/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers find a bug in the ThroughTek Kalay SDK, which connects over 83M IoT devices with apps, that lets attackers access audio and video streams

A vulnerability in the Kalay platform leaves countless IoT devices susceptible to hackers.  —  A VULNERABILITY IS lurking in numerous types … Source: FireEye .

Wired Lily Hay Newman

Context & Ripple Effects

The Kalay finding extends a research thread that keeps exposing how IoT devices share vulnerable plumbing. Researchers had already documented SweynTooth flaws crashing Bluetooth Low Energy devices like pacemakers in early 2020, then Amnesia:33 vulnerabilities in four open source TCP/IP stacks running on millions of embedded devices that December.

What makes Kalay different is the layer it sits on: not a radio protocol but a cloud-connect SDK that bridges more than 83 million devices to their companion apps — meaning a single flaw becomes an eavesdropping channel for whatever cameras and microphones ride through it. Weeks later, the same pattern surfaced again with BrakTooth's 16 Bluetooth firmware flaws across SoC boards from 11 vendors.

First-order effects

  • ThroughTek and every device maker shipping the Kalay SDK face an urgent patch cycle, since attackers can access audio and video streams on affected devices today.

Second-order effects

  • OEMs that bundled Kalay for its convenience now carry the reputational cost of a supplier's flaw, pushing device makers to demand security audits and faster disclosure terms from SDK vendors before integration.

Third-order effects

  • If the pattern holds — one shared component exposing millions of branded devices at once — procurement and regulators will treat third-party SDKs as attack surface in their own right, forcing visibility into the software supply chain inside IoT products.

The trend: IoT security research is shifting up the stack from individual radios and firmware to the shared middleware and SDKs that quietly connect entire product categories.