More than 60 Flock AI-powered surveillance cameras had their live streams exposed on the web without requiring a username or password. Critical vulnerabilities CVE-2025-59403 (Auth Bypass) and CVE-2025-59405 (Hardcoded Credentials) have been assigned. While the vendor claims a cloud fix, firmware remains vulnerable.
Vulnerability Details
Affected Product: Flock AI Surveillance Cameras
Identifier: CVE-2025-59403 & CVE-2025-59405
Exploitation Status: Trivial / Active Exposure
Risk & Impact
Triage: High Urgency
Attack Vector: Unprotected web access to live camera feeds.
Ease of Exploit: Trivial
Action Plan
Immediate Action: Secure all Flock AI camera feeds with proper authentication.
Workaround: Implement network segmentation to isolate camera feeds.
Detection: Monitor network traffic for unauthorized access to camera feeds.
Relevant professional terms
Surveillance Camera
A video camera used for observing an area.
Authentication
The process of verifying the identity of a user, device, or other entity.
The University of Phoenix suffered a data breach affecting approximately 3.5 million individuals after unauthorized access to its systems. The Clop ransomware group claimed responsibility, exploiting a zero-day vulnerability in the Oracle E-Business Suite (EBS).
Attack Overview
Attack Path: Exploitation of a zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite (EBS).
Attacker: Clop ransomware group.
Impact Assessment
Data Stolen: Sensitive personal and financial information, including names, contact information, dates of birth, Social Security numbers, and bank account details, of approximately 3.5 million individuals.
Uzbekistan's national license plate scanning system was exposed to the internet due to a lack of password protection. This allowed unauthorized access to sensitive data, including vehicle locations, driver images, and traffic violations.
Attack Overview
Attack Path: Unauthenticated access to the surveillance system via the internet.
Impact Assessment
Data Stolen: Terabytes of data (millions of records/events), including vehicle locations, driver images, and traffic violations.
Strategic Takeaway
The exposure highlights the critical need for robust access controls and security measures in national surveillance systems to protect sensitive personal data.
Relevant professional terms
ALPR (Automatic License Plate Recognition)
A technology that uses optical character recognition to automatically read vehicle license plates.
Surveillance System
A system used to monitor the activities, behavior, or other changing information, usually of people for the purpose of influence, management, direction, or protection.
The Urban VPN Proxy browser extension is intercepting and capturing user conversations across multiple AI platforms. This data harvesting is enabled by default, without a user-facing option to disable it, and operates continuously, regardless of VPN functionality.
Key TTPs
Initial Access: Users install the Urban VPN Proxy browser extension.
Execution: The extension uses dedicated "executor" scripts for each targeted AI platform to actively intercept and capture conversational data.
Defense Evasion: The harvesting is enabled by default with no user-facing toggle to disable.
Campaign Analysis
The extension injects code into supported AI websites, overriding standard browser network functions to capture prompts, responses, timestamps, and session identifiers. The collected data is then compressed and transmitted to analytics servers.
Targeting & Infrastructure
Target Profile: Users of AI platforms such as ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, DeepSeek, Grok (xAI), and Meta AI.
Infrastructure: The extension affects over 8 million users across Chrome and Edge.
Actionable Intelligence
IPs: N/A
Domains: N/A
Relevant Terms
Data Exfiltration: The unauthorized transfer of data from a computer or network to an external device or location.
Clickstream Data: A record of the websites a user has visited and the sequence of clicks they made while browsing the Internet.
The Evasive Panda APT group is conducting adversary-in-the-middle (AitM) attacks to deliver the MgBot implant. This campaign, active from November 2022 to November 2024, showcases the group's evolving tactics.
Key TTPs
Initial Access: Strategic website compromise and supply chain intrusion.
Execution: Uses shellcode encrypted with DPAPI and RC5 to deploy MgBot.
Defense Evasion: Employs a new loader to evade detection and uses hybrid encryption.
Campaign Analysis
Evasive Panda is improving its tactics by developing new loaders and employing hybrid encryption practices. The group leverages distinct implants for Windows (MgBot) and macOS (Macma).
Targeting & Infrastructure
Target Profile: Targets include government entities, NGOs, universities, and private individuals, primarily in Taiwan, Hong Kong, and mainland China.
Infrastructure: Compromised Internet service providers (ISPs) are used to distribute malicious software updates.
Actionable Intelligence
IPs:60.28.124.21, 123.139.57.103, 140.205.220.98
Relevant Terms
APT: An Advanced Persistent Threat (APT) is a sophisticated, long-term cyberattack targeting specific entities.
DNS Poisoning: A type of DNS attack where falsified DNS records are introduced to redirect traffic to malicious servers.
The WebRAT malware is being spread through GitHub repositories disguised as proof-of-concept exploits. This campaign targets users seeking game cheats, pirated software, and security researchers.
Key TTPs
Initial Access: Exploiting GitHub repositories with fake PoCs.
Execution: Dropper (rasmanesc.exe) elevates privileges and disables Windows Defender to download WebRAT.
Defense Evasion: Uses password-protected ZIP archives with decoy files.
Campaign Analysis
The malware is sold to cybercriminals, and discussions suggest it has been used for blackmail and swatting. WebRAT can deploy additional malicious payloads like cryptocurrency miners.
Targeting & Infrastructure
Target Profile: Gamers, users of pirated software, and security researchers.
Infrastructure: GitHub repositories, YouTube, and pirated software websites.
Nomani Scam Leverages AI Deepfakes for Investment Fraud
Executive Summary
The Nomani investment scam utilizes AI-generated deepfake videos and social media malvertising to deceive users into investing in fraudulent schemes. This campaign targets individuals through social media platforms, aiming to steal money and personal data.
Key TTPs
Initial Access: Fraudulent ads on social media platforms like Facebook and YouTube, often impersonating legitimate brands and trusted entities.
Execution: Victims are directed to phishing websites that mimic local news outlets or advertise cryptocurrency management tools.
Defense Evasion: Use of AI-generated video testimonials featuring well-known personalities to build trust.
Campaign Analysis
The Nomani scam has grown significantly, with a 62% increase in detections, expanding its reach beyond Facebook to other platforms. This campaign uses increasingly short-lived ad campaigns designed to churn identities and infrastructure faster than defenders can blacklist.
Targeting & Infrastructure
Target Profile: Individuals interested in investment opportunities, including those previously targeted by scams.
Infrastructure: Utilizes fake social media profiles, stolen legitimate accounts, and phishing websites mimicking trusted brands.