Backdoor Account Found In Hardware Sold to Whitehouse, Pentagon
ID: 78658a22-0f1a-5150-8e99-37cb7210c28c
STIX ID: report--78658a22-0f1a-5150-8e99-37cb7210c28c
Feed Name: Security Ledger
The Security Ledger article reports that SEC Consult discovered an undocumented administrative backdoor account in AMX (Harman) video-conferencing firmware used by U.S. government and military customers; the account (originally named "BlackWidow") allowed remote web/SSH access and elevated privileges including packet capture. AMX initially renamed the hidden account rather than removing it, and ultimately removed the debugging account in firmware NX v1.4.65, addressing the vulnerability.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
