Author: Osiris

  • Virginia Tech Opens Counter-UAS Testing and Research Center Backed by $5 Million Army Futures Command Award

    Virginia Tech Opens Counter-UAS Testing and Research Center Backed by $5 Million Army Futures Command Award

    Virginia Tech held a ribbon-cutting ceremony on August 28, 2026, for a new Counter-UAS Testing and Research Center at its Kentland Farms property in Blacksburg, Virginia, a facility the university’s National Security Institute says will support development of drone-defense technology for both the US Army and civilian critical-infrastructure operators, according to Virginia Tech News and local coverage from WSLS.

    The outdoor site is backed by a $5 million award from the US Army Futures Command’s Combat Capabilities Development Command C5ISR Center and gives researchers a real-world, open-air environment to test detection, tracking, and identification systems against unmanned aircraft — complementing indoor and virtual test environments the university already operates. University President Tim Sands, US Senator Mark Warner, and 9th District Congressman Morgan Griffith attended the opening.

    Officials Cite a Capability Gap

    “This is an area where we have to catch up, where America is behind,” Warner said at the ceremony. Austin Phoenix, director of mission systems at the Virginia Tech National Security Institute, said unmanned aircraft present a distinct detection challenge “because they’re just much smaller” than the aerial threats legacy air-defense systems were designed around.

    The center is intended to provide independent verification and validation testing for both government and private-industry counter-UAS systems, adding to a small number of dedicated outdoor test ranges nationally as drone incursions over military installations, airports, and other sensitive sites continue to draw federal attention. Virginia was one of seven states granted early federal UAS test-site designation roughly twelve years ago, giving the university a long-running base of aviation-research infrastructure to build on. The opening follows a string of counter-drone contract awards this year, including DHS’s department-wide counter-drone contracts.

  • ServiceNow Patches Three Maximum-Severity Flaws That Allowed Unauthenticated Code Execution

    ServiceNow Patches Three Maximum-Severity Flaws That Allowed Unauthenticated Code Execution

    ServiceNow disclosed and patched three maximum-severity vulnerabilities in its Now Platform and AI Platform on August 28, 2026, each exploitable by an unauthenticated attacker with low complexity and no user interaction, according to the company’s own security advisories and reporting from BleepingComputer and The Hacker News.

    Two of the flaws, CVE-2026-18885 and CVE-2026-18886, are code-injection vulnerabilities in the ServiceNow AI Platform that could let an attacker execute arbitrary code, access or modify instance data beyond intended permissions, or escalate privileges. A third, CVE-2026-74820, is a SQL-injection flaw in the same platform that could allow an unauthenticated user to run arbitrary SQL statements against the underlying database and alter instance data. A separate, high-severity sandbox-escape bug, CVE-2026-6876, was disclosed alongside the three critical issues.

    No Confirmed Exploitation, but a Pattern of Prior Abuse

    ServiceNow said it is “not currently aware of malicious exploitation against ServiceNow instances” tied to the newly disclosed flaws. The company has hosted-instance customers already patched, while partners and self-hosted customers running on-premises deployments are responsible for applying fixes themselves across the affected Xanadu, Yokohama, Zurich, and Aspen release families.

    The disclosure follows a related ServiceNow flaw, CVE-2026-6875, that researchers confirmed was actively exploited in July 2026, and echoes a pattern from 2024 in which several ServiceNow vulnerabilities were chained together in attacks against government and private-sector targets. Given ServiceNow’s widespread use for enterprise workflow and identity-adjacent processes, security teams are advised to prioritize patching self-hosted instances even in the absence of confirmed in-the-wild exploitation.

  • Iran-Linked Hackers Disable UK Power Plant for Four Days as US Water Utilities Report Coordinated Attacks

    Iran-Linked Hackers Disable UK Power Plant for Four Days as US Water Utilities Report Coordinated Attacks

    A small power generation facility in the United Kingdom was disabled for four days after a suspected Iran-linked cyberattack, in a window that overlapped with a wider wave of intrusions against wastewater treatment plants across roughly a dozen US states, according to reporting from Security Affairs and The Register published August 23–24, 2026, citing UK government and industry sources.

    The UK facility, not named publicly for security reasons, was small enough that its outage did not affect the wider national power supply, and staff were able to restore operations without formal notification thresholds being triggered. A UK government source told reporters the plant fell below the legal reporting threshold for “important generators,” while the National Cyber Security Centre declined to comment on the specific incident. NCSC chief Richard Horne said in June that the agency had handled more than 200 attacks on UK critical national infrastructure over the preceding year.

    US Wastewater Plants Hit Across Multiple States

    In parallel, US authorities traced a separate series of intrusions affecting dozens of wastewater treatment facilities, with the earliest reports emerging from Minnesota on July 26 and subsequent incidents confirmed in Michigan, Georgia, South Dakota, New Jersey, and Alabama. Several affected utilities reported flooding and loss of water pressure, and some jurisdictions issued boil-water advisories as a precaution. The FBI has attributed the water-sector intrusions to “malicious cyber actors,” and US government sources cited by Security Affairs indicated the activity likely originated in Iran.

    Researchers characterize both incidents as capability demonstrations rather than attempts to cause lasting damage, consistent with a broader pattern of suspected Iranian probing reported in recent months against infrastructure operators in Germany, Poland, Finland, Belgium, and Albania. UK officials have said the activity has accelerated since February airstrikes involving the United States and Israel against Iranian targets.

    The incidents add to a year in which operational technology at water and wastewater facilities has faced sustained scrutiny, and follow a separate US executive action restricting foreign-made equipment in bulk-power systems over cybersecurity concerns.

  • Chemical Plant and Hazardous Materials Facility Security Technology

    Chemical Plant and Hazardous Materials Facility Security Technology

    Chemical manufacturing and hazardous-materials storage facilities present a security profile that differs meaningfully from most other industrial verticals: the consequence of a security failure is not limited to theft or operational downtime, but can extend to toxic release, explosion, or environmental contamination affecting surrounding communities. That elevated consequence has shaped both the regulatory environment governing the sector and the security technology commonly deployed within it.

    Regulatory Context Shapes the Technology Stack

    In the United States, chemical facilities meeting certain hazardous-chemical thresholds have historically been subject to federal chemical facility security regulation requiring layered physical security measures, background screening for personnel with access to critical assets, and cybersecurity protections for process control systems. This regulatory framework has pushed the sector toward standardized layered-security architectures more consistently than in less-regulated industrial verticals, where security investment varies more widely based on individual operator risk tolerance.

    Layered Physical Security

    Perimeter and Access Control

    Chemical facilities typically implement multiple concentric security layers: an outer perimeter with fencing, intrusion detection and vehicle barriers; an intermediate layer controlling access to process areas; and the tightest access restrictions around chemicals of highest concern, such as facilities handling theft-attractive or release-hazardous materials. Vehicle access control, including barriers rated to stop forced-entry attempts, is a more prominent design consideration at chemical sites than at many other industrial facility types, given the potential consequences of a vehicle-borne intrusion into a process area.

    Detection Technology for Process Areas

    Gas detection systems monitoring for leaks of specific hazardous compounds are integrated with facility-wide alarm and evacuation systems, and increasingly correlated with video analytics and access-control data so that a detected leak can be cross-referenced against personnel location data to support faster, more targeted emergency response.

    Video Surveillance and Analytics

    Explosion-rated and intrinsically safe camera housings are required in classified hazardous areas within chemical facilities, a specification not typically relevant to general commercial or office-building surveillance deployments. Video analytics tuned to detect unauthorized personnel in restricted process zones, or unusual activity around chemical storage and loading areas, extend monitoring coverage across large facility footprints.

    Operational Technology and Cybersecurity

    Chemical process control systems — the distributed control systems (DCS) and PLCs governing reaction parameters, temperature and pressure — represent a high-consequence target if compromised, since manipulation of process parameters can directly cause a safety incident rather than only a data or availability loss. This has made the sector an early and consistent adopter of OT network segmentation, industrial firewalls, and continuous monitoring for anomalous commands issued to process controllers, generally ahead of adoption rates seen in less safety-critical industrial verticals.

