#iotsecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #iotsecurity, aggregated by home.social.
-
You know what’s in your CPS environment. Now what?
Asset visibility is just the starting point. The next step is turning that knowledge into action.
📗 In this eBook, we walk you through concrete next steps taken by many Claroty customers across four solution areas: 𝗘𝘅𝗽𝗼𝘀𝘂𝗿𝗲 𝗠𝗮𝗻𝗮𝗴𝗲𝗺𝗲𝗻𝘁, 𝗦𝗲𝗰𝘂𝗿𝗲 𝗔𝗰𝗰𝗲𝘀𝘀, 𝗡𝗲𝘁𝘄𝗼𝗿𝗸 𝗣𝗿𝗼𝘁𝗲𝗰𝘁𝗶𝗼𝗻, and 𝗧𝗵𝗿𝗲𝗮𝘁 𝗗𝗲𝘁𝗲𝗰𝘁𝗶𝗼𝗻.
👉 Choose a section based on your greatest area of need to get started: https://claroty.com/resources/reports/the-cyber-physical-systems-security-playbook
#CPSsecurity #Cybersecurity #OT #OTSecurity #IoTSecurity #ExposureManagement
-
You know what’s in your CPS environment. Now what?
Asset visibility is just the starting point. The next step is turning that knowledge into action.
📗 In this eBook, we walk you through concrete next steps taken by many Claroty customers across four solution areas: 𝗘𝘅𝗽𝗼𝘀𝘂𝗿𝗲 𝗠𝗮𝗻𝗮𝗴𝗲𝗺𝗲𝗻𝘁, 𝗦𝗲𝗰𝘂𝗿𝗲 𝗔𝗰𝗰𝗲𝘀𝘀, 𝗡𝗲𝘁𝘄𝗼𝗿𝗸 𝗣𝗿𝗼𝘁𝗲𝗰𝘁𝗶𝗼𝗻, and 𝗧𝗵𝗿𝗲𝗮𝘁 𝗗𝗲𝘁𝗲𝗰𝘁𝗶𝗼𝗻.
👉 Choose a section based on your greatest area of need to get started: https://claroty.com/resources/reports/the-cyber-physical-systems-security-playbook
#CPSsecurity #Cybersecurity #OT #OTSecurity #IoTSecurity #ExposureManagement
-
CVE-2026-68067 (CVSS 9.8) lets attackers control user accounts on the Mira Hormone Monitor by bypassing the cloud login. Eight flaws total.
#MiraMonitor #CVE202668067 #MedicalDevice #AccountTakeover #CISA #IoTSecurity #Cybersecurity
-
CVE-2026-68067 (CVSS 9.8) lets attackers control user accounts on the Mira Hormone Monitor by bypassing the cloud login. Eight flaws total.
#MiraMonitor #CVE202668067 #MedicalDevice #AccountTakeover #CISA #IoTSecurity #Cybersecurity
-
CVE-2026-68067 (CVSS 9.8) lets attackers control user accounts on the Mira Hormone Monitor by bypassing the cloud login. Eight flaws total.
#MiraMonitor #CVE202668067 #MedicalDevice #AccountTakeover #CISA #IoTSecurity #Cybersecurity
-
🏠🔐 YOUR HOME IS CONNECTED. IS IT PROTECTED?
Smart cameras, lights, speakers, locks and other IoT devices make life easier — but every connected device can become a potential security risk. 📱🛡️
Secure your network. Update your devices. Control access. Protect your smart home. ⚡
#SmartHome #CyberSecurity #IoTSecurity #OnlineSafety #Privacy
-
🏠🔐 YOUR HOME IS CONNECTED. IS IT PROTECTED?
Smart cameras, lights, speakers, locks and other IoT devices make life easier — but every connected device can become a potential security risk. 📱🛡️
Secure your network. Update your devices. Control access. Protect your smart home. ⚡
#SmartHome #CyberSecurity #IoTSecurity #OnlineSafety #Privacy
-
🏠🔐 YOUR HOME IS CONNECTED. IS IT PROTECTED?
