Beautiful Virgin Islands

Friday, Mar 27, 2026

More than 83 million smart devices, including baby monitors, at risk from hackers

More than 83 million smart devices, including baby monitors, at risk from hackers

Hackers could listen to and watch live audio and video feeds from smart cameras and baby monitors, due to a vulnerability being disclosed by Mandiant and the US Cybersecurity and Infrastructure Security Agency.
A critical vulnerability affecting more than 83 million smart devices, including smart cameras and baby monitors, could allow hackers to listen to and watch live audio and video feeds, it has emerged.

The flaw "poses a huge risk" to people's security and privacy said security company Mandiant, which is coordinating its disclosure with the US Cybersecurity and Infrastructure Security Agency (CISA).

While default passwords have prompted UK security services to warn consumers about criminal activity, the flaw discovered by Mandiant also affects devices which do not use default passwords.

According to Mandiant, the problem is in an IoT (Internet of Things) software protocol called Kalay, developed by Taiwanese company ThroughTek, which offers a platform to control smart devices from.

Before the coordinated disclosure was made, ThroughTek warned users to update their software to stop hackers accessing "sensitive information in transmission and on victim devices".

A similar vulnerability was discovered in the Kalay protocol by Nozomi Networks earlier this year, although Mandiant says its discovery is more severe, allowing attackers to remotely control affected devices as well as snoop on them.

Because the Kalay protocol is installed by both original equipment manufacturers (OEMs) and resellers before smart devices reach consumers, Mandiant said it couldn't determine a complete list of products affected.

However, the business - which is part of cyber security company FireEye - noted ThroughTek's website "reports more than 83 million active devices on the Kalay platform at the time of writing".

Back in 2014, the UK's data watchdog warned Britons that private webcam feeds were being streamed on a Russian website, using default logins and passwords to access the devices.

The British government plans to introduce a new law which will force OEMs and resellers of smart devices to meet minimum security requirements in the UK.

The government announced the Product Security and Telecommunications Infrastructure Bill during the Queen's Speech earlier this year, although this is not yet law.

Announcing the law earlier this year, digital infrastructure minister Matt Warman said: "We are changing the law to ensure shoppers know how long products are supported with vital security updates before they buy and are making devices harder to break into by banning easily guessable default passwords.

"The reforms, backed by tech associations around the world, will torpedo the efforts of online criminals and boost our mission to build back safer from the pandemic."

A spokesperson for the UK's National Cyber Security Centre (NCSC) said: "We are aware of this vulnerability and ThroughTek has released an update to fix the issue.

"Simply using the platform does not automatically make you vulnerable to real-world impact, as additional information that is hard to guess is needed to exploit the vulnerability in an individual device successfully.

"To maximise protection, the NCSC recommends individuals keep their software up to date by installing the latest vendor updates as soon as practicable."
Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
Jaguar Land Rover Halts Production at UK Plant Amid Supplier Disruption
UK Police Reverse Position, Confirm Arrests Will Resume for Palestine Action Protests
UK Small Businesses Face Europe’s Steepest Cost Pressures, New Survey Reveals
US Envoy Urges UK to Proceed with King’s Visit Amid Diplomatic Sensitivities
FTSE 100 Drops Over One Percent as Middle East Tensions Weigh on Markets
UK CO2 Plant Set to Reopen as Authorities Move to Safeguard Supplies Amid Middle East Tensions
Trump Urges Stronger Defence Investment as He Questions Allied Naval Capabilities
New COVID Variant Detected in UK Raises Concerns Over Vaccine Effectiveness
FTSE Russell Moves to Standardise Free-Float Rules for UK and International Listings
HBO Max Launches in UK and Ireland, Marking Major Step in Global Streaming Expansion
UK Signals Readiness to Seize Russian ‘Shadow Fleet’ Vessels in Escalation of Sanctions Enforcement
Escalating Middle East Conflict Seen as Major Threat to UK Economic Stability
Early Challenges Mark Prince Harry and Meghan’s Australia Visit
UK Government Rejects Cover-Up Claims After Theft of Former PM Aide’s Phone
Cyprus Opens Strategic Talks with UK Over Sovereign Base Areas
UK Faces Risk of Sharp Inflation Surge Despite Stable Pre-Crisis Figures
UK Police Arrest Two Over Suspected Antisemitic Arson as Iran Link Investigated
UK Inflation Holds at Three Percent Ahead of Oil Price Shock from Iran Conflict
UK Fuel Prices Face Upward Pressure as Global Oil Trends Raise Cost Outlook
Girlguiding UK Sets September Deadline for Membership Policy Change Affecting Trans Participants
Germany and UK Accelerate Wind Power Expansion to Strengthen Energy Security
UK Moves to Ban Cryptocurrency Donations to Political Parties Over Foreign Influence Concerns
UK and Turkey Finalise Major Air Defence Agreement Worth Billions
Apple Introduces Mandatory Age Verification for iPhone Users in the UK
Diverging Views Emerge Over Meghan Markle’s Planned Australia Appearance
Trump Signals Frustration with UK Leadership Amid Diverging Approaches to Iran Conflict
UK Government Takes Control of Hunterston B as Landmark Nuclear Decommissioning Begins
UK Public Inflation Expectations Jump Sharply in March, Raising Pressure on Bank of England
UK Ministers Warn Expanded North Sea Drilling Would Deepen Exposure to Global Energy Volatility
Delayed UK Defence Investment Plan Leaves Suppliers Under Severe Financial Strain
Can Iran Strike the UK? Assessing the Real Military Threat as Conflict Escalates
Sanctioned Iranian Banker Linked to Luxury Marbella Villa Through UK Corporate Structure
Casey Bloys Navigates HBO Max UK Launch, Paramount Integration and Industry Buzz Over Netflix Meeting
Iran Conflict Sparks Sharp Turbulence in UK Mortgage Market, Reaching Pandemic-Era Disruption Levels
Major Donor Urges University of Kentucky to Reconsider Mitch Barnhart’s Post-Retirement Role
United Kingdom Moves to Lead International Effort to Reopen Strait of Hormuz
UK Police Investigate Targeted Attack on Jewish Ambulance Vehicles
UK Police Investigate Targeted Attack on Jewish Ambulance Vehicles
Senior UK Advocate Criticises Barnhart Retirement Appointment, Calls for Reconsideration
UK Finds No Evidence of Direct Iranian Threat to Britain, Says Prime Minister Starmer
Assessing Iran’s Strike Capability and the UK’s Readiness Amid Rising Tensions
NATO Unable to Confirm Iran’s Role in Strike on UK-US Base as Tehran Denies Involvement
University of Kentucky’s Youling Xiong Receives SEC Faculty Achievement Award for 2026
Trump Highlights Satirical Portrayal of UK Leadership Amid Talks with Prime Minister Starmer on Iran Conflict
Trump Highlights Satirical Portrayal of UK Leadership Amid Talks with Prime Minister Starmer on Iran Conflict
UK Fuel Prices Surge Toward Crisis Levels as Experts Warn of Further Sharp Increases
UK Fuel Prices Surge Toward Crisis Levels as Experts Warn of Further Sharp Increases
Duchess of Sussex Secures ‘As Ever’ Trademark Rights in Australia Ahead of High-Profile Visit
UK Reaffirms Security as Officials Reject Claims of Immediate Iranian Missile Threat
Rising Middle East Tensions Spark ‘Trumpflation’ Debate Over Impact on UK Households
×