Sammy Azdoufal claims he wasn’t trying to hack every robot vacuum in the world. He just wanted to remote control his brand-new DJI Romo vacuum with a PS5 gamepad, he tells The Verge, because it sounded fun.
Technology
The DJI Romo robovac had security so poor, this man remotely accessed thousands of them
But when his homegrown remote control app started talking to DJI’s servers, it wasn’t just one vacuum cleaner that replied. Roughly 7,000 of them, all around the world, began treating Azdoufal like their boss.
He could remotely control them, and look and listen through their live camera feeds, he tells me, saying he tested that out with a friend. He could watch them map out each room of a house, generating a complete 2D floor plan. He could use any robot’s IP address to find its rough location.
“I found my device was just one in an ocean of devices,” he says.
On Tuesday, when he showed me his level of access in a live demo, I couldn’t believe my eyes. Ten, hundreds, thousands of robots reporting for duty, each phoning home MQTT data packets every three seconds to say: their serial number, which rooms they’re cleaning, what they’ve seen, how far they’ve traveled, when they’re returning to the charger, and the obstacles they encountered along the way.
I watched each of these robots slowly pop into existence on a map of the world. Nine minutes after we began, Azdoufal’s laptop had already cataloged 6,700 DJI devices across 24 different countries and collected over 100,000 of their messages. If you add the company’s DJI Power portable power stations, which also phone home to these same servers, Azdoufal had access to over 10,000 devices.

When I say I couldn’t believe my eyes at first, I mean that literally. Azdoufal leads AI strategy at a vacation rental home company; when he told me he reverse engineered DJI’s protocols using Claude Code, I had to wonder whether AI was hallucinating these robots. So I asked my colleague Thomas Ricker, who just finished reviewing the DJI Romo, to pass us its serial number.
With nothing more than that 14-digit number, Azdoufal could not only pull up our robot, he could correctly see it was cleaning the living room and had 80 percent battery life remaining. Within minutes, I watched the robot generate and transmit an accurate floor plan of my colleague’s house, with the correct shape and size of each room, just by typing some digits into a laptop located in a different country.


Separately, Azdoufal pulled up his own DJI Romo’s live video feed, completely bypassing its security PIN, then walked into his living room and waved to the camera while I watched. He also says he shared a limited read-only version of his app with Gonzague Dambricourt, CTO at an IT consulting firm in France; Dambricourt tells me the app let him remotely watch his own DJI Romo’s camera feed before he even paired it.
Azdoufal was able to enable all of this without hacking into DJI’s servers, he claims. “I didn’t infringe any rules, I didn’t bypass, I didn’t crack, brute force, whatever.” He says he simply extracted his own DJI Romo’s private token — the key that tells DJI’s servers that you should have access to your own data — and those servers gave him the data of thousands of other people as well. He shows me that he can access DJI’s pre-production server, as well as the live servers for the US, China, and the EU.

Here’s the good news: On Tuesday, Azdoufal was not able to take our DJI Romo on a joyride through my colleague’s house, see through its camera, or listen through its microphone. DJI had already restricted that form of access after both Azdoufal and I told the company about the vulnerabilities.
And by Wednesday morning, Azdoufal’s scanner no longer had access to any robots, not even his own. It appears that DJI has plugged the gaping hole.
But this incident raises serious questions about DJI’s security and data practices. It will no doubt be used to help retroactively justify fears that led to the Chinese dronemaker getting largely forced out of the US. If Azdoufal could find these robots without even looking for them, will it protect them against people with intent to do harm? If Claude Code can spit out an app that lets you see into someone’s house, what keeps a DJI employee from doing so? And should a robot vacuum cleaner have a microphone? “It’s so weird to have a microphone on a freaking vacuum,” says Azdoufal.
It doesn’t help that when Azdoufal and The Verge contacted DJI about the issue, the company claimed it had fixed the vulnerability when it was actually only partially resolved.
