CareCam CM2507 IP Cameras Expose Credentials via Missing Auth and Cleartext Storage
CISA advisory details multiple flaws in CareCam CM2507 cameras allowing unauthenticated video access, credential recovery, and arbitrary code execution.
A running digest of identity-related exploit and breach news — new zero-days, exposed credential dumps, and directory-security advisories — each summarized in our own words with a link to the primary source.
CISA advisory details multiple flaws in CareCam CM2507 cameras allowing unauthenticated video access, credential recovery, and arbitrary code execution.
Hard-coded credentials and missing authentication in Digital Watchdog VMAX recorders (CVSS 9.6) could grant attackers full admin control.
CISA advisory warns of missing authentication/authorization flaws (CVSS 9.8) in mySCADA myPRO Manager <=2.1 exposing privileged management functions.
An unauthenticated XSS flaw in Teamcenter's /auth/ redirect lets attackers hijack authenticated user sessions via a crafted URL.
A CVSS 6.5 flaw in Schneider Electric SCADAPack x70 RTUs insufficiently protects credentials, risking unauthorized access to device configuration.
A signature-validation flaw in Siemens' Mendix SAML module (CVE-2026-80465) allows unauthenticated remote attackers to hijack accounts in certain SSO setups.
CISA advisory flags multiple vulnerabilities in Siemens Reyrolle 7SR5 protection relays, including authentication bypass and missing authentication for critical functions.
CISA advisory warns hardcoded crypto key vulnerabilities in Wärtsilä FOS-Onboard could let attackers extract credentials and impersonate privileged clients.
Millions of Chess.com records posted online in August 2026 contained emails, usernames, names, and countries, likely obtained via scraping.
Three newly cataloged KEV bugs involve broken authentication, authorization, and privilege management across JFrog Artifactory and ConnectWise ScreenConnect.
CISA advisory details four vulnerabilities in AVEVA Pipeline Integrity Monitor, including hard-coded crypto keys and weak algorithms that expose hashes to brute-force attacks.
CISA added two MikroTik RouterOS flaws to its KEV Catalog, including a missing-authentication bug enabling access to critical functions under active exploitation.
ShinyHunters published data allegedly stolen from McKesson, exposing 6.4M unique email addresses along with patient, staff, and provider details.
CISA added four exploited CVEs to its KEV Catalog, including Citrix NetScaler and Cisco FMC authentication bypass vulnerabilities.
CISA warns of a hard-coded credential in CareCam Pro (ANJIA AJL33PC0801) IP cameras allowing bootloader access and full device takeover via physical access.
CISA warns Tycon Systems TPDIN-Monitor-WEB3 (<=2.2.9) contains hard-coded credentials, CSRF, and missing authorization flaws that can expose credentials and enable MitM attacks.
FulcrumSec published emails, phone numbers and service data for 8.7M MAG airport customers after an August 2026 breach.
CISA's latest KEV additions include improper-authentication flaws in LiteLLM and JFrog Artifactory being exploited in the wild.
ShinyHunters leaked 1.2M email addresses and contact details from French IP firm Questel after a 'pay or leak' extortion attempt.
A vulnerability in FactoryTalk Activation Manager (V5.02 and below) lets an authenticated user hijack installer console windows to gain SYSTEM-level access.
CISA added two PaperCut NG/MF flaws to its KEV Catalog, including a missing-authentication bug enabling access to critical functions.
CISA flags active exploitation of an ownCloud improper authentication flaw among three new KEV entries requiring rapid federal remediation.
CISA warns Ebyte NA111-M firmware contains multiple critical authentication and authorization flaws (CVSS 9.8) that could let attackers fully take over the device.
CISA advisory warns that OTTO Fleet Manager ≤V2.36.2 stores password hashes with insufficient computational effort, aiding offline brute-force attacks.
CISA warns of critical vulnerabilities in Xiiaozet LK100W devices, including authentication bypass and missing auth for critical functions, enabling full device takeover.
CISA flagged six vulnerabilities under active exploitation, several enabling privilege escalation and remote access relevant to identity security.
ShinyHunters published data from a Carhartt extortion attack, exposing 12.9M email addresses, names, phone numbers, and physical addresses.
CISA's dual red team exercises both reached full Active Directory domain compromise, with only one org detecting and containing the intrusion.
CISA warns Ebyte NE2-D11 devices carry critical auth-bypass and credential-exposure flaws (CVSS 9.8) enabling unauthenticated admin access.
CISA advisory warns FURUNO FA-50 AIS transponders contain hard-coded credentials and missing authentication, allowing attackers to alter device settings.
A missing authentication flaw in the Node-RED HTTP interface on Siemens SIMATIC IoT2050 Advanced lets unauthenticated remote attackers run arbitrary code with max privileges.
A July 2025 breach at German outlet NIUS leaked 6k email addresses along with names, addresses and payment details.
Hundreds of thousands of Golf Canada user records surfaced on Telegram, exposing emails, names, birth dates and location data.
