Advertisement
Australia Pilot: Smart Device Security Labelling Scheme
Australia launches a pilot program for smart device security labelling, aiming to empower consumers with clear information on IoT product security.
Generic Streaming Sticks: Covert Proxy Networks & Ad Fraud Exposed
Generic TV streaming sticks are being used in a dual-pronged attack: creating a covert proxy network and engaging in extensive ad fraud through spoofed mobile traffic on…
Tengu Botnet Exploits Linux Watchdog for Reboot-Based Persistence
The Mirai-derived Tengu botnet utilizes hardware watchdog timers to trigger reboots when its process is terminated, ensuring persistence on Linux devices.
Hikvision ISAPI Scanning Trends: Analysis and Mitigation Guide
Recent honeypot data reveals a surge in probes targeting the Hikvision Intelligent Security API. Learn how to identify and defend against these IoT scans.
FatFs Vulnerabilities: Securing Embedded Devices Against RCE
Security researchers at runZero have disclosed seven vulnerabilities in the widely used FatFs library, impacting millions of IoT and industrial devices.
NIST Drafts Updated IoT Security Guidance for Federal Networks
NIST updates its IoT security guidance to help federal agencies manage risks and establish product cybersecurity requirements for connected devices.
Advertisement
CSIS Deploys First-of-Its-Kind Warrant to Neutralize Foreign Botnets
Canada's CSIS utilized a unique threat reduction warrant to access and clean botnet-infected IoT devices and servers located within Canadian borders.
Yarbo Mobile App & Cloud: Critical Robot Fleet Vulnerabilities
Critical vulnerabilities CVE-2026-10557 & CVE-2026-7368 in Yarbo mobile app and cloud allow attackers to control robot fleets via hard-coded credentials.
C0XMO Botnet Targets DD-WRT Router Firmware — Analysis and Mitigation
C0XMO, a Gafgyt-based botnet, exploits DD-WRT router vulnerabilities to launch DDoS attacks and eliminate rival malware on infected IoT devices.
Bright Data SDK: Smart TVs Used as AI Web-Scraping Proxies
Smart TVs and iOS apps are being converted into web-scraping exit nodes via embedded SDKs, fueling residential proxy networks used by AI companies.
Google Gemini Hijack: Command Injection via Messaging Notifications
Researchers demonstrate how Google Gemini voice assistant can be hijacked via malicious messaging notifications to control smart homes and start video calls.
Dutch Police Seize 200 Servers to Dismantle 17-Million Device Botnet
Dutch authorities and the NCSC dismantled a global botnet affecting 17 million devices. Learn how the seizure of 200 servers impacts global cybercrime operations.
Kimwolf Botmaster Arrested: Impacts on IoT Botnet DDoS Mitigation
Canadian and U.S. authorities arrest the alleged operator of the massive Kimwolf IoT botnet, linked to millions of compromised devices and disruptive DDoS attacks.
Gafgyt and Mirai Variants Target IoT Devices via CVE-2017-17215
Analysis of Gafgyt and Mirai botnet activity targeting IoT devices through RCE vulnerabilities such as CVE-2017-17215 and CVE-2014-2320.
Mirai-Based xlabs_v1 Botnet Hijacks IoT Devices via ADB
Learn how the xlabs_v1 botnet exploits Android Debug Bridge (ADB) on port 5555 to enroll IoT devices into a DDoS network and how to secure your hardware.
Security Analysis of Prediction Market Oracle Manipulation on Polymarket
An investigation into the vulnerabilities of decentralized oracles, including physical sensor tampering and insider trading risks within Polymarket.
BRIDGE:BREAK: 22 Flaws in Lantronix and Silex Serial Converters
Forescout researchers uncover 22 BRIDGE:BREAK vulnerabilities in Lantronix and Silex serial-to-IP converters, risking device hijacking and data tampering.
Compromised DVRs: Identifying and Mitigating IoT Botnet Threats
Explore how Digital Video Recorders (DVRs) are compromised and incorporated into IoT botnets.
Masjesu Botnet DDoS-for-Hire: Analysis of IoT Malware Campaigns
The Masjesu botnet targets IoT devices across multiple architectures to facilitate DDoS-for-hire services via Telegram, posing risks to global infrastructure.
Masjesu Botnet: Stealthy DDoS Malware Targets Linux IoT Devices
Masjesu is a highly evasive DDoS botnet targeting Linux IoT devices. It prioritizes persistence and avoids critical infrastructure to remain undetected.
Geopolitical Exploitation of Compromised IP Cameras
Nation-states including Russia and Iran are weaponizing compromised IP cameras for battlefield intelligence and critical infrastructure surveillance.
CI/CD Pipeline Backdoors: Analyzing Recent Supply Chain Attacks
Exploration of supply chain risks in CI/CD pipelines, IoT device exploitation trends, and the security implications of government data acquisition.
DOJ Disrupts Aisuru, Kimwolf, JackSkid, and Mossad IoT Botnets
Federal authorities dismantle infrastructure for four major IoT botnets controlling 3 million devices used in record-breaking DDoS attacks worldwide.
DJI Romo Remote Camera Access via MQTT Vulnerability
An MQTT misconfiguration in DJI Romo vacuums allows unauthorized remote control and camera access for 7,000 devices. Learn the risks and mitigation steps.