Skip to main content
  1. Home
  2. Computing
  3. News

Analysis of internet-connected devices reveals millions are vulnerable to attack

Add as a preferred source on Google

For anyone involved in information security and combating the incredible breadth and depth of malware that’s constantly aimed at stealing our most important information, it’s not enough to simply know whether a given machine is compromised. Just as important is knowing which machines are vulnerable to attack.

That’s precisely the objective of projects that scan the internet looking for unsecured systems. One such initiative is Shodan, a search engine that scans online systems and “cyber assets” looking for any with security flaws that could open them up for attack. Security company Trend Micro conducted its own analysis of Shodan data for February 2016 and summarized the findings on its Security and Intelligence blog, noting that literally millions of internet-connected devices are vulnerable, including many in the most sensitive industries.

Recommended Videos

Shodan is particularly helpful because it reports on not just the IP address of connected devices, but also offers information on application software installed on devices and their firmware version numbers. That information can help companies like Trend Micro identify the kinds of devices that are connected. Of course, if Shodan can discover this kind of information, then malicious parties can do so as well using various tools and techniques of their own.

Trend micro identified a number of important trends, which it outlined in the blog post. Here are the highlights:

  • Los Angeles had the highest number of exposed cyber assets when compared to other top 10 most populated cities in the U.S. The city had more than 4 million devices that could be targeted for cyberattack. Houston was second at 3.9 million exposed cyber assets.
  • Unsurprisingly, web servers are particularly problematic, in that they’re some of the most commonly attacked machines, and they’re also often unsecured. Web servers, therefore, represent a known quantity of exposed cyber assets that could be secured against attack.
  • Web servers hosted by the U.S. government, along with education, health care, and public utilities sectors in the U.S., were particularly open for attack. Servers in the emergency services and financial sectors, however, had relatively few unsecured machines.
  • Nevertheless, most of the unsecured devices in the Shodan data were those often used for distributed denial-of-service (DDoS) attacks, and included firewalls, webcams, routers, and wireless access points. That correlates with a DDoS attack on October 21, 2016, that involved Mirai malware running on unsecured devices like webcams.

The most important conclusion to draw from Trend Micro’s analysis of the Shodan data is that there’s lots of work to be done in securing the millions of vulnerable internet-connected devices. The company will be presenting its analysis and conclusions at the RSA conference that’s currently underway, and you can dig into the details yourself in its report titled “U.S. Cities Exposed in Shodan.”

Mark Coppock
Former Computing Writer
Mark Coppock is a Freelance Writer at Digital Trends covering primarily laptop and other computing technologies. He has…
What happens when AI detectors fail? Researchers say we must be trained to spot fake AI faces
Researchers say spotting AI faces may soon depend more on people than software
Zuckerberg Deepfake

Artificial intelligence has become remarkably good at creating fake human faces. So good, in fact, that the old tricks people relied on - counting fingers, spotting warped earrings, or looking for distorted backgrounds - are quickly becoming obsolete. According to a new study highlighted by the BBC, the next line of defence may not be a better AI detector at all. It might simply be a better-trained human.

Researchers from the University of Aberdeen, working alongside Australia's National University, found that people can dramatically improve their ability to distinguish AI-generated faces from real ones after a relatively short period of structured training. Instead of hunting for obvious visual glitches, participants were taught to recognise subtle patterns that modern image generators still struggle to replicate consistently.

Read more
Google’s new Magic Pointer Play Store listing reveals a Gemini shortcut built for Googlebooks
The unannounced app turns the cursor into a contextual AI tool for search, image creation, and shopping
Plant, Text, Business Card

Google has quietly published a new Play Store listing for Magic Pointer, an unannounced app built for Googlebooks. Updated on July 10, the app turns the cursor into a Gemini shortcut that can act on whatever a user selects on screen.

Magic Pointer can send an image to Lens, generate a related image, or surface a shopping action without forcing users to open a separate chatbot. Regular Android devices currently show as incompatible, so the listing offers an early preview rather than a broad release.

Read more
You can stop using AI, but this new report says you probably can’t escape it
A UK survey found that most people feel AI exposure is unavoidable, raising harder questions about consent, privacy, and whether opting out is still realistic
AI Chatbots

More people are trying to use less AI, but avoiding it altogether may already be impossible.

A survey of 2,055 UK adults found that 42% deliberately limit how much AI they use. Another 70% said avoiding AI exposure would be difficult or impossible, even when they actively wanted less of it.

Read more