“DJI can confirm the issue was resolved last week and remediation was already underway prior to public disclosure,” reads part of the original statement provided by DJI spokesperson Daisy Kong. We received that statement on Tuesday morning at 12:28PM ET — about half an hour before Azdoufal showed me thousands of robots, including our review unit, reporting for duty.

To be clear, it’s not surprising that a robot vacuum cleaner with a smartphone app would phone home to the cloud. For better or for worse, users currently expect those apps to work outside of their own homes. Unless you’ve built a tunnel into your own home network, that means relaying the data through cloud servers first.
But people who put a camera into their home expect that data to be protected, both in transit and once it reaches the server. Security professionals should know that — but as soon as Azdoufal connected to DJI’s MQTT servers, everything was visible in cleartext. If DJI has merely cut off one particular way into those servers, that may not be enough to protect them if hackers find another way in.
Unfortunately, DJI is far from the only smart home company that’s let people down on security. Hackers took over Ecovacs robot vacuums to chase pets and yell racist slurs in 2024. In 2025, South Korean government agencies reported that Dreame’s X50 Ultra had a flaw that could let hackers view its camera feed in real time, and that another Ecovacs and a Narwal robovac could let hackers view and steal photos from the devices. (Korea’s own Samsung and LG vacuums received high marks, and a Roborock did fine.)
It’s not just vacuums, of course. I still won’t buy a Wyze camera, despite its new security ideas, because that company tried to sweep a remote access vulnerability under the rug instead of warning its customers. I would find it hard to trust Anker’s Eufy after it lied to us about its security, too. But Anker came clean, and sunlight is a good disinfectant.
DJI is not being exceptionally transparent about what happened here, but it did answer almost all our questions. In a new statement to The Verge via spokesperson Daisy Kong, the company now admits “a backend permission validation issue” that could have theoretically let hackers see live video from its vacuums, and it admits that it didn’t fully patch that issue until after we confirmed that issues were still present.
Here’s that whole statement:
DJI identified a vulnerability affecting DJI Home through internal review in late January and initiated remediation immediately. The issue was addressed through two updates, with an initial patch deployed on February 8 and a follow-up update completed on February 10. The fix was deployed automatically, and no user action is required.
The vulnerability involved a backend permission validation issue affecting MQTT-based communication between the device and the server. While this issue created a theoretical potential for unauthorized access to live video of ROMO device, our investigation confirms that actual occurrences were extremely rare. Nearly all identified activity was linked to independent security researchers testing their own devices for reporting purposes, with only a handful of potential exceptions.
The first patch addressed this vulnerability but had not been applied universally across all service nodes. The second patch re-enabled and restarted the remaining service nodes. This has now been fully resolved, and there is no evidence of broader impact. This was not a transmission encryption issue. ROMO device-to-server communication was not transmitted in cleartext and has always been encrypted using TLS. Data associated with ROMO devices, such as those in Europe, is stored on U.S.-based AWS cloud infrastructure.
DJI maintains strong standards for data privacy and security and has established processes for identifying and addressing potential vulnerabilities. The company has invested in industry-standard encryption and operates a longstanding bug bounty program. We have reviewed the findings and recommendations shared by the independent security researchers who contacted us through that program as part of our standard post-remediation process. DJI will continue to implement additional security enhancements as part of its ongoing efforts.
Azdoufal says that even now, DJI hasn’t fixed all the vulnerabilities he’s found. One of them is the ability to view your own DJI Romo video stream without needing its security pin. Another one is so bad I won’t describe it until DJI has more time to fix it. DJI did not immediately promise to do so.
And both Azdoufal and security researcher Kevin Finisterre tell me it’s not enough for the Romo to send encrypted data to a US server, if anyone inside that server can easily read it afterward. “A server being based in the US in no way, shape, or form prevents .cn DJI employees from access,” Finisterre tells me. That seems evident, as Azdoufal lives in Barcelona and was able to see devices in entirely different regions.
“Once you’re an authenticated client on the MQTT broker, if there are no proper topic-level access controls (ACLs), you can subscribe to wildcard topics (e.g., #) and see all messages from all devices in plaintext at the application layer,” says Azdoufal. “TLS does nothing to prevent this — it only protects the pipe, not what’s inside the pipe from other authorized participants.”
