惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The Last Watchdog
The Last Watchdog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
S
Secure Thoughts
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
T
Tor Project blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Google DeepMind News
Google DeepMind News
L
LINUX DO - 最新话题
博客园_首页
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Vercel News
Vercel News
Last Week in AI
Last Week in AI
月光博客
月光博客
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
P
Proofpoint News Feed
博客园 - 叶小钗
NISL@THU
NISL@THU
C
Check Point Blog
K
Kaspersky official blog
N
News and Events Feed by Topic
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
A
Arctic Wolf
T
Threatpost
GbyAI
GbyAI
L
LINUX DO - 热门话题
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
P
Privacy & Cybersecurity Law Blog
N
News and Events Feed by Topic
Scott Helme
Scott Helme
P
Privacy International News Feed
The Register - Security
The Register - Security
G
GRAHAM CLULEY
Recorded Future
Recorded Future
Apple Machine Learning Research
Apple Machine Learning Research
C
Cybersecurity and Infrastructure Security Agency CISA
B
Blog
Project Zero
Project Zero
Cyberwarzone
Cyberwarzone
Webroot Blog
Webroot Blog
Microsoft Security Blog
Microsoft Security Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
D
DataBreaches.Net
J
Java Code Geeks
AWS News Blog
AWS News Blog
Help Net Security
Help Net Security
Engineering at Meta
Engineering at Meta
M
MIT News - Artificial intelligence
T
Threat Research - Cisco Blogs
Google DeepMind News
Google DeepMind News

hackers Archives - VICE

Hackers Are Spreading Malware Through LinkedIn Comments Now Feds Want to Ban the World’s Cutest Hacking Device. Experts Say It's a ‘Scapegoat’ Hackers Took Over Transit Ads with Messages from Queer Palestinians in Gaza ‘Windows for Gamers’ Rolls Dice With Your Security Senator Asks Big Banks How They're Going to Stop AI Cloned Voices From Breaking Into Accounts The Car Thieves Using Tech Disguised Inside Old Nokia Phones and Bluetooth Speakers Hackers Can Remotely Open Smart Garage Doors Across the World The Cure Tried to Stop Scalpers. Brokers Are Selling Entire Ticketmaster Accounts Instead Inside the DEA Tool Hackers Allegedly Used to Extort Targets
Smart Garage Company Fixes Vulnerability by Breaking Customers' Devices
Joseph Cox · 2023-04-07 · via hackers Archives - VICE

A smart garage company has taken a scorched earth approach to cybersecurity, by disabling internet access to its smart lock devices, according to multiple posts on social media by impacted customers. The news comes after Motherboard reported a security researcher found serious issues in the company’s smart locks that allowed hackers to remotely openly garages anywhere in the world across the internet, potentially exposing customers to theft.

“It has come to our attention of a potential internet security vulnerability with the following products: Nexx Garage, Nexx Gate, and Nexx Plug,” an email sent by the company, called Nexx, to customers, reads according to a post on Hacker News. A member of a Facebook Page for Nexx customers wrote a post saying they received a similarly worded email. “As we examine the issue, we are taking proactive action by temporarily disabling internet access remote control” for the products, the message continues.

Videos by VICE

Have you discovered any other serious vulnerabilities? We’d love to hear from you. Using a non-work phone or computer, you can contact Joseph Cox securely on Signal on +44 20 8133 5190, Wickr on josephcox, or email joseph.cox@vice.com.

Instead customers can control their smart locks by Bluetooth, which allows them to be opened within 30 to 50 feet, the message adds.

“I have two NXG100 units that both stopped working at the same time last night.  I disconnected power and reconnected just to see if that would reset it…. that didn’t work,” one impacted customer wrote on the Nexx Community Facebook page. “If they don’t address their security vulnerabilities, it might be time to move onto another product,” the customer added in another post.

It also appears Nexx has removed items for sale from its website after Motherboard’s coverage.

“Completely remote. Anywhere in the world,” Sam Sabetan, the security researcher who found the issues, previously told Motherboard, describing the hack.

In its message to customers Nexx claimed it took “proactive” action. But Sabetan warned Nexx about these vulnerabilities for months in an attempt to responsibly disclose them, according to an email Sabetan shared with Motherboard. On top of that, Motherboard has contacted Nexx about them for weeks. Sabetan said the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) told him it had also attempted contact with Nexx. CISA published its own advisory about the issues on Tuesday.

It appears Nexx actively ignored Sebetan’s warnings. When he didn’t receive a response, he contacted Nexx’s support email and this time said he was looking for help with his own Nexx product. Nexx replied to that email.

“Great to know your support is alive and well and that I’ve been ignored for two months,” Sabetan replied. Please respond to ticket [ticket number,” he wrote, referring to his vulnerability report.

Nexx never did. Sabetan then shared details of the issue with Motherboard, and we published an article discussing them on Tuesday. Only after that did Nexx take steps to mitigate the security risk posed to its customers.

Nexx did not respond to multiple requests for comment sent on Thursday.

Subscribe to our cybersecurity podcast, CYBER. Subscribe to our new Twitch channel.