The Internet on devices continues to be a major problem when it comes to security. Unfortunately, a big part of the reason why comes down to end users. Recently, Bitdefender released a new report entitled “The IoT Threat Landscape And Top Smart Home Vulnerabilities in 2018,” and it paints a grim picture indeed.
The average home now contains twenty smart devices, and most of them contain security vulnerabilities. 95 percent of those vulnerabilities reside in the firmware.
While the majority of smart device users (60 percent ) claim to be “worried” or “very worried” about identity theft, most are utterly failing to adequately protect their IoT devices. In fact, sixty percent indicated that they had never performed a firmware update on their router, and 55 percent reported that they had never updated their smart TVs.
It gets worse. 40 percent of users surveyed indicated that they use the same password for each of their devices, and half of all smart TV owners said they had literally never updated their password.
Thirty percent of users claim that they’re worried about the prospect of a hacker accessing a smart camera to spy on them, but paradoxically, fully 70 percent have at least one camera connected to a vulnerable router.
To provide a sense of scope and scale, the company reported that its BOX product blocked nearly half a million threats (461,718) in just a 30-day period, with 76 percent of those being malicious websites.
Analyst Bogdan Botezatu stressed that while weak passwords are a big part of the problem, it’s not only users who are to blame.
He added:
“Smart device manufacturers share responsibility for the current state of IoT security because most of them are overlooking the security aspect. In their rush to launch the product ahead of the competition, they are leaving attack avenues wide open to attackers interested in user sensitive data.”
If you have one or more smart devices in your home, and you probably do, it’s time to get serious about securing them.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
Do you use the Chrome browser extension for the MEGA file storage service? If you do, please read this article carefully. The official extension for that service has been compromised. It has been replaced with a malware version that has the capability to steal user login data for a number of popular websites, including Github, Google, Amazon, Microsoft and more.
If you fly Air Canada and use their mobile app, it may be time to change your password. The company recently announced that between August 22nd and August 24th of this year, they detected “unusual log-in behavior,” and that a small fraction (some 20,000) of their 1.7 mobile app users may have had their data compromised as a result.
Tech Support scams are nothing new, but they are getting increasingly sophisticated. Worse, tech giants like Google are finding it notoriously difficult to detect them.
Business Email Compromise (BEC) attacks are a major threat, costing business nearly three billion dollars a year.
2017 was “The Year of Ransomware.” It saw an incredible number of ransomware attacks and infections, paired with a tremendous number of innovations.
A new study recently published by Sitchfast Technologies paints a grim picture of the threat landscape for small and medium-sized business. Their key finding? A staggering 60 percent of small businesses that suffer a data breach of any magnitude go out of business within six months. Worse, one business owner in three does not have a plan or safeguards in place to prevent a breach.
Researchers operating out of the University of Florida, Stony Brook University and Samsung Research America have made a disturbing discovery. Millions of Android smartphones manufactured by eleven different OEMs (Original Equipment Manufacturers) were found to be vulnerable to attack via AT Commands.
There’s a new threat to point of sale (POS) systems coming out of Russia, according to security researchers from Booz Allen Hamilton. The malware, which they’re calling “RtPOS” isn’t bleeding edge technology, and does not approach the level of sophistication of other recently discovered strains, but that doesn’t mean it should be taken lightly. These strains include RawPOS, MajikPOS, UDPOS, and Treasure hunter.
Quick question – how much do the world’s cyber criminals make every sixty seconds?