Author: Osiris

  • IQSIGHT Names Michael Schulte Chief Executive Officer

    IQSIGHT Names Michael Schulte Chief Executive Officer

    IQSIGHT, the video security business formerly known as Bosch Video Systems, has appointed Michael J. Schulte as chief executive officer, effective Sept. 1, 2026. Schulte will lead the company’s global operations and report to Chairman Steve Shine.

    A Veteran Operator Takes the Helm

    Schulte brings more than 30 years of leadership experience across technology, industrial and private-equity-backed businesses, including senior roles at Safe Fleet, Atkore International, Danaher Corporation and Boston Consulting Group. He holds an MBA from Harvard Business School.

    “IQSIGHT has a strong heritage, outstanding people and a compelling strategy,” Schulte said. “I am excited to join the team and build on the excellent work already underway. Together, we will focus on execution, innovation and creating even greater value for our customers, partners and employees.”

    Positioning for the Next Growth Phase

    Shine, who remains chairman and will work with Schulte on strategic direction, said the appointment follows months of work with the leadership team to define IQSIGHT’s direction following its transition from Bosch Video Systems.

    “Over the past months, we have worked closely with the leadership team to define a clear strategic direction for IQSIGHT and position the business for its next phase of growth,” Shine said. “With that foundation in place, this is the right time for Michael to take the helm.”

    The leadership change comes as IQSIGHT continues to build a standalone identity in the video security market, aiming to maintain continuity for existing customers and channel partners while pursuing global expansion.

  • Maximum-Severity SAP Commerce Cloud Flaw Targeted Days After Patch

    Maximum-Severity SAP Commerce Cloud Flaw Targeted Days After Patch

    A maximum-severity vulnerability in SAP Commerce Cloud is facing active exploitation attempts, according to threat intelligence firm Defused and reporting by Cybersecurity Dive and The Hacker News, only days after SAP issued a fix.

    A Default-Authentication Bypass Rated CVSS 10.0

    The flaw, tracked as CVE-2026-58231, is described by SAP and CVE.org as an improper authorization issue in the Commerce Cloud Data Hub Adapter that allows an unauthenticated attacker to abuse a default authentication client and submit crafted input to functions that lack sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, according to CVE.org’s description, affecting confidentiality, integrity and availability. SAP Commerce Cloud is an enterprise e-commerce platform widely used by retailers to run online storefronts.

    From Patch to Exploitation in Days

    SAP shipped the fix, detailed in Security Note 3771065, as part of its August 2026 Security Patch Day on August 11, 2026. Defused CEO Simo Kohonen told Cybersecurity Dive that the firm’s honeypots began recording exploitation activity just three days after the patch was released, and that, as of the firm’s report, only one threat actor appeared to have attempted exploitation, suggesting the activity is not yet widespread. Defused said no proof-of-concept had circulated publicly before this exploitation was observed.

    Why It Matters

    No specific breached retailer had been publicly confirmed as of the most recent reporting; coverage has focused on exploitation attempts and defensive urgency. Prior SAP vulnerabilities, including CVE-2025-31324 in NetWeaver, have previously been weaponized by China-nexus espionage groups and ransomware actors such as BianLian and RansomExx, according to The Hacker News, underscoring the importance of applying SAP’s patch immediately rather than waiting for a confirmed incident.

  • Security 101 Expands Southern California Reach With Silverstrand Technologies Acquisition

    Security 101 Expands Southern California Reach With Silverstrand Technologies Acquisition

    Security 101, a national provider of commercial electronic security solutions, announced on August 26, 2026 that it has acquired Silverstrand Technologies Inc., a San Diego-based systems integrator, according to Security 101’s own announcement and reporting by SDM Magazine and Security Info Watch.

    Strengthening the West Region

    Silverstrand has operated for 19 years, providing video surveillance, access control, structured cabling, wireless networking, sound masking and life safety solutions to commercial, government, hospitality, aviation and institutional clients across Southern California. The acquisition strengthens Security 101’s presence in the San Diego, Orange County, Los Angeles and Riverside markets and folds Silverstrand’s regional team into the company’s West Region operations.

    Local Team Stays in Place

    “Silverstrand is one of Southern California’s most respected technology integrators, with a culture centered on taking care of both employees and customers,” said Greg Daly, CEO of Security 101, in the announcement. “That focus mirrors our own. Bringing this team into the Security 101 organization strengthens our West Region and gives customers access to national resources delivered by the same local team they already trust.” Silverstrand founder Jeremy Johnson will remain with the operation as general manager, continuing to lead the team that built the company’s regional reputation.

    Part of a Broader Consolidation Trend

    The deal is the latest in a wave of consolidation among regional security integrators, as national platforms acquire established local firms to combine deep market relationships with broader technical portfolios and lifecycle support. Security 101, based in West Palm Beach, Florida and founded in 2005, delivers design, installation and maintenance of access control, video surveillance, intrusion detection, visitor management and managed services across healthcare, education, financial and government end markets nationwide.

  • L3Harris and ARX Robotics Mount Counter-Drone Sensors on Uncrewed Ground Vehicle

    L3Harris and ARX Robotics Mount Counter-Drone Sensors on Uncrewed Ground Vehicle

    L3Harris Technologies and ARX Robotics UK demonstrated a mobile counter-drone capability during the U.S. Army’s Project Convergence-Capstone 6 experimentation campaign, mounting L3Harris’ CORVUS-RAVEN counter-small uncrewed aircraft system onto ARX’s remotely controlled Gereon unmanned ground vehicle, according to a joint announcement published on L3Harris’ newsroom on August 27, 2026.

    Moving Sensors Closer to the Threat

    CORVUS-RAVEN is a lightweight, portable system that provides passive detection of drone threats out to four kilometers, along with bearing information fed into command-and-control and battle management applications, according to L3Harris’ product materials. By mounting the sensor on the Gereon UGV, the companies said the demonstration showed how robotic mobility can extend passive drone-detection coverage into forward or hazardous areas without placing personnel directly in those zones.

    An Open-Architecture Partnership

    “Project Convergence has allowed us to demonstrate how uncrewed ground systems can extend the reach of specialist capabilities without extending the risk to personnel,” said David Roberts, CEO of ARX Robotics UK, in the companies’ announcement. L3Harris said the collaboration reflects modular, open-architecture integration between an established defense contractor and an emerging robotics provider, and that lessons from the exercise at Fort Irwin, California will inform further development of combined counter-drone and uncrewed ground system capabilities.

    Context

    The demonstration is part of a broader push by defense and physical security organizations to pair ground robotics with counter-UAS sensing as drone threats to installations, personnel and critical infrastructure continue to grow. L3Harris said Project Convergence-Capstone 6 will help identify further opportunities to integrate counter-drone technology with robotic platforms across additional missions.

  • Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Records

    Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Records

    Thomson Reuters disclosed on September 2, 2026 that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in an intrusion the company says occurred in March 2026, according to Thomson Reuters’ own disclosure and reporting by Reuters and The Hacker News.

    Scope: 11 States, the U.S. Virgin Islands and Ontario

    West Publishing said it discovered the unauthorized activity on June 30, 2026 and notified affected courts and Ontario’s Ministry of the Attorney General between July 23 and July 27. According to the company’s notice, a subset of affected court records could contain individuals’ names, Social Security numbers, driver’s license numbers, dates of birth, medical information and health insurance information. Some states reported that only backup data was involved, while Ohio said its production platform was accessed; Montana and Minnesota said court documents themselves were not part of the accessed data, though the vendor’s notice indicates sealed material may have been affected for certain courts.

    Coordinated, Delayed Public Disclosure

    Public disclosure came more than two months after the affected courts and Ontario were notified. Montana officials said the September 2 disclosure date was chosen so that the vendor and the various affected states could issue simultaneous announcements. Thomson Reuters said it has found no evidence to date that the exposed data has been misused.

    Why It Matters

    Court case management platforms sit at a sensitive intersection of physical and information security: they hold sealed records, victim and witness information, and identity data whose exposure carries legal as well as privacy consequences. The incident underscores the exposure created by shared third-party software used across many independent government bodies, where a single vendor compromise can cascade into simultaneous notifications across multiple jurisdictions.

  • Maximum-Severity SonicWall SMA 1000 Flaws Under Active Exploitation, CISA Warns

    Maximum-Severity SonicWall SMA 1000 Flaws Under Active Exploitation, CISA Warns

    SonicWall disclosed on September 1, 2026 that two vulnerabilities in its SMA 1000 series secure remote access appliances are being actively exploited in the wild, according to the vendor’s own advisory, SNWLID-2026-0016, and confirmed by CISA, Rapid7 and Qualys Threat Protect.

