Skip to content
Threat Feed

Tag

Mqtt

7 briefs RSS
medium advisory

Detection of Unauthorized External MQTT Broker Connections

This brief describes the detection of anomalous MQTT traffic to external brokers, a communication channel leveraged by malware like BambooToken and WailingCrab for command and control.

network-security command-and-control mqtt bamboo-token wailing-crab
1r 1t
critical advisory

Multiple Security Vulnerabilities in Moquette MQTT Broker

Moquette-broker versions <= 0.18.0 are susceptible to cross-tenant ACL bypass, remote unauthenticated denial-of-service, and cross-session durable storage corruption.

moquette-broker mqtt broker authentication-bypass dos
1c
high threat

Toy Ghouls Deploying Custom HiveMQ and Matrix-Based Backdoors

The threat actor Toy Ghouls is using WinRM to deploy custom 'Bird' backdoors that utilize HiveMQ MQTT brokers and the Matrix protocol for C2, featuring machine-bound encrypted configurations.

Toy Ghouls backdoors persistence winrm c2 mqtt
1r 3t 1i
critical advisory

Unauthenticated Remote Access to Phoenix Contact CHARX SEC MQTT Broker

A critical vulnerability (CVE-2026-44090) in Phoenix Contact CHARX SEC controllers allows unauthenticated remote attackers to gain full device control by bypassing authentication on the MQTT broker.

CHARX SEC-3150 +7 industrial-control-systems mqtt cve-2026-44091 ics cve injection authentication-bypass cve-2026-44100 +14
2r 5t 12c
high threat

NATS Server Authorization Bypass Vulnerability (CVE-2026-58252)

CVE-2026-58252 identifies an authorization bypass vulnerability in NATS Server, described as a 'Subscribe Authz Bypass via Wildcard-Overlap', which allows unauthorized access or actions by exploiting how wildcard subscriptions are handled.

exploited NATS Server authorization-bypass cve nats server vulnerability mqtt information-disclosure filter-bypass +1
2t 1c
high advisory

NATS.io MQTT ACL Bypass Vulnerability

A vulnerability in NATS.io versions before v2.12.6 or v2.11.15 allows MQTT clients to bypass ACL checks for MQTT subjects due to ACLs not being applied in the `$MQTT.>` namespace, potentially allowing unauthorized access and control of MQTT communications.

NATS server nats.io mqtt acl-bypass vulnerability
2r 1t
high advisory

NATS Server MQTT Password Disclosure Vulnerability

The NATS server exposes MQTT passwords in plaintext via monitoring endpoints due to incorrect classification as JWTs, affecting versions before v2.12.6 or v2.11.15.

NATS server nats mqtt credential-access vulnerability
3r 1t