home.social

#iotsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #iotsecurity, aggregated by home.social.

fetched live
  1. 🏠🔐 YOUR HOME IS CONNECTED. IS IT PROTECTED?

    Smart cameras, lights, speakers, locks and other IoT devices make life easier — but every connected device can become a potential security risk. 📱🛡️

    Secure your network. Update your devices. Control access. Protect your smart home. ⚡

    #SmartHome #CyberSecurity #IoTSecurity #OnlineSafety #Privacy

  2. 🏠🔐 YOUR HOME IS CONNECTED. IS IT PROTECTED?

    Smart cameras, lights, speakers, locks and other IoT devices make life easier — but every connected device can become a potential security risk. 📱🛡️

    Secure your network. Update your devices. Control access. Protect your smart home. ⚡

    #SmartHome #CyberSecurity #IoTSecurity #OnlineSafety #Privacy

  3. Mira Firmware v1.7.1.47 has a CRITICAL auth bug (CVE-2026-68067): login accepts any valid-format password, exposing hormone records. No patch yet; restrict access & monitor accounts. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #CVE202668067

  4. CVE-2026-19348 in Shenzhen Aitemi M300 Wi-Fi Repeater: CRITICAL command injection via /protocol.csp (enable, name, mac). Public exploit code out; no patch yet. Restrict access & monitor traffic. radar.offseq.com/threat/cve-20 #OffSeq #CVE202619348 #IoTSecurity

  5. TIL that the UK government’s Code of Practice for consumer IoT security was published 14 October 2018

    Here it is being largely ignored.

  6. TIL that the UK government’s Code of Practice for consumer IoT security was published 14 October 2018

    Here it is being largely ignored.

  7. 💡 Can a smart light bulb put your home network at risk?

    Not by magic—but like any Internet-connected device, a vulnerable or poorly secured smart bulb can become an entry point if it isn't updated or configured properly. In this Reel, I show why securing every smart device matters—not just your computer or phone.

    💬 Comment "IoT" if you want more smart home security tips.

    #CyberSecurity #IoTSecurity #SmartHome #Privacy #CyberKid

  8. 💡 Can a smart light bulb put your home network at risk?

    Not by magic—but like any Internet-connected device, a vulnerable or poorly secured smart bulb can become an entry point if it isn't updated or configured properly. In this Reel, I show why securing every smart device matters—not just your computer or phone.

    💬 Comment "IoT" if you want more smart home security tips.

    #CyberSecurity #IoTSecurity #SmartHome #Privacy #CyberKid

  9. CVE-2026-18684 | CRITICAL command injection in GL.iNet GL-MT3000 (fw 4.4.0 – 4.4.5) 🛡️ Remote attackers can execute commands — no patch yet. Restrict access and watch for vendor updates. Info: radar.offseq.com/threat/cve-20 #OffSeq #CVE202618684 #IoTSecurity

  10. I just published my first ever GitHub repo!
    fwpt - Firmware Pentest Toolkit

    A fast native C scanner for extracted IoT/embedded firmware filesystems.
    Finds hardcoded creds, keys and sensitive configs with zero noise.
    Super lightweight, no deps.

    github.com/bashcore/fwpt

    #infosec #firmware #iotsecurity #pentest #opensource #cprogramming

  11. I just published my first ever GitHub repo!
    fwpt - Firmware Pentest Toolkit

    A fast native C scanner for extracted IoT/embedded firmware filesystems.
    Finds hardcoded creds, keys and sensitive configs with zero noise.
    Super lightweight, no deps.

    github.com/bashcore/fwpt

    #infosec #firmware #iotsecurity #pentest #opensource #cprogramming

  12. CVE-2026-8983: Autel Maxi Charger Single ≤1.03.51 is affected by a CRITICAL flaw — hard-coded token bypasses authentication, exposing management endpoints. Restrict access & monitor for abuse. Patch status unknown. radar.offseq.com/threat/autel- #OffSeq #CVE20268983 #IoTSecurity

  13. CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE #IoTSecurity

  14. CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE #IoTSecurity

  15. CVE-2026-15511 (CRITICAL, CVSS 9.3): OS command injection in Comfast CF-WR631AX V3 (fw 2.7.0.0 – 2.7.0.8) enables unauthenticated remote code execution. No patch. Restrict access & disable remote mgmt. radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoTSecurity #Router

  16. CVE-2026-15481 (HIGH, CVSS 8.7) affects Trendnet TEW-635BRM <=1.00.03: Remote command injection via IPoA WAN setup. Exploit is public. Devices are EOL — replace hardware ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Infosec #IoTSecurity

  17. wolfSSL: 57 CVEs, 4 critical, 11 high. 70% unpatched. Trust Score: C. CVE trend up 24. Key flaws: CWE-295 (improper cert validation). #wolfSSL #IoTsecurity #cybersecurity

    valtersit.com/vendors/wolfssl/

  18. CVE-2026-13768: Gardyn Home Firmware (CRITICAL, CVSS 10) exposes a privileged iothubowner key, enabling attackers to control devices & move laterally on networks. No patch yet. Monitor and segment IoT devices. radar.offseq.com/threat/cve-20 #OffSeq #IoTSecurity #CVE202613768

  19. CVE-2026-13564: HIGH (CVSS 8.7) stack-based buffer overflow in Edimax EW-7478APC v1.04. Remote exploit via pppUserName; public PoC, no patch. Disable remote access or segment device. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #CVE202613564

  20. Tenda JD12L routers (fw 16.03.53.23) face HIGH severity stack-based buffer overflow (CVE-2026-13516, CVSS 8.7). Remote code execution possible — exploit code is public. Restrict remote access, monitor endpoints. radar.offseq.com/threat/cve-20 #OffSeq #infosec #IoTSecurity #CVE

