Category: Intelligence

  • North Korean Hackers Deploy Stealthy Linux Backdoor Hidden Inside HAProxy

    North Korean Hackers Deploy Stealthy Linux Backdoor Hidden Inside HAProxy

    A North Korea-aligned threat actor has been using a new Linux-based espionage toolkit to target automotive and media organizations in South Korea, according to research published by Rapid7. The framework is designed for long-term, stealthy surveillance rather than smash-and-grab data theft.

    A Backdoor Compiled Into the Load Balancer Itself

    At the center of the toolkit is a custom HAProxy plugin the researchers call the “ted” backdoor, compiled directly into a HAProxy 2.8.12 instance running in the victim’s environment. Rather than running as a separate malicious process, it hooks into HAProxy’s native filter API, internal memory pools, event scheduler and HTTP parser, letting it intercept and inject traffic while genuine load-balancing operations continue normally, which helps it evade routine monitoring.

    The broader framework also includes trojanized versions of common Linux utilities, including agetty, atd, crond, polkitd and sshd, along with a curl-based remote access tool the researchers call CurlRAT and an SSH keylogger that doubles as a staging server. CurlRAT polls its command-and-control server roughly every 12 hours and can decrypt and execute stored commands, write new configuration payloads to disk, or spawn a full interactive shell.

    Initial Access and Attribution

    Rapid7 says the attackers first gained access to an edge server by exploiting a vulnerability in a groupware login portal, then used the SSH keylogger to harvest credentials for lateral movement into internal systems. Once installed, the ted backdoor let attackers redirect or serve malicious content to selected visitors browsing through the compromised load balancer, using low-cost commodity domains designed to blend in with legitimate traffic, in one case mimicking a Naver static-content domain.

    Rapid7 says the toolkit has likely been in use since late 2024, based on the release date of the first HAProxy version it was compiled against. Attack infrastructure and techniques observed overlap with watering-hole methods previously used by APT37 and Lazarus, and the campaign’s timeframe overlaps with Operation SyncHole, a watering-hole campaign against South Korean firms attributed to Lazarus in 2025 — pointing toward a North Korean state-linked actor, though Rapid7 stops short of formal attribution to a specific named group.

  • Geutebrück Enters New Ownership Phase With IBEX and Merantix Momentum Investment

    Geutebrück Enters New Ownership Phase With IBEX and Merantix Momentum Investment

    German video security specialist Geutebrück is entering a new corporate phase after receiving a majority investment from IBEX Wachstumspartner, alongside European AI group Merantix Momentum, according to Security Info Watch and confirmed by law firm Schmitz Knoth, which advised Geutebrück’s shareholders on the transaction. The deal closed on August 31, 2026.

    New Leadership and International Ambitions

    As part of the transition, Tobias Huemmerich will take over management of the company, with plans to further internationalize the business and expand its customer offering, according to Security Middle East. Geutebrück has operated in the video security market for more than 55 years and has built a reputation as a provider of video management software and hardware for public-sector and highly critical infrastructure clients.

    Merantix Momentum Brings AI Expertise

    Merantix Momentum, described as Europe’s leading AI group, is joining the investment specifically to help Geutebrück develop new AI-based applications, according to the companies. Geutebrück has said it sees opportunities to extend its video management platform beyond traditional security use cases, including the potential use of anonymized video data to identify workflow efficiencies and improve occupational safety.

    Part of a Broader Consolidation Trend

    The investment adds to a string of ownership changes across the video surveillance sector as manufacturers seek capital and AI expertise to keep pace with larger competitors. IBEX Wachstumspartner, an owner-managed investment firm focused on succession situations at German medium-sized businesses, said the deal reflects its strategy of pairing growth capital with digitalization expertise for established technology companies entering a generational transition.

  • Smart Building Security Integration: Converging BMS, IoT and Physical Security Systems

    Smart Building Security Integration: Converging BMS, IoT and Physical Security Systems

    A modern commercial building typically runs several parallel digital systems: a building management system (BMS) controlling HVAC, lighting and elevators; a physical security platform handling access control and video surveillance; and a growing layer of IoT sensors monitoring everything from occupancy to air quality to energy consumption. Historically, these systems were built, procured and operated independently, often by different contractors using proprietary protocols with little interoperability. That is changing as building owners push for centralized operational visibility and as IP-based communication becomes the default across all three domains.

