Search/intercom
Vendor

intercom

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
intercom
Connections
7 relationships
How to protect yourself from webcam spying: five simple steps | Kaspersky official blog
These days, it can feel like there’s a camera watching us from every corner: a video doorbell by the front door, a laptop webcam in the home office, an IP baby monitor in the children’s room, a smart TV with a camera and microphone in the bedroom, a robot vacuum with a navigation camera roaming around the house… Even a smart cat feeder could be spying on you! And any one of these cameras can easily become a useful tool for extortionists, blackmailers, or simply curious malicious actors. You don’t have to look far for examples. South Korea, late 2025: not one device, but 120,000 IP cameras were hacked . The criminals sold intimate footage and recordings of people’s everyday lives by subscription in private chats. In this article, we look at exactly where the threat comes from, and outline five rules that can greatly reduce your chances of becoming the star of a voyeur’s show. Real-life cases of surveillance Hotel porn by subscription Unfortunately, reports of miniature cameras being discovered in hotel rooms and rental apartments have become almost routine. Technically, these belong to a separate category of devices — “spy cameras” disguised as power outlets, smoke detectors, or alarm clocks. We’ll explain a little later how to detect them. Criminals don’t just publish footage from spy cameras — they even livestream it. Access to intimate videos, naturally, isn’t free. In some regions, criminals have built an entire infrastructure around spy cameras: some people install the cameras, others process the footage, while still others sell access through the dark web or messaging apps. Victims typically discover that there was a hidden camera in their hotel room purely by accident , after coming across videos of themselves on porn sites. Hunting motorists Another popular attack vector is hacking dashcams that can connect to the internet. These devices are tempting targets for attackers: their security is often weak, while the footage clearly shows license plates, road signs, and addresses on buildings. The recordings also contain detailed metadata, including exact dates, GPS coordinates, and more. This can allow criminals to identify a victim’s regular routes, determine where their car is parked, or even eavesdrop on conversations with passengers. There can be enough information for full-scale surveillance, car theft, or even blackmail if the camera records conversations and video inside the car. Stalking Not all stolen camera footage is the result of attacks by professional cybercriminals looking to profit from it. Sometimes, stalkers hack webcams to spy on specific people — often someone they know. For example, in 2025 a case came to light in which a man had been spying on his colleagues for years through their home IP cameras. All of the victims were women, who had no idea they were being watched. In another case, a man monitored his ex-wife and daughter through an intercom system and IP cameras. He made no attempt to hide the fact that he was spying on his own family, and even sent his daughter screenshots from the webcam. As a result, she eventually had to move away. Why does this happen? Neglecting basic cybersecurity rules This is probably the main reason IP cameras get hacked. Most users never change the factory-default passwords on their routers, smart devices, or the apps connected to them. Such passwords are essentially public knowledge. They often use simple combinations such as “admin/admin” or “root/1234”, which are known worldwide and can be guessed in a matter of seconds — no sophisticated algorithm is required. This is exactly what recently allowed attackers to hack 120,000 cameras in South Korea. Irresponsible camera manufacturers Even when manufacturers give assurances that camera data is stored only locally, in practice this is often far from the truth. For example, in 2022 researchers discovered that one popular range of video cameras sent snapshots to the manufacturer’s server every time a person appeared in the frame . And that wasn’t all: remote access to all cameras’ recordings was available through URLs generated in a predictable way — making them relatively easy to generate or guess. At the same time, the company claimed that its cameras used end-to-end encryption, stored recordings exclusively on the device, and didn’t transmit data to external servers. Incidentally, the supposedly “secure encryption” was implemented using a fixed key that was identical for every user. And the key itself could easily be found in the source code published by the manufacturer. In short, if a device has a lens and Wi-Fi, be prepared for the possibility that sooner or later a serious security flaw will be discovered in it. Search engines for vulnerable devices are becoming