    A Chainable Path to Unauthenticated RCE

    The more severe flaw, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) vulnerability in the SMA 1000 Appliance Work Place interface, carrying the maximum possible CVSS score of 10.0. According to SonicWall’s advisory, an unintended alternate access path causes the appliance to act as an unintended forward proxy, letting a remote unauthenticated attacker reach sensitive functionality. Rapid7’s analysis found that this SSRF flaw can be chained with a second, high-severity OS command injection vulnerability in the Appliance Management Console, CVE-2026-83549, which normally requires authenticated administrator access, to achieve full unauthenticated remote code execution.

    Federal Deadline and Wide Exposure

    CISA added the flaw to its Known Exploited Vulnerabilities catalog and set a September 5, 2026 remediation deadline for federal civilian agencies. SonicWall SMA 1000 appliances are widely deployed as VPN and zero-trust access gateways by large enterprises, government agencies and managed service providers, making the appliance an attractive target given the level of internal network access it typically brokers.

    Response

    SonicWall has released a hotfix addressing CVE-2026-83548; the company states no workaround is available for organizations that cannot immediately patch. Security researchers recommend organizations apply the hotfix without delay, review SMA 1000 logs for signs of the unauthorized proxy behavior described in the advisory, and treat any indicators of compromise found before the patch was applied as a potential breach requiring further investigation.

  • Microsoft Preparing to Unveil Maia 300 AI Chip as Early as This Month

    Microsoft Preparing to Unveil Maia 300 AI Chip as Early as This Month

    Microsoft is planning to unveil its next-generation Maia 300 AI accelerator chip this fall, potentially as soon as September, Reuters reported on August 10, 2026, citing a report from The Information based on people with direct knowledge of the plans. The report has since been corroborated by multiple outlets including Yahoo Finance and Quartz, though Microsoft has not confirmed an exact date.

    A Third Attempt at Homegrown AI Silicon

    Maia 300 would be Microsoft’s third generation of custom AI silicon following Maia 100, introduced in November 2023, and Maia 200, which arrived in January 2026 built on TSMC’s 3-nanometer process with a large SRAM allocation for inference throughput. According to Reuters, Microsoft is negotiating with TSMC to secure manufacturing capacity for more than 300,000 Maia 300 units for delivery in 2027, with an eventual goal of surpassing one million units, though component supply and ongoing capacity talks could constrain that target. Microsoft general manager for Azure Maia, Andrew Wall, said in a statement reported by Reuters that the company “continues to invest in custom silicon as part of our long-term AI infrastructure strategy,” without confirming reported production volumes.

    Reducing Reliance on Nvidia

    The push comes as Microsoft has lagged rivals Alphabet and Amazon in scaling in-house AI chip programs to reduce dependence on Nvidia’s GPUs. Reuters reported that Microsoft is also seeking to pitch Maia 300 to external cloud customers, including Anthropic, as an alternative to Nvidia hardware. The timing places Maia 300 alongside a broader wave of hyperscaler silicon activity in 2026, including Google’s Ironwood TPU reaching general availability and Meta beginning production of its own AI chip in September.

    What to Watch

    Because Maia 300 has not yet been formally unveiled, key questions remain open: which cloud customers, if any, will be named at launch, what performance benchmarks Microsoft will disclose against Nvidia’s Blackwell-generation chips, and whether the TSMC capacity Microsoft is seeking will materialize on the timeline reported. Widespread availability is not expected before 2027 even if the chip is revealed this fall.

  • UK Aviation Cyber Assessment Finds Suppliers Are the Sector’s Weakest Link

    UK Aviation Cyber Assessment Finds Suppliers Are the Sector’s Weakest Link

    A new assessment of UK aviation’s external cyber exposure has found that third-party suppliers, not airport operators, account for the overwhelming majority of the sector’s cyber security weaknesses, according to research firm MyDomainRisk and coverage published by International Airport Review on September 3, 2026.

    Scanning 43 Operators and 51 Suppliers From the Outside

    MyDomainRisk said it examined the public web estate of 43 UK airport operators, covering 54 airports, alongside 51 organizations those airports depend on, using only externally visible, unauthenticated scanning. The firm emphasized that no airport operational technology, air-traffic, airline, baggage-handling or screening system was accessed or tested as part of the work; the scope was limited to what is visible to anyone on the public internet.

    Exposure Is Concentrated in the Supply Chain

    Of 1,152 exposed employee credential records identified across both groups, only 10 belonged to airport operators, according to MyDomainRisk; the remainder sat with suppliers, which also accounted for three leak-site mentions. Ground-operations providers were flagged as the weakest supplier class, with the firm reporting that 92 percent of staff-credential exposure across the study sits within three airside supplier categories. Gabriel Higgins, writing for International Airport Review, said suppliers’ average security posture score badly trailed that of the operators they serve.

