2840 stories
·
0 followers

Watch out — TP-Link Tapo Camera vulnerabilities could let hackers spy inside homes, so patch now

1 Share
  • Opswat found two flaws in TP‑Link Tapo C200 cameras: auth bypass (CVE‑2026‑15315) and DoS (CVE‑2026‑15316)
  • Bugs let attackers hijack admin sessions or crash devices; millions of users potentially exposed
  • TP‑Link patched with firmware V5_1.4.6 on Aug 18, 2026; users urged to update immediately

Security researchers found a pair of vulnerabilities in popular smart cameras, which could allow threat actors to peep into people’s homes and businesses.

Earlier this week, Opswat disclosed finding two bugs in the TP-Link Tapo C200 smart security camera - an authentication bypass flaw, and a denial-of-service vulnerability. The former is tracked as CVE-2026-15315 and was given a severity score of 8.7/10 (high). Opswat says the bug allows unauthenticated attackers to obtain valid admin sessions without having a password, which would allow them to manage the device and even watch the stream.

The latter is tracked as CVE-2026-15316. With a severity score of 7.1/10 (high), this bug allows threat actors to send oversized crypted ciphertext values that may trigger exception handling failures and cause the affected device to crash or restart. “Successful exploitation may temporarily disrupt HTTPS management and monitoring functionality, resulting in a denial-of-service (DoS) condition until the service recovers,” according to the NVD.

Patching the bugs

The C200 is a mass-market product, advertised as a security camera, a baby monitor, or a pet camera, with motion detection, 1080p video, 2-way audio, night vision, cloud & SD card storage, and integrations with both Alexa and Google Home.

Opswat disclosed their findings to TP-Link in mid-April this year, which started working on a fix in early July this year. On August 18, 2026, TP-Link released firmware version V5_1.4.6, which addressed both flaws. Users are advised to install the fix as soon as possible.

The researchers did not discuss if the flaws were being abused in the wild, or to what extent. We do know that TP-Link Tapo cameras are rather popular, with the C200 model being relatively widely sold. According to TP-Link, the Tapo app has more than 13 million users, while the Google Play Store shows 10+ million downloads.

On Amazon, the C200 specifically is listed as the #1 top rated product in its category, with more than 3,000 purchases this month alone.

"Camera bugs always get attention because of the "spy factor," but they usually sound cooler and scarier than they actually are," said Dahvid Schloss, OSCP, Chief Operating Officer at Suzu Labs. "The main reason not to "worry" about this one is that running this exploit requires local network access, so a threat actor has to be on your Wi-Fi or already own a device that is.

"If someone's made it that far into your network, they're not after the baby monitor. Now, if the camera was port-forwarded to the internet, that's a bigger design issue and probably should be a concern, but not a common setup for the everyday home user. Either way, I'd still patch the camera, but it's pretty low on the totem pole of what a cybercriminal wants."

"I'm quite curious about the undisclosed vulnerability that reportedly allows full compromise and a foothold to pivot from," Schloss added. "Based on what was reported, I would guess the exploit would be a command injection or a memory-safety bug in the same management service, chained behind that auth bypass to get code execution as root, where they then dropped a static binary to return a shell on the device whose firmware ships with almost no tooling. That attack chain isn't uncommon on cheap, older consumer IoT devices where security wasn't top of mind, but if that's the case here, seeing it hold up on a modern TP-Link device would be a bit of a blast from the past.



Read the whole story
NerdsToGo
1 day ago
reply
Share this story
Delete

CISA urges business to deploy decoys, lures, and honeypots to catch hackers in the act

1 Share
  • CISA urged organizations to deploy honeypots, lures, and honeytokens as cyber decoys
  • Decoys complement Zero Trust by detecting LOTL activity and producing high‑fidelity alerts
  • Guidance outlines tripwires, breadcrumbs, MITRE ATT&CK/Engage steps for scalable implementation

The US Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to deploy honeypots and various lures to better detect cyber-intrusions and keep hackers busy with spoofed materials. To that end, it recently published a new guidance to help businesses of different sizes and cybersecurity maturity implement these “cyber decoy strategies”.

“Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data,.” CISA said in a new security advisory.

“Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI). As organizations adopt Zero Trust models, they should assume that a malicious threat actor may gain some level of access to their environment and plan accordingly.”

Tripwires, breadcrumbs, and honeytokens

CISA’s advisory hints that Zero Trust is the preferred way to go about securing corporate infrastructure. Zero Trust treats no user, device, or network segment as inherently trustworthy and requires organizations to operate on the assumption that compromise is inevitable, it says. If you want to learn more, read our in-depth guide on what ZTNA is.

However, it adds that cyber decoys are consistent with this paradigm and complement ZTNA by supporting continuous monitoring and verification, creating high-fidelity alerts for suspicious activity, reducing alert fatigue, and helping defenders detect post-compromise activity such as adversary LOTL techniques. They are also incremental, cost-effective, and scalable, and can be introduced into the cybersecurity tech stack without major architectural changes.

The guidance can be found on this link (PDF). It introduces different decoy concepts such as tripwires, breadcrumbs, and honeytokens, and uses the MITRE Engage and MITRE ATT&CK frameworks to provide the steps needed to plan, implement, and refine these operations.



Read the whole story
NerdsToGo
1 day ago
reply
Share this story
Delete

FBI confirms two Texas-bound oil tankers hit by hackers who disabled coms and put the engines into overdrive — and Iran is possibly to blame

1 Share
  • FBI and US Coast Guard boarded tanker VL Prosperity after foreign cyber compromise indications
  • Iranian media claimed attackers sabotaged engine systems and communications; Kohaku vessel also affected
  • No group claimed responsibility; US agencies investigating “malicious cyber activity” on targeted ships

Last month, two tankers heading for the United States were hit by a cyberattack, forcing the FBI and Coast Guard to board at least one of the vessels and investigate.

The first vessel is called VL Prosperity, which was allegedly transporting 2.3 million barrels of oil. It is a Liberian crude oil tanker, travelling from Egypt’s Sidi Kerir Oil Terminal towards Galveston, Texas, where it was supposed to dock on August 24. On its route, lasting roughly 25 days, it passed through the Strait of Gibraltar.

Some three days before arriving, it requested assistance from law enforcement, prompting a “highly specialized team” of FBI and Coast Guard cyber experts to board. The ship is currently sitting in the Gulf of Mexico.

Iranians (indirectly) claiming responsibility

“On August 21, a highly specialized team – comprised of USCG Law Enforcement personnel, USCG Cyber Protection Team members, a vessel inspector, and FBI Cyber Action Team operators – embarked the vessel to conduct a comprehensive cyber security boarding and investigation,” a US Coast Guard spokesperson told Cybernews.

The spokesperson also said the team’s activity is “designed to ensure the integrity of the vessel’s operational and information technology systems." The Coast Guard apparently saw “indications that the vessel’s network were compromised by foreign cyber actors.” It later described the incident as “malicious cyber activity.”

The second vessel in question is called Kohaku, flying under the flag of the Marshall Islands. It was travelling towards Texas to load liquefied petroleum gas, as per Wall Street Journal, and has been sitting near Malta for the past couple of days. At press time (Friday morning), it was travelling through the East Mediterranean Sea.

So far, no threat actors have publicly claimed responsibility for these attacks. However, the Iranian Mehr News Agency allegedly hinted the attack was a “message from Iran’s “Resistance Front” to Washington and the broader Middle East.”

The same publication - also the first one to report on the incident and name VL Prosperity as one of the victims - said the attackers infiltrated engine-room systems, reduced the engine’s cooling flow, increased the engine speed, and disabled the ship’s fuel and engine-oil tank, all citing an unnamed crew member. Apparently, the ship’s communications were knocked offline for a day and a half, as well.

Via Cybernews



Read the whole story
NerdsToGo
1 day ago
reply
Share this story
Delete

Meta Muse already has a majorly worrying zero-day security issue

1 Share
  • Researcher Patrick Wardle finds zero‑day in Meta’s new Muse AI assistant,
  • Dubbed not‑a‑mused, the exploit requires local compromise, voice dictation, and app integrations; attackers can hijack tokens and exfiltrate data
  • Meta has been informed but no patch yet; flaw highlights risks of AI assistants with broad permissions

Meta’s new Artificial Intelligence (AI) assistant Muse reportedly carried a zero-day vulnerability that allowed attackers to gain access to people’s apps, such as WhatsApp or email.

However, it’s not as straightforward as your usual zero-day - to exploit it, simply deploying malware will not suffice. Certain features need to be enabled, and certain integrations established before the bug could be leveraged.

Not-a-mused

A little background, for context: Meta recently released Muse, describing it as an assistant that can “book appointments, fill out forms, and handle customer service.” It says the tool, available exclusively for the Mac ecosystem for now, “proactively takes tasks off your plate” and makes purchases, generates images, and creates documents.

To do that, however, it needs to connect to apps such as email, WhatsApp, calendar, or social media accounts - and this connection is the first prerequisite needed to exploit the flaw.

The second prerequisite is voice dictation. The vulnerability was found in the way Muse handles commands received via voice, meaning the attacker must piggyback onto voice commands in order to escalate privileges and access other apps and their content.

Now for the flaw itself. It was discovered by security researcher Patrick Wardle, founder of nonprofit Objective-See. He named it “not-a-mused” and says it hides in an undocumented setting called endo_voyager_dictation_endpoint. When a user narrates a voice command, that instruction is sent and processed in the cloud, where Meta can log it. This setting allows the user to change which endpoint receives the dictation.

Which brings us to the third prerequisite. The threat actor must have local access to be able to change this setting in the first place. In other words, the device must already be compromised in some way, either via remote monitoring and management tools, or via low-level malware (or with physical access).

For the sake of the report, let’s say that a theoretical user checks all the right boxes - they’re running a compromised machine and are talking to Muse that’s already connected to other productivity apps. Instead of reaching Meta’s endpoints, the voice commands are first sent to attacker-controlled infrastructure, where the AI assistant, together with the instructions, also sends authentication tokens for the tool.

If the attacker reacts fast enough, they can grab the token and access their target’s AI tool. If it’s connected to other apps, such as WhatsApp or calendar, they can simply prompt it to extract whatever sensitive information is found inside.

Not-a-mused is therefore a combination of data exfiltration and privilege escalation.

Ironing out the kinks

“We can manipulate the agent and leverage its privileges to do whatever we want,” Wardle told Ars Technica.

“So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.” Wardle said he has developed several proof-of-concept attacks that do things like writing malicious files to disk and snapping pictures, in many cases with no indication to even an alert user.

Meta has been informed, but is yet to comment, or issue a patch.

AI assistants are all the rage nowadays. They’ve turned elaborate answer machines into tools that can complete assignments, even more complex ones. They can book flights and restaurant tables, make purchases, schedule and reschedule calls and meetings, and more. However, to do that, these tools need extensive permissions - something the security community is warning of.

While they’re not openly speaking against it, they are advising caution. There are many stories of AI agents either going rogue, or simply being tricked by malicious actors. For example, a hidden prompt in a phishing email can trick an AI agent tasked with summarizing the message into exfiltrating all .PDF documents from the victim’s inbox.

In the early days of agentic AI, there were reports of assistants simply deleting people’s inboxes.

Assistants are likely here to stay, but there are still quite a few kinks to iron before they can hit the mainstream.



Read the whole story
NerdsToGo
1 day ago
reply
Share this story
Delete

Hackers hit the FBI — ShinyHunters say they have stolen 2TB of employee data, but the attack isn't looking for money, just an apology

1 Share
  • ShinyHunters defaces FBI’s jobs site, claiming a PeopleSoft zero‑day let them steal 2TB of HR data
  • Group says attack is not for ransom but to dispute FBI’s May PSA alleging harassment and swatting tactics
  • Experts warn exploit itself is highly valuable; FBI site reclaimed, investigation ongoing into breach claims

The ShinyHunters extortion group is currently doing brand management in the most ShinyHunters way possible - by hacking into the FBI and stealing the agency’s sensitive files.

The Bureau’s jobs site was defaced and replaced with the usual ShinyHunters content - an ASCII image of the group’s logo, and a message saying “This site has been seized by ShinyHunters. Rooting your systems since ‘19 :)”.

But instead of putting the FBI on its data leak site and threatening to release stolen files if a ransom isn’t paid, ShinyHunters started speaking to the press, telling The Register it found a zero-day vulnerability in the Oracle PeopleSoft human resource management system, which allowed them to remotely execute arbitrary code on the underlying server.

They used this ability to (allegedly) steal more than 2TB of sensitive data from the FBI’s servers, including names, addresses, phone numbers, and information on spouses for current, former, and prospective FBI employees.

“We hold data on all FBI employees and applicants,” the spokesperson told The Register, noting they had compromised human resources, MedLink, and Criminal Justice Information Services.

Brand management

The FBI has yet to comment, and so do both Oracle and AWS, but what’s most peculiar about this incident is that it doesn’t seem to be financially motivated.

So far, everything ShinyHunters’ have been doing was for the money. They would break into a company, steal their files, and then pressure the victims into paying a ransom demand in exchange for deleting the stolen information. This time around, the group claims the goal of the attack is to force the FBI to change the record on how it operates.

“This is NOT financially motivated,” the group told The Register. “We want the FBI to correct or retract their statements they made, which included substantial false allegations.”

The statements were made in a security bulletin published on May 15 this year, right after the Canvas attack. In early May 2026 Instructure, the edtech giant behind the popular Canvas learning system, confirmed suffering a cyberattack and losing sensitive customer data. It was later disclosed that some of the world’s top universities, including Harvard, Oxford, and MIT, were among the victims.

The attack was so disruptive that Instructure’s CEO was called to testify in front of the US House Committee on Homeland Security a few weeks later.

On May 15, the FBI issued a public service announcement (PSA) saying ShinyHunters “commonly use harassment strategies” to exert pressure on victims, including “sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.”

Swatting means calling the police to report criminal activity so severe that the SWAT team is sent. This is usually done to live streamers as a practical, albeit life-threatening, joke.

“Threat actors may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist. Following these pressure tactics, SH actors have sometimes posted exfiltrated data to various iterations of the SH data leak site on the Tor network,” the PSA concluded.

“I have been doing my very best to combat these allegations,” ShinyHunters told the media. “And this is the best way to do it.”

No money?

Not everyone is sold on the idea that ShinyHunters isn’t doing this for the money.

In a statement shared with TechRadar Pro, CTO of Suzu Labs, Denis Calderone, said the claims should be taken with a grain of salt: “I have a hard time believing terabytes of FBI personnel data just sit on a shelf. Foreign intelligence services would love to have it, and having the FBI on their resume makes every future extortion demand more believable, and if the PeopleSoft zero-day is real, the exploit may be worth more than the data. Meanwhile, agents and their spouses could have their home addresses posted publicly within a week if this threat is followed through.”

Calderone also stressed that instead of focusing on the incident, people should be paying more attention to the zero-day.

“If you run PeopleSoft, don't wait for a patch. Get it off the public internet wherever you can, put what has to stay public behind a WAF, and make sure admin components like the /PSEMHUB/ path in their screenshot aren't reachable from outside. Hunt for the June indicators and for SSH attempts against the psoft and oracle accounts. Then ask yourself what your applicant portal can reach. At the FBI, a website built for strangers to upload resumes allegedly led straight into GovCloud.”

