Category: News

Current, event-driven reporting, announcements and industry developments.

  • White House Bans Foreign-Made Bulk-Power System Equipment Over Cyber Backdoor Concerns

    White House Bans Foreign-Made Bulk-Power System Equipment Over Cyber Backdoor Concerns

    President Trump signed an executive order on August 26, 2026 declaring a national emergency over the security of the U.S. bulk-power system and banning the acquisition or installation of foreign-made equipment used to manage electricity transmission and generation, according to the order published by the White House and reporting by The Record. The order covers technology tied to transmission lines rated at 69,000 volts or higher, along with substations, control rooms, power generating stations and reactors, as well as associated software and firmware that could be remotely accessed or updated by foreign governments.

    The administration said the action responds to a pattern of foreign actors “creating and exploiting vulnerabilities” in bulk-power system technology that could enable remote access or supply-chain disruptions. The order directs the Departments of Defense, Commerce and Energy to review transactions involving bulk-power equipment and calls for a published list of pre-qualified vendors and components that federal agencies and utilities can rely on going forward.

    The order follows a string of confirmed intrusions into critical infrastructure operators this year, including cyberattacks affecting water utilities in multiple U.S. states and a reported multi-day shutdown of a small power plant in the United Kingdom, incidents that researchers have variously linked to Iranian, Russian and Chinese-linked hacking groups. For operators of power generation and transmission facilities, the order effectively elevates supply-chain vetting of grid control and monitoring equipment to the same priority long applied to physical perimeter security and access control systems protecting the same sites.

  • CISA Adds Six Vulnerabilities to Known Exploited Vulnerabilities Catalog, Including Citrix NetScaler Flaw

    CISA Adds Six Vulnerabilities to Known Exploited Vulnerabilities Catalog, Including Citrix NetScaler Flaw

    The Cybersecurity and Infrastructure Security Agency (CISA) added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on August 26, 2026, based on confirmed evidence of active exploitation. The catalog is the authoritative federal list of vulnerabilities that malicious actors are actively using in real-world attacks.

    The newly added entries are:

    • CVE-2026-8452 — Citrix NetScaler ADC and NetScaler Gateway improper restriction of operations within the bounds of a memory buffer vulnerability
    • CVE-2022-0995 — Linux Kernel out-of-bounds write vulnerability
    • CVE-2021-23758 — Ajax.NET Professional deserialization of untrusted data vulnerability
    • CVE-2019-1068 — Microsoft SQL Server remote code execution vulnerability
    • CVE-2015-5287 — Red Hat Automatic Bug Reporting Tool (ABRT) privilege escalation vulnerability
    • CVE-2015-3246 — Red Hat Libuser race condition vulnerability

    The mix illustrates a pattern CISA has flagged repeatedly this year: threat actors continue to exploit vulnerabilities dating back a decade alongside newly disclosed flaws, particularly where organizations have failed to retire legacy systems or apply available patches. The Citrix NetScaler entry is the most recent disclosure in the group and affects widely deployed application delivery and remote access infrastructure, making it an attractive target for initial network access.

    Federal Remediation Requirements

    Binding Operational Directive (BOD) 26-04, Prioritizing Security Updates Based on Risk, requires Federal Civilian Executive Branch (FCEB) agencies to remediate catalog vulnerabilities by CISA-assigned due dates, with particular urgency for flaws that grant an attacker total control of an affected asset post-exploitation. The directive also establishes baseline expectations for agencies to check whether a system was already compromised before a patch was applied.

    While BOD 26-04 formally applies only to FCEB agencies, CISA continues to encourage all organizations — including operators of industrial, commercial, and critical infrastructure systems — to treat KEV Catalog membership as a high-priority signal for patch management, given that every entry reflects confirmed, not merely theoretical, exploitation activity.

  • Lockheed Martin Demonstrates AI-Driven Battle Management Prototype for Guam Missile Defense

    Lockheed Martin Demonstrates AI-Driven Battle Management Prototype for Guam Missile Defense

    Lockheed Martin demonstrated a prototype AI-driven battle management system for the Guam Defense System (GDS) on August 26, 2026, showing how artificial intelligence analytics can compress the time it takes to detect, evaluate, and respond to air and missile threats in a simulated Guam operational environment.

    The prototype, called the GDS Battle Manager Suite, networks data from multiple Integrated Air and Missile Defense (IAMD) systems slated for deployment to Guam, including Aegis Guam and the Integrated Battle Command System (IBCS), into a single tactical picture. Powered by Lockheed Martin’s CommandIQ software, the system applies AI analytics to assess incoming tracks and generate fire-direction recommendations for human operators.

