Breaking 14:30 Traders anticipate possible Federal Reserve interest rate cut by September 14:20 Musk warns parents to keep ChatGPT away from children after Canada shooting lawsuit 14:07 Aluminum hits four year high as Gulf war disrupts global supply 13:50 Silo AI founder launches QuTwo to link enterprise AI with quantum computing 13:45 Netherlands adopts cautious stance on US and Israeli strikes against Iran 13:43 BofA strategist warns markets echo conditions before the 2008 financial crisis 13:15 Hungary calls on EU to reconsider sanctions on Russian oil after US decision 13:00 China urges US to halt new arms sales to Taiwan ahead of Trump visit 12:20 Crypto fear index exits extreme fear after 41 day market slump 11:50 U.S. dollar hits four month high as Middle East war drives safe haven demand 10:50 Oil surges above $100 as Iran vows to keep Strait of Hormuz closed 09:50 Japan signals readiness to intervene as yen nears 160 against dollar 09:20 Altman says AI will be sold by usage like electricity 08:50 Apple launches $599 MacBook Neo, shaking up the budget laptop market 08:20 Gold steadies near $5,175 as strong dollar offsets safe haven demand 07:50 Scientists uncover 300 million year old DNA code hidden in plant genomes 07:20 Oil prices could drop to $55 despite Strait of Hormuz crisis 07:00 Asian stock markets fall as Iran conflict keeps oil near $100 15:50 Swedish startup Lovable reaches $400 million revenue with 146 employees 15:32 Kremlin says Russia-US cooperation could stabilize global energy markets 15:20 Bitcoin short bets hit three year extreme as price drops below $70,000 14:50 UBS urges investors to favor gold, dollar and TIPS amid US Iran tensions

DJI Romo vacuum hack reveals global security risks

Monday 09 - 11:50
By: Dakir Madiha
DJI Romo vacuum hack reveals global security risks

Spanish software engineer Sammy Azdoufal modified his DJI Romo robot vacuum to respond to a PlayStation 5 controller. He used AI tool Claude to reverse-engineer the DJI app's MQTT communication protocol with company servers. A backend authentication flaw let his device token access roughly 7000 vacuums and power stations across more than 20 countries.​

Azdoufal viewed live camera streams, microphone audio, 3D floor plans, precise locations, battery levels, cleaning progress, and obstacle reports from strangers' homes. A Verge journalist shared a test vacuum's serial number; Azdoufal pulled its real-time data within minutes, including room scans. In one demo, about 6700 devices reported current rooms, cleaning operations, hurdles faced, and charging spots.

Azdoufal alerted DJI, which patched the main vulnerability by February 24, 2026, blocking cross-device access. The company revoked his token, including for his own unit, and pulled the Romo model from its store two days later. Some issues persist, like PIN overrides for camera views.​

The flaw used weak device-agnostic authentication in MQTT messaging. No misuse occurred, but experts warn connected home gadgets with cameras and mics pose privacy threats. Prior incidents include 2024 Ecovacs Deebot hacks in U.S. cities, where intruders remotely drove vacuums and played slurs.​


  • Fajr
  • Sunrise
  • Dhuhr
  • Asr
  • Maghrib
  • Isha

This website, walaw.press, uses cookies to provide you with a good browsing experience and to continuously improve our services. By continuing to browse this site, you agree to the use of these cookies.