A critical security vulnerability affecting KMW CCTV cameras has been disclosed under CVE-2026-5386. The flaw allows attackers to bypass authentication controls and change device credentials without proper verification, potentially granting full access to surveillance systems. The vulnerability received a CVSS v3 score of 9.1, reflecting its high severity and the significant risks it poses to organizations that depend on CCTV infrastructure for security monitoring. The vulnerability originates from an unverified password change mechanism within affected KMW CCTV devices. Due to insufficient validation during credential modification operations, an attacker can alter passwords without successfully authenticating to the device. Once access is obtained, threat actors may gain administrative control over the camera, view live video streams, and modify system configurations. According to the advisory, the issue impacts KM-IP521 devices running firmware IPCAM_V4.04.91.230307 and KM-IP421 devices running IPCAM_V4.04.53.210416. Because these products are deployed across critical infrastructure sectors, exploitation could facilitate unauthorized surveillance, intelligence gathering, operational disruption, or preparation for broader attacks against enterprise environments. Although no active exploitation has been reported at the time of disclosure, the simplicity and impact of the flaw make it an attractive target for cybercriminals and nation-state actors alike. The vulnerability was reported to CISA by security researcher Souvik Kandar.
A recently disclosed supply chain vulnerability in Anthropic’s Claude Code GitHub Actions integration exposed numerous repositories to potential compromise through a single malic...
A critical vulnerability, tracked as CVE-2026-4387, has been disclosed in StrongDM, exposing organizations to authentication token theft and session hijacking. Discovered by Specte...
Researchers have uncovered a sophisticated malware campaign by the Chinese state-sponsored threat group Mustang Panda, which leverages its well-known PlugX Remote Access Trojan (RA...