Robot Lawn Mower Vulnerabilities Allow Remote Takeover and Data Theft
Security researchers identified multiple flaws in a $5,000 robot lawn mower that could let hackers seize control of the device, access its camera, and obtain owners' email addresses, Wi-Fi passwords and home locations. The company said it is developing a fix for at least one of the issues.
WiredA security researcher discovered numerous vulnerabilities in Yarbo robot lawn mowers that allow remote takeover of the machines, including access to their camera feeds. The flaws also enable extraction of owners' email addresses, Wi-Fi passwords and home locations.
The Verge reported that after a company spokesperson said the robots' diagnostic environment is not publicly accessible, the researcher and reporter demonstrated the issues by nearly running over the reporter with a hijacked robot. It can function as a lawn mower, leaf blower, snowblower and edger.
The company has since reported that it is developing a fix to at least one of the flaws the researcher identified.
Meta stopped offering end-to-end encryption on Instagram direct messages on May 8. The company had previously introduced an opt-in version of encryption for Instagram and planned to make it the default setting. Meta decided in March that not enough users had opted in and removed the option.
The move reverses earlier steps by the company to expand encryption. In 2023 Meta said it had rolled out default encryption for Messenger after years of development. The change makes it easier for the company to access Instagram DMs.
Researchers this week revealed that thousands of applications created with vibe coding were left exposed on the open internet, revealing sensitive corporate and personal data. The security failings serve as a reminder of risks associated with rapid development methods.
The Department of Homeland Security subpoenaed Google in an attempt to obtain the location data and account activity of a Canadian man who criticized US immigration enforcement tactics. The American Civil Liberties Union filed a complaint against the department on the man's behalf.
The man has not visited the United States in more than 10 years. New research found that scammers, low-level hackers and other cybercriminals are increasingly frustrated with low-quality AI-generated content. Meta is updating its age-verification technology after a study showed that children are bypassing online age checks with simple methods, including one case involving a drawn-on fake mustache.
A consortium of journalists reported this week on leaked documents detailing a unit at Bauman Moscow State Technical University that provides training and a pipeline into Russia's GRU military intelligence agency. The unit, known as Department 4, teaches hacking skills including penetration testing.
Some graduates have joined groups linked to major cyberattacks. Poland's domestic intelligence agency warned that hackers infiltrated networks of water utilities in five towns last year. In some cases the attackers reached industrial control systems that could have affected physical operations of the facilities.
The agency described the incidents as part of a broader Russian reconnaissance campaign targeting Polish military and critical infrastructure.
Key Facts
Story Timeline
5 events- May 8, 2026
Meta stopped offering end-to-end encryption on Instagram direct messages.
1 sourceWired - This week
Security researcher demonstrated vulnerabilities in Yarbo robot lawn mowers.
1 sourceWired - This week
Leaked documents revealed details about Russia's GRU-linked hacking training unit.
1 sourceWired - This week
Poland's ABW warned of Russian hackers infiltrating water utility networks last year.
1 sourceWired - March 2026
Meta decided to remove the encryption option for Instagram chats.
1 sourceWired
Potential Impact
- 01
Meta users on Instagram will have all direct messages readable by the company without end-to-end encryption.
- 02
Yarbo owners may face unauthorized access to home locations and camera feeds until fixes are deployed.
- 03
Polish water utilities must address vulnerabilities in industrial control systems after confirmed intrusions.
- 04
The ACLU complaint could lead to court limits on DHS requests for location data of non-US residents.
Transparency Panel
Related Stories
EuronewsWorld Urban Forum 2026 Draws 57,000 Participants from 176 Countries
The 13th World Urban Forum concluded with discussions on housing, climate resilience and urban governance. Organisers reported that the sessions informed future strategic priorities.
theverge.comTrump Mobile website still lists T1 phone as American-made
The product page for the T1 phone continues to describe the device as American-made. The Verge reported that the site may conflict with FTC advertising rules. The phone was announced in June 2025.
France 24EU Discusses Readiness for Artificial Intelligence Changes
A France 24 program examined whether European Union policies can address the effects of artificial intelligence. The discussion covered potential impacts across daily life and economic sectors.