Two Santa Cruz students uncover security bug that could let millions do their laundry for free
ID: 64246f76-e235-53c5-85f8-3d3d98f78f4b
STIX ID: report--64246f76-e235-53c5-85f8-3d3d98f78f4b
Feed Name: TechCrunch Security News
Two UC Santa Cruz students discovered and responsibly disclosed an API security vulnerability in CSC ServiceWorks' CSC Go mobile app that allowed client-side manipulation of account balances and direct commands to over a million connected laundry machines; they demonstrated creating arbitrarily large balances, starting cycles without payment, and remote enumeration/interaction of devices. The students reported the issue to CSC and CERT but received little initial response; CSC later acknowledged the flaw, worked with suppliers to remediate, and pledged to improve security reporting, while the researchers warned of financial loss and potential safety risks from internet-connected appliances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
