Tag: iot
-
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators.Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019.The…
-
IoT Sector Given Final EU Cyber Resilience Act Guidance
Incident Reporting Starts Sept. 11, Other Mandates Wait Until Dec. 11, 2027. The European Commission published final guidance for complying with the Cyber Resilience Act, a 2024 law that aims to boost the cybersecurity of software and internet-connected hardware products. The greatest change from a previous draft is which software falls within the CRA’s scope.…
-
Tengu Mirai Botnet Uses Watchdog Reboots and Binary Bricking to Resist Removal
Tengu, a newly observed Mirai-derived botnet, is demonstrating how modern IoT malware is rapidly evolving beyond traditional distributed denial-of-service (DDoS) operations by integrating persistence, evasion, and multi-functional attack capabilities. Unlike legacy Mirai variants, Tengu employs a hybrid C2 model that blends plaintext and encrypted communications. Initial registration and heartbeat messages are transmitted in cleartext, while…
-
Dysphoria IoT Botnet Uses Blockchain Domains and 200,000 Devices for DDoS Attacks
A rapidly evolving IoT botnet dubbed “Dysphoria” has emerged as a significant global threat, leveraging blockchain-based domain resolution and a hybrid command-and-control (C2) architecture to sustain large-scale distributed denial-of-service (DDoS) operations. Dysphoria’s evolution has been unusually aggressive, transitioning from early jackskid-derived variants to more sophisticated fbot-based implementations within weeks. Initial samples observed in March 2026…
-
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to disrupt.CNCERT, China’s national computer emergency response team, and XLab, the threat-intelligence lab of Chinese First seen…
-
Cyberresilienz im Zeitalter von KI: Wie sicher ist das IoT wirklich?
Die Bedrohungslage im Bereich der Cybersicherheit verändert sich rasant. Das Bundesamt für Sicherheit in der Informationstechnik (BSI) warnt aktuell, dass künstliche Intelligenz die Geschwindigkeit, Skalierung und Automatisierung von Cyberangriffen erheblich erhöht und Unternehmen ihre Sicherheitsstrategien entsprechend anpassen müssen [1]. Vor diesem Hintergrund gewinnt der Cyber Resilience Act (CRA) der Europäischen Union zusätzlich an Bedeutung und……
-
Wansview IoT Camera Flaw Exposes Supply Chain Security Risks
Researchers found decades-old software flaws in a Wansview IoT camera that expose software supply chain security risks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/wansview-iot-camera-flaw-exposes-supply-chain-security-risks/
-
KI-generierter Quellcode bei neuem Botnetz TuxBot v3 entdeckt
Sicherheitsforscher haben das IoT-Botnetz-Framework TuxBot v3 Evolution entdeckt. Es wurde nachweislich unter Einsatz von künstlicher Intelligenz entwickelt. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ki-generierter-quellcode-botnetz
-
TuxBot v3: The IoT Botnet Built With AI Bugs, Disclaimers and All
TuxBot v3, an AI-built IoT botnet for 17 architectures, shipped with LLM bugs and safety disclaimers the developer never removed. Palo Alto Networks’ Unit 42 identified a previously undocumented modular IoT botnet framework called TuxBot v3 Evolution, and it comes with an unusual detail: the developer used a large language model to write significant portions…
-
New VEXAIoT AI Agents Autonomously Exploit IoT Vulnerabilities With 95% Success Rate
VEXAIoT, an autonomous multi-agent framework designed to discover and exploit vulnerabilities in the Internet of Things (IoT) within controlled test environments. In 200 attack trials against the intentionally vulnerable IoTGoat platform, the system completed 189 attacks, achieving an overall success rate of 94.5% (rounded to 95%). New VEXAIoT AI Agents Attack Workflow VEXAIoT, short for…
-
Warum ManagedProvider beim Manufacturing 4.0 IT und OT gemeinsam denken müssen