    The One Place Airports Underperform

    The assessment identified a single measure where airport operators scored worse than their suppliers: email authentication. Seventeen of the 43 airport operators studied, or 40 percent, cannot instruct receiving mail systems to reject an email forged in their name, according to the research. Higgins quoted the study’s author describing this as both one of the sector’s simplest fixes and one of its most consequential, since an airport’s own domain is a far more attractive identity for attackers to spoof than that of a lesser-known supplier.

  • Google Patches Actively Exploited Chrome V8 Zero-Day, Sixth of 2026

    Google Patches Actively Exploited Chrome V8 Zero-Day, Sixth of 2026

    Google released Chrome 152 security updates on September 3, 2026, patching 12 vulnerabilities including a high-severity flaw that attackers are already exploiting, according to Google’s own advisory and reporting from The Hacker News, SecurityWeek and BleepingComputer.

    A Type Confusion Bug in Chrome’s Core Engine

    The exploited flaw, tracked as CVE-2026-85046 and rated CVSS 8.8, is a type confusion vulnerability in V8, the JavaScript and WebAssembly engine that powers Chrome. Google’s advisory describes the bug as allowing a remote attacker to execute arbitrary code inside Chrome’s sandbox via a specially crafted HTML page. Google said it is aware that an exploit for the flaw exists in the wild but withheld technical details of the observed attacks to limit further exploitation while users update. Security researcher Salvatore Gulizia, credited with reporting the issue on August 4, 2026, received a $1,000 bug bounty for the disclosure.

    Sixth Exploited Chrome Zero-Day This Year

    CVE-2026-85046 is the sixth actively exploited Chrome zero-day Google has patched in 2026, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281 and CVE-2026-11645. The same update, which brings Chrome to version 152.0.7977.82/.83 on Windows and macOS and 152.0.7977.82 on Linux, also fixes nine other high-severity issues spanning Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools and Skia components.

    Why It Matters for Security Operators

    Chromium-based browsers sit behind a large share of enterprise workstations, control-room terminals and web-based video management and access-control clients, making browser zero-days a recurring entry point into otherwise segmented environments. Google is rolling out the fix gradually; users and IT administrators are advised to confirm they are running version 152.0.7977.82 or later via Chrome’s Settings > About Chrome menu and restart the browser to complete the update rather than waiting for automatic rollout.

  • Attackers Exploit MikroTik RouterOS Flaw Chain to Seize Routers Without Authentication

    Attackers Exploit MikroTik RouterOS Flaw Chain to Seize Routers Without Authentication

    Poland’s national CSIRT, CERT Polska, disclosed on September 5, 2026 that attackers are actively exploiting a chain of MikroTik RouterOS vulnerabilities to gain full administrative control of internet-exposed routers with no valid login and no private key required, according to CERT Polska’s advisory and reporting by The Hacker News and Security Affairs.

    Two Flaws Chained Into Full Takeover

    CERT Polska disclosed six RouterOS vulnerabilities in total, naming the exploited chain “MikroTrick.” The first, CVE-2026-67276 (CVSS 9.2), is an SSH authentication bypass rooted in how RouterOS verifies RSA public keys: an attacker who knows a valid username and the public portion of that user’s RSA key can forge a key and log in without possessing the corresponding private key. The second, CVE-2026-86060 (CVSS 9.2), is a privilege-escalation flaw triggered by a crafted username beginning with a disallowed character, which alters the trusted RouterOS policy mask and grants the resulting SSH session full administrative rights. Chained together, the two flaws let an attacker take over any internet-facing RouterOS device with SSH enabled.

    Exploitation Already Under Way

    CERT Polska said observed exploitation dates back to at least September 2, 2026, three days before public disclosure. Independent researcher Costin Raiu published a technical breakdown the same day as the advisory, writing that anyone running a MikroTik router with SSH exposed to the internet should treat the device as compromised until proven otherwise. Shodan scans referenced in coverage of the advisory show roughly 300,000 vulnerable devices still reachable from the public internet.

    Fixes and Recommended Response

    MikroTik has released patched builds: 6.49.21 for the long-term 6.x branch, 7.23.4 for the long-term 7.x branch, and 7.24.2 for the stable 7.x branch. CERT Polska is advising administrators to update immediately, restrict SSH management access to trusted networks rather than the open internet, and check devices for unknown users, unfamiliar scripts and other signs of compromise before assuming a device is clean.