<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Lightstar - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/lightstar/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 04 Sep 2026 03:24:07 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/lightstar/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Hard-coded Credentials in SmartIT Desktop Manager</title><link>https://feed.craftedsignal.io/briefs/2026-09-smartit-hardcoded-creds/</link><pubDate>Fri, 04 Sep 2026 03:24:07 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-smartit-hardcoded-creds/</guid><description>SmartIT Desktop Manager contains a hard-coded credentials vulnerability that allows unauthenticated remote attackers to retrieve SSH service account credentials for the SmartIT Agent via application source code.</description><content:encoded><![CDATA[<p>Lightstar SmartIT Desktop Manager is affected by a hard-coded credentials vulnerability (CVE-2026-85146). The vulnerability stems from the inclusion of SSH service account credentials directly within the application's source code. An unauthenticated remote attacker with access to the application binary or source code can extract these hard-coded secrets. Once obtained, the attacker can leverage these credentials to authenticate via SSH to any endpoint running the SmartIT Agent, potentially leading to full administrative control over the affected infrastructure. Given the critical nature of these credentials, this vulnerability poses a significant risk to organizations using the SmartIT Desktop Manager, as it provides a clear path for lateral movement and system compromise without requiring prior authentication.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated attackers to gain unauthorized SSH access to internal systems managed by SmartIT Agents. This can result in complete system compromise, data exfiltration, and the ability to persist within the environment, impacting any organization utilizing the SmartIT Desktop Manager platform.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all instances of SmartIT Desktop Manager and SmartIT Agent within the environment.</li>
<li>Contact Lightstar support to determine if a security update exists to remove hard-coded credentials.</li>
<li>If no patch is available, isolate systems running the SmartIT Agent from untrusted networks and restrict SSH access to authorized management segments.</li>
<li>Implement strict ingress filtering for SSH (TCP/22) to prevent unauthorized remote access using the exposed service account credentials.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>credential-exposure</category><category>remote-access</category></item></channel></rss>