๐ต๏ธ RESEARCH & DEEP DIVES
-
Hunt.io Reconstructs Russian-Speaking Toolkit Targeting Ukrainian IP Cameras Hunt.io researchers reconstructed a toolkit used to compromise Ukrainian IP cameras.
- Internet-exposed Ukrainian IP cameras were targeted, with live-view sessions recorded from 58 cameras.
- The toolkit targeted Hikvision, Dahua, D-Link, and Reolink cameras affected by
CVE-2017-7921,CVE-2021-36260,CVE-2021-33044,CVE-2021-33045,CVE-2020-25078, andCVE-2020-25169. - A FastAPI/Docker project called camview wrapped the open-source Ingram scanner.
- The operator brute-forced HTTP and RTSP credentials using a 3,811-pair dictionary.
- The toolkit transcoded RTSP streams into MJPEG for browser viewing. ๐ Coverage: hunt.io ยท ๐ via r/netsec
-
Picus Finds Play Ransomware Evaded Most Security Controls in 2026 Tests Picus found Play ransomware had the lowest prevention score among 10 tested ransomware families.
- The analysis covered Play, BlackByte, LockBit, BabLock, Magniber, FAUST, Sodinokibi/REvil, Hive, BlackKingdom, and Maori.
- Play achieved a 13% prevention score, while the other families scored 25% to 38%.
- Ransomware families used obfuscation, process injection, masquerading, registry modification, and reflective code loading.
- BabLock disabled security and backup services and cleared Windows event logs; LockBit 5.0 patched ETW telemetry.
- Magniber used thread hijacking and in-memory .NET loading, while Play masqueraded tools and services as legitimate utilities. ๐ Coverage: cyberpress.org ยท ๐ via securityboulevard.com (discovered)
๐ CVEs & KEV
- Other โ 18 CVEs (worst 10.0)