Author: Osiris

  • ASUS Patches Critical Flaws Letting Attackers Seize Control Center Enterprise and Nearby Hosts

    ASUS Patches Critical Flaws Letting Attackers Seize Control Center Enterprise and Nearby Hosts

    ASUS has released security updates fixing critical vulnerabilities across two of its device-management products, including a maximum-severity flaw that let an unauthenticated attacker gain root access to the server managing an organization’s fleet of PCs and workstations.

    A Chained Path to Root on Control Center Enterprise

    The more severe issue, CVE-2026-75754, carries a CVSS score of 10.0 and affects ASUS Control Center Enterprise (ACC) version 4.0.0.2 and all earlier releases. It stems from a chain of missing authentication, server-side request forgery and hard-coded credentials: an attacker can send a crafted HTTP request to obtain the system’s encryption key, which causes a local service to open SSH on port 2222, then use hard-coded credentials to obtain a root shell on the ACC server. Successful exploitation gives an attacker full control of the platform, including the ability to read, modify or delete stored data and remotely manage every server, PC and workstation the platform oversees. ASUS published the fix on September 4, 2026.

    A Second, Separate Flaw in Control Center Express

    ASUS separately patched CVE-2026-19397, a missing-authentication vulnerability in the Control Center Express Agent affecting versions before 1.7.24. The flaw, classified as CWE-306, allows an unauthenticated nearby attacker with a direct connection to the agent to take control of a host that has an active login session, potentially executing code or performing any action available to the logged-in user. ASUS published updates for Control Center Express and its Armoury Crate software, which separately addressed a flaw that could expose a user’s NTLM hash, on September 8, 2026. Neither vulnerability has been reported as actively exploited, but organizations running either platform are advised to update immediately given the scope of access each flaw can grant.

  • Mercury Security Launches S4 I/O Module Family to Modernize Access Control Infrastructure

    Mercury Security Launches S4 I/O Module Family to Modernize Access Control Infrastructure

    Mercury Security, an HID brand and a longtime supplier of open-architecture access control hardware, has launched its Mercury S4 I/O Module family, a new generation of intelligent modules designed to help organizations expand and modernize physical access control systems built on existing Mercury infrastructure.

    More Capacity, Built-In Cryptographic Headroom

    According to Mercury, the S4 family delivers six times the memory and eight times the storage of prior-generation modules, along with support for post-quantum cryptography aimed at hardening access control communications against future cryptographic threats to critical infrastructure. The modules are built for forward and backward compatibility, letting integrators add doors, readers and other security devices to existing Mercury intelligent controllers without replacing them, while increasing door density and reducing the physical footprint of the resulting installation.

    Responding to Longer Infrastructure Lifecycles

    The company said its ongoing research into access control professionals’ priorities identified sustained emphasis on cybersecurity and data protection standards, alongside a need for hardware that supports both forward and backward compatibility as organizations plan access control investments over longer timeframes. The Mercury S4 I/O Modules are available now through Mercury’s OEM partner network, extending an open-architecture platform the company has developed since its founding in 1992.

  • Qualcomm and AWS Sign Multi-Generation Deal for Custom AI Inference Silicon

    Qualcomm and AWS Sign Multi-Generation Deal for Custom AI Inference Silicon

    Qualcomm and Amazon Web Services have signed a multi-generation collaboration agreement to develop customized silicon and optical connectivity for AWS’s AI data center infrastructure, marking one of Qualcomm’s most significant moves yet into the data-center chip market long dominated by Nvidia.

    Custom Inference Chips and High-Speed Optical Links

    Under the agreement announced September 8, 2026, Qualcomm Technologies will work with AWS to design customized silicon focused on AI inference workloads, alongside advanced optical connectivity solutions supporting interconnect speeds up to 1.6 terabits per second and future generations beyond that. “As AI demand accelerates, data center infrastructure will require advances in both computing and connectivity to deliver greater performance with more efficiency,” said Cristiano Amon, president and chief executive of Qualcomm, adding that the company aims to bring “decades of leadership in advanced processing and power-efficient compute” to AWS’s AI infrastructure.

    A Warrant Tied to Billions in Future Purchases

    As part of the deal, Qualcomm issued Amazon a warrant to acquire up to 25 million shares of Qualcomm common stock, vesting as AWS makes purchases under the agreement, up to a cap of $60 billion over a ten-year term. The warrant carries an exercise price of $161.26, roughly 4.4% below Qualcomm’s September 4 closing price, with 3.75 million shares vesting immediately at signing. Qualcomm shares rose sharply following the announcement. The agreement follows Qualcomm’s introduction of its AI200 and AI250 data-center inference chips last year and reflects the company’s broader push to diversify beyond smartphone processors into AI infrastructure, an area where hyperscalers including Amazon, Google and Microsoft have increasingly sought custom silicon to reduce reliance on Nvidia.

  • Pavion Expands Midwest Reach With Acquisition of Indiana-Based Communication Company

    Pavion Expands Midwest Reach With Acquisition of Indiana-Based Communication Company

    Pavion, a systems integrator specializing in fire, life safety, security and critical communications, has acquired Communication Company, a South Bend, Indiana-based technology solutions provider that has served the region for roughly five decades, the company announced.

    Regional Relationships and Healthcare Expertise

    Founded in 1976, Communication Company brings established local customer relationships, technical expertise and service capabilities to Pavion’s broader portfolio, which spans fire and life safety, security, critical communications, audiovisual and integrated technology solutions. Pavion said the deal also strengthens its healthcare capabilities, since Communication Company has experience supporting hospitals and healthcare systems, complementing Pavion’s existing work in nurse call, real-time location systems and life-safety technology for the sector.

    Part of a Broader Growth Strategy

    “Communication Company has built an impressive legacy by earning the trust of its customers through exceptional service, technical expertise and strong local responsiveness,” said Joe Oliveri, chief executive officer of Pavion, adding that the acquisition expands the combined company’s ability to help organizations across the Midwest “connect and protect their people, property and assets.” The Chantilly, Virginia-based company, backed by private equity firm Wind Point Partners since 2020, has built its growth strategy around acquiring regional integrators with strong customer relationships and local market leadership, continuing a multi-year acquisition run across the fire, life-safety and security integration sector.

  • Estonian Startup Unveils Self-Balancing Monowheel Robot for Autonomous Security Patrols

    Estonian Startup Unveils Self-Balancing Monowheel Robot for Autonomous Security Patrols

    Estonian startup Rollo Robotics has unveiled 1Rollo, a self-balancing, one-wheeled autonomous robot designed to patrol warehouses, factories, campuses and other large properties, offering what the company positions as a lower-cost alternative to traditional guard patrols and security vehicles.

    A Narrow Footprint Built for Estonian Winters

    Currently in functional prototype form, 1Rollo uses gyroscopic stabilization to balance and move on a single wheel, a design the company says gives it a narrower footprint than wheeled or tracked patrol robots. Rollo Robotics, based in Viljandi, Estonia, says the platform was developed and tested through the country’s harsh winters, addressing traction, battery performance and sensor reliability in snow and sub-zero temperatures. The robot is intended to operate around the clock without the breaks, shift changes or attention lapses associated with human patrols.

    Subscription Model, Open Cybersecurity Questions

    Rather than selling the hardware outright, Rollo Robotics plans to offer 1Rollo through a Robotics-as-a-Service subscription that would bundle current hardware, software updates and support, according to CEO and co-founder Sander Sebastian Agur. The company says the model removes a large upfront equipment cost and simplifies future upgrades and repairs for customers.

    As with other connected patrol robots, 1Rollo depends on wireless connectivity and a cloud platform, which raises questions buyers will need to ask about video encryption, footage retention, operator-account protection and how the robot behaves if it loses its connection. The launch also comes as US lawmakers consider legislation that would restrict government use of some foreign-made robots over national-security concerns, a debate that is likely to shape how autonomous patrol platforms built outside the United States are received by security buyers.

  • 12-Year-Old PostgreSQL Flaw ‘PostGREShell’ Lets Low-Privilege Accounts Seize Full Server Control

    12-Year-Old PostgreSQL Flaw ‘PostGREShell’ Lets Low-Privilege Accounts Seize Full Server Control

    A PostgreSQL vulnerability that has existed undetected for roughly 12 years can let a low-privileged database account escalate to complete, persistent control of the server, researchers have disclosed.

