
Increased Cybersecurity Threats Targeting Hikvision Cameras, LG Monitors, Hugging Face, and WordPress
On July 20, 2020, the SANS Internet Storm Center reported increased scanning activity targeting Hikvision cameras via their ISAPI (Intelligent Security API), specifically probing the system/status endpoint for reconnaissance. The REST API uses basic or digest authentication, and while no active exploitation was confirmed, the scans may precede brute-force attacks by checking for HTTP 400/401/403 errors. Separately, LG monitors were found installing On-Screen Control Plus software—classified as adware and spyware—via Windows Device Manager and Update, with McAfee ads prominently displayed; removal requires deleting registry hives. Hugging Face disclosed a breach where attackers exploited a code execution vulnerability in a data pipeline, then harvested cloud and cluster credentials, prompting users to rotate access tokens and review account activity. WordPress core versions 6.9 and 7.0 were identified as vulnerable to an unauthenticated SQL injection flaw in the REST API, with patches released to mitigate the remote code execution risk. The video also noted that disabling anonymous API access or using plugins could provide temporary protection.