    From Request to Demonstration in Under Two Months

    The U.S. Army issued a call for a GDS Battle Manager Suite solution in June 2026. Lockheed Martin was invited to a Phase 2 evaluation at the Army Tactical Systems Integration Laboratory at Fort Bliss, Texas, where the company said its prototype was integrated and met demonstration requirements within 24 hours of arrival on site.

    Traditional IAMD battle management has relied on operators manually correlating information across documents, voice channels, and text messages — a process that is time-consuming and prone to error under the compressed timelines of a missile engagement. By automating that correlation and applying algorithmic shot selection informed by extensive simulation data, Lockheed Martin says the system is designed to give operators machine-speed decision support while helping preserve high-cost interceptor inventories.

    Part of a Broader Command-and-Control Push

    The Guam prototype follows related software-based command-and-control integration work Lockheed Martin performed during the Valiant Shield 2026 exercise, which the company has cited as evidence that capabilities developed across different programs and vendors can be connected rapidly to meet emerging operational requirements — a recurring theme as the Pentagon pushes for faster, more interoperable air and missile defense architectures across the Indo-Pacific.

    Guam’s defense architecture has been a focus of U.S. missile defense investment for several years given the island’s strategic role as a forward operating location. Layering AI-assisted battle management on top of existing sensor and interceptor networks is intended to help defenders manage a more complex and saturated threat picture without proportionally increasing the number of personnel required to operate it.

  • CISA Warns of Hardcoded Credentials in Johnson Controls TL280 Security Cameras

    CISA Warns of Hardcoded Credentials in Johnson Controls TL280 Security Cameras

    CISA published an Industrial Control Systems advisory on August 6, 2026 (ICSA-26-218-02) warning that Johnson Controls TL280 cameras running firmware versions prior to 5.63 contain hardcoded credentials that could allow an attacker to access sensitive information on the device.

    The vulnerability, tracked as CVE-2026-27871 and rated 4.1 on the CVSS v3 scale, stems from the use of a broken or risky cryptographic algorithm tied to authentication values embedded directly in the device firmware. Because the credentials are fixed at the firmware level rather than generated per device, an attacker who recovers them from one unit could potentially reuse them across other TL280 deployments running the same vulnerable firmware version.

    Johnson Controls, headquartered in Ireland, reports that TL280 units are deployed worldwide across Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, and Energy sectors — reflecting how widely IP camera platforms from major building-security vendors have been integrated into critical infrastructure environments. As of the advisory’s publication, CISA said it was not aware of public exploitation specifically targeting this vulnerability.

    Recommended Mitigations

    Johnson Controls’ primary recommended fix is to apply firmware update 5.63, which addresses the hardcoded credential weakness directly. CISA and the vendor also recommend layered compensating controls for cameras that cannot be updated immediately:

    • Restrict network access to affected cameras to trusted management VLANs only, and avoid exposing devices directly to the internet or untrusted network segments
    • Monitor device access logs for anomalous authentication activity
    • Rotate any shared or downstream credentials that may have been derived from or associated with the hardcoded values
    • Segment ICS/SCADA and physical-security device networks behind firewalls, isolated from general business networks
    • Use up-to-date VPNs for any required remote access rather than direct internet exposure

    The advisory is a reminder that video surveillance hardware sits at the intersection of physical and cyber risk: a credential weakness in a camera is not just a data-exposure issue but a potential foothold into the broader network segment the camera is connected to, particularly in environments where security devices are deployed on flat, unsegmented networks.

  • Nvidia Posts Blowout Quarterly Results, Guides to Accelerating Growth as Data Center Demand Surges

    Nvidia Posts Blowout Quarterly Results, Guides to Accelerating Growth as Data Center Demand Surges

    Nvidia reported second-quarter fiscal 2027 results after market close on August 26, 2026 that topped Wall Street expectations and sent the stock and broader semiconductor sector higher the following trading day. According to CNBC and The Motley Fool, the company reported quarterly revenue of $96.2 billion, more than double the prior-year period, with adjusted earnings per share of $2.22, both ahead of analyst consensus estimates of roughly $92.1 billion in revenue and $2.09 in adjusted EPS.

    Nvidia’s data center segment, which includes the GPUs and networking hardware powering large-scale AI training and inference clusters, contributed roughly $89 billion of the quarter’s revenue, according to Yahoo Finance’s reporting on the release, ahead of average analyst estimates near $85.8 billion. CNBC reported that CFO Colette Kress guided investors to expect approximately 70% revenue growth in fiscal 2028, sharply above the roughly 44% growth analysts surveyed by LSEG had anticipated, while CEO Jensen Huang said actual demand “is much greater than 70%” but that the company remains constrained by how much product it can manufacture and ship.

