home.social

#iotsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #iotsecurity, aggregated by home.social.

  1. The Transportation & Mobility Special Interest Group (#SIG) is building a dedicated space within the FIRST community for collaboration across the #transportation and #mobility industry on cybersecurity challenges in the IT, OT, and #IoT space.

    This practitioner-focused group will help organizations share best practices, improve coordination, and develop more unified approaches to incident response across connected transportation environments and mobility technologies.

    The SIG also aims to advance standards and guidelines development while helping integrate transportation and mobility-focused incident response planning into the broader FIRST framework.

    If you work in transportation security, OT/IoT security, incident response, infrastructure protection, or mobility technology, we encourage you to get involved and help shape this growing community!

    Learn more at: first.org/global/sigs/transpor

    #FIRST #CyberSecurity #TransportationSecurity #OTSecurity #IoTSecurity

  2. The Transportation & Mobility Special Interest Group (#SIG) is building a dedicated space within the FIRST community for collaboration across the #transportation and #mobility industry on cybersecurity challenges in the IT, OT, and #IoT space.

    This practitioner-focused group will help organizations share best practices, improve coordination, and develop more unified approaches to incident response across connected transportation environments and mobility technologies.

    The SIG also aims to advance standards and guidelines development while helping integrate transportation and mobility-focused incident response planning into the broader FIRST framework.

    If you work in transportation security, OT/IoT security, incident response, infrastructure protection, or mobility technology, we encourage you to get involved and help shape this growing community!

    Learn more at: first.org/global/sigs/transpor

    #FIRST #CyberSecurity #TransportationSecurity #OTSecurity #IoTSecurity

  3. 📣 THE COUNTDOWN TO NEXUS IS ON

    Join more than 250 CPS security leaders from global organizations in Washington, DC. as we tackle business resilience in the AI era.

    With the cybersecurity industry at an inflection point, Nexus Conference 2026 is your opportunity to lead the way forward.

    👉 Apply to attend: nexusconference.io

    #Nexus2026 #cybersecurity #OTsecurity #IoTsecurity #industrial #healthcare #publicsector #commercial #AI #artificialintelligence #CISO

  4. 📣 THE COUNTDOWN TO NEXUS IS ON

    Join more than 250 CPS security leaders from global organizations in Washington, DC. as we tackle business resilience in the AI era.

    With the cybersecurity industry at an inflection point, Nexus Conference 2026 is your opportunity to lead the way forward.

    👉 Apply to attend: nexusconference.io

    #Nexus2026 #cybersecurity #OTsecurity #IoTsecurity #industrial #healthcare #publicsector #commercial #AI #artificialintelligence #CISO

  5. 📣 THE COUNTDOWN TO NEXUS IS ON

    Join more than 250 CPS security leaders from global organizations in Washington, DC. as we tackle business resilience in the AI era.

    With the cybersecurity industry at an inflection point, Nexus Conference 2026 is your opportunity to lead the way forward.

    👉 Apply to attend: nexusconference.io

    #Nexus2026 #cybersecurity #OTsecurity #IoTsecurity #industrial #healthcare #publicsector #commercial #AI #artificialintelligence #CISO

  6. 📣 THE COUNTDOWN TO NEXUS IS ON

    Join more than 250 CPS security leaders from global organizations in Washington, DC. as we tackle business resilience in the AI era.

    With the cybersecurity industry at an inflection point, Nexus Conference 2026 is your opportunity to lead the way forward.

    👉 Apply to attend: nexusconference.io

    #Nexus2026 #cybersecurity #OTsecurity #IoTsecurity #industrial #healthcare #publicsector #commercial #AI #artificialintelligence #CISO

  7. 🔥 CRITICAL: CVE-2026-42854 in arduino-esp32 (<3.3.8) enables stack buffer overflow via HTTP multipart boundary — can crash device or allow RCE. Patch ASAP by upgrading to 3.3.8! radar.offseq.com/threat/cve-20 #OffSeq #CVE202642854 #IoTSecurity #Espressif

  8. 🔥 CRITICAL: CVE-2026-42854 in arduino-esp32 (<3.3.8) enables stack buffer overflow via HTTP multipart boundary — can crash device or allow RCE. Patch ASAP by upgrading to 3.3.8! radar.offseq.com/threat/cve-20 #OffSeq #CVE202642854 #IoTSecurity #Espressif

  9. 🔥 CRITICAL: CVE-2026-42854 in arduino-esp32 (<3.3.8) enables stack buffer overflow via HTTP multipart boundary — can crash device or allow RCE. Patch ASAP by upgrading to 3.3.8! radar.offseq.com/threat/cve-20 #OffSeq #CVE202642854 #IoTSecurity #Espressif

  10. 🔥 CRITICAL: CVE-2026-42854 in arduino-esp32 (<3.3.8) enables stack buffer overflow via HTTP multipart boundary — can crash device or allow RCE. Patch ASAP by upgrading to 3.3.8! radar.offseq.com/threat/cve-20 #OffSeq #CVE202642854 #IoTSecurity #Espressif

  11. 📰 Mirai Variant 'xlabs_v1' Builds DDoS Botnet by Hijacking IoT Devices with Exposed ADB Ports

    🚨 New Mirai-based botnet 'xlabs_v1' hijacks IoT devices & Android TVs via exposed ADB ports (TCP/5555). The botnet is used for DDoS-for-hire services, targeting Minecraft servers. #Mirai #Botnet #DDoS #IoTSecurity

    🔗 cyber.netsecops.io

  12. We’re securing systems… but ignoring the fastest growing attack surface.

    While studying IoT security, one thing became clear:

    It’s not the big systems that worry me anymore.

    It’s the small, always-on, barely monitored devices inside the same network.

    Smart cameras. Sensors. Wearables. Controllers.

    Individually harmless.

    Collectively… a blind spot.

    The problem isn’t one vulnerability

    It’s this:
    • Devices that are always trusted
    • Minimal visibility into what they do
    • Weak or inconsistent updates
    • Constant background communication
    • Growing faster than we can track

    At scale, this creates something dangerous:

    A network you don’t fully understand anymore

    Why this matters

    IoT devices are rarely the final target.

    But they can become:
    • Silent entry points
    • Internal visibility nodes
    • Pivot points between systems
    • Long-term unnoticed presence

    Not because they’re powerful —
    but because they’re overlooked and trusted.

    What I’m learning

    IoT security is less about the device itself…
    and more about:
    • How it fits into the system
    • What it communicates with
    • What assumptions exist around it

    Because risk doesn’t always come from complexity.

    Sometimes it comes from what we stop paying attention to.

    I wrote a deeper breakdown on this 👇

    dev.to/blackcipher/the-iot-bli

    Curious to hear your thoughts —

    #CyberSecurity #IoT #IoTSecurity #InfoSec #RedTeam #ThreatIntel #EmbeddedSecurity #BlackCipher

  13. We’re securing systems… but ignoring the fastest growing attack surface.

    While studying IoT security, one thing became clear:

    It’s not the big systems that worry me anymore.

    It’s the small, always-on, barely monitored devices inside the same network.

    Smart cameras. Sensors. Wearables. Controllers.

    Individually harmless.

    Collectively… a blind spot.

    The problem isn’t one vulnerability

    It’s this:
    • Devices that are always trusted
    • Minimal visibility into what they do
    • Weak or inconsistent updates
    • Constant background communication
    • Growing faster than we can track

    At scale, this creates something dangerous:

    A network you don’t fully understand anymore

    Why this matters

    IoT devices are rarely the final target.

    But they can become:
    • Silent entry points
    • Internal visibility nodes
    • Pivot points between systems
    • Long-term unnoticed presence

    Not because they’re powerful —
    but because they’re overlooked and trusted.

    What I’m learning

    IoT security is less about the device itself…
    and more about:
    • How it fits into the system
    • What it communicates with
    • What assumptions exist around it

    Because risk doesn’t always come from complexity.

    Sometimes it comes from what we stop paying attention to.

    I wrote a deeper breakdown on this 👇

    dev.to/blackcipher/the-iot-bli

    Curious to hear your thoughts —

    #CyberSecurity #IoT #IoTSecurity #InfoSec #RedTeam #ThreatIntel #EmbeddedSecurity #BlackCipher

  14. Reflecting on Day 1 of the HTX CTF Finals here in Singapore.

    I didn't win, but the technical takeaway was clear: Precision is a force multiplier.

    By focusing on a high hit rate rather than just speed, I held 5th place for a good portion of the day. It’s a great reminder that in our field, being precise is a technical skill in itself.

    Looking forward to the Day 2 challenges tomorrow!

    #CTF #Cybersecurity #AISecurity #IoTSecurity #DEFCON #HTXsg #DEFCONSG #EthicalHacking #CaptureTheFlag #PublicSafety #HTXctf

  15. Reflecting on Day 1 of the HTX CTF Finals here in Singapore.

    I didn't win, but the technical takeaway was clear: Precision is a force multiplier.

    By focusing on a high hit rate rather than just speed, I held 5th place for a good portion of the day. It’s a great reminder that in our field, being precise is a technical skill in itself.

    Looking forward to the Day 2 challenges tomorrow!

    #CTF #Cybersecurity #AISecurity #IoTSecurity #DEFCON #HTXsg #DEFCONSG #EthicalHacking #CaptureTheFlag #PublicSafety #HTXctf

  16. 🔒 CVE-2026-7031: HIGH-severity buffer overflow in Tenda F456 (v1.0.0.5). Remote, no user interaction needed. Exploit public, no patch yet. Limit device exposure & monitor for updates. More: radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #NetSec

  17. Raspberry Pi OS Tightens Sudo Security with Password Mandate

    Raspberry Pi OS just got a major security boost: the latest release now requires a password by default when using the sudo command, putting an end to its previously open-door policy and adding an extra layer of protection to your device. This simple yet significant change means you'll need to enter a password to access sudo, giving…

    osintsights.com/raspberry-pi-o

    #RaspberryPiOs #SudoSecurity #PasswordMandate #LinuxSecurity #IotSecurity

  18. Qualified for HTX CTF Finals at DEF CON Singapore 🇸🇬 - 13th in the online round, 65/74 solved. 🔥

    Both tracks were AI Security and IoT Exploitation. Neither is my daily work. Meant learning how prompt-driven systems break, how MQTT/CoAP expose attack surface, and how one forgotten device pivots into everything else.

