{"id":28534,"date":"2019-08-19T10:08:04","date_gmt":"2019-08-19T10:08:04","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\/"},"modified":"2019-08-19T10:08:04","modified_gmt":"2019-08-19T10:08:04","slug":"knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\/","title":{"rendered":"KNOB turns up the heat on Bluetooth encryption, hotels leak guest info, city hands $1m to crook, and much, much more"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2018\/04\/24\/11_volume_knob_shutterstock.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p><strong class=\"trailer\">Roundup<\/strong> Let&#8217;s run through all the bits and bytes of security news beyond <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/security\/\" rel=\"noopener noreferrer\">what we&#8217;ve already covered<\/a>. Also, don&#8217;t forget our articles from this year&#8217;s <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/Tag\/blackhat2019\" rel=\"noopener noreferrer\">Black Hat<\/a>, <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/Tag\/defcon2019\" rel=\"noopener noreferrer\">DEF CON<\/a>, and <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/Tag\/bsides2019\" rel=\"noopener noreferrer\">BSides Las Vegas<\/a> conferences in the American desert.<\/p>\n<p><strong>KNOB opens door to Bluetooth snooping:<\/strong> Microsoft&#8217;s Patch Tuesday dump included <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-9506\">the disclosure<\/a> of a security flaw in the Bluetooth protocol. The design blunder affects more than just Microsoft products, though: it is at the heart of the Bluetooth specification. The flaw therefore affects any gear using Bluetooth chipsets that implement the standard; more than 14 such vulnerable chips have been identified, including parts from Intel, Broadcom, Apple, and Qualcomm.<\/p>\n<p>The security hole is dubbed Key Negotiation of Bluetooth, or KNOB for short \u2013 and even though we&#8217;ve thought long and hard about making jokes about this, sadly, we&#8217;ve come up with nothing. It involves a shortcoming in the process that two devices use to establish a secret key between themselves to encrypt data exchanged over the air. It is possible for a nearby miscreant-in-the-middle to force a pair of gadgets to agree on a key with only 8 bits of entropy, allowing the wireless snooper to decrypt their subsequent communications using brute force.<\/p>\n<p>Boffins Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.usenix.org\/system\/files\/sec19-antonioli.pdf\">described<\/a> [PDF] their eavesdropping technique in a paper presented at the USENIX Security Symposium in the US this month. CMU CERT <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.kb.cert.org\/vuls\/id\/918987\/\">explained<\/a> how the method using the &#8220;Alice and Bob&#8221; key analogy:<\/p>\n<p>And the upshot of all that?<\/p>\n<p>Oops. That&#8217;s pretty upsetting. It means nearby miscreants can potentially snoop on or tamper with Bluetooth connections to keyboards, speakers, and other gizmos. Thus far, though, the vulnerability has only been <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.bluetooth.com\/security\/statement-key-negotiation-of-bluetooth\/\">exploited in the lab<\/a>, according to the Bluetooth specification folks. However, it would be wise to install patches for your gadgets as they become available. Microsoft and Apple have both released fixes for their products to thwart KNOB attacks \u2013 the official solution being to enforce a &#8220;minimum encryption key length of 7 octets [seven bytes] for BR\/EDR connections,&#8221; according to the Bluetooth team. Expect more from other vendors, hopefully.<\/p>\n<p>&#8220;The attacking device would need to intercept, manipulate, and retransmit key length negotiation messages between the two devices while also blocking transmissions from both, all within a narrow time window,&#8221; the Bluetooth spec people noted. &#8220;If the attacking device was successful in shortening the encryption key length used, it would then need to execute a brute force attack to crack the encryption key.&#8221;<\/p>\n<div class=\"boxout\" readability=\"20.805914972274\">\n<p><strong>In brief&#8230;<\/strong> Someone at DEF CON has told of how they set their vehicle license plate to <strong>NULL<\/strong> \u2013 and has been <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/mashable.com\/article\/dmv-vanity-license-plate-def-con-backfire\/\">slapped with strangers&#8217; traffic tickets<\/a> whenever police officers leave that field blank in citations&#8230; The <strong>TP-Link M7350<\/strong> 4G hotspot has various command-injection vulnerabilities, found using the NSA&#8217;s <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2019\/03\/06\/nsa_ghidra_joyce\/\" rel=\"noopener noreferrer\">Ghidra<\/a> toolkit, and you should <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.pentestpartners.com\/security-blog\/cve-2019-12103-analysis-of-a-pre-auth-rce-on-the-tp-link-m7350-with-ghidra\/\">update<\/a> yours now&#8230; A Black Hat <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/twitter.com\/Dinosn\/status\/1161203350681071616\">presentation<\/a> talked people through the exploitation of Samsung&#8217;s Arm TrustZone code&#8230; Another Black Hat talk <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/twitter.com\/c7zero\/status\/1160273950716420098\">revealed<\/a> the insides of <strong>Apple&#8217;s T2 security chip<\/strong>&#8230; Thousands of cars were <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.wired.com\/story\/mycar-remote-start-vulnerabilities\">exposed<\/a> to hackers thanks to a <strong>remote-start app<\/strong>.<\/p>\n<p>An out-of-nowhere hit at DEF CON was <strong>the O.MG cable<\/strong>, and its sibling DemonSeed, which <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/mg.lol\/blog\/defcon-2019\/\">appears to be a USB cable<\/a> yet it can be controlled wirelessly to take control of the connected device or laptop. We&#8217;ve seen these sorts of stealth cables before but none quite so normal looking. They sold out at DEF CON, and more are promised <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/shop.hak5.org\/products\/o-mg-cable\">from the Hak5 store<\/a>.