惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Engineering at Meta
Engineering at Meta
Cloudbric
Cloudbric
云风的 BLOG
云风的 BLOG
A
About on SuperTechFans
The GitHub Blog
The GitHub Blog
IT之家
IT之家
F
Full Disclosure
B
Blog RSS Feed
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Hugging Face - Blog
Hugging Face - Blog
B
Blog
H
Help Net Security
The Cloudflare Blog
Recorded Future
Recorded Future
P
Proofpoint News Feed
P
Proofpoint News Feed
C
Cisco Blogs
T
Tailwind CSS Blog
P
Palo Alto Networks Blog
D
Docker
爱范儿
爱范儿
Know Your Adversary
Know Your Adversary
博客园 - 聂微东
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Y
Y Combinator Blog
雷峰网
雷峰网
AWS News Blog
AWS News Blog
D
DataBreaches.Net
博客园 - 司徒正美
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
博客园 - Franky
C
Cybersecurity and Infrastructure Security Agency CISA
Blog — PlanetScale
Blog — PlanetScale
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Latest news
Latest news
Google DeepMind News
Google DeepMind News
Martin Fowler
Martin Fowler
MongoDB | Blog
MongoDB | Blog
C
CERT Recently Published Vulnerability Notes
阮一峰的网络日志
阮一峰的网络日志
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
C
CXSECURITY Database RSS Feed - CXSecurity.com
酷 壳 – CoolShell
酷 壳 – CoolShell
C
Cyber Attacks, Cyber Crime and Cyber Security
腾讯CDC
小众软件
小众软件
G
Google Developers Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
Scott Helme
Scott Helme
O
OpenAI News

hackers Archives - VICE

Hackers Are Spreading Malware Through LinkedIn Comments Now Feds Want to Ban the World’s Cutest Hacking Device. Experts Say It's a ‘Scapegoat’ Hackers Took Over Transit Ads with Messages from Queer Palestinians in Gaza ‘Windows for Gamers’ Rolls Dice With Your Security Senator Asks Big Banks How They're Going to Stop AI Cloned Voices From Breaking Into Accounts The Car Thieves Using Tech Disguised Inside Old Nokia Phones and Bluetooth Speakers Hackers Can Remotely Open Smart Garage Doors Across the World The Cure Tried to Stop Scalpers. Brokers Are Selling Entire Ticketmaster Accounts Instead Inside the DEA Tool Hackers Allegedly Used to Extort Targets
Smart Garage Company Fixes Vulnerability by Breaking Customers' Devices
Joseph Cox · 2023-04-07 · via hackers Archives - VICE

A smart garage company has taken a scorched earth approach to cybersecurity, by disabling internet access to its smart lock devices, according to multiple posts on social media by impacted customers. The news comes after Motherboard reported a security researcher found serious issues in the company’s smart locks that allowed hackers to remotely openly garages anywhere in the world across the internet, potentially exposing customers to theft.

“It has come to our attention of a potential internet security vulnerability with the following products: Nexx Garage, Nexx Gate, and Nexx Plug,” an email sent by the company, called Nexx, to customers, reads according to a post on Hacker News. A member of a Facebook Page for Nexx customers wrote a post saying they received a similarly worded email. “As we examine the issue, we are taking proactive action by temporarily disabling internet access remote control” for the products, the message continues.

Videos by VICE

Have you discovered any other serious vulnerabilities? We’d love to hear from you. Using a non-work phone or computer, you can contact Joseph Cox securely on Signal on +44 20 8133 5190, Wickr on josephcox, or email joseph.cox@vice.com.

Instead customers can control their smart locks by Bluetooth, which allows them to be opened within 30 to 50 feet, the message adds.

“I have two NXG100 units that both stopped working at the same time last night.  I disconnected power and reconnected just to see if that would reset it…. that didn’t work,” one impacted customer wrote on the Nexx Community Facebook page. “If they don’t address their security vulnerabilities, it might be time to move onto another product,” the customer added in another post.

It also appears Nexx has removed items for sale from its website after Motherboard’s coverage.

“Completely remote. Anywhere in the world,” Sam Sabetan, the security researcher who found the issues, previously told Motherboard, describing the hack.

In its message to customers Nexx claimed it took “proactive” action. But Sabetan warned Nexx about these vulnerabilities for months in an attempt to responsibly disclose them, according to an email Sabetan shared with Motherboard. On top of that, Motherboard has contacted Nexx about them for weeks. Sabetan said the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) told him it had also attempted contact with Nexx. CISA published its own advisory about the issues on Tuesday.

It appears Nexx actively ignored Sebetan’s warnings. When he didn’t receive a response, he contacted Nexx’s support email and this time said he was looking for help with his own Nexx product. Nexx replied to that email.

“Great to know your support is alive and well and that I’ve been ignored for two months,” Sabetan replied. Please respond to ticket [ticket number,” he wrote, referring to his vulnerability report.

Nexx never did. Sabetan then shared details of the issue with Motherboard, and we published an article discussing them on Tuesday. Only after that did Nexx take steps to mitigate the security risk posed to its customers.

Nexx did not respond to multiple requests for comment sent on Thursday.

Subscribe to our cybersecurity podcast, CYBER. Subscribe to our new Twitch channel.