Breaking 20:00 Man arrested after suspected arson attack outside federal building in New York 19:31 NASA says Artemis III remains on track despite Blue Origin setback 17:45 US appeals court overturns class action status in Boeing 737 MAX 9 shareholder lawsuit 15:45 US accuses Cuba of decades-long espionage and subversion campaign 15:36 New York reports three deaths and 74 cases linked to Legionnaires’ disease outbreak 15:10 Trump demands compensation from Canada over Ontario wildfire smoke impact 13:46 US expands electronic warfare capabilities for Morocco’s Apache helicopters 13:45 Tempus to acquire Personalis in $1.5 billion deal to strengthen AI-driven cancer diagnostics 12:15 Trump expresses interest in bringing another World Cup to the United States 12:00 Jd Vance welcomes fourth child after World Cup final 11:30 FIFA's first World Cup final halftime show sparks debate despite star-studded lineup 11:06 Hut 8 secures $9.8 billion AI data center lease to fully commercialize Texas campus 10:31 Meta faces Tennessee trial over claims Instagram was designed to encourage addictive use 10:30 Netanyahu's office condemns New York mayor's remarks over possible arrest during UN General Assembly 10:05 Morgan Stanley expands digital services with direct cryptocurrency trading 09:30 Trump Media considers premium subscription for early access to Trump's Truth Social posts 09:00 New York records second death as Legionnaires' disease outbreak grows 07:30 Nine people injured in Tucson shooting as police investigate motive

DJI Romo vacuum hack reveals global security risks

Monday 09 March 2026 - 11:50
By: Dakir Madiha
DJI Romo vacuum hack reveals global security risks

Spanish software engineer Sammy Azdoufal modified his DJI Romo robot vacuum to respond to a PlayStation 5 controller. He used AI tool Claude to reverse-engineer the DJI app's MQTT communication protocol with company servers. A backend authentication flaw let his device token access roughly 7000 vacuums and power stations across more than 20 countries.​

Azdoufal viewed live camera streams, microphone audio, 3D floor plans, precise locations, battery levels, cleaning progress, and obstacle reports from strangers' homes. A Verge journalist shared a test vacuum's serial number; Azdoufal pulled its real-time data within minutes, including room scans. In one demo, about 6700 devices reported current rooms, cleaning operations, hurdles faced, and charging spots.

Azdoufal alerted DJI, which patched the main vulnerability by February 24, 2026, blocking cross-device access. The company revoked his token, including for his own unit, and pulled the Romo model from its store two days later. Some issues persist, like PIN overrides for camera views.​

The flaw used weak device-agnostic authentication in MQTT messaging. No misuse occurred, but experts warn connected home gadgets with cameras and mics pose privacy threats. Prior incidents include 2024 Ecovacs Deebot hacks in U.S. cities, where intruders remotely drove vacuums and played slurs.​


  • Fajr
  • Sunrise
  • Dhuhr
  • Asr
  • Maghrib
  • Isha

This website, walaw.press, uses cookies to provide you with a good browsing experience and to continuously improve our services. By continuing to browse this site, you agree to the use of these cookies.