SANS Stormcast Friday, July 17th, 2026: Hikvision Scans; LG Spyware; Huggingface Hack; Wordpress Core RCE
7 min
•Jul 20, 20269 days agoSummary
This Stormcast episode covers four critical cybersecurity threats: reconnaissance scans targeting Hikvision camera APIs, LG monitors installing adware/spyware via Windows Update, a breach at HuggingFace involving AI-led attacks, and a WordPress core RCE vulnerability exploitable via REST API without authentication.
Insights
- Hardware manufacturers can exploit legitimate OS update mechanisms to install unwanted software, making removal difficult and affecting users long after purchase
- Reconnaissance scans on specific API endpoints may indicate attackers discovering new attack vectors before widespread exploitation
- AI platforms are vulnerable to supply chain attacks through data pipeline poisoning that can lead to credential harvesting
- WordPress core vulnerabilities are rare but critical; disabling anonymous REST API access is a practical interim mitigation
- Security researchers are increasingly using AI tools to analyze incidents, creating a feedback loop in cybersecurity defense
Trends
Hardware-based supply chain attacks leveraging OS update mechanismsReconnaissance scanning for API fingerprinting before exploitation attemptsAI-led attacks targeting AI infrastructure platformsSQL injection vulnerabilities in REST APIs as persistent attack vectorsDifficulty in removing manufacturer-installed software creating long-term exposureAggressive monetization through adware bundled with legitimate driversIncreased focus on API security and access control in web applications
Topics
Hikvision Open Intelligent Security API reconnaissanceWindows Device Manager and Windows Update exploitationLG monitor adware and spyware distributionHuggingFace data pipeline security breachAI-led attack methodologyWordPress REST API SQL injection vulnerabilityUnauthenticated remote code executionAPI endpoint fingerprinting techniquesRegistry-level malware removalCloud credential harvestingAccess token rotation proceduresREST API access control policies
Companies
Hikvision
Reconnaissance scans detected targeting their Open Intelligent Security API used for remote camera control and config...
LG
Monitors installing adware and spyware via Windows Update mechanism, including OnScreen Control Plus software difficu...
HuggingFace
AI community platform breached via AI-led attack through data pipeline vulnerability, compromising credentials and cl...
WordPress
Core platform affected by SQL injection vulnerability in REST API allowing unauthenticated remote code execution
McAfee
Antivirus software being promoted as primary advertisement through LG monitor adware installation
Searchlight Cyber
Security research team that discovered and disclosed the WordPress core RCE vulnerability
GamerNexus
Technology publication that investigated LG monitor adware in detail and examined other LG smart TV practices
Windows
Operating system whose Device Manager and Update mechanisms are exploited by LG to install unwanted software
People
Johannes Ulrich
Host recording the Stormcast episode from Jacksonville, Florida
Quotes
"This API, often abbreviated as IS API, is used essentially to remote control these cameras and configure them. It's a fairly straightforward REST API using basic or digest authentication."
Johannes Ulrich•Early in episode
"The manufacturer can install whatever software they wish on your system and lg took it upon themselves to basically show us how far you can push this feature"
Johannes Ulrich•LG discussion
"A full AI agent-led attack that did compromise HackingFace"
Johannes Ulrich•HuggingFace breach discussion
"It can be exploited without authentication via the WordPress REST API"
Johannes Ulrich•WordPress vulnerability discussion
Full Transcript