    All under the clock. ⏱️ Finals end of April. 💪

    #CTF #Infosec #AISecurity #IoTSecurity #DEFCON #HTXsg #DEFCONSG #EthicalHacking #CaptureTheFlag #PublicSafety

  19. Qualified for HTX CTF Finals at DEF CON Singapore 🇸🇬 - 13th in the online round, 65/74 solved. 🔥

    Both tracks were AI Security and IoT Exploitation. Neither is my daily work. Meant learning how prompt-driven systems break, how MQTT/CoAP expose attack surface, and how one forgotten device pivots into everything else.

    All under the clock. ⏱️ Finals end of April. 💪

    #CTF #Infosec #AISecurity #IoTSecurity #DEFCON #HTXsg #DEFCONSG #EthicalHacking #CaptureTheFlag #PublicSafety

  20. Qualified for HTX CTF Finals at DEF CON Singapore 🇸🇬 - 13th in the online round, 65/74 solved. 🔥

    Both tracks were AI Security and IoT Exploitation. Neither is my daily work. Meant learning how prompt-driven systems break, how MQTT/CoAP expose attack surface, and how one forgotten device pivots into everything else.

    All under the clock. ⏱️ Finals end of April. 💪

    #CTF #Infosec #AISecurity #IoTSecurity #DEFCON #HTXsg #DEFCONSG #EthicalHacking #CaptureTheFlag #PublicSafety

  21. Qualified for HTX CTF Finals at DEF CON Singapore 🇸🇬 - 13th in the online round, 65/74 solved. 🔥

    Both tracks were AI Security and IoT Exploitation. Neither is my daily work. Meant learning how prompt-driven systems break, how MQTT/CoAP expose attack surface, and how one forgotten device pivots into everything else.

    All under the clock. ⏱️ Finals end of April. 💪

    #CTF #Infosec #AISecurity #IoTSecurity #DEFCON #HTXsg #DEFCONSG #EthicalHacking #CaptureTheFlag #PublicSafety

  22. Qualified for HTX CTF Finals at DEF CON Singapore 🇸🇬 - 13th in the online round, 65/74 solved. 🔥

    Both tracks were AI Security and IoT Exploitation. Neither is my daily work. Meant learning how prompt-driven systems break, how MQTT/CoAP expose attack surface, and how one forgotten device pivots into everything else.

    All under the clock. ⏱️ Finals end of April. 💪

    #CTF #Infosec #AISecurity #IoTSecurity #DEFCON #HTXsg #DEFCONSG #EthicalHacking #CaptureTheFlag #PublicSafety

  23. Fitness Equipment Exposes Weak Link in Gym Security

    A recent security mishap at a gym serves as a stark reminder of the importance of safeguarding sensitive information, as a technician's careless mistake - stapling configuration details to a cupboard - left fitness equipment vulnerable to exploitation by mischief makers. This embarrassing blunder highlights the need for vigilance in…

    osintsights.com/fitness-equipm

    #GymSecurity #PhysicalSecurity #IotSecurity #EmergingThreats #FitnessEquipment

  24. CVE-2026-1679: HIGH severity buffer overflow in Zephyr RTOS (all versions). Local attackers can trigger kernel memory corruption via eswifi socket offload driver. Patch ASAP, enforce access controls. Details: radar.offseq.com/threat/cve-20 #OffSeq #ZephyrRTOS #IoTSecurity #CVE

  25. CVE-2026-1679: HIGH severity buffer overflow in Zephyr RTOS (all versions). Local attackers can trigger kernel memory corruption via eswifi socket offload driver. Patch ASAP, enforce access controls. Details: radar.offseq.com/threat/cve-20 #OffSeq #ZephyrRTOS #IoTSecurity #CVE

  26. CVE-2026-1679: HIGH severity buffer overflow in Zephyr RTOS (all versions). Local attackers can trigger kernel memory corruption via eswifi socket offload driver. Patch ASAP, enforce access controls. Details: radar.offseq.com/threat/cve-20 #OffSeq #ZephyrRTOS #IoTSecurity #CVE

  27. CVE-2026-1679: HIGH severity buffer overflow in Zephyr RTOS (all versions). Local attackers can trigger kernel memory corruption via eswifi socket offload driver. Patch ASAP, enforce access controls. Details: radar.offseq.com/threat/cve-20 #OffSeq #ZephyrRTOS #IoTSecurity #CVE