All Events

« All Events

  • This event has passed.

Talk: Wand Protocol — A Full-Chain Security Assessment of an FDA-Listed Fertility Hormone Analyzer (hybrid/Boston)

September 17 @ 2:00 pm 4:00 pm EDT

This hybrid talk (via Teams and on the Boston campus) will present a coordinated vulnerability disclosure involving an FDA-listed fertility hormone analyzer, its mobile app, and its cloud infrastructure. The assessment identified vulnerabilities across three attack surfaces: an unauthenticated Bluetooth Low Energy connection enabling device impersonation and the injection of fabricated hormone readings; publicly accessible production firmware; and a hardcoded third-party API key that could expose sensitive health-profile data associated with approximately 659,000 accounts.

The researchers also observed health-related data being transmitted to analytics and advertising SDKs, although this represents an identified data flow rather than a confirmed breach. The seminar will include a live demonstration of the device-impersonation attack, examine the gap between FDA listing and cybersecurity assurance, and present recommended mitigations.

All research was conducted using researcher-owned devices and accounts. The findings were disclosed to the manufacturer, the FDA Center for Devices and Radiological Health, and CISA before this presentation.

Speakers

Gigi Xiaoqing Liu is a Northeastern graduate researcher specializing in embedded systems, medical-device security, and AI security. Her experience includes wireless and mobile reverse engineering, binary exploitation, and cloud security.

En Mong (Lucas) is an MS Cybersecurity student and medical-device security researcher at Northeastern. His work spans BLE analysis, firmware reverse engineering, endpoint security, and vulnerability management. He contributed to research resulting in eight CVEs and a CISA medical advisory.

Muzzammil Mohammed is a Northeastern MS Cybersecurity graduate, offensive security researcher, and penetration tester. A core developer of the WandKit BLE auditing toolkit, he specializes in cloud API exploitation, authentication bypasses, and AI-assisted security auditing.

Narmina Karimova is a Northeastern cybersecurity graduate researcher with experience in enterprise technology at financial institutions and the United Nations. She developed the project’s Python-based BLE attack suite, reverse-engineered the Android application, uncovered hardcoded credentials, and confirmed a critical authorization vulnerability involving sensitive health data.

366 West Village H

440 Huntington Avenue
Boston, MA 02115 United States
+ Google Map

Audience

Current Master’s Students, Faculty and Research