Monday, July 30, 2018

Samsung's SmartThings hub suffered from 20 vulnerabilities that could have allowed attackers to control the internet-of-things devices connected to it. Thankfully, security intelligence firm Cisco Talos discovered the flaws and worked with the Korean company to resolve the issues, allowing Samsung to release a firmware update that patches them for all affected customers. Talos admits in its report that some of the vulnerabilities would've been difficult to exploit, but attackers can combine several at once to launch a "significant attack on the device."

While the hub may not have access to credit card and bank account numbers, hackers could have taken advantage of the flaws to disable smart locks and gain physical entry to people's homes, for instance, or to take command of nanny cams and CCTVs to monitor a house's occupants or an establishment's activities. They could've used the flaws to disable motion and alarm systems or even to damage appliances connected to the hub.

Despite the multiple vulnerabilities, Talos praised the company for working to resolve the situation after being informed. Craig Williams, Director of Cisco Talos Outreach, told ZDNet that Samsung "did a lot of things right and should be commended for the way [it] designed [its] devices to be easily updated." He added "Every piece of software from every vendor has bugs if you look closely enough." A Samsung spokesperson also told the publication that it had already released an automatic update to fix all the flaws Talos found and "all active SmartThings Hub V2 devices in the market are updated to date."

Via: ZDNet

Source: Talos Intelligence



from Engadget RSS Feed https://ift.tt/2OqoHUH

Related Posts:

  • LATEST TECHNOLOGY NEWS AT&T is facing quite the pushback over its decision to label its upgraded LTE network as "5G Evolution," and not just from rival carriers (yes, including Engadget parent Verizon) taking cheap shots at a competitor. Howev… Read More
  • LATEST TECHNOLOGY NEWS Sure, you can play immersive games and watch whales come out of the floor with Magic Leap, but another potential use case of AR is teleconferencing and work collaboration. That's mostly done via avatars these days, but at CE… Read More
  • LATEST TECHNOLOGY NEWS Our editors have been hard at work the past few days finding the latest and greatest gadgets here at CES 2019. Now, after a long and arduous debate, we're ready to announce our finalists for the official Best of CES awards. … Read More
  • LATEST TECHNOLOGY NEWS We've announced our Best of CES finalists so now it's time for you to cast your vote for your favorite gadget at CES 2019! Just head over here (or below) to pick your three favorite items from our pool of finalists. You have… Read More
  • LATEST TECHNOLOGY NEWS The folks behind Wattpark see an opportunity to bring the gig economy to electric vehicles. They envision a future where people purchase reasonably affordable EV charging ports and install them at home, a business or anywhe… Read More

0 comments:

Post a Comment

Followers

Contact Form

Name

Email *

Message *

Popular Posts

FOLLOW BY EMAIL

Enter your email address:

Delivered by FeedBurner