BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: 1.1 Million Cameras\, One Wildcard: Architectural Su
 rveillance\n   in an IoT Cloud\n   Tags: DEF CON Official Talk | Demo ðŸ’»
  | Tool ðŸ›  | Exploit ðŸª²\n   When: Sunday\, Aug 9\, 12:00 - 12:59 PDT\n
    Where: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - [1]Map\n\n 
   Description:\n\n   In March 2026\, while reverse-engineering the cloud p
 latform behind a\n   popular line of consumer baby monitors and home secur
 ity cameras\, I\n   discovered that one MQTT SUBSCRIBE wildcard returned t
 he live message\n   stream from every device on the platform. 1.1 million 
 cameras. Motion\n   alerts with image URLs. Floor plans. P2P credentials. 
 Audio events.\n   From baby monitors\, doorbells\, indoor cameras.\n\n   T
 hat was one of twelve.\n\n   This talk presents a complete vendor surveill
 ance audit of Meari\n   Technology â€” a Hangzhou-based ODM whose firmware
  ships under 300+\n   white-label brands across 118 countries. Not a singl
 e bug. Twelve\n   independent evidence chains\, each one separately demons
 trating that\n   the vendor possesses by-design\, architectural access to 
 every camera\n   they sell. EMQX brokers with admin/public on four regions
 . An Apollo\n   configuration server returning 600+ production secrets wit
 hout\n   authentication. A CMS portal with 25+ live-camera endpoints acces
 sible\n   to 678 employees through DingTalk SSO. A universal TUTK authcode
 \n   shared across every device. Cloud video IDOR. Plain-JPEG alerts on\n 
   shared OSS buckets with no per-customer isolation.\n\n   Then I'll walk 
 through what happened after disclosure: the vendor's\n   IPO twelve days a
 fter first contact\, the backdated security\n   advisories\, the three reg
 ional brokers fixed five days apart (incident\n\n     * Disclosure reposit
 ory (public May 11\, 2026):\n       github.com/xn0tsa/meari-cloudedge-secu
 rity-audit\n\n     * CVE-2026-33356 â€” MQTT Broker Missing Per-Device Sub
 scribe ACL\n\n     * CVE-2026-33357 â€” OpenAPI Device Status IDOR (WAN IP
  Disclosure)\n\n     * CVE-2026-33358 â€” Cloud Video IDOR (No Ownership C
 heck)\n\n     * CVE-2026-33359 â€” Alert Images Unauthenticated\n\n     * 
 CVE-2026-33360 â€” API Signature Validation Disabled (CN\n       Productio
 n)\n\n     * CVE-2026-33361 â€” Weak XOR Encryption on Baby Monitor Images
 \n\n     * CVE-2026-33362 â€” Hardcoded Static Cryptographic Keys in Clien
 t\n       SDK\n\n     * CVE coordination: Tod Beardsley\, runZero\, Inc.\n
 \n     * CISA coordinated advisory (publication pending)\n\n     * Speaker
 's prior work: DJI ROMO MQTT ACL bypass disclosure\n       (February 2026)
 \, as covered by The Verge\, Cybernews\, Popular\n       Science\, TheGuar
 dian\, The Wired...\n\n     * Meari Technology official security advisorie
 s:\n       meari.com/en/securityCenter\n\n     * EMQX broker: emqx.io\n\n 
     * Apollo Configuration Management: github.com/apolloconfig/apollo\n\n 
     * XXL-Job scheduler: github.com/xuxueli/xxl-job\n\n     * GDPR Article
 s 33 and 34: eur-lex.europa.eu\n\n     * EU Whistleblower Directive 2019/1
 937: eur-lex.europa.eu\n\n   SpeakerBio:  Sammy Azdoufal\n\n   Sammy Azdou
 fal is an independent security researcher and software\n   engineer based 
 in Barcelona. His work focuses on the cloud and mobile\n   attack surface 
 of consumer IoT\, with an emphasis on Chinese ODM/OEM\n   ecosystems suppl
 ying the smart-home market in Europe and North\n   America.\n\n   In Febru
 ary 2026\, he disclosed a critical MQTT ACL bypass affecting\n   roughly 7
 \,000 DJI ROMO robot vacuums across 24 countries\, granting\n   live camer
 a and microphone access. The disclosure was covered by The\n   Verge\, Cyb
 ernews\, Popular Science\, The Guardian...\, and led to a\n   $30\,000 bug
  bounty award from DJI. He is known for using AI coding\n   assistants â€”
  specifically Anthropic's Claude Code â€” as part of his\n   reverse-engin
 eering workflow\, and for combining hands-on protocol\n   analysis with di
 sciplined responsible-disclosure practice.\n\n   The Meari Technology audi
 t presented in this talk was conducted\n   between February and April 2026
 \, with CVE coordination performed by\n   Tod Beardsley (runZero\, Inc.) a
 nd disclosure coordinated with CISA. It\n   is his largest single-vendor I
 oT audit to date.\n\n   Public handle: xn0tsa (GitHub). This will be Sammy
 's first DEF CON\n   Main Stage presentation.\n\n   '\n\n   1. #LVCCW_Leve
 l1_Hall3\n\n\n
DTEND:20260809T195900Z
DTSTART:20260809T190000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5
SUMMARY:1.1 Million Cameras\, One Wildcard: Architectural Surveillance in a
 n IoT Cloud
END:VEVENT
END:VCALENDAR
