CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

LABScon25 Replay | Are Your Chinese Cameras Spying For You Or On You?

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 609

As cited

Copy frozen at (site build).

threat intel

LABScon25 Replay | Are Your Chinese Cameras Spying For You Or On You?

Researchers Marc Rogers and Silas Cutler analyzed ultra-cheap Chinese smart home cameras and video doorbells sold globally under rotating brand names, revealing they share identical hardware platforms, contain hardcoded root passwords, and route user data through servers in China and Hong Kong despite claims of local processing. The devices are distributed through shell companies designed to evade regulatory oversight, with minimal security updates and rapid hardware iterations resembling malware distribution patterns. The investigation demonstrates a widespread, vulnerable Internet of Things (IoT) surface accessible to remote configuration from overseas actors.

Why it matters: Organizations and consumers deploying these devices face data exfiltration and remote compromise risks; security teams should audit smart home camera deployments, restrict network access, and evaluate supply chain transparency as part of IoT governance.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

LABScon25 Replay | Are Your Chinese Cameras Spying For You Or On You?

Researchers Marc Rogers and Silas Cutler analyzed ultra-cheap Chinese smart home cameras and video doorbells sold globally under rotating brand names, revealing they share identical hardware platforms, contain hardcoded root passwords, and route user data through servers in China and Hong Kong despite claims of local processing. The devices are distributed through shell companies designed to evade regulatory oversight, with minimal security updates and rapid hardware iterations resembling malware distribution patterns. The investigation demonstrates a widespread, vulnerable Internet of Things (IoT) surface accessible to remote configuration from overseas actors.

Why it matters: Organizations and consumers deploying these devices face data exfiltration and remote compromise risks; security teams should audit smart home camera deployments, restrict network access, and evaluate supply chain transparency as part of IoT governance.

VendorsGoogleOktaCrowdStrikeSentinelOneCloudflare
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary