IoT Device Compromise
IoT device compromise hits cameras, routers, sensors, smart televisions, locks, controllers and all the equipment connected to a network that does not behave like a classic computer. The problem is that these devices are often forgotten the moment they are switched on.
Term
description · examples · notesIoT device compromise hits cameras, routers, sensors, smart televisions, locks, controllers and all the equipment connected to a network that does not behave like a classic computer. The problem is that these devices are often forgotten the moment they are switched on.
Description
Many IoT devices carry weak or default passwords, rare updates, insecure firmware and open services that should never be reachable from the internet. Once compromised they can serve for DDoS, for espionage, as a way into the network, and more often as passive but sometimes active infrastructure for the attacker.
IoT is awkward because organizations often do not see it as IT. A camera is a camera, a printer is a printer, a sensor is a sensor. But to an attacker each of them is a device with a network, an identity, software and vulnerabilities.
Examples
- A camera with a default password joins a botnet and is used for DDoS.
- A router with old firmware becomes the entry point into the internal network.
- A smart device in the office sends unusual outbound traffic to a command server.
Notes
- Anything with an IP address, firmware and network access is part of the attack surface.
- An IoT device without updates and without segmentation should be treated as a device that will be compromised sooner or later.
Mentioned in the news
- 22. JUN 2026. AryStinger pretvara stare D-Link rutere u proxy čvorove za sajber napade →
- 19. APR 2026. Mirai napadi ciljaju stare TP-Link rutere preko CVE-2023-33538 →
- 4. APR 2026. Kritični propusti u TP-Link Tapo kameri omogućavaju rušenje uređaja i zaobilaženje prijave →
- 21. MAR 2026. Međunarodna akcija poremetila rad velikih DDoS botneta koji zloupotrebljavaju IoT uređaje →
- 13. MAR 2026. Ugašen SocksEscort servis koji je prodavao pristup kompromitovanim kućnim ruterima →
- 13. MAR 2026. Ugašen SocksEscort botnet koji je kompromitovao 369.000 rutera širom sveta →
- 5. MAR 2026. Iran-povezane grupe iskorišćavaju ranjivosti u IP kamerama →
Techniques
carried out with 4Techniques used to carry it out. Select one to open its page.
Defenses
countered by 6How it is defended against. Select one to open its page.