<\/p>\n<p>And Apple strangely broke a security patch it earlier released for iOS 12.3, allowing a <strong>jailbreak<\/strong> to <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/twitter.com\/Pwn20wnd\/status\/1163102269518204930\">now work with iOS 12.4<\/a>.<\/p>\n<\/div>\n<p><strong>Choice chopped by open server:<\/strong> Choice Hotels is the latest organization to be stung by a poorly configured cloud database. It <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.comparitech.com\/blog\/vpn-privacy\/choice-hotels-data-leak\/\">was revealed<\/a> this month that some 700,000 Choice hotel guest records were left in a MongoDB instance exposed to the public internet.<\/p>\n<p>Open-cloud-bucket hunter Bob Diachenko sniffed out the leak and notified the biz, which said that the exposed archive included records containing names, email addresses, and phone numbers among other things. It is understood hackers accessed the server, scrambled the data, and demanded that Choice pay a ransom of $3,850 or so (depending on the price of Bitcoin) to restore the info. No word on whether that demand will be met.<\/p>\n<p><strong>Dating apps risk hooking up with stalkers:<\/strong> Mobile dating apps are sharing a dangerous amount of personal information with the general public, according to <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.pentestpartners.com\/security-blog\/dating-apps-that-track-users-from-home-to-work-and-everywhere-in-between\/\">a report<\/a> from Pentest Partners.<\/p>\n<p>The Brit infosec outfit estimates as many as 10 million users could be prone to having their whereabouts tracked thanks to the locating features offered by dating apps. As the report notes, this is particularly dangerous for members of the LGBT+ community who could find the tools used to target and harass them. The team recommends developers make the apps less precise in their locations, and give lonely-hearts the ability to tag themselves rather than use GPS.<\/p>\n<div class=\"boxout\" readability=\"11.095477386935\">\n<p><strong>GitLab<\/strong> has pushed out version 12.1.6, 12.0.6, and 11.11.8 of the repository management project, mitigating three critical security flaws, our pals at software-engineering sister site <a target=\"_blank\" href=\"https:\/\/devclass.com\/2019\/08\/15\/gitlab-gets-rid-of-privilege-escalation-vulnerability-with-slew-of-security-releases\/\" rel=\"noopener noreferrer\">DevClass report<\/a>.<\/p>\n<\/div>\n<p><strong>Credit Karma glitch sends strangers&#8217; report data:<\/strong> A website glitch at credit-monitoring service Credit Karma appears to have caused an accidental exposure of some user records. TechCrunch <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/techcrunch.com\/2019\/08\/14\/credit-karma-glitch-accounts\/\">reported<\/a> that a number of users on Reddit and other public forums complained that when they asked for their own credit reports, they were instead shown those of other users on the site. This is annoying on its own, but since we are talking about personal credit reports, it is also an exposure of sensitive personal data.<\/p>\n<p>Credit Karma has since fixed the issue, which sounds like a classic caching cock-up. No word on just how many people had their records shared with strangers.<\/p>\n<p><strong>Lenovo patches EOP bug:<\/strong> Sorry to bear the bad news, but your patching duties might not be done if you use or administer some Lenovo notebooks. The Chinese computing giant <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/support.lenovo.com\/us\/en\/product_security\/LEN-27764\">said that<\/a> it had fixed an information disclosure vulnerability in one of the hardware controllers in Thinkpad notebooks that can potentially lead to firmware tampering and an escalation of privileges. This isn&#8217;t considered a huge risk, as you would have to already be in control of the notebook with an administrator account to exploit the flaw, but it is still worth taking a minute or two to install the fix.<\/p>\n<p><strong>Warren wants probe of Equifax&#8217;s sweetheart settlement:<\/strong> US Senator Elizabeth Warren (D-MA) took some time off the presidential campaign trail to <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.warren.senate.gov\/imo\/media\/doc\/2019.08.13%20Letter%20to%20FTC%20IG%20on%20Equifax%20settlement.pdf\">ask America&#8217;s trade watchdog<\/a> [PDF] why it struck a <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2019\/07\/31\/ftc_equifax_settlement\/\" rel=\"noopener noreferrer\">settlement<\/a> deal with disgraced credit monitor Equifax that was so bad many of the affected can&#8217;t even claim a payout.<\/p>\n<p>&#8220;The FTC has the authority to investigate and protect the public from unfair or deceptive acts or practices, including deceptive advertising,&#8221; Warren writes. &#8220;Unfortunately it appears as though the agency itself may have mislead the American public about the terms of the Equifax settlement and their ability to obtain the full reimbursement to which they are entitled.&#8221;<\/p>\n<p><strong>Danabot malware goes under the microscope:<\/strong> Researchers at Webroot&#8217;s H3 Collective have done <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/h3collective.io\/review-of-a-danabot-infection\/\">a detailed teardown<\/a> of Danabot, an online-bank-account-draining nasty that has been circulating for a little over two years. The dissection found that the malware has not only become more sophisticated in targeting victims for account theft, but may also be used as the first step for ransomware infections.<\/p>\n<p>&#8220;It continues to evolve its geo targets as more affiliates get added, and has branched out to test ransom functionality,&#8221; H3 writes. &#8220;This change in tactics certainly aligns with other shifts we\u2019ve observed in which criminals are performing more recon upfront to profile a victim\u2019s worth before executing ransomware from a domain controller.