CVE-2026-27875 lets a low-privileged local attacker dump passwords and auth tokens from memory in Simplex Incident Manager <=V2.01.
CISA added two TrueConf Server vulnerabilities to its KEV Catalog, including a missing-authentication flaw enabling access to critical functions.
Australian retailer Oz Hair and Beauty had nearly 2M customer records leaked after an xpl0itrs extortion attack in August 2026.
OTW disclosed unauthorized access to its Fanlore wiki, exposing ~145k emails, usernames, and MD5/PBKDF2 password hashes.
CISA added four exploited vulnerabilities to its KEV Catalog, including a SharePoint weak authentication bug and a macOS improper authentication flaw.
CISA advisory flags multiple auth-related flaws in ANDRITZ HIPASE-250/250 SCALA energy devices, including reversible password storage and hard-coded credentials.
A shared hard-coded credential in the FL-100 brain stimulation device lets nearby attackers bypass authentication and alter stimulation parameters.
ShinyHunters leaked data on ~1.6M RingCentral users including emails, names, addresses and phone numbers after a July 2026 extortion attempt.
CISA advisory warns Airwall <=4.0.4 contains a hardcoded cryptographic key and path traversal flaw enabling authentication bypass and data decryption.
Two vulnerabilities in Siemens License Server allow local privilege escalation and arbitrary file reads, with one leading to full root compromise.
Hardcoded AES key and unsalted hashing in Siemens LOGO! Soft Comfort let local attackers decrypt project data and crack passwords.
CISA advisory details multiple authentication and credential vulnerabilities in Mira's health monitor and app that could enable full account takeover.
CISA details Gunra ransomware-as-a-service, which abuses exposed VPN and RDP infrastructure and lateral movement to encrypt and exfiltrate data.
Eye care firm Alcon named in a ShinyHunters 'pay or leak' extortion; leaked data includes 218k emails, names, phone numbers and addresses.
ShinyHunters published data allegedly stolen from Brinks Home, exposing 732K email addresses plus personal and partial payment details of leads, customers and staff.
ShinyHunters published stolen Exact Sciences data affecting 10.9M people, including emails, contact details and health records.
CISA advisory warns Johnson Controls TL280 devices below v5.63 contain embedded credentials and a weak cryptographic algorithm exposing sensitive data.
ShinyHunters published data allegedly stolen from Inter-Con Security, exposing 276K email addresses plus names, addresses, job titles and phone numbers.
Three vulnerabilities added to CISA's KEV Catalog, including an actively exploited authentication bypass in N-able N-central RMM.
A shared, hard-coded Bluetooth authentication key in KARR BT and DR-100 anti-theft systems lets nearby attackers unlock doors and bypass immobilizers.
CVE-2026-18577, an authentication bypass in N-able N-central, is under active exploitation and added to CISA's KEV Catalog.
Russian VPN service SplitVPN (formerly NotVPN) suffered a July 2026 breach exposing 865K email addresses, IPs, and partial payment card details.
CISA warns of a missing-authentication flaw (CVE-2026-12562) giving unauthenticated attackers full root access to Toptech energy-sector devices.
CVE-2026-20316, a hard-coded password flaw in Cisco Secure FMC, is under active exploitation and added to CISA's KEV Catalog.
A ShinyHunters extortion campaign leaked 832k email addresses plus names, addresses, phone numbers, and academic records from Houston City College.
A CISA advisory flags CVE-2026-16581 in the igloohome Smart Lock Android app, where hardcoded sensitive data let attackers reach insufficiently protected backend services.
CISA warns MikroTik RouterOS and Cloud Hosted Router lack effective brute-force protections, letting attackers rapidly guess credentials for unauthorized access.
A documentation gap around the System.User entity in Siemens Mendix leads to overly permissive access rules, risking data exposure and privilege escalation.
CISA advisory flags multiple IntraVUE vulnerabilities, including plaintext password storage that leaks cleartext credentials through the API.
CISA warns that Russian state-backed actors are targeting Zimbra Collaboration Suite users via phishing and a novel zero-day to steal email data.
CISA advisory details vulnerabilities in Weintek cMT3092X HMI that let low-privileged users escalate privileges and view other users' credentials.
CISA added two actively exploited flaws to its KEV Catalog, including a Check Point SmartConsole improper authentication bug directly relevant to identity security.
CISA advisory warns a CVSS 9.8 auth bypass lets unauthenticated attackers gain admin sessions and access stored credentials on Tycon monitoring devices.
An unquoted search path vulnerability in Siemens IAM Client lets an authenticated local attacker escalate privileges across many Siemens engineering products.
A critical flaw in Siemens Opcenter X before V2604 lets unauthenticated attackers forge JWTs and impersonate any user, including admins.
CVE-2026-10714 in FactoryTalk Services Platform allows JWT signature bypass, enabling low-privilege users to impersonate authorized accounts.
A November 2025 breach at AI music tool Suno leaked over 55M unique emails, phone numbers, and tens of thousands of partial Stripe payment records.
