Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-89174 exposes a critical authentication weakness in Kingdom Communication Associated's Smart Video Intercom System. The vulnerability stems from missing brute-force protection mechanisms (CWE-307), allowing unauthenticated remote attackers to systematically guess valid credentials through unlimited login attempts. This affects any organization deploying these intercoms for physical security—from office buildings and residential complexes to healthcare facilities and government installations. Since video intercom systems control access to restricted areas, successful compromise creates direct physical security breaches alongside data exposure risks.
While this CVE lacks explicit MITRE ATT&CK technique mapping, Casky's 754 security skills trained on Claude AI would detect the underlying attack patterns through extended reasoning analysis. Practitioners using Casky would identify findings aligned with T1110 (Brute Force) and T1078 (Valid Accounts), observing behavioral indicators such as: repeated failed authentication attempts from external IPs, account lockout patterns that never trigger, authentication logs showing systematic username/password combinations, and successful logins following suspicious attempt clusters. The platform's reasoning engine would correlate these anomalies across logs to surface the missing rate-limiting controls and absent account lockout thresholds, enabling security teams to recognize exploitation attempts in real-time and recommend immediate compensating controls like network-based login throttling or WAF rate-limiting rules.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-89174. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation