I don't understand how they can scan IoT devices if IoT devices are behinds a router which is usually our home network setup. So we will expose a public IP, and NAT is usually not enabling by default anyway so how the heck they can telnet/connect to the IoT devices to brute force password?
It seems like somehow we