Search Results for "default password"

Shoddy Supply Chain Lurks Behind Mirai Botnet

In-brief: A common, China-based supplier of management software is the common thread that ties together the myriad digital video recorders, IP-based cameras and other devices that make up the Mirai botnet, according to analysis by the firm Flashpoint. 

Mirai, The Internet of Things Bot, Goes Open Source

In-brief: The code for malicious software that is behind a worldwide network of compromised cameras and home routers has been released on the Internet, a move that may lead to a rapid increase in use of the software.

Pretty Much All Consumer Internet of Things Vulnerabilities Are Avoidable

In-brief: A study by the Online Trust Alliance (OTA), a non-profit focused on online trust, put a figure on how many consumer security vulnerabilities could have been easily avoided. That figure: 100 percent. That’s right…every single one.  We’ve been reporting about the low-hanging fruit of vulnerabilities in consumer-focused connected devices for a long time. Years, in fact. Whether the device is a home surveillance camera or a “smart TV” or Bluetooth [fill in the blank], trivial and (often) exploitable security holes are often part of the package. Now a study by the Online Trust Alliance (OTA), a non-profit focused on online trust, put a figure on how many consumer security vulnerabilities could have been easily avoided. That figure: 100 percent. That’s right…every single one. OTA did a survey of vulnerabilities in consumer facing IoT devices between November 2015 and July 2016 and found that all of them could have been avoided had device manufacturers and developers […]

The Worm (Re)Turns, Targets Embedded Linux AirOS

In-brief: A self-reproducing Internet worm is spreading globally, infecting embedded systems running AirOS, Linux-based firmware that runs hardware like wireless routers and wireless access points.

CERT Warns Wind Turbines Open to Compromise

In-brief: Wind turbines made by the UK firm XZERES Wind are susceptible to common, web-based attacks including cross site scripting, according to a warning published by the Industrial Control System CERT (ICS-CERT).