    A Decade-Old Gap in a ‘Low-Risk’ Privilege

    Tracked as CVE-2026-6471 and nicknamed PostGREShell by the Cyera Research team that found it, the flaw carries a CVSS score of 7.2 and stems from a missing authorization check in PostgreSQL’s logical decoding feature, present since the capability was introduced in version 9.4 in 2014. An account holding only the REPLICATION privilege — typically granted for backup or data-pipeline purposes and long treated as a low-risk, read-only permission — can use a logical decoding output plugin to make the server load an arbitrary shared library file. That library executes as native code inside the PostgreSQL server process, running with the privileges of the operating-system account that runs the database.

    Successful exploitation can lead to arbitrary code execution, privilege escalation to permanent superuser status, and installation of a persistent backdoor, effectively handing an attacker full control of the server and any data it holds.

    Patched in August, Disclosed in September

    The PostgreSQL project shipped a fix for CVE-2026-6471 on August 13, 2026, bundled with 27 other security patches in versions 18.6, 17.11, 16.15, 15.19 and 14.24. Branches earlier than version 14 do not receive a fix. Cyera reported the issue to the PostgreSQL security team on February 21, 2026, with the team confirming it six days later; discovery credit was given to researchers Vladimir Tokarev and Yu Kunpeng. Security researchers are advising organizations to update affected instances immediately, audit which accounts hold the REPLICATION attribute, and remove it from any account that does not strictly require it.

  • Broadcom Patches Critical VMware Workstation and Fusion Flaws That Enable Host Takeover

    Broadcom Patches Critical VMware Workstation and Fusion Flaws That Enable Host Takeover

    Broadcom has patched two vulnerabilities in VMware Workstation and Fusion that could let an attacker with administrative privileges inside a virtual machine escape the VM and execute code on the underlying host system, a scenario that undermines the isolation virtualization is meant to provide.

    Two Distinct Escape Paths

    The more severe issue, tracked as CVE-2026-59346 and carrying a CVSS score of 9.3, is an integer-overflow flaw in how the software handles the VMXNET3 virtual network adapter. According to Broadcom’s advisory, a malicious actor with local administrative privileges on a virtual machine configured with a VMXNET3 adapter can exploit the bug to execute code on the host.

    The second flaw, CVE-2026-59347 (CVSS 8.1), is a stack-based buffer overflow in the Host-Guest File System (HGFS), the VMware component that lets a guest VM access files and folders on the physical host. Exploiting it allows code execution as the host’s VMX process, though Broadcom notes the exploitation conditions differ from the first bug.

    Patches Available, No Known Exploitation Yet

    Both vulnerabilities are fixed in VMware Fusion Pro 26H1u1, released September 3, 2026, and the corresponding Workstation update, detailed in advisory VMSA-2026-0007. CVE-2026-59346 was reported by researchers h4urek, cameudis and Stan S working with Trend’s Zero Day Initiative; CVE-2026-59347 was credited to Yeonghyeon Choi and Tianchu Chen of Tencent’s Xuanwu Lab. As of September 4, Belgium’s national cybersecurity center said it had no indication either flaw was being actively exploited, though it urged administrators to patch immediately given the risk of lateral movement, data exfiltration and host compromise if exploitation conditions are met.

    The disclosures follow reports last month that threat actors, including a suspected China-nexus group, were already exploiting separate flaws in VMware vCenter, underscoring sustained attacker interest in Broadcom’s virtualization stack.

  • Duress Alarms and Panic Buttons: Technology Options Explained

    Duress Alarms and Panic Buttons: Technology Options Explained

    A duress alarm, commonly known as a panic button, exists to let someone silently or quickly signal for help during a threatening situation. The concept is simple, but the technology behind it has diversified considerably as organizations look for options that fit different environments, from fixed retail counters to mobile hospital staff moving between patient rooms.

