Author: Osiris

  • Stadium and Large-Venue Security: Screening, Crowd Monitoring and Command Coordination

    Stadium and Large-Venue Security: Screening, Crowd Monitoring and Command Coordination

    Stadiums and large public venues concentrate tens of thousands of people, media, vendors and staff into a fixed footprint for a defined window of time. That combination of scale, timing and public exposure makes venue security a distinct discipline from everyday facility protection.

    Perimeter screening at scale

    Entry screening for a major event has to process large crowds quickly without creating dangerous queuing at the perimeter itself. Many venues now combine walkthrough magnetometers or AI-assisted weapons-detection lanes with bag policies and staffed pat-downs, tuning the mix of technology and staffing to the expected attendance and threat level of a given event.

    Video surveillance and crowd-density monitoring

    Venue-wide camera networks support both security monitoring and operational needs such as identifying overcrowding at concourses, exits or transit points. Crowd-density analytics can alert operators when a specific area approaches capacity, which supports both security response and general life-safety planning for evacuation.

    Access control for restricted areas

    Beyond the general admission perimeter, stadiums manage layered access to locker rooms, broadcast areas, VIP suites, loading docks and back-of-house corridors. Credentialing systems for staff, media and vendors typically combine badges with access-control integration so that movement through restricted zones is logged and can be reviewed after an incident.

    Counter-drone and airspace awareness

    Unauthorized drone activity over stadiums during events has become a more frequent operational concern, and some major venues have added counter-UAS detection capability to identify unauthorized aircraft near the venue during events, coordinating with local aviation and law-enforcement authorities on any mitigation response, since counter-drone mitigation options are tightly regulated in most jurisdictions.

    Unified command and multi-agency coordination

    Large events typically involve venue security, local police, fire and emergency medical services operating from a shared or closely coordinated command structure. A unified command center that brings together video feeds, access-control status, radio communications and public-address control lets these agencies share situational awareness in real time rather than working from separate information sources.

    Planning around specific event risk

    Security planning for a venue is not static: a regular-season game, a championship event and a concert with a different audience profile can carry different risk considerations. Venue operators generally adjust staffing, screening intensity and technology configuration event by event rather than applying a single fixed posture year-round.

    Conclusion

    Stadium and large-venue security depends on technology that can operate at crowd scale, from rapid screening to crowd-density analytics to counter-drone awareness, integrated through a command structure that allows venue security and public-safety agencies to act on the same information together.

  • School and Campus Security Technology: Access, Detection and Communication

    School and Campus Security Technology: Access, Detection and Communication

    Schools and college campuses share a difficult security profile: they must stay open and welcoming to students, staff, families and visitors, while protecting large populations across buildings that were often not designed with modern security requirements in mind.

    Layered access control

    Many K-12 campuses now control building entry with electronic locks, visitor check-in systems and single-point-of-entry designs during the school day, while allowing classrooms to be locked from inside in an emergency. University campuses typically layer broader perimeter and building access around more open pedestrian environments, since restricting movement across an entire campus is rarely practical.

    Visitor management

    Digital visitor-management systems that screen visitors against watchlists, print time-limited badges and log entry and exit have become standard in many districts, replacing paper sign-in sheets. These systems give administrators a real-time record of who is on site, which matters both for day-to-day safety and for emergency accountability.

    Weapons detection and screening

    Some districts and universities have introduced weapons-detection systems at building entrances, ranging from traditional metal detectors to newer AI-assisted scanning designed to move larger volumes of students through checkpoints with less friction than manual bag checks. Adoption varies widely by district and budget, and the technology is generally deployed as one layer among several rather than a standalone solution.

    Video surveillance and analytics

    Camera coverage of entrances, hallways, parking areas and building perimeters supports both incident response and day-to-day safety and discipline needs. Some systems add analytics for tasks such as detecting a propped-open door or unusual after-hours activity, which can be more useful on large, multi-building campuses than continuous human monitoring alone.

    Mass notification and emergency communication

    Rapid, campus-wide communication is central to school security planning. Mass-notification systems typically combine PA announcements, text and email alerts, and integration with local law enforcement, and many districts now tie lockdown procedures to a single trigger that activates locks, notifications and camera views simultaneously.

    Balancing security and learning environment

    Security leaders in education generally caution against measures that make schools feel like fortified facilities, since that can affect student wellbeing without necessarily improving safety outcomes. Physical security investments are typically paired with threat-assessment programs, staff training and clear procedures, which education-security researchers describe as at least as important as the technology itself.

    Conclusion

    Effective school and campus security combines layered access control, visitor management, appropriate detection technology, video coverage and fast communication, implemented in a way that fits the culture and openness required of a learning environment rather than working against it.

  • Retail Loss Prevention Technology: Cameras, EAS and AI in 2026

    Retail Loss Prevention Technology: Cameras, EAS and AI in 2026

    Retail security has to solve two problems at once: reduce theft and operational loss, and keep stores welcoming to paying customers. That balance shapes almost every technology decision in the sector.

    Shrink is more than shoplifting

    Retailers typically group loss into external theft, internal theft, process failures such as pricing or receiving errors, and vendor fraud. Because the causes differ, effective loss-prevention programs combine several tools rather than relying on a single system, and they measure results against the specific type of loss they are meant to address.

    Video analytics and exception-based reporting

    Modern video management systems can flag specific patterns for review, such as high-value transactions without a matching item scan, repeated returns, or unusual dwell time near high-shrink categories. Exception-based reporting narrows a large volume of camera footage down to the clips most likely to matter, which is essential in stores with dozens of cameras and limited loss-prevention staff.

    Electronic article surveillance and RFID

    Electronic article surveillance (EAS) tags and gates remain a baseline deterrent at store exits. Item-level RFID adds a further layer by giving retailers near real-time visibility into inventory location, which supports both loss prevention and out-of-stock reduction. The two technologies are increasingly deployed together rather than as alternatives.

    Point-of-sale integration

    Connecting video to point-of-sale and self-checkout transaction data lets a system correlate what a camera captured with what was actually rung up. This is particularly relevant for self-checkout, where scan-avoidance and mis-scanning account for a meaningful share of shrink at many retailers, and where store layout and camera placement affect how well a system can verify a transaction.

    Access control and back-of-house protection

    Loss prevention extends beyond the sales floor. Receiving docks, stockrooms and cash offices benefit from access control, audit trails and camera coverage focused on internal theft and vendor-fraud risks, which studies consistently identify as a significant share of total retail shrink.

    Balancing security with customer experience

    Overly visible or intrusive security measures can affect how customers perceive a store. Retailers increasingly favor systems that operate quietly in the background, use data to focus staff attention where it is most useful, and avoid treating every shopper as a suspect.

    Conclusion

    Retail loss-prevention technology works best as a layered, data-driven program rather than a single device. The strongest deployments combine video analytics, EAS or RFID, point-of-sale integration and access control, and they measure outcomes against the specific categories of loss each layer is designed to reduce.

  • Denmark Selects Terma to Build Nationwide Counter-Drone Defense System

    Denmark Selects Terma to Build Nationwide Counter-Drone Defense System

    A Shared National Drone Picture

    Denmark’s Ministry of Defence Acquisition and Logistics Organisation (DALO) announced on August 19, 2026 that it has selected Danish defense contractor Terma to deliver an integrated, nationwide command-and-control system for counter-drone defense. The system will connect existing and future sensors operated by the Danish Armed Forces, civilian authorities and critical infrastructure operators into a single shared drone situational picture, according to Terma.

    “To defend ourselves, we need to be able to eliminate enemy drones in our airspace,” Danish Defense Minister Jeppe Bruus said of the contract. Terma said the platform will support the management of drone incidents at military installations, airports, ports, energy facilities, government buildings and other critical infrastructure sites, and that its architecture is designed to allow additional sensors, sites and countermeasures to be integrated over time.

    Built on Terma’s Helion Data Backbone

    The system is based on Terma Helion, the company’s multi-domain data backbone, and will integrate command-and-control and data-fusion software from OSL Technology, which Terma acquired in 2025. The combined platform uses artificial intelligence to process, classify and prioritize sensor data, fusing input from radar, other surveillance systems and third-party sensors to support tactical decision-making at both local and central command levels.

    “This new agreement with Terma is an important cornerstone in the ongoing effort to build a strong counter-drone capability, both within the Danish Armed Forces and Danish industry,” said Lieutenant General Per Pugholm Olsen, chief of DALO. The contract comes as European states have grown increasingly concerned about unauthorized drone activity near military sites, airports and other critical infrastructure. Terma and DALO did not disclose the contract value.

    Sources

  • DHS Awards Department-Wide Contracts for Counter-Drone Capabilities

    DHS Awards Department-Wide Contracts for Counter-Drone Capabilities

    A Common Acquisition Pathway Across DHS

    The Department of Homeland Security announced on August 5, 2026 that it has made multiple contract awards to support department-wide access to Counter-Unmanned Aircraft Systems (C-UAS) capabilities. The awards give DHS components a common pathway to acquire C-UAS hardware, software and services tailored to fixed-site, mobile, aviation, maritime, aircraft-based and special-mission environments, according to the department’s Science and Technology Directorate.

    “These awards mark an important step in strengthening DHS’s ability to respond to unauthorized and malicious unmanned aircraft systems,” said Homeland Security Secretary Markwayne Mullin. “By taking a Department-wide approach, we are improving mission readiness, supporting more consistent capabilities, and helping ensure DHS personnel have access to the right tools for the job.”

    Replacing Fragmented Procurement

    DHS components have historically procured C-UAS capabilities through separate acquisition efforts. The new contract structure is intended to support greater consistency, interoperability, operational flexibility, technology refresh and lifecycle management across the department, while still letting individual components select solutions aligned to their specific missions. The awarded contracts cover detection, tracking, classification, identification, mitigation, command-and-control integration, training, maintenance, technical support, system integration, research and development, test and evaluation, and vendor-operated turnkey services.

    “As unmanned aircraft systems become more capable and more widely available, DHS needs solutions that can adapt,” said Under Secretary for Science and Technology Pedro Allende. Components expected to use the contract include the U.S. Secret Service, U.S. Coast Guard, Customs and Border Protection, Immigration and Customs Enforcement, the Transportation Security Administration, FEMA, the Federal Protective Service, U.S. Citizenship and Immigration Services, and the Science and Technology Directorate itself. DHS did not disclose specific contract values or awardee names in its announcement.

    Sources

  • Johnson Controls Metasys Building Automation Platform Patches Persistent XSS Vulnerability

    Johnson Controls Metasys Building Automation Platform Patches Persistent XSS Vulnerability

    Crafted URL Can Hijack Administrator Sessions

    CISA published ICS advisory ICSA-26-225-14 on August 13, 2026, disclosing a cross-site scripting vulnerability in Johnson Controls Metasys, a building automation and management platform used across critical manufacturing, commercial facilities, government facilities, transportation systems and energy sites worldwide. Tracked as CVE-2026-34491 and rated CWE-79, the flaw carries a CVSS v3 base score of 8.0.

    According to CISA, a low-privilege user can inject a malicious payload into the Metasys web interface through a crafted URL. The payload persists across logins and executes in the browser context of other users who view the affected page, including administrators, which could lead to session hijacking and unauthorized access to building systems. The advisory lists Metasys 12 and 13 as affected in all versions, and Metasys 14 before v14.1.5 and Metasys 15 before v15.0.1.

    Mitigation

    Johnson Controls has released patched versions for the affected Metasys 14 and 15 branches and published mitigation guidance for the platform. CISA recommends operators apply the available updates, restrict Metasys web interface access to trusted networks, and follow standard input-validation and session-management hardening for building management system deployments.

    Sources

  • Siemens Patches Critical Remote Code Execution Flaw in Siveillance Video Management Servers

    Siemens Patches Critical Remote Code Execution Flaw in Siveillance Video Management Servers

    Command Injection Rated Critical

    CISA published ICS advisory ICSA-26-225-09 on August 13, 2026, describing a critical vulnerability in Siemens Siveillance Video, a video management platform deployed worldwide across the critical manufacturing, communications and commercial facilities sectors. Tracked as CVE-2026-3014 and rated CWE-78 (OS Command Injection), the flaw affects Siveillance Video V2023 R3 versions before 23.3.27, V2024 R1 versions before 24.1.16, and V2025 versions before 25.1.15, with a CVSS v3 base score of 9.1.

    According to the advisory, a user with edit permissions on the Management Server can exploit the flaw to execute arbitrary code in the context of the Management Server service, which could allow an attacker to take control of connected video management infrastructure.

    Updates Available for All Affected Branches

    Siemens has released fixed versions for each affected release branch: V23.3 HotfixRev27 or later, V24.1 HotfixRev16 or later, and the V25.1.15 update for the 2025 branch. CISA and Siemens recommend that operators update to the corrected versions as soon as practical and, in line with general ICS hardening guidance, restrict Management Server edit permissions to trusted administrators and segment video management infrastructure from untrusted networks.

    Sources

  • CISA Details Credential Exposure Flaw in Johnson Controls Simplex Incident Manager

    CISA Details Credential Exposure Flaw in Johnson Controls Simplex Incident Manager

    Cleartext Credentials Found in Memory

    The Cybersecurity and Infrastructure Security Agency published ICS advisory ICSA-26-232-01 on August 20, 2026, disclosing a vulnerability in Johnson Controls Simplex Incident Manager, a fire and life-safety incident-management application used across critical manufacturing, commercial facilities, government facilities, transportation systems and energy sites worldwide. Tracked as CVE-2026-27875, the flaw stores user credentials, including passwords and authentication tokens, in an unencrypted form in system memory while the application is running.

    CISA assigned the vulnerability a CVSS v3.1 base score of 5.8 (medium), rating it CWE-316, Cleartext Storage of Sensitive Information in Memory. A local attacker with low privileges, or an insider with memory-dumping tools, could extract the exposed credentials and use them for unauthorized access to the application and connected systems. Exploitation requires local access to the host, and CISA rates the attack complexity as high.

    Patch Available

    Johnson Controls has released version v2.01.01 to address the flaw and published Product Security Advisory JCI-PSA-2026-28 with mitigation guidance. CISA and the vendor recommend upgrading affected Simplex Incident Manager deployments (v2.01 and earlier), restricting local system access to authorized personnel, deploying endpoint monitoring to detect memory-dumping activity, enforcing least-privilege access controls, and using full-disk encryption and secure boot to reduce the risk of offline memory analysis.

    Johnson Controls reported the vulnerability to CISA. No public evidence of active exploitation has been disclosed.

    Sources

  • Flock Safety Cuts License-Plate Data Retention to Seven Days Amid Surveillance Backlash

    Flock Safety Cuts License-Plate Data Retention to Seven Days Amid Surveillance Backlash

    New Guardrails Announced Amid Growing Criticism

    Flock Safety, which operates a nationwide network of more than 119,000 automated license-plate-reader (ALPR) cameras used by law enforcement agencies, announced a set of privacy and accountability reforms on August 13, 2026, according to Fox Business. The changes come as the company faces mounting criticism from privacy advocates and elected officials over mass surveillance concerns and reports of officers misusing the technology, including cases documented by Wired in which police reportedly used Flock data to track romantic partners.

    Flock CEO Garrett Langley discussed the changes publicly, telling Fox Business’s “Varney & Co.” that the reforms were a direct response to backlash the company has faced over its car-tracking cameras. Some local officials have gone further than criticism: Knox County, Tennessee, Mayor Glenn Jacobs has called for a national moratorium on further deployment of Flock’s camera network, according to Fox Business.

    Shorter Retention, Mandatory Audit Controls

    The centerpiece of the announcement is a reduction in Flock’s standard data-retention window from 30 days to seven. The company said that roughly 90% of all searches conducted on its platform already occur within a week of data capture, arguing the shorter window would have limited practical effect on law enforcement’s ability to use the system while narrowing the amount of location data stored on Flock’s servers at any given time. For cases requiring longer retention, Flock is introducing an “Evidence Mode” feature that lets agencies preserve specific data for extended periods under state or local policy.

