ZoomEye Finds 2.7 Million Home Assistant Instances Exposed on Public Internet
A ZoomEye fingerprint search conducted on September 23, 2026, identified approximately 2.71 million publicly reachable Home Assistant installations, highlighting the scale of consumer automation platforms exposed beyond their intended private-network boundaries. Home Assistant is a local-first smart home platform designed to operate without internet connectivity, typically running on a small in-home device managing lights, locks, cameras, and thermostats. Security concerns arise because many installations may lack multi-factor authentication or rely on simple port forwarding rather than a VPN or managed tunnel, leaving login interfaces directly accessible from the internet. Long-lived API access tokens, which carry no built-in expiry, compound the risk as they are rarely audited after initial setup, and installed add-ons can extend attacker reach to the underlying host operating system. Experts recommend verifying whether installations appear in public indexes, enforcing authenticated access paths, enabling multi-factor authentication, and regularly reviewing issued tokens and trusted-network configurations.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in