The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory regarding a critical vulnerability in Avtech Security cameras. Tracked as CVE-2024-7029, this flaw affects Avtech AVM1203 IP cameras running firmware versions FullImg-1023-1007-1011-1009 and earlier, and potentially other Avtech cameras and NVRs. The vulnerability allows remote command injection over the network without authentication, making it highly exploitable. CISA Confirms Active Exploitation of Vulnerability. Unfortunately, Avtech has not responded to CISA’s efforts to address the issue, suggesting that the vulnerability remains unpatched. CISA’s awareness of this vulnerability stems from a report by Akamai, which was corroborated by an anonymous third-party organization that identified the affected products and firmware versions. While no public reports currently describe attacks exploiting CVE-2024-7029, it is important to note that Avtech cameras have previously been targeted by IoT botnets like Hide ‘N Seek and Mirai variants. The affected Avtech products are used globally across critical sectors, including commercial facilities, healthcare, financial services, and transportation. As of now, CISA has not included CVE-2024-7029 in its Known Exploited Vulnerabilities Catalog. Users of Avtech products are advised to monitor for any unusual activity and consider alternative security measures until a patch is available.
DeepDoor is a stealthy Python-based Remote Access Trojan (RAT) identified by Securonix Threat Research, delivered through a heavily obfuscated batch script. The malware embeds its ...
Multiple vulnerabilities have been discovered in Wireshark, a popular network protocol analyzer, affecting several versions in the 4.6.x branch. These flaws allow attackers to expl...
According to cybersecurity experts, there has been a significant increase in ransomware attacks powered by artificial intelligence technology. In the past several months, 7,831 vic...