Urgent Patches for Ivanti Sentry and IoT Security

Let me ask you something: Have you ever left your office for the day and had that nagging feeling that you forgot to lock the back door?

It’s an uncomfortable itch at the back of your mind.

You know that if a door is open, someone will eventually try the handle.

In the digital world, that door isn't just your front entrance.

It's your mobile device manager, your office cameras, and even your smart doorbells.

Right now, the Cybersecurity and Infrastructure Security Agency (CISA) is ringing the alarm bells.

Two major "doors" have been left wide open, and hackers aren't just trying the handle: they’re already walking inside.

Platinum Insight

For Ivanti Sentry: If your business uses Ivanti Sentry to manage mobile devices, you need to stop what you are doing and patch it immediately.

Cybercriminals are actively using a flaw (CVE-2026-10520) to take complete control of systems.

This isn't a "wait until the weekend" update.

For IoT and Cameras: Your office cameras and smart devices are often the weakest link in your security chain.

Recent advisories for Brickcom and Naxclow devices show how easy it is for hackers to turn your security tools against you.

Start by changing every default password and keeping your firmware updated.

It’s the simplest way to keep your business from becoming an easy target.

A sleek silver metal door lock on a modern glass office door, symbolizing security

The Ivanti Emergency: A "10 out of 10" Threat

When security experts talk about risks, they use a scale from one to ten.

Most vulnerabilities might hit a six or a seven.

The latest flaw in Ivanti Sentry? It’s a perfect ten.

That means it is as serious as it gets.

Ivanti Sentry is a tool that helps manage and secure mobile devices for your team.

But a bug known as CVE-2026-10520 allows an unauthenticated attacker to inject "commands" directly into the system.

In plain English: A hacker can send a message to your server and take over as the "root" user: the person with total control.

They don't even need a password to do it.

Why this is scary

Imagine a stranger being able to walk into your office and instantly become the CEO.

That’s what "root access" feels like in a computer system.

CISA recently added this to its "Known Exploited Vulnerabilities" catalog.

This means it’s not just a theory anymore.

Hackers are already using this specific trick to break into businesses just like yours.

Research shows that some unpatched systems have already been backdoored.

If you haven't updated yet, there's a high chance someone has already been looking around your files.

What you need to do

If you run Ivanti Sentry versions 10.5.1, 10.6.1, or 10.7.0 (and earlier), you are at risk.

You must upgrade to versions 10.5.2, 10.6.2, or 10.7.1 immediately.

At Platinum Web Services, we help our clients stay ahead of these threats through predictive patching and proactive maintenance.

Don't wait for a breach to happen before you take action.

A modern office desk with a laptop and a digital shield symbolizing cyber security

When Your Security Cameras Become the Problem

Most of us install security cameras to feel safe.

But what if those very cameras were the way a hacker got into your network?

On June 11, CISA released several advisories regarding the Naxclow IoT Platform and Brickcom cameras.

These devices are common in offices and warehouses across the country.

The Naxclow platform, which manages devices like the Smart Doorbell X3 and various "ix cam" models, was found to have seven different vulnerabilities.

Brickcom cameras weren't far behind, with two major flaws of their own.

The "Weakest Link" Syndrome

The problem with these "Internet of Things" (IoT) devices is that we often set them up and forget about them.

We plug them in, they work, and we never think about them again.

But to a hacker, a smart camera is just a small computer with a permanent connection to your internet.

If that camera has a weak password or old software, it's like leaving a window cracked open in a high-security building.

Once they get into the camera, they can often jump to the rest of your office network.

Suddenly, your entire business security checklist is compromised because of one small device.

A professional security camera mounted on a modern office ceiling

Why Small Businesses Are the Main Target

It makes sense to think, "Why would a hacker care about my small business?"

You might think they only want the big fish: the global corporations.

But the truth is, small businesses are actually preferred targets.

Think about it.

Big corporations have massive IT teams and multi-million dollar budgets.

Small businesses often lack those resources, making them "low-hanging fruit."

According to recent studies, four out of five security breaches involve small to mid-sized organizations.

They know you're busy running your company.

They're betting that you haven't had time to check your Ivanti patches or update your camera firmware.

The Cost of a "Small" Breach

A breach isn't just a headache; it’s a massive financial blow.

Between the cost of data recovery, potential legal fees, and the damage to your reputation, many businesses struggle to recover.

It’s not just about the data.

It’s about the peace of mind you lose when you realize your "private" office wasn't private at all.

An IT specialist monitoring cybersecurity metrics on a large screen with 'SECURE' status

Technical Summary: The CISA Report

For those who need the technical details, here is the breakdown of the recent CISA advisories.

1. Ivanti Sentry (CVE-2026-10520 & CVE-2026-10523)

  • Vulnerability: OS Command Injection and Authentication Bypass.
  • Impact: Allows remote, unauthenticated attackers to execute commands with root privileges.
  • CVSS Score: 10.0 (Critical).
  • Status: Actively exploited in the wild. Added to KEV catalog on June 11, 2026.

2. Naxclow IoT Platform

  • Advisory: ICSA-26-162-02.
  • Devices Affected: Smart Doorbell X3, V720, ix cam variants.
  • Risk: Seven vulnerabilities that could lead to unauthorized access and system compromise.

3. Brickcom Cameras

  • Advisory: ICSA-26-162-03.
  • Devices Affected: Multiple network camera models.
  • Risk: Two vulnerabilities allowing for potential bypass of security controls.

Your 3-Step Action Plan

So, what can you do right now to protect your business?

You don't need to be a computer genius to take the first steps.

  1. Audit Your Hardware: Walk through your office and list every device connected to your Wi-Fi. Cameras, printers, doorbells: everything. If it's a Brickcom or Naxclow device, check for updates immediately.
  2. Patch Ivanti: If you use Ivanti Sentry, contact your IT provider or your internal team today. This cannot wait. Ensure you are on the latest "fixed" version.
  3. Segment Your Network: Don't put your office cameras on the same network as your accounting software. Using smart network design can prevent a hacker from moving from a camera to your customer data.

How Platinum Web Services Can Help

At Platinum Web Services, we believe you shouldn't have to worry about these burdens.

You should be focused on growing your business, not monitoring CISA alerts at midnight.

We offer personalized IT strategies that prioritize your security, flexibility, and peace of mind.

Our team handles the "boring" stuff: system updates, predictive analytics, and 24/7 monitoring: so your infrastructure operates without a hitch.

Whether you need help securing your IoT devices or want a robust cyber security solution that scales with you, we're here to help.

The digital world is full of open doors.

Let’s make sure yours are all locked tight.

Two professionals collaborating at a conference table with a laptop

0 Comments