Vendor
Hard-coded RSA-512 Mesh Key in TP-Link Deco Routers
1 TTP 1 CVEA hard-coded RSA-512 private key in TP-Link Deco mesh firmware allows adjacent attackers to impersonate trusted nodes, enabling unauthorized configuration changes and firmware modification.
Authenticated Remote Code Execution in TP-Link Archer BE800
1 TTP 1 CVEAn authenticated remote code execution vulnerability (CVE-2026-16348) in the TP-Link Archer BE800 management interface allows attackers with administrator privileges to execute arbitrary commands via shell injection in the VPN key field.
Authenticated OS Command Injection in TP-Link Archer C20 Routers
1 TTP 1 CVEAn authenticated OS command injection vulnerability, CVE-2026-75616, in TP-Link Archer C20 v6 routers allows an administrator to achieve root-level code execution via the BPA WAN configuration interface.
BadIIS Malware-as-a-Service Ecosystem Targeting IIS Servers
2 rules 1 TTP 6 IOCsA commodity BadIIS malware variant is fueling a thriving malware-as-a-service (MaaS) ecosystem for Chinese-speaking cybercrime groups, allowing them to execute malicious SEO fraud, hijack server content, and redirect traffic to illicit sites.
Adversaries Leveraging AI for Vulnerability Exploitation and Augmented Operations
2 rules 3 TTPsThreat actors are leveraging AI to enhance vulnerability discovery, exploit development, defense evasion, and autonomous operations, with state-sponsored groups showing particular interest in AI-driven vulnerability research and exploit generation.
Mirai Campaign Exploiting CVE-2025-29635 in D-Link Routers
2 rules 4 TTPs 2 CVEsA new Mirai-based malware campaign is exploiting CVE-2025-29635, a command-injection vulnerability affecting D-Link DIR-823X routers, to enlist devices into the botnet.