<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Iot on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/iot/</link><description>Recent content in Iot on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 03 Jun 2026 21:15:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/iot/index.xml" rel="self" type="application/rss+xml"/><item><title>AWS IoT Device Management MQTT Session Data API</title><link>https://zxcloudsecurity.co.uk/posts/aws-iot-device-management-mqtt-session-connectivity-api/</link><pubDate>Wed, 03 Jun 2026 21:15:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/aws-iot-device-management-mqtt-session-connectivity-api/</guid><description>AWS IoT Device Management adds MQTT session and socket data to its connectivity API. Learn the IAM controls and security implications for IoT fleets.</description><content:encoded><![CDATA[<p>🟢 <strong>Low</strong>  |  <strong>Source:</strong> <a href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-iot-device-management-mqtt/">AWS What&rsquo;s New</a></p>
<hr>
<p>AWS IoT Device Management has enhanced its connectivity status API to include detailed MQTT session data, such as session timeout and expiry values, plus optional socket-level details including IP addresses, ports, and VPC endpoint IDs. Unlike the IoT Core GetConnection API, which only retains data for 30 minutes post-disconnect, this API stores connection history indefinitely. This is useful for security auditing, forensic investigation of disconnect events, and monitoring connection patterns across large IoT fleets.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review and tighten IAM policies controlling access to the new socket-level details (source/destination IPs, ports, VPC endpoint IDs), as this data could aid lateral movement reconnaissance if exposed to over-privileged roles. Use the indefinite data retention capability to feed IoT connectivity logs into your SIEM for anomaly detection and post-incident forensics.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-iot-device-management-mqtt/">AWS IoT Device Management adds MQTT session data to connectivity status API</a></p>
]]></content:encoded></item><item><title>AWS IoT Device Management: MQTT Session Data in API</title><link>https://zxcloudsecurity.co.uk/posts/aws-iot-device-management-mqtt-session-data-connectivity-status-api/</link><pubDate>Wed, 03 Jun 2026 21:15:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/aws-iot-device-management-mqtt-session-data-connectivity-status-api/</guid><description>AWS IoT Device Management adds MQTT session data to its connectivity status API, with indefinite retention and IAM-controlled socket-level access for IoT f</description><content:encoded><![CDATA[<p>🟢 <strong>Low</strong>  |  <strong>Source:</strong> <a href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-iot-device-management-mqtt/">AWS What&rsquo;s New</a></p>
<hr>
<p>AWS IoT Device Management has enhanced its connectivity status API to include detailed MQTT session data, such as session timeout and expiry values, plus optional socket-level details including IP addresses, ports, and VPC endpoint IDs. Unlike the AWS IoT Core GetConnection API, which only retains data for 30 minutes post-disconnect, this API stores connection history indefinitely, improving long-term auditability. Access to sensitive socket-level information is controlled via IAM policies, allowing organisations to limit visibility to authorised teams.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review and tighten IAM policies governing access to the connectivity status API, particularly the socket-level data permissions, to ensure only operations and security teams have visibility into source/destination IPs and VPC endpoint IDs. Additionally, consider integrating the indefinite data retention capability into your IoT incident response and audit workflows to leverage historical disconnect data for forensic investigations.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-iot-device-management-mqtt/">AWS IoT Device Management adds MQTT session data to connectivity status API</a></p>
]]></content:encoded></item><item><title>Curved Radio Beams Can Defeat Anti-Jamming Systems</title><link>https://zxcloudsecurity.co.uk/posts/curved-radio-beams-defeat-anti-jamming-technology-wireless-security/</link><pubDate>Wed, 03 Jun 2026 20:57:39 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/curved-radio-beams-defeat-anti-jamming-technology-wireless-security/</guid><description>Rice University researchers show that bending radio signals defeats direction-finding anti-jamming tech, posing risks to wireless and IoT infrastructure.</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/networks/2026/06/03/curving-beams-could-fool-anti-jamming-tech/5250872">The Register — Security</a></p>
<hr>
<p>Researchers at Rice University have demonstrated that curving or bending radio beams can defeat anti-jamming systems that rely on locating the source of interference. Because the signal no longer travels in a straight line, direction-finding techniques used to identify and counter jammers become ineffective. This has implications for any wireless communication infrastructure, including those supporting cloud-connected IoT, satellite links, and enterprise wireless networks.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Cloud architects relying on wireless backhaul, satellite connectivity, or IoT sensor networks should review their signal resilience strategy — consider whether your anti-jamming or interference-detection controls assume line-of-sight propagation, and engage your network security team to assess whether alternative detection methods (e.g. signal fingerprinting or multi-point triangulation) are in scope.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/networks/2026/06/03/curving-beams-could-fool-anti-jamming-tech/5250872">Bend the beam like Beckham to defeat anti-jamming tech</a></p>
]]></content:encoded></item></channel></rss>