Shark vacuum flaw exposes cameras, home maps and Wi-Fi passwords
ID: 9518ae4c-74c7-5f39-b27f-3fe677040fd4
STIX ID: report--9518ae4c-74c7-5f39-b27f-3fe677040fd4
Feed Name: Malwarebytes Blog
Shark robot vacuums ship with an overly permissive AWS IoT/MQTT policy and embedded device certificates that allow a stolen certificate from one vacuum to publish/subscribe to shadows for many other devices in the same AWS Region. A researcher who extracted a certificate demonstrated the ability to monitor and issue remote commands, potentially exposing cameras, plaintext Wi‑Fi credentials, and home maps; the issue is cloud-side (requires vendor action) and reportedly remains unpatched after more than six months.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
