<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[(nattothoughts.com) Insecure-by-Design: How Meari Technology&#x27;s IoT Infrastructure Exposes Global Surveillance Risks and AI Training Ambitions]]></title><description><![CDATA[<p>(nattothoughts.com) Insecure-by-Design: How Meari Technology's IoT Infrastructure Exposes Global Surveillance Risks and AI Training Ambitions</p><p>Meari Technology’s IoT infrastructure exposes over 1M devices (baby monitors, security cameras) across 118 countries due to systemic architectural flaws enabling unauthorized vendor/third-party access to live/stored feeds. No security boundary exists between backend and user devices.</p><p>In brief - A Chinese ODM’s insecure-by-design IoT platform risks global surveillance exposure, with delayed remediation and potential AI training data exploitation. Disclosure process revealed hostile vendor response and partial fixes.</p><p>Technically - Flaws include unauthenticated MQTT brokers, hardcoded credentials, misconfigured P2P relays, and unsecured alert image storage. Researcher documented 12 evidence points confirming vendor access. RunZero disclosed 5 high-risk CVEs post-contentious 2-month CVD process. Systemic design choices, not bugs, enable persistent access.</p><p>Source: <a href="https://www.nattothoughts.com/p/is-this-chinese-company-watching" rel="nofollow noopener"><span>https://www.</span><span>nattothoughts.com/p/is-this-ch</span><span>inese-company-watching</span></a></p><p><a href="https://swecyb.com/tags/Cybersecurity" rel="tag">#<span>Cybersecurity</span></a> <a href="https://swecyb.com/tags/ThreatIntel" rel="tag">#<span>ThreatIntel</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/f74514c3-22d1-4669-b8bc-4fce2743b2c7/nattothoughts.com-insecure-by-design-how-meari-technology-s-iot-infrastructure-exposes-global-surveillance-risks-and-ai-training-ambitions</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 11:25:45 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/f74514c3-22d1-4669-b8bc-4fce2743b2c7.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 20 May 2026 15:36:47 GMT</pubDate><ttl>60</ttl></channel></rss>