    Fixed Panic Buttons

    The most traditional form is a physical button mounted at a specific location, such as under a reception desk, at a bank teller station, or beside a cash register, wired or wirelessly connected to a monitoring system or directly to local law enforcement. Fixed buttons are simple, reliable and require no action beyond pressing them, but they only protect the person standing at that specific location, which limits their usefulness for staff who move throughout a building.

    Wearable Duress Devices

    Wearable panic devices, worn as a badge, pendant or wristband, extend duress alarm coverage to mobile staff. These devices typically communicate over a building’s Wi-Fi network or a dedicated real-time locating system (RTLS), allowing a monitoring center to see not just that an alarm was triggered but roughly where the wearer is located at the time. This location capability has made wearable duress devices particularly common in healthcare settings, where staff may be assisting a patient anywhere in a facility, and in hospitality, where housekeeping staff often work alone in guest rooms.

    Mobile App-Based Alerts

    Smartphone apps have become a lower-cost alternative or complement to dedicated wearable hardware, letting an employee trigger a duress alert directly from a phone they already carry, often using GPS to share location and sometimes activating audio or video recording automatically when triggered. App-based systems are easier and cheaper to deploy at scale than dedicated wearable hardware, though they depend on the user actively carrying and being able to access their phone during an incident, which is not always possible.

    Integration With Broader Security Systems

    Regardless of form factor, modern duress alarm systems increasingly integrate with video management and access control platforms, so that triggering an alert can automatically pull up live or recorded video from cameras nearest the alarm location, lock down access points in the area, and notify both on-site security staff and, where configured, local law enforcement simultaneously. This integration is intended to compress the time between an alert being triggered and a meaningful response being coordinated, which is generally considered the most important performance factor for any duress system.

    FAQ

    Are silent alarms better than audible panic buttons? It depends on the scenario. Silent alarms are generally preferred when the goal is to avoid escalating a confrontation, such as during a robbery, while audible alarms can be more effective for general emergencies where drawing immediate attention is the priority.

    Do wearable duress devices always include location tracking? Not always continuous tracking, but most wearable systems are designed to report location, either continuously or at the moment an alarm is triggered, since responding effectively to a duress alert usually depends on knowing where the person is.

    Can duress alarms be accidentally triggered? False activations do occur, particularly with wearable devices that can be bumped or pressed unintentionally, which is why many systems include a brief cancellation window or require deliberate multi-second presses to confirm an intentional alert.

  • Guard Tour Systems Explained: From Paper Logs to Real-Time Verification

    Guard Tour Systems Explained: From Paper Logs to Real-Time Verification

    Verifying that a security guard actually walked an assigned patrol route, and did so on schedule, used to depend entirely on paper logs and clock-in sheets that were easy to falsify and difficult to audit. Guard tour systems were built to solve that problem, and the technology behind them has evolved considerably from its original mechanical form.

    The Original Problem: Verifying an Unwitnessed Patrol

    A security guard’s patrol route often covers areas with no cameras and no supervision, which historically made it nearly impossible to confirm that checkpoints were actually visited rather than simply logged after the fact. Early guard tour systems addressed this with mechanical clock stations mounted at fixed checkpoints, where a guard inserted a key to record a timestamp on a paper tape carried on their person, creating a physical record that could later be checked against the expected schedule.

    From Mechanical Clocks to Electronic Checkpoints

    Electronic guard tour systems replaced mechanical clock stations with small, fixed data-collection points, originally barcode tags or magnetic buttons, that a guard would scan or touch with a handheld wand or reader while on patrol. Each scan recorded the checkpoint identifier and a timestamp on the handheld device, which was later downloaded to a central system for review. This eliminated the physical paper tape and made it far easier to generate reports, but the data was still typically reviewed after the fact rather than monitored live.

    Real-Time, Networked Verification

    Current-generation guard tour systems generally run on smartphones or dedicated handheld devices connected over cellular or Wi-Fi networks, using near-field communication (NFC) tags, QR codes, GPS location, or a combination of these methods to verify a checkpoint visit. Because these devices are connected in real time rather than downloaded after a shift, a missed checkpoint, a late arrival, or a patrol that stops moving unexpectedly can trigger an immediate alert to a supervisor or monitoring center, turning guard tour data from a historical audit tool into an active safety and accountability system.

