Theverge Yarbo's Robot Mowers Compromised: Security Flaws Exposed
Article Content
- •Yarbo's robot mowers were compromised, allowing remote control and data exposure.
- •Hardcoded root passwords provided hackers with full access to the devices.
- •Yarbo plans to implement unique credentials but will retain a controversial remote access backdoor.
Yarbo's autonomous lawn mowers have been compromised due to severe security vulnerabilities, allowing hackers to remotely control the devices. Security researcher Andreas Makris demonstrated the flaws by hijacking a mower from 6,000 miles away, exposing sensitive user data including GPS coordinates and Wi-Fi credentials. The robots were shipped with hardcoded root passwords, granting full administrative access to malicious actors. Yarbo has acknowledged these issues and is implementing a security update to replace the universal passwords with unique credentials for each device. However, the company plans to retain a remote access backdoor for internal use, raising concerns among privacy advocates. The incident highlights the risks associated with deploying autonomous technology without adequate security measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track Yarbo in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…