My Adventures Hacking the iParcelBox
ID: cc5132be-cad0-51a6-90d9-4edc6ac4bea3
STIX ID: report--cc5132be-cad0-51a6-90d9-4edc6ac4bea3
Feed Name: McAfee Labs Blog
McAfee ATR researched the iParcelBox smart parcel box and discovered multiple critical security issues: exposed admin credentials and GitHub token in logs, inappropriate use of shared AWS certificates/keys and Cognito/DynamoDB access that allowed database enumeration by DeviceID (MAC), and RPC-over-MQTT functionality that enabled remote administrative control (including unlocking boxes and retrieving Wi‑Fi credentials). The team demonstrated local and remote attack paths, reported the problems to iParcelBox, and the vendor deployed fixes within 12 hours (rotated admin credentials, constrained certificate/key scope, added API checks and improved SSL handling).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