    Beyond Simple Checkpoint Logging

    Many current systems layer additional functionality onto the basic checkpoint model: incident reporting with photos and notes logged directly at the point of observation, duress or panic alerts a guard can trigger if they encounter a threat, two-way messaging with a control room, and integration with video management systems so that footage from the time and location of a checkpoint scan can be pulled up automatically during an investigation. This integration reflects a broader trend of guard tour data becoming one more input feed into a unified security operations platform, rather than a standalone record-keeping tool.

    FAQ

    Do modern guard tour systems require special hardware? Many current systems run on standard smartphones using an app paired with inexpensive NFC tags or QR code stickers at checkpoints, though dedicated ruggedized handheld devices remain common in industrial or outdoor environments.

    Can guard tour systems work without cellular or Wi-Fi coverage? Most systems can log checkpoint scans offline and sync the data once connectivity is restored, though real-time alerting for missed checkpoints depends on having an active network connection at the time of the scan.

    Are guard tour records used as legal evidence? Time-stamped, GPS- or NFC-verified checkpoint logs are often used to demonstrate compliance with contractual patrol requirements or to support investigations, though their evidentiary weight depends on the specific system’s audit trail and how the records are maintained.

  • Cyber Insurance for Physical Security Systems: What Underwriters Actually Look At

    Cyber Insurance for Physical Security Systems: What Underwriters Actually Look At

    Cyber insurance underwriting has traditionally focused on IT systems, email, servers and cloud applications, but connected physical security devices have increasingly become part of that conversation. Cameras, access control panels, intrusion sensors and video management servers all sit on an organization’s network, and each one is a potential point of compromise that an insurer now has reason to ask about.

    Why Physical Security Devices Matter to Cyber Underwriters

    Network-connected security devices are, from a risk standpoint, IT endpoints, and they often carry the same vulnerabilities that make any embedded device attractive to attackers: default or weak credentials, infrequently updated firmware, and, in some deployments, direct internet exposure for remote viewing. A compromised camera or access control panel can serve as an entry point into a broader network, which is precisely the scenario cyber insurers are trying to price and prevent.

    What Underwriters Commonly Ask About

    During underwriting or renewal, insurers typically want to know whether security devices sit on a segmented network separate from general business IT systems, whether default manufacturer credentials have been changed, how firmware and software updates are managed across the device fleet, and whether remote access to video management or access control systems requires multi-factor authentication. Some insurers also ask about vendor support status, since devices that are past their manufacturer’s end-of-life date and no longer receive security patches represent a harder-to-mitigate risk.

    Network Segmentation as a Recurring Theme

    Segmentation, keeping security devices on a dedicated VLAN or subnet isolated from general corporate IT, has become one of the most consistently requested controls, because it limits how far an attacker can move if a single camera or panel is compromised. Organizations that can demonstrate this separation, along with documented patch management and credential practices, are generally viewed more favorably during underwriting than those that cannot.

    A Two-Way Relationship

    The relationship between physical security posture and cyber insurance is not one-directional. A poorly secured camera network can affect a company’s cyber insurance premium or coverage terms, but conversely, a well-documented, segmented and actively maintained physical security network can be used as supporting evidence during underwriting to help demonstrate an organization’s overall security maturity. Security integrators and end users increasingly treat cyber insurance requirements as a design input for new physical security deployments, rather than a separate compliance exercise handled after installation.

    FAQ

    Do cyber insurance policies typically name physical security devices specifically? Policy language varies, but many cyber policies cover incidents originating from any network-connected device, including physical security equipment, without necessarily naming device categories individually; underwriting questionnaires are where device-specific practices are usually assessed.

    Is network segmentation required for cyber insurance coverage? Requirements vary by insurer and policy, but segmentation of IoT and security devices from core business systems is increasingly requested as a condition for favorable pricing or, in some cases, coverage eligibility.

    Can outdated security cameras affect a cyber insurance claim? If an incident is traced to an unpatched or end-of-life device that a policyholder failed to disclose or maintain according to policy requirements, an insurer may scrutinize the claim more closely, underscoring the value of keeping device inventories and patch status current.