Skip to main content

Tag: iot security

35 articles

Router on a table with visible lights and ports, surrounded by blurred furniture.

ZBT Routers Expose Critical Flaw with Factory-Installed Implants

Millions of ZBT routers are at risk due to a critical flaw caused by factory-installed implants that grant hackers root access to every device connected to them. This severe vulnerability, rated 9.3 out of 10, allows attackers to take full control with just a network connection.

Analyst 207
Network equipment rack with modern devices and cables, one device showing an open panel.

Ubiquiti Patches Three Maximum-Severity Flaws in UniFi Line

Ubiquiti has patched three critical vulnerabilities in its UniFi line, with a severity score of 10 out of 10, that could allow hackers to gain control of affected devices. These flaws, along with 19 others, were disclosed in a security bulletin, highlighting the need for immediate updates.

Analyst 207
Network operations room with computer workstations and equipment.

Ubiquiti Disrupts Three Max-Severity Flaws in UniFi Systems

Ubiquiti has just dropped a critical security update to fix three massive vulnerabilities in its UniFi systems that hackers can exploit remotely without needing any special access. If you're using UniFi, now's the time to patch up and keep your network safe!

Analyst 207
Calix router on a shelf near a window with internal devices blurred in the background.

Unpatched Calix Routers Expose Internal Devices to Internet Threats

A single, unauthorized request can create a permanent vulnerability in your Calix router's firewall, exposing internal devices to internet threats - no password or prompt required. This shocking flaw, tracked as CVE-2026-75501, leaves devices running EXOS/6.6.47 firmware alarmingly susceptible to attack.

Analyst 207
City street with multiple IP cameras and subtle network connectivity hint.

Hackers Compromise 14,500 Dahua Cameras in 35-Day Global Campaign

In just 35 days, hackers compromised a staggering 14,530 Dahua IP cameras worldwide, with a surprising focus on Russian and CIS telecom networks. The massive operation, dubbed CameraSwarm, exposed a vast amount of sensitive data, revealing the intruders' tactics and targets.

Analyst 207
Security camera on exterior wall with network cables nearby.

Hackers Exploit Dahua Devices via Credential Attacks and Auth Bypasses

Over 14,530 Dahua devices were compromised in a massive cyberattack, dubbed Operation CameraSwarm, which used credential attacks and authentication bypasses to gain control of cameras and other devices. The attackers hit hard in Ukraine and Russia, infiltrating devices via exposed credentials, flaws, and peer-to-peer relay tech.

Analyst 207
Technical lab with network and IoT devices on a workbench surrounded by testing equipment and screens.

ETSI Advances 17 Cybersecurity Standards for EU Compliance

The European Telecommunications Standards Institute (ETSI) is pushing forward with 17 crucial cybersecurity standards to help vendors and buyers across the continent meet the EU's Cyber Resilience Act requirements. These draft standards cover 17 major product categories, setting a vital baseline for manufacturers to ensure their products are secure and compliant.

Analyst 207
Network equipment and routers in a server room with a prominent router in the foreground.

Evooo1Bot Malware Targets Routers in Global Traffic Relay Botnet

Meet Evooo1Bot, a sneaky malware that's turning routers worldwide into unwitting traffic relays, harvesting credentials, and launching devastating DDoS attacks. This modular Linux botnet is packed with powerful tools, including encrypted communication, SSH brute-forcing, and exploit arsenals to take down vulnerable devices.

Analyst 207
Technicians walk by rows of server racks and networking equipment in a modern network operations center.

Kimwolf Botnet Evolves with Enhanced DDoS Capabilities

Meet Kimwolf v7, a highly evolved botnet that's taken DDoS capabilities to the next level with its cutting-edge command-and-control resolution via Ethereum's blockchain naming system, ENS. First discovered in February 2026, this malware has been quietly building its arsenal since August 2024, targeting a range of devices from Linux IoT gadgets to Android TV boxes.

Analyst 207
Close-up of a partially disassembled cellular IoT device with exposed internal components and a visible SIM card on a…

Malicious SIMs Exploit Cellular IoT Devices via Hidden Modem Interface

Researchers uncovered a shocking vulnerability in cellular IoT devices, finding that malicious SIMs can exploit hidden modem interfaces to run code on the device, thanks to a little-known proactive capability defined in cellular communication specs. Nine out of 26 tested devices, including some popular phones, were susceptible to this type of attack.

Analyst 207
Generic router on a neutral surface with visible lights and ports, conveying vulnerability.

Zbtlink Routers Expose Unauthenticated Root Shells via Factory-Shipped Backdoor

Meet ENDLESSDOORS, a sneaky backdoor embedded in over 20 Zbtlink router models that lets hackers tap into an unauthenticated root shell, allowing them to remotely control your device. This hidden threat masquerades as a harmless Linux kernel thread, but in reality, it's a powerful tool that can phone home to Chinese command-and-control infrastructure every 35 seconds.

Analyst 207
A generic router sits on a neutral surface with visible lights and ports.

Zbtlink Router Firmware Exposes Potential Backdoor Risks

Some Zbtlink routers have a shocking secret: they come equipped with a built-in backdoor that lets them phone home and wait for orders, all without needing to be hacked. This unsettling feature, dubbed ENDLESSDOORS, was found on twenty models across years of images, sparking concerns about potential security risks.

Analyst 207
A network router sits on a clean surface with a blurred background, conveying vulnerability.

OpenWrt Fixes Critical DHCPv6 Flaw That Exposes Root Code Execution Risk

OpenWrt has patched a critical DHCPv6 flaw, known as CVE-2026-53921, that could allow an unauthenticated attacker to execute root code by sending a crafted request to the DHCPv6 server. This severe vulnerability, rated 9.8 out of 10, highlights the importance of updating your OpenWrt setup to prevent potential security breaches.

Analyst 207
LG smart TV on in a living room with scattered app icons and remotes nearby.

LG Moves to Block Residential Proxies in Smart TV Apps

LG is cracking down on a sneaky practice that's been hiding in plain sight: using its smart TVs as residential proxy nodes, a use that's far from what the company intended. The move comes after a security firm found that over 42% of LG's webOS apps contain software that can turn TVs into always-on proxy nodes.

Analyst 207
Bootloader circuit board with microcontroller and components on a neutral background.

U-Boot Flaws Expose Devices to Code Execution, Crashes

Six newly discovered flaws in U-Boot, a widely used bootloader, leave devices from home routers to data-center servers vulnerable to code execution and crashes, posing a significant risk to everything that loads after it. These vulnerabilities can be exploited before the operating system even starts, undermining the entire security chain.

Analyst 207
Modern smart home network setup with various connected devices.

Ubiquiti Fixes Flaws in UniFi Ecosystem

Ubiquiti has patched a critical vulnerability in its UniFi ecosystem, specifically a command injection flaw with a perfect 10.0 CVSS score, that could let hackers take control of your device. The update fixes issues across UniFi products, shielding you from potential attacks that could escalate privileges or make unauthorized changes.

Analyst 207
A typical home network setup with a router, laptop, smartphone, and books, focusing on the router's visible lights and ports.

Tenda Router Firmware Exposes Hidden Admin Backdoor

A critical vulnerability in Tenda router firmware, tracked as CVE-2026-11405, allows hackers to bypass password verification and gain full administrative control of your device. This hidden backdoor puts your online security at risk, and a patch is still pending.

Analyst 207
Dimly lit network closet with scattered outdated devices and cables.

RustDuck Botnet Evolves with Rust Rewrite to Evade Detection

Meet RustDuck, a sneaky botnet that's been evolving to evade detection since February 2026, tracked by researchers at QiAnXin's XLab. It gains a foothold by exploiting weak passwords, unpatched vulnerabilities, and targeting specific web software.

Analyst 207
Smart TV on an entertainment center in a living room with ambient daylight and low-utility apps on the screen.

Smart TVs Compromised by Proxyware Vulnerabilities Plague 24-Year-Old Curl AI Emerges in Cybercrime Forums Hackers Exploit Microsoft Teams Legacy Credentials Fuel Data Breaches

Over a third of smart TV apps, including clocks, screensavers, and games, contain residential proxy software, putting your device at risk. Researchers found that 42.5% of LG webOS and 26.9% of Samsung Tizen apps harbour these vulnerabilities.

Analyst 207
CSIS agent surrounded by technology equipment in a neutral setting.

Canada's Spy Agency Neutralizes Foreign Botnets with Landmark Warrant

In a groundbreaking move, Canada's spy agency, CSIS, has successfully neutralized two foreign-run botnets operating on Canadian soil, thanks to a landmark warrant that allowed them to access and shut down infected devices. This pioneering threat-reduction tactic marks a major win in the fight against botnet threats.

Analyst 207
Cluttered electronics shelf with Android TV boxes and streaming devices surrounded by tangled cables.

NetNut Exposed in Massive Popa Botnet Operation

Meet Popa, a sneaky Android-based plugin that's been secretly infiltrating over 1.4 million internet addresses via unofficial streaming apps and set-top devices, researchers have uncovered. This stealthy operation is linked to the notorious Vo1d botnet family, which has been targeting vulnerable Android TV boxes.

Analyst 207
Microsoft Surface device on a well-lit workbench with a blank screen.

Microsoft Fixes Flaw in Surface Hardware That Allowed Devices to Be Bricked

A security researcher recently discovered that Microsoft's Copilot AI tool could be used to create a series of aggressive Python scripts that accidentally bricked a Surface device by overwriting its firmware. The incident highlights a flaw in Microsoft's Surface hardware that has since been fixed.

Analyst 207
Rack-mounted router surrounded by devices and cables in a network closet overlooking an urban area.

China Exposes Botnet Resurgence, AI Influence Ops Targeting US

A botnet once dismantled by US law enforcement has made a stunning comeback, with over 1,500 compromised routers and IoT devices now under the control of China-nexus actors, who are using it to fuel influence campaigns and recruitment scams. This resurgence poses a significant threat, with the same group of actors still active and causing chaos.

Analyst 207
A dimly lit, disrupted computer server room with rows of equipment racks and monitors, some server casings and cables…

Ransomware Attacks Surge as Clop Gang Dominates Threat Landscape

Ransomware attacks have skyrocketed, with over 343 million blocked by Kaspersky products in just the first quarter of 2026 alone, highlighting a surge in threats from the notorious Clop gang and other malicious players. This alarming trend underscores a quarter marked by intensified ransomware activity and rapidly evolving cyber threats.

Analyst 207