WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with forged commands to disrupt classroom operations.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
WeenyGenius, a widely-deployed computer lab management system by Howyar Technologies, relies on ZMTP (ZeroMQ Message Transport Protocol) in Null authentication mode, creating a critical network-level vulnerability. This insecure protocol implementation allows unauthenticated attackers positioned on the same network segment to passively capture unencrypted packets, exposing sensitive classroom data including student credentials, lab assignments, and system commands. Beyond eavesdropping, attackers can forge and replay commands to disrupt classroom operations—shutting down labs, altering grades, or disrupting instruction. Educational institutions managing computer labs, vocational training centers, and corporate training environments are directly affected, particularly those with shared or guest network access.
While this CVE currently maps to zero Casky skills due to its network protocol specificity, Casky's Claude AI-powered platform with extended reasoning would detect the attack patterns underlying exploitation through behavioral analysis on network traffic and command execution anomalies. Practitioners using Casky would identify suspicious indicators including: unexpected ZMQ message sequences without proper authentication headers, replay patterns showing identical command structures across different time intervals, and lateral movement attempts from low-privilege network segments toward lab management infrastructure. Detection would align with ATT&CK techniques like T1040 (Traffic Capture), T1556 (Modify Authentication Process), and T1021 (Remote Services) by correlating unencrypted protocol usage with command injection attempts. The absence of matching skills highlights a gap where custom detection rules around ZMTP traffic analysis and replay attack signatures would strengthen institutional defenses.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-89177. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation