---
title: Advisories | 1898 & Co.
description: Stay informed on emerging threats and vulnerabilities with timely advisories from 1898 & Co.
image: https://1898advisories.burnsmcd.com/hubfs/AssetLens.jpg
---

[Skip to content](https://1898advisories.burnsmcd.com#main-content)

[![1898-logo-grey-R-1](https://1898advisories.burnsmcd.com/hs-fs/hubfs/1898-logo-grey-R-1.webp?width=188&height=100&name=1898-logo-grey-R-1.webp)](https://1898andco.burnsmcd.com/)

- [Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)
- [Threat Hunt](https://1898advisories.burnsmcd.com/tag/threat-hunt)
- [View All](https://1898advisories.burnsmcd.com/)

Open main navigation

Close main navigation

- [Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)
- [Threat Hunt](https://1898advisories.burnsmcd.com/tag/threat-hunt)
- [View All](https://1898advisories.burnsmcd.com/)
- [Contact Us](https://1898andco.burnsmcd.com/contact-us)

[Contact Us](https://1898andco.burnsmcd.com/contact-us)

#### Advisories

[Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)

## [Critical Unauthenticated Command Injection in Legacy VIVOTEK Network Camera Firmware](https://1898advisories.burnsmcd.com/critical-unauthenticated-command-injection-in-legacy-vivotek-network-camera-firmware)

 October 5, 2026

Security Advisory Brief On September 29, 2026, the Cybersecurity and Infrastructure Security Agency ...

[Read More](https://1898advisories.burnsmcd.com/critical-unauthenticated-command-injection-in-legacy-vivotek-network-camera-firmware)

[Threat Hunt](https://1898advisories.burnsmcd.com/tag/threat-hunt)

## [Threat Hunt Plan: VIVOTEK Network Camera Firmware — Unauthenticated Command Injection and Post-Exploitation Pivot](https://1898advisories.burnsmcd.com/threat-hunt-plan-vivotek-network-camera-firmware-unauthenticated-command-injection-and-post-exploitation-pivot-1)

 October 5, 2026

Date: 2026-10-02 | Revision 1.0 | Source: CISA ICS Advisory ICSA-26-272-03

[Read More](https://1898advisories.burnsmcd.com/threat-hunt-plan-vivotek-network-camera-firmware-unauthenticated-command-injection-and-post-exploitation-pivot-1)

[Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)

## [Actively Exploited Zero-Day Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway Used to Deploy Web Shells](https://1898advisories.burnsmcd.com/actively-exploited-zero-day-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway-used-to-deploy-web-shells)

 October 2, 2026

Security Advisory Brief Citrix has released security updates for two critical zero-day vulnerabiliti...

[Read More](https://1898advisories.burnsmcd.com/actively-exploited-zero-day-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway-used-to-deploy-web-shells)

[Threat Hunt](https://1898advisories.burnsmcd.com/tag/threat-hunt)

## [Threat Hunt Plan: ABB dynovaPRO and Keycloak Reset-Credentials Account Takeover — Identity, Cloud Session and DER Control Hunt](https://1898advisories.burnsmcd.com/threat-hunt-plan-abb-dynovapro-and-keycloak-reset-credentials-account-takeover-identity-cloud-session-and-der-control-hunt)

 September 23, 2026

Revision 1.1 — September 22, 2026

[Read More](https://1898advisories.burnsmcd.com/threat-hunt-plan-abb-dynovapro-and-keycloak-reset-credentials-account-takeover-identity-cloud-session-and-der-control-hunt)

[Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)

## [Keycloak Reset-Credentials Account Takeover Vulnerability in ABB dynovaPRO Energy Management Cloud](https://1898advisories.burnsmcd.com/keycloak-reset-credentials-account-takeover-vulnerability-in-abb-dynovapro-energy-management-cloud)

 September 23, 2026

Security Advisory Brief On September 17, 2026, ABB published a cyber security advisory for dynovaPRO...

[Read More](https://1898advisories.burnsmcd.com/keycloak-reset-credentials-account-takeover-vulnerability-in-abb-dynovapro-energy-management-cloud)

[Threat Hunt](https://1898advisories.burnsmcd.com/tag/threat-hunt)

## [Threat Hunt Plan: Check Point Quantum VPN Certificate-Path Exploitation — Unauthenticated RCE on Security Gateway and Security Management Server](https://1898advisories.burnsmcd.com/threat-hunt-plan-check-point-quantum-vpn-certificate-path-exploitation-unauthenticated-rce-on-security-gateway-and-security-management-server)

 September 11, 2026

Version 1.0 — September 11, 2026

[Read More](https://1898advisories.burnsmcd.com/threat-hunt-plan-check-point-quantum-vpn-certificate-path-exploitation-unauthenticated-rce-on-security-gateway-and-security-management-server)

[Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)

## [Critical VPN Certificate Validation Flaws in Check Point Quantum Security Gateway and Security Management Server Enabling Unauthenticated Remote Code Execution](https://1898advisories.burnsmcd.com/critical-vpn-certificate-validation-flaws-in-check-point-quantum-security-gateway-and-security-management-server-enabling-unauthenticated-remote-code-execution)

 September 11, 2026

Security Advisory Brief On September 9, 2026, Check Point Software Technologies disclosed two critic...

[Read More](https://1898advisories.burnsmcd.com/critical-vpn-certificate-validation-flaws-in-check-point-quantum-security-gateway-and-security-management-server-enabling-unauthenticated-remote-code-execution)

[Threat Hunt](https://1898advisories.burnsmcd.com/tag/threat-hunt)

## [Threat Hunt Plan: Rockwell Automation RSLinx Classic — Crafted CIP Message Service Crash and Loss of View](https://1898advisories.burnsmcd.com/threat-hunt-plan-rockwell-automation-rslinx-classic-crafted-cip-message-service-crash-and-loss-of-view)

 September 8, 2026

Date: 3 September 2026 | Revision 1.0

[Read More](https://1898advisories.burnsmcd.com/threat-hunt-plan-rockwell-automation-rslinx-classic-crafted-cip-message-service-crash-and-loss-of-view)

First Prev [1](https://1898advisories.burnsmcd.com/) [2](https://1898advisories.burnsmcd.com/page/2) [3](https://1898advisories.burnsmcd.com/page/3) [4](https://1898advisories.burnsmcd.com/page/4) [5](https://1898advisories.burnsmcd.com/page/5) [Next](https://1898advisories.burnsmcd.com/page/2) [Last](https://1898advisories.burnsmcd.com/page/22)

*The information in this cybersecurity advisory is provided "as is" for informational purposes only. 1898 & Co. does not provide any warranties or guarantees of any kind regarding this information. You assume all risks if you choose to rely on this information. In no event shall 1898 & Co. or its contractors or subcontractors be liable for any damages including, but not limited to, direct, indirect, special or consequential damages, arising out of, resulting from, or in any way connected with, this information, whether or not based upon warranty, contract, tort, or otherwise, whether or not arising out of negligence, and whether or not injury was sustained from, or arose out of the results of, or reliance upon the information*

*1898 & Co. does not endorse any product or service, except as expressly stated otherwise. Any reference to products or processes does not constitute or imply 1898 & Co.’s endorsement or recommendation.*

Subscribe

✕ Close

 

[Accessibility](https://1898andco.burnsmcd.com/accessibility)  |  [Privacy Statement](https://1898andco.burnsmcd.com/privacy)

© 2026 1898 & Co., a part of Burns & McDonnell. All Rights Reserved.