What’s in the Box? Part II: Hacking the iParcelBox
ID: 1232da44-6b1b-531e-b307-f96eb80dfe6a
STIX ID: report--1232da44-6b1b-531e-b307-f96eb80dfe6a
Feed Name: McAfee Labs Blog
Threat Score
McAfee ATR examined the iParcelBox secure package delivery system and found that developer-posted credentials and insecure cloud permissions allowed an attacker to unlock devices, extract sensitive certificates/keys and obtain primary-owner access via AWS IoT queries; predictable MAC generation made targeting easier. The vendor was notified and remedied the leaks and misconfigurations promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