increasingly popular To access a camera, an attacker often only needs to know its IP address and try a handful of common passwords. There are search engines that index not websites, but devices and their open ports: webcams, routers, industrial controllers, medical equipment — you name it. If an IP camera requires no username and password, or is “protected” by the default “admin/admin” credentials, it may easily be discovered and added to the database of an OSINT service. Journalists and researchers have used such services to find publicly accessible cameras in children’s rooms, offices, hospital operating rooms, banks, and shops. So what can you do? What can you do at home or in a small office without a dedicated security team? These five simple recommendations can help. 1. Research the manufacturer When choosing an IP camera model, make sure you check whether cameras from that manufacturer have been hacked before — for example, by searching for “IP camera hack manufacturer name “. Then visit the Support section of the manufacturer’s website and check the date of the most recent firmware update both for the model you are considering and older models. If you find that firmware has not been updated for more than six months, or that updates are released irregularly, you may want to choose a different model. Most cameras run specialized embedded versions of Linux, and more than 2,300 vulnerabilities were recorded in the Linux kernel in the first six months of 2026 alone. If a manufacturer fails to update its firmware regularly, sooner or later a security hole is almost certain to appear in its cameras. Consider models from major manufacturers if you don’t want to end up with a whole collection of vulnerabilities and virtually no chance of them ever being patched. Cheap cameras from obscure companies with limited functionality and weak protection can ultimately cost you dearly. 2. Disable unnecessary features The fewer third-party cloud storage services involved in your surveillance system, the better. When choosing a camera, look for a microSD card slot, or support for a home network-attached storage device (NAS), so you can store all recordings locally. Ideally, the camera should be able to operate entirely within your local network without transmitting data to the cloud or the manufacturer’s servers — with viewing available over the LAN or through a secure connection  to your home or office. When buying other smart home appliances, consider whether you really need a built-in camera in, say, a smart TV, smart speaker , robot vacuum , or automatic pet feeder . Each and every one of these devices expands the potential attack surface. After buying an IP camera, go through its settings — usually available in the manufacturer’s app or through the camera’s web interface — and disable anything you don’t need. Pay attention to features related to person recognition, artificial intelligence, system permissions, discovery of other devices on the network, and cloud storage. If you don’t use a feature, feel free to disable it. In the network settings, make sure UPnP (Universal Plug and Play) is disabled or even absent as an option. UPnP can allow the camera to make itself accessible to other devices over the internet. Check that P2P access to the webcam is disabled or unavailable, so that the camera does not connect to external servers and cannot be reached from the internet without your direct control. Make a habit of checking who’s logged into your account and who still has access to your recordings. If you gave a friend access to your webcam so they could keep an eye on your dog while you’re away, remember to remove any unnecessary sessions afterwards. And if you’ve recently ended a relationship, pay particularly close attention to whether an ex-partner still has access. For more on this, see Post-breakup digital hygiene: what to check and shut down . 3. Change the default settings Factory-default passwords have been known to attackers for years. If you haven’t changed the username and password for your router or IP camera, an attacker may be able to gain access in a matter of seconds. Replace your router’s factory-default username and password with unique, long credentials. You can do this through the router’s web interface — we explain how to access it below. To generate and store strong, unique passwords, we recommend using Kaspersky Password Manager . If your camera is linked to an account on a website or in an app, make sure you use a strong password there too, and enable two-factor authentication or passkey authentication whenever possible. By the way, both 2FA tokens and passkeys can also be stored in Kaspersky Password Manager  and synchronized across all your devices. Update the firmware on both your router and IP camera to the latest versions, even if you just bought the device, and make regular updates a habit. Large-scale IP camera hacking campaigns often exploit long-known vulnerabilities that can only be fixed by installing updates. 