Researchers found a semi-legit way to turn an Amazon Echo into a wiretap

An Amazon Echo application created by security researchers proves how the popular smart home device can be co-opted to remotely listen to people’s nearby conversations, according to cybersecurity firm CheckMarx. The research describes how an inherent design flaw in the Amazon Echo could be exploited to covertly and remotely launch the Alexa voice assistant on compromised devices. Alexa was engineered to be able to record and react to voice commands within a predetermined distance from the device. During their controlled experiment, CheckMarx researchers disguised a malicious Echo skill by marketing it as a voice-enabled calculator application that leverages Alexa to execute certain commands. “It can be done totally remotely,” said Erez Yalon, manager of application security research at Checkmarx. “While a hacker creates a malicious skill and publish it to the Amazon store, every user that will use this Amazon skill is exposed.” CheckMarx says the trick didn’t “break or hack […]

The post Researchers found a semi-legit way to turn an Amazon Echo into a wiretap appeared first on Cyberscoop.

Continue reading Researchers found a semi-legit way to turn an Amazon Echo into a wiretap

Infosec expert viewpoint: DevOps security

A Ponemon Institute survey of nearly 1,250 global public sector IT decision makers and managers revealed that public sector organizations undergoing digital transformation are losing confidence in IT operations’ ability to manage the influx of new tech… Continue reading Infosec expert viewpoint: DevOps security

Two Popular IP Cameras Riddled With Vulnerabilities

Two IP cameras sold by Loftek and VStartcam are leaving over 1.3 million users open to 21 vulnerabilities that range from a lack of HTTPS encryption to bugs that open users up to cross-site request forgery attacks. Continue reading Two Popular IP Cameras Riddled With Vulnerabilities

Two Popular IP Cameras Riddled With Vulnerabilities

Two IP cameras sold by Loftek and VStartcam are leaving over 1.3 million users open to 21 vulnerabilities that range from a lack of HTTPS encryption to bugs that open users up to cross-site request forgery attacks. Continue reading Two Popular IP Cameras Riddled With Vulnerabilities