Internet-facing webcams pose security risk to organizations

Share post:

According to a recent BitSight report, internet-facing webcams pose a significant security risk to businesses. These webcams, which are commonly used for surveillance and video conferencing, are accessible from outside the network and can be easily hacked by cybercriminals.

In contrast to best practices, nearly 3% of BitSight-tracked organizations have at least one Internet-facing video- and/or audio-enabled device, according to BitSight’s analysis. In this group, 9% of the devices had exposed video and/or audio feeds, allowing an attacker to directly view video feeds and/or eavesdrop on conversations. As a result, one out of every twelve BitSight-tracked organizations with Internet-facing webcams and/or similar devices is vulnerable to video and/or audio compromise.

The report focuses on the vulnerabilities associated with internet-facing webcams, such as weak passwords, out-of-date firmware, and unsecured network connections. Hackers can use these flaws to gain unauthorized access to the cameras, allowing them to spy on the organization, steal sensitive data, or launch a cyberattack.

According to BitSight’s analysis, many organizations use Internet-facing video and/or audio-enabled devices, with a subset of those organizations using devices with exposed video and/or audio feeds (exposed devices). Exposed organizations are those who have at least one exposed device.

The risks of internet-facing webcams are especially concerning for organizations that handle sensitive data, such as government agencies, financial institutions, and healthcare providers. This is because an attacker could potentially view private activities and eavesdrop on sensitive conversations, as well as reveal individuals’ locations.

Furthermore, an attacker could potentially observe business-related activities and listen in on professional conversations, potentially exposing sensitive business information of the target and/or third parties. While the physical security and cybersecurity infrastructure of such an organization may also be jeopardized.

The sources for this piece include an article in TechRepublic.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Google Chrome update essential for Windows users

The latest Chrome update has just been rolled out, bringing the version up to 124.0.6367.78/.79. This update is...

Cyber Security Today, Week in Review for week ending Friday, April 26, 2024

This episode features a discussion on the latest in the Change Healthcare ransomware attack, a vulnerability in an abandoned Apache open source project, the next step in Canada's proposed critical infrastructure cybersecurity law and the future

Cyber Security Today, April 26, 2024 – Patch warnings for Cisco ASA gateways and a WordPress plugin

This episode reports on the malicious plugin worm that refuses to die

Cyber Security Today, April 24, 2024 – Good news/bad news in Mandiant report, UnitedHealth admits paying a ransomware gang, and more

This episode reports on the danger of using expired open-source packages, a tool used by a Russian hacking group and passw

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways