The Connected Home Is Under Siege

The Connected Home Is Under Siege: Australia’s 29-A-Day Cybersecurity Wake-Up Call

Surprisingly Useful AI Article Enhancements

Australians have long embraced the benefits of smart technology. But behind every connected device, from the smart TV in your living room to the inverter on your solar panel, is a potential access point for attackers. According to Bitdefender’s new 2025 IoT Security Landscape Report, the average Australian household is now hit by 29 cyberattacks per day. That’s up nearly threefold from 2024, and it’s not just a case of more devices attracting more attention. It’s a sign that adversaries are evolving faster than our security habits.

The data tells a clear and urgent story. Bitdefender analysed threat intelligence from more than 6.1 million homes globally, including thousands in Australia, and found that many smart devices are running on insecure firmware or remain unpatched for months – sometimes years – after vulnerabilities are made public. That’s a recipe for systemic exploitation.

Australia isn’t just an early adopter of smart home tech; it’s a leader in smart device adoption. With 22 connected devices per household on average, Australians have among the highest device densities in the world. But security hasn’t kept pace with enthusiasm. Our research shows that more than 99 per cent of exploits target known and already-fixed vulnerabilities. This means that these aren’t novel, undetectable threats, they are opportunistic attacks targeting preventable weaknesses.

Smart TVs, IP cameras, and streaming devices made up the bulk of vulnerable endpoints in 2025, accounting for over 55 per cent of all observed IoT weaknesses. These are devices many Australians rely on every day. Yet they often lack user-friendly update mechanisms, or worse, are unsupported altogether once they leave the factory.

Perhaps the most unsettling discovery in this year’s report is BadBox, a China-based botnet that managed to infect more than one million Android devices before they even reached store shelves. Pre-installed malware is no longer rare, but an emerging attack that bypasses user vigilance entirely. And while the FBI has issued warnings in the US, I believe that Australia needs a tighter regulatory stance to prevent these devices from reaching consumers in the first place.

From a security perspective, BadBox represents a troubling shift: when attackers compromise the supply chain, consumers can no longer be expected to ‘secure their devices’ through traditional means. The threat becomes embedded.

From Private Risk To Public Threat

It’s tempting to view IoT risks as personal inconveniences, privacy intrusions, and financial theft. But in 2025, we’re seeing how vulnerable interconnected devices can create repercussions on a national scale.

One of the most sobering insights from our report involves an unsuspecting type of device, solar inverters, which convert electricity from solar panels into usable power. Our researchers found that thousands of these inverters are accessible via the open internet due to insecure configurations and outdated firmware. If hijacked in sufficient numbers, they could be weaponised to destabilise power grids through coordinated pushes and pulls of energy.

For a country like Australia, where rooftop solar is ubiquitous, this presents a new kind of threat: consumer-grade devices being chained into attacks with infrastructure-scale consequences. It’s a stark reminder that the definition of ‘critical infrastructure’ is evolving.

Most of today’s IoT threats rely on simple scripts that scan for known vulnerabilities, default passwords, or exposed ports. In many cases, these attacks can compromise devices in seconds. Once inside, attackers can pivot, for example, turning a smart TV into a surveillance tool, or leveraging your router to launch DDoS attacks like the 22.2 tb/s event that made headlines this year.

For businesses, this means that every unsecured home device in an employee’s house can become a potential backdoor. For individuals, it means that what you watch or say in your living room may not be as private as you think.

A Call For Collective Responsibility

While there’s no single fix for the rising tide of IoT attacks, there are clear places to start.

For consumers, changing default passwords, disabling remote access when not needed, and applying firmware updates regularly might seem tedious, but it’s now part of digital hygiene.

Manufacturers must ensure that security is embedded, not simply bolted on. Devices should be designed with updateability, visibility, and resilience in mind. Those that cannot be patched should not be sold.

Security providers also play a crucial role in helping close the gap between risk and user behaviour. Bitdefender, for example, works with infrastructure manufacturers like Netgear to integrate threat prevention directly into home networks through systems like Netgear Armor, a built-in security platform that identifies vulnerabilities, blocks known and emerging threats, and protects households from phishing, data theft, and other attacks. These types of behind-the-scenes protections will be essential as the average household becomes more complex and harder to manage manually.

From a policy perspective, exploring initiatives similar to the US Cyber Trust Mark could help consumers more easily identify secure-by-design devices. Better labelling, minimum standards, and tighter supply chain scrutiny are needed.

What Comes Next

IoT has delivered tremendous convenience but also created one of the largest attack surfaces in history. In 2025, smart homes are being turned into staging grounds for mass-scale attacks. What we once saw as fringe threats, like hijacked baby monitors or snooped smart speakers, have become everyday realities.

The good news is that we’re not helpless. As an industry, we have the tools to secure this ecosystem. As individuals, we have the power to demand better defaults, better design, and better accountability.

Australians have the opportunity to lead by acting decisively now, not just to protect their homes, but to also help define what a secure digital society looks like in this new IoT age.

Bogdan Botezatu is Senior Director, Threat Research and Reporting at Bitdefender.

Last Updated on December 1, 2025 by Bogdan Botezatu

Surprisingly Useful AI Article Enhancements

Sign-up to the SMBtech Daily Newsletter

We will not spam you. You can easily unsubscribe any time. Read our privacy policy.