tag: Iot-Security · 5 items
- Engineer — Plan: If your environment uses Unitree G1 EDU robots, review network segmentation and disable unnecessary BLE/network services; no KEV listing and near-zero EPSS suggest limited active exploitation pressure, but public PoCs exist so schedule patching.
- SOC/IR — Skip
- Leader — Skip
- Signals: CVE-2026-76639 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub · CVE-2026-76640 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
- Engineer — Act: If your environment includes Dahua cameras or NVRs, audit for these two auth-bypass CVEs and enforce credential rotation immediately; also review whether P2P relay features are exposed to the internet and disable if not required.
- SOC/IR — Plan: Build detections for unusual outbound P2P relay traffic from camera subnets and sweep network logs for connections to Dahua cloud relay infrastructure since June 17, 2026; full IOC set not confirmed in enrichment signals but Hunt.io research may provide indicators.
- Leader — Learn: Large-scale IoT compromise campaign is worth noting for vendor risk assessments if Dahua devices are deployed in physical security infrastructure, but no immediate leadership action is required absent confirmed breach at your organization.
- Engineer — Plan: If Dahua cameras are in scope, audit all units for default or weak credentials and remove any direct internet exposure; the campaign scale suggests opportunistic credential stuffing across this device class, but no KEV or PoC shifts this below Act.
- SOC/IR — Learn: No IOCs or ATT&CK-mappable TTPs are surfaced in this item, and the compromise is geographically concentrated in Ukraine and Russia — limited detection work is actionable for a typical enterprise SOC without more detail.
- Leader — Skip
- Engineer — Plan: If your environment includes Hikvision cameras, audit whether their Intelligent Security API is exposed to the internet and place them behind a firewall or VPN; no new CVE is cited but active scanning indicates exploitation interest.
- SOC/IR — Plan: Add or tune detections for inbound probes against Hikvision API paths (e.g., /ISAPI/ endpoints) in perimeter logs; SANS honeypots are detecting active internet-wide scans worth tracking as a precursor to exploitation.
- Leader — Skip
- Engineer — Learn: Solid research demonstrating that ESP32 WDEV output is pseudorandom when RF is disabled yet passes statistical tests — a reminder that output testing is insufficient for source-state validation. Worth reviewing if your team ships ESP32-based IoT products; no patch or CVE to act on yet.
- SOC/IR — Skip
- Leader — Skip