logo

When your IoT Device Logs in as Admin, It?s too Late! [Guest Diary], (Wed, Mar 11th)

ID: 6fdcd98a-c7a2-52a0-ba98-f7f03980fdd7

STIX ID: report--6fdcd98a-c7a2-52a0-ba98-f7f03980fdd7

Feed Name: SANS ISC Diary

Threat Score
60/100

Date Published: 2026-03-12

Date Updated: 2026-04-19

...
...

**Executive summary:** This guest diary documents active, automated scanning and brute-force exploitation of default or trivial credentials against IoT and networked devices observed in a honeypot and vulnerability assessment, reporting ~44k failed attempts, 1,286 successful logins, dominant credentials (e.g., root, 123456), HASSH fingerprints, and examples of post-compromise actions (persistence and password manipulation), and concludes with mitigation recommendations such as changing defaults, MFA, segmentation, and continuous monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.