The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Consumer Electronics

Breach intelligence, attack campaigns, and threat reports targeting the Consumer Electronics sector.

90 threat reports
Page 1 of 8

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Consumer Electronics Threat Reports

Showing 1–12 / 90 reports
Critical Eufy Robot Vacuum Vulnerabilities Expose Enterprise IoT Security Gaps
Impact· MEDIUM

Critical Eufy Robot Vacuum Vulnerabilities Expose Enterprise IoT Security Gaps

CISA disclosed critical vulnerabilities in Eufy's Omni C20 and X10 Pro robotic vacuum cleaners, affecting devices running firmware versions below 1.6.4. The vulnerabilities include command injection during device pairing (CVE-2026-93289), hard-coded credentials allowing unauthorized access to mapping data (CVE-2026-93290), and improper certificate validation enabling man-in-the-middle attacks (CVE-2026-93291). These flaws could allow unauthenticated attackers to execute system-level commands and arbitrary code on millions of IoT devices deployed worldwide. The timing coincides with increased scrutiny of IoT security following high-profile supply chain compromises and the growing attack surface of connected home devices. Organizations are under mounting pressure to secure IoT ecosystems as these devices become entry points for lateral movement and data exfiltration in corporate networks.

7 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Bluetooth Flaw Exposes Millions of Skullcandy Dime 3 Users to Device Hijacking
Impact· HIGH

Critical Bluetooth Flaw Exposes Millions of Skullcandy Dime 3 Users to Device Hijacking

Skullcandy Dime 3 wireless earbuds contain a critical Bluetooth vulnerability (CVE-2025-20701) that allows attackers to hijack devices without user interaction. The flaw exists in the Airoha Bluetooth Audio SDK used by these popular earbuds, enabling nearby attackers to connect without pairing PINs or approval requests. Once connected, attackers can intercept audio, access microphone feeds, and maintain persistent access through automatic reconnection. While Skullcandy released firmware version 1.0.0.30 to address the issue, existing users with vulnerable firmware version 1.0.0.28 have no available update mechanism through the mobile app or other consumer-accessible methods. This incident highlights the growing threat landscape targeting IoT devices and consumer electronics, particularly as Bluetooth-based attacks become more sophisticated and accessible to threat actors seeking to exploit trusted device relationships for surveillance and data collection purposes.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
StyleSmuggler Zero-Day: How CVE-2026-75650 Compromised Magento E-commerce Security
Impact· CRITICAL

StyleSmuggler Zero-Day: How CVE-2026-75650 Compromised Magento E-commerce Security

In September 2026, threat actors began exploiting CVE-2026-75650 (StyleSmuggler), a critical zero-day vulnerability in Adobe Commerce and Magento Open Source with a CVSS score of 10.0. The flaw allows unauthenticated remote code execution through PHP code injection in Magento's template system, specifically targeting the 'Payment Transaction Failed Reminder' email function. Attackers deployed sophisticated payloads including a Rust-based Linux backdoor and PHP web shells on compromised e-commerce sites, with exploitation beginning September 4, 2026. This incident highlights the growing sophistication of supply chain attacks targeting e-commerce platforms, as attackers increasingly focus on high-value web applications that process financial transactions and customer data, demonstrating the critical need for runtime application security controls.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Trezor Breach Exposes 81,000 Customers: Third-Party Risk Management Failures
Impact· CRITICAL

Trezor Breach Exposes 81,000 Customers: Third-Party Risk Management Failures

In August 2026, cryptocurrency hardware wallet maker Trezor disclosed a significant data breach at its third-party shipping provider ShipMonk, initially affecting 14,000 customers across multiple countries. The breach expanded dramatically when it was revealed that ShipMonk had failed to delete historical customer data as contractually required, ultimately exposing personal information of 81,000 customers including names, addresses, email addresses, and phone numbers. The attack exploited a critical SQL injection zero-day vulnerability in the Metabase analytics platform, with the ShinyHunters extortion gang later claiming responsibility and sending extortion demands to ShipMonk. This incident highlights the persistent vulnerability of third-party supply chains and the critical importance of data retention policies in an era where cryptocurrency adoption is accelerating and regulatory scrutiny is intensifying. The breach demonstrates how a single compromised analytics platform can cascade across multiple organizations, affecting everything from hardware manufacturers to online service providers.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Plex Issues Urgent Security Warning: Multiple Critical Vulnerabilities Require Immediate Patching
Impact· MEDIUM

