What happens when you go to modify / #hack #cybersecurity your own automated vacuum cleaner and end up pwning about 7000 vacuum cleaners! He didn't deliberately set out to look thru vac cleaner cameras into strangers' homes but that happened!

https://www.theguardian.com/world/2026/feb/24/spanish-engineer-smart-vacuums-remote-control

Vulnerability was disclosed and issue fixed. How many other such vulnerabilities are waiting for discovery? Or discovered and not disclosed? Was NZ #MediMap hack the result of another attempt to make a small change?
#cybersecurity

https://www.rnz.co.nz/news/national/587832/medimap-health-portal-hack-a-wake-up-call-cyber-security-expert-says

Spanish engineer reports flaw in ‘smart’ vacuums after gaining control of 7,000 devices

Sammy Azdoufal alerted New York-based outlet the Verge after he took control of DJI Romo devices around the world

The Guardian

@Kay IOT/Smart Devices are always a security nightmares...

Almost all notorious Botnet variants are relying on hacked Smart Devices...

For example, Aisuru botnet become the record breaking botnet with highest DDoS volumes in October 2025.

https://securityaffairs.com/183969/malware/aisuru-botnet-is-behind-record-20tb-sec-ddos-attacks.html

Aisuru botnet is behind record 20Tb/sec DDoS attacks

A new Mirai-based IoT botnet, dubbed Aisuru, was used to launch multiple high-impact DDoS attacks exceeding 20Tb/sec and/or 4gpps.

Security Affairs

@AmmarSpaces I wouldn't buy or use an IoT device other than a phone or computer both of which can have better security. I have found stories of hacks interesting.

Like the one by dev who when home with flu decided to check options for the apartment's door camera. Yep. Reversible options and he could look into other people's apartments. Talk was shared at an #infosec conference.

@Kay Yes, I do so too. I only bought things that I just really needed. It is important not to fall of snake oil hype.

As for the talk you mentioned it seems interesting. Can you share me the video/link of the supposed talk?

@AmmarSpaces I don't know if that particular Kiwicon (infosec conference in Wellington New Zealand) was recorded. If so, I haven't yet found it.

Kiwicon has been running for years and earlier events were before everything ended up on Youtube.

Here's a talk from Kiwicon 6: The Mysterious Case of the Disappearing Pen Test Toolkit ... not the same but with similar "I mucked around and this is what I found" energy
https://youtu.be/Jtc1l3E1bIM

More recently Kiwicon has handed over the reins to a mixed crowd and become Kawaiicon. Here's a playlist from the most recent conference Kawaiicon III in 2025
https://www.youtube.com/playlist?list=PL4DuIEuo6yHZ5OzPZohrwTZ34vePQ3Rgz

If you search online I'm sure you'll find more discussions of Kiwicon and its NZ successor Kawaiicon

Kiwicon 6: The Mysterious Case of the Disappearing Pen Test Toolkit

YouTube

@AmmarSpaces Here's a list of talks from Kiwicon 2018
https://2018.kiwicon.org/the-con/talks/

Aha! Found the talk I was looking for in Kiwicon 2014. On screen colours are hell on my eyes but info was there.

Title I know what you did last Wednesday: exploitation of the humble apartment video intercom

Abstract I live in a building with over 700 apartments. Every apartment has a VOIP phone re-purposed as an apartment intercom. One rainy & hungover Sunday I decided to try and pop a shell on the device. A linux device, with a camera, connected to a network, in every one of the seven hundred apartments in my building. You can see where this is going.

Bio Caleb has kicked around the scene long enough that someone finally gave him a job. After a brief stint in the military industrial complex, he now toils in the security mines for .... He enjoys prison tattoos, spoken word poetry, and long walks on the beach with members of the GCSB.
https://2014.kiwicon.org/the-con/talks/

Talks | Kiwicon 2038

Talks

@Kay Thanks, I have something to watch for the night 👌

@AmmarSpaces The links are to short text only content but depending on where you're located local infosec communities may have other recommendations.

I read RiskyBiz newsletter to spot items of interst. Others may watch their news focused videos on Youtube too. Some of the same people as helped run Kiwicon and Kawaiicon. Many friendly if very cynical #infosec people.
https://www.youtube.com/@riskybizmedia

I like looking through DefCon talks too.
https://www.youtube.com/@DEFCONConference

Generally interesting but some talks (like apartment cameras) are more relatable.

Risky Business Media

Cybersecurity news, commentary and product demos.

YouTube
@Kay I do follow Cyber sec conferences in YT too... thanks for referencing Risky Biz Media, it's new one for me.