#GoogleFastPair
WhisperPair: un bug critico mette a rischio milioni di dispositivi Bluetooth

📌 Link all'articolo : www.redhotcyber.com/post/whi...

#redhotcyber #news #cybersecurity #hacking #bluetooth #vulnerabilita #googlefastpair #whisperpair
January 19, 2026 at 11:39 AM
Verizon’s $20 Credit After 10-Hour 911 Outage & Google’s Silent Earbud Hack: When Convenience Kills Security
> Verizon’s network crashed for 10 hours — 911 services degraded, $600M lost, and their ‘solution’? A $20 credit. Meanwhile, Google’s Fast Pair bug lets hackers eavesdrop on your earbuds… silently. No password. No alert. Just betrayal. Are your devices safe? #Cybersecurity #VerizonOutage #GoogleFastPair #BluetoothHack #Privacy #SecurityFail ## Verizon’s $20 Band-Aid for a 10-Hour Network Heart Attack A single misconfigured traffic-shaping parameter in Verizon’s 5G Stand-Alone core caused a 10-hour nationwide outage. No hackers. No solar flare. Just a script that said, 'Drop all sessions.' Result? 175K concurrent Downdetector complaints, SOS mode on phones, and 911 centers scrambling. The fix? A $20 credit. Because nothing says 'we care' like a manual billing adjustment. ### How Bad Was It? * **Affected users** : ~2 million (2% of Verizon’s base) * **Downtime** : 10 hours (12 p.m. to 10 p.m. ET) * **Peak complaints** : 175K concurrent (Downdetector) * **Share price drop** : 2% ($39.69) * **Revenue loss estimate** : $500M–$600M * **Emergency impact** : 911 routing degraded; FCC opened investigation ### The $20 Credit Is a Joke (And We Know It) Verizon’s compensation? A $20 credit—auto-applied to _some_ accounts. Half the users had to file claims. That’s not customer service. That’s a delay tactic wrapped in a spreadsheet. AT&T’s 2024 outage affected 92M calls. Verizon’s affected 2M people. Yet only Verizon got an FCC probe. Why? Because 911 didn’t work. And that’s not a billing error—it’s a public safety failure. ### What’s Next? * **FCC rulemaking** : Mandatory 911 isolation (separate hardware path) by Q3 2026. * **Auto-credits** : $20 for ≥4h, $50 for ≥8h—no claims, no delays. * **Canary deployments** : Roll out updates to ≤1% of cells first. Then, if it breaks, only 1% of users cry. * **Public outage dashboard** : Real-time status API. If Downdetector detects it faster than Verizon’s NOC, you’ve already lost. ### The Real Problem Isn’t the Code—It’s the Culture Verizon’s engineers didn’t fail because they were lazy. They failed because the process assumed human perfection. No automated rollback. No synthetic traffic validation. No pre-deployment kill switch. In 2026, deploying core network code without automated health checks is like flying a 747 without autopilot and hoping the co-pilot remembers how to read the altimeter. ### Fix It Like a Telecom, Not a Retailer Stop treating network outages like a coupon campaign. Build redundancy. Isolate emergency traffic. Automate compensation. Publish real-time status. And for heaven’s sake, require two engineers to approve _any_ core change—preferably one who’s had coffee. The $20 credit isn’t a fix. It’s a footnote. The real question: When’s the next one? * * * ## Google’s Fast Pair Bug Lets Hackers Eavesdrop on Your Earbuds — And You Didn’t Even Notice Google’s Fast Pair protocol — the "one-tap" Bluetooth magic that connects your headphones faster than your coffee brews — has a flaw so elegant, it’s almost impressive. CVE-2025-36911, nicknamed "WhisperPair," lets attackers spoof a pairing request. Your earbuds, thinking they’re being paired with your phone, instead accept commands from a nearby attacker. Audio control? Check. Microphone access? Obviously. Silent enrollment into Google’s Find Hub for location tracking? Of course — because why not make your headphones a GPS tracker you didn’t consent to? Affected devices? Hundreds of millions. Sony WH-1000XM6? Vulnerable. JBL Tune 500BT? Yes. Pixel Buds Pro 2? Surprisingly, no — Google’s own hardware got lucky. But most OEMs? They shipped firmware that skipped basic validation. No check for pairing mode. No cryptographic handshake. Just: "Oh, you’re my phone? Cool, here’s my mic." ### What’s Actually Happening? * Attackers within 10 meters send a forged Fast Pair packet. * Device accepts it as legitimate — no user interaction required. * Attacker plays audio, listens via mic, and registers device in Find Hub. * No red flags. No alerts. Just… silence. Google patched it in January 2026. But many OEMs delayed OTA updates. Some devices still run unpatched firmware. And yes — a work-around bypassed the first patch. Google issued a second fix. You’re probably still running the first. ### What Should You Do? 1. Open your phone’s Bluetooth settings. Turn off "Fast Pair" for every device. 2. Open your headphone app. Check firmware version. Update if below 2026.01.20. 3. Go to findmy.google.com. Remove any device you don’t recognize. Yes, even that one you lost in 2023. 4. If you’re in a corporate environment: block Fast Pair advertisements within 15 meters. Seriously. ### The Irony? Google’s "convenience" feature was never designed to be secure — just fast. And now, hundreds of millions of users are living proof that convenience without security is just a Trojan horse with noise-canceling. And if you thought Bluetooth dropouts were just bad signal? Nope. That’s not your router. That’s someone listening to your Zoom call through your AirDots. * * * ### What else is happening? * RustyWater Implant Uses Cloud Identity Compromise and Pipeline Manipulation to Evade Detection, Linked to Muddy Water Threat Actor * ShinyHunters Extort Grubhub After Stealing 1.5B Records; Dark Web Leaks Include Credentials from Salesloft, Zendesk, and Salesforce * Microsoft patches Reprompt attack enabling silent AI chatbot data exfiltration via enterprise bypass * Ransomware groups hit record 124 active actors in 2025, with 1,500+ attacks relying solely on data theft * CastleLoader malware compromises 469 devices targeting US govt and European critical infrastructure * China enforces Xinchuang mandate to replace 100% of foreign cybersecurity vendors by 2027
espresso.cafecito.tech
January 16, 2026 at 1:30 PM
Xiaomi Redmi Buds 6 Lite ハイブリッドANC 40dB 38h再生 GoogleFastPair 急速充電 USB-C 黒 🎧

