Over 14,000 Dahua Cameras Compromised With Backdoors That Survive Factory Resets
Researchers at Hunt.io say a 35-day campaign compromised more than 14,000 internet-connected Dahua cameras, planting hidden administrator accounts and abusing cloud recovery codes that persist even through password...
FBI Dismantles Chinese State-Sponsored Botnet That Powered a Global Hacking Platform
The FBI and Department of Justice have seized the domains behind QScan and QTRouter, a pair of linked platforms that a Chinese state-sponsored group allegedly used to hijack...
Tenda Router Backdoor (CVE-2026-11405) Lets Attackers Skip Login and Seize Full Admin Control
A hardcoded authentication backdoor in Tenda FH1201, W15E, AC10, AC5, and AC6 routers (CVE-2026-11405) lets attackers log in as admin with any username. The undocumented flaw sits in...
Seven New CVEs in FatFs Filesystem Driver Put Millions of Embedded and IoT Devices at Risk
runZero has disclosed seven new CVEs in FatFs, the FAT/exFAT filesystem driver used across ESP-IDF, STM32Cube, Zephyr, MicroPython, and countless other embedded platforms. The bugs range from CVSS...
Critical wolfSSL Vulnerabilities Expose Billions of Servers and IoT Devices to Certificate Forgery and RCE
Multiple newly disclosed vulnerabilities in the wolfSSL embedded TLS library — including certificate trust bypasses, heap overflows, and post-quantum cryptography weaknesses — put billions of servers, IoT devices,...