4. Put all cameras and smart devices on a separate Wi-Fi segment We recommend segmenting your home Wi-Fi into separate subnets. You’ve probably encountered this arrangement in cafés, which often have one Wi-Fi network for staff and another for guests. All IP cameras and other smart home gadgets should ideally be moved to a separate Wi-Fi network and completely isolated from laptops, phones, and other work devices. Better still, IP cameras should be isolated from all other devices by creating a dedicated Wi-Fi network specifically for them. Most modern routers allow you to create at least two Wi-Fi networks — a primary network and a guest network — while more advanced models can support more. That way, even if your camera is hacked, the attacker won’t be able to reach your other devices or access sensitive files. How to open your router’s web interface Enter the router’s IP address in your browser’s address bar. It is usually printed on a label on the bottom of the router. Common IP addresses for home routers include 168.0.1 , 192.168.1.1 , and 10.0.0.1. Sign in on the page that opens. Most routers have a default username and password, which are usually also printed on the same label. Some routers may ask you to create your own username and password. We recommend choosing a strong one and storing it in Kaspersky Password Manager . Factory-default passwords have long been known to attackers, and if you don’t change your router password, they may be able to get into your home network with ease. Open the settings and look for sections related to Wi-Fi segmentation or the creation of subnets or guest networks. For detailed setup instructions, consult your router’s manual or the support section of the manufacturer’s website. For more advice on protecting your smart home, see our post How to secure your smart home . 5. Learn how to detect hidden cameras — both at home and while traveling Our final set of recommendations is not about configuring the camera itself, but about good security hygiene. Make a habit of checking the client list on your router. If you see an unknown device with a strange name or MAC address, investigate what it is and why it’s connected to your home network. Our security solution  includes a dedicated Smart Home Monitor component . This feature can alert you when a new device connects to your home wired or wireless network, provide simple recommendations for improving home network security, and identify weak router passwords and insecure encryption. When traveling, we recommend checking hotel rooms and rental properties for hidden recording devices: inspect places that offer a “convenient” view of the room, such as ventilation grilles, smoke detectors, power outlets, and decorative objects; in the dark, use your smartphone as an improvised optical detector: turn on the flashlight and camera, slowly scan the room, and look for distinctive reflections from a camera lens; use the front-facing camera to look for infrared light sources that are invisible to the human eye — this can help you spot the IR illumination used for “night vision”. For more practical methods of finding spy cameras, see our article Four ways to find spy cameras . What else you should know about surveillance and cameras: Korean-style webcam breach: 120 000 IP cameras hacked IP camera security: the bad, the ugly, and the evil Airbnb security: tips for safe travel Lumos: IoT device detection system Finding hidden cameras with your smartphone’s ToF sensor
kaspersky.comAug 19, 2026extracted
1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, Intercom
Over 1,800 developers were affected by the Mini Shai-Hulud supply chain attack that hit the PyPi, NPM, and PHP ecosystems over the past two days. Attributed to the TeamPCP hacking group, the campaign was first spotted on April 29, after malicious versions of four SAP NPM packages were caught delivering information-stealing malware and attempting to propagate to other packages. The malware would collect credentials, keys, tokens, and other secrets from the infected machines and publish the data to GitHub repositories containing the hardcoded description “A Mini Shai-Hulud has Appeared”. The same description has been used in a fresh round of infections linked to the compromise of the Lightning PyPi package and the intercom-client NPM package, which have a combined monthly download count of nearly 10 million. According to Ox Security, over 1,800 repositories containing stolen developer credentials have been created as part of the Mini Shai-Hulud attacks. The campaign appears to be a continuation of the Shai-Hulud supply chain attacks from late 2025. As part of the supply chain attack, the Lightning Python package versions 2.6.2 and 2.6.3 and the intercom-client NPM package versions 7.0.4 and 7.0.5 were injected with the information stealer. Additionally, the supply chain attack expanded to Packagist, through