< ciso
brief />
Tag Banner

All news with #iot security tag

107 articles

Supply-chain malware infects Android car head units

🔍 Kaspersky researchers say a supply-chain attack abused a legitimate DoFun update app to deliver JarService malware to Android-based car head units, attributing the campaign to the MoYu group. The loader retrieves encrypted payloads and exposes nine remote commands used to collect device metadata, run code, open URLs, and perform network checks. Operators primarily install a reverse-proxy module named zhima to convert head units into proxy nodes for ad fraud and monetization, while DoFun says it has remediated the issue.
read more →

Five rules to reduce IP camera surveillance risks

🔒 This article explains where the threat to IP cameras comes from and outlines five practical rules to reduce the risk of becoming a target. It describes real-world incidents — mass hacks, livestreamed footage sales, and stalker cases — and highlights common failures such as unchanged factory passwords, insecure cloud implementations, and lack of firmware updates. The guidance covers device selection, local storage, network segmentation, and good security hygiene to lower exposure.
read more →

Comcast adds WiFi-based home motion detection

📡 Comcast has added WiFi-based motion detection to its new Xfinity Shield home protection suite, enabling compatible gateways and stationary WiFi devices to detect movement without cameras or motion sensors. The feature, called WiFi Motion, is included with WiFi Shield for Xfinity Internet customers and offers sensitivity settings to reduce false alerts from pets or adjacent units. Comcast emphasizes the feature is opt-in, does not identify individuals or precise locations, and pairs with paid Shield Select hardware and response services.
read more →

Malicious SIMs can remotely commandeer cellular modules

🔒 Researchers from the University of Birmingham and Fuzzware demonstrate that a hostile SIM card can use the SIM's standard proactive commands (RUN AT) to instruct modems to execute AT commands, enabling code execution on affected devices. They tested 26 devices and found nine accepted the command, including several Quectel modules in EV chargers, industrial routers, and car telematics units. Vendors including Qualcomm and Quectel have responses in progress, but no public advisories have been broadly published.
read more →

Researchers Find Major Flaw in Car Anti-Theft Systems

🔍 A UC San Diego research team discovered critical vulnerabilities in the aftermarket KARR Security System, which they estimate is installed in over two million US vehicles. The flaw allows any attacker within Bluetooth range to send radio commands that can silently unlock vehicles, disable alarms, honk horns, flash lights, or even prevent the ignition from starting. This poses risks to vehicle security and driver safety and highlights systemic issues in the design and testing of aftermarket telematics devices.
read more →

Ad fraud and proxy risk in generic TV streaming sticks

🛡️ Security researchers uncovered that inexpensive, off‑brand TV streaming sticks not only run residential proxy software but also impersonate mobile phones to click ads on AI‑generated sites. Bitsight TRACE researcher Pedro Falé analyzed telemetry from an expired domain tied to H96 devices and found apps linked to Zhejiang Fengwo IoT Technology that coordinate ad‑fraud campaigns. These devices switch roles between proxying traffic when in use and executing ad‑clicking jobs when idle, enabling large‑scale monetization and deceptive marketing claims.
read more →

Dysphoria botnet compromises 200,000 IoT devices

🔍 Researchers report a new botnet named Dysphoria has infected roughly 200,000 devices globally and is being used for DDoS attacks and traffic relay operations. QiAnXin XLab attributes Dysphoria's evolution to earlier malware families and notes it uses Ethereum ENS and Solana SNS domains for covert C2 resolution. The botnet spreads via weak Telnet/SSH credentials and known router and IoT vulnerabilities, and some variants now solely provide proxy services.
read more →

LG to ban residential proxies from smart TV apps

🛡️ LG Electronics USA will suspend smart TV apps that convert televisions into always-on residential proxy nodes, following research showing over 42% of webOS apps contain such proxy SDKs. The company is working with developers to remove the option and will suspend noncompliant apps, while tightening its app evaluation process. Spur’s research also found similar proxy components in Samsung’s Tizen apps, and proxy providers such as Bright Data were commonly identified. LG emphasized ongoing platform reviews to protect users.
read more →

When AI gets a body, it inherits an attack surface

🤖 Embodied AI systems—robots, arms, humanoids—turn models into cyber-physical assets that inherit hardware, firmware, supply-chain and remote-access risks the vendor demo hides. Buyers should evaluate five areas: provenance (hardware/firmware BOM and update authority), access (remote paths and teleoperation), integrity (sensor spoofing and model manipulation), evidence (independent field data) and accountability (contractual responsibility and liability).
read more →

Smashing Security podcast episode 476 recap

🎧 In episode 476 of the Smashing Security podcast Graham Cluley and Geoff White discuss Geoff's new podcast season on the Conti ransomware gang, personal scam attempts, and a startling prank targeting e-rickshaws in India. They describe how an app called BatBMS — intended for battery management — has been misused to remotely disable electric rickshaws, creating safety and livelihood risks for drivers. The hosts also cover sponsors and lighthearted anecdotes about smartphone pranks.
read more →