Smart cameras, lights, speakers, locks and other IoT devices make life easier — but every connected device can become a potential security risk. 📱🛡️
Secure your network. Update your devices. Control access. Protect your smart home. ⚡
#SmartHome #CyberSecurity #IoTSecurity #OnlineSafety #Privacy
-
🏠🔐 YOUR HOME IS CONNECTED. IS IT PROTECTED?
Smart cameras, lights, speakers, locks and other IoT devices make life easier — but every connected device can become a potential security risk. 📱🛡️
Secure your network. Update your devices. Control access. Protect your smart home. ⚡
#SmartHome #CyberSecurity #IoTSecurity #OnlineSafety #Privacy
-
🏠🔐 YOUR HOME IS CONNECTED. IS IT PROTECTED?
Smart cameras, lights, speakers, locks and other IoT devices make life easier — but every connected device can become a potential security risk. 📱🛡️
Secure your network. Update your devices. Control access. Protect your smart home. ⚡
#SmartHome #CyberSecurity #IoTSecurity #OnlineSafety #Privacy
-
Mira Firmware v1.7.1.47 has a CRITICAL auth bug (CVE-2026-68067): login accepts any valid-format password, exposing hormone records. No patch yet; restrict access & monitor accounts. https://radar.offseq.com/threat/cve-2026-68067-cwe-1390-weak-authentication-in-quanovate-tech-inc-operating-as-mira-mira-care-mira-85cdd6a62acb5a46 #OffSeq #Vulnerability #IoTSecurity #CVE202668067
-
Mira Firmware v1.7.1.47 has a CRITICAL auth bug (CVE-2026-68067): login accepts any valid-format password, exposing hormone records. No patch yet; restrict access & monitor accounts. https://radar.offseq.com/threat/cve-2026-68067-cwe-1390-weak-authentication-in-quanovate-tech-inc-operating-as-mira-mira-care-mira-85cdd6a62acb5a46 #OffSeq #Vulnerability #IoTSecurity #CVE202668067
-
Mira Firmware v1.7.1.47 has a CRITICAL auth bug (CVE-2026-68067): login accepts any valid-format password, exposing hormone records. No patch yet; restrict access & monitor accounts. https://radar.offseq.com/threat/cve-2026-68067-cwe-1390-weak-authentication-in-quanovate-tech-inc-operating-as-mira-mira-care-mira-85cdd6a62acb5a46 #OffSeq #Vulnerability #IoTSecurity #CVE202668067
-
Mira Firmware v1.7.1.47 has a CRITICAL auth bug (CVE-2026-68067): login accepts any valid-format password, exposing hormone records. No patch yet; restrict access & monitor accounts. https://radar.offseq.com/threat/cve-2026-68067-cwe-1390-weak-authentication-in-quanovate-tech-inc-operating-as-mira-mira-care-mira-85cdd6a62acb5a46 #OffSeq #Vulnerability #IoTSecurity #CVE202668067
-
CVE-2026-19348 in Shenzhen Aitemi M300 Wi-Fi Repeater: CRITICAL command injection via /protocol.csp (enable, name, mac). Public exploit code out; no patch yet. Restrict access & monitor traffic. https://radar.offseq.com/threat/cve-2026-19348-command-injection-in-shenzhen-aitemi-m300-wi-fi-repeater-50170c9de7b315c0 #OffSeq #CVE202619348 #IoTSecurity
-
CVE-2026-19348 in Shenzhen Aitemi M300 Wi-Fi Repeater: CRITICAL command injection via /protocol.csp (enable, name, mac). Public exploit code out; no patch yet. Restrict access & monitor traffic. https://radar.offseq.com/threat/cve-2026-19348-command-injection-in-shenzhen-aitemi-m300-wi-fi-repeater-50170c9de7b315c0 #OffSeq #CVE202619348 #IoTSecurity
-
CVE-2026-19348 in Shenzhen Aitemi M300 Wi-Fi Repeater: CRITICAL command injection via /protocol.csp (enable, name, mac). Public exploit code out; no patch yet. Restrict access & monitor traffic. https://radar.offseq.com/threat/cve-2026-19348-command-injection-in-shenzhen-aitemi-m300-wi-fi-repeater-50170c9de7b315c0 #OffSeq #CVE202619348 #IoTSecurity
-
CVE-2026-19348 in Shenzhen Aitemi M300 Wi-Fi Repeater: CRITICAL command injection via /protocol.csp (enable, name, mac). Public exploit code out; no patch yet. Restrict access & monitor traffic. https://radar.offseq.com/threat/cve-2026-19348-command-injection-in-shenzhen-aitemi-m300-wi-fi-repeater-50170c9de7b315c0 #OffSeq #CVE202619348 #IoTSecurity
-
TIL that the UK government’s Code of Practice for consumer IoT security was published 14 October 2018
-
TIL that the UK government’s Code of Practice for consumer IoT security was published 14 October 2018
-
TIL that the UK government’s Code of Practice for consumer IoT security was published 14 October 2018
-
TIL that the UK government’s Code of Practice for consumer IoT security was published 14 October 2018
-
TIL that the UK government’s Code of Practice for consumer IoT security was published 14 October 2018
-
💡 Can a smart light bulb put your home network at risk?