intercom-php version 5.0.2. A popular PHP package, intercom-php had over 20 million lifetime downloads. The Intercom compromise was a direct result of the Lightning supply chain attack. A local package installation used the infected Lightning PyPi package as a dependency, Socket reports. In addition to the malicious functions observed in the SAP compromise, the Lightning and Intercom payload added a dedicated infrastructure for data exfiltration, the zero[.]masscan[.]cloud domain, cybersecurity firm Wiz notes. The code also implements a dynamic fallback mechanism that searches GitHub for commits containing the ‘beautifulcastle’ and ‘EveryBoiWeBuildIsAWormyBoi’ strings to retrieve embedded command-and-control (C&C) commands, NetSkope says. Additionally, Wiz has observed the intercom-client payload actively scanning for Kubernetes environments and HashiCorp Vault secrets. “It queries Kubernetes service endpoints and Vault configurations, using extensive regex-based matching to extract credentials such as AWS keys, GitHub and npm tokens, database connection strings, private keys, and API secrets (e.g., Stripe, Slack, Twilio),” Wiz says. According to Aikido, the information stealer also targets VPN credentials, cryptocurrency wallet data, and Discord and Slack session data. Related: AI Fuels ‘Industrial’ Cybercrime as Time-to-Exploit Shrinks to Hours Related: Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks Related: Checkmarx Confirms Data Stolen in Supply Chain Attack Related: Critical GitHub Vulnerability Exposed Millions of Repositories
securityweek.comMay 1, 2026extracted
The never-ending supply chain attacks worm into SAP npm packages, other dev tools
SAAS Salesforce partners not seeing meaningful revenue from Agentforce AI platform, report saysShow us the money ai and ml AI companies are burning books, advocates complain to FTCFahrenheit 203, the temperature GPUs stop gorging on literature DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
go.theregister.comApr 30, 2026extracted
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
New research from Broadcom's Symantec and Carbon Black Threat Hunter Team has discovered evidence of an Iranian hacking group embedding itself in several U.S. companies' networks, including banks, airports, non-profit, and the Israeli arm of a software company. The activity has been attributed to a state-sponsored hacking group called MuddyWater (aka Seedworm). It's affiliated with the Iranian Ministry of Intelligence and Security (MOIS). The campaign is assessed to have begun in early February, with recent activity detected following U.S. and Israeli military strikes on Iran. "The software company is a supplier to the defense and aerospace industries, among others, and has a presence in Israel, with the company's Israel operation seeming to be the target in this activity," the security vendor said in a report shared with The Hacker News. The attacks targeting the software company, as well as a U.S. bank and a Canadian non-profit, have been found to pave the way for a previously unknown backdoor dubbed Dindoor, which leverages the Deno JavaScript runtime for execution. Broadcom said it also identified an attempt to exfiltrate data from the software company using the Rclone utility to a Wasabi cloud storage bucket. However, it's currently not known if the effort paid off. Also found in the networks of a U.S. airport and a non-profit was a separate Python backdoor called Fakeset, which was downloaded from servers belonging to Backblaze, an American cloud storage and data backup company. The digital certificate used to sign Fakeset has also been used to sign Stagecomp and Darkcomp malware, both previously linked to MuddyWater. Brigid O Gorman, senior intelligence analyst, Symantec and Carbon Black Threat Hunter Team, said Microsoft and Kaspersky have detected samples associated with the Stagecomp and the Darkcomp malware with Muddywater-linked signatures – "Trojan:Python/MuddyWater.DB!MTB" for Microsoft and "Backdoor.Python.MuddyWater.a" for Kaspersky. "While this malware wasn't seen on the targeted networks, the use of the same certificates suggests the same actor -- namely Seedworm -- was behind the activity on the networks of the U.S. companies," Symantec and Carbon Black said. "Iranian threat actors have become increasingly proficient in recent years. Not only has their tooling and malware improved, but they've also demonstrated strong social engineering capabilities, including spear-phishing campaigns and 'honeytrap' operations used to build relationships with targets of interest to gain access to accounts or sensitive information." The findings come against the backdrop of an escalating military conflict in Iran, triggering a barrage of cyber attacks in the digital sphere. Recent research from Check Point has uncovered the pro-Palestinian hacktivist group known as Handala Hack (aka Void Manticore) routing its operations through Starlink IP ranges