Yarbo Android and iOS applications contain hard-coded MQTT credentials (CVE-2026-10557) that, combined with missing cloud authorization controls (CVE-2026-7368), allow attackers to access global robot telemetry and issue unauthorized commands to any device in the fleet.
Hardcoded Credentials
5 posts
Yarbo Android/iOS Mobile Application and Cloud Infrastructure (CVE-2026-10557, CVE-2026-7368) - 7 minWeekly Recap — 2026-06-01 -> 2026-06-08
Trojanized Build Pipelines and Blind-Spot Appliances Redefine the Perimeter Attackers are bypassing traditional network defenses by compromising the tools developers use to build software and the AI assistants they rely on to write code. Campaigns like Mini Shai-Hulud and Miasma - The Spreading Blight flooded package registries with malicious code that steals cloud credentials and CI/CD tokens, while researchers proved that public AI agent skill marketplaces are completely ineffective at catching malicious add-ons. Nation-state actors and cybercriminals are simultaneously shifting their focus to blind spots in corporate networks and trusted platforms. The VerdantBamboo group exploited firewalls to bypass conditional access, while UNC3753 used IT impersonation to trick law firm employees into installing remote access tools, and Kali365 expanded its phishing infrastructure to steal multi-factor authentication tokens. Defenders must shift their focus from perimeter email filtering to securing the software build pipeline and monitoring edge appliances for anomalous traffic. Hunt for unexpected connections to cloud storage APIs and review developer environments for compromised packages or AI skills.
NAVTOR NavBox (CVE-2026-21404) NAVTOR NavBox versions 4.16.1.20 and prior contain a hard-coded credentials vulnerability (CVE-2026-21404) within the Windows Communication Foundation (SOAP) implementation. A local attacker can extract these credentials to authenticate against the SOAP interface, gaining access to privileged WCF methods to write or overwrite files within application-defined paths, potentially causing operational disruption.
CISA and Partners Urge Hardening Automatic Tank Gauge Systems (2026-06-02) CISA and partner agencies have observed unattributed malicious cyber activity targeting internet-exposed Automatic Tank Gauge (ATG) systems across multiple U.S. critical infrastructure sectors. Threat actors are leveraging authentication bypass, hardcoded credentials, and command execution vulnerabilities to gain administrative control, enabling them to manipulate tank parameters, disable safety alerts, and create denial-of-view conditions.
MacGregor Voyage Data Recorder (VDR) G4e (CVE-2026-42941, CVE-2026-42951, CVE-2026-44611 +2 more) CISA released an advisory detailing multiple vulnerabilities in Danelec's MacGregor Voyage Data Recorder (VDR) G4e devices, including default and hard-coded credentials, weak password hashing, and insecure file access. Exploitation of these flaws could allow an attacker on an adjacent network to gain full administrator access to the affected transportation sector devices. Danelec has released firmware version V5.250 to address these vulnerabilities.