A gig economy platform breach leaked over 23M email addresses along with bcrypt password hashes, banking data, and payout history.
CVE-2026-11889 allows an authenticated operator to bypass partition boundaries and access spaces outside their assigned tenancy in SALTO ProAccess Space <6.13.
CISA advisory covers multiple SICAM 8 vulnerabilities, including an unverified password change weakness and insecure default initialization affecting ICS devices.
CISA advisory warns of a stored XSS flaw (CVE-2026-9292) in FactoryTalk DataMosaix that can lead to credential theft and account takeover.
ShinyHunters published 100GB+ of data from test equipment maker Fluke, exposing 800k+ email addresses, names, phone numbers and addresses.
A breach of Goose Creek's Shopify instance leaked 6.6M email addresses along with names, phone numbers, addresses, and order details.
Three actively exploited SharePoint Server flaws allow unauthorized access, RCE, and IIS machine key theft for persistence across all supported on-prem versions.
CISA flagged four actively exploited CVEs, including a Microsoft AD FS access-control flaw and SonicWall SMA1000 gateway bugs, mandating federal remediation.
A missing-authentication flaw in Rockwell's 1715-AENTR adapter lets unauthenticated remote attackers run intrusive CLI commands via an exposed debug port.
Joint advisory details FSB Center 16 opportunistically compromising poorly configured networking devices, including via weak SNMP and default credentials, across critical sectors.
A ShinyHunters 'pay or leak' campaign hit Glendale Community College, leaking nearly 800k emails plus SSNs, names and enrollment data.
CISA advisory flags multiple vulnerabilities in Schneider PowerChute Serial Shutdown <=1.4 that could allow unauthorized account access and credential resets.
CVSS 9.8 access control and session flaws in Hydro-Québec's Le Circuit Electrique charging backend could enable privilege escalation and DoS.
CISA advisory warns of authentication bypass and XSS flaws in Digi International serial device servers that could expose credentials.
A cleartext HTTP transmission flaw (CVE-2026-10763) in PROMOD V could let attackers intercept credentials, hijack sessions, or gain unauthorized access.
A ShinyHunters 'pay or leak' campaign led to 2.3M email addresses and personal details of donors, students and alumni being published publicly.
Satellite terminals expose REST API endpoints without authentication, letting remote attackers pull sensitive device identity data or trigger DoS.
CISA advisory details critical Gardyn IoT Hub vulnerabilities, including a hard-coded privileged key allowing unauthenticated attackers to control managed devices.
CISA warns Delta Electronics DVP12SE PLCs allow unauthenticated Modbus TCP commands, letting remote attackers control device logic without credentials.
CVE-2026-13207 lets remote attackers bypass authentication via dot-segment path tricks to enumerate all users and role assignments in FUXA SCADA/HMI.
CISA advisory warns unauthenticated attackers can access credentials stored in firmware or system files of Schneider Electric RTUs.
CISA warns of critical StoneFly Storage Concentrator vulnerabilities, including hard-coded credentials enabling root-level unauthorized access.
CISA added a SimpleHelp authentication bypass flaw to its KEV Catalog citing active exploitation, requiring rapid federal remediation.
A ShinyHunters extortion attack on Sysco leaked 2.7M email addresses plus names, phone numbers, addresses, and internal job titles.
ShinyHunters published data on 200k+ individuals tied to American Tower after a pay-or-leak extortion attempt, exposing emails, names, addresses, and phone numbers.
CISA advisory details missing authentication, weak session handling, and exposed credentials in EVoke CSMS, enabling unauthorized admin control of charging stations.
CISA warns of path traversal, unrestricted file upload, and hard-coded credential flaws in Daktronics Controller Firmware enabling unauthenticated root-level takeover.
A SSRF flaw in OHIF DICOM Web Viewer (<=v3.12.0) can leak an authenticated clinician's OIDC Bearer token to an attacker-controlled server.
UNC6395 stole OAuth tokens tied to the Salesloft Drift integration and used them to export data — and hunt for cloud credentials — from over 700 organizations' Salesforce instances.
UNC5537 used credentials harvested by infostealer malware — some years old and never rotated — to loot 100+ Snowflake customer databases, including AT&T and Ticketmaster.
BlackCat ransomware actors logged into Change Healthcare's Citrix remote-access portal with stolen credentials and no MFA — the largest healthcare data breach in U.S. history.
A legacy, non-production tenant account with no MFA was compromised by password spray, then abused through OAuth to read senior Microsoft executives' email.
Attackers reused passwords leaked on other sites to break into ~14,000 23andMe accounts, then scraped the DNA Relatives feature to reach 6.9 million users.
Attackers accessed Okta's customer support case-management system and obtained HAR files containing session tokens, which were then used against several downstream customers.
A zero-click Outlook vulnerability (CVE-2023-23397) let attackers capture Net-NTLMv2 authentication hashes simply by sending a crafted email — exploited in the wild before patch.
CVE-2020-1472 let an unauthenticated attacker with network access to a domain controller reset its machine-account password and seize the entire Active Directory domain.