to probe externally facing applications for misconfigurations and weak credentials. In recent months, multiple Iran-nexus adversaries, such as Agrius (aka Agonizing Serpens, Marshtreader, and Pink Sandstorm), have also observed scanning for vulnerable Hikvision cameras and video intercom solutions using known security flaws such as CVE-2017-7921 and CVE-2023-6895. The targeting, per Check Point, has intensified in the wake of the current Middle East conflict. The exploitation attempts against IP cameras have witnessed a surge in Israel and Gulf countries, including the U.A.E., Qatar, Bahrain, and Kuwait, along with Lebanon and Cyprus. The activity has singled out cameras from Dahua and Hikvision, weaponizing the two aforementioned vulnerabilities, as well as CVE-2021-36260, CVE-2025-34067, and CVE-2021-33044. "Taken together, these findings are consistent with the assessment that Iran, as part of its doctrine, leverages camera compromise for operational support and ongoing battle damage assessment (BDA) for missile operations, potentially in some cases prior to missile launches," the company said. "As a result, tracking camera-targeting activity from specific, attributed infrastructures may serve as an early indicator of potential follow-on kinetic activity." The U.S. and Israel's war with Iran has also prompted an advisory from the Canadian Centre for Cyber Security (CCCS), which cautioned that Iran will likely use its cyber apparatus to stage retaliatory attacks against critical infrastructure and information operations to further the regime's interests. Some other key developments that have unfolded in recent days are listed below - Israeli intelligence agencies hacked into Tehran's extensive traffic camera network for years to monitor the movements of bodyguards of Ayatollah Ali Khamenei and other top Iranian officials in the lead up to the assassination of the supreme leader last week, the Financial Times reported. Iran's Islamic Revolutionary Guard Corps (IRGC) targeted Amazon's data center in Bahrain for the company's support of the "enemy's military and intelligence activities," state media Fars News Agency said on Telegram. Active wiper campaigns are said to be underway against Israeli energy, financial, government, and utilities sectors. "Iran's wiper arsenal includes 15+ families (ZeroCleare, Meteor, Dustman, DEADWOOD, Apostle, BFG Agonizer, MultiLayer, PartialWasher, and others)," Anomali said. Iranian state-sponsored APT groups like MuddyWater, Charming Kitten, OilRig, Elfin, and Fox Kitten "demonstrated clear signs of activation and rapid retooling, positioning themselves for retaliatory operations amid the escalating conflict," LevelBlue said, adding "cyber represents one of Iran's most accessible asymmetric tools for retaliation against Gulf states that condemned its attacks and support U.S. operations." According to Flashpoint, a massive #OpIsrael cyber campaign involving pro-Russian and pro-Iranian actors has targeted Israeli industrial control systems (ICS) and government portals across Kuwait, Jordan, and Bahrain. The campaign is driven by NoName057(16), Handala Hack, Fatemiyoun Electronic Team, and Cyber Islamic Resistance (aka 313 Team). Between 28 February 2026 and 2 March 2026, pro-Russia hacktivist group Z-Pentest claimed responsibility for compromising several U.S.-based entities, including ICS and SCADA systems and multiple CCTV networks. "The timing of these unverified claims, coinciding with Operation Epic Fury, suggests Z-Pentest likely began prioritizing U.S. entities as targets," Adam Meyers, head of Counter Adversary Operations at CrowdStrike, told The Hacker News. "Iran's offensive cyber capability has matured into a durable instrument of state power used to support intelligence collection, regional influence, and strategic signaling during periods of geopolitical tension," UltraViolet Cyber said. "A defining feature of Iran's current cyber doctrine is its emphasis on identity and cloud control planes as the primary attack surface." "Rather than prioritizing zero-day exploitation or highly novel malware at scale, Iranian operators tend to focus on repeatable access techniques such as credential theft, password spraying, and social engineering, followed by persistence through widely deployed enterprise services." Organizations are advised to bolster their cybersecurity posture, strengthen monitoring capabilities, limit exposure to the internet, disable remote access to operational technology (OT) systems, enforce phishing-resistant multi-factor authentication (MFA), implement network segmentation, take offline backups, and ensure that all internet-facing applications, VPN gateways, and edge devices are up-to-date "Western organizations should continue to remain on high-alert for potential cyber response as the conflict continues and activity may move beyond hacktivism and into destructive operations," Meyers said.
thehackernews.comMar 6, 2026extracted