Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
11/15/2017
12:10 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Airborne Cyber Threats Reach Amazon Echo and Google Home, Reveals IoT Security Company Armis

PALO ALTO, Calif., NOV. 15, 2017  Armis, the enterprise IoT security company, today announced that popular, voice-activated personal assistant devices including the Amazon Echo and Google Home were impacted by BlueBorne vulnerabilities recently discovered by Armis researchers. By exploiting unpatched devices, hackers can take them over, spread malware, and establish a "man-in-the-middle" attack to gain access to critical data, personal information, traffic and networks. BlueBorne is especially dangerous as hackers can execute airborne attacks through any vulnerable Bluetooth-enabled device without having to fool users by clicking on malicious links, downloading a file, or interacting with them in any way.  

In the first wave of BlueBorne vulnerabilities announced, Armis revealed that more than 5 billion devices were subject to attack. In this new phase, researchers have confirmed the attack surface includes as many as 20 million Amazon Echo and Google Home devices running on Android and Linux. BlueBorne is the first severe airborne vulnerability found to affect the Amazon Echo; it doesn’t require an extensive physical attack.

Device Demand Climbing

Amazon and Google voice-activated intelligent personal assistants have created a multibillion-dollar market. It is estimated that there are 15 million Amazon Echoes sold and 5 million Google Home devices sold, according to September report by Consumer Intelligence Research Partners (CIRP).  Additional estimates indicate that more than 128 million Echoes will be installed by 2020 and that they will drive more than $10 billion in revenue for the company by then.

“Burgeoning demand for digital personal assistants is expanding the avenues by which attackers can infiltrate consumers’ lives to steal personal information and commit fraud,” said Yevgeny Dibrov, CEO of Armis. “Consumers and businesses need to be aware how their devices are connecting via Bluetooth, and the networks they may be accessing, in order to take security precautions to protect their information.”

Enterprise Impact

In addition to Echo and Google-powered smart devices and assistants being present in consumers’ homes around the world, both are making their way into business environments, with usage taking place from the boardroom to the copy room. Armis data shows that 82% of its customers have the Amazon Echo in their businesses. A 2016 survey from Spiceworks revealed that almost half of IT professionals polled are either using intelligent assistants or will be within three years at their organizations. With the increased adoption of the devices, it become all the more critical that they are secured in their interactions.    

“Rising airborne threats such as BlueBorne and KRACK are a wakeup call to the enterprise that traditional security simply cannot defend against new attack vectors that are targeting IoT and connected devices in the corporate environment,” added Dibrov. “Every organization must gain visibility over sanctioned and unsanctioned IoT devices in their environments. If they don’t,  they’ll be victimized by a breach that can lead to stolen identities for customers and employees,  impact their bottom lines, and even cost top executives their jobs.”

Coordinated Disclosure

Armis coordinated the disclosed these latest BlueBorne vulnerabilities directly with Google and Amazon ahead of making the discovery publicly known. This allowed them to to release appropriate security patches and updates ahead of hackers gaining knowledge of the vulnerabilities. Google has already released patches to its partners to address the BlueBorne vulnerabilities. Both Amazon and Google have released security updates to the Echo and Home respectively. Updates are automatic and users do not have to do anything to get them.

Scanning App, Patching Available

To help consumers, device manufacturers and business users determine if any devices in use are vulnerable to BlueBorne, Armis has released an app on the Google Play Store that can be used to identify impacted devices. It has been downloaded between over 260,000 times since being released in September, and  can be downloaded here.

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 11/19/2020
New Proposed DNS Security Features Released
Kelly Jackson Higgins, Executive Editor at Dark Reading,  11/19/2020
How to Identify Cobalt Strike on Your Network
Zohar Buber, Security Analyst,  11/18/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: A GONG is as good as a cyber attack.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-20925
PUBLISHED: 2020-11-24
An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects: MongoDB Inc. MongoDB Server v4.2 versions prior to 4.2.1; v4.0 versions prior to 4.0.13; v3.6 versions...
CVE-2020-5641
PUBLISHED: 2020-11-24
Cross-site request forgery (CSRF) vulnerability in GS108Ev3 firmware version 2.06.10 and earlier allows remote attackers to hijack the authentication of administrators and the product's settings may be changed without the user's intention or consent via unspecified vectors.
CVE-2020-5674
PUBLISHED: 2020-11-24
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
CVE-2020-29002
PUBLISHED: 2020-11-24
includes/CologneBlueTemplate.php in the CologneBlue skin for MediaWiki through 1.35 allows XSS via a qbfind message supplied by an administrator.
CVE-2020-29003
PUBLISHED: 2020-11-24
The PollNY extension for MediaWiki through 1.35 allows XSS via an answer option for a poll question, entered during Special:CreatePoll or Special:UpdatePoll.