When I tell Azdoufal that some may judge him for not giving DJI much time to resolve the issues before going public, he notes that he didn’t hack anything, didn’t expose sensitive data, and isn’t a security professional. He says he was simply livetweeting everything that happened while trying to control his robot with a PS5 gamepad.
“Yes, I don’t follow the rules, but people stick to the bug bounty program for money. I fucking don’t care, I just want this fixed,” he says. “Following the rules to the end would probably make this breach happen for a way longer time, I think.”
He doesn’t believe that DJI truly discovered these issues by itself back in January, and he’s annoyed the company only ever responded to him robotically in DMs on X, instead of answering his emails.
But he is happy about one thing: He can indeed control his Romo with a PlayStation or Xbox gamepad.
Technology
This Windows gaming handheld has a screen that folds in half
Lenovo put a foldable display on a gaming handheld. The Legion Go Fold Concept is a Windows-based handheld with a flexible POLED display, detachable Joy-Con-like controllers, and a folio case to turn the whole thing into a mini laptop.
You can use it as a standard Steam Deck-esque handheld with the display folded down to 7.7 inches and controllers attached at its sides, or you can unfold it for a bigger experience. When unfolded, the controllers can be repositioned to all four sides, allowing you to play with the screen in vertical or horizontal orientations.
In vertical splitscreen mode, you can put your game on one half of the screen and a second window (like your chat or game guide) on the other half. Horizontal fullscreen mode gives your game the full 11.6 inches of real estate in a 16:10 aspect ratio. To go into laptop mode, you remove the controllers and mount the handheld into a folio case with a stand, built-in keyboard, and trackpad. The controllers can be put into a separate grip mount to unify them as one gamepad.
There are a lot of ways you can use this folding handheld, including turning one of its controllers into a vertical mouse like on other Legion Go handhelds, but there’s one thing it doesn’t do: fold down to close and protect its screen. The Go Fold only folds outwards, so don’t expect a Nintendo DS or GameBoy Advance-like clamshell that closes for portability. Instead, it’s all about getting bigger than your average gaming handheld and offering more. (Though we’ve tried bigger before.)
The Legion Go Fold has some formidable specs: an Intel Core Ultra 7 258V Lunar Lake processor, 32GB of RAM, 1TB of storage, and a 48Whr battery. The plastic-covered OLED has a resolution of 2435 x 1712 and 165Hz refresh rate. And there’s even a second, circular toushscreen on the right controller, under the face buttons. It doubles as a touchpad and can be a support display, allowing you to swipe between extracted UI elements from a game (which I wouldn’t expect to be widely supported), a clock, system monitoring, or an animated GIF (just for fun).
During my brief in-person demo I didn’t get to play any graphically-intense games — just Balatro, which can practically play on a potato. The screen looked plenty sharp, but like any foldable there’s a crease down the middle; it’s very visible, but you learn to look past it and ignore it after just a bit. The build and feel of the whole thing felt a little fragile, and detaching and reattaching the controllers was definitely janky. Build quality will hopefully be improved if this device ever actually makes it to market.
The laptop mode was a pleasant surprise for me though. I did not expect a gaming handheld to double as a conventional computer you could get work done on. The Legion Go Fold’s case took quite a bit of fumbling before I set it up correctly, but it shouldn’t take too long to get used to if you actually lived with it.
Then again, I don’t know if anyone is going to be able to live with this thing — ever. I’d love for the Legion Go Fold to go from concept to real product like other out-there Lenovo ideas, but I shudder to think what it might cost. The Legion Go 2 is already priced well over $1,000. And with the ongoing RAMageddon crisis we’re living through, there’s no telling how much more expensive an actual Legion Go Fold would be if it came out in a year or more.
But even if it’s not the kind of foldable I expected, and even though it may never come out, it’s certainly cool. Now somebody please make a folding PC handheld that goes from kinda-big to really small. I think that’d be the one for me.
