Security Watch: Hacking the Robot Spies
The “Internet of Things” is a bigger security risk than your front door

By Thomas Neuburger
“The love of money is a sickness with these people.” —Attributed to an American chief as he watched Europeans move west
“We live among predators and praise their work.” —Yours truly
In today’s Security Watch, another good find by Twitter source Hedgie. Several elements of this story are worth your attention. First, the report:
A researcher pulled a live camera feed, a home floor plan, and the Wi-Fi password in plain text from a Shark robot vacuum he didn't own. One security certificate unlocked every other Shark vacuum. He listened to Shark's system for 24 hours, counted 1.5 million vacuums checking in, and 673,000 responded to a command he sent. He told Shark in March. They promised a fix by July 10. No patch, no response, so he published.
All this is verified. From a white paper issued by the Internet-of-Things (IoT) company Amotus:
1.5 Million Devices, One Certificate In July 2026, a security researcher disclosed that a single client certificate pulled from a Shark robot vacuum could be used to issue root-level commands to any other Shark vacuum in the same AWS region. A 24-hour scan of one AWS region found 1.5 million unique Shark devices; roughly 673,000 responded in a way that confirmed they were exploitable, exposing camera feeds, stored floor plans, drive control, and plaintext Wi-Fi credentials. SharkNinja was notified in March 2026 and shipped a fix on July 20, roughly four months later, following three vague status updates. The underlying defect was not exotic: the device’s AWS IoT policy granted publish-and-subscribe access to any device’s topic instead of scoping access to the device holding the certificate. This is precisely the misconfiguration AWS’s own Device Defender fleet-auditing tool is built to flag as critical, the tooling existed; the provisioning discipline to use it didn’t.
Here’s a similar report from Hacker News:
Pull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people’s Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the house, and take the Wi-Fi password in plaintext. A researcher publishing under the handle tokay0 put the method online on Monday [July 13, 2026], having tested it only against vacuums he bought himself. The flaw was unpatched then.He says SharkNinja, the company behind the Shark and Ninja appliance brands, has had his report since March.
The researcher proved that using information from the label of one Shark vacuum, anyone could hack into all other vacuums of that type in the same AWS (Amazon Web Service) region and download all the data those devices collected.
What This Story Teaches Us
There are valuable lessons from this — hard truths for hard times:
The smart phone world, where every device you own is connected to companies you can’t trust, is inherently dangerous. Not accidentally. Inherently.
Shark never addressed the collection and sending of data; just its vulnerability to hacks. That tells you a lot.
None of these companies will care about your security until a problem is publicly known. Not “until there’s a problem,” which is bad enough. The problem has to be publicly known before they will act. That also tells you a lot.
And because every large corporation is part of the security state, this will only get worse.
We’re already pre-revolutionary, both here and abroad. Do you think the elites will stand down? They haven’t yet.
Now Hedgie’s take on this story:
Your vacuum cleaner is now a bigger security risk than your front door. Someone with basic hardware skills can pull your Wi-Fi password, watch your camera, and download the layout of your home, and the company that sold it to you knew for four months and couldn't be bothered to fix it. Every week there's a new device on the list. LG monitors, Flock cameras, smart TVs, now vacuums. I'm running out of appliances. The reason none of this gets fixed is because there's no consequence. A car manufacturer would face a mandatory recall. Shark faces a Reddit thread. Until connected devices are held to the same product safety standards as everything else people bring into their homes, companies will keep shipping cameras and microphones with barely any investment in security.






Comments