Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Webcam Maker Recalls Devices After Friday’s Internet Outage
News & Analysis

Webcam Maker Recalls Devices After Friday’s Internet Outage

ISBuzz TeamBy ISBuzz TeamOctober 25, 2016Updated:July 4, 20247 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Chinese electronics firm Xiongmai is initiating a product recall after the enormous hacking attack that took down much of the internet on the eastcoast of the US and also affected Europe on Friday. The root of the attack, was a network of hacked “Internet of Things” devices, such as webcams and digital recorders, many of which were made by Xiongmai. IT security experts from  Redscan, ESET, AlienVault, prpl Foundation and NSFOCUS commented below.

Robert Page, Lead Penetration Tester at Redscan:

“In the interests of keeping up with competitors and making IoT devices easier to use, hardware manufacturers routinely compromise the security of customers. By rushing to get new products to market, companies can unwittingly introduce vulnerabilities through sloppy software source code or by a failure to allow sufficient time for testing. This ‘release now, fix later’ approach puts users at risk as hackers will purposely compromise newly-released devices.

Shipping devices with default credentials that are easy to crack using brute force is another common failing. As is use of insecure web interfaces that are vulnerable to common attack methods such as SQL injection and cross-site scripting.

To improve security of IoT devices, organisations should heed common failings and continually review and penetration test their products to ensure that they are as safe as possible.  Through better user education and implementation of regular updates, end-to-end data encryption and proactive network monitoring, manufacturers can significantly reduce their likelihood of being exploited.”

Mark James, Security Specialist at ESET:

mark-jamesI don’t think Xiongmai could be held liable for this attack, but they obviously recognise a concern here and are making good steps in the right direction by recalling products that may have been affected. Hopefully other manufacturers will follow suit and take a look at what they can do to increase security of their own products. It seems these days that security takes a back seat, low cost affordable mass consumer use seems to be the preferred option and it has to change if we want a safer environment for our digital presence.

One of the biggest problems with IoT is its lack of security, the race is currently on to get customers involved with your product. The divide between usability and security is hard to get right at the early adoption stage. People like ease, sadly the average user will very often choose ease over security and if offered cheaper or safer, will choose cheaper every time.

IoT device manufacturers have to design security into their products from day one, it has to stop being an afterthought or sadly in some cases no thought. As our digital presence expands we need to accept security is everyone’s responsibility, if we stop buying insecure products and force the manufacturers to make better and safer products things will have to change.

As for IoT devices already in use, you can secure them by upgrading through firmware. In some cases minor changes may make them more secure but in most cases it’s getting those updates out to the public. A lot of IoT devices are purchased, configured, installed and forgotten about, the idea of checking for updates on those devices is alien to most users.

Javvad Malik, Security Advocate at AlienVault:

Javvad Malik“IoT devices have proliferated at a rapid pace, and anyone that can take control of them can wield significant power. The Mirai botnet has given us the first real glimpse into the power of an IoT botnet and the damage that can be done.

With no patching feasible for most devices, there is no easy fix in sight. IoT device manufacturers will need to consider architecting fundamental security principles into the designs, such as avoiding the use of default credentials.

Until such a time that IoT devices have secure options, these devices will continue to feature prominently at the forefront of cyber security attacks.

The challenge with IoT devices is that not only are they often insecure by design, but they lack the options to apply patches or upgrade. Enterprises deploying IoT devices may spend the time needed to change default credentials, place the devices in a segregated network zone, or otherwise harden their systems – but consumers are highly unlikely to implement any such measures.”

Cesare Garlati, Chief Security Strategist at prpl Foundation:

Cesare GarlatiCould Xiongmai be liable for this attack?

Regulators can certainly go after vendors who fail to provide basic security in any consumer products – see FCC Vs Asus precedent. This is an area where regulators must play a role and, for example, ban from sale any connected devices that ship with standard/default/no passwords or heavily fine vendors who fail to recall/patch these devices.

In addition, regulators may force ISPs to temporarily block IP addresses known from being part of active botnets/DDOS – i.e. the ones detected by the Level 3 analysis. A more drastic approach might even include a deliberate cyber attack targeted to these devices to make them unusable – and therefore harmless. In the end, this is no different than stopping a vehicle with broken tail lights to prevent accidents on a highway – just multiplied by hundreds of thousands. There is no need for new technology to block these kinds of unsophisticated attacks – just a good dose of concentration and common sense.”

Is such basic security common across IoT devices?

IoT devices tend to run in constrained environments so security is a bit more difficult to implement on “bare metal” applications but certainly possible using the principals of open source and security by separation using hardware virtualisation.

What should IoT device manufacturers be doing to secure their products?

Prpl’s Security Guidance for Critical Areas of Embedded Computing lays out its revolutionary vision for a secure Internet of Things.  It describes a fresh hardware-led approach that is easy to implement, scalable and interoperable. Based on open source and interoperable standards, it proposes to engineer security into connected and embedded devices from the ground up, using three general areas of guidance. These are not the only areas that require attention, but they will help to establish a base of action as developers begin deal with security in earnest.

Can anything be done to secure IoT devices which are already in use?

The prpl Smart Home Security report recommends the top 10 ways end users can take more control over the security of their devices:

  • Regularly check router firmware updates
  • Change default admin password on router
  • Configure firewall policies – close all ports
  • Enable MAC filtering
  • Use guest network for guest devices
  • Use guest network for all home devices
  • Enable wireless isolation
  • Disable DNS setting via DHCP
  • Disable USB file sharing
  • Disable UPnP

Any other comments?
“This new massive attack to core Internet services confirms the importance of securing IoT devices. Individually, they don’t represent a serious threat but combined in the hundreds of thousands they can easily disrupt critical infrastructure. It also confirms the low level of sophistication of the exploit: mostly directed to common/default user ID and passwords and insecure Internet protocols, which should never been enabled on devices that connect to the public Internet.”

Stephen Gates, Chief Research Intelligence Analyst at NSFOCUS IB:

StephenGates_ProfessionalCould Xiongmai be liable for this attack?

Theoretically speaking, Xiongmai could be held somewhat liable for their technologies being used as an accessory to the attack that occurred last Friday; however, that’s a stretch by any imagination. If an organisation can tangibly prove the attack caused a loss of revenue or maybe even a loss of life, then Xiongmai could hypothetically be held accountable.  Again is has to do with the concept of “due care”, or lack thereof.  As a result, Xiongmai has taken the responsible approach by initiating a recall and also providing a patch to their systems that are already deployed.  Their pre-emptive actio

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}