    What Integration Actually Enables

    • Occupancy-aware building operations. Access control and video occupancy data can inform HVAC and lighting schedules in real time, reducing energy use in unoccupied zones without requiring separate occupancy sensors purpose-built for BMS use.
    • Correlated alarm response. A door-forced-open alarm correlated with an unexpected HVAC or lighting change in the same zone can help security operators distinguish a genuine intrusion from a false alarm or scheduled maintenance activity.
    • Unified emergency response. Fire alarm, access control and BMS integration allows automated responses during emergencies — such as unlocking designated egress doors and adjusting HVAC to support smoke control — to be coordinated from a single event trigger rather than requiring separate manual actions across disconnected systems.
    • Centralized operational dashboards. Facility operators increasingly want a single interface showing security status, environmental conditions and building system health, rather than switching between multiple vendor-specific consoles.

    The Security Cost of Convergence

    Integration is not free from a risk standpoint. Building management systems have historically been built with less emphasis on cybersecurity than IT infrastructure, and connecting them to the same network as access control and video systems can create pathways for an attacker who compromises a lower-security BMS component to reach higher-value security infrastructure, or vice versa. IoT sensors, in particular, are frequently deployed in large numbers with minimal device management, making them a common weak point in an otherwise well-secured network if not properly segmented and monitored.

    Effective smart-building integration therefore requires the same network segmentation discipline applied to any converged IT/OT environment: BMS, IoT and security systems should typically sit on segmented VLANs with controlled inter-segment communication, rather than a single flat network simply because integration is technically possible.

    Governance and Organizational Challenges

    Beyond the technical architecture, smart-building integration raises questions of system ownership that many organizations have not fully resolved: does facilities management or security operations own the integrated platform? Who is responsible for patching BMS controllers that were historically outside the IT department’s purview? These governance questions frequently prove harder to resolve than the underlying technical integration, and unresolved ownership questions are a common reason integration projects stall after the initial technology deployment.

    FAQ

    Does smart building integration require replacing existing BMS or security systems?

    Not necessarily. Many integration platforms are designed to sit above existing BMS and security systems, aggregating data through APIs or middleware rather than requiring wholesale replacement of underlying infrastructure, though the degree of integration achievable depends on how open or proprietary the existing systems’ interfaces are.

    Is network segmentation still necessary if all systems are managed by the same integrated platform?

    Yes. A shared management platform does not eliminate the value of network segmentation; the two operate at different layers. Segmentation limits the blast radius of a compromised device at the network level, regardless of which platform is used to manage the devices sitting on that network.

    Conclusion

    Converging BMS, IoT and physical security in commercial buildings delivers real operational value, from energy efficiency to more coordinated emergency response, but it also expands the attack surface if approached purely as a data-integration exercise without corresponding network segmentation and governance work. Organizations that succeed at smart-building integration tend to treat it as a security architecture project with an operational-efficiency benefit, not the reverse.

  • DHS Awards Department-Wide Contracts for Counter-Drone Capabilities

    DHS Awards Department-Wide Contracts for Counter-Drone Capabilities

    A Common Acquisition Pathway Across DHS

    The Department of Homeland Security announced on August 5, 2026 that it has made multiple contract awards to support department-wide access to Counter-Unmanned Aircraft Systems (C-UAS) capabilities. The awards give DHS components a common pathway to acquire C-UAS hardware, software and services tailored to fixed-site, mobile, aviation, maritime, aircraft-based and special-mission environments, according to the department’s Science and Technology Directorate.

    “These awards mark an important step in strengthening DHS’s ability to respond to unauthorized and malicious unmanned aircraft systems,” said Homeland Security Secretary Markwayne Mullin. “By taking a Department-wide approach, we are improving mission readiness, supporting more consistent capabilities, and helping ensure DHS personnel have access to the right tools for the job.”

    Replacing Fragmented Procurement

    DHS components have historically procured C-UAS capabilities through separate acquisition efforts. The new contract structure is intended to support greater consistency, interoperability, operational flexibility, technology refresh and lifecycle management across the department, while still letting individual components select solutions aligned to their specific missions. The awarded contracts cover detection, tracking, classification, identification, mitigation, command-and-control integration, training, maintenance, technical support, system integration, research and development, test and evaluation, and vendor-operated turnkey services.

    “As unmanned aircraft systems become more capable and more widely available, DHS needs solutions that can adapt,” said Under Secretary for Science and Technology Pedro Allende. Components expected to use the contract include the U.S. Secret Service, U.S. Coast Guard, Customs and Border Protection, Immigration and Customs Enforcement, the Transportation Security Administration, FEMA, the Federal Protective Service, U.S. Citizenship and Immigration Services, and the Science and Technology Directorate itself. DHS did not disclose specific contract values or awardee names in its announcement.

    Sources

  • Flock Safety Cuts License-Plate Data Retention to Seven Days Amid Surveillance Backlash

    Flock Safety Cuts License-Plate Data Retention to Seven Days Amid Surveillance Backlash

    New Guardrails Announced Amid Growing Criticism

    Flock Safety, which operates a nationwide network of more than 119,000 automated license-plate-reader (ALPR) cameras used by law enforcement agencies, announced a set of privacy and accountability reforms on August 13, 2026, according to Fox Business. The changes come as the company faces mounting criticism from privacy advocates and elected officials over mass surveillance concerns and reports of officers misusing the technology, including cases documented by Wired in which police reportedly used Flock data to track romantic partners.

    Flock CEO Garrett Langley discussed the changes publicly, telling Fox Business’s “Varney & Co.” that the reforms were a direct response to backlash the company has faced over its car-tracking cameras. Some local officials have gone further than criticism: Knox County, Tennessee, Mayor Glenn Jacobs has called for a national moratorium on further deployment of Flock’s camera network, according to Fox Business.

    Shorter Retention, Mandatory Audit Controls

    The centerpiece of the announcement is a reduction in Flock’s standard data-retention window from 30 days to seven. The company said that roughly 90% of all searches conducted on its platform already occur within a week of data capture, arguing the shorter window would have limited practical effect on law enforcement’s ability to use the system while narrowing the amount of location data stored on Flock’s servers at any given time. For cases requiring longer retention, Flock is introducing an “Evidence Mode” feature that lets agencies preserve specific data for extended periods under state or local policy.

    Flock is also making its “Audit Assistance” feature — which flags abnormal search behavior and can lock a user out of the system in real time pending administrator review — mandatory for all law enforcement customers rather than optional; the company said roughly a third of agencies had turned the feature on voluntarily before the change. Separately, Flock is making the previously optional requirement to log a case code with every search mandatory going forward, with an override reserved for emergencies such as missing-child cases. “A search without a reason is a search that shouldn’t happen in the first place, and now Flock’s system automatically treats it that way,” the company told Fox Business.

    New Controls Over Cross-Agency Data Sharing

    The company is also giving individual agencies more granular control over which types of cases they will share camera search access for with other jurisdictions. In comments to Fox Business, Flock gave the example that “City A could allow City B to search its cameras for a stolen vehicle or violent crime while blocking searches related to immigration enforcement” — an option aimed at addressing concerns that Flock’s interconnected camera network could be used for purposes individual municipalities have not authorized.

    Civil liberties groups were not satisfied by the announcement. The American Civil Liberties Union said in a statement reported by Fox Business that the reforms “seem to be a thinly veiled PR attempt to counter communities’ genuine privacy concerns with its mass surveillance system with largely hollow security promises, rather than an earnest effort to address them.” Flock, for its part, has pointed to its own figures on the technology’s investigative use, telling Fox Business that its cameras were involved in roughly 1 million investigations last year and were tied to the location of about 10,000 missing people — figures that reflect the company’s own reporting and have not been independently verified.

