< ciso
brief />
Tag Banner

All news with #iot security tag

117 articles

Most Medical Devices Unready for PQC Transition

🔒 A Forescout investigation across 50+ healthcare delivery organizations found most medical devices cannot be upgraded to post-quantum cryptography, leaving sensitive healthcare data at risk of future quantum-enabled decryption. Only 6% of IoMT and 16% of medical OT devices use SSH implementations that could support PQC, compared with around 50% of traditional IT devices. The report highlights exposed systems holding EMRs and PACS and urges immediate inventory, segmentation, TLS 1.3 enforcement and vendor engagement to prepare for quantum threats.
read more →

ClingSTUN backdoor exploits unpatched IoT flaws

🔍 FortiGuard Labs has identified a Linux proxy backdoor named ClingSTUN that leverages unpatched internet-facing IoT vulnerabilities to turn devices into remotely controlled proxy nodes. The malware abuses legitimate public STUN servers to keep NAT bindings open and blend its traffic with normal VoIP/WebRTC communications. Operators deployed the campaign in three waves, expanding exploited vulnerabilities to at least 24 CVEs and adding hard-coded exploits to aid propagation. FortiGuard urges device inventory, prioritised patching and compensating controls where updates are unavailable.
read more →

Connected Cars as Comprehensive Surveillance Platforms

🛡️ Researchers from Northeastern University and Consumer Reports examined how modern vehicles collect and share driver data by reviewing automaker privacy policies, regulatory filings, and industry practices. They found that consent is often obtained via infotainment systems or mobile apps at setup, where many users accept terms without reading them. Data recipients include insurers, lenders, telematics exchanges, data brokers, and government agencies, meaning manufacturers can continuously monitor and monetize driving behavior.
read more →

Mixed Device Segments Increase Lateral Movement Risk

🔍 Forescout's analysis of 47,700 real-world network segments found many contain mixed device types—IT, OT, IoT and IoMT—broadening attack surfaces and increasing lateral movement risk. The study shows only a minority of OT or IoMT segments are isolated, with common co-location like IP cameras alongside workstations enabling single-point compromises. Forescout recommends continuous visibility, device prioritization, tighter segmentation and policy-based controls to prevent breaches spreading to critical systems.
read more →

Zero-day Flaws Found in TP-Link Home Security Cameras

🔒 Security researchers disclosed two zero-day vulnerabilities in TP-Link Tapo C200 cameras used for home and SOHO monitoring. Vendor firmware V5_1.4.6, released 18 August, addresses CVE-2026-15315 (auth bypass via replay) and CVE-2026-15316 (onboarding DoS). OPSWAT warns the auth bypass can expose live video and recordings, while the DoS crashes the HTTPS service. A third, still-unpatched bug is considered critical and may allow full device compromise.
read more →

Smart TV and Set‑Top Box Proxyware Risks

🛡️ A recent analysis shows cheap smart TVs and TV boxes are increasingly recruited into proxyware and botnets, turning household devices into gateways for malicious traffic. Infected devices often run multiple proxy clients concurrently and can expose internal network resources, allowing remote attackers to reach router admin panels and other devices. The study of a popular SuperBox model revealed persistent malware, remote code execution via firmware flaws, and over 1,300 attacks in three weeks. Users are advised to monitor network traffic, avoid dubious apps and devices, disconnect compromised hardware, and protect routers with strong unique passwords and reputable security tools.
read more →

Comcast Adds Motion Detection to Home Routers

📡 Comcast has rolled out a WiFi-based motion detection feature on its routers that notifies users when motion is detected near connected devices and provides live activity feeds. The feature includes modes for Home, Sleep, and Away, and its effectiveness varies with home layout, materials, and device placement. Comcast warns it does not guarantee detection performance and notes the system has limitations. The company’s support documentation also states that motion data may be shared with third parties under certain circumstances.
read more →

Two root RCE chains found in Unitree G1 EDU

🔒 Security researcher Olivier Laflamme disclosed two independent root remote code execution (RCE) chains impacting the Unitree G1 EDU, tracked as CVE-2026-76639 and CVE-2026-76640. One path is network-adjacent via chat_go and bashrunner, the other begins from an unauthenticated BLE bootstrap write leading to Wi‑Fi provisioning and a buffer overflow. Unitree's cloud account-to-robot ownership check was reportedly patched in July 2026, but no fixed firmware release has been publicly confirmed for the G1 EDU.
read more →

FBI Disrupts China-Linked QTFY Botnet Operations

🔒 The U.S. Department of Justice and FBI announced the disruption of two hacking platforms, QScan and QTRouter, used by the China-linked group QTFY to target U.S. critical infrastructure and sensitive networks. Lumen Black Lotus Labs, which tracked the group since 2018, collaborated with the FBI after observing extensive targeting of research and public sector organizations. QScan infected IoT devices to build a proxy mesh while QTRouter and associated services obfuscated attack origins using compromised routers, commercial proxy services, and leased VPSs. The court-authorized seizure of hard-coded domains caused the platforms to cease operations.
read more →

