR Security System, an aftermarket vehicle alarm installed in approximately 2.2 million vehicles across brands like Honda, Toyota, Mazda, Ford, and Jeep. The flaw stemmed from the use of a universal Bluetooth authentication key across all devices, allowing attackers within Bluetooth range to remotely unlock doors, control vehicle functions, and disable engine startup. This vulnerability affected vehicles sold since 2017, many of which had the system installed without owners' active knowledge or subscription. ([malwarebytes.com](https://www.malwarebytes.com/blog/bugs/2026/07/millions-of-cars-could-be-tracked-and-unlocked-by-a-hidden-security-flaw?utm_source=openai)) The incident underscores the growing risks associated with aftermarket automotive security systems, especially those installed by dealerships without stringent security protocols. As vehicles become increasingly connected, the potential attack surface expands, necessitating robust security measures and prompt vulnerability disclosures to protect consumers from unauthorized access and potential theft.
1 month ago
Kill Chain
Critical Bluetooth Vulnerability in KARR Security System Affects Millions of Vehicles
In July 2026, researchers at the University of California, San Diego, identified a critical Bluetooth vulnerability in the KARR Security System, an aftermarket car alarm installed in over 2.2 million vehicles across the United States. This flaw allows attackers within Bluetooth range to unlock doors, disable alarms, control vehicle lights and horns, and even prevent engine startup, all without the owner's knowledge. The vulnerability stems from the use of a universal authentication key stored in plain text within the system's mobile application, making all installed units susceptible to remote exploitation. This incident underscores the growing security risks associated with aftermarket automotive devices, especially those utilizing wireless communication protocols like Bluetooth. As vehicles become increasingly connected, the potential attack surface expands, highlighting the urgent need for robust security measures and regular vulnerability assessments in automotive systems to protect consumers from emerging cyber threats.
1 month ago
Kill Chain
ShinyHunters Exploit Vishing to Breach Brinks Home in 2026
In July 2026, Brinks Home, a residential security company, experienced a data breach orchestrated by the cybercriminal group ShinyHunters. The attackers gained access through a voice phishing (vishing) attack targeting a Microsoft Entra account, leading to the exfiltration of over 4.9 million Salesforce records containing personally identifiable information (PII). Brinks Home promptly activated its incident response procedures and engaged forensic experts to contain the breach. The company's alarm monitoring and system functionality remained unaffected. ([en.wikipedia.org](https://en.wikipedia.org/wiki/ShinyHunters?utm_source=openai)) This incident underscores the escalating threat posed by sophisticated social engineering tactics, particularly vishing, employed by groups like ShinyHunters. Organizations must enhance their security awareness training and implement robust multi-factor authentication mechanisms to mitigate such risks.
1 month ago
Kill Chain
Critical Security Flaws Discovered in H.VIEW HV-500S6 IP Cameras
In June 2026, two critical vulnerabilities were identified in the H.VIEW HV-500S6 IP Camera, specifically in firmware version IPCAM_V4.06.88.251229. CVE-2026-55975 allows authenticated users to execute arbitrary commands with elevated privileges by injecting unsanitized XML fields into the device's certificate generation interface. CVE-2026-56414 permits authenticated users to upload arbitrary files without validation, potentially compromising system integrity. Exploitation of these vulnerabilities could lead to unauthorized access and control over the affected devices. The discovery of these vulnerabilities underscores the growing security challenges in IoT devices, particularly those deployed in critical infrastructure sectors. Organizations must prioritize regular security assessments and firmware updates to mitigate such risks.
2 months ago
Kill Chain
Critical Security Flaws Discovered in Brickcom Cameras
In June 2026, critical vulnerabilities were identified in Brickcom cameras, specifically models Cube, Dome, Bullet, and Box version 3.2.3.5.6. These flaws, cataloged as CVE-2026-50245 and CVE-2026-50005, allow unauthenticated remote attackers to access live video feeds and still images via the /ONVIF endpoint without requiring authentication. Additionally, the use of default credentials enables silent access to camera feeds, compromising sensitive visual information and potentially granting administrative control over the devices. The exploitation of these vulnerabilities poses significant risks to sectors such as Commercial Facilities, Critical Manufacturing, Financial Services, and Healthcare, where surveillance systems are integral to security operations. The absence of authentication mechanisms in these cameras underscores the critical need for robust access controls and regular security assessments to prevent unauthorized access and data breaches.
3 months ago
Kill Chain
Critical Vulnerability in KMW CCTV Security Cameras (CVE-2026-5386)
In May 2026, a critical vulnerability (CVE-2026-5386) was identified in KMW CCTV Security Cameras, specifically models KM-IP521 and KM-IP421. This flaw allows unauthenticated attackers to remotely reset the administrator password to a known value, granting full access to camera feeds and settings. The vulnerability poses significant risks to critical infrastructure sectors, including commercial facilities, government services, and financial services. KMW has released firmware updates to address this issue and recommends users apply these updates promptly. ([windowsforum.com](https://windowsforum.com/threads/cisa-icsa-26-148-06-kmw-cctv-critical-password-reset-flaw.420548/?utm_source=openai)) This incident underscores the growing security challenges associated with IoT devices in critical infrastructure. The ease of exploitation and potential impact highlight the necessity for robust security measures, including regular firmware updates and network segmentation, to protect against unauthorized access and potential breaches.
3 months ago
Kill Chain
Critical XSS Vulnerability in CP Plus NVRs: CVE-2026-6824
In May 2026, a critical stored Cross-Site Scripting (XSS) vulnerability, identified as CVE-2026-6824, was discovered in CP Plus 8 Channel Network Video Recorders (NVRs). This flaw allows attackers to inject malicious scripts into the device's web interface, which execute in the browsers of authenticated users or administrators upon access. Exploitation can lead to session hijacking, unauthorized actions, data exposure, and compromise of system integrity. The affected versions include CP-UNR-108F1 Hardware V1.0, Web V3.2.7.128806, and System V4.001.00AT009.0.R. ([socdefenders.ai](https://www.socdefenders.ai/item/a70ca9af-a0bb-4b2f-9cf8-a89beb76b2b9?utm_source=openai)) This incident underscores the persistent threat posed by web-based vulnerabilities in critical infrastructure devices. As attackers increasingly target such systems, organizations must prioritize regular security assessments, timely patching, and adherence to best practices to mitigate risks associated with similar vulnerabilities.
3 months ago
Kill Chain
Critical Vulnerability in ZKTeco CCTV Cameras: CVE-2026-8598
In May 2026, a critical vulnerability (CVE-2026-8598) was identified in ZKTeco CCTV cameras, specifically affecting the SSC335-GC2063-Face-0b77 model with firmware versions prior to V5.0.1.2.20260421. This flaw involved an undocumented configuration export port that lacked authentication, potentially exposing sensitive information such as camera account credentials and open services. Exploitation of this vulnerability could lead to unauthorized access and control over the affected devices. This incident underscores the importance of securing physical security devices, as they can serve as entry points for broader network compromises. Organizations are urged to promptly update their firmware to the latest version and implement robust network segmentation to mitigate such risks.
4 months ago
Kill Chain
ADT Data Breach 2026: Lessons in SSO Security
In April 2026, home security company ADT experienced a data breach orchestrated by the ShinyHunters extortion group. The attackers gained unauthorized access to ADT's systems through a voice phishing (vishing) attack, compromising an employee's Okta single sign-on (SSO) account. This access allowed them to infiltrate ADT's Salesforce instance and exfiltrate personal information, including names, phone numbers, addresses, and, in some cases, dates of birth and partial Social Security numbers. Notably, no payment information or customer security systems were affected. ADT promptly terminated the intrusion, launched an investigation, and notified all affected individuals. This incident underscores the escalating threat posed by sophisticated social engineering attacks targeting SSO credentials. Organizations must enhance their security awareness training and implement robust multi-factor authentication protocols to mitigate such risks.
5 months ago
Kill Chain
Critical Vulnerability in Xiongmai XM530 IP Cameras: CVE-2025-65856
In December 2025, a critical authentication bypass vulnerability, identified as CVE-2025-65856, was discovered in Xiongmai XM530 IP cameras running Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. This flaw allows unauthenticated remote attackers to access sensitive device information and live video streams by exploiting the ONVIF implementation, which fails to enforce authentication on 31 critical endpoints. The vulnerability poses significant privacy and security risks to organizations and individuals relying on these surveillance devices. The public release of proof-of-concept exploit code in April 2026 has heightened the urgency for remediation. Despite the severity of the issue, the manufacturer has yet to provide a patch, leaving thousands of devices worldwide vulnerable to potential exploitation.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports