Security News

Transform Any Place into a Smart Space
2023-05-16 12:00

TechRepublic Premium Hiring kit: Computer research scientist PURPOSE Industries that depend on information technology and related fields of research often call upon the computer research scientist for innovative ideas. This hiring kit from TechRepublic Premium provides an adjustable framework your business can use to find the right person for the job.

It's this easy to seize control of someone's Nexx 'smart' home plugs, garage doors
2023-04-07 11:00

A handful of bugs in Nexx's smart home devices can be exploited by crooks to, among other things, open doors, power off appliances, and disable alarms. The five vulnerabilities affect Nexx garage door controllers with firmware version nxg200v-p3-4-1 and prior; Nexx smart plugs version nxpg100cv4-0-0 and prior; and Nexx smart alarms version nxal100v-p1-9-1 and prior.

Hey Siri, use this ultrasound attack to disarm a smart-home system
2023-04-04 00:59

Academics in the US have developed an attack dubbed NUIT, for Near-Ultrasound Inaudible Trojan, that exploits vulnerabilities in smart device microphones and voice assistants to silently and remotely access smart phones and home devices. In an interview with The Register this month, Chen and Xia demonstrated two separate NUIT attacks: NUIT-1, which emits sounds to exploit a victim's smart speaker to attack the same victim's microphone and voice assistant on the same device, and NUIT-2, which exploits a victim's speaker to attack the same victim's microphone and voice assistant on a different device.

Smart Mobility has a Blindspot When it Comes to API Security
2023-03-29 11:43

WAF is not enough: developing a contextual framework for smart mobility API security#. Smart mobility services have always been monitoring and securing API transactions to avoid revenue loss due to fraud, service downtime, and compromising organizational or users private data.

Inaudible ultrasound attack can stealthily control your phone, smart speaker
2023-03-25 15:14

American university researchers have developed a novel attack called "Near-Ultrasound Inaudible Trojan" that can launch silent attacks against devices powered by voice assistants, like smartphones, smart speakers, and other IoTs. The main principle that makes NUIT effective and dangerous is that microphones in smart devices can respond to near-ultrasound waves that the human ear cannot, thus performing the attack with minimal risk of exposure while still using conventional speaker technology.

Researchers Uncover Over a Dozen Security Flaws in Akuvox E11 Smart Intercom
2023-03-13 07:36

More than a dozen security flaws have been disclosed in E11, a smart intercom product made by Chinese company Akuvox. "The vulnerabilities could allow attackers to execute code remotely in order to activate and control the device's camera and microphone, steal video and images, or gain a network foothold," Claroty security researcher Vera Mens said in a technical write-up.

Smart security
2023-03-03 10:15

Webinar Trying to keep on top of all the hype and complexity in cybersecurity can be more than an just an uphill struggle and more like a veritable mountain to climb every morning. So IT staff can be forgiven for wanting to change their security setups over and over again.

Researcher Uncovers Potential Wiretapping Bugs in Google Home Smart Speakers
2022-12-30 09:25

A security researcher was awarded a bug bounty of $107,500 for identifying security issues in Google Home smart speakers that could be exploited to install backdoors and turn them into wiretapping devices. The problem, in a nutshell, has to do with how the Google Home software architecture can be leveraged to add a rogue Google user account to a target's home automation device.

What’s the Matter with digital trust in smart home devices?
2022-12-06 05:30

With so many manufacturers and devices to choose from, the smart home landscape is often a mishmash of support and usability. Simply put, until now, the lack of a unifying standard among various smart home technology standards made using devices together complicated and difficult.

Sirius XM flaw unlocks so-called smart cars thanks to code flaw
2022-11-30 23:30

Sirius XM's Connected Vehicle Services has fixed an authorization flaw that would have allowed an attacker to remotely unlock doors and start engines on connected cars knowing only the vehicle identification number. Yuga Labs' Sam Curry detailed the exploit in a series of tweets, and confirmed that the patch issued by SiriusXM fixed the security issue.