Not by magic—but like any Internet-connected device, a vulnerable or poorly secured smart bulb can become an entry point if it isn't updated or configured properly. In this Reel, I show why securing every smart device matters—not just your computer or phone.
💬 Comment "IoT" if you want more smart home security tips.
-
💡 Can a smart light bulb put your home network at risk?
Not by magic—but like any Internet-connected device, a vulnerable or poorly secured smart bulb can become an entry point if it isn't updated or configured properly. In this Reel, I show why securing every smart device matters—not just your computer or phone.
💬 Comment "IoT" if you want more smart home security tips.
-
💡 Can a smart light bulb put your home network at risk?
Not by magic—but like any Internet-connected device, a vulnerable or poorly secured smart bulb can become an entry point if it isn't updated or configured properly. In this Reel, I show why securing every smart device matters—not just your computer or phone.
💬 Comment "IoT" if you want more smart home security tips.
-
💡 Can a smart light bulb put your home network at risk?
Not by magic—but like any Internet-connected device, a vulnerable or poorly secured smart bulb can become an entry point if it isn't updated or configured properly. In this Reel, I show why securing every smart device matters—not just your computer or phone.
💬 Comment "IoT" if you want more smart home security tips.
-
💡 Can a smart light bulb put your home network at risk?
Not by magic—but like any Internet-connected device, a vulnerable or poorly secured smart bulb can become an entry point if it isn't updated or configured properly. In this Reel, I show why securing every smart device matters—not just your computer or phone.
💬 Comment "IoT" if you want more smart home security tips.
-
CVE-2026-18684 | CRITICAL command injection in GL.iNet GL-MT3000 (fw 4.4.0 – 4.4.5) 🛡️ Remote attackers can execute commands — no patch yet. Restrict access and watch for vendor updates. Info: https://radar.offseq.com/threat/cve-2026-18684-command-injection-in-glinet-gl-mt3000-4a4de87391e0f428 #OffSeq #CVE202618684 #IoTSecurity
-
CVE-2026-18684 | CRITICAL command injection in GL.iNet GL-MT3000 (fw 4.4.0 – 4.4.5) 🛡️ Remote attackers can execute commands — no patch yet. Restrict access and watch for vendor updates. Info: https://radar.offseq.com/threat/cve-2026-18684-command-injection-in-glinet-gl-mt3000-4a4de87391e0f428 #OffSeq #CVE202618684 #IoTSecurity
-
CVE-2026-18684 | CRITICAL command injection in GL.iNet GL-MT3000 (fw 4.4.0 – 4.4.5) 🛡️ Remote attackers can execute commands — no patch yet. Restrict access and watch for vendor updates. Info: https://radar.offseq.com/threat/cve-2026-18684-command-injection-in-glinet-gl-mt3000-4a4de87391e0f428 #OffSeq #CVE202618684 #IoTSecurity
-
CVE-2026-18684 | CRITICAL command injection in GL.iNet GL-MT3000 (fw 4.4.0 – 4.4.5) 🛡️ Remote attackers can execute commands — no patch yet. Restrict access and watch for vendor updates. Info: https://radar.offseq.com/threat/cve-2026-18684-command-injection-in-glinet-gl-mt3000-4a4de87391e0f428 #OffSeq #CVE202618684 #IoTSecurity
-
