< ciso
brief />
Tag Banner

All news with #iot security tag

107 articles · page 2 of 6

China-linked JDY botnet accelerates enterprise risk

🔍 Lumen’s Black Lotus Labs reports a China-linked botnet called JDY has grown to over 1,500 compromised SOHO and IoT devices used to rapidly discover and fingerprint internet-facing systems after public vulnerability disclosures. The activity, tied to nation-state actors including Volt Typhoon, enables persistent, distributed reconnaissance that can evade geofencing and IP-reputation controls. Researchers warn this marks a shift toward industrialized pre-exploitation scanning and undermines traditional perimeter patch and monitoring assumptions.
read more →

Research shows free apps turn smart TVs into proxies

🔍 A reverse-engineered iOS SDK from Bright Data reveals free apps can turn devices, including always-on smart TVs, into exit nodes that relay web-scraping traffic. The SDK, embedded behind opt-in screens, uses peer channels with weak authentication and can bypass VPNs on iOS, allowing background relays that consume home bandwidth. Blocking a handful of SDK domains at the router or scanning apps on managed devices can stop the behavior.
read more →

AWS IoT Device Management adds MQTT session visibility

🔧 AWS IoT Device Management now surfaces MQTT session data in its connectivity status API, helping teams troubleshoot device connectivity and audit connection patterns across IoT fleets. The update provides session timeout and expiry values and, optionally, socket-level details like source/destination IPs, ports, and client VPC endpoint IDs. Access to socket information is controlled by granular IAM policies. The API keeps connection records indefinitely, exceeding the 30-minute retention of AWS IoT Core's GetConnection API.
read more →

AWS IoT Core adds Ping and AuthNError logs

🔍 AWS IoT Core now emits two new Amazon CloudWatch Log event types to help troubleshoot device connectivity and authentication across IoT fleets. The Ping log captures MQTT Keep‑alive messages to identify connections or devices that fail to maintain connectivity. The Connection.AuthNError log records rejected connection attempts with detailed error codes to speed resolution of credential and certificate issues. Enable event-level logging and choose a CloudWatch log group, then opt into these event types; they are available in all AWS Regions where AWS IoT Core operates.
read more →

AWS IoT Core adds MQTT connection management APIs

🔧 AWS IoT Core introduces two MQTT connection management APIs: GetConnection and ListSubscriptions. These APIs provide detailed visibility into device MQTT connections and subscriptions, including session details and optional socket-level data, controlled by granular IAM policies. They complement the existing DeleteConnection API to offer a fuller connection management capability available in all supported AWS regions.
read more →

AWS IoT Core adds point-to-point direct messaging

🔔 AWS IoT Core now supports direct point-to-point messaging to any connected device, enabling delivery acknowledgements and improved visibility into message status. The new SendDirectMessage API lets you send messages directly to a device and optionally receive delivery confirmations. Delivery acknowledgements produce detailed API response codes and Amazon CloudWatch Logs for diagnostics. Direct messaging is available in all regions where AWS IoT Core operates, including Amazon China and AWS GovCloud (US).
read more →

Critical unauthenticated password reset in KMW cameras

🔒 The advisory details a critical vulnerability in KMW CCTV Security Cameras that allows an unauthenticated attacker to reset the administrator password to a known value, granting full access to camera feeds and settings. Vendor firmware (KM-IP421) is available to address the issue, though it may require re-authorizing cloud P2P connections. CISA urges network segmentation, restricted internet access, regular firmware updates, and other defensive measures to reduce exposure.
read more →

XCharge C6 charger firmware and access vulnerabilities

🔒 CISA reports critical vulnerabilities in the XCharge C6 electric vehicle charging controller that could allow attackers to gain administrator rights or execute arbitrary code. A firmware update mechanism lacks signature validation, a stack-based buffer overflow exists in signal processing, and a management service exposes default credentials over the charging interface. XCharge has deployed updates for affected units; users should contact XCharge Support for details.
read more →

Frontier X2 BLE Authentication Vulnerability Alert

🔒 The Frontier X2 wearable and its companion Frontier X mobile app are affected by a vulnerability allowing unauthenticated BLE read/write access to critical GATT characteristics, enabling attackers in range to control device functions and inject fabricated health telemetry. Fourth Frontier is developing a fix; users should contact the vendor for assistance and connect the device to only one app at a time. CISA recommends isolating control networks, minimizing exposure, using secure remote access, and following ICS defensive best practices to reduce exploitation risk.
read more →

Hard-coded Credentials in USR-W610 Converter Exposed

🔒 The USR-W610 RS232/485 to Wi‑Fi/Ethernet Converter from Jinan USR IOT Technology Limited contains plaintext administrative credentials embedded in its firmware. These hard-coded credentials can be extracted through firmware analysis and used to authenticate to device services, enabling potential administrator access. CISA reports no confirmed public exploitation and encourages users to contact the vendor and apply updates where available. Mitigations include network segmentation, firewalling, and using secure remote access methods such as VPNs with current updates.
read more →

