:

MILLION BABY MONITORS EXPOSED TO HACKERS

SECURITY DESK2 MIN READ
MON, MAY 11, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A vulnerability in Meari-brand baby monitors and security cameras left approximately one million devices accessible to unauthorized viewers worldwide. The flaw allowed hackers to watch live feeds from homes without authentication.

Security researchers discovered that Meari devices—popular baby monitors and home security cameras—contained a critical vulnerability that exposed private video streams to anyone with basic technical knowledge. The exposure meant that intimate moments in family homes, including bedrooms and nurseries, were potentially viewable by malicious actors. Researchers found live feeds showing children, bedrooms, and personal spaces that should have been protected by password authentication. What Happened The vulnerability stemmed from inadequate security controls in Meari's cloud infrastructure. Devices lacked proper authentication mechanisms, allowing unauthorized access to video feeds without requiring login credentials. This left millions of households vulnerable to privacy breaches. Impact Affected users included families relying on these devices for child safety monitoring. The exposure represents a serious privacy violation, as home security footage can reveal daily routines, physical layouts, and personal information about residents. Response Meari acknowledged the issue and released security patches to address the vulnerability. The company advised users to update their devices immediately and reset passwords. However, the incident highlights broader security concerns in the smart home device market, where manufacturers sometimes prioritize convenience over protection. Lessons This breach underscores the importance of choosing connected devices from vendors with strong security track records. Users should regularly update firmware, use strong passwords, and verify that devices employ encryption and proper authentication protocols. Security researchers continue investigating the full scope of the exposure and whether bad actors exploited the vulnerability before it was patched. The incident serves as a reminder that devices with access to private spaces require the highest security standards.

■ SOURCES

The Verge

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Security firm Huntress analyzed a real-world intrusion to reveal how threat actors operate once inside a network. The findings show attackers focus on persistence and defense evasion rather than stopping after initial access.

2H AGOIndustry Desk

TP-Link routers face scrutiny tied to FCC regulatory issues rather than product performance. Here's what users need to know about the controversy.

3H AGOIndustry Desk

South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) for data protection violations.

3H AGOSecurity Desk

JetBrains has disclosed a critical authentication bypass vulnerability in TeamCity On-Premises that allows attackers to execute remote code. The flaw affects the company's continuous integration and deployment platform.

3H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.