Author: Osiris

  • Caterpillar and FieldAI Partner to Bring Physical AI and Autonomy to Jobsites and Factories

    Caterpillar and FieldAI Partner to Bring Physical AI and Autonomy to Jobsites and Factories

    Caterpillar Inc. has entered a collaboration with robotics startup FieldAI to bring physical AI, autonomy and robotics to construction, mining and manufacturing sites, the companies announced. The partnership pairs Caterpillar’s decades of jobsite and equipment data with FieldAI’s robot-agnostic autonomy platform, aiming to help industrial operators address labor shortages and rising productivity demands.

    Combining Operational Data With Robot-Agnostic Autonomy

    The collaboration, announced September 2, 2026, combines Caterpillar’s engineering expertise and operational data with FieldAI’s AI-enabled robot foundation models, which are designed to process large volumes of jobsite and operational data and turn real-time observations into actionable insight. FieldAI says its foundation models are already deployed across hundreds of sites worldwide and are built to operate in the kind of complex, dynamic industrial environments where conventional automation has historically struggled. The work also incorporates NVIDIA accelerated computing and Omniverse digital-twin technology, allowing the companies to build virtual representations of jobsites and manufacturing facilities for testing and validation before deployment.

    Early Applications Target Inspection and Situational Awareness

    The companies identified autonomous inspections, enhanced situational awareness, operational optimization and digital-twin modeling of jobsites and equipment as initial applications. For heavy-industry operators, autonomous inspection capabilities in particular could extend how facilities monitor equipment condition and site hazards without relying solely on scheduled manual walkthroughs. “This collaboration brings leading physical AI capabilities to a leading manufacturer of construction and mining equipment,” said Ali Agha, founder and CEO of FieldAI, adding that the companies are “shaping the next century of AI-enabled heavy industry.” The initiative builds on Caterpillar’s existing autonomous-mining programs and its broader push to extend autonomy into more complex, less structured industrial settings.

  • Microsoft Ships Record September 2026 Patch Tuesday, Fixing 964 Flaws Including Two Exploited Zero-Days

    Microsoft Ships Record September 2026 Patch Tuesday, Fixing 964 Flaws Including Two Exploited Zero-Days

    Microsoft shipped its largest Patch Tuesday on record this week, fixing 964 vulnerabilities across its product line — more than double August’s release and a new monthly high for the company. The September 2026 update includes patches for two zero-day flaws already being exploited in the wild, along with 113 vulnerabilities rated Critical.

    Two Exploited Zero-Days Among 964 Fixes

    The two actively exploited flaws include CVE-2026-81963, an elevation-of-privilege vulnerability in the Windows Update Stack that stems from improper link resolution before file access, commonly known as link following. Security researchers note the bug is most relevant to post-compromise activity, letting an attacker who already has a foothold on a system escalate to greater control. Cybersecurity companies Volexity and Proofpoint were credited with reporting one of the exploited flaws, while a researcher at Airbus Helicopters and Microsoft’s own threat intelligence team were credited with the second. The U.S. Cybersecurity and Infrastructure Security Agency has added both to its Known Exploited Vulnerabilities catalog, giving federal civilian agencies until September 22, 2026 to apply the fixes.

    A Record Critical Count Across Windows Components

    Among the 113 Critical-rated bugs, several affect core Windows security components, including CVE-2026-83939 in Windows Secure Kernel Mode and CVE-2026-83498 in Virtualization-Based Security enclave privileges. Microsoft also patched a string of remote-code-execution flaws carrying CVSS scores of 9.8, including issues in Skype for Business, the Windows Routing and Remote Access Service, the Windows HTTP Print Provider, Windows Shell and the Windows Imaging Component. None of the RCE flaws are confirmed to require no user interaction, but their severity ratings and broad footprint across widely deployed Windows components make rapid patch validation and deployment a priority for enterprise IT and security teams this month.

  • Fire Suppression Systems Explained: Wet, Dry, Clean Agent and Water Mist

    Fire Suppression Systems Explained: Wet, Dry, Clean Agent and Water Mist

    Fire suppression systems put out or contain a fire automatically, and the right choice depends heavily on what a space is protecting, since water, chemical and gas-based suppression methods each bring different trade-offs for occupant safety, equipment damage and environmental impact.

