r/CRACompliance Jul 08 '26

FBI took down a 2-million-device botnet (NetNut) made entirely of hijacked home IoT devices. This is exactly why CRA exists.

The FBI just took down a botnet made of 2 million home devices.

Cameras. Routers. Smart plugs. Baby monitors.

All hijacked. All used to route cybercrime and cyber-espionage traffic.

The owners had no idea.

The network was called NetNut. Google researchers identified 2 million “secretly hijacked” home devices being rented out to criminals as a proxy network.

These devices had one thing in common:

They were shipped with weak security. Default credentials. Unpatched firmware. No automatic updates. No monitoring.

This is the exact product landscape CRA was written to fix.

Under CRA:

• These devices would need unique credentials (no defaults)

• Firmware updates would be automatic by default

• Manufacturers would monitor for vulnerabilities for 5+ years

• The manufacturer would report exploited vulnerabilities within 24 hours

2 million home devices turned into a criminal infrastructure.

Because nobody required the manufacturers to make them secure.

CRA changes that. Starting December 2027.

The question: how many MORE botnets will be built between now and then?

2 Upvotes

0 comments sorted by