    Flock is also making its “Audit Assistance” feature — which flags abnormal search behavior and can lock a user out of the system in real time pending administrator review — mandatory for all law enforcement customers rather than optional; the company said roughly a third of agencies had turned the feature on voluntarily before the change. Separately, Flock is making the previously optional requirement to log a case code with every search mandatory going forward, with an override reserved for emergencies such as missing-child cases. “A search without a reason is a search that shouldn’t happen in the first place, and now Flock’s system automatically treats it that way,” the company told Fox Business.

    New Controls Over Cross-Agency Data Sharing

    The company is also giving individual agencies more granular control over which types of cases they will share camera search access for with other jurisdictions. In comments to Fox Business, Flock gave the example that “City A could allow City B to search its cameras for a stolen vehicle or violent crime while blocking searches related to immigration enforcement” — an option aimed at addressing concerns that Flock’s interconnected camera network could be used for purposes individual municipalities have not authorized.

    Civil liberties groups were not satisfied by the announcement. The American Civil Liberties Union said in a statement reported by Fox Business that the reforms “seem to be a thinly veiled PR attempt to counter communities’ genuine privacy concerns with its mass surveillance system with largely hollow security promises, rather than an earnest effort to address them.” Flock, for its part, has pointed to its own figures on the technology’s investigative use, telling Fox Business that its cameras were involved in roughly 1 million investigations last year and were tied to the location of about 10,000 missing people — figures that reflect the company’s own reporting and have not been independently verified.

    Sources

  • UK and Ukraine Sign AI Defense Partnership Granting Access to Ukraine’s Avengers AI Labs

    UK and Ukraine Sign AI Defense Partnership Granting Access to Ukraine’s Avengers AI Labs

    Britain and Ukraine signed a partnership in Kyiv on Monday, August 24, 2026, to jointly develop artificial intelligence tools for defense and security, with the UK becoming the first international partner granted access to Ukraine’s Avengers AI Labs battlefield-data platform, according to Reuters and a UK government statement.

    A Battlefield Dataset Built From Ukraine’s War

    UK Prime Minister Andy Burnham and Ukrainian President Volodymyr Zelenskyy signed the agreement, which the UK government describes as part of the two countries’ “100 Year Partnership.” Avengers AI Labs is built around an annotated dataset of roughly 5 million battlefield images, according to Ukraine’s Defence Ministry, drawn largely from the DELTA combat management and situational-awareness system. The platform aggregates data from cameras and sensors deployed across Ukraine’s front lines, capturing tanks, artillery, air-defense systems, infantry and aerial targets including Shahed drones and reconnaissance UAVs, which is used to train AI models that the UK government says currently identify a majority of targets in real time.

    Under the deal, Britain will in turn back Ukraine with access to its universities, researchers and technology companies, which the UK government describes as the world’s third-largest AI ecosystem. The agreement initially focuses on defense and national-security applications, bringing together engineers, academics, businesses and military operational experts from both countries.

    Fiber-Optic Sensing and Low-Power AI Chips Among First Pilot Projects

    Three British startups — Bristol-based Sintela, Oxford-based Mind Foundry, and London-based Skyral — are involved in the initial pilot projects announced alongside the partnership. The first project turns buried fiber-optic cables into a distributed AI-enabled sensor system, initially being trialed at a UK defense site to detect protesters and hostile actors attempting to gather intelligence; UK officials say the same approach could later extend to protecting airports, prisons, railways and energy plants. A second pilot project will explore low-power AI chips designed for future drones, robotics and autonomous systems.

    The AI agreement was announced alongside a separate decision by the UK to let defense contractor MBDA release classified information on UK-made components for the SCALP long-range missile, enabling local assembly lines in Ukraine. UK Defence Secretary Wes Streeting and AI Minister Kanishka Narayan both framed the AI partnership as part of a broader push to convert Ukraine’s wartime operational data into long-term technology and national-security capability for both countries.

    Sources