    Wet and Dry Pipe Sprinkler Systems

    Wet pipe sprinkler systems, the most common type in commercial and residential buildings, keep water constantly present in the piping so it discharges immediately when a sprinkler head activates from heat. Dry pipe systems instead hold the piping full of pressurized air, releasing water only after a valve opens, which makes them suitable for unheated spaces such as parking structures or freezer warehouses where standing water in pipes would freeze, at the cost of a short delay between activation and water reaching the fire compared with a wet system.

    Clean Agent Systems for Sensitive Equipment

    Data centers, server rooms, museums, archives and other spaces containing valuable or sensitive electronic equipment often use clean agent suppression instead of water, since gaseous agents extinguish a fire without leaving residue or causing water damage to equipment. These systems typically work by displacing oxygen below the level needed to sustain combustion or by chemically interrupting the fire’s combustion reaction, and they are designed to be used in occupied spaces at concentrations considered safe for brief human exposure, though occupants are still expected to evacuate immediately upon activation.

    Water Mist as a Middle Ground

    Water mist systems use much finer water droplets than conventional sprinklers, discharged at higher pressure, which absorb heat more efficiently and displace oxygen locally around the fire while using a fraction of the water volume of a traditional sprinkler system. This makes water mist attractive in spaces where minimizing water damage matters but a fully gaseous clean agent system is not practical or affordable, such as certain industrial machinery enclosures, heritage buildings, or marine engine rooms.

    Matching the System to the Risk

    Fire protection engineers select a suppression approach based on the specific fuel and hazard present, the value and sensitivity of what is being protected, whether the space is normally occupied, and applicable code requirements, rather than defaulting to a single technology across every building type. A single facility often uses several suppression technologies in different areas, pairing conventional sprinklers in general office space with clean agent protection in an adjoining server room, for example.

    FAQ

    Why don’t all buildings use clean agent suppression instead of water sprinklers? Clean agent systems are considerably more expensive to install and maintain than sprinklers and are typically reserved for spaces with high-value or sensitive equipment where water damage would be especially costly.

    Is water mist as effective as traditional sprinklers? Water mist can be highly effective for the specific hazards and enclosure types it is designed and tested for, but it is not a universal substitute for conventional sprinklers across all occupancy types and fire hazards.

    Are dry pipe systems slower to respond than wet pipe systems? Yes, dry pipe systems have an inherent delay because air must be released from the piping before water arrives, which is why they are used primarily where freezing risk rules out a wet pipe system rather than as a general-purpose choice.

  • Fire Alarm Control Panels Explained: Addressable vs. Conventional Systems

    Fire Alarm Control Panels Explained: Addressable vs. Conventional Systems

    The fire alarm control panel is the brain of a building’s fire detection system, and the choice between an addressable and a conventional design affects everything from how precisely a fire can be located to how much wiring an installation requires and how the system can be diagnosed and expanded later.

    Conventional Panels: Zones, Not Individual Devices

    Conventional fire alarm panels wire groups of detectors and pull stations together into zones, with each zone reporting back to the panel as a single circuit. When an alarm triggers, the panel can tell responders which zone is affected, such as a wing or floor of a building, but not which specific detector within that zone activated, meaning staff still have to physically search the zone to find the fire’s exact location. Conventional systems remain common in smaller buildings where the cost of extensive zoning is unnecessary and the building is simple enough to search quickly.

    Addressable Panels: Every Device Has an Identity

    Addressable panels assign a unique digital address to every individual detector, pull station and other device on the system, so the panel’s display can report the precise device that activated rather than just a general zone. This precision becomes increasingly valuable as buildings grow larger or more complex, since it can mean the difference between directing responders to a specific room versus an entire floor. Addressable systems also typically support continuous device-level diagnostics, such as detecting a dirty or failing smoke detector before it causes a false alarm or fails to detect a real fire, and they generally require less wiring than an equivalently sized conventional system because devices can share a single looped circuit rather than needing separate zone wiring.

    Choosing Between Them

    The decision generally comes down to building size, complexity and growth plans: conventional panels remain a cost-effective choice for small, simple buildings, while addressable panels are standard in larger commercial buildings, campuses, hospitals and any facility where precise fire location and easy future expansion justify the higher upfront cost of addressable devices and panel hardware. Many jurisdictions and insurance requirements effectively push larger or higher-occupancy buildings toward addressable systems even where a conventional system would technically satisfy basic code minimums.

