Smart homes
& IoT
The camera, the bulbs, the robot vacuum, the NAS — every connected gadget is a small computer without a screen, without antivirus, and often without anyone remembering its password. Here's the threat picture category by category, the action list that takes one evening, and the guest-network trick that makes a hijacked gadget irrelevant.
Mirai — when the gadgets went to war
In 2016, large parts of the US internet were knocked out by Mirai — a botnet built from hundreds of thousands of hijacked cameras and routers, recruited with a simple list of factory passwords. The technique is anything but history: Cloudflare reported in January 2025 that it had fended off a record attack of 5.6 terabits per second — generated by a Mirai variant running on roughly 13,000 hijacked IoT devices.
The episode 1 lesson in gadget form: nobody cares what your smart bulb does — but its connection, around the clock and unwatched, is exactly the raw material botnets are built from. Search engines like Shodan index openly exposed devices worldwide; your gadgets have already been found.
The threat picture, gadget by gadget
Security cameras & video doorbells
The worst category: pointed into your home, often no-name brands with cloud accounts, default passwords and dead update schedules. Hijacked camera feeds are sold and published openly.
Risk: privacy + botnetNAS — the home server
Full of your files and reachable around the clock — ransomware gangs run targeted campaigns against NAS devices specifically. Update immediately (vendor security bulletins), never expose the admin interface to the internet, and back up per episode 9.
Risk: your filesBulbs, plugs, appliances
Little data, big volume — classic botnet fodder. Harmless to you only once they can't reach your real devices (see the guest network below).
Risk: botnetVoice assistants
Technically well maintained (Amazon/Google/Apple update them), but a microphone in your home is a privacy decision. Review recording history and deletion settings.
Risk: privacyRobot vacuums
Map your home, increasingly carry cameras, and route data via the manufacturer's cloud — incidents of leaked images have already happened. Mozilla's Privacy Not Included reviews the category.
Risk: privacyThe action list — and guest networks with AP isolation
- Change every default password — gadget by gadget, into the password manager. The Mirai list still works today for a reason.
- Update firmware and enable automation where available (episode 5). A gadget without updates = a gadget on its way out.
- Move all gadgets to the guest network (episode 10) — and enable AP isolation ("client isolation") if the router supports it: the gadgets then can't even see each other, and a hijacked device stands completely alone in its cell.
- Switch off what you don't use: cloud access, microphones, remote control from outside. Every disabled feature is a closed door — and UPnP on the router has been off since episode 10.
- Take inventory quarterly: the router's device list (episode 10). Gadgets you forgot you own are gadgets nobody updates.
Buying right: update promises and the EU's new rules
The cheapest camera on the marketplace is cheap for a reason: nobody is paying for security work and updates after the sale. Buying rules:
- An established brand with an update track record beats an unknown brand with more features.
- Look for an explicit update promise — for how long does the product receive security fixes?
- Does the gadget work locally without the cloud? Locally controlled devices (e.g. via Home Assistant/Matter) survive even the manufacturer's shuttered servers.
- Check the privacy rating in Mozilla's Privacy Not Included before buying anything with a camera or microphone.
Legal help is also on the way: the EU's Cyber Resilience Act imposes security requirements on connected products — no default passwords, mandatory security updates over the product's lifetime, vulnerability handling — fully applicable in 2027. In line with the principles of CISA's Secure by Design: security should be built in, not left to the buyer.
Sources
Want to dig deeper? These are the sources behind this episode.
- Cloudflare — DDoS threat report 2024 Q4 — the record 5.6 Tbps attack from ~13,000 IoT devices.
- Wikipedia — Mirai — the botnet that defined the IoT threat.
- Shodan — shodan.io — the search engine for exposed devices.
- Mozilla — Privacy Not Included — privacy reviews of connected products.
- European Commission — Cyber Resilience Act — the security requirements for connected products.
- CISA — Secure by Design — the principles behind built-in security.
- Synology — Security advisories — an example of NAS vendor security work.
- ENISA — enisa.europa.eu — the EU cybersecurity agency on IoT threats.
- Internetstiftelsen — internetstiftelsen.se — smart home guides.
- CERT-SE — cert.se — alerts when IoT vulnerabilities are exploited.
Episode 14 — Cloud services & data privacy
The CLOUD Act, sharing settings that leak — and the GDPR basics for small business owners.