The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about the exploitation of two critical-severity vulnerabilities affecting multiple Dahua products. These vulnerabilities, identified as CVE-2021-33044 and CVE-2021-33045, could allow attackers to gain unauthorized access to Dahua devices and networks. The vulnerabilities impact a range of Dahua products, including IP cameras, indoor monitors, intercom stations, and digital video recorders (DVRs). They can be exploited by attackers to bypass authentication and gain control of devices. The first vulnerability, CVE-2021-33044, can be triggered by specifying a specific argument during authentication. This allows attackers to bypass authentication on older Dahua devices that do not support a particular feature. The second vulnerability, CVE-2021-33045, can be exploited by specifying custom parameters in login requests. This can trick the device into bypassing authentication and granting the attacker access. CISA urges organizations using Dahua products to apply the necessary patches to address these vulnerabilities.
Balancer’s V2 deployment was hit by a large-scale exploit on November 3, 2025, that drained well over $100 million worth of wrapped and liquid-staked ETH variants. Attackers move...
Security researchers have uncovered a malicious IDE extension, named SleepyDuck, which infiltrated the Open VSX registry under a seemingly legitimate Solidity-tooling name (juan-bi...
On October 30, 2025, cybersecurity researchers identified a highly evolved version of the RondoDox botnet, marking a major shift in the global threat landscape. The upgraded varian...