Die Konvergenz von IT und OT schreitet mit hoher Geschwindigkeit voran und sorgt für grundlegende Veränderungen in industriellen Infrastrukturen. Immer öfter sind Produktionsanlagen, Sensorik, Edge-Geräte, IoT-Sensoren und industrielle Steuerungssysteme (ICS) eng mit klassischen IT-Infrastrukturen vernetzt. Auch für Managed-Service-Provider (MSPs) bedeutet das einen tiefgreifenden Wandel ihrer Rolle. Denn anstelle von getrennten Silos erwarten Kunden von MSPs…
-
Internet-Intelligence und Attack-Surface-Management als Basis für Exposure-Management
Die Angriffsfläche von Unternehmen wächst kontinuierlich. Cloud-Dienste, SaaS-Anwendungen, IoT-Sensoren, hybride Infrastrukturen und Remote-Work sorgen dafür, dass immer mehr Systeme direkt über das Internet erreichbar sind. Eine umfassende Transparenz mit Exposure-Management wird damit zu einer zentralen Voraussetzung für wirksame Cybersecurity. Externe Angriffspunkte bilden den Ausgangspunkt vieler erfolgreicher Angriffe. Fehlkonfigurationen, Schatten-IT, unbeabsichtigter Remote-Access und im Internet sichtbare…
-
Seven Bugs in FatFs Put IoT and Embedded Devices at Risk
runZero found 7 flaws in FatFs, a filesystem used in IoT and embedded devices. Bugs can cause memory corruption, crashes, or data leaks via crafted storage. Cybersecurity firm runZero has disclosed seven vulnerabilities in FatFs, a compact open-source library that lets embedded devices read and write FAT and exFAT formatted storage, the same formats used…
-
Angriff per USB-Stick: KI findet gefährliche Lücke in populärem FatFs-Treiber
Das bloße Anschließen eines USB-Sticks reicht aus, um auf vielen Embedded- und IoT-Geräten Schadcode einzuschleusen. Einen Patch gibt es bisher nicht. First seen on golem.de Jump to article: www.golem.de/news/angriff-per-usb-stick-ki-findet-gefaehrliche-luecke-in-populaerem-fatfs-treiber-2607-210484.html
-
Healthcare Cybersecurity Threats Persist in 2026
SonicWall found healthcare remains the top cybersecurity target, with rising malware, ransomware, and medical IoT threats. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/healthcare-cybersecurity-threats-persist-in-2026/
-
RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow
RustDuck is a small, evolving DDoS botnet migrating to Rust. It uses advanced encryption, anti-analysis evasion, and exploits known IoT flaws. Since February 2026, researchers at QiAnXin’s XLab have been tracking a new malware family, called RustDuck, that hijacks routers, cameras, Android set-top boxes, and exposed servers, then uses them to flood targets with junk…
-
New RustDuck Botnet Targets IoT Devices and Servers With Weak Passwords and RCE Exploits
A sophisticated new botnet family dubbed RustDuck emerged in early 2026, leveraging a two-stage Loader and Core architecture to compromise IoT devices, routers, and enterprise servers through brute-force credential attacks and remote code execution vulnerabilities. RustDuck employs a multi-pronged infection strategy combining weak password attacks against Telnet and SSH services with exploitation of known RCE…
-
NIST seeks public feedback on updated IoT security guidelines
First seen on scworld.com Jump to article: www.scworld.com/brief/nist-seeks-public-feedback-on-updated-iot-security-guidelines
-
Forescout macht Quantenrisiken sichtbar: Neue PQC-Dashboards für IT, OT, IoT und IoMT
Tags: iotMit den neuen PQC-Readiness- und Verschlüsselungshygiene-Dashboards will Forescout Unternehmen einen praktischen Einstieg in die Post-Quantum-Sicherheit geben. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/forescout-macht-quantenrisiken-sichtbar-neue-pqc-dashboards-fuer-it-ot-iot-und-iomt/a45608/
-
Canada’s Spy Agency Used FirstIts-Kind Warrant to Clean Botnet-Infected Devices
Canada’s spy service got a judge’s permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and neutralize two foreign-run botnets.The Federal Court released a public version of the ruling on June 15. It is the first time the Canadian Security Intelligence Service has used its threat reduction warrant powers…