Photography by Antonio G. Di Benedetto / The Verge
Technology
Iran networks suffer losses amid airstrikes, showing digital evolution of conflicts
NEWYou can now listen to Fox News articles!
When missiles fly, we expect explosions. We expect smoke, sirens and satellite images. What we do not expect is silence.
On February 28, 2026, as fighter jets and cruise missiles struck Iranian Revolutionary Guard command centers during Operation Roar of the Lion, a parallel assault reportedly unfolded in cyberspace.
Official news sites and key media platforms went offline, government digital services and local apps failed across major cities, and security communications systems reportedly stopped functioning, plunging Iran into a near-total digital blackout.
According to NetBlocks, a global internet monitoring organization that tracks connectivity disruptions, nationwide internet traffic in Iran plunged to just 4 percent of normal levels.
That level of collapse suggests either a deliberate state-ordered shutdown or a large-scale cyberattack designed to paralyze critical infrastructure. Western intelligence sources later indicated the digital offensive aimed to disrupt IRGC command and control systems and limit coordination of counterattacks.
For the United States and its allies, the episode offers a stark reminder that modern conflict now blends airstrikes with digital warfare in ways that can ripple far beyond the battlefield.
In a matter of hours, modern conflict looked less like tanks and more like a blinking cursor.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter
Iran’s national symbols stand in contrast to reports of a sweeping digital blackout that reportedly disrupted communications and critical systems across the country. (Kurt “CyberGuy” Knutsson)
Iran internet shutdown: A country offline in real time
Reports described widespread outages across Iran. Official news sites stopped functioning. IRNA, Iran’s state-run news agency, went offline.
Tasnim, a semi-official news outlet closely aligned with the Islamic Revolutionary Guard Corps, reportedly displayed subversive messages targeting Supreme Leader Ali Khamenei.
THINK YOUR NEW YEAR’S PRIVACY RESET WORKED? THINK AGAIN
The IRGC, Iran’s powerful military and intelligence force, plays a central role in national security and regional operations. At the same time, local apps and government digital services failed in cities like Tehran, Isfahan and Shiraz.
This was not one website defaced for headlines. It appeared systemic. Electronic warfare reportedly disrupted navigation and communications systems.
Distributed denial of service attacks, often called DDoS attacks, flooded networks with traffic to overwhelm and disable them.
Deep intrusions targeted energy and aviation systems. Even Iran’s isolated national internet struggled under pressure.
CHINA VS SPACEX IN RACE FOR SPACE AI DATA CENTERS
For a regime that tightly controls information, losing digital command creates both operational and political risk.
Why cyber warfare matters in the Iran conflict
Cyber operations offer something missiles cannot. They disrupt without always killing. They send a signal without immediately triggering full-scale war. That matters in a region where escalation can spiral fast.
History shows Iran understands this logic. Between 2012 and 2014, Iranian actors targeted U.S. financial institutions in Operation Ababil. Saudi Aramco also suffered a major cyberattack.
ARTIFICIAL INTELLIGENCE HELPS FUEL NEW ENERGY SOURCES
After Israeli strikes in 2025, cyberattacks targeting Israel surged dramatically within days.
Cyber retaliation lets leaders respond while limiting direct military confrontation. It buys leverage in negotiations. It creates pressure without necessarily crossing a red line.
But there is a catch. Every cyber strike risks miscalculation. And digital damage can spill into the real world fast if critical infrastructure is hit.
As military strikes targeted IRGC command centers, internet traffic inside Iran reportedly plunged to just 4 percent of normal levels. (Kurt “CyberGuy” Knutsson)
If the blackout and strikes mark a turning point, Tehran has options. None are simple.
1) Cyberattacks against U.S. or allied infrastructure
Cyber retaliation remains one of Iran’s most flexible tools. It can range from disruptive attacks and influence campaigns to more targeted intrusions that pressure critical services. Recent expert commentary warns that U.S. cyber defenses and the private sector could face sustained testing.
2) Targeting U.S. drones and unmanned systems
Iran has used drones and electronic interference as signals before. Analysts continue to flag jamming, spoofing and harassment of unmanned systems as a way to raise costs without immediately striking large numbers of personnel.