    Sources

  • UK and Ukraine Sign AI Defense Partnership Granting Access to Ukraine’s Avengers AI Labs

    UK and Ukraine Sign AI Defense Partnership Granting Access to Ukraine’s Avengers AI Labs

    Britain and Ukraine signed a partnership in Kyiv on Monday, August 24, 2026, to jointly develop artificial intelligence tools for defense and security, with the UK becoming the first international partner granted access to Ukraine’s Avengers AI Labs battlefield-data platform, according to Reuters and a UK government statement.

    A Battlefield Dataset Built From Ukraine’s War

    UK Prime Minister Andy Burnham and Ukrainian President Volodymyr Zelenskyy signed the agreement, which the UK government describes as part of the two countries’ “100 Year Partnership.” Avengers AI Labs is built around an annotated dataset of roughly 5 million battlefield images, according to Ukraine’s Defence Ministry, drawn largely from the DELTA combat management and situational-awareness system. The platform aggregates data from cameras and sensors deployed across Ukraine’s front lines, capturing tanks, artillery, air-defense systems, infantry and aerial targets including Shahed drones and reconnaissance UAVs, which is used to train AI models that the UK government says currently identify a majority of targets in real time.

    Under the deal, Britain will in turn back Ukraine with access to its universities, researchers and technology companies, which the UK government describes as the world’s third-largest AI ecosystem. The agreement initially focuses on defense and national-security applications, bringing together engineers, academics, businesses and military operational experts from both countries.

    Fiber-Optic Sensing and Low-Power AI Chips Among First Pilot Projects

    Three British startups — Bristol-based Sintela, Oxford-based Mind Foundry, and London-based Skyral — are involved in the initial pilot projects announced alongside the partnership. The first project turns buried fiber-optic cables into a distributed AI-enabled sensor system, initially being trialed at a UK defense site to detect protesters and hostile actors attempting to gather intelligence; UK officials say the same approach could later extend to protecting airports, prisons, railways and energy plants. A second pilot project will explore low-power AI chips designed for future drones, robotics and autonomous systems.

    The AI agreement was announced alongside a separate decision by the UK to let defense contractor MBDA release classified information on UK-made components for the SCALP long-range missile, enabling local assembly lines in Ukraine. UK Defence Secretary Wes Streeting and AI Minister Kanishka Narayan both framed the AI partnership as part of a broader push to convert Ukraine’s wartime operational data into long-term technology and national-security capability for both countries.

    Sources

  • Denver Police to Let ShotSpotter Gunshot-Detection Contract Expire After a Decade

    Denver Police to Let ShotSpotter Gunshot-Detection Contract Expire After a Decade

    City Will Phase Out Acoustic Sensors by Year’s End

    The Denver Police Department says it will let its contract for ShotSpotter gunshot-detection technology expire at the end of 2026, ending more than a decade of automated gunfire alerting in the city, according to CBS Colorado and Denver7 reporting on the department’s August 20-21, 2026 announcement. The system uses acoustic sensors mounted on utility poles to detect the sound of gunfire and alert Denver’s 911 dispatch center, often before a human caller reports a shooting. Denverite reported the city’s contract with SoundThinking, the company behind ShotSpotter, is worth roughly $4.7 million and expires at the close of the year.

    Rather than an abrupt shutdown, DPD says it will begin removing sensors from areas generating the fewest alerts first, with most of the network remaining active through the rest of 2026. According to Denver7, the department said it is evaluating “whether a new vendor can provide greater public safety benefits” and plans to launch a bidding process to assess alternative gunshot-detection capabilities while gathering community input on how to reallocate resources. As part of the initial ramp-down, DPD said it will begin phasing out ShotSpotter coverage specifically in the Sun Valley and Park Hill neighborhoods.

    A Decade of Data on Alerts, Arrests and Recovered Firearms

    In its release announcing the change, the department said that from 2020 through June 2026 the program generated 25,217 alerts, leading to 655 arrests and the recovery of 721 firearms, according to CBS Colorado. Officers also located shell-casing evidence tied to 6,672 of those alerts. Denver’s decision comes amid what Denver7 described as broader nationwide scrutiny of police gunshot-detection and surveillance technology, as cities weigh the systems’ operational value against their cost and questions about alert accuracy and community impact that have been raised in other jurisdictions.

    What Happens Next

    City officials have not yet named a preferred replacement vendor or detailed the criteria for the planned bidding process. The wind-down gives Denver several months to evaluate alternative gunshot-detection platforms and to solicit public feedback before the current sensor network is fully retired, according to the reporting from Denver7 and Denverite.

    Sources

  • CISA, NSA and FBI Warn of Active AI-Assisted Reconnaissance Against Siemens S7 PLCs

    CISA, NSA and FBI Warn of Active AI-Assisted Reconnaissance Against Siemens S7 PLCs

    Joint Advisory Warns of Active Targeting

    The National Security Agency, the Cybersecurity and Infrastructure Security Agency, the FBI, the Department of Energy and the Environmental Protection Agency released a joint cybersecurity advisory on August 19, 2026, warning that threat actors are actively targeting Siemens S7 Series programmable logic controllers (PLCs) that are exposed to the internet or insufficiently segmented from it. The advisory, designated AA26-231A, covers the S7-200, S7-300, S7-400, S7-1200 and S7-1500 controller families, including the F-series safety variants.

    According to the agencies, the activity spans several critical infrastructure sectors, with Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities named as the most-targeted. Siemens S7 controllers are also used in the Defense Industrial Base, which the advisory says could be affected as well. CISA describes the threat as “not a theoretical risk” and says exploitation of poorly protected PLCs could disrupt industrial processes, damage equipment, trigger safety incidents through manipulation of interlocks or emergency shutdown systems, and cause cascading effects across interconnected systems.

    AI-Generated Scripts and the Snap7 Library

    The advisory says the threat actors are combining publicly available industrial automation tooling with AI-assisted scripting to build custom software that mimics legitimate operational-technology monitoring tools. Specifically, the agencies describe adversaries using internet-scanning services such as Censys and ZoomEye to locate exposed S7 controllers, then deploying AI-generated Python scripts built on the open-source snap7 library to read and write PLC memory, configuration data and ladder-logic programs over the S7comm protocol on TCP port 102. CISA characterizes the use of AI to generate this exploitation code as “an evolution in threat actor capabilities” that lowers the technical bar for building working industrial-control exploitation tools and speeds adversaries’ ability to adapt to defenses.

    The agencies assess the pattern observed so far as consistent with reconnaissance and capability development — testing techniques against specific PLC models and using read access to understand target environments — rather than a confirmed disruptive attack. The advisory maps the observed techniques to the MITRE ATT&CK for ICS and Enterprise frameworks and to MITRE D3FEND countermeasures.

    A Distinct Threat From the Iran-Linked Water Sector Warning

    AA26-231A is separate from an earlier joint advisory, AA26-097A, which described confirmed Iran-linked exploitation of PLCs at a U.S. water-sector victim, including modification of ladder logic that disabled safety shutdown and alarm functions. The new Siemens-specific advisory does not attribute the reconnaissance activity it describes to any named nation-state or group, and it explicitly frames the observed activity as pre-attack staging rather than a confirmed disruptive incident. CISA also cautions that PLC targeting more broadly extends beyond Siemens equipment, and that the Siemens-specific guidance in the advisory should be treated as one subset of a wider threat landscape facing internet-exposed industrial controllers.

    Mitigations Recommended by the Authoring Agencies

    The agencies are urging asset owners to inventory all Siemens S7 controllers in their environments, apply available firmware and engineering-software patches, verify that PLCs are not reachable from the internet, and block TCP port 102 at perimeter firewalls. Additional recommendations include restricting engineering-workstation access through IP or MAC allowlisting, enabling PLC password protection and configurable read/write protection levels, deploying ICS-aware intrusion detection, and monitoring for anomalous S7comm traffic patterns, unauthorized write operations, and use of the snap7 library outside approved engineering systems. The advisory also recommends organizations that rely on third-party systems integrators or managed service providers share the guidance with those parties directly, since asset owners may not always be aware that PLCs accessible to vendors are also exposed to the wider internet.

    Sources

  • DOJ and FBI Seize Domains Behind Chinese State-Sponsored QScan and QTRouter Hacking Platforms

    DOJ and FBI Seize Domains Behind Chinese State-Sponsored QScan and QTRouter Hacking Platforms

    The U.S. Department of Justice and FBI announced August 26, 2026 that they had executed court-authorized domain seizures to disable two linked hacking platforms, known as QScan and QTRouter, used by a China-based, state-sponsored group the department identified as QTFY. According to the DOJ’s press release, court documents unsealed in the Southern District of California name Nanjing Xinjiuwei Network Technology Company as the operator of QTFY, which the department said sells hacking services to clients including the Chinese Ministry of State Security and the People’s Liberation Army.

    Court filings describe QScan and QTRouter as complementary tools: QScan searches the internet and automatically infects vulnerable internet-of-things devices, such as home routers and security cameras, while QTRouter forms an obfuscation network from those compromised devices that lets operators route attack traffic through infected machines in more than 130 countries, concealing the true origin of intrusions, FBI Cyber Assistant Director Brett Leatherman said in a video statement released by the bureau.

    The DOJ said the disruption made both platforms inoperable because the seized domains were hard-coded into their communication and authentication functions, a technique reported by The Record based on court documents. According to the department, victims of QTFY’s activity since at least 2018 include NASA, the Federal Reserve, the Department of Energy, the Department of Justice itself, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate, as well as power companies, telecommunications providers, hospitals, financial institutions and defense contractors.

    Leatherman described the action as the disruption of “a global botnet used by a Chinese state-sponsored group … to target U.S. critical infrastructure,” adding that QTFY had “exploited software vulnerabilities to launch cyberattacks against U.S. government agencies, power companies, telcos, and major hospital systems” for nearly a decade. The FBI said QTFY’s services were also sold to customers beyond the Chinese government, though it did not name additional clients.

    The takedown is the latest in a series of U.S. actions targeting Chinese state-linked infrastructure-scanning and botnet operations, and underscores continuing concern among federal agencies about the use of compromised consumer and small-business IoT devices, including routers and security cameras, as staging infrastructure for espionage-linked intrusions into critical infrastructure networks.

  • CISA Red-Team Assessments Show Why One SOC Detected an Intrusion and Another Did Not

    CISA Red-Team Assessments Show Why One SOC Detected an Intrusion and Another Did Not

    The US Cybersecurity and Infrastructure Security Agency published A Tale of Two SOCs: Insights From Two Red Team Assessments on August 25, 2026. The advisory compares assessments conducted at two critical-infrastructure organizations and shows how similar adversary techniques produced very different defensive outcomes.

    Two assessments, two outcomes

    At the first organization, CISA’s red team gained access to multiple workstations, elevated privileges across the domain and moved laterally without being detected by the security operations center. The assessment identified gaps in monitoring, cloud visibility, identity protection and communication between separate security teams.

    At the second organization, the SOC detected and quarantined the red team’s initial access. That response forced the assessors to move to an assumed-breach scenario. Defenders also detected and contained portions of the follow-on activity, limiting the red team’s freedom of movement.

    What made the difference

    CISA’s comparison emphasizes operational fundamentals rather than a single security product. Tuned alerts, established network and identity baselines, documented escalation procedures, communication between SOC teams and system owners, and visibility across IT, cloud and operational-technology environments all affected the result.

    The advisory also highlights the risk created by fragmented tooling. Multiple SOCs or endpoint-detection platforms do not automatically improve security when teams cannot see one another’s alerts or coordinate investigations. Cloud identity and application controls require the same operational ownership as traditional endpoint and network monitoring.

    Why it matters for critical infrastructure

    Critical-infrastructure operators increasingly manage connected IT, cloud and OT environments. An attacker who begins on a workstation may use identity systems, remote administration paths or cloud services to move toward operationally important resources. Detection quality therefore depends on whether defenders can correlate events across those boundaries before activity becomes a domain-wide compromise.

    Red-team assessments do not predict every real intrusion, but they provide controlled evidence of how existing people, procedures and technology perform against realistic adversary behavior. CISA’s findings support a practical priority: organizations should test whether their SOC can detect and coordinate a response across the complete environment, rather than assuming that deployed tools are functioning as an integrated defense.

    Sources

    Follow additional developments on Technology News.