{"id":41367,"date":"2021-06-16T13:43:52","date_gmt":"2021-06-16T13:43:52","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/32384\/Peloton-Bike-Was-Vulnerable-To-Remote-Hacking-Researchers-Find.html"},"modified":"2021-06-16T13:43:52","modified_gmt":"2021-06-16T13:43:52","slug":"peloton-bike-was-vulnerable-to-remote-hacking-researchers-find","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\/","title":{"rendered":"Peloton Bike+ Was Vulnerable To Remote Hacking, Researchers Find"},"content":{"rendered":"<figure class=\"sc-1eow4w5-1 dhDQnh align--bleed js_lazy-image js_marquee-assetfigure\" data-id=\"e34f0b3deb7f22c7781a7664a295b724\" data-recommend-id=\"image:\/\/e34f0b3deb7f22c7781a7664a295b724\" data-format=\"jpg\" data-width=\"1315\" data-height=\"740\" data-lightbox=\"true\" data-alt=\"Peloton Bike in front of the Peloton Studio in New York City\" data-recommended=\"false\" contenteditable=\"false\" draggable=\"false\">\n<div class=\"sc-1eow4w5-2 loxZOX img-wrapper\" contenteditable=\"false\" data-alt=\"Peloton Bike in front of the Peloton Studio in New York City\" data-syndicationrights=\"true\" data-imagerights=\"getty\" data-hidecredit=\"false\"><span class=\"sc-1eow4w5-0 dnhHtZ js_lightbox-wrapper\"><\/p>\n<div class=\"sc-1eow4w5-3 lktKQM image-hydration-wrapper\">\n<div><img decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Peloton Bike in front of the Peloton Studio in New York City\" data-expanded-srcset=\"https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,fl_progressive,g_center,h_80,pg_1,q_80,w_80\/e34f0b3deb7f22c7781a7664a295b724.jpg 80w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_140\/e34f0b3deb7f22c7781a7664a295b724.jpg 140w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_265\/e34f0b3deb7f22c7781a7664a295b724.jpg 265w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_340\/e34f0b3deb7f22c7781a7664a295b724.jpg 340w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_490\/e34f0b3deb7f22c7781a7664a295b724.jpg 490w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_645\/e34f0b3deb7f22c7781a7664a295b724.jpg 645w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_740\/e34f0b3deb7f22c7781a7664a295b724.jpg 740w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_965\/e34f0b3deb7f22c7781a7664a295b724.jpg 965w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_1165\/e34f0b3deb7f22c7781a7664a295b724.jpg 1165w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_1315\/e34f0b3deb7f22c7781a7664a295b724.jpg 1315w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_1465\/e34f0b3deb7f22c7781a7664a295b724.jpg 1465w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,g_center,pg_1,q_60,w_1600\/e34f0b3deb7f22c7781a7664a295b724.jpg 1600w\" sizes=\" (max-width: 25em) calc(100vw - 32px), (max-width: 37.31em) calc(100vw - 32px), (min-width: 37.37em) and (max-width: 49.94em) calc(100vw - 32px), (min-width: 50em) and (max-width: 63.69em) 800px, (min-width: 63.75em) and (max-width: 85.19em) calc(66.5vw - 32px), 800px \" draggable=\"auto\" data-chomp-id=\"e34f0b3deb7f22c7781a7664a295b724\" data-format=\"jpg\" data-alt=\"Peloton Bike in front of the Peloton Studio in New York City\" data-anim-src srcset=\"https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fill,f_auto,fl_progressive,g_center,h_80,pg_1,q_80,w_80\/e34f0b3deb7f22c7781a7664a295b724.jpg 80w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,fl_progressive,q_80,w_320\/e34f0b3deb7f22c7781a7664a295b724.jpg 320w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_fit,f_auto,fl_progressive,pg_1,q_80,w_470\/e34f0b3deb7f22c7781a7664a295b724.jpg 470w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_scale,f_auto,fl_progressive,pg_1,q_80,w_800\/e34f0b3deb7f22c7781a7664a295b724.jpg 800w, https:\/\/i.kinja-img.com\/gawker-media\/image\/upload\/c_scale,f_auto,fl_progressive,pg_1,q_80,w_1600\/e34f0b3deb7f22c7781a7664a295b724.jpg 1600w\"><\/div>\n<\/div>\n<p><\/span><figcaption class=\"sc-7s1ndr-0 bRZZJw no-caption\">Photo<!-- -->: <!-- -->Scott Heins\/Stringer<!-- --> (<!-- -->Getty Images<!-- -->)<\/figcaption><\/div>\n<p><span data-id=\"e34f0b3deb7f22c7781a7664a295b724\" data-recommend-id=\"image:\/\/e34f0b3deb7f22c7781a7664a295b724\" data-format=\"jpg\" data-width=\"1315\" data-height=\"740\" data-lightbox=\"true\" data-alt=\"Peloton Bike in front of the Peloton Studio in New York City\" data-recommended=\"false\" class=\"js_recommend\"><\/span><\/figure>\n<p class=\"sc-77igqf-0 bOfvBY\">Following news that Peloton\u2019s API <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;Internal link&quot;,&quot;https:\/\/gizmodo.com\/peloton-api-exposed-user-data-even-for-private-account-1846826991&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/gizmodo.com\/peloton-api-exposed-user-data-even-for-private-account-1846826991\">exposed private user account data<\/a><\/span>, McAfee\u2019s Advanced Threat Research team says the <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;Internal link&quot;,&quot;https:\/\/gizmodo.com\/i-love-this-bike-so-much-1845891832&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/gizmodo.com\/i-love-this-bike-so-much-1845891832\">Bike+<\/a><\/span> had a dangerous flaw that could enable hackers to invisibly and remotely gain control of bikes. <\/p>\n<div id class=\"bxm4mm-11 gamHXh js_ad-mobile-dynamic js_ad-dynamic ad-mobile-dynamic movable-ad\">\n<div class=\"bxm4mm-12 iqioLK ad-unit ad-mobile\">\n<p>Advertisement<\/p>\n<\/div>\n<\/div>\n<p class=\"sc-77igqf-0 bOfvBY\">McAfee says its researchers began poking around Peloton\u2019s systems once the workout-at-home trend took off during the pandemic. In the process, they found that the Bike+ software wasn\u2019t verifying whether the device\u2019s bootloader was unlocked, enabling them to upload a custom image that wasn\u2019t meant for Peloton hardware. After downloading an official Peloton update package, the researchers were then able to modify Peloton\u2019s actual boot image and gain root access to the bike\u2019s software. The Android Verified Boot process wasn\u2019t able to detect that the image had been tampered with. <\/p>\n<p class=\"sc-77igqf-0 bOfvBY\">Or put more simply, a hacker could use a USB key to upload a fake boot image file that grants them access to a bike remotely without a user ever knowing. That hacker can then install and run programs, modify files, harvest login credentials, intercept encrypted internet traffic, or spy on users through the bike\u2019s camera and microphone. <\/p>\n<p class=\"sc-77igqf-0 bOfvBY\">This vulnerability may not sound all that serious for home users, as it requires physical access to the Bike+ to pull off. However, McAfee says that a bad actor could load the malware at any point during construction, at a warehouse, or in the delivery process. The original <!-- -->Peloton bikes are also popular fixtures at gyms and fitness centers in hotels and apartment buildings\u2014an area that the company is keen to expand in. Peloton dropped <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;Internal link&quot;,&quot;https:\/\/gizmodo.com\/maybe-now-peloton-orders-wont-take-so-long-1845933064&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/gizmodo.com\/maybe-now-peloton-orders-wont-take-so-long-1845933064\">$420 million to acquire Precor<\/a><\/span> in December, and a big reason why is that Precor had an extensive commercial network that includes hotels, corporate campuses, colleges, and apartment complexes. The Bike+ may not be commercially available at the moment<!-- -->, but that doesn\u2019t mean they won\u2019t be in the future.<\/p>\n<p class=\"sc-77igqf-0 bOfvBY\">Peloton reportedly patched the issue on June 4 during the <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/support.onepeloton.com\/hc\/en-us\/articles\/360024551291-Security-Compliance&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/support.onepeloton.com\/hc\/en-us\/articles\/360024551291-Security-Compliance\" target=\"_blank\" rel=\"noopener noreferrer\">disclosure window<\/a><\/span>, and there are no indications the vulnerability has been exploited in the wild. The company also confirmed that the flaw was also found on the Peloton Tread, which was <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;Internal link&quot;,&quot;https:\/\/gizmodo.com\/holy-hell-peloton-is-recalling-both-its-treadmills-1846827897&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/gizmodo.com\/holy-hell-peloton-is-recalling-both-its-treadmills-1846827897\">recalled last month<\/a><\/span> along with the Peloton Tread+.<\/p>\n<div class=\"bxm4mm-19 fIUNXF\" readability=\"2.3142857142857\">\n<div class=\"sc-1atgi65-0 sc-1atgi65-1 bdNdA-D js_commerce-inset-permalink\" data-inset-url=\"https:\/\/go.linkby.com\/YMTUOZML\" data-inset-category=\"CommerceInsetMobile\" readability=\"2.7\">\n<p>G\/O Media may get a commission<\/p>\n<\/div>\n<\/div>\n<p class=\"sc-77igqf-0 bOfvBY\">This is usually the point where we tell you to go and make sure you have the most recent firmware update\u2014which you can do <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/support.onepeloton.com\/hc\/en-us\/articles\/4402287359380-How-Do-I-Verify-That-I-Have-The-Latest-System-Updates-&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/support.onepeloton.com\/hc\/en-us\/articles\/4402287359380-How-Do-I-Verify-That-I-Have-The-Latest-System-Updates-\" target=\"_blank\" rel=\"noopener noreferrer\">following these instructions<\/a><\/span>. That said,<!-- --> the company doesn\u2019t publicize software release notes. It\u2019s an omission that Peloton should perhaps fix, considering how <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;Internal link&quot;,&quot;https:\/\/gizmodo.com\/how-smartwatches-workout-apps-and-connected-bikes-dom-1845926648&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/gizmodo.com\/how-smartwatches-workout-apps-and-connected-bikes-dom-1845926648\">popular connected fitness has become<\/a><\/span> in the past year. In cases like these, it\u2019s a good idea to enable automatic updates if possible. Another thing to keep in mind is Peloton prohibits users from downloading other apps, such as Netflix or Spotify, onto its bikes and treadmills. (Though there are <span><a class=\"sc-1out364-0 hMndXN sc-145m8ut-0 kVnoAv js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/www.theverge.com\/2019\/8\/14\/20801983\/youtube-plex-web-browser-peloton-bike-treadmill-how-to-watch&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/www.theverge.com\/2019\/8\/14\/20801983\/youtube-plex-web-browser-peloton-bike-treadmill-how-to-watch\" target=\"_blank\" rel=\"noopener noreferrer\">ways to get around that<\/a><\/span>.) So, if you ever happen to be on a public Peloton and it has other apps&#8230; you probably shouldn\u2019t use it.