Updated – Hackout: Philips Smart Lightbulbs Go Dark In Remote Attack
ID: cd45406f-786c-58c1-8295-909f405710f2
STIX ID: report--cd45406f-786c-58c1-8295-909f405710f2
Feed Name: Security Ledger
A security researcher disclosed proof-of-concept attacks against Philips HUE Wi‑Fi lightbulbs and the wireless bridge: the system trusts tokens that are MD5 hashes of a device MAC address (a public value), enabling an attacker who can obtain MACs or operate on the internal network to impersonate allowed devices and send commands (e.g., turn lights off or change color). The report also highlights weak web admin password practices, an IFTTT-based manipulation case, and Philips' limited response and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