3) Maritime attacks in the Strait of Hormuz
This risk is rising fast. An EU naval mission official reportedly said IRGC radio transmissions warned ships that passage through Hormuz was “not allowed”. Greece has also urged ships to avoid high-risk routes and warned about electronic interference that can disrupt navigation. Insurers are already repricing the danger, with reports of war-risk policies being canceled or sharply increased.
4) Support for allied or informal armed groups
Iran has long worked with allied forces and militias in the region, and some of those groups could step up attacks on U.S. interests or allied partners in retaliation, widening the clash without direct state-to-state engagement.
5) Limited ballistic missile strikes
Missile strikes remain a high-impact option, but they raise the odds of rapid escalation. Recent expert analysis continues to frame them as a tool Iran may use for signaling, especially if leadership feels cornered.
Tehran’s skyline, including the Azadi Tower, became the backdrop to a crisis shaped as much by cyber disruption as by missiles in the sky. (Kurt “CyberGuy” Knutsson)
The escalation risk between the U.S. and Iran
Here is the uncomfortable truth. Neither Washington nor Tehran likely wants a full-scale regional war. In moments like this, military strikes rarely stand alone.
They often move alongside diplomacy. Leaders send signals. They apply pressure. At the same time, they try to leave room for talks.
But escalation has momentum. Each missile changes the equation. Each casualty raises the stakes. The more damage done, the harder it becomes to step back.
5 SIMPLE TECH TIPS TO IMPROVE DIGITAL PRIVACY
Fear plays a role. So does pride. Domestic audiences demand strength. Leaders feel pressure to respond in kind. That is how limited strikes can spiral into something much larger.
What the Iran cyberattack blackout means for global cybersecurity
This episode highlights something bigger than regional tension. Nation-states now pair kinetic strikes with digital offensives.
Cyberattacks can blind communications, freeze infrastructure and disrupt financial systems before the world even processes the first explosion.
TRUMP TELLS IRANIANS THE ‘HOUR OF YOUR FREEDOM IS AT HAND’ AS US-ISRAEL LAUNCH STRIKES AGAINST IRAN
For businesses and individuals, that reality matters. Modern conflict no longer stays confined to battlefields.
Supply chains, energy grids and online platforms can feel the ripple effects. The blackout in Iran serves as a reminder that digital resilience is now a national security issue.
How to stay safe during rising cyber tensions
When a country’s internet can plunge to just 4 percent of normal traffic in hours, it is a reminder that cyber conflict can escalate quickly.
Even if the disruption happens overseas, global networks are interconnected. Financial systems, supply chains and online platforms can feel the ripple effects.
You cannot control geopolitics. You can control your digital hygiene. Here are practical steps to reduce your personal risk during periods of heightened cyber activity:
Install strong antivirus software to guard against state-linked phishing and malware campaigns that often spike during geopolitical conflicts.
Nation-state actors frequently exploit breaking news and global instability to spread malicious links and ransomware. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
Keep devices updated so security patches close vulnerabilities that attackers often exploit during global cyber spikes.
WORLD LEADERS SPLIT OVER MILITARY ACTION AS US-ISRAEL STRIKE IRAN IN COORDINATED OPERATION
Use strong, unique passwords stored in a reputable password manager to protect your accounts if cyber retaliation campaigns expand beyond government targets. Check out the best expert-reviewed password managers of 2026 at Cyberguy.com
Enable two-factor authentication (2FA) on financial, email and social accounts to safeguard access in case stolen credentials circulate during heightened cyber conflict.
Be cautious with urgent headlines or alerts about international conflict, since attackers frequently mimic breaking news.
Monitor financial accounts for unusual activity in case broader disruptions spill into banking systems.
When tensions rise, phishing campaigns often rise with them. Threat actors exploit fear and confusion. Staying disciplined with basic security habits makes you a harder target if malicious traffic increases.
Take my quiz: How safe is your online security?
