Shark robot vacuum flaw exposes fleet-wide IoT risks
Source Summary
Security researcher “tokay0” recently published a serious vulnerability affecting Shark robot vacuums. A certificate extracted from one compromised Shark robot vacuum could be used to access other devices, exposing live camera feeds, stored home maps and Wi-Fi credentials held in plaintext. During a 24-hour observation, the researcher identified more than 1.5 million Shark serial numbers in one AWS region, with approximately 674,000 devices responding to a command probe. Edwin Shuttleworth, Lead Penetration Tester and Security Researcher at Finite State, offered the following comments: - Opinion / affiche
Advertisement