    Personnel and Insider Risk

    Because a portion of chemical-facility risk stems from insider access to hazardous materials or process controls rather than external intrusion, background screening, access-tiering based on role, and behavioral monitoring for personnel with elevated process-control privileges are treated as core components of the security program rather than optional additions, aligning chemical-sector practice with the broader industry shift toward merging physical and cyber insider-threat signals.

    FAQ

    Why do chemical facilities require explosion-rated security cameras?

    In areas classified as hazardous due to the presence of flammable gases, vapors or dust, standard electronic equipment can pose an ignition risk. Explosion-rated (intrinsically safe or explosion-proof) camera housings are engineered to prevent the equipment itself from becoming an ignition source in those classified zones.

    Is chemical facility security primarily a regulatory compliance exercise?

    Regulatory requirements set a baseline, but facilities handling genuinely high-consequence materials generally implement security measures beyond minimum compliance thresholds, given that the potential consequences of a security failure extend to surrounding communities and not just the facility itself.

    Conclusion

    Chemical and hazardous-materials facility security sits at an unusually high-stakes intersection of physical security, process safety and OT cybersecurity. The sector’s layered, regulation-informed approach — combining hardened perimeter and access control, hazardous-area-rated detection technology, and mature OT segmentation practices — reflects consequences that go well beyond typical industrial security concerns of theft or downtime.

  • Smart Building Security Integration: Converging BMS, IoT and Physical Security Systems

    Smart Building Security Integration: Converging BMS, IoT and Physical Security Systems

    A modern commercial building typically runs several parallel digital systems: a building management system (BMS) controlling HVAC, lighting and elevators; a physical security platform handling access control and video surveillance; and a growing layer of IoT sensors monitoring everything from occupancy to air quality to energy consumption. Historically, these systems were built, procured and operated independently, often by different contractors using proprietary protocols with little interoperability. That is changing as building owners push for centralized operational visibility and as IP-based communication becomes the default across all three domains.

    What Integration Actually Enables

    • Occupancy-aware building operations. Access control and video occupancy data can inform HVAC and lighting schedules in real time, reducing energy use in unoccupied zones without requiring separate occupancy sensors purpose-built for BMS use.
    • Correlated alarm response. A door-forced-open alarm correlated with an unexpected HVAC or lighting change in the same zone can help security operators distinguish a genuine intrusion from a false alarm or scheduled maintenance activity.
    • Unified emergency response. Fire alarm, access control and BMS integration allows automated responses during emergencies — such as unlocking designated egress doors and adjusting HVAC to support smoke control — to be coordinated from a single event trigger rather than requiring separate manual actions across disconnected systems.
    • Centralized operational dashboards. Facility operators increasingly want a single interface showing security status, environmental conditions and building system health, rather than switching between multiple vendor-specific consoles.

    The Security Cost of Convergence

    Integration is not free from a risk standpoint. Building management systems have historically been built with less emphasis on cybersecurity than IT infrastructure, and connecting them to the same network as access control and video systems can create pathways for an attacker who compromises a lower-security BMS component to reach higher-value security infrastructure, or vice versa. IoT sensors, in particular, are frequently deployed in large numbers with minimal device management, making them a common weak point in an otherwise well-secured network if not properly segmented and monitored.

    Effective smart-building integration therefore requires the same network segmentation discipline applied to any converged IT/OT environment: BMS, IoT and security systems should typically sit on segmented VLANs with controlled inter-segment communication, rather than a single flat network simply because integration is technically possible.

    Governance and Organizational Challenges

    Beyond the technical architecture, smart-building integration raises questions of system ownership that many organizations have not fully resolved: does facilities management or security operations own the integrated platform? Who is responsible for patching BMS controllers that were historically outside the IT department’s purview? These governance questions frequently prove harder to resolve than the underlying technical integration, and unresolved ownership questions are a common reason integration projects stall after the initial technology deployment.

    FAQ

    Does smart building integration require replacing existing BMS or security systems?

    Not necessarily. Many integration platforms are designed to sit above existing BMS and security systems, aggregating data through APIs or middleware rather than requiring wholesale replacement of underlying infrastructure, though the degree of integration achievable depends on how open or proprietary the existing systems’ interfaces are.

    Is network segmentation still necessary if all systems are managed by the same integrated platform?