Think your devices and data are truly protected? Take this quick quiz to see where your digital habits stand. From passwords to Wi-Fi settings, you’ll get a personalized breakdown of what you’re doing right and what needs improvement. Take my Quiz here: Cyberguy.com
Kurt’s key takeaways
The reported cyber blackout inside Iran may signal a new chapter in modern conflict. Jets and missiles still matter. But so do servers, satellites and code. Leaders may try to contain the damage while showing strength.
Still, history shows how quickly careful plans can unravel once pressure builds. War today runs on electricity and bandwidth as much as fuel and ammunition.
When networks go dark, the impact does not stay on a battlefield. It spills into banking systems, airports, hospitals and the phones in our pockets. That is what makes this moment different.
If an entire nation’s digital systems can be disrupted in hours, how prepared is your community if something similar ever hits closer to home? Let us know by writing to us at Cyberguy.com
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Soundcore new Space 2 promise improved ANC and sound
We finally have an update to the Soundcore Space One that launched two and a half years ago. At MWC 2026, Soundcore has announced the Space 2, which will be available in the US on April 21st in three colors — linen white, jet black, and seafoam green — for $129.99. That’s $30 more than the Space One’s original price.
According to Soundcore, the Space 2 have had a full-band noise cancellation upgrade with the focus of those improvements on the low-frequency sounds we all generally use ANC headphones to block — things like airplane, train, and bus engine sounds while traveling. The Space 2 use the same number of microphones as the Space One for noise canceling, instead relying on optimized mic placement and structure and materials improvements for the boost in performance.
Redesigned 40mm drivers incorporate dual layers in their design. There’s a silk diaphragm with metal ceramic that supposedly results in faster transient response — the driver’s ability to respond to sudden sound quickly and accurately — with better balanced sound reproduction. The Space One had great sound performance for the price, but I’m all for any improvement to sound performance accuracy. Like the Space One, the Space 2 will support LDAC high-res audio.
The headphones connect wirelessly over Bluetooth 6.1, although they do not support Auracast transmissions — an unfortunate exclusion. There’s also a 3.5mm jack for a wired connection.
Battery life has been increased to up to 50 hours with ANC and 70 hours with ANC off. This is up from 40 hours with ANC and 55 hours without ANC with the Space One headphones. With a five-minute charge the Space 2 get an additional four hours of listening.
The Space 2 will include many of the features found on the Space One. You can use HearID 3.0 to go through a series of sound samples to tune the headphones’ sound to your preferences. It worked well for me on the Space One to get them closer to a sound I liked, with a bit of the edge taken off the higher frequencies. There’s also a sensor that detects when you remove the headphones and stops playback so you don’t miss any of your music or podcast. They once again come with a cloth bag that matches the color of the headphones instead of a case, which is one change I wish Soundcore had made, as the cloth bag doesn’t offer as much protection if you tend to throw your headphones into your backpack or bag.
The Soundcore Space One were among the best budget ANC headphones when they came out, and still hold up to more recent releases. But with the bump in price to over $100 for the Space 2, there’s a bit more expectation on them. ANC performance continues to improve — and products get cheaper — across manufacturers, so the Soundcore Space 2 has some competition from companies like Sony, EarFun, and JLab. If the ANC on the Space 2 stands up to current budget headphones and they still sound as good and are as comfortable as the Space One, you can expect to see the new Soundcore Space 2 on many recommendation lists.
-
World4 days agoExclusive: DeepSeek withholds latest AI model from US chipmakers including Nvidia, sources say
-
Massachusetts4 days agoMother and daughter injured in Taunton house explosion
-
Denver, CO4 days ago10 acres charred, 5 injured in Thornton grass fire, evacuation orders lifted
-
Louisiana7 days agoWildfire near Gum Swamp Road in Livingston Parish now under control; more than 200 acres burned
-
Technology1 week agoYouTube TV billing scam emails are hitting inboxes
-
Politics1 week agoOpenAI didn’t contact police despite employees flagging mass shooter’s concerning chatbot interactions: REPORT
-
Technology1 week agoStellantis is in a crisis of its own making
-
News1 week agoWorld reacts as US top court limits Trump’s tariff powers