Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Encryption - Massive RSA Encryption Flaw Exposes Millions of IoT Devices to Attack
Encryption Data Protection Identity & Access Management Internet of Things Security Latest News News & Analysis Security

Massive RSA Encryption Flaw Exposes Millions of IoT Devices to Attack

Kirsten DoyleBy Kirsten DoyleMarch 18, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
RSA
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

A major security flaw has been found in RSA encryption keys used across the internet. Researchers discovered that about one in 172 online certificates are at risk due to a mathematical weakness. 

The issue mainly affects Internet of Things (IoT) devices but could impact any system using improperly generated RSA keys, arising from poor random number generation during key creation, particularly in devices with limited entropy sources. 

If RSA keys lack enough randomness, they could share prime factors with other keys, making them easy to break using a factorization attack.  

Factorization Attacks 

This type of attack takes advantage of a key RSA property: if two keys share a prime factor, both can be broken by computing the Greatest Common Divisor (GCD). While standard RSA key cracking is difficult, finding a shared factor is much easier, allowing full recovery of private keys. 

According to the International Institute of Informatics and Systemics (IIIS), factoring attacks are based on the fact that the private key d can be computed if p and q can be discovered by factoring n. “Given n and e (which is already known) d can be computed by solving the equation de≡mod φ (n) where the totient is φ (n) = (p-1) (q-1).” 

Keyfactor Security researchers analyzed more than 75 million RSA certificates and found a whopping 435,000 compromised by the simple mathematical technique. 

Researchers used the GNU MultiPrecision (GMP) library to efficiently compute GCDs on a cloud-based virtual machine. Instead of checking each pair, they used a faster product tree and remainder tree approach. 

IoT Most at Risk 

They said IoT devices were most at risk, with about half (50%) of compromised certificates linked to a major network equipment manufacturer. Many vulnerable devices remained unpatched despite previous warnings—highlighting the difficulty of securing IoT systems. 

IoT devices are being used more and more in critical places like hospitals, vehicles, and industrial systems, so the researchers urged manufacturers to improve entropy sources and follow cryptographic best practices to prevent vulnerabilities of this nature.  

Continuous Evaluation Needed  

“This discovery highlights the need for continuous evaluation and improvement of our security infrastructure, particularly as IoT devices are increasingly ubiquitous,” says Javvad Malik, Lead Security Awareness Advocate at KnowBe4.  

Malik adds that a multi-faceted approach is crucial, and that entities need to evaluate their exposure and prior and that entities need to evaluate their exposure and prioritize mitigation efforts. “This should be coupled with implementing more rigorous standards for cryptographic implementations, especially in IoT devices. Fostering increased cooperation between manufacturers, developers, and security professionals is crucial to address systemic vulnerabilities effectively.” 
 
Regulatory considerations should not be overlooked, and exploring the potential for updated guidelines or regulations to ensure minimum security standards across the industry could provide a necessary framework for improvement, he adds. “Cybersecurity is an ongoing process, not a one-time implementation, and something that needs the cooperation of a broad set of stakeholders to cultivate a security-focussed culture throughout the whole ecosystem.” 

“Deepy Disturbing News” 

“This is deeply disturbing news,” says Jamie Akhtar, CEO and Co-founder at CyberSmart. “RSA keys are vital for the most commonly used forms of encryption to work properly. Badly generated RSA keys effectively mean that cybercriminals can crack encryption using a technique known as factorization.” 

Akhtar says the security of RSA relies on the difficulty of factoring large numbers, specifically the product of two large prime numbers. However, if two different RSA keys share a prime factor, both can be broken, pretty easily. “In other words, any system using these faulty RSA keys is open to a breach. And, if early estimates are accurate, this could affect millions of devices and systems, with IoT devices particularly vulnerable. This is very worrying as IoT devices can be found in sensitive places like hospitals, industrial control systems and vehicles. It’s something manufacturers need to lock down quickly.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Britain Drops Apple ‘Backdoor’ Demand After U.S. Pushback

August 20, 20253 Mins Read

A Comparative Analysis of Encryption Algorithms in Protecting Sensitive Data

April 4, 202510 Mins Read

The Looming Quantum Threat: NCSC Urges Encryption Upgrades

March 24, 20255 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}