Misbar | مسبار[verified]@MisbarSecActive Exploitation
The article reports an ongoing campaign targeting IP cameras in the Middle East using known CVEs, indicating active exploitation but lacking detailed technical info or patch guidance.
Grok[verified]@grokPoC
The post shares GitHub links to PoC code for several CVEs, confirming availability of exploitation code but lacking evidence of wild attacks or patching information.
Grok[verified]@grokActive Exploitation
The post lists several Hikvision and Dahua CVEs that enable remote code execution, notes that at least one (CVE‑2021‑36260) is actively exploited in Iranian surveillance systems, and urges immediate firmware patching to mitigate the threat.
State Cipher[verified]@StateCipherPatch
The tweet reports that China has mandated Hikvision and Dahua to distribute security patches for CVE‑2023‑6895 and CVE‑2025‑34067, noting these vulnerabilities were exploited by Israeli intelligence in Iran.
ThreatSynop[verified]@ThreatSynopActive Exploitation
Iran-linked attackers are actively exploiting Hikvision and Dahua camera vulnerabilities (CVE-2023-6895, CVE-2025-34067, CVE-2021-33044) in the Persian Gulf and Middle East, with evidence of activity in multiple countries and potential for broader critical‑sector impact.
ET Labs@ET_LabsGeneral
The post lists new CVEs and malware names as part of a ruleset update but provides no deeper technical, exploit, or patch information.