<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Iot Security</title><description>Cybersecurity articles tagged #Iot Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Australia Pilot: Smart Device Security Labelling Scheme</title><link>https://runtimerebel.com/blog/australia-pilot-smart-device-security-labelling-scheme</link><guid isPermaLink="true">https://runtimerebel.com/blog/australia-pilot-smart-device-security-labelling-scheme</guid><description>Australia launches a pilot program for smart device security labelling, aiming to empower consumers with clear information on IoT product security.</description><pubDate>Fri, 21 Aug 2026 16:25:52 GMT</pubDate><category>Iot Security</category><category>Australia</category><category>Regulatory Compliance</category><category>Cybersecurity Policy</category><category>Smart Devices</category></item><item><title>Generic Streaming Sticks: Covert Proxy Networks &amp; Ad Fraud Exposed</title><link>https://runtimerebel.com/blog/generic-streaming-sticks-covert-proxy-networks-ad-fraud-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/generic-streaming-sticks-covert-proxy-networks-ad-fraud-exposed</guid><description>Generic TV streaming sticks are being used in a dual-pronged attack: creating a covert proxy network and engaging in extensive ad fraud through spoofed mobile traffic on…</description><pubDate>Thu, 30 Jul 2026 17:31:49 GMT</pubDate><category>Ad Fraud</category><category>Proxy Network</category><category>Streaming Devices</category><category>Iot Security</category><category>Botnet</category><category>Consumer Devices</category></item><item><title>Tengu Botnet Exploits Linux Watchdog for Reboot-Based Persistence</title><link>https://runtimerebel.com/blog/tengu-botnet-exploits-linux-watchdog-for-reboot-based-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/tengu-botnet-exploits-linux-watchdog-for-reboot-based-persistence</guid><description>The Mirai-derived Tengu botnet utilizes hardware watchdog timers to trigger reboots when its process is terminated, ensuring persistence on Linux devices.</description><pubDate>Tue, 28 Jul 2026 17:36:22 GMT</pubDate><category>Tengu</category><category>Mirai</category><category>Linux Botnet</category><category>Iot Security</category><category>DDoS</category></item><item><title>Hikvision ISAPI Scanning Trends: Analysis and Mitigation Guide</title><link>https://runtimerebel.com/blog/hikvision-isapi-scanning-trends-analysis-and-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/hikvision-isapi-scanning-trends-analysis-and-mitigation-guide</guid><description>Recent honeypot data reveals a surge in probes targeting the Hikvision Intelligent Security API. Learn how to identify and defend against these IoT scans.</description><pubDate>Sun, 19 Jul 2026 17:02:19 GMT</pubDate><category>Hikvision</category><category>ISAPI</category><category>Iot Security</category><category>CVE-2021-36260</category><category>Botnet</category></item><item><title>FatFs Vulnerabilities: Securing Embedded Devices Against RCE</title><link>https://runtimerebel.com/blog/fatfs-vulnerabilities-securing-embedded-devices-against-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/fatfs-vulnerabilities-securing-embedded-devices-against-rce</guid><description>Security researchers at runZero have disclosed seven vulnerabilities in the widely used FatFs library, impacting millions of IoT and industrial devices.</description><pubDate>Sat, 04 Jul 2026 03:19:25 GMT</pubDate><category>FatFs</category><category>Embedded Security</category><category>Iot Security</category><category>Filesystem Vulnerabilities</category><category>runZero</category></item><item><title>NIST Drafts Updated IoT Security Guidance for Federal Networks</title><link>https://runtimerebel.com/blog/nist-drafts-updated-iot-security-guidance-for-federal-networks</link><guid isPermaLink="true">https://runtimerebel.com/blog/nist-drafts-updated-iot-security-guidance-for-federal-networks</guid><description>NIST updates its IoT security guidance to help federal agencies manage risks and establish product cybersecurity requirements for connected devices.</description><pubDate>Thu, 25 Jun 2026 09:14:59 GMT</pubDate><category>NIST</category><category>Iot Security</category><category>Federal Cybersecurity</category><category>SP 800 213A</category><category>NIST IR 8425</category></item><item><title>CSIS Deploys First-of-Its-Kind Warrant to Neutralize Foreign Botnets</title><link>https://runtimerebel.com/blog/csis-deploys-first-of-its-kind-warrant-to-neutralize-foreign-botnets</link><guid isPermaLink="true">https://runtimerebel.com/blog/csis-deploys-first-of-its-kind-warrant-to-neutralize-foreign-botnets</guid><description>Canada&apos;s CSIS utilized a unique threat reduction warrant to access and clean botnet-infected IoT devices and servers located within Canadian borders.</description><pubDate>Mon, 22 Jun 2026 10:08:59 GMT</pubDate><category>CSIS</category><category>Botnet Cleanup</category><category>Iot Security</category><category>Active Defense</category><category>Canada</category></item><item><title>Yarbo Mobile App &amp; Cloud: Critical Robot Fleet Vulnerabilities</title><link>https://runtimerebel.com/blog/yarbo-mobile-app-cloud-critical-robot-fleet-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/yarbo-mobile-app-cloud-critical-robot-fleet-vulnerabilities</guid><description>Critical vulnerabilities CVE-2026-10557 &amp; CVE-2026-7368 in Yarbo mobile app and cloud allow attackers to control robot fleets via hard-coded credentials.</description><pubDate>Thu, 11 Jun 2026 17:28:13 GMT</pubDate><category>CVE-2026-10557</category><category>CVE-2026-7368</category><category>Yarbo</category><category>Iot Security</category><category>Hard Coded Credentials</category><category>Missing Authorization</category><category>MQTT Security</category></item><item><title>C0XMO Botnet Targets DD-WRT Router Firmware — Analysis and Mitigation</title><link>https://runtimerebel.com/blog/c0xmo-botnet-targets-dd-wrt-router-firmware-analysis-and-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/c0xmo-botnet-targets-dd-wrt-router-firmware-analysis-and-mitigation</guid><description>C0XMO, a Gafgyt-based botnet, exploits DD-WRT router vulnerabilities to launch DDoS attacks and eliminate rival malware on infected IoT devices.</description><pubDate>Sun, 07 Jun 2026 16:34:52 GMT</pubDate><category>C0XMO</category><category>Gafgyt</category><category>DD WRT</category><category>Iot Security</category><category>DDoS</category><category>Botnet</category></item><item><title>Bright Data SDK: Smart TVs Used as AI Web-Scraping Proxies</title><link>https://runtimerebel.com/blog/bright-data-sdk-smart-tvs-used-as-ai-web-scraping-proxies</link><guid isPermaLink="true">https://runtimerebel.com/blog/bright-data-sdk-smart-tvs-used-as-ai-web-scraping-proxies</guid><description>Smart TVs and iOS apps are being converted into web-scraping exit nodes via embedded SDKs, fueling residential proxy networks used by AI companies.</description><pubDate>Sat, 06 Jun 2026 08:58:49 GMT</pubDate><category>Bright Data</category><category>Residential Proxy</category><category>Iot Security</category><category>Smart TV</category><category>SDK Exploitation</category></item><item><title>Google Gemini Hijack: Command Injection via Messaging Notifications</title><link>https://runtimerebel.com/blog/google-gemini-hijack-command-injection-via-messaging-notifications</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-gemini-hijack-command-injection-via-messaging-notifications</guid><description>Researchers demonstrate how Google Gemini voice assistant can be hijacked via malicious messaging notifications to control smart homes and start video calls.</description><pubDate>Thu, 04 Jun 2026 13:16:24 GMT</pubDate><category>Google Gemini</category><category>Prompt Injection</category><category>Voice Assistant</category><category>Iot Security</category><category>Android Security</category></item><item><title>Dutch Police Seize 200 Servers to Dismantle 17-Million Device Botnet</title><link>https://runtimerebel.com/blog/dutch-police-seize-200-servers-to-dismantle-17-million-device-botnet</link><guid isPermaLink="true">https://runtimerebel.com/blog/dutch-police-seize-200-servers-to-dismantle-17-million-device-botnet</guid><description>Dutch authorities and the NCSC dismantled a global botnet affecting 17 million devices. Learn how the seizure of 200 servers impacts global cybercrime operations.