iot-security
Safeguard articles tagged "iot-security" — guides, analysis, and best practices for software supply chain and application security.
6 articles
A Weather Station Gateway With Root-Level Command Injection, No Login Required
Smartbedded Meteobridge's CGI-shell-script web interface lets a remote unauthenticated attacker execute arbitrary commands as root, a legacy embedded architecture problem still live in 2026.
A 2017 Hikvision Camera Bug Is Still Getting Exploited in 2026
CVE-2017-7921 spans seven Hikvision camera product families and grants unauthenticated privilege escalation — confirmed exploited nearly nine years after its original disclosure.
Precision Agriculture Security: An Industrial Control Problem With No Regulatory Framework Yet
GPS-guided tractors, sensor networks, and cloud farm management platforms have made agriculture an IoT and ICS security question — without the sector-specific framework other critical industries have.
Lantronix EDS5000's Failed-Login Logging Was Itself the Vulnerability
CVE-2025-67038 triggers on a failed login attempt alone: the device server shells out to write a log entry, concatenating the attacker-supplied username unsanitised into the command.
IoT device security fundamentals: firmware integrity, credentials, and network isolation
One hardcoded Telnet password list built a 100,000-device botnet in 2016. A decade later, the same three failures still define most IoT breaches.
Zyxel Router Command Injection: CVE-2024-40891 Exploited in the Wild
Threat actors began mass-exploiting a Telnet-based command injection flaw in Zyxel CPE routers, with over 1,500 devices compromised in botnet campaigns. Zyxel initially refused to patch.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.