<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Flow Neuroscience - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/flow-neuroscience/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 13 Aug 2026 16:52:34 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/flow-neuroscience/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Hard-coded Authentication Credentials in Flow Neuroscience FL-100</title><link>https://feed.craftedsignal.io/briefs/2026-08-flow-neuroscience-hardcoded-creds/</link><pubDate>Thu, 13 Aug 2026 16:52:34 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-flow-neuroscience-hardcoded-creds/</guid><description>Flow Neuroscience FL-100 and Halo Neuroscience FL-100 devices contain a hard-coded credential vulnerability that allows an attacker within Bluetooth range to manipulate brain stimulation parameters and bypass safety controls.</description><content:encoded><![CDATA[<p>Flow Neuroscience has identified a critical security vulnerability, CVE-2026-18164, affecting the FL-100 brain stimulation medical device. The vulnerability is rooted in the use of hard-coded credentials that are shared across all device units. An attacker positioned within Bluetooth range of a vulnerable device can leverage these credentials to bypass authentication mechanisms. Once authenticated, the attacker can manipulate brain stimulation parameters and override safety limit thresholds. This flaw poses a significant risk to the health and safety of patients, as the unauthorized modification of device output could result in unintended medical impact. The issue affects all Flow Neuroscience FL-100 and Halo Neuroscience FL-100 devices with firmware versions released prior to July 2026. Defenders should prioritize applying the vendor-supplied firmware updates via the official mobile application to remediate this authentication bypass.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthorized control over medical device settings by an actor within physical Bluetooth range. While there are no reports of active exploitation in the wild, the potential impact includes physical harm to patients due to the manipulation of brain stimulation levels and the disabling of device-level safety overrides. The vulnerability is classified as high-severity, impacting both the Flow Neuroscience and Halo Neuroscience product lines worldwide.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Ensure all affected Flow Neuroscience FL-100 and Halo Neuroscience FL-100 units are updated to the latest firmware version released by the manufacturer after July 2026 via the Flow app.</li>
<li>Implement physical access controls and security awareness training to limit unauthorized proximity to medical devices in healthcare settings.</li>
<li>Monitor for unauthorized Bluetooth pairing attempts or abnormal device management activity in environments where these units are deployed.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category></item></channel></rss>