Skip to main content

Internet-connected Mr. Coffee machines have security vulnerability, McAfee says

Mr. Coffee Smart Coffeemaker
Image used with permission by copyright holder

It may sound scary, but while you’re making yourself a cup of coffee, a hacker just may be brewing up an attack. According to security firm McAfee, an internet-connected coffee maker produced by Mr. Coffee and Wemo suffers from a security vulnerability that could let a malcious actor intercept traffic from the device and even schedule the machine to make coffee without the owner’s permission.

The affected device is the Mr. Coffee Coffee Maker with Wemo, first introduced back in 2014. The issue stems from the connectivity provided by Wemo. According to McAfee, Wemo devices communicate with a connected Wemo smartphone app, and can transfer date in two ways: Remotely via the internet or locally, bysending the information directly to the Wemo application. The vulnerabilty occurs when the communication is taking place locally.

Recommended Videos

McAfee researchers discovered it is possible to intercept transmissions made between the Mr. Coffee Coffee Maker with Wemo and the connected Wemo app. This can occur because the data is transferred in plaintext with no additional encryption or protection to prevent the information from being viewed by a malicious third party. By viewing that information, an attacker can see different data that is bouncing between the device and the Wemo app, including the brew schedule — times that the device owner has set up the machine to automatically brew a new pot of coffee.

With access to the communication between the coffee maker and app, a hacker could theoretically start inserting their own commands and pushing them to the device. That means an attacker could schedule the coffee maker to turn on without the permission or knowledge of the owner. McAfee pointed out that there is no validation on the source of a scheduled brew, so there is nothing to prevent the action from going forward even though it’s from an illegitimate source.

“Cybercriminals are relentless, and as long as we continue to connect devices to the internet, they will continue to search for ways to exploit them,” Raj Samani, McAfee fellow and chief scientist, said in a statement. “Vulnerability disclosures can be frightening for both the consumers using connected devices and the organizations that create them, however, the process is an essential component of creating a safer future. Cybersecurity researchers, businesses, and consumers working together to expose and eliminate these vulnerabilities keeps us all a step ahead of the bad guys.”

It’s worth noting that these types of attacks would have to be targeted efforts. A hacker would have to be connected to the same network that the vulnerable coffee maker is on. It also requires the coffee maker to be communicating locally rather than remotely, when remote access is the default setting for the machine. When conacted, Wemo parent company Belkin told Digital Trends it issued an advisory for the issue in August and offered a firmware update to address the issue on January 8, 2019.

AJ Dellinger
AJ Dellinger is a freelance reporter from Madison, Wisconsin with an affinity for all things tech. He has been published by…
Everything on Amazon’s new ‘Haul’ store costs less than $20
Amazon's new Haul shopping site.

Amazon has just launched a new store full of stuff costing no more than $20. It’s the tech behemoth’s way of taking on the likes of Chinese retailers Temu and Shein, whose own bargains are becoming increasingly popular with online shoppers in the U.S.

Currently in beta, Amazon’s new store, called Haul, is a mobile-only offering and will appear as a new tab on the company’s shopping app after the next time you update it. Alternatively, visit www.amazon.com/haul on your phone’s web browser.

Read more
AMD Ryzen AI claimed to offer ‘up to 75% faster gaming’ than Intel
A render of the new Ryzen AI 300 chip on a gradient background.

AMD has just unveiled some internal benchmarks of its Ryzen AI 9 HX 370 processor. Although it's been a few months since the release of the Ryzen AI 300 series, AMD now compares its CPU to Intel's Lunar Lake, and the benchmarks are highly favorable for AMD's best processor for thin-and-light laptops. Let's check them out.

For starters, AMD compared the Ryzen AI 9 HX 370 to the Intel Core Ultra 7 258V. The AMD CPU comes with 12 cores (four Zen 5 and eight Zen 5c cores) and 24 threads, as well as 36MB of combined cache. The maximum clock speed tops out at 5.1GHz, and the CPU offers a configurable thermal design power (TDP) ranging from 15 watts to 54W. Meanwhile, the Intel chip sports eight cores (four performance cores and four efficiency cores), eight threads, a max frequency of 4.8GHz, 12MB of cache, and a TDP ranging from 17W to 37W. Both come with a neural processing unit (NPU), and AMD scores a win here too, as its NPU provides 50 trillion operations per second (TOPS), while Intel's sits at 47 TOPS. It's a small difference, though.

Read more
Microsoft brought back this feature to the new version of Outlook
A tablet and a phone showing the calendar feature in the Outlook app.

 

Microsoft soft-launched a redesigned version of its Outlook app this year, and it hasn't received the best reception. Not only will the new version of Outlook replace the old one, but it'll also replace the default Windows Mail & Calendar app.

Read more