Hello readers!

This week, we’re talking about a new paradigm for IoT security, embedded software, physical AI, and more!

IoT's Weakest Point Has Moved. Have You?

For a decade, enterprise security programs have run on a quiet hierarchy: laptops and servers get patch schedules, endpoint agents, and asset inventories, while the router or switch connecting them to the internet gets a login page nobody remembers the password to. That hierarchy assumed network equipment was plumbing — trusted by default, updated when convenient, sitting outside the vulnerability-management program built around everything plugged into it. New numbers invert the assumption. Routers and switches are no longer the quiet infrastructure behind the real targets. They are the target, and the device category security teams have spent the least effort watching now generates more of the highest-severity risk than anything sitting on the network it's supposed to protect.

Forescout's 2026 research found that routers and switches average 32 vulnerabilities per device and account for 34 percent of the most critical vulnerabilities in enterprise networks, while 40 percent of 2026's riskiest device types weren't on the list a year earlier, which means the shift is still moving rather than settling into a new equilibrium. The mechanism lines up with what IoT practitioners have been warning about for years: a compromised device with a path to sensitive systems does more damage than one sitting alone, and a router by definition has a path to everything behind it. Attackers found that math faster than most security programs revisited their own device inventories.

This isn't a new vulnerability class announcing itself. The Mirai botnet that took down Dyn in 2016 and knocked half the internet's biggest sites offline was built almost entirely on hijacked routers, cameras, and DVRs — the same device types that a decade later carry the most critical exposure inside enterprise networks. What changed is the target. Kimwolf, one of four botnets a U.S.-Germany-Canada operation dismantled this March, introduced a propagation method that reaches devices behind home routers, crossing into internal networks the router used to shield. The device built to be the boundary became the way through it. Guidance on choosing an IoT router has said for years to look for firmware-update commitments and built-in intrusion detection. The advice was sound; most organizations simply never revisited the hardware once it shipped.

Network segmentation is the standard prescription for this exact exposure — isolate IoT devices from critical systems so a compromised camera can't reach a domain controller. It works when the device drawing the boundary is itself trustworthy. It breaks down when that device is running 32 vulnerabilities on average and going unpatched for months, because a segmentation policy enforced by a compromised router isn't a boundary at all. RondoDox's exploitation of HPE OneView, a platform that manages the servers and firmware sitting behind it, launched more than 40,000 automated attack attempts in a single four-hour window in January — the same pattern one layer up. Control-plane infrastructure, treated as trusted rather than as a monitored device, gave one vulnerability access to an entire data center.

For anyone running an IoT or OT security program, the fix is less a new tool than a reclassification. Routers, switches, and infrastructure-management platforms need the same inventory, patch cadence, and default-credential audit that endpoint devices have had for years — not because they're exotic new risks, but because they quietly stopped being exempt from the risks everything else already gets managed for. An organization that can name every laptop on its network but not every router's firmware version hasn't secured its network; it has measured the wrong half of it. Closing that gap starts with treating the equipment in the wiring closet as a device population, not as furniture.

📖 Top Articles

As AI moves from cloud applications into physical systems like vehicles, industrial equipment, and medical devices, embedded software must transform to include AI-driven behavior control. This transformation requires combining technologies with fundamentally different characteristics: deterministic control and probabilistic AI. And the key challenge shifts from “how to run AI” to “how to make AI work reliably in the physical world.”

The EU Cyber Resilience Act (CRA) represents a significant change in how cybersecurity is treated for products with digital elements. Beyond security needing to be demonstrated before a product reaches market, it becomes a responsibility that extends throughout the product lifecycle. The regulations apply to device manufacturers, but it would be easy for an IoT service provider to accidentally become a manufacturer for the purposes of the CRA.

The drone industry has grown far beyond recreational use, becoming essential for defense, agriculture, logistics, infrastructure inspections and emergency response. As demand increases, manufacturers must produce lighter, stronger and more reliable drones while maintaining efficient production.

Amazon Developer Global Hackathon

Build and compete for $190K in prizes. The Amazon Developer Hackathon is an 8-week virtual challenge with multiple categories including smart home, wearables, voice AI, and building TV app experiences.

Create AI-enhanced experiences on Fire TV or extend Alexa+ with new agent capabilities. Integrate Bee wearable AI with any product or device or explore Amazon’s computer vision APIs to build IoT automation use cases and more.

You can build solo or join a team. The top prize is $40K ($25K cash + $15K AWS credits).

🔥 Rapid Fire

🎙 The IoT For All Podcast

In this episode of the IoT For All Podcast, Wienke Giezeman, CEO and co-founder of The Things Industries, joins Ryan Chacon to discuss how IoT is finally delivering what it promised ten years ago. The conversation covers what changed technically and commercially, the ROI of IoT, why deployments failed in the early days, criticism of IoT, what companies still get wrong about LoRaWAN, and The Things Conference 2026.

📆 Events & Webinars

Hosted by Informa Connect

The era of network convergence demands a unified response. Network X brings together operators, vendors, and innovators to navigate AI, cloud, and sovereignty complexity as one ecosystem.

15% Discount Code: IOTFORALL15

Brought to you by

Amazon Developer

Giving developers the tools to build awesome apps and games, and reach millions of consumers worldwide.