The Cybersecurity Course · Episode 13
Read time ~8 min · No prior knowledge

Smart homes
& IoT

The camera, the bulbs, the robot vacuum, the NAS — every connected gadget is a small computer without a screen, without antivirus, and often without anyone remembering its password. Here's the threat picture category by category, the action list that takes one evening, and the guest-network trick that makes a hijacked gadget irrelevant.

Contents
  1. Mirai — when the gadgets went to war
  2. The threat picture, gadget by gadget
  3. The action list — and guest networks with AP isolation
  4. Buying right: update promises and the EU's new rules
  5. Sources

Mirai — when the gadgets went to war

In 2016, large parts of the US internet were knocked out by Mirai — a botnet built from hundreds of thousands of hijacked cameras and routers, recruited with a simple list of factory passwords. The technique is anything but history: Cloudflare reported in January 2025 that it had fended off a record attack of 5.6 terabits per second — generated by a Mirai variant running on roughly 13,000 hijacked IoT devices.

The episode 1 lesson in gadget form: nobody cares what your smart bulb does — but its connection, around the clock and unwatched, is exactly the raw material botnets are built from. Search engines like Shodan index openly exposed devices worldwide; your gadgets have already been found.

The threat picture, gadget by gadget

Security cameras & video doorbells

The worst category: pointed into your home, often no-name brands with cloud accounts, default passwords and dead update schedules. Hijacked camera feeds are sold and published openly.

Risk: privacy + botnet

NAS — the home server

Full of your files and reachable around the clock — ransomware gangs run targeted campaigns against NAS devices specifically. Update immediately (vendor security bulletins), never expose the admin interface to the internet, and back up per episode 9.

Risk: your files

Bulbs, plugs, appliances

Little data, big volume — classic botnet fodder. Harmless to you only once they can't reach your real devices (see the guest network below).

Risk: botnet

Voice assistants

Technically well maintained (Amazon/Google/Apple update them), but a microphone in your home is a privacy decision. Review recording history and deletion settings.

Risk: privacy

Robot vacuums

Map your home, increasingly carry cameras, and route data via the manufacturer's cloud — incidents of leaked images have already happened. Mozilla's Privacy Not Included reviews the category.

Risk: privacy

The action list — and guest networks with AP isolation

  1. Change every default password — gadget by gadget, into the password manager. The Mirai list still works today for a reason.
  2. Update firmware and enable automation where available (episode 5). A gadget without updates = a gadget on its way out.
  3. Move all gadgets to the guest network (episode 10) — and enable AP isolation ("client isolation") if the router supports it: the gadgets then can't even see each other, and a hijacked device stands completely alone in its cell.
  4. Switch off what you don't use: cloud access, microphones, remote control from outside. Every disabled feature is a closed door — and UPnP on the router has been off since episode 10.
  5. Take inventory quarterly: the router's device list (episode 10). Gadgets you forgot you own are gadgets nobody updates.

Buying right: update promises and the EU's new rules

The cheapest camera on the marketplace is cheap for a reason: nobody is paying for security work and updates after the sale. Buying rules:

Legal help is also on the way: the EU's Cyber Resilience Act imposes security requirements on connected products — no default passwords, mandatory security updates over the product's lifetime, vulnerability handling — fully applicable in 2027. In line with the principles of CISA's Secure by Design: security should be built in, not left to the buyer.

Next time Your files live less and less at home and more and more in the cloud. Episode 14: who can actually read them (the CLOUD Act and jurisdiction), the sharing settings that leak, and the GDPR basics for small business owners.

Sources

Want to dig deeper? These are the sources behind this episode.

  1. Cloudflare — DDoS threat report 2024 Q4 — the record 5.6 Tbps attack from ~13,000 IoT devices.
  2. Wikipedia — Mirai — the botnet that defined the IoT threat.
  3. Shodan — shodan.io — the search engine for exposed devices.
  4. Mozilla — Privacy Not Included — privacy reviews of connected products.
  5. European Commission — Cyber Resilience Act — the security requirements for connected products.
  6. CISA — Secure by Design — the principles behind built-in security.
  7. Synology — Security advisories — an example of NAS vendor security work.
  8. ENISA — enisa.europa.eu — the EU cybersecurity agency on IoT threats.
  9. Internetstiftelsen — internetstiftelsen.se — smart home guides.
  10. CERT-SE — cert.se — alerts when IoT vulnerabilities are exploited.
Next episode

Episode 14 — Cloud services & data privacy

The CLOUD Act, sharing settings that leak — and the GDPR basics for small business owners.