logo

Updated – Hackout: Philips Smart Lightbulbs Go Dark In Remote Attack

ID: cd45406f-786c-58c1-8295-909f405710f2

STIX ID: report--cd45406f-786c-58c1-8295-909f405710f2

Feed Name: Security Ledger

Threat Score
30/100

Date Published: 2013-08-14

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

A security researcher disclosed proof-of-concept attacks against Philips HUE Wi‑Fi lightbulbs and the wireless bridge: the system trusts tokens that are MD5 hashes of a device MAC address (a public value), enabling an attacker who can obtain MACs or operate on the internal network to impersonate allowed devices and send commands (e.g., turn lights off or change color). The report also highlights weak web admin password practices, an IFTTT-based manipulation case, and Philips' limited response and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.