    Yes. A shared management platform does not eliminate the value of network segmentation; the two operate at different layers. Segmentation limits the blast radius of a compromised device at the network level, regardless of which platform is used to manage the devices sitting on that network.

    Conclusion

    Converging BMS, IoT and physical security in commercial buildings delivers real operational value, from energy efficiency to more coordinated emergency response, but it also expands the attack surface if approached purely as a data-integration exercise without corresponding network segmentation and governance work. Organizations that succeed at smart-building integration tend to treat it as a security architecture project with an operational-efficiency benefit, not the reverse.

  • Water and Wastewater Treatment Facility Security Technology

    Water and Wastewater Treatment Facility Security Technology

    Water and wastewater treatment facilities occupy an unusual position among critical infrastructure sectors: they are simultaneously among the most physically distributed — with treatment plants, pump stations, storage tanks and distribution infrastructure often spread across large geographic areas — and among the most operationally sensitive, since a disruption can affect public health directly rather than only causing economic damage. U.S. federal agencies, including CISA, have repeatedly flagged the sector for elevated attention, warning water and wastewater system operators to protect programmable logic controllers (PLCs) and other operational-technology assets against reconnaissance and exploitation attempts by both criminal and state-linked threat actors.

    Physical Security Layers

    Perimeter Protection at Distributed Sites

    Because water infrastructure includes remote, often unstaffed sites such as pump stations and lift stations, perimeter security technology for the sector leans heavily on remote-monitoring approaches: fence-mounted or buried intrusion sensors, thermal and visible-light cameras with video analytics tuned for rural or low-activity environments, and cellular or satellite backhaul for sites without reliable wired connectivity. Given the number of remote sites a typical utility must cover, cost-effective, low-maintenance sensing technology is often prioritized over higher-precision but more expensive systems better suited to single high-value facilities.

    Access Control for Critical Process Areas

    Within treatment plants, access control is typically layered around process criticality: chemical storage and dosing areas, SCADA control rooms, and treatment process areas warrant stricter access restrictions than administrative buildings. Credential-based access control integrated with visitor management is standard practice for controlling contractor and vendor access, which represents a recurring risk category across critical infrastructure sectors generally.

    Video Surveillance and Analytics

    Video coverage of treatment processes, chemical handling areas and perimeter zones supports both security monitoring and operational documentation. Analytics capable of detecting loitering, unauthorized vehicle presence, or intrusion at remote unstaffed sites help utilities extend effective monitoring coverage without proportionally increasing staffing.

    The Cyber-Physical Dimension

    Water and wastewater utilities have drawn specific attention from cybersecurity agencies because their operational technology — the PLCs and SCADA systems that control chemical dosing, pumping and treatment processes — is frequently older, harder to patch, and in some cases directly internet-accessible due to historical remote-access configurations designed for operational convenience rather than security. Advisories describing reconnaissance and exploitation attempts against water-sector PLCs have specifically warned operators to review remote-access configurations, apply available patches, and segment OT networks from IT infrastructure. This makes the sector a clear example of where physical security and OT cybersecurity cannot be treated as separate disciplines: a compromised remote-access pathway into a chemical dosing PLC is as much a physical-safety issue as a cybersecurity one.

    Practical Constraints Facing the Sector

    Unlike well-funded critical-infrastructure operators in sectors such as energy or aviation, many water and wastewater utilities are small municipal operations with limited security budgets and technical staff. This constraint shapes technology adoption in the sector: solutions that require minimal specialized staffing to operate, that consolidate physical and cyber monitoring into fewer platforms, and that can be deployed incrementally across a large number of small remote sites tend to see faster adoption than more sophisticated but resource-intensive alternatives designed for larger, better-funded facilities.

    FAQ

    Why are water utilities considered attractive targets?

    Water systems combine public-health impact, historically under-resourced cybersecurity programs, and operational technology that in many cases predates modern security design practices — a combination that has drawn attention from both criminal ransomware actors and state-linked groups conducting reconnaissance against OT infrastructure, according to public advisories from CISA and allied agencies.

    What is the biggest practical barrier to improving water-sector security?

    Funding and staffing constraints are widely cited as the primary barrier, particularly for small municipal utilities that lack dedicated cybersecurity or physical-security personnel and must prioritize a limited budget across a large number of distributed sites.

