AnyCubic has released new Kobra 2 firmware to fix a zero-day vulnerability that was exploited last month to print security warnings on 3D printers worldwide.
See also: Anycubic 3D printers hacked worldwide

At the end of February, AnyCubic printer users began reporting that their Kobra 3Dhad been compromisedafter devices printed a warning that their printers were vulnerable to a critical zero-day vulnerability.
This vulnerability allowed attackers to abuse insecure permissions in the company's MQTT service API to send commands to the printer.
This allowed the attacker to request a G-code file named 'hacked_machine_readme.gcode,' which, when opened in a text editor, contained a warning that a critical vulnerability had affected the printers.
“ Your machine has a critical vulnerability, which poses a significant threat to your security. Immediate action is recommended to prevent potential exploitation ,” the text file says
The researchers claim that they had emailed AnyCube three times about the vulnerability and were ignored, which led them to take the unconventional approach of exploiting the zero-day to publicly warn printer owners.
See also: HP Printers: No more third-party ink cartridges

AnyCubic releases security update
On March 5, AnyCubic released new firmware for its Kobra 2 Pro/Plus/Max 3D printers with a fix for this zero-day vulnerability.
To address the issue, AnyCubic says it has strengthened the security of authentication and permission/rights management in its MQTT server, which was abused to send warnings to printers.
The company says it plans to implement the following security measures in future firmware updates, with the next one scheduled for March 13.
- Implementing network segmentation measures to limit external access to services.
- Performing regular checks and updates for systems, software and the MQTT server.
For those who feel insecure about printers accessing AnyCubic's cloud service, the company provides instructions on how to disable WiFi via the printer's display. While AnyCubic apologizes for the incident, they have yet to explain why three emails sent by security researchers over the past two months were ignored.
See also: Bambu Lab recalls all A1 3D Printers

What are the basic protection measures against a Zero-Day?
One of the key measures to protect against a Zero-Day, such as the one affecting AnyCubic printers, is to keep your software up to date. Software companies are constantly patching vulnerabilities in products , so it is important to update your software regularly to protect your system from the latest threats. The second measure is to use security software. A reliable security program can protect your computer from most forms of malware, including zero-day attacks. User education is also crucial. Finally, using the principle of least privilege can be very effective. This means that users should only have the rights they need to perform their tasks, thus limiting the number of systems that can be affected by an attack.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