Six U-Boot Vulnerabilities Enable Stealthy Firmware Attacks

🔒 Binarly disclosed six vulnerabilities in the widely used U-Boot bootloader's FIT signature verification that can lead to crashes or arbitrary code execution during device boot. These flaws, present in code dating back to U-Boot 2013.07, potentially affect many releases and vendor forks across BMCs, networking gear, industrial systems, and IoT devices. While patches have been accepted upstream, vendor firmware updates are required to protect devices, and unsupported hardware may remain vulnerable.
read more →

Yarbo robot mower backdoor exposes devices

🛠️ Independent researcher Andreas Makris discovered a universal hardcoded root password and permanent remote-access mechanism in Yarbo robotic mowers that allowed him to control thousands of units remotely. He demonstrated the flaw by hijacking a mower in the U.S. from Germany, showing how attackers could steer the machine, access cameras, and extract owner data. Yarbo has issued updates and plans to make remote access opt-in, but owners should install patches and follow basic IoT security hygiene.
read more →

AWS releases IoT Device SDK for Swift across platforms

🔒 The AWS IoT Device SDK for Swift is now generally available, enabling Swift developers to build secure, scalable IoT applications natively on Apple platforms (macOS, iOS, tvOS) and Linux. The SDK fills a prior gap in native Swift support for AWS IoT services and provides production-ready APIs for teams managing device fleets and cross-platform Apple ecosystem solutions. It integrates service clients for AWS IoT Device Shadow, Jobs, and Fleet Provisioning and includes built-in TLS 1.3 support on Apple platforms. Install via Swift Package Manager and consult the documentation and GitHub samples to get started.
read more →

Canada’s Spy Agency Uses Court Warrant to Disrupt Botnets

🛡️ The Federal Court authorized the Canadian Security Intelligence Service to reach into infected servers, SOHO routers, and IoT devices on Canadian soil to neutralize two foreign-run botnets. The public ruling, released June 15, confirms CSIS used its threat reduction warrant powers for the first time to alter, degrade, and destroy botnet data while ensuring the operation targeted devices rather than people. The court found the threat imminent and proportional, but redactions leave the precise foreign actor(s) unidentified.
read more →

AryStinger malware converts legacy routers into relays

🔍 QiAnXin XLab has identified a new malware family named AryStinger that has infected at least 4,300 legacy home routers, turning them into a distributed reconnaissance and proxy network rather than a typical DDoS botnet. The campaign targets routers using Realtek RTL819X chips via old vulnerabilities (CVE-2013-3307, CVE-2016-5681) and favors D-Link DIR-850L units, with infections concentrated in South Korea and China. A second strain targeting QNAP NAS devices via CVE-2025-11837 was also observed; both builds support scanning, tunneling, and remote task execution. Defenders are advised to check for C2 connections, suspicious binaries and processes, retire unsupported devices, and disable remote administration.
read more →

Bluetooth flaws in Apollo Pharmacy glucose monitor

🔒 CISA warns that the Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT suffers from vulnerabilities allowing cleartext transmission of sensitive data and missing authorization. An attacker within BLE range can passively intercept glucose readings or monopolize the device's single BLE connection, blocking legitimate users. Users are urged to follow Bluetooth security guidance and contact Apollo Pharmacy for vendor-specific information.
read more →

AVer PTC Camera Remote Code Execution Advisory

🔒 AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras contain an input validation flaw that could permit unauthenticated remote arbitrary code execution via a crafted web request. Affected devices are rated CVSS v3 9.8 and relate to CWE-552 Files or Directories Accessible to External Parties. AVer has released firmware to address the issue and CISA advises minimizing network exposure, placing devices behind firewalls, and using secure remote access methods such as updated VPNs.
read more →

Brickcom Camera Flaw Allows Unauthenticated Video Access

🔒 The advisory describes vulnerabilities in Brickcom cameras that permit unauthenticated attackers to access live snapshots via the /ONVIF endpoint and exploit default credentials to obtain administrative control. CISA reports vendor non-coordination and urges users to contact Brickcom for support while following defensive measures. Recommended mitigations include isolating devices behind firewalls, minimizing internet exposure, and using secure remote access methods such as updated VPNs.
read more →

Yarbo MQTT Credentials and Authorization Flaw

🔒 Yarbo mobile apps and cloud infrastructure expose hard-coded MQTT broker credentials and lack per-device authorization, enabling broad access to telemetry and command topics across the robot fleet. The vulnerability allows wildcard subscription to telemetry and publishing to individual robot command topics using only a serial number. Yarbo recommends updating the mobile app to 3.17.4 or later; server-side broker authorization will be enforced with the May 2026 update. CISA advises network restrictions, isolation behind firewalls, and use of secure remote access methods while organizations perform risk assessments.
read more →

Critical IoT Platform Flaws Enable Device Takeover

🔒 CISA published an advisory on multiple critical vulnerabilities in the Naxclow IoT Platform that allow device impersonation, credential exposure, and fleet enumeration. A replayable onboarding flow and inadequate authorization let attackers reassign devices, while persistent, non-rotating relay credentials enable long-term access. Additional weaknesses include a hard-coded platform salt for request signing, predictable device identifiers, and cleartext Wi‑Fi secrets exposed via UART.
read more →