    Conclusion

    Securing water and wastewater infrastructure requires treating physical security, remote-site monitoring and OT cybersecurity as a single integrated problem rather than three separate budget lines. Given the sector’s resource constraints, the technologies most likely to see real-world adoption are those that consolidate monitoring, minimize specialized staffing requirements, and scale cost-effectively across large numbers of distributed, often unstaffed sites.

  • Securing the Video Surveillance Network: Camera and VMS Cybersecurity Hardening

    Securing the Video Surveillance Network: Camera and VMS Cybersecurity Hardening

    A video surveillance deployment is, from a network architecture standpoint, a fleet of embedded computers with microphones and lenses attached. Every IP camera runs firmware, exposes management interfaces, and communicates over the network with a video management system (VMS) that itself typically runs on general-purpose server infrastructure. That reality has made surveillance infrastructure an increasingly attractive target: camera botnets, credential-stuffing campaigns against exposed device management ports, and compromises of large fleets of network video recorders have all been documented by security researchers in recent years, with campaigns targeting tens of thousands of devices at a time through weak default credentials, unpatched authentication bypasses, and exposed peer-to-peer discovery services.

    Where the Attack Surface Actually Lives

    Camera and VMS security incidents tend to cluster around a small number of recurring weaknesses:

    • Default and weak credentials. Cameras and NVRs shipped with default administrative passwords, or deployed without forcing a credential change during commissioning, remain one of the most common initial-access vectors documented in mass-compromise campaigns.
    • Exposed management interfaces. Web-based camera configuration portals and VMS admin consoles left reachable from the public internet — whether through direct exposure or through port-forwarding and peer-to-peer relay services intended to simplify remote viewing — substantially expand the attack surface beyond what a properly segmented deployment would allow.
    • Unpatched firmware and software. Camera firmware and VMS platforms both accumulate disclosed vulnerabilities over their service life; devices that are difficult to patch at scale, or that are past vendor support, accumulate risk the longer they remain in service.
    • Flat network architecture. Surveillance devices placed on the same network segment as general IT infrastructure, without VLAN segmentation or firewall rules restricting camera-to-camera and camera-to-internet traffic, allow a single compromised device to become a pivot point into the broader network.

    Baseline Hardening Practices

    Network Segmentation

    Placing surveillance devices on a dedicated VLAN, with firewall rules limiting traffic to only the VMS server and required management systems, is widely regarded as the single highest-value control. Properly segmented deployments prevent a compromised camera from being used as a stepping stone to reach payroll systems, building automation, or other unrelated infrastructure.

    Credential and Access Management

    Forcing unique, strong credentials at commissioning, disabling unused default accounts, and integrating camera and VMS authentication with centralized identity management where supported all reduce the practical value of credential-based attacks. Multi-factor authentication on VMS administrative accounts is increasingly treated as a baseline expectation rather than an optional enhancement.

    Patch and Lifecycle Management

    Maintaining an inventory of camera models, firmware versions and support end-dates allows security teams to prioritize patching and plan replacement of end-of-life devices before they become the weakest link in the deployment. Vendor security advisories should be monitored on an ongoing basis, not just at initial deployment.

    Disabling Unnecessary Services

    Many cameras ship with peer-to-peer discovery, UPnP, and remote-access features enabled by default to simplify consumer setup. In enterprise deployments, these services are frequently unnecessary and expand the attack surface without a corresponding operational benefit; disabling them where not explicitly required is standard hardening guidance.

    FAQ

    Are IP cameras less secure than older analog systems?

    Not inherently — but IP cameras carry cybersecurity risks that analog systems did not, because they are addressable network devices. The security question is less about IP versus analog and more about whether the network deployment follows segmentation, credential and patch-management practices appropriate to a networked device fleet.

    Who is responsible for camera cybersecurity in most organizations?

    This varies significantly. In organizations where physical security and IT/cybersecurity functions remain siloed, camera and VMS hardening can fall into a gap between the two teams. Organizations further along in cyber-physical convergence typically assign shared or explicit ownership of surveillance-network security to avoid this gap.

    Conclusion

    Video surveillance infrastructure has moved from being a passive physical-security tool to being an active part of the enterprise attack surface. Treating cameras and VMS platforms with the same network segmentation, credential hygiene and patch discipline applied to other networked IT assets — rather than as a separate, lower-scrutiny category — is now a baseline expectation for any organization operating surveillance infrastructure at scale.

  • Industrial AI for Physical Security Operations: Predictive Maintenance Meets Threat Detection

    Industrial AI for Physical Security Operations: Predictive Maintenance Meets Threat Detection

    For most of its history, industrial artificial intelligence has lived in a separate silo from physical security. Predictive maintenance teams watched vibration sensors, thermal signatures and power-draw curves to forecast when a compressor or conveyor motor would fail. Security teams watched cameras, access logs and perimeter sensors to catch intruders and policy violations. The two disciplines rarely shared data, tooling or staff.

    That separation is eroding. As industrial facilities instrument more of their operational technology (OT) environment with connected sensors, the same telemetry streams that feed predictive-maintenance models are increasingly valuable to security operations — and vice versa. An unexplained vibration pattern on a pump, for instance, can indicate mechanical wear, or it can indicate physical tampering. A model trained to distinguish the two cases needs a security-aware view of the asset, not just a maintenance-aware one.

    Where the Overlap Is Real

    Three areas show the clearest convergence between industrial AI and physical security today:

    • Anomaly detection on shared sensor infrastructure. Vibration, thermal, acoustic and power-quality sensors originally deployed for condition monitoring can also flag events consistent with tampering, unauthorized equipment access, or sabotage — provided the analytics layer is trained to separate mechanical degradation signatures from disruption events.
    • Video analytics tied to process state. Rather than analyzing camera feeds in isolation, some facilities now correlate video analytics with process control data, so that a person detected near a valve or control panel is evaluated against whether that area is expected to be active, under maintenance, or should be unoccupied at that point in the process cycle.
    • Predictive risk scoring for OT assets. Machine-learning models that already rank equipment by failure risk are being extended to also incorporate cybersecurity exposure — patch status, network segmentation, and known-vulnerability data — producing a single risk score that blends reliability and security concerns for the same physical asset.

    Why This Convergence Is Accelerating Now

    Several forces are pushing industrial AI and physical security together. Regulatory attention on critical infrastructure has increased scrutiny of both operational reliability and cyber-physical resilience simultaneously, making it harder to justify maintaining separate, uncoordinated monitoring programs. At the same time, the cost of deploying and training separate machine-learning pipelines for maintenance and security has made a shared data platform more attractive from a budget standpoint. And as attacks on industrial control systems and programmable logic controllers have drawn public attention — including advisories from agencies such as CISA covering active reconnaissance and exploitation attempts against OT protocols — security leaders have become more willing to treat OT telemetry as a security signal in its own right, not just a reliability metric.

    Implementation Challenges

    The convergence is not without friction. OT and security teams typically report through different organizational structures, use different tools, and are measured against different KPIs — uptime for one, incident count for the other. Merging their data streams requires governance decisions about who owns alert triage, how false positives are handled without disrupting production, and how sensitive process data is protected when it becomes visible to a broader set of security personnel.

    There is also a technical challenge in model training: industrial equipment failure signatures are often well-documented after years of maintenance history, but tampering and sabotage events are comparatively rare, making it harder to train reliable classifiers without synthetic data or carefully designed red-team exercises to generate labeled examples.

    FAQ

    Does industrial AI replace dedicated physical security systems?

    No. Industrial AI applied to OT telemetry is a complementary signal, not a replacement for access control, video surveillance, or perimeter detection. Its value lies in correlating operational anomalies with security context that purpose-built security systems may not otherwise capture.

    What data is typically shared between maintenance and security teams in a converged model?

    Common shared signals include vibration and acoustic sensor data, thermal imaging, power-quality metrics, and access-control logs tied to specific equipment zones. Process control data itself is usually kept segmented and shared only in summarized or access-controlled form.

    Conclusion

    The line between predictive maintenance and physical security is blurring for a straightforward reason: both disciplines are trying to answer variations of the same question — is this asset behaving as expected? Facilities that build a shared data and governance layer between OT reliability teams and security operations are positioned to catch a wider range of anomalies than either discipline could catch alone, provided they invest in the organizational coordination the convergence requires, not just the underlying sensors and models.