Unpatched Calix NAT bypass risk exposes internal devices

🔒 An unpatched authentication flaw in Calix GS7 XGS (GS5239XG) residential gateways running EXOS/6.6.47 lets remote unauthenticated attackers create and manipulate port-forwarding rules via the MiniUPnPd control endpoint on TCP port 5000. Researcher Brian Khan Quintana reported the issue as CVE-2026-75501 after failed vendor notification and worked with CERT/CC for disclosure. Exploitation can permanently open firewall rules that expose internal cameras, NAS, IoT devices, and admin interfaces; users are advised to disable UPnP or contact their ISP if the setting is locked.
read more →

Supply-chain malware infects Android car head units

🔍 Kaspersky researchers say a supply-chain attack abused a legitimate DoFun update app to deliver JarService malware to Android-based car head units, attributing the campaign to the MoYu group. The loader retrieves encrypted payloads and exposes nine remote commands used to collect device metadata, run code, open URLs, and perform network checks. Operators primarily install a reverse-proxy module named zhima to convert head units into proxy nodes for ad fraud and monetization, while DoFun says it has remediated the issue.
read more →

Five rules to reduce IP camera surveillance risks

🔒 This article explains where the threat to IP cameras comes from and outlines five practical rules to reduce the risk of becoming a target. It describes real-world incidents — mass hacks, livestreamed footage sales, and stalker cases — and highlights common failures such as unchanged factory passwords, insecure cloud implementations, and lack of firmware updates. The guidance covers device selection, local storage, network segmentation, and good security hygiene to lower exposure.
read more →

Comcast adds WiFi-based home motion detection

📡 Comcast has added WiFi-based motion detection to its new Xfinity Shield home protection suite, enabling compatible gateways and stationary WiFi devices to detect movement without cameras or motion sensors. The feature, called WiFi Motion, is included with WiFi Shield for Xfinity Internet customers and offers sensitivity settings to reduce false alerts from pets or adjacent units. Comcast emphasizes the feature is opt-in, does not identify individuals or precise locations, and pairs with paid Shield Select hardware and response services.
read more →

Malicious SIMs can remotely commandeer cellular modules

🔒 Researchers from the University of Birmingham and Fuzzware demonstrate that a hostile SIM card can use the SIM's standard proactive commands (RUN AT) to instruct modems to execute AT commands, enabling code execution on affected devices. They tested 26 devices and found nine accepted the command, including several Quectel modules in EV chargers, industrial routers, and car telematics units. Vendors including Qualcomm and Quectel have responses in progress, but no public advisories have been broadly published.
read more →

Researchers Find Major Flaw in Car Anti-Theft Systems

🔍 A UC San Diego research team discovered critical vulnerabilities in the aftermarket KARR Security System, which they estimate is installed in over two million US vehicles. The flaw allows any attacker within Bluetooth range to send radio commands that can silently unlock vehicles, disable alarms, honk horns, flash lights, or even prevent the ignition from starting. This poses risks to vehicle security and driver safety and highlights systemic issues in the design and testing of aftermarket telematics devices.
read more →

Ad fraud and proxy risk in generic TV streaming sticks

🛡️ Security researchers uncovered that inexpensive, off‑brand TV streaming sticks not only run residential proxy software but also impersonate mobile phones to click ads on AI‑generated sites. Bitsight TRACE researcher Pedro Falé analyzed telemetry from an expired domain tied to H96 devices and found apps linked to Zhejiang Fengwo IoT Technology that coordinate ad‑fraud campaigns. These devices switch roles between proxying traffic when in use and executing ad‑clicking jobs when idle, enabling large‑scale monetization and deceptive marketing claims.
read more →

Dysphoria botnet compromises 200,000 IoT devices

🔍 Researchers report a new botnet named Dysphoria has infected roughly 200,000 devices globally and is being used for DDoS attacks and traffic relay operations. QiAnXin XLab attributes Dysphoria's evolution to earlier malware families and notes it uses Ethereum ENS and Solana SNS domains for covert C2 resolution. The botnet spreads via weak Telnet/SSH credentials and known router and IoT vulnerabilities, and some variants now solely provide proxy services.
read more →

LG to ban residential proxies from smart TV apps

🛡️ LG Electronics USA will suspend smart TV apps that convert televisions into always-on residential proxy nodes, following research showing over 42% of webOS apps contain such proxy SDKs. The company is working with developers to remove the option and will suspend noncompliant apps, while tightening its app evaluation process. Spur’s research also found similar proxy components in Samsung’s Tizen apps, and proxy providers such as Bright Data were commonly identified. LG emphasized ongoing platform reviews to protect users.
read more →

When AI gets a body, it inherits an attack surface

🤖 Embodied AI systems—robots, arms, humanoids—turn models into cyber-physical assets that inherit hardware, firmware, supply-chain and remote-access risks the vendor demo hides. Buyers should evaluate five areas: provenance (hardware/firmware BOM and update authority), access (remote paths and teleoperation), integrity (sensor spoofing and model manipulation), evidence (independent field data) and accountability (contractual responsibility and liability).
read more →

Smashing Security podcast episode 476 recap

🎧 In episode 476 of the Smashing Security podcast Graham Cluley and Geoff White discuss Geoff's new podcast season on the Conti ransomware gang, personal scam attempts, and a startling prank targeting e-rickshaws in India. They describe how an app called BatBMS — intended for battery management — has been misused to remotely disable electric rickshaws, creating safety and livelihood risks for drivers. The hosts also cover sponsors and lighthearted anecdotes about smartphone pranks.
read more →