<\/p>\n<p class=\"sc-77igqf-0 bOfvBY\"><strong>Update, 06\/16\/2021, 8:40 am:<\/strong> Clarified that only original Peloton bikes are currently found in commercial settings. An earlier version of this article noted that it wasn\u2019t easy to check Peloton updates; we\u2019ve since<!-- --> added a <!-- -->link on how to<!-- --> verify you have the <!-- -->latest Peloton updates. We regret the error.<\/p>\n<div id class=\"bxm4mm-11 gamHXh js_ad-mobile-dynamic js_ad-dynamic ad-mobile-dynamic movable-ad\">\n<div class=\"bxm4mm-12 iqioLK ad-unit ad-mobile\">\n<p>Advertisement<\/p>\n<\/div>\n<\/div>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/32384\/Peloton-Bike-Was-Vulnerable-To-Remote-Hacking-Researchers-Find.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":41368,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[256],"class_list":["post-41367","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinehackerflaw"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Peloton Bike+ Was Vulnerable To Remote Hacking, Researchers Find 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Peloton Bike+ Was Vulnerable To Remote Hacking, Researchers Find 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-16T13:43:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/06\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find.gif\" \/>\n\t<meta property=\"og:image:width\" content=\"1\" \/>\n\t<meta property=\"og:image:height\" content=\"1\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/gif\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Peloton Bike+ Was Vulnerable To Remote Hacking, Researchers Find\",\"datePublished\":\"2021-06-16T13:43:52+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\\\/\"},\"wordCount\":570,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find.gif\",\"keywords\":[\"headline,hacker,flaw\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\\\/\",\"name\":\"Peloton Bike+ Was Vulnerable To Remote Hacking, Researchers Find 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find.gif\",\"datePublished\":\"2021-06-16T13:43:52+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find.gif\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find.gif\",\"width\":1,\"height\":1},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,flaw\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackerflaw\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Peloton Bike+ Was Vulnerable To Remote Hacking, Researchers Find\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Peloton Bike+ Was Vulnerable To Remote Hacking, Researchers Find 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\/","og_locale":"en_US","og_type":"article","og_title":"Peloton Bike+ Was Vulnerable To Remote Hacking, Researchers Find 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-06-16T13:43:52+00:00","og_image":[{"width":1,"height":1,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/06\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find.gif","type":"image\/gif"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Peloton Bike+ Was Vulnerable To Remote Hacking, Researchers Find","datePublished":"2021-06-16T13:43:52+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\/"},"wordCount":570,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/06\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find.gif","keywords":["headline,hacker,flaw"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\/","url":"https:\/\/www.threatshub.org\/blog\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\/","name":"Peloton Bike+ Was Vulnerable To Remote Hacking, Researchers Find 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/06\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find.gif","datePublished":"2021-06-16T13:43:52+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/06\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find.gif","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/06\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find.gif","width":1,"height":1},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/peloton-bike-was-vulnerable-to-remote-hacking-researchers-find\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,flaw","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackerflaw\/"},{"@type":"ListItem","position":3,"name":"Peloton Bike+ Was Vulnerable To Remote Hacking, Researchers Find"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/41367","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=41367"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/41367\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/41368"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=41367"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=41367"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=41367"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}