  • ProdataKey and Aiphone Launch Integrated Cloud-Based Access Control and Video Intercom Solution

    ProdataKey and Aiphone Launch Integrated Cloud-Based Access Control and Video Intercom Solution

    ProdataKey (PDK) and Aiphone announced on August 26, 2026, a new cloud-based integration designed to unify access control and video intercom management for commercial and multi-tenant properties. The integration connects AiphoneCloud, Aiphone’s cloud-managed intercom platform, with PDK.io, ProdataKey’s mobile-first access control management software.

    “The future of physical security is built on connected, intuitive technologies,” said Dallan Labrum, Executive Vice President of Sales at ProdataKey. “Our integration with Aiphone gives dealers, integrators, and end users a smarter way to manage access control and video intercoms from a unified ecosystem. Together, we’re helping customers improve operational efficiency while delivering a better experience for everyone who enters and manages their buildings.”

    Automatic Tenant Sync Eliminates Duplicate Record-Keeping

    According to the companies, when tenant information is added, updated, or removed in PDK.io, those changes automatically sync to connected Aiphone IXG intercoms, eliminating the need for dealers and property managers to maintain duplicate records or manually coordinate directory updates between two separate systems. Security administrators and property managers can manage both access control and video intercom operations through a single streamlined workflow, which the companies say reduces administrative overhead and helps close security gaps caused by human error in manual record-keeping.

    The launch follows ProdataKey’s earlier preview of the integration at ISC West 2026, where the company showcased new locksets, readers, burglar-panel integrations, and video intercom offerings alongside the incoming Aiphone connection. For multi-tenant and commercial property operators, the combined platform reflects a broader industry shift toward converging previously siloed access control and visitor-verification systems into single-pane-of-glass management, reducing the operational friction that has historically accompanied maintaining separate vendor ecosystems for door access and intercom hardware.

  • Iranian State-Backed Nimbus Manticore Expands Toolset With New Backdoor and SSH Tunneler

    Iranian State-Backed Nimbus Manticore Expands Toolset With New Backdoor and SSH Tunneler

    Cybersecurity researchers at Group-IB have identified additional operational infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps. In an analysis published August 26, 2026, and reported the same day by The Hacker News, Group-IB described the group as among the most active Iranian advanced persistent threat actors of 2026.

    Nimbus Manticore — also tracked as GalaxyGato, Mirage Kitten, Screening Serpens, Smoke Sandstorm, Subtle Snail, and UNC1549 — is assessed by Group-IB to be linked to the Tortoiseshell cluster (also known as Imperial Kitten and Unyielding Wasp), itself part of the broader Charming Kitten activity cluster. The group has a documented history of using social-engineering campaigns, including fake recruitment and “Dream Job” lures, to deliver malware to targets in aerospace, defense, IT services, and telecommunications.

    New Backdoor and Tunneling Infrastructure Found Across Two Regions

    Group-IB researchers Mansour Alhmoud and Mohamed Emam identified a C++ backdoor with characteristics similar to the group’s existing TWOSTROKE implant, along with an SSH-based tunneling utility, deployed across newly discovered infrastructure spanning both Europe and the Middle East. “The discovered Tortoiseshell infrastructure potentially suggests an expanded targeting profile, focusing on Middle Eastern countries, alongside European countries,” the researchers wrote.

    The findings follow earlier reporting on the group’s NightLedger backdoor and custom WebSocket tunnelers, which Group-IB said have been used to turn compromised systems into covert network relays capable of executing commands, uploading files, and capturing screenshots while tunneling traffic through victim networks. Group-IB said the continued development of new tools alongside the expanding infrastructure footprint “demonstrates a threat actor that is steadily evolving its toolset and adapting its techniques to maintain access across a growing number of targets.”

    Organizations in the aerospace, defense, telecommunications, and critical-infrastructure-adjacent sectors that operate in Europe or the Middle East are advised to review indicators associated with the Tortoiseshell/Nimbus Manticore cluster as part of routine threat-intelligence monitoring.