  21. H.VIEW HV-500S6 IP Camera has a HIGH severity bug (CVE-2026-55975, CVSS 7.2): Authenticated users may inject commands using unsanitized XML in cert generation. Restrict access, monitor activity, and check for patches. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity 🔒

  22. CVE-2026-56414: H.VIEW HV-500S6 IP Camera has a HIGH-severity vuln (CVSS 7.2) allowing authenticated users to upload arbitrary files via certificate upload, risking persistent compromise. Restrict admin access & monitor uploads. radar.offseq.com/threat/cve-20 #OffSeq #IoTSecurity #CVE #Vulnerability

  23. GeoVision GV-LPC2011/2211 devices (≤1.12) face CRITICAL CVE-2026-57880: stack-based buffer overflow in RTSP auth enables remote, unauthenticated DoS or code execution. Restrict RTSP access, monitor traffic. Patch status unknown. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSecurity #CVE

  24. GeoVision GV-LPC2011/2211 (<=1.12) hit by CVE-2026-57881: CRITICAL stack-based buffer overflow in vlsvr enables unauthenticated RCE or DoS. No patch yet — restrict access & monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSecurity #CVE202657881

  25. CVE-2026-12851: CRITICAL OS command injection in GeoVision GV-I/O Box 4E v2.09 via DVRSearch/Network.cgi allows remote code execution. Patch status pending — restrict access & monitor endpoints. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #CVE #Security

  26. 🔍 HIGH severity: Buffer overflow in GALAYOU Y4 v1.0.0 (CVE-2026-12192). Exploitable via local network — no patch or vendor response yet. Restrict network access & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSecurity #BufferOverflow

  27. Iran built cameras to surveil its people. Israel hacked them, tracked Khamenei's guards for years, and killed him on Feb 28, 2026 with 30 precision strikes. Authoritarianism built the weapon that killed its author. #Unit8200 #IoTsecurity #CyberWar

  28. Iran built cameras to surveil its people. Israel hacked them, tracked Khamenei's guards for years, and killed him on Feb 28, 2026 with 30 precision strikes. Authoritarianism built the weapon that killed its author. #Unit8200 #IoTsecurity #CyberWar

  29. 🛡️ CVE-2026-12187: HIGH severity command injection in GL.iNet GL-MT3000 (fw 4.4.0 – 4.4.5). Remote code execution possible via /usr/bin/one_click_upgrade. Upgrade to v4.7 now! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #CVE202612187

  30. 🔍 CVE-2026-12186 (HIGH, CVSS 8.7) hits GL.iNet GL-MT3000 (4.4.0 – 4.4.5): Remote command injection via Tor Proxy config handler. Exploit is public — patch to 4.7 now! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Infosec #IoTSecurity

  31. 🚨 CRITICAL: CVE-2026-28742 in Naxclow Smart Doorbell X3 — hard-coded platform-wide key + no replay protection = broad request forgery & device impersonation. No patch yet. Avoid untrusted networks & monitor devices. radar.offseq.com/threat/cve-20 #OffSeq #IoTSecurity #Vuln

  32. ⚠️ CVE-2026-50101 (CRITICAL): Naxclow Smart Doorbell X3 uses static relay credentials, allowing attackers who gain access to maintain persistent control, even after resets. No patch yet. Limit network exposure & monitor advisories. radar.offseq.com/threat/cve-20 #OffSeq #IoTSecurity #CVE202650101

  33. 🚨 CRITICAL: CVE-2026-45328 impacts esp-idf 5.5.4 & 6.0 — improper input validation in esp_tee could enable privilege escalation or disrupt secure hardware ops. Patch to 5.5.5/6.0.1 now! radar.offseq.com/threat/cve-20 #OffSeq #IoTSecurity #CVE202645328

  34. CVE-2026-11451: MEDIUM severity command injection in GL.iNet GL-MT3000 (v4.4.5). 🛡️ Remote attackers can exploit FTP handler via media_dir. Fixed in 4.8.1 — update now! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #GLiNet #IoTSecurity

  35. The Transportation & Mobility Special Interest Group (#SIG) is building a dedicated space within the FIRST community for collaboration across the #transportation and #mobility industry on cybersecurity challenges in the IT, OT, and #IoT space.

    This practitioner-focused group will help organizations share best practices, improve coordination, and develop more unified approaches to incident response across connected transportation environments and mobility technologies.

    The SIG also aims to advance standards and guidelines development while helping integrate transportation and mobility-focused incident response planning into the broader FIRST framework.

    If you work in transportation security, OT/IoT security, incident response, infrastructure protection, or mobility technology, we encourage you to get involved and help shape this growing community!

    Learn more at: first.org/global/sigs/transpor

    #FIRST #CyberSecurity #TransportationSecurity #OTSecurity #IoTSecurity

  36. 📣 THE COUNTDOWN TO NEXUS IS ON

    Join more than 250 CPS security leaders from global organizations in Washington, DC. as we tackle business resilience in the AI era.

    With the cybersecurity industry at an inflection point, Nexus Conference 2026 is your opportunity to lead the way forward.

    👉 Apply to attend: nexusconference.io

    #Nexus2026 #cybersecurity #OTsecurity #IoTsecurity #industrial #healthcare #publicsector #commercial #AI #artificialintelligence #CISO

  37. 🔒 CVE-2026-7031: HIGH-severity buffer overflow in Tenda F456 (v1.0.0.5). Remote, no user interaction needed. Exploit public, no patch yet. Limit device exposure & monitor for updates. More: radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #NetSec