LIVE · cybersecurity feed
Live wire
Security Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITIONWebmail CSS Attacks Expose a New Risk for AI-Powered Email ToolsMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and TokensCVE-2023-38646 · Metabase Zero-Day Exploited in Wild Allows Admin Access Without AuthenticationCVE-2026-18577 · N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
vulnerability

Black Hat USA: TP-Link Flaws Put Omada Controllers and Camera Feeds at Risk

Forescout disclosed 15 TP-Link flaws at Black Hat USA 2026 that could expose Omada credentials and VPN keys, allow internal access and affect VIGI camera feeds.

zeroday.news ·

At the recent Black Hat USA conference, researchers from Forescout disclosed a series of vulnerabilities impacting TP-Link Omada controllers and VIGI camera systems. The disclosure detailed 15 distinct flaws that could lead to the exposure of sensitive credentials, including those for Omada controllers and VPN keys. The vulnerabilities also reportedly create pathways for unauthorized internal network access and could compromise the integrity of VIGI camera feeds.

The reported vulnerabilities span a range of technical mechanisms, though specific details on each of the 15 flaws were not provided in the summary. Typically, such a number of disclosed vulnerabilities in a single product line can include issues like authentication bypasses, command injection flaws, insecure handling of sensitive data, or logical errors in the application's design. The mention of exposed credentials and VPN keys suggests potential weaknesses in cryptographic implementations, key management, or secure storage mechanisms within the Omada ecosystem.

The impact on VIGI camera feeds points to potential vulnerabilities in the streaming protocols, the camera's firmware, or the integration between the cameras and the Omada controller. This could manifest as unauthorized access to video streams, manipulation of feed data, or denial-of-service attacks affecting surveillance capabilities. Flaws allowing internal access often stem from improper network segmentation, misconfigurations, or vulnerabilities that permit an attacker to pivot from an internet-facing service into the internal network.

The affected products are TP-Link's Omada controllers, which are central management devices for TP-Link's business networking solutions, and their VIGI camera systems, which are part of their surveillance offerings. These products are commonly deployed in small to medium-sized businesses, educational institutions, and other environments requiring centralized network and security management. The nature of the flaws suggests that both the management plane and potentially the data plane of these systems could be at risk.

Mitigation guidance for this class of issues typically involves applying vendor-supplied patches and firmware updates as soon as they become available. Network segmentation is also crucial, isolating management interfaces and IoT devices like cameras from critical internal networks. Strong, unique passwords for all administrative accounts, multi-factor authentication where supported, and regular security audits of network configurations are also standard recommendations to reduce the attack surface.

The disclosure of these vulnerabilities at a prominent security conference like Black Hat USA underscores the ongoing challenges in securing interconnected network infrastructure and IoT devices. As more business operations rely on integrated network and surveillance systems, the security of foundational components like network controllers and cameras becomes paramount. This incident highlights the critical need for continuous security research and prompt vendor response to protect organizations from evolving cyber threats.

vulnerabilitycloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert won’t show you In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far a malware campaign spread. He walks through the research behind

breach

Hackers breach TrueConf to trojanize client installers with backdoors

The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]

malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 109

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums DarkSword’s Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting

zero-dayhigh

Security Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions Metabase Zero-Day Exploited in the Wild, […]

ransomware

Ransomware gangs skip the CEO, head straight for the 40-something IT manager

Gen Xers who feel triggered by this should remember to unplug the network cable and call the cops

css attackshigh

Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools

Researchers have discovered that CSS, typically used for styling web pages, can be weaponized in webmail clients to steal user credentials, hijack sessions, and manipulate AI tools. These attacks exploit vulnerabilities in how email clients handle HTML and CSS, allowing malicious styling to interact with the trusted interface. The research highlights risks for major services like Outlook, Gmail, and Yahoo Mail, particularly concerning AI integrations.