Here is Yarbo’s promise to fix the robot mower that ran me over

Yarbo, a robot lawn mower manufacturer, has acknowledged critical security vulnerabilities that exposed customer GPS coordinates, Wi-Fi passwords, and email addresses to unauthorized access, committing to deploy security updates within one week and implement device-level credentials to prevent fleet-wide compromise. However, the company is retaining a persistent remote backdoor (albeit with enhanced controls) rather than eliminating it entirely, raising ongoing questions about customer choice and security architecture that IT leaders should monitor. This incident underscores the urgent need for organizations to establish robust IoT device security policies, vendor security assessment frameworks, and supply chain risk management practices before deploying connected hardware at scale.

Sean HollisterThe Verge2 min read
Read full article
Here is Yarbo’s promise to fix the robot mower that ran me over
Yesterday, I told you how a hacker ran me over with a robot lawn mower. We explained how thousands of these bladed Chinese robots, made by Yarbo, could be hijacked with ease - exposing people's GPS coordinates, Wi-Fi passwords, email addresses, and more to any casual hacker who comes along. Today, Yarbo has issued a thorough 1,200-word response that you can read in full below. The company is confirming the security researcher's findings, apologizing, and providing a detailed plan to tackle many of its self-created security issues head-on. Yarbo writes that it's already temporarily cut off remote access and is addressing many of its most he … Read the full story at The Verge.