Researchers Demonstrate Person Identification via Wi‑Fi

📡 Researchers show WiFi signals can reveal people and environments by analyzing how radio waves reflect, scatter, and absorb compared with expected patterns. WiFi sensing uses these variations to infer spatial structure and presence, effectively creating an image of surroundings and occupants. Thorsten Strufe of KIT explains it functions like a camera, but with radio waves instead of light, enabling recognition through signal propagation analysis.
read more →

Eppendorf BioFlo 320 VNC Hard‑coded Password Risk

🔒 The Eppendorf BioFlo 320 is affected by a high‑severity vulnerability (CVSS 9.8) due to a VNC server that uses a hard‑coded password. If remote access is enabled and an attacker knows the device's network address, they can gain full control of the controller interface; VNC traffic is unencrypted. Eppendorf has released Version 5.0 software that removes VNC access and urges users to verify VNC is disabled and restrict configuration changes to Admin and Supervisor roles.
read more →

ABB Terra AC Heap Overflow Risks and Fixes

🔒 ABB reported a heap-based buffer overflow in select Terra AC EV chargers that can be triggered via crafted OCPP messages. Exploitation may allow heap pollution, denial-of-service, altered firmware behavior, or possible remote code execution; the vendor has released patched firmware versions. ABB strongly recommends avoiding unencrypted HTTP for OCPP connections and applying updates promptly to mitigate remote exploitation risks.
read more →

AWS IoT Core Device Location: Confidence & Metadata

📍 AWS IoT Core for Device Location now lets developers specify a confidence level (50–99%) for Cell ID, Wi‑Fi, and Cell+Wi‑Fi solvers when resolving device positions via HTTP, trading radius size for statistical certainty. It also adds a measurement type field in resolved metadata to indicate GNSS, Wi‑Fi, or BLE sources, improving data quality assessment and debugging. These enhancements are available in all supported regions.
read more →

FreeRTOS 202604 LTS: security, MPU, and protocol updates

🛡️ FreeRTOS 202604 LTS is now available, providing a two-year Long Term Support window with security updates, critical bug fixes, and feature stability for embedded and IoT device manufacturers. The FreeRTOS kernel advances to v11.3.0 with new hardware ports, security hardening, and expanded MPU support that reduces claimed MPU regions and allows reservation of hardware regions for application-specific protection. Core libraries include coreMQTT v5.0.2 (MQTT v5.0 features) and coreSNTP v2.0.0 (year-2038 readiness); the release emphasizes memory safety and MISRA-C compliance, with migration guides and an Extended Maintenance Plan to support upgrades.
read more →

How Vehicles Become Tools for Law Enforcement Surveillance

📡 Modern cars act as mobile computers that log and transmit extensive telemetry to manufacturers and third parties. Law enforcement increasingly uses Car Intelligence (CARINT) tools and vendor solutions such as Ateros, Berla, and Toka to extract GPS histories, call logs, paired-device lists, and driving statistics — sometimes without warrants. Even sensor systems like unencrypted TPMS can enable low-cost tracking. Recommended mitigations include avoiding phone syncs, clearing head-unit data, disabling voice commands, and minimizing use of manufacturer apps.
read more →

One in Four Healthcare Organizations Hit by Device Attacks

🏥 A new RunSafe Security index found that 24% of healthcare organizations experienced cyber-attacks affecting medical devices in the past year, with 80% of those incidents causing moderate or significant patient impact, from delayed imaging to interruptions in critical care. The survey of 551 professionals across the US, UK and Germany shows growing integration of security into procurement—82% deploying runtime exploit protection and 84% including cyber requirements in vendor RFPs—yet legacy devices remain a major exposure.
read more →

Countering China-Nexus Covert Networks of Edge Devices

🔒 This advisory from CISA and international partners, informed by UK NCSC analysis, describes a tactical shift by China‑nexus actors toward externally provisioned, large‑scale covert networks of compromised edge devices. Such networks—made up of SOHO routers, IoT cameras, NAS units and firewalls—are used for reconnaissance, malware delivery, multi‑hop C2 proxying and data exfiltration. The guidance urges organizations to map and inventory edge assets, baseline normal connections, leverage dynamic threat feeds, and enforce multifactor authentication to reduce exposure and improve detection.
read more →

Yadea T5 Electric Bicycle Weak Authentication Risk

🔓 CISA warns that Yadea T5 electric bicycles are affected by a weak authentication vulnerability tracked as CVE-2025-70994. A local attacker who intercepts a legitimate key fob transmission can forge signals to unlock and start the bicycle, enabling theft; CISA assigns a CVSS v3.1 score of 7.3 (High) and notes the issue is not remotely exploitable. Yadea did not respond to coordination efforts; users should secure property with external locks, keep devices updated, and contact vendor support.
read more →

Milesight Cameras: Multiple Critical and High Vulnerabilities

🔒 CISA warns of five vulnerabilities in Milesight camera firmware that can cause device crashes or permit remote code execution. The flaws affect numerous MS-, PM-, TS-, SC-, and SP-series models and include a CRITICAL use-of-default SSL private key (CVE-2026-32644) plus several HIGH-severity issues such as hard-coded credentials and a heap-based buffer overflow. Milesight has released firmware updates; operators should apply the latest PE/PC/PA builds and follow recommended network isolation and secure remote-access practices.
read more →