▼Amazon
商品ページはこちら!
▼Yahooショッピング
商品ページはこちら!
▼メルカリ
商品ページはこちら!

#RedmiBuds6Lite #PR #フォロバ100
September 26, 2025 at 4:30 AM
交換してもらいましたが1日で症状再発ですね…
調べたらBoseアプリが悪いとか色々あったけどとりあえずGoogleFastPairを無効化して様子見かな
October 28, 2024 at 7:04 AM
New research reveals “WhisperPair,” a flaw that lets hackers hijack Google Fast Pair devices in seconds. Affected brands include Sony, JBL, Nothing, and OnePlus. The bug enables tracking and mic access.

itmatterss.in/global/googl...

#GoogleFastPair #Bluetooth #CyberSecurity
Google Fast Pair Hit by WhisperPair Hack: What You Can Do to Protect Your Headphones
WhisperPair exposes a flaw in Google Fast Pair that lets hackers hijack Bluetooth accessories in seconds. Learn what’s affected.
itmatterss.in
January 16, 2026 at 8:30 AM
小米14系列新增超低功耗協處理器支援CHRE,大幅提升Fast Pair響應速度!即使螢幕關閉也能持續掃描藍牙裝置,不影響續航。這項技術為未來新增更多高階功能鋪平道路,如車禍檢測等。想了解更多細節和潛在影響,快來評論區點選閱讀完整報道吧!
https://biggo.com.tw/news/202410221801_Xiaomi_Enhances_Fast_Pair

#小米14 #GoogleFastPair
October 22, 2024 at 6:34 PM
"One Tap to Hijack Them All: A Security Analysis of the Google Fast Pair Protocol" (Sayon Duttagupta, Seppe Wyns, Nikola Antonijević, Dave Singelée, Bart Preneel) was presented at the IEEE S&P 2026 conference in San Francisco.
#whisperpair #bluetooth #googlefastpair #ieeesp
May 21, 2026 at 8:06 AM
XiaomiRedmibuds6Play36時間再生AIノイズリダクション低遅延超軽量GoogleFastPair対応急速充電ブラック🎧

▼Amazon
商品ページはこちら!
▼メルカリ
商品ページはこちら!

#RedmiBuds6Play #PR #フォロバ100
December 6, 2025 at 1:36 PM
Google Fast Pairの脆弱性「WhisperPair」で、SonyやJBLなど主要ブランドのワイヤレスイヤホンが盗聴・位置追跡のリスクに。KU Leuven大学が発見、ファームウェア更新が急務です。詳細はコメント欄のリンクから。
https://biggo.jp/news/202601160022_Google-Fast-Pair-Vulnerability-Headphones-Security

#GoogleFastPair #Bluetoothセキュリティ
January 16, 2026 at 12:50 AM
你的藍牙耳機可能正被陌生人監聽與追蹤!研究證實Sony、JBL等12大品牌耳機存有安全漏洞。
https://biggo.com.tw/news/202601160022_Google-Fast-Pair-Vulnerability-Headphones-Security

#GoogleFastPair #藍牙安全漏洞
January 16, 2026 at 12:50 AM