Tag

Iot

All articles tagged with #iot

Security flaw lets 7,000 DJI Romo vacuums stream live home footage
technology18 hours ago

Security flaw lets 7,000 DJI Romo vacuums stream live home footage

A security demonstration revealed that a tester could use a PS5 controller-connected app to access DJI Romo robot vacuums through DJI’s servers, seeing and hearing from camera feeds on about 7,000 devices worldwide by leveraging a private token from his own Romo; DJI claimed fixes were in place, but The Verge showed a live demonstration of continued access, and DJI says remaining vulnerabilities will be patched in weeks, underscoring ongoing privacy risks for home cameras.

The Private Surveillance Economy: When Ring and IoT Cameras Redefine Intelligence
technology8 days ago

The Private Surveillance Economy: When Ring and IoT Cameras Redefine Intelligence

Private companies are shifting intelligence gathering from governments to a commercial market, turning everyday sensors—door cameras, license-plate readers, drones—into a coordinated data network used by law enforcement and investigators. Ring's controversial 'Search Party' pet-recovery push illustrated how partnerships and AI could blur privacy protections and enable mass surveillance without traditional warrants. As this 'intelligence as a service' model expands, questions about national sovereignty, democratic oversight, and civil liberties loom, even as governments retain traditional capabilities.

A single bug unlocked thousands of DJI Romo vacuums, exposing live feeds and floor plans
tech11 days ago

A single bug unlocked thousands of DJI Romo vacuums, exposing live feeds and floor plans

An investigation shows a back-end permission flaw in DJI’s Romo system allowed a researcher to access roughly 7,000 robot vacuums (and up to 10,000 related devices) worldwide, remotely control them, view live video, and map rooms before DJI patched the flaw in early February. The episode raises questions about smart-home security and data practices, even though traffic was encrypted and DJI says the issue is resolved and that the vulnerability was rare beyond researchers testing their own devices.

800k Telnet Devices Open to Root-Login Bypass (CVE-2026-24061)
security29 days ago

800k Telnet Devices Open to Root-Login Bypass (CVE-2026-24061)

Shadowserver has identified about 800,000 IPs fingerprinted for Telnet activity, highlighting widespread exposure to the root-login bypass in GNU InetUtils telnetd (CVE-2026-24061) affecting 1.9.3–2.7 and patched in 2.8; attackers can bypass authentication by sending USER=-f root via Telnet IAC. GreyNoise detected limited exploits starting Jan 21 from 18 IPs across 60 sessions, with 83% targeting root; attackers also attempted Python malware deployment but failed due to missing binaries. Most exposed devices are in Asia and the Americas; admins should disable vulnerable telnetd or block port 23 until patching.

Qualcomm Q4 Earnings Surpass Expectations Despite Challenges
technology3 months ago

Qualcomm Q4 Earnings Surpass Expectations Despite Challenges

Qualcomm reported strong Q4 earnings with $10.4B revenue driven by automotive and IoT growth, and announced strategic moves into AI data centers, PC ecosystems, and automotive, including the acquisition of Arduino to democratize AI development. Despite a GAAP loss due to tax charges, the company's fundamentals remain robust, with significant growth in automotive, IoT, and AI at the edge sectors, positioning it for continued expansion.

Raspberry Pi Unveils Compute Module 5 with Enhanced Power and Affordability
technology1 year ago

Raspberry Pi Unveils Compute Module 5 with Enhanced Power and Affordability

The Raspberry Pi Compute Module 5 (CM5) has been launched, featuring a Broadcom BCM2712 quad-core Cortex-A76 SoC, up to 16GB LPDDR4 ECC memory, and optional WiFi 5 and Bluetooth 5.0. It maintains the form factor of the CM4 but offers enhanced performance, making it suitable for embedded applications. The CM5 is available in various configurations, with prices ranging from $45 to $135, and includes options for eMMC storage and wireless connectivity. An IO board and development kit are also available to support early software development.

Raspberry Pi Pico 2 W: Affordable Microcontroller with Wi-Fi
technology1 year ago

Raspberry Pi Pico 2 W: Affordable Microcontroller with Wi-Fi

Raspberry Pi has launched the Pico 2 W, an updated version of its microcontroller board featuring built-in Wi-Fi and Bluetooth 5.2, priced at $7. The board is powered by the RP2350 microcontroller, which supports both Arm and RISC-V architectures, and is compatible with standard Raspberry Pi Pico accessories. The Pico 2 W's Wi-Fi 4 capability makes it suitable for various IoT applications, from smart home devices to custom gadgets. It is currently available for preorder at select retailers.

"LG Issues Critical Updates to Prevent Smart TV Hacking"
technology1 year ago

"LG Issues Critical Updates to Prevent Smart TV Hacking"

Researchers discovered four vulnerabilities in LG WebOS software affecting thousands of LG TVs, allowing hackers to add themselves as users, gain elevated access, drop malware, monitor traffic, and move throughout smart home networks. LG released patches for the vulnerabilities in a software update on March 22, affecting WebOS versions 4 through 7. The vulnerabilities were disclosed to LG in November, and the company confirmed the issues two weeks later, asking for an extension before patching the vulnerabilities last month.

"Global Cybersecurity Standards and Certifications for Smart Home Devices Launched by CSA and FCC"
technology1 year ago

"Global Cybersecurity Standards and Certifications for Smart Home Devices Launched by CSA and FCC"

The Connectivity Standards Alliance (CSA) has introduced a new IoT Device Security Specification program, aiming to provide a globally recognized security certification for consumer IoT devices. The program, which includes requirements such as unique device identity and secure software updates, will offer a Product Security Verified (PSV) Mark to compliant devices. This initiative, supported by major companies like Google, Amazon, and Philips Hue, seeks to simplify the certification process for manufacturers and provide consumers with easily identifiable indicators of a product's security. While the program focuses on device security rather than privacy, it represents a significant step forward in addressing IoT device security concerns, with plans for ongoing updates and incident response requirements.

"Shim Bootloader Vulnerability Threatens Linux Distros"
cybersecurity2 years ago

"Shim Bootloader Vulnerability Threatens Linux Distros"

Linux has a shim problem due to Secure Boot and GPLv3, resulting in a broken shim with serious vulnerabilities. LastPass was banned from the App Store due to a suspiciously similar app. Reports of three million compromised smart toothbrushes used in a DDoS attack were found to be based on a hypothetical scenario, not actual events. Security researchers are facing challenges due to the abundance of honeypots, while undocumented SSH access with a known root password was discovered in some heat pumps. A vulnerability in Mastodon's federated account handling was published, prompting an update to address the issue.