-
China-Linked JDY Botnet Hijacks 1,500+ IoT Devices for Rapid Exploits
A significant resurgence of the JDY botnet, a covert reconnaissance network tied to China-nexus threat activity. Once a component of the larger KV-botnet ecosystem, JDY has expanded to more than 1,500 compromised small office/home office (SOHO) and Internet of Things (IoT) devices and now functions as a high-performance, centrally controlled scanner that accelerates vulnerability discovery…
-
Top 10 Best Zero Trust Network Access (ZTNA) Solutions 2026
In 2026, the traditional network perimeter is obsolete. With the widespread adoption of remote and hybrid work models, multi-cloud environments, and a proliferation of IoT devices, the old >>castle-and-moat<< security model where everything inside the network is trusted by default is no longer viable. This outdated approach leaves organizations vulnerable to sophisticated attacks, including lateral…
-
IoT Botnet C0XMO Adds Competitor-Killing Capability
C0XMO is a new Gafgyt botnet variant exploiting old router flaws, spreading across IoT devices, killing rivals, and enabling large-scale DDoS attacks. In March 2026, FortiGuard Labs discovered a new variant of the Gafgyt botnet, dubbed C0XMO, which is noticeably more capable than its predecessors. The malware spreads through CVE-2021-27137, a stack buffer overflow in…
-
New Gafgyt Variant Targets Linux Systems With Modular Spread Tactics
A new Gafgyt-family botnet, tracked as C0XMO, marks a notable technical shift in IoT malware design: the separation of scanning and propagation into distinct components and multi-architecture payloads that maximize reach across heterogeneous Linux devices. The operator delivered C0XMO by exploiting CVE-2021-27137 a stack buffer overflow in the UPnP SSDP parser of vulnerable DD-WRT firmware…
-
AI-Powered Worm Leverages Stolen Compute to Target Linux, Windows, and IoT Devices
AI-powered malware is moving from theory to reality, with new proof-of-concept worms showing how large language models (LLMs) can autonomously compromise mixed networks of Linux, Windows, and IoT devices while parasitically hijacking GPU compute for their own reasoning. Instead of shipping with a fixed exploit toolkit, this new class of AI-driven malware uses an embedded…
-
Dragos Expands Into Connected Devices With Phosphorus Buy
OT Firm Looks to Secure IoT, Industrial and Medical Devices. Dragos, one of the first OT cybersecurity companies, announced Monday it acquired Phosphorus, the IoT security and management player, a move analysts said was designed to catch Dragos up with its competitors and expand its offerings to cover the quickly growing IoT sector. First seen…
-
Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices
Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices, to carry out malicious attacks.The bot network, per the Dutch Politie and the National Cyber Security Center (NCSC), consisted of at least 17 million infected devices. More than 200 servers located in the…
-
Sichtbarkeit in der Netzwerksicherheit: Vom blinden Fleck zur kontrollierten Abwehr
Die Bedeutung von Sichtbarkeit in der Netzwerksicherheit kann nicht hoch genug bewertet werden, da viele Unternehmen ihre tatsächliche Geräte- und Systemlandschaft nicht vollständig kennen, was Risiken erhöht. Moderne Netzwerke bestehen aus IT, OT, IoT und IoMT, was eine vollständige Kontrolle und Erkennung aller Geräte erfordert, zumal viele Geräte nicht verwaltet oder schwer zu patchen… First…
-
Sichtbarkeit in der Netzwerksicherheit: Vom blinden Fleck zur kontrollierten Abwehr
Die Bedeutung von Sichtbarkeit in der Netzwerksicherheit kann nicht hoch genug bewertet werden, da viele Unternehmen ihre tatsächliche Geräte- und Systemlandschaft nicht vollständig kennen, was Risiken erhöht. Moderne Netzwerke bestehen aus IT, OT, IoT und IoMT, was eine vollständige Kontrolle und Erkennung aller Geräte erfordert, zumal viele Geräte nicht verwaltet oder schwer zu patchen… First…