    FAQ

    Can a conventional system be upgraded to addressable? Generally not by simply swapping the panel; addressable systems typically require compatible addressable devices and different wiring topology, so upgrading usually means a substantial retrofit rather than a simple panel replacement.

    Are addressable panels always required by code? Not universally. Requirements vary by jurisdiction, occupancy type and building size, though many codes and insurance standards effectively favor addressable systems in larger or higher-occupancy buildings.

    Do addressable systems reduce false alarms? They can help, since device-level diagnostics let facility staff identify and service a specific failing or contaminated detector before it causes a false alarm, something a conventional zone-based system cannot pinpoint as precisely.

  • Access Control Cybersecurity: Hardening Controllers, Readers and Credentials

    Access Control Cybersecurity: Hardening Controllers, Readers and Credentials

    Access control systems were once treated as purely physical hardware: a card reader, a controller board and a locked door. Today most systems run over IP networks, store credential databases, and expose management interfaces, which means they carry the same categories of cybersecurity risk as any other networked infrastructure, alongside the physical risk of an unlocked door.

    Controllers Are Endpoints, Not Just Hardware

    Access control panels and controllers are, functionally, small networked computers, and vulnerabilities in their firmware or management interfaces can let an attacker unlock doors, disable alarms, or extract stored credential data without ever touching the building. Recently disclosed flaws in access control and device management platforms have shown that missing authentication or hard-coded credentials in these systems can hand an attacker root-level control, underscoring why manufacturers and integrators treat firmware update discipline and network segmentation as security-critical rather than optional maintenance.

    Weak Credential Technology Is Still Common

    Despite years of known weaknesses, many sites still rely on older low-frequency proximity cards and legacy Wiegand wiring between readers and controllers, both of which can be cloned or intercepted with inexpensive, widely available equipment. Modern smart cards and mobile credentials using encrypted protocols close much of this gap, but only if a site has actually migrated its readers, controllers and credentials together; a modern reader paired with an unencrypted legacy card format, or vice versa, can leave the original vulnerability largely intact.

    Network Segmentation and Monitoring

    Best practice increasingly places access control controllers on a segmented network separate from general office IT traffic, limiting what an attacker who compromises one system can reach from the other. Pairing that segmentation with logging and monitoring of controller and management-software activity helps detect unusual behavior, such as after-hours credential changes or unexpected firmware update attempts, before it results in an unauthorized physical entry.

    FAQ

    Can a cyberattack on access control lead to a physical break-in? Yes. If an attacker gains control of an access control system’s management interface, they may be able to unlock doors, add unauthorized credentials, or disable alarms, translating a network compromise directly into physical access.

    Are older proximity cards insecure? Many legacy low-frequency proximity card formats can be cloned with low-cost, readily available equipment, which is why organizations are increasingly migrating to encrypted smart card or mobile credential technology.

    Should access control systems be on the same network as office computers? Security best practice generally recommends network segmentation, keeping access control controllers and servers on a separate network segment from general office IT traffic to limit the blast radius of a compromise on either side.

  • Airport Security Technology: Layered Perimeter, Screening and Access Control

    Airport Security Technology: Layered Perimeter, Screening and Access Control

    Airports operate one of the most complex physical security environments of any facility type, combining a large outdoor perimeter, high-throughput passenger screening, tightly restricted airside access, and constant coordination with law enforcement and aviation authorities, all while keeping flights moving on schedule.

    Protecting the Airfield Perimeter

    The airfield perimeter, often several miles of fence line separating public areas from runways, taxiways and aircraft, is typically monitored with a combination of fencing, ground radar, thermal cameras and buried or fence-mounted intrusion sensors, since a single unauthorized incursion onto an active runway can halt operations across the entire airport. Larger airports increasingly integrate airfield perimeter sensors with counter-drone detection systems, addressing the growing risk that unauthorized drone activity near runways poses to aircraft during takeoff and landing.

    Passenger and Baggage Screening

    Checkpoint screening combines walk-through metal detectors or millimeter-wave body scanners for passengers with X-ray and, increasingly, computed tomography (CT) scanning for carry-on baggage, giving screeners a rotatable 3D image rather than the flat 2D image older X-ray systems produce. Checked baggage passes through separate, higher-throughput explosive detection systems behind the scenes, and biometric identity verification, typically facial recognition matched against a passport or boarding pass, is increasingly used to speed passengers through checkpoints and boarding gates without manual document checks at every step.

