#iotsecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #iotsecurity, aggregated by home.social.
-
🏠🔐 YOUR HOME IS CONNECTED. IS IT PROTECTED?
Smart cameras, lights, speakers, locks and other IoT devices make life easier — but every connected device can become a potential security risk. 📱🛡️
Secure your network. Update your devices. Control access. Protect your smart home. ⚡
#SmartHome #CyberSecurity #IoTSecurity #OnlineSafety #Privacy
-
🏠🔐 YOUR HOME IS CONNECTED. IS IT PROTECTED?
Smart cameras, lights, speakers, locks and other IoT devices make life easier — but every connected device can become a potential security risk. 📱🛡️
Secure your network. Update your devices. Control access. Protect your smart home. ⚡
#SmartHome #CyberSecurity #IoTSecurity #OnlineSafety #Privacy
-
Mira Firmware v1.7.1.47 has a CRITICAL auth bug (CVE-2026-68067): login accepts any valid-format password, exposing hormone records. No patch yet; restrict access & monitor accounts. https://radar.offseq.com/threat/cve-2026-68067-cwe-1390-weak-authentication-in-quanovate-tech-inc-operating-as-mira-mira-care-mira-85cdd6a62acb5a46 #OffSeq #Vulnerability #IoTSecurity #CVE202668067
-
CVE-2026-19348 in Shenzhen Aitemi M300 Wi-Fi Repeater: CRITICAL command injection via /protocol.csp (enable, name, mac). Public exploit code out; no patch yet. Restrict access & monitor traffic. https://radar.offseq.com/threat/cve-2026-19348-command-injection-in-shenzhen-aitemi-m300-wi-fi-repeater-50170c9de7b315c0 #OffSeq #CVE202619348 #IoTSecurity
-
TIL that the UK government’s Code of Practice for consumer IoT security was published 14 October 2018
-
TIL that the UK government’s Code of Practice for consumer IoT security was published 14 October 2018
-
💡 Can a smart light bulb put your home network at risk?
Not by magic—but like any Internet-connected device, a vulnerable or poorly secured smart bulb can become an entry point if it isn't updated or configured properly. In this Reel, I show why securing every smart device matters—not just your computer or phone.
💬 Comment "IoT" if you want more smart home security tips.
-
💡 Can a smart light bulb put your home network at risk?
Not by magic—but like any Internet-connected device, a vulnerable or poorly secured smart bulb can become an entry point if it isn't updated or configured properly. In this Reel, I show why securing every smart device matters—not just your computer or phone.
💬 Comment "IoT" if you want more smart home security tips.
-
CVE-2026-18684 | CRITICAL command injection in GL.iNet GL-MT3000 (fw 4.4.0 – 4.4.5) 🛡️ Remote attackers can execute commands — no patch yet. Restrict access and watch for vendor updates. Info: https://radar.offseq.com/threat/cve-2026-18684-command-injection-in-glinet-gl-mt3000-4a4de87391e0f428 #OffSeq #CVE202618684 #IoTSecurity
-
CVE-2026-18589 (CRITICAL, CVSS 9.3) in Wavlink WL-NU516U1: Stack buffer overflow in nas.cgi enables unauthenticated RCE/DoS. Patch available — update ASAP. https://radar.offseq.com/threat/cve-2026-18589-stack-based-buffer-overflow-in-wavlink-wl-nu516u1-be242f6f491145cd #OffSeq #CVE202618589 #IoTSecurity #PatchManagement
-
I just published my first ever GitHub repo!
fwpt - Firmware Pentest ToolkitA fast native C scanner for extracted IoT/embedded firmware filesystems.
Finds hardcoded creds, keys and sensitive configs with zero noise.
Super lightweight, no deps.https://github.com/bashcore/fwpt
#infosec #firmware #iotsecurity #pentest #opensource #cprogramming
-
I just published my first ever GitHub repo!
fwpt - Firmware Pentest ToolkitA fast native C scanner for extracted IoT/embedded firmware filesystems.
Finds hardcoded creds, keys and sensitive configs with zero noise.
Super lightweight, no deps.https://github.com/bashcore/fwpt
#infosec #firmware #iotsecurity #pentest #opensource #cprogramming
-
CVE-2026-8983: Autel Maxi Charger Single ≤1.03.51 is affected by a CRITICAL flaw — hard-coded token bypasses authentication, exposing management endpoints. Restrict access & monitor for abuse. Patch status unknown. https://radar.offseq.com/threat/autel-maxi-charger-single-firmware-through-v10351-contains-a-hard-coded-authentication-token-that-cb2fec544a5f031e #OffSeq #CVE20268983 #IoTSecurity
-
CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: https://radar.offseq.com/threat/cve-2026-42566-cwe-20-improper-input-validation-in-meshtastic-firmware-f4cb4608f8fc25f1 #OffSeq #infosec #CVE #IoTSecurity
-
CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: https://radar.offseq.com/threat/cve-2026-42566-cwe-20-improper-input-validation-in-meshtastic-firmware-f4cb4608f8fc25f1 #OffSeq #infosec #CVE #IoTSecurity
-
CVE-2026-15511 (CRITICAL, CVSS 9.3): OS command injection in Comfast CF-WR631AX V3 (fw 2.7.0.0 – 2.7.0.8) enables unauthenticated remote code execution. No patch. Restrict access & disable remote mgmt. https://radar.offseq.com/threat/cve-2026-15511-os-command-injection-in-comfast-cf--f966bd818b8c5835 #OffSeq #CVE #IoTSecurity #Router
-
CVE-2026-15481 (HIGH, CVSS 8.7) affects Trendnet TEW-635BRM <=1.00.03: Remote command injection via IPoA WAN setup. Exploit is public. Devices are EOL — replace hardware ASAP. https://radar.offseq.com/threat/cve-2026-15481-command-injection-in-trendnet-tew-6-0618f5678477012c #OffSeq #Vulnerability #Infosec #IoTSecurity
-
wolfSSL: 57 CVEs, 4 critical, 11 high. 70% unpatched. Trust Score: C. CVE trend up 24. Key flaws: CWE-295 (improper cert validation). #wolfSSL #IoTsecurity #cybersecurity
-
CVE-2026-13768: Gardyn Home Firmware (CRITICAL, CVSS 10) exposes a privileged iothubowner key, enabling attackers to control devices & move laterally on networks. No patch yet. Monitor and segment IoT devices. https://radar.offseq.com/threat/cve-2026-13768-cwe-798-in-gardyn-gardyn-home-firmw-08332214fc38f3ba #OffSeq #IoTSecurity #CVE202613768
-
CVE-2026-13564: HIGH (CVSS 8.7) stack-based buffer overflow in Edimax EW-7478APC v1.04. Remote exploit via pppUserName; public PoC, no patch. Disable remote access or segment device. https://radar.offseq.com/threat/cve-2026-13564-stack-based-buffer-overflow-in-edim-026db0243354aebd #OffSeq #Vulnerability #IoTSecurity #CVE202613564
-
Tenda JD12L routers (fw 16.03.53.23) face HIGH severity stack-based buffer overflow (CVE-2026-13516, CVSS 8.7). Remote code execution possible — exploit code is public. Restrict remote access, monitor endpoints. https://radar.offseq.com/threat/cve-2026-13516-stack-based-buffer-overflow-in-tend-c61568839c0ead88 #OffSeq #infosec #IoTSecurity #CVE
-
H.VIEW HV-500S6 IP Camera has a HIGH severity bug (CVE-2026-55975, CVSS 7.2): Authenticated users may inject commands using unsanitized XML in cert generation. Restrict access, monitor activity, and check for patches. https://radar.offseq.com/threat/cve-2026-55975-cwe-78-in-hview-hv-500s6-ip-camera-32fd47fcf53b8f7c #OffSeq #Vulnerability #IoTSecurity 🔒
-
CVE-2026-56414: H.VIEW HV-500S6 IP Camera has a HIGH-severity vuln (CVSS 7.2) allowing authenticated users to upload arbitrary files via certificate upload, risking persistent compromise. Restrict admin access & monitor uploads. https://radar.offseq.com/threat/cve-2026-56414-cwe-434-in-hview-hv-500s6-ip-camera-2fc4d58c6ce82381 #OffSeq #IoTSecurity #CVE #Vulnerability
-
GeoVision GV-LPC2011/2211 devices (≤1.12) face CRITICAL CVE-2026-57880: stack-based buffer overflow in RTSP auth enables remote, unauthenticated DoS or code execution. Restrict RTSP access, monitor traffic. Patch status unknown. https://radar.offseq.com/threat/cve-2026-57880-cwe-121-stack-based-buffer-overflow-1d88eee9b47ed7bb #OffSeq #Vuln #IoTSecurity #CVE
-
GeoVision GV-LPC2011/2211 (<=1.12) hit by CVE-2026-57881: CRITICAL stack-based buffer overflow in vlsvr enables unauthenticated RCE or DoS. No patch yet — restrict access & monitor activity. https://radar.offseq.com/threat/cve-2026-57881-cwe-121-stack-based-buffer-overflow-0de9014b0e3f1945 #OffSeq #Vuln #IoTSecurity #CVE202657881
-
CVE-2026-12851: CRITICAL OS command injection in GeoVision GV-I/O Box 4E v2.09 via DVRSearch/Network.cgi allows remote code execution. Patch status pending — restrict access & monitor endpoints. https://radar.offseq.com/threat/cve-2026-12851-cwe-78-improper-neutralization-of-s-3964552d83f5f479 #OffSeq #Vulnerability #IoTSecurity #CVE #Security
-
🔍 HIGH severity: Buffer overflow in GALAYOU Y4 v1.0.0 (CVE-2026-12192). Exploitable via local network — no patch or vendor response yet. Restrict network access & monitor for updates. https://radar.offseq.com/threat/cve-2026-12192-buffer-overflow-in-galayou-y4-555d7b50 #OffSeq #Vuln #IoTSecurity #BufferOverflow
-
Iran built cameras to surveil its people. Israel hacked them, tracked Khamenei's guards for years, and killed him on Feb 28, 2026 with 30 precision strikes. Authoritarianism built the weapon that killed its author. #Unit8200 #IoTsecurity #CyberWar
-
Iran built cameras to surveil its people. Israel hacked them, tracked Khamenei's guards for years, and killed him on Feb 28, 2026 with 30 precision strikes. Authoritarianism built the weapon that killed its author. #Unit8200 #IoTsecurity #CyberWar
-
🛡️ CVE-2026-12187: HIGH severity command injection in GL.iNet GL-MT3000 (fw 4.4.0 – 4.4.5). Remote code execution possible via /usr/bin/one_click_upgrade. Upgrade to v4.7 now! https://radar.offseq.com/threat/cve-2026-12187-command-injection-in-glinet-gl-mt30-4b35174f #OffSeq #Vulnerability #IoTSecurity #CVE202612187
-
🔍 CVE-2026-12186 (HIGH, CVSS 8.7) hits GL.iNet GL-MT3000 (4.4.0 – 4.4.5): Remote command injection via Tor Proxy config handler. Exploit is public — patch to 4.7 now! https://radar.offseq.com/threat/cve-2026-12186-command-injection-in-glinet-gl-mt30-8e4f5f3d #OffSeq #Vulnerability #Infosec #IoTSecurity
-
🚨 CRITICAL: CVE-2026-28742 in Naxclow Smart Doorbell X3 — hard-coded platform-wide key + no replay protection = broad request forgery & device impersonation. No patch yet. Avoid untrusted networks & monitor devices. https://radar.offseq.com/threat/cve-2026-28742-cwe-321-use-of-hard-coded-cryptogra-637b7b61 #OffSeq #IoTSecurity #Vuln
-
⚠️ CVE-2026-50101 (CRITICAL): Naxclow Smart Doorbell X3 uses static relay credentials, allowing attackers who gain access to maintain persistent control, even after resets. No patch yet. Limit network exposure & monitor advisories. https://radar.offseq.com/threat/cve-2026-50101-cwe-262-not-using-password-aging-in-f27f494a #OffSeq #IoTSecurity #CVE202650101
-
🚨 CRITICAL: CVE-2026-45328 impacts esp-idf 5.5.4 & 6.0 — improper input validation in esp_tee could enable privilege escalation or disrupt secure hardware ops. Patch to 5.5.5/6.0.1 now! https://radar.offseq.com/threat/cve-2026-45328-cwe-20-improper-input-validation-in-93c234d5 #OffSeq #IoTSecurity #CVE202645328
-
CVE-2026-11451: MEDIUM severity command injection in GL.iNet GL-MT3000 (v4.4.5). 🛡️ Remote attackers can exploit FTP handler via media_dir. Fixed in 4.8.1 — update now! https://radar.offseq.com/threat/cve-2026-11451-command-injection-in-glinet-gl-mt30-53c0e750 #OffSeq #Vulnerability #GLiNet #IoTSecurity
