Breaking 08:02 Ancient complex life depended on oxygen, study of early fossils finds 07:45 Syrian president thanks Trump for “Precious” perfume gift 07:37 Sea level rise has nearly doubled since 1960, study finds 07:30 Eswatini faces criticism over acceptance of U.S. deportees 07:16 Webb telescope suggests Neptune moon Nereid formed within planet’s system 07:02 Nvidia concedes Chinese AI chip market as Huawei gains dominance 16:30 Amazon.com wins appeal in tariff evasion case 16:20 Three supertankers move six million barrels through Hormuz 16:15 James Murdoch expands media footprint with Vox Media acquisitions 16:01 U.S and Israel planned postwar iran leadership shift with ahmadinejad 15:30 Southwest Airlines plans major expansion of India innovation hub to 1,000 employees 14:30 Marco Rubio calls for a “New Path” for Cuba amid rising tensions with Havana 14:15 Elon Musk could become the first trillionaire following SpaceX stock market debut 14:00 Intuit announces major workforce reduction to strengthen AI strategy 13:06 GitHub internal repositories breached through malicious VS Code extension 12:00 Lowe’s maintains annual forecast despite weak U.S. housing demand 11:50 Alibaba launches powerful AI chip to challenge Nvidia dominance in China 11:45 AI financing drives record surge in U.S. convertible bond issuance 09:56 Qatar says Strait of Hormuz remains closed to normal shipping traffic 09:30 Bulgaria requests US visa-free travel for its citizens, says prime minister 09:15 Hyundai recalls over 54,000 vehicles in the US due to fire risk 09:00 Google unveils new connected glasses featuring AI assistant Gemini

DJI Romo vacuum hack reveals global security risks

Monday 09 March 2026 - 11:50
By: Dakir Madiha
DJI Romo vacuum hack reveals global security risks

Spanish software engineer Sammy Azdoufal modified his DJI Romo robot vacuum to respond to a PlayStation 5 controller. He used AI tool Claude to reverse-engineer the DJI app's MQTT communication protocol with company servers. A backend authentication flaw let his device token access roughly 7000 vacuums and power stations across more than 20 countries.​

Azdoufal viewed live camera streams, microphone audio, 3D floor plans, precise locations, battery levels, cleaning progress, and obstacle reports from strangers' homes. A Verge journalist shared a test vacuum's serial number; Azdoufal pulled its real-time data within minutes, including room scans. In one demo, about 6700 devices reported current rooms, cleaning operations, hurdles faced, and charging spots.

Azdoufal alerted DJI, which patched the main vulnerability by February 24, 2026, blocking cross-device access. The company revoked his token, including for his own unit, and pulled the Romo model from its store two days later. Some issues persist, like PIN overrides for camera views.​

The flaw used weak device-agnostic authentication in MQTT messaging. No misuse occurred, but experts warn connected home gadgets with cameras and mics pose privacy threats. Prior incidents include 2024 Ecovacs Deebot hacks in U.S. cities, where intruders remotely drove vacuums and played slurs.​


  • Fajr
  • Sunrise
  • Dhuhr
  • Asr
  • Maghrib
  • Isha

This website, walaw.press, uses cookies to provide you with a good browsing experience and to continuously improve our services. By continuing to browse this site, you agree to the use of these cookies.