Researchers at NSB Cyber and Abstract Shield found more than a dozen security and privacy flaws affecting two low-cost smart-glasses products, their companion application, and an associated website. The most serious issue, unauthenticated Bluetooth pairing, could let a nearby attacker connect to powered-on, unpaired glasses, take photos or recordings, copy stored media, intercept traffic between the device and phone, or impersonate the glasses in the owner’s app. A Bluetooth-visible device identifier combined with a website weakness could also reveal a user’s email address and date of birth.
The researchers reported that voice, text, image, and other AI inputs were transmitted to a server in Shenzhen and could be forwarded onward; their analysis indicated Chinese sovereign AI models may be involved. The findings add to wider privacy concerns around camera-equipped smart glasses, including facial-recognition capabilities, and may raise obligations under Australian privacy law and the Cyber Security Act. Whether the products are subject to Australia’s smart-device security standards depends partly on whether they were manufactured on or after 4 March 2026.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
After ABC News shared the researchers' findings, HeyCyan developers reportedly attempted to patch some of the identified security issues. Most of the vulnerabilities reportedly remained unaddressed.
NSB Cyber and Abstract Shield identified more than a dozen security and privacy issues in two inexpensive smart-glasses products, their companion app, and an associated website. The findings included unauthenticated Bluetooth pairing, potential access to recordings and stored media, exposure of personal data through a device identifier and website weakness, and AI inputs sent to a Shenzhen server.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalwarebytes.com
Open sourceabc.net.au
Open sourcemalwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.