CVE-2026-18589 (CRITICAL, CVSS 9.3) in Wavlink WL-NU516U1: Stack buffer overflow in nas.cgi enables unauthenticated RCE/DoS. Patch available — update ASAP. https://radar.offseq.com/threat/cve-2026-18589-stack-based-buffer-overflow-in-wavlink-wl-nu516u1-be242f6f491145cd #OffSeq #CVE202618589 #IoTSecurity #PatchManagement
-
CVE-2026-18589 (CRITICAL, CVSS 9.3) in Wavlink WL-NU516U1: Stack buffer overflow in nas.cgi enables unauthenticated RCE/DoS. Patch available — update ASAP. https://radar.offseq.com/threat/cve-2026-18589-stack-based-buffer-overflow-in-wavlink-wl-nu516u1-be242f6f491145cd #OffSeq #CVE202618589 #IoTSecurity #PatchManagement
-
CVE-2026-18589 (CRITICAL, CVSS 9.3) in Wavlink WL-NU516U1: Stack buffer overflow in nas.cgi enables unauthenticated RCE/DoS. Patch available — update ASAP. https://radar.offseq.com/threat/cve-2026-18589-stack-based-buffer-overflow-in-wavlink-wl-nu516u1-be242f6f491145cd #OffSeq #CVE202618589 #IoTSecurity #PatchManagement
-
CVE-2026-18589 (CRITICAL, CVSS 9.3) in Wavlink WL-NU516U1: Stack buffer overflow in nas.cgi enables unauthenticated RCE/DoS. Patch available — update ASAP. https://radar.offseq.com/threat/cve-2026-18589-stack-based-buffer-overflow-in-wavlink-wl-nu516u1-be242f6f491145cd #OffSeq #CVE202618589 #IoTSecurity #PatchManagement
-
An OpenRemote vulnerability, CVE-2026-66013 (CVSS 9.3), enables unauthenticated asset takeover. Full advisory details are now public. Patch to 1.26.2.
#OpenRemote #CVE202666013 #IoTSecurity #AssetTakeover
https://securityonline.info/openremote-cve-2026-66013/?utm_source=mastodon&utm_medium=jetpack_social
-
I just published my first ever GitHub repo!
fwpt - Firmware Pentest ToolkitA fast native C scanner for extracted IoT/embedded firmware filesystems.
Finds hardcoded creds, keys and sensitive configs with zero noise.
Super lightweight, no deps.https://github.com/bashcore/fwpt
#infosec #firmware #iotsecurity #pentest #opensource #cprogramming
-
I just published my first ever GitHub repo!
fwpt - Firmware Pentest ToolkitA fast native C scanner for extracted IoT/embedded firmware filesystems.
Finds hardcoded creds, keys and sensitive configs with zero noise.
Super lightweight, no deps.https://github.com/bashcore/fwpt
#infosec #firmware #iotsecurity #pentest #opensource #cprogramming
-
I just published my first ever GitHub repo!
fwpt - Firmware Pentest ToolkitA fast native C scanner for extracted IoT/embedded firmware filesystems.
Finds hardcoded creds, keys and sensitive configs with zero noise.
Super lightweight, no deps.https://github.com/bashcore/fwpt
#infosec #firmware #iotsecurity #pentest #opensource #cprogramming
-
I just published my first ever GitHub repo!
fwpt - Firmware Pentest ToolkitA fast native C scanner for extracted IoT/embedded firmware filesystems.
Finds hardcoded creds, keys and sensitive configs with zero noise.
Super lightweight, no deps.https://github.com/bashcore/fwpt
#infosec #firmware #iotsecurity #pentest #opensource #cprogramming
-
I just published my first ever GitHub repo!
fwpt - Firmware Pentest ToolkitA fast native C scanner for extracted IoT/embedded firmware filesystems.
Finds hardcoded creds, keys and sensitive configs with zero noise.