</description><pubDate>Sun, 31 May 2026 16:31:15 GMT</pubDate><category>Botnet</category><category>Dutch Politie</category><category>NCSC</category><category>Iot Security</category><category>Infrastructure Takedown</category></item><item><title>Kimwolf Botmaster Arrested: Impacts on IoT Botnet DDoS Mitigation</title><link>https://runtimerebel.com/blog/kimwolf-botmaster-arrested-impacts-on-iot-botnet-ddos-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/kimwolf-botmaster-arrested-impacts-on-iot-botnet-ddos-mitigation</guid><description>Canadian and U.S. authorities arrest the alleged operator of the massive Kimwolf IoT botnet, linked to millions of compromised devices and disruptive DDoS attacks.</description><pubDate>Fri, 22 May 2026 00:56:39 GMT</pubDate><category>Kimwolf</category><category>Botnet</category><category>Iot Security</category><category>DDoS</category><category>Cyber Arrest</category></item><item><title>Gafgyt and Mirai Variants Target IoT Devices via CVE-2017-17215</title><link>https://runtimerebel.com/blog/gafgyt-and-mirai-variants-target-iot-devices-via-cve-2017-17215</link><guid isPermaLink="true">https://runtimerebel.com/blog/gafgyt-and-mirai-variants-target-iot-devices-via-cve-2017-17215</guid><description>Analysis of Gafgyt and Mirai botnet activity targeting IoT devices through RCE vulnerabilities such as CVE-2017-17215 and CVE-2014-2320.</description><pubDate>Fri, 08 May 2026 08:41:11 GMT</pubDate><category>Gafgyt</category><category>Mirai</category><category>CVE-2017-17215</category><category>Iot Security</category><category>Botnet</category></item><item><title>Mirai-Based xlabs_v1 Botnet Hijacks IoT Devices via ADB</title><link>https://runtimerebel.com/blog/mirai-based-xlabs-v1-botnet-hijacks-iot-devices-via-adb</link><guid isPermaLink="true">https://runtimerebel.com/blog/mirai-based-xlabs-v1-botnet-hijacks-iot-devices-via-adb</guid><description>Learn how the xlabs_v1 botnet exploits Android Debug Bridge (ADB) on port 5555 to enroll IoT devices into a DDoS network and how to secure your hardware.</description><pubDate>Thu, 07 May 2026 00:50:20 GMT</pubDate><category>Xlabs V1</category><category>Mirai Variant</category><category>ADB Exploitation</category><category>Iot Security</category><category>DDoS Botnet</category></item><item><title>Security Analysis of Prediction Market Oracle Manipulation on Polymarket</title><link>https://runtimerebel.com/blog/security-analysis-of-prediction-market-oracle-manipulation-on-polymarket</link><guid isPermaLink="true">https://runtimerebel.com/blog/security-analysis-of-prediction-market-oracle-manipulation-on-polymarket</guid><description>An investigation into the vulnerabilities of decentralized oracles, including physical sensor tampering and insider trading risks within Polymarket.</description><pubDate>Mon, 04 May 2026 12:44:50 GMT</pubDate><category>Polymarket</category><category>Oracle Security</category><category>Insider Trading</category><category>Iot Security</category><category>Prediction Markets</category></item><item><title>BRIDGE:BREAK: 22 Flaws in Lantronix and Silex Serial Converters</title><link>https://runtimerebel.com/blog/bridge-break-22-flaws-in-lantronix-and-silex-serial-converters</link><guid isPermaLink="true">https://runtimerebel.com/blog/bridge-break-22-flaws-in-lantronix-and-silex-serial-converters</guid><description>Forescout researchers uncover 22 BRIDGE:BREAK vulnerabilities in Lantronix and Silex serial-to-IP converters, risking device hijacking and data tampering.</description><pubDate>Tue, 21 Apr 2026 16:29:38 GMT</pubDate><category>BRIDGE BREAK</category><category>Lantronix</category><category>Silex</category><category>Serial to Ethernet</category><category>Iot Security</category><category>Industrial Control Systems</category></item><item><title>Compromised DVRs: Identifying and Mitigating IoT Botnet Threats</title><link>https://runtimerebel.com/blog/compromised-dvrs-identifying-and-mitigating-iot-botnet-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/compromised-dvrs-identifying-and-mitigating-iot-botnet-threats</guid><description>Explore how Digital Video Recorders (DVRs) are compromised and incorporated into IoT botnets.