    The S&P 500 and Nasdaq Composite both closed higher on August 27 following the results, with semiconductor peers including Broadcom, Micron and SanDisk also gaining in premarket and regular trading as investors read the results as confirmation that hyperscaler AI infrastructure spending remains on an accelerating trajectory rather than plateauing, according to CNBC and StockAnalysis.com market coverage.

    For the security technology sector, sustained data center capital expenditure from hyperscale and enterprise AI infrastructure buyers has direct downstream implications: physical security, fire suppression, and access control specification for new data center campuses typically track the pace of underlying compute buildouts, and integrators serving that vertical have increasingly cited data center project pipelines as a primary growth driver, a dynamic separately highlighted in trade coverage of building-systems suppliers this year.

  • Over 100 Tech Companies Including OpenAI, Anthropic, Google and Microsoft Sign Letter on Defending Against AI-Driven Cyber Threats

    Over 100 Tech Companies Including OpenAI, Anthropic, Google and Microsoft Sign Letter on Defending Against AI-Driven Cyber Threats

    More than 100 technology companies, including OpenAI, Anthropic, Google and Microsoft, signed an open letter published August 27, 2026 urging closer cooperation between the private and public sectors to defend against AI-related cyber threats, according to TechCrunch. The letter calls for coordinated action as increasingly capable AI models are used both to accelerate cyberattacks and, in parallel, to help defenders detect and respond to them faster.

    TechCrunch reported that several of the signatories are, in the same period, continuing to develop more advanced frontier AI models even as they promote defensive programs built on that same technology, including OpenAI’s Daybreak program, Anthropic’s Mythos initiative, and a newly introduced cyber-defense platform from Microsoft called Perception. The report characterized this as a “conflicted position” for labs simultaneously advancing capability and warning about the risks that capability can pose in the hands of attackers.

    The initiative follows a series of disclosures throughout 2026 in which security researchers and AI labs described attackers using large language models to accelerate reconnaissance, vulnerability discovery and exploit development, alongside separate efforts by AI companies to formalize responsible-disclosure and defensive-use programs for their own models. The letter does not, according to the report, set out binding commitments, but frames the current moment as one requiring shared standards and cooperation between AI developers, security vendors, and government agencies as both offensive and defensive uses of AI systems mature.

    For security teams evaluating AI-enabled defensive tools, the emergence of vendor-specific programs from major model developers adds a new category of capability alongside established security operations center analytics platforms, though it also raises procurement questions about how defensive AI programs from foundation model vendors will integrate with, or compete against, existing security information and event management and extended detection and response tooling already deployed across enterprise and critical infrastructure environments.

  • Texas Governor Orders Pause on New Data Center Approvals Amid Grid Interconnection Strain

    Texas Governor Orders Pause on New Data Center Approvals Amid Grid Interconnection Strain

    Texas Governor Greg Abbott has ordered a pause on approvals for new large data center projects seeking to connect to the state’s power grid, a move that Houston Public Media reported on August 27, 2026 could delay roughly 300 large data center projects, though not every planned facility in the state is covered by the pause.

    The order responds to mounting pressure on the Electric Reliability Council of Texas (ERCOT) interconnection queue, as AI-driven data center demand has produced a wave of large-load requests competing for grid capacity and connection timelines. According to the report, Beth Garza, who previously served as ERCOT’s independent market monitor, said the interconnection process could take significantly longer than originally projected, whether because of the governor’s pause or because the initial timeline itself was unrealistic; Garza said she “will be pleasantly surprised” if by April 2027 the industry has a clear picture of which data center loads will ultimately be able to move forward.

    Texas has emerged as one of the largest hubs for hyperscale and AI-focused data center construction in the country, drawing investment from major cloud and AI infrastructure providers seeking access to relatively fast permitting and available land, but also straining grid planning as operators request power commitments that can rival the demand of entire cities. The pause reflects a broader tension states are navigating between courting large-scale data center investment and protecting grid reliability and consumer electricity costs for existing residential and industrial customers.

    For the physical security and critical infrastructure sector, large-scale data center buildouts have significant downstream implications beyond power supply: campus perimeter security, access control, and fire and life-safety systems are typically scoped and budgeted alongside the underlying facility and power infrastructure, meaning delays or restructuring of a project’s grid interconnection timeline can directly affect the pace of associated physical security procurement and installation work tied to new builds.

  • CISA Publishes New Round of ICS Advisories Covering Industrial Test, Fleet and IoT Devices

    CISA Publishes New Round of ICS Advisories Covering Industrial Test, Fleet and IoT Devices

    The Cybersecurity and Infrastructure Security Agency published a new batch of industrial control system advisories on August 27, 2026, covering vulnerabilities in products used across manufacturing, transportation and utility test environments. Among the advisories was one for Rockwell Automation’s OTTO Fleet Manager, tagged to the Critical Manufacturing and Transportation Systems sectors, which CISA said contains a flaw (CVE-2026-75112) that could reduce the computational cost required for an attacker to carry out offline brute-force attacks against stored password hashes in versions up to V2.36.2.

    A separate advisory covered the Applied Systems Engineering ASE2000 V2 Communications Test Set, a tool used to test IEC 60870-5-104 protocol communications common in electric utility SCADA environments. According to the advisory and a technical writeup published by Trout Software, the affected versions (2.25 through 2.37) carry two flaws: a legacy XML external entity issue tied to an outdated bundled Apache log4net library, and an improper certificate validation weakness in the product’s IEC 60870-5-104 TLS client that could allow an attacker to intercept and impersonate a trusted peer during protocol testing. CISA credited researcher Enoch Wang with the report and noted the vendor has released version 2.38 as a fix.

    CISA also published advisories for the Xiiaozet LK100W device, warning that successful exploitation of the flaws it identified could allow an attacker to take control of the device, and for the All-Line Equipment Company Fuel-Boss and Ebyte NA111-M products. As with its standard ICS advisory practice, CISA’s guidance recommends that asset owners minimize network exposure of control system devices, ensure they are not directly reachable from the internet, and place control system networks behind firewalls, isolated from business IT networks.

    The advisories arrive amid a broader pattern industry researchers have flagged this year: security vendor Forescout reported that ICS advisory volume topped 500 for the first time in 2025, with a growing share of vulnerabilities affecting field controllers, remote terminal units and other Purdue Model Level 1 devices that directly interface with physical processes. CISA continues to publish advisories on a rolling weekly basis covering vendors ranging from major industrial automation suppliers to smaller niche device manufacturers used in specific utility and manufacturing test workflows.

  • CISA Adds ownCloud, Linux Kernel and JFrog Artifactory Flaws to Known Exploited Vulnerabilities Catalog

    CISA Adds ownCloud, Linux Kernel and JFrog Artifactory Flaws to Known Exploited Vulnerabilities Catalog

    The Cybersecurity and Infrastructure Security Agency added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 27, 2026, citing evidence of active exploitation. The additions are CVE-2023-49105, an improper authentication vulnerability in ownCloud; CVE-2026-53362, an unspecified vulnerability in the Linux Kernel; and CVE-2026-66384, an improper limitation of a pathname to a restricted directory vulnerability affecting JFrog Artifactory, according to CISA’s alert.

    CISA’s advisory notes that vulnerabilities of this type are “a frequent attack vector for malicious cyber actors” and pose significant risk to federal networks. Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies are required to remediate KEV catalog entries within CISA-specified timeframes, though the directive does not legally bind private-sector organizations.

    The JFrog Artifactory path traversal flaw is notable given the platform’s widespread use as a binary and package repository in enterprise software development pipelines; a pathname restriction bypass in that context can potentially allow an attacker to read or write files outside intended directories, a class of vulnerability that has previously been leveraged for both data exfiltration and remote code execution in build and artifact-management systems. The ownCloud authentication flaw, tracked since 2023, affects a self-hosted file-sharing platform used by organizations that manage sensitive document storage internally rather than through commercial cloud providers.

    CISA said it “will continue to add vulnerabilities to the catalog that meet the specified criteria” and encouraged all organizations, not just federal agencies, “to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.” The agency’s KEV catalog has become a widely used reference point across the security industry for prioritizing patch management amid a growing volume of disclosed vulnerabilities.

  • ATF Confirms Data Breach After Ransomware Group Claims Access to Investigation Data

    ATF Confirms Data Breach After Ransomware Group Claims Access to Investigation Data

    The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a cyberattack affected a system containing information about the targets of its investigations, following claims by a ransomware group that it had gained access to the agency’s data, Reuters reported.

    What’s New

    According to court documents and public reporting, the ransomware group gained access to a computer system holding information related to ATF investigative targets. The agency confirmed the breach but has not disclosed the full scope of the data involved or attributed the intrusion to a specific threat actor.

    Why It Matters

    A breach touching active investigation data raises risks beyond typical data-exposure incidents, potentially compromising ongoing law enforcement operations and the safety of investigative targets and personnel if the information is misused or leaked. The incident adds to a string of confirmed breaches at U.S. federal agencies this year and comes weeks after the Justice Department and FBI moved to disrupt state-sponsored hacking infrastructure targeting other parts of the federal government.