<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Iot on CuraSec</title><link>https://curasec.metacog.co.kr/tags/iot/</link><description>Recent content in Iot on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 28 Jul 2026 13:01:43 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/iot/index.xml" rel="self" type="application/rss+xml"/><item><title>Dysphoria DDoS Botnet Compromises 200k Devices Globally</title><link>https://curasec.metacog.co.kr/insights/2026-07-28-new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/</link><pubDate>Tue, 28 Jul 2026 13:01:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-28-new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No KEV, PoC, or EPSS signal provided; no specific vulnerability or affected software named in the summary. Monitor for follow-up reporting with exploitation details or affected device types that may be in your estate.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> A 200k-node botnet generating DDoS and relay traffic is worth building or tuning detections for — watch for follow-up IOC releases and prepare to hunt for anomalous outbound traffic patterns consistent with botnet C2 or relay behavior.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Awareness-level item for now; if your organization relies on internet-facing services, DDoS resilience posture is worth a periodic review but this report lacks specifics that would require immediate leadership action.&lt;/li>
&lt;/ul></description></item><item><title>Hanwha security camera firmware leaked GitHub admin token in login page</title><link>https://curasec.metacog.co.kr/insights/2026-07-25-my-security-camera-shipped-a-github-admin-token-in-its-login/</link><pubDate>Sat, 25 Jul 2026 12:08:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-25-my-security-camera-shipped-a-github-admin-token-in-its-login/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> If you run Hanwha/Samsung security cameras, audit firmware or network-exposed login pages for embedded credentials; more broadly, scan your own build artifacts and container images for hardcoded tokens using tools like truffleHog or gitleaks, as this pattern recurs in IoT and embedded firmware.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs or active exploitation reported, but the incident illustrates how IoT device web UIs can leak credentials visible to anyone on the network — worth noting for device inventory reviews and camera network segmentation practices.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Illustrates third-party hardware supply-chain risk: vendor-embedded credentials in devices deployed on corporate networks can expose upstream source repositories; factor into hardware procurement and vendor security assessment criteria.&lt;/li>
&lt;/ul></description></item></channel></rss>