MQTT is a lightweight, publish-subscribe messaging protocol designed for low-bandwidth, resource-constrained IoT devices.
Overview
MQTT is a lightweight, publish-subscribe messaging protocol designed for low-bandwidth, resource-constrained IoT devices. It relies on a broker-based architecture and is widely used in embedded and IoT deployments; cybersecurity considerations include weak authentication, misconfigurations, and potential use in botnets or device compromise if brokers and clients are not properly secured.
Related Threat Clusters
-
New Android Malware Targets Car Head Units for Ad Fraud and Botnet Creation
A new Android malware has been discovered targeting automotive head units, specifically those using firmware from the Chinese company DoFun. This malware exploits a legitimate system application, TWCore, to deliver a…
20 articles · Updated August 21, 2026 -
Cyber Threats Target Solar Infrastructure Beyond Inverters
In late December 2025, a cyber attack impacted 30 solar plants in Poland, primarily targeting substation equipment with wiper malware, while inverters remained unaffected. The attack highlighted vulnerabilities in the…
2 articles · Updated June 4, 2026 -
Iran's Cyber Response to U.S. Military Strikes Expected Amid Rising Tensions
Following U.S. military strikes on Iran, there is an anticipated increase in cyber warfare activities targeting U.S. operational technology and critical infrastructure. Iran is expected to retaliate with cyber attacks…
768 articles · Updated February 28, 2026 -
Russian Hackers Target Ukrainian Military with Charity-Themed Malware Campaign
Between October and December 2025, Ukrainian Defense Forces were targeted by a cyberattack disguised as a charitable foundation. The attack, attributed to the Russian group Void Blizzard (Laundry Bear), installed…
3 articles · Updated January 14, 2026
Recent Intelligence Reports
- Hackers infect Android car head units with proxy botnet malware — Bleepingcomputer · August 22, 2026
- Android Car Head-Unit Malware Linked to BadBox Uses Firmware Updates — Technadu · August 21, 2026
- Iranian Hackers Infiltrate Siemens and Schneider PLCs, Blinding Operators With Fake Readings — Techtimes · July 23, 2026
- Solar Cyber Threats Expand But Inverters Still Stay In The Crosshairs — www.pv-magazine.com · June 4, 2026
- Russian hackers posed as charities to install malware on Ukrainian military devices - Межа — Mezha.Ua · January 14, 2026