</description><pubDate>Thu, 16 Apr 2026 00:48:59 GMT</pubDate><category>DVR</category><category>Iot Security</category><category>Botnet</category><category>Shodan</category><category>Compromise</category><category>DDoS</category></item><item><title>Masjesu Botnet DDoS-for-Hire: Analysis of IoT Malware Campaigns</title><link>https://runtimerebel.com/blog/masjesu-botnet-ddos-for-hire-analysis-of-iot-malware-campaigns</link><guid isPermaLink="true">https://runtimerebel.com/blog/masjesu-botnet-ddos-for-hire-analysis-of-iot-malware-campaigns</guid><description>The Masjesu botnet targets IoT devices across multiple architectures to facilitate DDoS-for-hire services via Telegram, posing risks to global infrastructure.</description><pubDate>Wed, 08 Apr 2026 20:18:14 GMT</pubDate><category>Masjesu Botnet</category><category>DDoS</category><category>Iot Security</category><category>Malware Analysis</category><category>Telegram Botnet</category></item><item><title>Masjesu Botnet: Stealthy DDoS Malware Targets Linux IoT Devices</title><link>https://runtimerebel.com/blog/masjesu-botnet-stealthy-ddos-malware-targets-linux-iot-devices</link><guid isPermaLink="true">https://runtimerebel.com/blog/masjesu-botnet-stealthy-ddos-malware-targets-linux-iot-devices</guid><description>Masjesu is a highly evasive DDoS botnet targeting Linux IoT devices. It prioritizes persistence and avoids critical infrastructure to remain undetected.</description><pubDate>Wed, 08 Apr 2026 12:27:42 GMT</pubDate><category>Masjesu</category><category>Iot Security</category><category>DDoS Botnet</category><category>Linux Malware</category><category>Persistence Mechanisms</category></item><item><title>Geopolitical Exploitation of Compromised IP Cameras</title><link>https://runtimerebel.com/blog/geopolitical-exploitation-of-compromised-ip-cameras</link><guid isPermaLink="true">https://runtimerebel.com/blog/geopolitical-exploitation-of-compromised-ip-cameras</guid><description>Nation-states including Russia and Iran are weaponizing compromised IP cameras for battlefield intelligence and critical infrastructure surveillance.</description><pubDate>Fri, 27 Mar 2026 16:26:24 GMT</pubDate><category>Iot Security</category><category>IP Cameras</category><category>Sandworm</category><category>Geopolitical Cyber Risk</category><category>Surveillance</category></item><item><title>CI/CD Pipeline Backdoors: Analyzing Recent Supply Chain Attacks</title><link>https://runtimerebel.com/blog/ci-cd-pipeline-backdoors-analyzing-recent-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/ci-cd-pipeline-backdoors-analyzing-recent-supply-chain-attacks</guid><description>Exploration of supply chain risks in CI/CD pipelines, IoT device exploitation trends, and the security implications of government data acquisition.</description><pubDate>Mon, 23 Mar 2026 16:24:41 GMT</pubDate><category>CI CD Security</category><category>Supply Chain Attack</category><category>Iot Security</category><category>Pipeline Backdoor</category></item><item><title>DOJ Disrupts Aisuru, Kimwolf, JackSkid, and Mossad IoT Botnets</title><link>https://runtimerebel.com/blog/doj-disrupts-aisuru-kimwolf-jackskid-and-mossad-iot-botnets</link><guid isPermaLink="true">https://runtimerebel.com/blog/doj-disrupts-aisuru-kimwolf-jackskid-and-mossad-iot-botnets</guid><description>Federal authorities dismantle infrastructure for four major IoT botnets controlling 3 million devices used in record-breaking DDoS attacks worldwide.</description><pubDate>Fri, 20 Mar 2026 04:38:34 GMT</pubDate><category>AISURU</category><category>Kimwolf</category><category>JackSkid</category><category>Mossad</category><category>DDoS</category><category>Iot Security</category><category>Botnet Disruption</category></item><item><title>DJI Romo Remote Camera Access via MQTT Vulnerability</title><link>https://runtimerebel.com/blog/dji-romo-remote-camera-access-via-mqtt-vulnerability</link><guid isPermaLink="true">https://runtimerebel.com/blog/dji-romo-remote-camera-access-via-mqtt-vulnerability</guid><description>An MQTT misconfiguration in DJI Romo vacuums allows unauthorized remote control and camera access for 7,000 devices. Learn the risks and mitigation steps.</description><pubDate>Thu, 19 Mar 2026 12:21:00 GMT</pubDate><category>Dji Romo</category><category>Iot Security</category><category>Mqtt Vulnerability</category><category>Privacy Breach</category></item><item><title>IoT Default Credentials: Preventing Unauthorized Admin Access</title><link>https://runtimerebel.com/blog/iot-default-credentials-preventing-unauthorized-admin-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/iot-default-credentials-preventing-unauthorized-admin-access</guid><description>The SANS ISC highlights the persistent threat of IoT devices compromised by default admin credentials. Learn critical steps to secure your smart devices.</description><pubDate>Thu, 12 Mar 2026 04:38:58 GMT</pubDate><category>Iot Security</category><category>Default Credentials</category><category>Credential Exploitation</category><category>Device Hardening</category></item><item><title>Iran Integrates Cyber-Kinetic Operations into Military Doctrine</title><link>https://runtimerebel.com/blog/iran-integrates-cyber-kinetic-operations-into-military-doctrine</link><guid isPermaLink="true">https://runtimerebel.com/blog/iran-integrates-cyber-kinetic-operations-into-military-doctrine</guid><description>Iran is leveraging cyber operations, including IP camera exploitation, to support kinetic military strikes and physical asset targeting globally.</description><pubDate>Fri, 06 Mar 2026 16:23:44 GMT</pubDate><category>Iran</category><category>Cyber Kinetic</category><category>Iot Security</category><category>Physical Security</category><category>Threat Intelligence</category></item><item><title>SD-WAN Zero-Day and Smart TV Proxy SDK Vulnerabilities Recap</title><link>https://runtimerebel.com/blog/sd-wan-zero-day-and-smart-tv-proxy-sdk-vulnerabilities-recap</link><guid isPermaLink="true">https://runtimerebel.com/blog/sd-wan-zero-day-and-smart-tv-proxy-sdk-vulnerabilities-recap</guid><description>Technical analysis of recent SD-WAN zero-day exploits and Smart TV proxy SDK risks, detailing how network infrastructure is increasingly targeted.</description><pubDate>Mon, 02 Mar 2026 16:17:18 GMT</pubDate><category>SD WAN</category><category>Zero-Day</category><category>Iot Security</category><category>Supply Chain</category><category>SDK Vulnerability</category></item><item><title>Samsung Settles Texas Privacy Dispute Over Smart TV Data Collection</title><link>https://runtimerebel.com/blog/samsung-settles-texas-privacy-dispute-over-smart-tv-data-collection</link><guid isPermaLink="true">https://runtimerebel.com/blog/samsung-settles-texas-privacy-dispute-over-smart-tv-data-collection</guid><description>Samsung settles with Texas over unauthorized smart TV data collection, mandating explicit consent for ACR features and highlighting regional privacy risks.</description><pubDate>Sun, 01 Mar 2026 16:09:03 GMT</pubDate><category>Samsung</category><category>Data Privacy</category><category>ACR</category><category>Texas Data Privacy and Security Act</category><category>Iot Security</category><category>TDPSA</category></item><item><title>Critical Vulnerabilities in Gardyn Smart Gardens Enable Remote Takeover</title><link>https://runtimerebel.com/blog/critical-vulnerabilities-in-gardyn-smart-gardens-enable-remote-takeover</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-vulnerabilities-in-gardyn-smart-gardens-enable-remote-takeover</guid><description>CISA warns of critical flaws in Gardyn Smart Gardens, including CVE-2024-39682 and CVE-2024-39683, allowing remote code execution and unauthorized access.</description><pubDate>Fri, 27 Feb 2026 08:18:33 GMT</pubDate><category>Gardyn</category><category>Iot Security</category><category>CVE-2024-39682</category><category>CVE-2024-39683</category><category>CISA</category><category>Bitdefender</category><category>Smart Home</category></item><item><title>Amazon Ring Terminals Partnership with Flock Safety Amid Surveillance Infrastructure Shifts</title><link>https://runtimerebel.com/blog/amazon-ring-terminals-partnership-with-flock-safety-amid-surveillance-infrastructure-shifts</link><guid isPermaLink="true">https://runtimerebel.com/blog/amazon-ring-terminals-partnership-with-flock-safety-amid-surveillance-infrastructure-shifts</guid><description>Analysis of the strategic discontinuation of data integration and interoperability between Amazon&apos;s Ring ecosystem and Flock Safety&apos;s ALPR tracking network.</description><pubDate>Mon, 23 Feb 2026 05:35:46 GMT</pubDate><category>Surveillance</category><category>Iot Security</category><category>Data Privacy</category><category>ALPR</category></item></channel></rss>