    Controlling Access to Restricted Airside Areas

    Access to the airfield, ramp areas and other restricted zones is controlled through badge-based access control systems layered with biometric verification, since a badge alone does not confirm that the person carrying it is its rightful holder. Airports also enforce strict escorting and challenge procedures for anyone in a restricted area without airport-issued credentials, backed by video surveillance covering gates, ramps and cargo areas to create an audit trail of who accessed which zone and when.

    FAQ

    Why do airports need counter-drone systems? Unauthorized drones near runways and approach paths pose a collision risk to aircraft during takeoff and landing, which has led many larger airports to add drone detection alongside their existing airfield perimeter sensors.

    What is the difference between X-ray and CT baggage screening? Traditional X-ray produces a flat 2D image of a bag’s contents, while CT scanning produces a rotatable 3D image, giving screeners a clearer view of items that might otherwise be obscured or ambiguous in a 2D scan.

    How is facial recognition used at airports? Facial recognition is typically used to match a live photo of a passenger against their passport or boarding pass photo at checkpoints or boarding gates, allowing faster verification than a manual document check.

  • Vehicle Barriers and Bollards: How Anti-Ram Perimeter Protection Actually Works

    Vehicle Barriers and Bollards: How Anti-Ram Perimeter Protection Actually Works

    Bollards and vehicle barriers have become a standard part of perimeter protection at government buildings, stadiums, transit hubs and commercial plazas, driven by a mix of vehicle-ramming attacks and simple traffic accidents. What looks like a decorative post or a low steel arm is, in most professional installations, a rated device engineered and tested to stop a specific vehicle at a specific speed.

    Fixed, Removable and Automatic Bollards

    Fixed bollards are permanently anchored and offer the highest reliability since there is no mechanism to fail, but they permanently block the space they occupy. Removable or retractable bollards can be taken out of the ground or lowered to allow authorized vehicle access, trading some convenience for a manual or semi-manual operating step. Automatic bollards rise and lower on command from an access control system, gate operator or guard station, letting a single lane serve both pedestrians and authorized vehicles without a fixed barrier permanently occupying the space, at the cost of added mechanical and power complexity that must be maintained.

    Crash Ratings Are Not Marketing Claims

    Serious perimeter security specifications reference independent crash-rating standards, most commonly the US State Department’s K-rating system and ASTM F2656, which test a barrier against a vehicle of a defined weight striking it at a defined speed and measure how far the vehicle penetrates past the barrier line after impact. A barrier rated to stop a 15,000-pound vehicle at 40 miles per hour behaves very differently in a real event than an unrated decorative post that merely looks similar, which is why security consultants specify barriers by their tested rating rather than their appearance.

    Barriers as Part of a Layered Approach

    Bollards and barriers are typically combined with standoff distance, planters, retaining walls, sloped grading and other landscape features that a site’s architects can use to keep vehicles away from a building without visually presenting as a fortress. Security planners generally treat the vehicle barrier line as the outermost layer of a broader protection plan that also includes access control, video surveillance and, at higher-risk sites, manned checkpoints, rather than as a standalone solution to vehicle-borne threats.

    FAQ

    What is a K-rating? K-ratings are a US State Department classification system that rates a barrier’s ability to stop a vehicle of a specified weight traveling at a specified speed, based on independent crash testing.

    Can automatic bollards fail open or closed during a power outage? Behavior varies by product and installation; many automatic bollards are specified to fail in a particular position (safe, secure, or last-known-state) depending on site requirements, which is a key design decision during installation.

    Do decorative bollards provide real vehicle protection? Only if they carry an independent crash rating for the intended threat vehicle and speed. Purely decorative posts without a tested rating should not be relied on to stop a vehicle.

  • Consumer Cybersecurity Firm Guardio Reaches $1.1 Billion Valuation as Wiz Co-Founder Invests

    Consumer Cybersecurity Firm Guardio Reaches $1.1 Billion Valuation as Wiz Co-Founder Invests

    Guardio, a consumer cybersecurity company focused on protecting individuals from online scams and phishing, has raised $40 million in new funding at a valuation of $1.1 billion, with Wiz co-founder and chief executive Assaf Rappaport joining as an investor.