Super lightweight, no deps.https://github.com/bashcore/fwpt
#infosec #firmware #iotsecurity #pentest #opensource #cprogramming
-
CVE-2026-8983: Autel Maxi Charger Single ≤1.03.51 is affected by a CRITICAL flaw — hard-coded token bypasses authentication, exposing management endpoints. Restrict access & monitor for abuse. Patch status unknown. https://radar.offseq.com/threat/autel-maxi-charger-single-firmware-through-v10351-contains-a-hard-coded-authentication-token-that-cb2fec544a5f031e #OffSeq #CVE20268983 #IoTSecurity
-
CVE-2026-8983: Autel Maxi Charger Single ≤1.03.51 is affected by a CRITICAL flaw — hard-coded token bypasses authentication, exposing management endpoints. Restrict access & monitor for abuse. Patch status unknown. https://radar.offseq.com/threat/autel-maxi-charger-single-firmware-through-v10351-contains-a-hard-coded-authentication-token-that-cb2fec544a5f031e #OffSeq #CVE20268983 #IoTSecurity
-
CVE-2026-8983: Autel Maxi Charger Single ≤1.03.51 is affected by a CRITICAL flaw — hard-coded token bypasses authentication, exposing management endpoints. Restrict access & monitor for abuse. Patch status unknown. https://radar.offseq.com/threat/autel-maxi-charger-single-firmware-through-v10351-contains-a-hard-coded-authentication-token-that-cb2fec544a5f031e #OffSeq #CVE20268983 #IoTSecurity
-
CVE-2026-8983: Autel Maxi Charger Single ≤1.03.51 is affected by a CRITICAL flaw — hard-coded token bypasses authentication, exposing management endpoints. Restrict access & monitor for abuse. Patch status unknown. https://radar.offseq.com/threat/autel-maxi-charger-single-firmware-through-v10351-contains-a-hard-coded-authentication-token-that-cb2fec544a5f031e #OffSeq #CVE20268983 #IoTSecurity
-
A Shark robot vacuum vulnerability lets attackers run code remotely, hijack movement, and access cameras. Over 673,000 devices confirmed exposed, unpatched.
#Shark #SharkNinja #RCE #IoTSecurity #RobotVacuum #Vulnerability
https://meterpreter.org/shark-vacuum-rce/?utm_source=mastodon&utm_medium=jetpack_social
-
A Shark robot vacuum vulnerability lets attackers run code remotely, hijack movement, and access cameras. Over 673,000 devices confirmed exposed, unpatched.
#Shark #SharkNinja #RCE #IoTSecurity #RobotVacuum #Vulnerability
https://meterpreter.org/shark-vacuum-rce/?utm_source=mastodon&utm_medium=jetpack_social
-
A TP-Link Kasa vulnerability (CVE-2026-9770) lets local attackers steal admin credentials via a hardcoded key. Patch your EC70 and EC71 firmware now.
#TPLink #Kasa #CVE20269770 #IoTSecurity #Cameras #ManInTheMiddle
https://meterpreter.org/tp-link-kasa-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
-
A TP-Link Kasa vulnerability (CVE-2026-9770) lets local attackers steal admin credentials via a hardcoded key. Patch your EC70 and EC71 firmware now.
#TPLink #Kasa #CVE20269770 #IoTSecurity #Cameras #ManInTheMiddle
https://meterpreter.org/tp-link-kasa-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
-
A TP-Link Kasa vulnerability (CVE-2026-9770) lets local attackers steal admin credentials via a hardcoded key. Patch your EC70 and EC71 firmware now.
#TPLink #Kasa #CVE20269770 #IoTSecurity #Cameras #ManInTheMiddle
https://meterpreter.org/tp-link-kasa-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
-
CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: https://radar.offseq.com/threat/cve-2026-42566-cwe-20-improper-input-validation-in-meshtastic-firmware-f4cb4608f8fc25f1 #OffSeq #infosec #CVE #IoTSecurity
-
CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: https://radar.offseq.com/threat/cve-2026-42566-cwe-20-improper-input-validation-in-meshtastic-firmware-f4cb4608f8fc25f1 #OffSeq #infosec #CVE #IoTSecurity
-
CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: https://radar.offseq.com/threat/cve-2026-42566-cwe-20-improper-input-validation-in-meshtastic-firmware-f4cb4608f8fc25f1 #OffSeq #infosec #CVE #IoTSecurity
-
CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: https://radar.offseq.com/threat/cve-2026-42566-cwe-20-improper-input-validation-in-meshtastic-firmware-f4cb4608f8fc25f1 #OffSeq #infosec #CVE #IoTSecurity