-
GitHub - nnonickreal/openqore: unleash the full power of your soundcores! :)
https://github.com/nnonickreal/openqore
Read on HackerWorkspace: https://hackerworkspace.com/article/github-nnonickreal-openqore-unleash-the-full-power-of-your-soundcores
-
Patch Now: Critical Flaw in OT Robot OS Gives Attackers Control
https://www.darkreading.com/ics-ot-security/patch-now-critical-flaw-ot-robot-os
Read on HackerWorkspace: https://hackerworkspace.com/article/patch-now-critical-flaw-in-ot-robot-os-gives-attackers-control
-
Inside the Secret World of DEF CON Hackers | VICE: Motherboard | Blueprint
-
The Transportation & Mobility Special Interest Group (#SIG) is building a dedicated space within the FIRST community for collaboration across the #transportation and #mobility industry on cybersecurity challenges in the IT, OT, and #IoT space.
This practitioner-focused group will help organizations share best practices, improve coordination, and develop more unified approaches to incident response across connected transportation environments and mobility technologies.
The SIG also aims to advance standards and guidelines development while helping integrate transportation and mobility-focused incident response planning into the broader FIRST framework.
If you work in transportation security, OT/IoT security, incident response, infrastructure protection, or mobility technology, we encourage you to get involved and help shape this growing community!
Learn more at: https://www.first.org/global/sigs/transport/
#FIRST #CyberSecurity #TransportationSecurity #OTSecurity #IoTSecurity
-
📣 THE COUNTDOWN TO NEXUS IS ON
Join more than 250 CPS security leaders from global organizations in Washington, DC. as we tackle business resilience in the AI era.
With the cybersecurity industry at an inflection point, Nexus Conference 2026 is your opportunity to lead the way forward.
👉 Apply to attend: https://nexusconference.io
#Nexus2026 #cybersecurity #OTsecurity #IoTsecurity #industrial #healthcare #publicsector #commercial #AI #artificialintelligence #CISO
-
Defending consumer web properties against modern DDoS attacks | Microsoft Security Blog
Read on HackerWorkspace: https://hackerworkspace.com/article/defending-consumer-web-properties-against-modern-ddos-attacks-microsoft-security-blog
-
LABScon25 Replay | Connect to the Foreign Entity to Enhance Your User Experience | FitzPatrick
-
This 'cardputer' sits between the Raspberry Pi and Flipper Zero - but it's uniquely better
https://www.zdnet.com/article/m5stack-cardputer-adv-review/
Read on HackerWorkspace: https://hackerworkspace.com/article/this-cardputer-sits-between-the-raspberry-pi-and-flipper-zero-but-it-s-uniquely-better
-
Tracking a Drone Indoors Without GPS | ESP32 BLE RSSI
-
I Tried Building a Cheap Indoor Positioning System… So I Built a Drone Instead - CiferTech
https://cifertech.net/i-tried-building-a-cheap-indoor-positioning-system-so-i-built-a-drone-instead/
Read on HackerWorkspace: https://hackerworkspace.com/article/i-tried-building-a-cheap-indoor-positioning-system-so-i-built-a-drone-instead-cifertech
-
HackRF PortaPack Splash Screen Without Removing the SD Card
-
Giving my Raspberry Pi LTE Connectivity - 4G LTE IoT Test Lab
-
The Internet Knows Who You Are — Even Offline
-
🔒 CVE-2026-7031: HIGH-severity buffer overflow in Tenda F456 (v1.0.0.5). Remote, no user interaction needed. Exploit public, no patch yet. Limit device exposure & monitor for updates. More: https://radar.offseq.com/threat/cve-2026-7031-buffer-overflow-in-tenda-f456-f28ef6c0 #OffSeq #Vulnerability #IoTSecurity #NetSec
-
Open-Source AI Assisted Firmware Analysis - WAIRZ