The FBI has since reclaimed its website, which now says it is under maintenance.



Read the whole story
NerdsToGo
1 day ago
reply
Share this story
Delete

Microsoft takes down AI-boosted phishing tool that hit 12,000 accounts

1 Share
  • Microsoft, UK police, and partners disrupted EvilTokens PhaaS, arresting two suspects and seizing 200+ domains/sites
  • EvilTokens used AI to scale device‑code phishing, compromising 12,000 inboxes across 10,000 organizations globally
  • Platform ran like a startup with subscriptions, dashboards, and AI‑driven targeting; US victims hit hardest

Two people have been arrested, 50 websites were seized, and 150 domains disabled, in a joint operation against the infamous EvilTokens phishing-as-a-service (PhaaS) kit.

In its report, Microsoft said the UK Metropolitan Police Service’s cybercrime team “arrested two men on suspicion of offenses connected with the alleged operation of EvilTokens.”

The two men, whose identities were not disclosed, are aged 32 and 38, and have been released on bail, subject to conditions while the investigation continues. Their digital services and other items have been confiscated, as well.

Among the partners are Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. We don’t know if these arrests and takedowns will be enough to completely obliterate EvilTokens, or if the platform will continue to operate. Usually, criminal infrastructure is a lot less resilient to disruptions when arrests are made, compared to when law enforcement simply disables the hardware.

The tech startup of organized crime

EvilTokens has been turning heads for a little while now. The platform was first spotted in February 2026, rising quickly to become one of the most widely used PhaaS solutions out there.

It can be bought through Telegram for $1,500, after which there is a recurring $500 subscription cost. Cybercriminals use it to run large-scale, personalized phishing attacks: they can create spoofed websites, landing pages, and other credential-capture assets; they can create custom-tailored phishing emails, and can even grab session tokens, one-time passwords, and other codes designed to protect accounts against phishing, granting attackers access to people’s inboxes.

But what makes EvilTokens particularly impressive is its use of artificial intelligence. The platform comes with an AI assistant that can sift through the inboxes, suggest which targets are of high value, and even how to approach them. Attackers can conduct Microsoft Graph reconnaissance as well, mapping out organizational structure and permissions, keeping access and moving laterally throughout the target network.

Microsoft said it found evidence of large portions of EvilTokens being vibe coded, “with AI helping its creators build the platform itself.”

The researchers also found the platform drawing on capabilities from multiple AI models. Looking at the platform as a whole, it runs like a well-organized startup, with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation.

According to Microsoft, EvilTokens facilitated business email compromise (BEC) campaigns that compromised more than 12,000 inboxes in more than 10,000 organizations worldwide. Victims are mostly in wholesale distribution, construction, and financial services, but those in real estate, higher education, and healthcare are not spared, either.

The victims are primarily located in the United States, with notable numbers found in Canada, the United Kingdom, Australia, India, and France. Microsoft said affected customers were notified, and that the company “helped remediate compromised accounts and shared intelligence to support further defensive and investigative action."

Popularizing device-code phishing

Device-code phishing as an attack technique is not that new. More than a year ago, in February 2025, security researchers Huntress reported on Russian threat actors Storm-2372 deploying the same technique, and while it’s been steadily growing in popularity, it wasn’t until EvilTokens’ appearance that it really exploded.

The same researchers said, in June 2026, that EvilTokens was used to run 1,380% more device-code phishing attacks in 2026, compared to the same period last year.

“We’re seeing a clear maturation of the phishing-as-a-service (PhaaS) market as threat actors increasingly integrate AI workflows into their product offerings,” Huntress said in a report.

“The result is directly observable in our telemetry: a 1,380% increase in device code phishing attacks detected between July–December 2025 and January–April 2026, with over 50% of those incidents linked to two major waves of correlated incidents.”



Read the whole story
NerdsToGo
1 day ago
reply
Share this story
Delete
Next Page of Stories