Skip to content
Review

IoT as a Cyber Attack Platform: Lessons from Real-World and Proof-of-Concept Incidents

Jul 2026 · International Symposium on Communication Systems, Networks and Digital Signal Processing · pp. 1-6 · 0 citations · 64 references
Computer Science

Abstract

The rapid proliferation of Internet of Things (IoT) devices has transformed everyday environments, connecting homes, enterprises, and industrial systems in unprecedented ways. While these devices offer significant convenience and functionality, their widespread deployment coupled with common weak security mechanisms, make them an attractive target for cyberattacks. In this paper, we examine IoT as a cyber attack platform, analysing both real-world incidents and proof-of-concept attacks to understand how compromised devices are leveraged to target other systems. We identify the IoT device vulnerabilities most frequently exploited, classified according to the OWASP Top 10 IoT vulnerabilities, and evaluate the resulting impact on the confidentiality, integrity, and availability (CIA) of targeted systems. Our review highlights the evolving strategies attackers use to harness IoT devices for distributed attacks, from botnets to lateral movement within networks. Based on these insights, we discuss the lessons learned and underscore the critical role of robust security mechanisms in enabling the next generation of secure IoT devices and services.

View source

Similar papers

Review Open access Aug 2026

Cybersecurity in the IoT Era: Protecting the Expanding Internet of Things

The Internet of Things (IoT) is transforming industries and daily life by connecting billions of devices, enabling smart homes, cities and industrial systems. This rapid expansion, however, introduces significant cybersecurity vulnerabilities, leaving IoT systems increasingly exposed to both established and emerging attack techniques. This paper presents a structured critical review of IoT cybersecurity, distinguished from prior general surveys by three contributions: first, a cross-layer mapping of named, dated case studies to the specific Security-by-Design principles that would have mitigated them; second, a comparative, feasibility-based evaluation of lightweight cryptographic primitives and blockchain consensus protocols for resource-constrained devices, rather than a descriptive overview; and third, a critical appraisal of the operational limitations of AI-based and blockchain-based defences, including adversarial manipulation, data scarcity and energy cost, set against the claims commonly made for these technologies. We examine the current state of IoT security across the perception, network and application layers; the common vulnerabilities that affect these systems, from insecure device design and weak default credentials to unencrypted communications; and the real-world consequences of these flaws through recent, named case studies, including the Aisuru botnet which is active since 2024 and 2024 vulnerability disclosures affecting Mitsubishi Electric and OMRON industrial controllers. We argue that securing the IoT ecosystem requires sustained, coordinated effort from manufacturers, regulators and end-users, and we identify where current technological and regulatory responses fall short of that goal.

K. Curran, J. Kyle, Lovepreet Singh · 0 citations
Review Open access Jul 2026

Penetration Testing for IoT Ecosystems: Unveiling Vulnerabilities in a Connected World

A novel Artificial Intelligence (AI)-enabled automated conceptual framework, AutoAIPenTest, is proposed that integrates machine learning, reinforcement learning, and large language models to perform intelligent, real-time security assessments in dynamic IoT ecosystems.

A. Alabdulatif · 0 citations
Review Open access Aug 2026

A Comprehensive Review of Cybersecurity Threats, Vulnerabilities, and Mitigation Techniques in the Internet of Things (IoT)

Internet of Things (IoT) has become a new paradigm that combines physical devices with computing and networking features to form intelligent systems that can accomplish their tasks with minimal human interaction. It is estimated that by 2030, there will be more than 30 billion interconnected IoT devices, which will transfer more than 40 zettabytes of data each year. Nevertheless, this exponential increase has brought surprising cybersecurity issues, and recent evaluations show that over 70% of IoT devices are susceptible to hacking. This review examines the complex security environment of IoT ecosystems, evaluates vulnerabilities at each layer of architecture, explores new threat vectors, and assesses new defense solutions. This paper introduces a systematic review of IoT security issues based on a five-layer architecture and specifically focuses on the vulnerabilities of the network and application layers. It examines the ways in which artificial intelligence, blockchain technology, edge computing, and Zero Trust Architecture will transform IoT security paradigms. This review helps reveal long-standing issues such as resource limitations, device heterogeneity, and scaling challenges through the analysis of actual attack cases and defenses in the field of smart healthcare, industrial IoT, smart cities, and other vital infrastructures. Recommendations on future research directions are then given at the end of the paper with an emphasis on quantum-resistant cryptography, 6G network security, and standardized security frameworks required to construct resilient IoT ecosystems.

Muhammad Sami Intizar, Maria Sikandar, Aqsa Siddique et al. · 0 citations
Review Open access Aug 2026

Security Vulnerabilities and Resilience Strategies in Healthcare IoT Systems: A Comprehensive Review

Internet of Things (IoT) technologies in the healthcare industry, also known as the Internet of Medical Things (IoMT), have proven to greatly improve patient monitoring, diagnostics, and clinical decision-making. The increasing prevalence of resource-challenged medical devices, wireless connectivity, and cloud services, however, has brought new risks around security and privacy concerns that can now directly impact patient safety and data integrity. In this paper, a thorough study of 41 peer-reviewed research papers from January 2018 through May 2025 revealed the current state of security vulnerabilities and resilience strategies in healthcare IoT systems. It provides a comprehensive analysis of security threats at the device, network, and application levels such as unauthorized access, malware and ransomware, data breaches, and denial-of-service attacks delivered in a systematic manner. This contrasts with existing surveys, which consider single security mechanisms and improve upon various multi-layered security means such as AI-enabled anomaly detection, blockchain-based authentication and auditability, low-compute cryptographic techniques, and privacy-preserving methods such as federated learning. The outcomes also show that although emerging technologies add a great deal of security and trust capabilities, issues on scalability, interoperability, deployment, and regulations are not yet fully addressed. This review highlights important knowledge gaps and offers structured knowledge and future directions for research to address the design of secure, resilient, and practically deployable IoMT architectures for real-world healthcare environments.

M. R. M. Hanan, M. J. A. Sabani · 0 citations
Review Open access Sep 2026

A Survey on Cyber Resilience in IoT Networks: Challenges, Mechanisms, and Future Directions

The rapid expansion of the Internet of Things (IoT) across industries such as healthcare, manufacturing, transportation, and smart cities has made these networks prime targets for cyber attacks. Due to their distributed nature, device diversity, and resource constraints, traditional cyber security solutions alone are insufficient to protect against evolving threats. In addition, the increasing complexity of managing numerous interconnected devices and the limitations of realtime threat detection heighten the risk of cyber breaches. As a result, researchers and engineers are shifting beyond purely defensive cyber security approaches and focusing instead on recoverability and adaptability through cyber resilience mechanisms. The primary objective of cyber resilience in IoT networks is to go beyond conventional protective layers, ensuring long-term sustainability and strengthening resilience against persistent and sophisticated cyber threats. This survey analyses the cyber resilience concept and its steps in IoT networks and outlines challenges in providing cyber resilience in these networks. We review existing definitions of cyber resilience, highlighting their limitations in the IoT context. Also, the relationship between the key security features of IoT networks and cyber resilience is examined. We categorise proposed cyber resilience mechanisms according to their operational layers within the IoT architecture and evaluate them across multiple dimensions, including resilience phases, alignment with IoT requirements, the application domain and employed techniques. Furthermore, this survey examines several directions for future research by highlighting the diverse challenges posed by the various facets of IoT networks within this research domain. The findings of this research contribute to the existing body of knowledge on IoT security and cyber resilience while laying the groundwork for future research and development. Ultimately, this survey seeks to support the development of effective and sustainable strategies to ensure the security and resilience of IoT networks in the face of evolving cyber threats.

Foroozan Darbandeh, Muhammad Rizwan Asghar, Li-Qun Chen · 0 citations
Review Open access Aug 2026

A Systematic Review of Smart Home IoT Security: Applications, Threat Taxonomy, Privacy Risks, and Emerging Defensive Solutions

The rapid proliferation of Internet of Things (IoT) technologies has transformed the modern home into a complex cyber–physical ecosystem encompassing hundreds of millions of connected devices globally. Smart homes support automation, energy management, and healthcare monitoring, but they also introduce a broad and evolving range of security and privacy challenges. This review examines 233 sources published between 2018 and May 2025, selected through a PRISMA-informed process covering five major academic databases and relevant standards and technical reports. It discusses communication protocols, including Matter, develops a Threat-Layer-Defense synthesis matrix covering ten attack categories; examines the practical limitations of AI-based anomaly detection and blockchain-based trust management; and derives recommendations for manufacturers, platform providers, users, and regulators. Privacy challenges, regulatory frameworks, and user behavior are considered alongside technical threats. The findings suggest that scalable smart home security requires coordinated progress in protocol standardization, enforceable device update lifecycles, gateway-level anomaly detection, and privacy-preserving local analytics rather than reliance on a single technical solution.

Dalibor Radovanovic, Nikola Savanović, Jelena Janackovic et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.