Plex Issues Urgent Security Warning: Multiple Critical Vulnerabilities Require Immediate Patching

In September 2026, Plex issued an urgent security advisory warning users to immediately update their media servers and desktop clients to patch multiple critical vulnerabilities affecting Plex Media Server v1.43.2 and earlier. The company released patched versions (Media Server 1.43.3 and Desktop 1.115.0) and took the unusual step of emailing customers directly about the severity of these flaws, though specific CVE details were not yet published. This follows Plex's history of serious security incidents, including a 2025 credential theft vulnerability (CVE-2025-34158) and a 2022 data breach that compromised user credentials and personal information. This incident highlights the growing trend of threat actors targeting popular media streaming platforms and home entertainment systems as attack vectors for lateral movement into personal and corporate networks, particularly as remote work continues to blur the lines between home and business environments.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Supply Chain Attack: Malicious Packagist Packages Exploit iOS Devices to Steal Cryptocurrency Wallets
Impact· HIGH

Supply Chain Attack: Malicious Packagist Packages Exploit iOS Devices to Steal Cryptocurrency Wallets

In September 2026, cybersecurity researchers discovered 13 malicious Composer theme packages on Packagist targeting Vietnamese movie and comic streaming sites. These supply chain attacks injected JavaScript that deployed spyware on unpatched iOS devices running versions 18.4 through 18.6.x. The campaign exploited WebKit vulnerabilities CVE-2025-31277 and CVE-2025-43529 to break out of Safari's sandbox and install kernel-level malware. The sophisticated attack chain exfiltrated keychain databases, Wi-Fi passwords, SMS data, photos, and cryptocurrency wallet seeds from popular wallets including Bitget, Trust Wallet, and OKX, uploading encrypted data to command and control servers hosted on Funnull infrastructure. This incident highlights the evolving threat landscape where supply chain attacks increasingly target mobile platforms and cryptocurrency assets. The campaign's focus on stealing wallet seeds represents a concerning escalation from traditional data theft to direct financial crime, particularly as mobile cryptocurrency adoption accelerates across Southeast Asia.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Hasbro Employee Data Breach Exposes Corporate Cybersecurity Vulnerabilities
Impact· MEDIUM

Hasbro Employee Data Breach Exposes Corporate Cybersecurity Vulnerabilities

In December 2024, toy manufacturing giant Hasbro disclosed a significant data breach affecting employee information after discovering unauthorized access to their systems. The company detected the security incident through their monitoring systems and immediately launched an investigation with external cybersecurity experts. The breach potentially exposed sensitive employee data including personal identification information, employment records, and other confidential details. Hasbro has notified affected employees and is working with law enforcement and regulatory authorities while implementing additional security measures to prevent future incidents. This incident highlights the ongoing vulnerability of large corporations to sophisticated cyber attacks targeting employee databases and internal systems, potentially affecting thousands of workers across the company's global operations. This breach reflects the accelerating trend of attackers targeting employee data as a pathway to broader organizational compromise, particularly as companies expand remote work capabilities and digital HR systems.

3 weeks ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
First Android Malware Targeting Car Head Units Discovered in MoYu Group Campaign
Impact· LOW

First Android Malware Targeting Car Head Units Discovered in MoYu Group Campaign

In August 2026, Kaspersky researchers discovered JarService, the first documented Android malware specifically targeting automotive head units. The malware, attributed to the MoYu Group behind the notorious BadBox botnet, infected DoFun-manufactured car head units by exploiting vulnerabilities in the TWCore firmware update system. The multistage downloader spreads through legitimate update functionality and ultimately deploys click-fraud malware and reverse-proxy modules to recruit infected vehicles into a botnet for ad fraud purposes. While the infected infotainment systems pose no direct physical safety risks to drivers, this represents a significant expansion of botnet operations into connected vehicle infrastructure. This incident highlights the growing threat surface as cybercriminals increasingly target IoT and connected vehicle ecosystems. With automotive systems becoming more interconnected and the rise of software-defined vehicles, securing update mechanisms and embedded systems has become critical for preventing botnet recruitment and protecting connected infrastructure from exploitation.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Calix Router Flaw Exposes Millions of Home Networks to Internet Attackers
Impact· HIGH

