this post was submitted on 21 Jul 2026
101 points (97.2% liked)

Technology

86512 readers
3351 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

Shark vacuum robots have an unpatched flaw that could let attackers access cameras, WiFi passwords, and home maps, researcher claims.

Researcher Tokay0 says SharkNinja failed to fix the issue more than 90 days after private disclosure.

The flaw involves AWS IoT certificates, with 673,000 exposed SharkNinja devices observed in one AWS region.

you are viewing a single comment's thread
view the rest of the comments
[–] Q_the_misanthrope@startrek.website 9 points 1 day ago* (last edited 1 day ago) (2 children)

Not shocked. I bought one four years ago, had a ton of issues. After many attempts they send me a new one with the exact same issues. So I have two and neither one works. I’d rather clean the floors myself than fight it.

Their software is garbage, their hardware is garbage.

Anyway based on that experience, I have no doubt their software is full of exploits and issues.

Not to reduce the impact of this article but it does point out:

Attackers need physical device access first, limiting the risk mainly to technically skilled people with a Shark device.

[–] SmoothLiquidation@lemmy.world 3 points 21 hours ago

Would this make them useful to side load your own firmware to them? This “exploit” could make these into a hobbyist’s dream

[–] Scipitie@lemmy.dbzer0.com 1 points 22 hours ago

To get to the certificate with which you THEN can attack devices remotely. I.e. the attacker needs one device. And the skill to extract the certificate and the willingness to abuse it.

One of each and then the 613k devices in the tested region are exposed.