Software

Home is where the XSS is: DHS Warns of Flaw in Building Automation System

In-brief: the Department of Homeland Security warned on Thursday that a common home automation controller manufactured by the firm Schneider Electric contains a software flaw that could leave the device vulnerable to hacking. 

Mirai Redux: A Year’s Worth of DVR Passwords Published Online

In-brief: DVRs pre-programmed with a list of date-specific master passwords that leaked online may have ties back to Xiongmai Technologies, the same firm whose software was compromised by the Mirai botnet. 

Flaw Lets Hackers Own Samsung Smartcams With Bogus Firmware

In-brief: a flaw in Samsung’s Smartcam product could allow remote attackers to take control of the devices. The news comes two years after Samsung took steps to patch other flaws in its Internet connected cameras.

St. Jude Patches Hole that allowed Medical Device Hacks

In-brief: St. Jude Medical said on Monday that it patched a serious hole in a product used to program implantable medical devices like defibrillators. But researchers and a Wall Street investment firm say the company still has more holes to close. 

FTC Sues D-Link Citing Security Flaws in Routers, Cameras

In-brief: The FTC filed suit against home networking gear maker D-Link alleging the company’s products are insecure and pose a danger to consumers. (Editor’s note: updated to include D-Link’s official statement on the FTC case. – PFR 1/10/2017)