CISA issued multiple ICS advisories covering Brickcom cameras, the Yarbo mobile app and cloud MQTT infrastructure, and the Naxclow IoT Platform, warning that weak authentication, default credentials, and hard-coded secrets could expose connected devices to takeover and surveillance. The Brickcom advisory said affected Cube, Dome, Bullet, and Box cameras running version 3.2.3.5.6 allow unauthenticated access to live snapshots through the /ONVIF endpoint and may ship with default credentials that permit administrative control and silent viewing of camera feeds. In Yarbo’s case, hard-coded MQTT broker credentials embedded in Android and iOS apps, combined with missing cloud authorization checks, could let attackers access telemetry from the global robot fleet and potentially issue commands to any robot using only its serial number.
CISA also detailed multiple vulnerabilities across all versions of Naxclow products including the Smart Doorbell X3, X Smart Home, V720, and ix cam, where authorization bypasses, predictable device identifiers, exposed relay credentials, and an exposed UART console could enable impersonation, fleet enumeration, interception of communications, and theft of Wi-Fi credentials. The most severe Naxclow issue, CVE-2026-28742, stems from a hard-coded platform-wide salt used for request signing and carries a CVSS 9.8 rating because a secret extracted from one device could be used to forge requests across the platform. Reporting indicates Naxclow had not responded and no official patch was available, while CISA said it had no evidence of public exploitation for any of the disclosed issues and urged organizations to reduce internet exposure, segment networks, and use secure remote access controls.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-16, SecurityOnline reported that CISA's Naxclow disclosure covered seven vulnerabilities affecting all versions of four product lines and said Naxclow had not responded, leaving no official patch available. The report highlighted risks including device takeover, video interception, and Wi-Fi credential theft.
On 2026-06-11, CISA published an advisory describing two high-severity vulnerabilities in Brickcom Cube, Dome, Bullet, and Box cameras running version 3.2.3.5.6. The issues involve missing authentication and default credentials that could allow unauthenticated access to live snapshots and administrative control; CISA also noted proof-of-concept material and no known public exploitation at publication.
On 2026-06-11, CISA published an advisory on multiple vulnerabilities affecting the Naxclow IoT Platform and associated products, including authorization bypass, hard-coded cryptographic material, predictable identifiers, and exposed UART access. CISA said Temuri Takalandze reported the vulnerabilities and that no known public exploitation had been reported at the time of publication.
On 2026-06-11, CISA published an advisory covering critical vulnerabilities in the Yarbo Android/iOS mobile application and cloud MQTT infrastructure, including hard-coded broker credentials and missing authorization controls. CISA said Markus Lassfolk of Truesec reported the issues and that no known public exploitation had been reported at the time of publication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.