As threats to IoT devices evolve, can security keep up?

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Zoltan Balazs, Head of the Vulnerability Research Lab, CUJO AI


  • Reports of IoT breaches are common and efforts have progressed to manage such risks, but some of these developments provoke mixed feelings among security researchers.
  • Devices that collect data have become increasingly common, particularly with the uptick in cloud-enabled technology.
  • New solutions that are developed to combat ongoing security issues often come with new or different problems.

Internet of Things (IoT) devices are some of the least secure connected machines, but they are also becoming ubiquitous in our lives. The McKinsey Global Institute estimates that 127 new IoT machines go online every second. Data from CUJO AI research shows the significant presence of these gadgets in Western households, where an average consumer home has upwards to 20 online-capable devices.

As we become more connected and 5G-enabled smart city solutions with even more points of connection proliferate, are we putting our connected lives at risk? To even start answering this question, we first have to realise that the IoT threat landscape is not stagnant.

What is the World Economic Forum doing on cybersecurity

The World Economic Forum’s Centre for Cybersecurity is leading the global response to address systemic cybersecurity challenges and improve digital trust. We are an independent and impartial global platform committed to fostering international dialogues and collaboration on cybersecurity in the public and private sectors. We bridge the gap between cybersecurity experts and decision makers at the highest levels to reinforce the importance of cybersecurity as a key strategic priority. World Economic Forum | Centre for Cybersecurity

Our community has three key priorities:

Strengthening Global Cooperation – to increase global cooperation between public and private stakeholders to foster a collective response to cybercrime and address key security challenges posed by barriers to cooperation.

Understanding Future Networks and Technology – to identify cybersecurity challenges and opportunities posed by new technologies, and accelerate forward-looking solutions.

Building Cyber Resilience – to develop and amplify scalable solutions to accelerate the adoption of best practices and increase cyber resilience.

Initiatives include building a partnership to address the global cyber enforcement gap through improving the efficiency and effectiveness of public-private collaboration in cybercrime investigations; equipping business decision makers and cybersecurity leaders with the tools necessary to govern cyber risks, protect business assets and investments from the impact of cyber-attacks; and enhancing cyber resilience across key industry sectors such as electricity, aviation and oil & gas. We also promote mission aligned initiatives championed by our partner organizations.

The Forum is also a signatory of the Paris Call for Trust and Security in Cyberspace which aims to ensure digital peace and security which encourages signatories to protect individuals and infrastructure, to protect intellectual property, to cooperate in defense, and refrain from doing harm.

For more information, please contact us.

The myth of perpetual, unchanging threats

Hardly a week goes by without an article about a new type of IoT device being hacked: internet protocol (IP) cameras, baby monitors, light bulbs, even rifles.

Nevertheless, the IoT security landscape has progressed a lot since 2010, even if the perception of IoT vulnerabilities has largely stayed the same. It’s true that people are still playing VNC roulette – trying to remotely access devices at random – or even attempting to hijack cars. For the most part, however, the public image of IoT threats is perpetuated by the media and attention-hungry security researchers. Scary headlines drive clicks.

The real truth is that a decade of threats and increased awareness has pushed IoT security to change course. Some of these changes are welcome, while others provoke mixed feelings among security researchers.

A decade of threats and increased awareness has pushed IoT security to change course. Some of these changes are welcome, while others provoke mixed feelings.—Zoltan Balazs, CUJO AI

Growth, data collection and shifting security challenges

A decade and a half ago, it was hard to find a smart household device, now it’s hard to find one that is not smart. More than 70% of TVs sold today are smart, and even the “dumb” ones can stream online content through Roku or other smart devices. Analysts predict a compound annual growth rate for Internet Connected Devices of 11% by 2023.

Although some of these devices have useful features, a key driver for developing smart devices is data collection. Some vendors even sell devices with data collection features at a lower price. Customer privacy is a wholly different topic, but it must be noted that having an additional point of contact and connectivity for data collection creates an additional risk vector. To put it simply: the risk of a home network getting hacked increases in line with the number of connected devices, especially if we take IoT devices’ long lifespans into account.

Nevertheless, there have also been positive changes in the IoT industry. IP cameras were once notorious hacking targets due to glaring vulnerabilities like open telnet ports. Nowadays, as devices such as these tend to operate via the cloud only, attacking them is more difficult because they do not usually have open ports or hardcoded default credentials and so are more secure.

Cloud connectivity may create more threats than solutions

Cloud connectivity has generally been good for security, but it is important to note that it is a key enabler for data collection in the IoT sector. Also, while the move towards cloud services may have solved some glaring security issues, new ones appear almost instantly.

While the move towards cloud services may have solved some glaring security issues, new ones appear almost instantly.—Zoltan Balazs, CUJO AI

If a device can only work with an internet connection to cloud servers, operational risk becomes a concern – what happens if the servers go down? Cloud dependency has rendered many devices non-functional in recent years, from smart pet feeders, to home temperature control and security devices, doorbells and vacuum cleaners.

Devices can also be hacked en masse through cloud connectivity. One researcher was able to generate valid camera IDs, use those IDs to connect to a device login screen and guess owners’ passwords or bypass the authentication altogether.

IoT security depends on good practices, which are still not followed by many developers. Standard username and password combinations remain common, as does password reuse. This leaves systems and accounts vulnerable because malicious actors can use that information to target IoT systems. This happened with Ring doorbells before its provider offered two-factor authentication, which significantly reduces the chances of a successful attack, according to our experience at CUJO AI. Sadly, not all IoT service providers offer multi-factor authentication.

Hacking centralised cloud services is also more lucrative for criminals. Once a cloud camera service provider is breached, hackers might be able to access all cameras operated by a provider and then sell that access. The recent case of 150,000 hacked Verkada cameras is a good example of this type of breach.

Another development in the IoT threat landscape is the shift towards targeting higher-value cloud-enabled devices, such as Network Attached Storage (NAS). Criminals focus more on the vulnerabilities of these devices and use them to install ransomware that encrypts the victim’s backups, such as family photos and videos. According to data from CUJO AI Labs, NAS adoption is stable at around 0.2-0.3% of all online devices, which makes it a common, but not pervasive target.

The near-term future of IoT threats and security

The growing number of connected devices is forcing the long-overdue transition to Internet Protocol version 6 (IPv6) addresses. As more Internet Service Providers (ISP) support IPv6 by default, IoT devices will be able to connect to the internet directly rather than operating on private networks. Unfortunately, few of these devices will be powerful enough to run any antivirus or antimalware software. As such, we expect to see more instances of attackers connecting directly to these devices from the internet.

ISPs could block such connections at the gateway (the router) or by adopting better network monitoring solutions, but it is unclear how many ISPs will be willing and able to do this. We will find out whether these new IoT threats appear at the ISP level in the very near future, although hopefully not as part of a new research article about an in-the-wild IPv6 botnet.


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

Aytac Mammadova is a third-year Public Health student at Azerbaijan Medical University

Inclusive Healthcare: Improving Accessibility and Care for Disabled Patients through Investment and Workforce Innovation

This article was exclusively written for The European Sting by Ms. Sadia Khalid, a Scientist-Physician (MBBS, MD) at Tallinn University of Technologye. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s view on […]
© UNICEF/Oleksii Filippov Workers secure plywood boards over the shattered windows of a residential building damaged by a missile strike in eastern Ukraine. (file)

Ukraine: UN aid convoy reaches frontlines in Dnipro

This article is published in association with United Nations. A UN humanitarian convoy reached frontline communities in Ukraine’s Dnipro region on Wednesday, delivering critical medical and hygiene supplies as fighting continues to take a heavy toll on civilians and infrastructure across the country. UN Spokesperson Stéphane Dujarric told reporters that access to the town had been […]
© WFP/Maxime Le Lijour A child helps to pitch his family's tent after it collapsed during heavy rain in Gaza.

UN warns civilians remain at risk as airstrikes continue across Gaza

This article is published in association with United Nations. Fresh airstrikes and shelling across the Gaza Strip over the past 24 hours have put civilians at renewed risk and compounded months of hardship, the UN said on Tuesday, warning that humanitarian needs continue to outpace access and capacity. UN Spokesperson Stéphane Dujarric told journalists at the […]
United Nations Palestinian families are being evicted from the Silwan neighborhood in East Jerusalem.

West Bank: New Israeli measures further erode prospects for two-State solution

This article is published in association with United Nations. UN Secretary-General António Guterres voiced grave concern on Monday over the reported decision by the Israeli security cabinet to authorize a series of administrative and enforcement measures in Areas A and B in the occupied West Bank.  The measures would make it easier for Jewish settlers to take over Palestinian […]
© Unsplash/Hosein Charbaghi A view of Tehran, Iran's capital city.

Guterres welcomes resumption of Iran-US talks

This article is published in association with United Nations. UN Secretary-General António Guterres on Friday welcomed the resumption of talks between Iran and the United States.  The development follows weeks of tensions surrounding Iran’s nuclear programme and threats of a US military attack.  Delegations headed by US Special Envoy to the Middle East Steve Witkoff and Iran’s Foreign […]
© State Specialized Enterprise IAEA inspectors help ensure safety at Ukrainian nuclear power plants. .

Ukraine war keeps nuclear safety on a knife-edge, UN watchdog warns

This article is published in association with United Nations. Attacks on Ukraine’s power system highlight how the ongoing war threatens the safety of the country’s nuclear facilities, the head of the International Atomic Energy Agency (IAEA) warned on Friday.  Russian forces have been carrying out strikes on critical infrastructure amid freezing winter temperatures as their full-scale invasion approaches the […]
This article is published in association with United Nations.

Disability-Inclusive Healthcare: Breaking Barriers to Equity

This article was exclusively written for The European Sting by Ms. Mechoiteu Jijou Berny is a seventh-year medical student at Université des Montagnes in Bangangté, West Region of Cameroon. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and […]
This article was exclusively written for The European Sting by one of our passionate readers, Mr. Andrew Gardner, a strategic and international business consultant. The opinions expressed within reflect only the writer’s views and not necessarily The European Sting’s position on the issue.

Most European Countries are not yet Prioritising European-Made Arms 

This article was exclusively written for The European Sting by one of our passionate readers, Mr. Andrew Gardner, a strategic and international business consultant. The opinions expressed within reflect only the writer’s views and not necessarily The European Sting’s position on the issue. In October 2025, the European Defence Industry Programme (EDIP) was approved by the European […]
UN chief warns of ‘grave moment’ as final US-Russia nuclear arms treaty expires

UN chief warns of ‘grave moment’ as final US-Russia nuclear arms treaty expires

UN Secretary-General António Guterres has warned that the expiration of the New START treaty represents a “grave moment” for international peace and security, as binding limits on US and Russian strategic nuclear weapons fall away amid heightened global tensions. In a statement issued as the treaty expired at midnight GMT Thursday, he said the world […]
UN Ukraine A residential building in Ukraine shows signs of damage following overnight attacks.

Ukraine: Civilians injured, miners killed, in separate Russian attacks

This article is published in association with United Nations. A fresh wave of Russian strikes overnight across Ukraine injured several people and left thousands “without heat in the heart of winter,” the UN Humanitarian Coordinator in the country said on Tuesday.  Matthias Schmale was “appalled” by the attacks in Dnipro, Kharkiv and Kyiv, noting that many more people in several […]
UN News An injured child waits in the courtyard of Al-Amal Hospital in Khan Younis.

Gaza: Limited Rafah crossing reopening sparks hope – but also ‘massive trepidation’

This article is published in association with United Nations. The reopening of the Rafah crossing in the southern Gaza Strip on Monday after more than a year is being met with both optimism and fear, a senior official with the UN agency that assists the Palestinian people, UNRWA, has said.  The sole border point with Egypt is a […]
WFP Children in Fangak county, Jonglei State eat a cooked meal of sorghum. WFP provides food rations to food insecure families containing sorghum, oil, salt, peas and maize (January 2022).

South Sudan: ‘All the conditions for a human catastrophe are present’

This article is published in association with United Nations. Military tensions in South Sudan are “rapidly expanding” between Government forces and opposition militia as fighting continues in restive Jonglei state. Briefing journalists based at UN Headquarters in New York on Friday, Anita Kiki Gbeho, Officer in Charge of the UN Mission in South Sudan (UNMISS), said […]
© UNICEF/Oleksii Fili Children's toys are covered in snow outside a residential building in Kyiv during prolonged winter power and heating outages.

World News in Brief: Syria ceasefire welcomed, ‘Olympic truce’, Ukraine’s freezing children

This article is published in association with United Nations. The UN Commission of Inquiry on Syria has welcomed a ceasefire agreement between the Syrian Government and the mainly-Kurdish Syrian Democratic Forces (SDF), urging all parties to seize the moment to protect civilians and prevent further violations in the country’s northeast.  “We welcome efforts to bring stability […]
This article was exclusively written for The European Sting by Mr. Frank Shao is a Tanzanian medical student. He is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s view on the topic, nor The European Sting’s one.

Access to Healthcare: is it too much to ask?

This article was exclusively written for The European Sting by Mr. Khalil Al Bilani is a 5th-year medical student at Saint George’s University of Beirut. He is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect […]
UN Photo/Manuel Elías Ramiz Alakbarov (on screen), Deputy Special Coordinator for the Middle East Peace Process, briefs the Security Council meeting on the situation in the Middle East.

Potential turning point for Gaza as peace plan enters second phase: UN envoy

This article is published in association with United Nations. The start of a second phase of a stabilisation plan for Gaza offers a potential turning point for the war-ravaged enclave, a senior UN official told the Security Council on Wednesday. Ramiz Alakbarov warned that risks of violence escalating again remain high, while the situation in the […]
This article is published in association with United Nations.

Gaza ceasefire improves aid access, but children still face deadly conditions

The fragile ceasefire in the Gaza Strip is making a difference to the lives of over a million children, and improving overall access to food – but more aid still needs to enter.  That’s the assessment of two senior officials from the UN Children’s Fund (UNICEF) and the World Food Programme (WFP), speaking on Monday to journalists in New York following a […]

A new blow for UNRWA as headquarters in East Jerusalem ‘set on fire’

© UNRWA Destruction at UNRWA headquarters in East Jerusalem after Israeli authorities sent in bulldozers on 20 January. This article is published in association with United Nations. The head of embattled UN relief agency for Palestinians, UNRWA, has condemned reports that its headquarters in East Jerusalem have been set alight deliberately. It comes after Israeli authorities […]
© UNHCR/Yevheniia Kozun This cinema in Saltivka, Kharkiv, was hit during an earlier strike (file Jan 2026).

‘Cycle of attacks must end’: Lead UN official in Ukraine

This article is published in association with United Nations. The senior UN official in Ukraine, Matthias Schmale, has issued a condemnation of the massive overnight Russian drone and missile strike on several major Ukrainian cities, killing and injuring civilians, and knocking out energy infrastructure amid sub-zero temperatures. The attacks on some of Ukraine’s most important population […]
WHO/P. Virot The flag of the UN World Health Organization (WHO) flies at its headquarters in Geneva, Switzerland.

US withdrawal from WHO ‘risks global safety’, agency says in detailed rebuttal

This article is published in association with United Nations. The World Health Organization (WHO) has issued a detailed statement regretting the United States decision to leave the UN agency, and declaring that it will leave both the US and the world less safe as a result. The statement, released on Saturday, also includes a rebuttal of […]

Trackbacks

  1. […] As threats to IoT devices evolve, can security keep up?  The European Sting “IOT” – Google News […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com