    Four Straight Years of Triple-Digit Growth

    The round, announced September 3, 2026, also included existing investors ION Crossover Partners, Union Tech Ventures, Vintage Investment Partners, Cerca Partners and Emerge Ventures, and brings Guardio’s total funding to date to $167 million. The Israeli company said it has grown revenue more than 100% year over year for four consecutive years, surpassing one million paying customers and $150 million in annual recurring revenue. Guardio plans to use the new capital to expand its suite of consumer-focused protection tools covering browsing, phishing and broader digital-presence risks.

    AI Cuts Both Ways for Consumer Fraud

    Gilad Shany, managing partner at ION Crossover Partners, said the company’s combination of cybersecurity expertise, consumer-product focus and distribution reach was behind the sustained growth. Rappaport, who invested personally in the round, pointed to artificial intelligence as a factor reshaping the threat landscape for ordinary consumers, making phishing, brand impersonation and deepfake voice scams more convincing and harder to distinguish from legitimate communication. Guardio’s raise adds to a run of large valuations for Israeli cybersecurity companies in 2026, as consumer-facing security products compete for a growing pool of capital alongside enterprise-focused vendors.

  • Researchers Build Zero-Click Worm That Hijacked WeChat Accounts via a Single Call

    Researchers Build Zero-Click Worm That Hijacked WeChat Accounts via a Single Call

    Security researchers at the firm Calif built a working worm capable of hijacking WeChat accounts on both iOS and Android through a single incoming call, then using the compromised account to spread automatically to the victim’s contacts, in what the company describes as the first zero-click worm demonstrated against a mainstream messaging app on both platforms.

    Attacker Calls Victim, Victim Becomes Attacker

    In a demonstration published September 8, 2026, Calif showed an Android phone calling an iPhone and taking over its WeChat account while the phone was still ringing, with no answer or user interaction required. The compromised iPhone then called a second Android phone and took control of it the same way, illustrating a self-propagating chain: attacker calls victim, victim becomes attacker, victim calls the next victim. Calif said the underlying issue is a memory-corruption bug in WeChat’s VoIP stack, and that because the caller must already be on the target’s contact list, the extra trust WeChat extends to contacts ends up working in the attacker’s favor once one account in a network is compromised. Once hijacked, an account can read and send messages, place calls, and act on the victim’s behalf.

    Patched Before Public Disclosure

    Calif reported the flaw to WeChat developer Tencent in July, and Tencent shipped version 8.0.77 for Android and 8.0.76 for iOS on August 21, 2026, mitigating the bug; Calif confirmed on August 28 that the specific exploit was also blocked on Tencent’s servers for all users regardless of app version. Tencent has not published a security advisory describing the flaw, and its release notes for the affected updates describe them only as general bug fixes. Researchers are advising WeChat users to keep the app updated, review their contact lists for unfamiliar connections, and treat unexpected incoming calls from known contacts with caution, since a compromised contact’s account could be used to continue the propagation chain.

  • Alby Discloses Critical Flaw in Internet-Exposed Bitcoin Lightning Wallets

    Alby Discloses Critical Flaw in Internet-Exposed Bitcoin Lightning Wallets

    Alby, the company behind the Bitcoin Lightning Network and Nostr tooling suite Alby Hub, has disclosed a critical vulnerability affecting older versions of its self-hosted Lightning wallet that could let an attacker take over and drain funds from any instance left reachable from the public internet.

    Unauthenticated Access to the Management API

    In a disclosure posted September 9, 2026, Alby said it had confirmed a critical flaw in Alby Hub versions 1.7.0 through 1.18.5, released before August 2025, when the Hub is publicly accessible from the internet. According to the company, an attacker who can reach the Hub’s management API over the network can access it without authorization and send funds out of the wallet, effectively draining any exposed node. Alby urged affected users to immediately take internet-exposed instances offline, update to a patched version, and change their unlock password after updating, since the credential itself could have been exposed during the window the Hub was reachable.

    Part of a Rough Stretch for Lightning-Adjacent Projects

    The disclosure follows a difficult few weeks for Lightning Network-adjacent infrastructure: Boltz, a separate non-custodial bridge that moves bitcoin between the main chain, the Lightning Network and the Liquid Network, took its swap functionality offline on August 3, 2026, after its own security issue, and Bitcoin’s Liquid Network separately suffered a $320 million theft that white-hat hackers later helped partially recover. Security researchers have pointed to the growing use of AI-assisted attack tooling as a factor putting increased pressure on smaller, self-hosted Bitcoin infrastructure projects that lack the security resources of larger custodial platforms.