&#8221;<\/p>\n<p><strong>Saskatoon loses $1m to fraud scam:<\/strong> The city of Saskatoon in Canada has admitted it <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.saskatoon.ca\/news-releases\/city-saskatoon-hit-online-fraud\">was tricked<\/a> by an online fraudster.<\/p>\n<p>Officials say someone contacted one of its offices claiming to be a contractor working on a project for the city. The person asked that the account for an outgoing payment be changed to one controlled by the fraudster. As a result, the city said, CAN$1.04m ($1.15m, \u00a3860,000) in construction bills were sent out to the criminal&#8217;s account rather than the actual contractor.<\/p>\n<p>&#8220;Our focus at this time is on recovery of the funds. We have experts engaged from our internal auditor, the banks affected, and the Saskatoon Police Service,&#8221; said city manager Jeff Jorgenson. &#8220;Additionally we have external and internal experts pouring over financial transactions and processes to do everything reasonably possible to protect the City from any further attacks.&#8221; \u00ae<\/p>\n<p class=\"wptl btm\"><span>Sponsored:<\/span> <a href=\"https:\/\/go.theregister.co.uk\/tl\/1842\/-7432\/balancing-consumerization-and-corporate-control?td=wptl1842\">Balancing consumerization and corporate control<\/a><\/p>\n<p>READ MORE <a href=\"http:\/\/go.theregister.com\/feed\/www.theregister.co.uk\/2019\/08\/19\/security_roundup\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Spec design flaw stiffs security of gizmos Roundup\u00a0 Let&#8217;s run through all the bits and bytes of security news beyond what we&#8217;ve already covered. Also, don&#8217;t forget our articles from this year&#8217;s Black Hat, DEF CON, and BSides Las Vegas conferences in the American desert.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":28535,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-28534","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>KNOB turns up the heat on Bluetooth encryption, hotels leak guest info, city hands $1m to crook, and much, much more 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"KNOB turns up the heat on Bluetooth encryption, hotels leak guest info, city hands $1m to crook, and much, much more 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2019-08-19T10:08:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/08\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"648\" \/>\n\t<meta property=\"og:image:height\" content=\"429\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"KNOB turns up the heat on Bluetooth encryption, hotels leak guest info, city hands $1m to crook, and much, much more\",\"datePublished\":\"2019-08-19T10:08:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\\\/\"},\"wordCount\":1451,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/08\\\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\\\/\",\"name\":\"KNOB turns up the heat on Bluetooth encryption, hotels leak guest info, city hands $1m to crook, and much, much more 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/08\\\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more.jpg\",\"datePublished\":\"2019-08-19T10:08:04+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/08\\\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/08\\\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more.jpg\",\"width\":648,\"height\":429},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"KNOB turns up the heat on Bluetooth encryption, hotels leak guest info, city hands $1m to crook, and much, much more\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"KNOB turns up the heat on Bluetooth encryption, hotels leak guest info, city hands $1m to crook, and much, much more 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\/","og_locale":"en_US","og_type":"article","og_title":"KNOB turns up the heat on Bluetooth encryption, hotels leak guest info, city hands $1m to crook, and much, much more 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2019-08-19T10:08:04+00:00","og_image":[{"width":648,"height":429,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/08\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"KNOB turns up the heat on Bluetooth encryption, hotels leak guest info, city hands $1m to crook, and much, much more","datePublished":"2019-08-19T10:08:04+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\/"},"wordCount":1451,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/08\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\/","url":"https:\/\/www.threatshub.org\/blog\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\/","name":"KNOB turns up the heat on Bluetooth encryption, hotels leak guest info, city hands $1m to crook, and much, much more 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/08\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more.jpg","datePublished":"2019-08-19T10:08:04+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/08\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/08\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more.jpg","width":648,"height":429},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/knob-turns-up-the-heat-on-bluetooth-encryption-hotels-leak-guest-info-city-hands-1m-to-crook-and-much-much-more\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"KNOB turns up the heat on Bluetooth encryption, hotels leak guest info, city hands $1m to crook, and much, much more"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/28534","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=28534"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/28534\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/28535"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=28534"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=28534"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=28534"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}