Author: Osiris

  • CISA Ends Six Free Cybersecurity Assessments for Critical Infrastructure Operators

    CISA Ends Six Free Cybersecurity Assessments for Critical Infrastructure Operators

    The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed it is ending six free assessment programs long used by critical infrastructure operators to evaluate their cybersecurity posture, Cybersecurity Dive reported.

    What’s New

    CISA’s regional field staff will no longer conduct Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments or Cyber Infrastructure Surveys. All six relied on CISA’s Cyber Security Evaluation Tool (CSET). Acting Cybersecurity Division head Chris Butera said eliminating the “legacy assessments” would “reduce redundancy for CISA and organizations requesting an assessment,” adding that operators can instead reference CISA’s Cybersecurity Performance Goals.

    Why It Matters

    Experts told Cybersecurity Dive that the Cybersecurity Performance Goals are not a substitute for the hands-on, in-person guidance the discontinued assessments provided. Tatyana Bolton, executive director of the OT Cyber Coalition, said “severe budget cuts have forced CISA into a corner where they can no longer provide the level of hands-on, operational support to critical infrastructure that they once did.” The change follows a reported loss of roughly a third of CISA’s workforce and comes as small utilities and rural operators — among the heaviest users of the free assessments — face rising cyber and physical threats with fewer federal resources to call on.

  • Ring Rolls Out TAKE Encryption to Limit Who Can Access Home Security Camera Footage

    Ring Rolls Out TAKE Encryption to Limit Who Can Access Home Security Camera Footage

    Amazon’s Ring announced a new default encryption system for its security cameras and video doorbells on August 26, 2026, called TAKE — short for Throw Away the Key Encryption — designed to limit ongoing access to customer video, including by Ring itself and by law enforcement without a user’s consent, according to the company’s announcement and reporting from The Verge and CEPRO.

    How TAKE Works

    Under the new system, each camera encrypts its video using unique keys that rotate roughly every five minutes. A temporary copy of each key is held in what Ring calls a secure enclave in the cloud, long enough to power features such as smart alerts, video search and AI-generated video descriptions, after which the company says it permanently deletes its copy of that key. Ring has framed the approach as a middle ground between full end-to-end encryption, which would block many of its AI-driven features outright, and its previous architecture, which gave Ring’s cloud infrastructure more persistent access to footage.

    Rollout Timeline

    TAKE is scheduled to become the default encryption setting for all Ring customers worldwide in phases starting in September 2026, according to the company’s announcement.

    Why the Framing Matters

    The change follows years of scrutiny over Ring’s video-sharing practices, including a 2023 FTC settlement over unauthorized employee and law-enforcement access to customer footage, and comes as its former data-sharing partner Flock Safety faces its own wave of municipal contract cancellations over surveillance and privacy concerns. Privacy researchers note that because Ring — not an independent, published standard — designed the key-deletion process itself, customers still have to trust Amazon’s implementation rather than verify it independently, a caveat also raised by outlets covering the announcement.

  • Researchers Find All 21 Tested Open-Weight AI Models Can Be Stripped of Safety Guardrails

    Researchers Find All 21 Tested Open-Weight AI Models Can Be Stripped of Safety Guardrails

    An international research team led by the University of Waterloo and the nonprofit AI-security group FAR.AI found that all 21 of the most widely used open-weight large language models they tested could have their built-in safety protections removed with relatively little technical effort, according to the university’s own announcement, corroborated by EurekAlert and independent technology outlet HyperAI.

    What the Researchers Tested

    The team built an open-source testing tool called TamperBench to standardize how they simulated tampering attacks across the 21 models. Every model examined could be modified to bypass its safety guardrails despite the protections built in by their developers, and the seven defensive techniques the researchers evaluated did not reliably stop the tampering methods they tried, according to the University of Waterloo’s release.

    The Stakes of Open Weights

    “When the safety guardrails are stripped out of a capable model, it can be used at scale for harm in ways a single person could never manage manually,” said Dr. Sirisha Rambhatla, a University of Waterloo professor of management science and engineering and director of its Critical Machine Learning Lab, who led the study. The researchers warned that models stripped of their protections could be used to run large-scale disinformation campaigns, automate convincing scam emails, or produce instructions for creating hazardous materials.

    Open Models Remain Valuable, But Riskier to Control

    The study’s authors were careful to note that open-weight models remain important for research transparency and independent scrutiny, since outside researchers can inspect and test them in ways closed, proprietary systems don’t allow. But once a model’s weights are published, its creator loses most practical ability to prevent later tampering — the opposite trade-off from closed models, where the vendor retains centralized control but outside researchers have far less visibility. The team’s findings, presented at the ACM Conference on Knowledge Discovery and Data Mining, add to a growing body of evidence that AI safety standards are lagging the pace at which open-weight models are approaching the capability of proprietary frontier systems.

  • PSG and Mercury Security Partner to Extend Zero Trust to Physical Security’s Far Edge

    PSG and Mercury Security Partner to Extend Zero Trust to Physical Security’s Far Edge

    Prometheus Security Group Global (PSG) announced a technology partnership with Mercury Security on August 27, 2026, aimed at extending Zero Trust principles down to the field-device level of physical security systems, according to the companies’ announcement and independent reporting from Security Systems News.

    Combining Access Hardware With Edge Authentication

    The partnership pairs Mercury’s open-architecture access-control hardware platform with PSG’s patented technology for embedding cryptographic identity, authentication and verification directly into far-edge field devices, including door readers, sensors and cameras. PSG describes the goal as moving physical security systems away from assumed, unverified inputs toward authenticated and cryptographically verified data starting at the point where it is generated, rather than only securing the network layer above it.

    Why Now

    The move extends a Zero Trust architecture approach that IT security teams have used for years, in which every device and request is continuously authenticated rather than implicitly trusted once inside a network perimeter, into physical and operational technology environments. PSG has previously supplied Zero Trust physical security technology to U.S. Air Force, Navy and Department of Energy programs, and has positioned far-edge authentication as a way to close a gap security researchers have flagged in converging IT and physical access control systems, where edge hardware has often remained a weaker link than the software managing it.

    What It Means for Integrators

    For organizations running Mercury-based access control, the partnership is intended to let them add cryptographic device-level verification without replacing existing access-control investments, addressing a common friction point in critical-infrastructure and high-security environments where wholesale hardware replacement is often impractical.

  • NextNav and Tiami Networks Partner to Test 5G-Powered Counter-Drone Sensing

    NextNav and Tiami Networks Partner to Test 5G-Powered Counter-Drone Sensing

    Positioning company NextNav has named Tiami Networks as a sensing ecosystem partner to jointly develop and evaluate counter-UAS detection capabilities built on 5G infrastructure, the companies announced on August 25, 2026, according to NextNav’s own release and independent reporting from UASweekly and Unmanned Airspace.

    The Technology

    The partnership will use NextNav’s existing 5G Positioning, Navigation and Timing (PNT) network, deployed on the licensed lower 900 MHz band, as a testbed in Santa Clara County, California. Tiami is contributing its radio-frequency sensing technology to the effort, with the two companies evaluating whether the same 5G infrastructure that provides positioning services can simultaneously support wide-area sensing for drone detection without adding load to the network. The approach falls under what the companies describe as integrated sensing and communications, or ISAC.

    Why Range Matters

    “The need for longer range situational awareness has never been more urgent as drones continue to threaten large-scale events, critical infrastructure, and government and military facilities including airports,” said David Gell, NextNav’s vice president of business development, in the companies’ announcement. That framing echoes a wider push across the counter-UAS sector this year toward detection systems that can spot drones farther out and earlier, giving operators more time to assess and respond before an unmanned aircraft reaches a protected site.

    Early-Stage Evaluation

    NextNav and Tiami characterized the work as an evaluation of performance and applicability rather than a finished product, with the companies planning to assess whether the low-band 5G approach can support counter-UAS, critical-infrastructure and national-security use cases alongside its existing positioning role.

  • Ambient.ai Adds Agentic Video Monitoring and Case Management Tools Ahead of GSX 2026

    Ambient.ai Adds Agentic Video Monitoring and Case Management Tools Ahead of GSX 2026

    Ambient.ai, a physical security AI vendor, announced new agentic capabilities across its platform on August 26, 2026, adding AI agents that continuously monitor camera feeds and automated case-management tools that assemble scattered video clips into a single incident timeline, according to the company’s announcement carried via PR Newswire and confirmed by Security Systems News.

    What’s New

    The centerpiece of the release is an AI agent Ambient.ai describes as continuously monitoring every connected camera and surfacing the events operators are most likely to need to see, rather than requiring security teams to actively watch banks of live video feeds. Alongside it, the company introduced a new case-management workflow intended to turn clips from multiple cameras and time windows into a single connected incident narrative, cutting down the manual work of stitching together footage during investigations. Ambient.ai also said it made infrastructure upgrades to support the new features at scale.

    Timed to GSX 2026

    The company plans to demonstrate the new Agentic Video Wall and case-management tools live at its booth (#3923) during GSX 2026 in Atlanta, positioning the release as part of a broader wave of “agentic” AI marketing across the physical security industry this year, as vendors compete to move video analytics from passive alerting toward autonomous monitoring and response.

    Why It Matters

    The announcement reflects a broader industry shift already visible in the growing adoption of AI-assisted video management platforms, where vendors are racing to differentiate on how much investigative and monitoring work their software can take on autonomously rather than leaving it to human operators watching screens.

