Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot
    I saved a doomed Windows laptop by embracing Linux

    I saved a doomed Windows laptop by embracing Linux

    April 3, 2026
    Apple’s best product ever

    Apple’s best product ever

    April 3, 2026
    This chatbot can prescribe psych meds. Kind of.

    This chatbot can prescribe psych meds. Kind of.

    April 3, 2026
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » Two students find security bug that could let millions do laundry for free
    News

    Two students find security bug that could let millions do laundry for free

    News RoomBy News RoomMay 19, 20242 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    Two students find security bug that could let millions do laundry for free

    A security lapse could let millions of college students do free laundry, thanks to one company. That’s because of a vulnerability that two University of California, Santa Cruz students found in internet-connected washing machines in commercial use in several countries, according to TechCrunch.

    The two students, Alexander Sherbrooke and Iakov Taranenko, apparently exploited an API for the machines’ app to do things like remotely command them to work without payment and update a laundry account to show it had millions of dollars in it. The company that owns the machines, CSC ServiceWorks, claims to have more than a million laundry and vending machines in service at colleges, multi-housing communities, laundromats, and more in the US, Canada, and Europe.

    CSC never responded when Sherbrooke and Taranenko reported the vulnerability via emails and a phone call in January, TechCrunch writes. Despite that, the students told the outlet that the company “quietly wiped out” their false millions after they contacted it.

    The lack of response led them to tell others about their findings. That includes that the company has a published list of commands, which the two told TechCrunch enables connecting to all of CSC’s network-connected laundry machines. CSC ServiceWorks didn’t immediately respond to The Verge’s request for comment.

    CSC’s vulnerability is a good reminder that the security situation with the internet of things still isn’t sorted out. For the exploit the students found, maybe CSC shoulders the risk, but in other cases, lax cybersecurity practices have made it possible for hackers or company contractors to view strangers’ security camera footage or gain access to smart plugs.

    Often, security researchers find these security holes and report them before they can be exploited in the wild. But that’s not helpful if the company responsible for them doesn’t respond.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleThe Mac Pro and Studio won’t get the M4 nod until mid-2025
    Next Article Elon Musk Finally Puts Twitter Out of Its Misery

    Related Posts

    I saved a doomed Windows laptop by embracing Linux

    I saved a doomed Windows laptop by embracing Linux

    April 3, 2026
    Apple’s best product ever

    Apple’s best product ever

    April 3, 2026
    This chatbot can prescribe psych meds. Kind of.

    This chatbot can prescribe psych meds. Kind of.

    April 3, 2026
    Reddit is moving on from r/all

    Reddit is moving on from r/all

    April 2, 2026
    PSA: Anyone with a link can view your Granola notes by default

    PSA: Anyone with a link can view your Granola notes by default

    April 2, 2026
    AO3 is finally out of beta after 17 years

    AO3 is finally out of beta after 17 years

    April 2, 2026
    Our Picks
    Apple’s best product ever

    Apple’s best product ever

    April 3, 2026
    This chatbot can prescribe psych meds. Kind of.

    This chatbot can prescribe psych meds. Kind of.

    April 3, 2026
    Reddit is moving on from r/all

    Reddit is moving on from r/all

    April 2, 2026
    PSA: Anyone with a link can view your Granola notes by default

    PSA: Anyone with a link can view your Granola notes by default

    April 2, 2026
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    AO3 is finally out of beta after 17 years News

    AO3 is finally out of beta after 17 years

    By News RoomApril 2, 2026

    Archive of Our Own (AO3) is officially exiting beta. The Organization for Transformative Works —…

    New York lawmakers want 3D-printer companies to block the creation of ‘ghost guns’

    New York lawmakers want 3D-printer companies to block the creation of ‘ghost guns’

    April 2, 2026
    The ABS Challenge System is exposing the worst umpire in baseball

    The ABS Challenge System is exposing the worst umpire in baseball

    April 2, 2026
    Pinterest said he violated laid-off colleagues’ privacy. Now he’s going public

    Pinterest said he violated laid-off colleagues’ privacy. Now he’s going public

    April 2, 2026
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2026 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.