ZeroHour

Search: “device code phishing”

15 items

CareCam Pro IP Cameras

CISA advisory details hard-coded bootloader credential CVE-2026-85083 in ANJIA AJL33PC0801 CareCam Pro cameras, allowing physical-access firmware compromise.

CISA ICS advisory ICSA-26-251-01 describes CVE-2026-85083, a hard-coded credential (CWE-798) used for bootloader authentication in the ANJIA AJL33PC0801 CareCam Pro IP camera. An attacker with physical access could gain privileged bootloader access and modify firmware and configuration, potentially fully compromising the device. The flaw scores 6.8 on CVSS 3.1 (7.0 on CVSS 4.0), is not remotely exploitable, and no public exploitation has been reported. Affected firmware is linux_linux_202008261138_svn13796 with U-Boot 2010.06; the vendor is headquartered in China with worldwide deployments.

CISA Advisories · 8d agoAdvisoryCVE-2026-85083

AI helps scammers build convincing antivirus renewal pages

Malwarebytes found scammers using AI to build polished fake antivirus renewal pages impersonating Avast, harvesting names, emails and phone numbers for follow-up fraud calls.

Malwarebytes analyzed a fake Avast renewal site targeting Belgian users in French, claiming a €129.99 Avast Premium Security renewal and collecting name, email address and Belgian mobile number through a cancellation form. Leftover code comments written in polite French and other stylistic clues suggest the page was generated with AI assistance, and the form was never connected to send data anywhere. The scam typically progresses to phone calls pressuring victims to install remote access software, and AI substantially lowers the barrier for producing polished, localized scam pages at scale.

Malwarebytes Labs · 16h agoPhishing & fraud

Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack

Cameron Curry sentenced to two years for stealing Brightly Software employee data and extorting the Siemens-owned firm for $7,540.92.

Cameron Nicholas Curry, a 27-year-old data analyst contractor at Siemens-owned Brightly Software, stole corporate and sensitive payroll data between August and December 2023 and sent more than 60 threatening emails to employees after his contract ended. He demanded roughly $2.5 million but received $7,540.92 in late January 2024, and was convicted of six counts of extortion in March. He was sentenced to two years in prison plus one year of supervised release, less than the 12-year maximum, after investigators traced him via operational security mistakes including a Coinbase account linked to family debit cards.

CyberScoop · Aug 13, 2026Policy & legal