  • Parking Facility and Garage Security Technology

    Parking Facility and Garage Security Technology

    Parking facilities present a security profile shaped by the tension between convenience and control: operators need to move large volumes of vehicles in and out efficiently while protecting parked vehicles, deterring crime in low-visibility areas, and managing liability in spaces that are frequently unstaffed for long stretches of the day.

    Automated Access Control and License Plate Recognition

    Modern parking access control has largely moved away from ticket-based entry toward license plate recognition systems that identify vehicles automatically at entry and exit, matching them against reservations, permits or payment records without requiring drivers to stop and interact with a gate or attendant. Automatic barrier gates paired with vehicle detection loops and LPR cameras allow facilities to enforce access restrictions and capacity limits with minimal staffing, while maintaining an auditable record of every vehicle movement through the facility.

    Video Surveillance in Low-Visibility Environments

    Parking structures present persistent lighting and sightline challenges, particularly in multi-level garages with support columns, stairwells and dimly lit corners that create natural blind spots. Camera placement strategy in garages typically prioritizes chokepoints — entry and exit lanes, elevator lobbies, stairwell doors and pedestrian walkways — supplemented by wide-area coverage of parking bays, with increasing use of AI-based analytics to detect loitering, unusual dwell time near parked vehicles, or people entering restricted areas after hours.

    Emergency Communication and Panic Infrastructure

    Because parking facilities are frequently used at hours when few other people are present, blue-light emergency phone towers and intercom call points remain a standard feature in many garages, giving pedestrians a direct, monitored line to security or law enforcement without needing a mobile device. Newer deployments increasingly pair these fixed call points with mobile safety apps that let users share their location and request an escort or check-in while walking to their vehicle.

    Vehicle and Asset Theft Prevention

    Beyond general surveillance, parking security technology addresses vehicle-specific theft risks, including catalytic converter theft and break-ins, through a combination of visible camera coverage, motion-activated lighting, and in some deployments, license-plate-linked alerting that flags when a vehicle associated with a prior incident re-enters the facility.

    Integration With Broader Building Security

    In commercial and residential developments, parking facility access control is frequently integrated with the building’s broader access control and video management systems, allowing a single credential to grant access to both the garage and the building above it, and giving security operations a unified view of a person’s movement from vehicle to building entry rather than treating the parking facility as a separate, disconnected system.

  • Telecommunications Infrastructure Security Technology

    Telecommunications Infrastructure Security Technology

    Telecommunications infrastructure — cell towers, central offices, data exchange facilities and the fiber networks connecting them — forms a foundational layer of critical infrastructure that other sectors depend on for their own operations, from emergency services dispatch to financial transactions to the remote monitoring systems used across utilities and industrial facilities. Securing this infrastructure combines dispersed-site physical protection with facility-level access control and a growing emphasis on supply-chain and hardware integrity.

    Securing Widely Distributed, Often Unmanned Sites

    Cell towers and remote equipment shelters are typically unmanned and geographically dispersed, making them attractive targets for copper and equipment theft as well as vandalism. Operators increasingly deploy solar-powered remote monitoring systems combining motion-activated cameras, door and cabinet intrusion sensors, and cellular or satellite backhaul for alerting, since many tower sites lack reliable wired connectivity of their own for security reporting.

    Central Office and Data Exchange Access Control

    Central offices and carrier-neutral data exchange facilities, where multiple network operators interconnect, apply layered access control similar to data center security: biometric or multi-factor authentication at building and cage-level entry points, mantrap vestibules to prevent tailgating, and comprehensive video surveillance covering both public and restricted areas. Because these facilities often host equipment belonging to multiple competing carriers within the same building, access segmentation between tenant spaces is a particular design priority.

    Fiber Route and Cable Landing Protection

    Long-haul fiber routes and cable landing stations, where undersea cables come ashore, represent concentrated points of failure for national and international connectivity. Security for these assets combines physical protection of landing station buildings with monitoring of the buried or undersea cable routes themselves, an area where distributed acoustic sensing technology has found growing application for detecting unauthorized digging, dragging anchors or other activity near cable paths before physical damage occurs.

    Network Operations Center Security

    Network operations centers, which provide real-time monitoring and control over telecommunications infrastructure, require the same access control and video surveillance rigor as other critical control-room environments, given that a compromise of NOC systems could allow an attacker to disrupt network operations directly rather than through physical damage to remote infrastructure.

    Supply Chain and Equipment Integrity

    Telecommunications security increasingly extends into supply-chain risk management, with regulatory scrutiny in multiple countries focused on the origin and integrity of network equipment given concerns that compromised hardware or firmware could introduce backdoors into national communications infrastructure, adding a procurement and vendor-vetting dimension to what has traditionally been a purely physical and operational security discipline.

  • Agriculture and Food Processing Facility Security Technology

    Agriculture and Food Processing Facility Security Technology

    Agricultural and food processing facilities occupy a growing place within critical infrastructure protection frameworks, reflecting the recognition that disruption to food production, processing or distribution can cascade into public health and supply-chain consequences far beyond a single site. Security technology for this sector must account for expansive rural footprints, biosecurity requirements and food-safety regulation alongside conventional theft and sabotage concerns.

    Perimeter Security Across Large, Remote Footprints

    Farms, feedlots and processing complexes often span hundreds or thousands of acres, making traditional fenced-perimeter models impractical for the outer boundary. Operators increasingly rely on a combination of strategically placed fencing around high-value structures — processing plants, chemical storage, equipment yards — supplemented by long-range video analytics, thermal cameras and, on the largest sites, radar systems capable of detecting vehicle or personnel intrusion across open land where fixed cameras alone cannot provide continuous coverage.

    Biosecurity-Driven Access Control

    Livestock and processing facilities implement access control designed as much to prevent disease introduction as to prevent theft or sabotage. Controlled entry points, vehicle wash stations, and credentialed access for employees and visitors work alongside traceability systems that log who entered which zone and when, supporting both security investigations and biosecurity incident response if a disease outbreak requires rapid contact tracing.

    Video Surveillance for Food Safety and Loss Prevention

    Processing plants deploy video surveillance across production lines, loading docks and cold storage areas, serving a dual purpose: deterring and investigating theft or tampering, and providing a documented record that supports food-safety compliance and audit requirements under regulations that increasingly expect traceable oversight of handling and processing conditions.

    Supply Chain and Cold Chain Monitoring

    Security technology extends into the cold chain itself, with sensor-based monitoring of temperature, humidity and door-open events on refrigerated storage and transport, integrated with alerting systems that flag deviations before spoiled product reaches distribution. GPS tracking on transport vehicles adds a security layer against cargo theft, a persistent risk for high-value agricultural shipments moving through less-monitored rural transit corridors.

    Cyber-Physical Risk in Modern Agricultural Operations

    As precision agriculture equipment, automated processing lines and remote monitoring systems proliferate, agricultural operators face a growing cyber-physical risk profile similar to other industrial sectors, with internet-connected control systems for irrigation, feed distribution and processing equipment representing a potential attack surface that security planning increasingly has to account for alongside traditional physical threats.

  • Public Transit and Bus Depot Security Technology

    Public Transit and Bus Depot Security Technology

    Public transit systems present a distinct security challenge: they must remain open, accessible and fast-moving for millions of daily riders while simultaneously protecting vehicles, depots, stations and passengers from crime, vandalism and, in rarer cases, deliberate attack. Unlike a controlled-access facility, a transit network is deliberately porous by design, which shapes the technology choices operators make.

    Onboard and Station Video Surveillance

    Modern transit fleets deploy multi-camera systems on every vehicle, covering the driver compartment, passenger cabin, doors and exterior approach zones, with footage typically recorded locally and synchronized to a central video management system whenever the vehicle returns to a depot or passes through a wireless upload zone. Stations and platforms are covered by fixed and pan-tilt-zoom cameras integrated with the same VMS, allowing operators to follow an incident across a rider’s entire journey rather than reviewing disconnected clips from separate systems.

    Depot and Yard Perimeter Protection

    Bus and rail depots concentrate high-value rolling stock, fuel or charging infrastructure, and maintenance facilities in a single location, making perimeter security a priority distinct from the open transit network itself. Depots typically combine fenced perimeters, access-controlled gates, license plate recognition for fleet and visitor vehicles, and video analytics tuned to detect loitering or unauthorized entry after operating hours, when yards are otherwise unattended.

    Real-Time Operator Communication and Panic Alerts

    Driver safety technology has become a growing focus as assaults on transit operators have drawn regulatory and labor attention. Systems now commonly include silent panic buttons that alert dispatch and trigger live video and audio streaming from the vehicle, GPS-based location tracking integrated with computer-aided dispatch, and in some deployments, driver-facing barriers combined with intercom systems that let control center staff communicate directly with passengers without requiring the driver to intervene.

    Access Control for Employee and Maintenance Areas

    Depots and control centers restrict access to maintenance bays, parts storage and operations rooms using badge-based or biometric access control, often layered with visitor management systems for contractors and vendors who require temporary, auditable access to secure areas.

    Integration With City-Wide Public Safety Systems

    Because transit incidents frequently require a coordinated response involving both transit security and municipal police, many agencies now integrate their video and alert systems with city-wide public-safety platforms, allowing real-time video sharing and location data to reach first responders faster than a traditional phone-based incident report would allow.