Critical Calix Router Flaw Exposes Millions of Home Networks to Internet Attackers

A critical unpatched vulnerability (CVE-2026-75501) in Calix GS7 XGS residential routers allows remote unauthenticated attackers to bypass NAT and firewall protections by creating arbitrary port-forwarding rules. The flaw affects EXOS/6.6.47 firmware and exposes the MiniUPnPd control endpoint on the WAN interface without authentication, enabling attackers to expose internal devices like cameras, NAS systems, and IoT appliances to the public internet with a single SOAP request. Major U.S. broadband providers including Cox Communications, Brightspeed, and ALLO deploy these vulnerable routers to residential customers. This vulnerability highlights the growing risk of perimeter-based security failures in an era where remote work and IoT adoption have expanded attack surfaces. With no vendor patch available and limited workarounds, this incident underscores the urgent need for zero-trust network architectures that don't rely solely on NAT and traditional firewall protections.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
First-Ever Android Car Head Unit Malware: MoYu Group's Supply Chain Attack Analysis
Impact· MEDIUM

First-Ever Android Car Head Unit Malware: MoYu Group's Supply Chain Attack Analysis

In August 2026, Kaspersky researchers discovered a sophisticated supply-chain attack by the MoYu threat group targeting Android-based car head units manufactured by DoFun, a Chinese automotive software provider. The attackers compromised the legitimate TWCore system app to deliver JarService malware, which established command-and-control communication and downloaded additional payloads. The malware transformed infected head units into proxy botnet nodes and conducted advertising fraud operations, marking the first documented malware infection chain specifically designed for automotive head units. While the malware did not interfere with critical vehicle systems, it demonstrated a new attack vector in the expanding Internet of Things landscape. This incident highlights the growing security risks in connected vehicle ecosystems as automotive manufacturers increasingly integrate internet-connected Android systems. The attack underscores vulnerabilities in automotive supply chains and the emergence of vehicles as new targets for cybercriminal monetization schemes.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
First Android Car Malware Campaign Targets Vehicle Head Units Through Update Compromise
Impact· MEDIUM

First Android Car Malware Campaign Targets Vehicle Head Units Through Update Compromise

In June 2026, Kaspersky discovered the first documented malware specifically targeting Android-based vehicle head units, marking a significant expansion of cybercriminal operations into automotive systems. The malware, attributed to the MoYu Group behind the BADBOX botnet, infected DoFun-powered head units through compromised legitimate update mechanisms. Attackers weaponized the TWCore system app's MQTT-based update channel to deliver JarService dropper malware, enabling ad fraud and proxy botnet creation. The sophisticated attack chain demonstrates how threat actors are adapting traditional mobile malware techniques for automotive platforms, exploiting SIM-enabled connectivity in modern vehicle infotainment systems. This incident highlights the emerging threat landscape as connected vehicles become mainstream targets, with automotive cybersecurity gaps creating new attack vectors for established cybercriminal groups seeking to monetize vehicle connectivity infrastructure.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Unisoc Modem Vulnerability: Millions of Android Devices at Risk
Impact· HIGH

Unisoc Modem Vulnerability: Millions of Android Devices at Risk

In August 2026, researchers at SSD Secure Disclosure identified a critical security vulnerability in Unisoc's T612 modem firmware. By chaining a previously disclosed remote code execution (RCE) flaw with a newly discovered memory isolation weakness, attackers can gain privileged access to the Android kernel on affected devices. The exploit involves delivering a malicious payload to the modem and then initiating a video call, which the victim must answer to trigger the attack. This vulnerability impacts devices from manufacturers such as Realme, Xiaomi, and Motorola, leaving millions of users at risk. The significance of this discovery lies in the increasing prevalence of sophisticated attack chains targeting mobile devices. As threat actors continue to exploit firmware-level vulnerabilities, it underscores the necessity for robust security measures and timely firmware updates to protect user data and device integrity.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports