Category: News

Current, event-driven reporting, announcements and industry developments.

  • TSMC Posts Record August Revenue, Up 53% Year-Over-Year on AI Chip Demand

    TSMC Posts Record August Revenue, Up 53% Year-Over-Year on AI Chip Demand

    TSMC reported August 2026 revenue of NT$514.8 billion ($16.35 billion), up 53.3% year-over-year and 10.1% month-over-month, according to the company’s investor relations release, corroborated by CNBC. It marked TSMC’s fourth consecutive month of revenue growth, driven by AI server chip demand.

    January-through-August 2026 revenue totaled NT$3.39 trillion, up 39.3% year-over-year.

    Why it matters: As the dominant manufacturer of advanced chips for AI accelerators, TSMC’s monthly revenue figures function as a leading indicator for the broader pace of AI infrastructure buildout — directly relevant to security and infrastructure planners tracking how fast data center and compute capacity is scaling globally.

    Source: TSMC investor relations release, corroborated by CNBC, September 10, 2026.

  • Resorts World Las Vegas Runs Milestone VMS Across 5,800 Cameras

    Resorts World Las Vegas Runs Milestone VMS Across 5,800 Cameras

    Resorts World Las Vegas, an 88-acre, $4.3 billion property, is operating Milestone Systems’ XProtect video management software across approximately 5,800 cameras from Axis, Bosch and Hanwha, SecurityInfoWatch reported. The deployment is integrated with BriefCam forensic video analytics, Oosto facial recognition, and Aeyesky card-counting and cheat-detection tools.

    Named Milestone and Resorts World executives said the integrated platform supports gaming compliance monitoring, fraud investigation, and day-to-day security operations across the resort’s gaming floor and public areas.

    Why it matters: The scale of the deployment — nearly 5,800 cameras on a single VMS with multiple layered analytics engines — illustrates how far integrated-platform video surveillance has moved beyond simple recording, toward real-time compliance and fraud-detection infrastructure at large commercial venues.

    Source: SecurityInfoWatch.com, September 10, 2026.

  • Vecna Robotics Raises $31 Million as FCC Foreign-Robot Restrictions Boost US-Built Warehouse Automation

    Vecna Robotics Raises $31 Million as FCC Foreign-Robot Restrictions Boost US-Built Warehouse Automation

    Waltham, Massachusetts-based Vecna Robotics raised $31 million led by Unless, DC Velocity reported, citing surging demand tied to a July 2026 Federal Communications Commission policy restricting purchases of certain foreign-made robots on cybersecurity grounds. The company builds case and pallet automation systems for warehouses.

    Vecna said the funding will be used to scale deployment teams and expand its automation capabilities as US-based logistics operators shift purchasing toward domestically built robotics platforms.

    Why it matters: The FCC’s restriction treats foreign-made warehouse and logistics robots as a potential cybersecurity and supply-chain risk category, similar to earlier restrictions on foreign-made telecom and video surveillance equipment — a signal that physical automation hardware is increasingly being evaluated through the same national-security lens as networking gear and cameras.

    Source: DC Velocity, September 10, 2026, corroborated by GlobeNewswire press release and Boston Business Journal.

  • Survey Finds Most Americans Believe Building Security Hasn’t Improved Since 9/11

    Survey Finds Most Americans Believe Building Security Hasn’t Improved Since 9/11

    A new YouGov survey commissioned by access-control vendor Alcatraz and reported by SecurityInfoWatch found that 79% of Americans do not believe physical building security has meaningfully improved in the 25 years since the September 11, 2001 attacks, and 73% called upgrading security technology at least somewhat urgent.

    Alcatraz tied the findings to a string of recent tailgating-related security breaches at Harvard, UCLA, 30 Rockefeller Center and the Empire State Building, arguing that standard badge-based access systems do not reliably detect a second, unauthorized person following an authorized badge-holder through a controlled door.

    Why it matters: The survey is vendor-commissioned research, and its framing understandably favors the sponsor’s tailgating-detection technology. But the underlying data point — persistent public skepticism about physical security investment a quarter-century after 9/11 — lands as the industry heads into GSX 2026, where access-control vendors are expected to lean heavily on anti-tailgating and mantrap messaging.

    Source: SecurityInfoWatch.com, September 10, 2026.

  • New PivotC2 RAT Delivered via Exploited Fortinet FortiOS Heap Overflow, Infects 178 Devices

    New PivotC2 RAT Delivered via Exploited Fortinet FortiOS Heap Overflow, Infects 178 Devices

    CISA added CVE-2025-25249, a heap-overflow vulnerability in Fortinet FortiOS, to its Known Exploited Vulnerabilities catalog after identifying active exploitation, The Hacker News reported. Attackers are using the flaw to deliver a newly identified Node.js-based remote access trojan dubbed PivotC2, which has infected 178 devices to date, the majority located in the United States.

    The disclosure was part of a broader CISA KEV update covering multiple actively exploited network-perimeter vulnerabilities, with a federal patch deadline tied to the update.

    Why it matters: FortiOS underpins firewall and VPN infrastructure across a large share of small and mid-sized enterprise and critical-infrastructure networks. A newly identified, purpose-built RAT delivered through an actively exploited perimeter flaw is a strong signal that organizations running FortiOS should treat this patch as time-sensitive rather than routine.

    Source: The Hacker News, September 10, 2026, citing CISA KEV catalog update.

  • UK Moves to Give Ministers Power to Block High-Risk Tech Suppliers From Critical Infrastructure

    UK Moves to Give Ministers Power to Block High-Risk Tech Suppliers From Critical Infrastructure

    The UK government has tabled late amendments to its Cyber Security and Resilience Bill that would give ministers new powers to block critical-sector organizations from using technology suppliers considered a national security risk, as concern grows over supply-chain vulnerabilities feeding attacks on critical infrastructure.

    A Response to a Recent Energy Sector Attack

    The government tabled the amendments on August 24, 2026, underscoring what officials describe as an urgent need to give ministers explicit authority to prevent critical infrastructure operators from engaging technology suppliers deemed high risk. The move follows a cyberattack, reportedly linked to a nation-state actor, that took a UK energy generator offline for four days, an incident that industry commentators say sharpened political attention on supply-chain exposure across the country’s critical infrastructure. Once passed, the legislation is expected to be referred to as the Cyber Security and Resilience Act.

    Targeting the Supply Chain, With SMEs in the Middle

    The Cyber Security and Resilience Bill is designed to give the UK stronger enforcement tools against the weak points that enable supply-chain attacks, extending obligations further down the vendor chain than earlier UK cybersecurity legislation. Security industry commentators have noted that while the bill’s blocking power targets specific high-risk suppliers, the practical burden falls heavily on smaller technology vendors serving critical infrastructure operators, who will need to demonstrate stronger security practices or risk being excluded from the market entirely once the provisions take effect.

    Scrutiny Alone Is Not a Complete Fix, Critics Say

    Industry reaction has been mixed: while cybersecurity professionals broadly welcomed greater scrutiny of high-risk suppliers, some cautioned that blocking individual vendors cannot substitute for broader supply-chain security improvements across the sector. Commentators pointed to the energy sector incident as evidence that nation-state-linked attacks on critical infrastructure increasingly exploit third-party and supply-chain relationships rather than targeting operators directly, a pattern the new ministerial powers are intended to address but cannot fully eliminate on their own.

  • Schneider Electric, Siemens and AVEVA Patch Critical Industrial Control System Flaws in September Patch Cycle

    Schneider Electric, Siemens and AVEVA Patch Critical Industrial Control System Flaws in September Patch Cycle

    Industrial automation vendors Schneider Electric, Siemens and AVEVA published their September 2026 Patch Tuesday advisories, disclosing and fixing a batch of vulnerabilities across products used to run and monitor industrial and critical infrastructure operations.

    A Critical Flaw in Widely Deployed Safety Controllers

    The most severe issue disclosed, tracked as CVE-2026-3869 with a CVSS score of 9.2, is a critical authentication vulnerability affecting Schneider Electric’s Modicon M580 and Modicon M580 Safety programmable controllers, hardware widely used to control physical processes in manufacturing and critical infrastructure environments. Schneider Electric published four new security advisories and updated four others, including one originally issued in 2019, and separately resolved high-severity flaws in its PowerLogic T300 platform (formerly Easergy T300) and EcoStruxure IT Data Center Expert product, along with a medium-severity issue in its SCADAPack x70 line.

    Denial-of-Service Risk in Rockwell’s Historian Software

    Rockwell Automation separately disclosed CVE-2026-12661, a high-severity denial-of-service vulnerability in FactoryTalk Historian Machine Edition, in which a network-adjacent, authenticated attacker can send crafted requests to the web interface to trigger a buffer overflow that crashes the device. AVEVA’s FactoryTalk Historian SE product, which is built on the AVEVA PI Server, carries a related issue that lets an unauthenticated attacker remotely crash or exhaust memory on the PI Message Subsystem, requiring a power cycle to recover affected systems.

    Part of a Broader Monthly Cadence Across the Sector

    Since the previous month’s patch cycle, CISA has separately published advisories covering additional industrial and IoT vulnerabilities from vendors including Inductive Automation, Hitachi Energy, Furuno, Johnson Controls and others, underscoring how large and continuous the flow of disclosed operational technology vulnerabilities has become. None of the newly disclosed Schneider, Siemens, AVEVA or Rockwell flaws in this cycle have been reported as under active exploitation, but organizations running the affected controllers and historian software are advised to apply vendor patches and review network segmentation between control systems and general IT networks.

  • Four Espionage Groups Used the Same New Exploit Kit Against Chrome and Windows Within a Week

    Four Espionage Groups Used the Same New Exploit Kit Against Chrome and Windows Within a Week

    At least four separate espionage-motivated threat groups, most with suspected links to Chinese state intelligence, deployed a previously undocumented exploit kit within the same week to break into government, defense, NGO and financial-sector targets across the United States and Southeast Asia, according to research published by security firm Proofpoint.

    Chaining a Patch Gap Into a Working Exploit

    Proofpoint named the kit BlueMoon, describing it as a chain combining two zero-day flaws in Chromium-based browsers with a Microsoft Windows privilege-escalation bug, letting an attacker escape Chrome’s V8 sandbox and gain elevated access on a victim’s machine. The underlying Chrome flaw, CVE-2026-85046, was fixed in Chromium’s source code on August 7 but did not reach the stable Chrome release until September 3, nearly four weeks later; researchers say that gap between the public fix and the downstream browser update gave attackers a window to reverse-engineer the patch and build a working exploit before most users were protected. The companion Windows flaw, CVE-2026-85880, was addressed as part of Microsoft’s September 2026 Patch Tuesday updates.

    Four Campaigns, Multiple Payloads, One Shared Toolkit

    The first confirmed use came from TA412, a China-nexus group also tracked as APT31 or Violet Typhoon, which began targeting US NGOs, mining companies and physical commodity trading firms on August 28 using phishing emails posing as university outreach. Proofpoint identified three additional clusters using the same kit in the following days, including a group tracked as UNK_DoubleCheck that targeted a Vietnamese manufacturing firm from a compromised Southeast Asian government email account, and UNK_QuietRacket, which used lures referencing Indonesian conferences to target government, consulting and financial organizations in Indonesia and Singapore. Payloads delivered through the kit included the GemStone and ShadowPad malware families.

    Patching Alone Does Not Remove Existing Footholds

    CISA added the exploited Chrome flaw to its Known Exploited Vulnerabilities catalog on September 4, giving US federal civilian agencies until September 18 to patch. Researchers caution that updating the browser closes the initial infection route but does not remove malicious components, such as the GemStone extension or scheduled tasks, that earlier-compromised systems may already be running, meaning organizations that may have been targeted need to actively check for signs of persistence rather than relying on patching alone.

  • Cisco Warns of Firewall Management Zero-Day Exploited With Built-In Static Credentials

    Cisco Warns of Firewall Management Zero-Day Exploited With Built-In Static Credentials

    Cisco is warning customers that a vulnerability in its Secure Firewall Management Center (FMC) software, caused by static credentials built into a low-privilege account, was actively exploited in zero-day attacks before a fix was available.

    Hard-Coded Credentials in a Low-Privilege Account

    The flaw, tracked as CVE-2026-20316, stems from static credentials embedded in a low-privilege account within Cisco Secure FMC Software, the centralized platform organizations use to manage and monitor their Cisco firewall deployments. An unauthenticated remote attacker who knows or discovers those credentials can log in to an affected device using that account, gaining a foothold on infrastructure that is meant to be tightly restricted. Cisco says the attack surface is reduced when the FMC management interface is not exposed directly to the public internet, though the company has not disclosed how many organizations had internet-facing management interfaces at the time of exploitation.

    Cisco Learned of Active Exploitation in July, Disclosed in September

    Cisco said it became aware of active exploitation of the flaw in July 2026 but has not shared when the attacks actually began, who is behind them, or which organizations were targeted. The vulnerability was reported by Jimi Sebree of Horizon3.ai. Cisco has released hot fixes addressing CVE-2026-20316, alongside a related flaw tracked as CVE-2026-20079 that the company says can achieve root access on affected devices without relying on the static credentials at all. No workarounds fully address either vulnerability short of applying the fixed software, and Cisco is urging FMC administrators to patch immediately and review whether their management interfaces are unnecessarily exposed to the internet.

  • Startup Bluecore Energy Raises $50 Million to Build Floating Nuclear Reactors for Ports and Data Centers

    Startup Bluecore Energy Raises $50 Million to Build Floating Nuclear Reactors for Ports and Data Centers

    California-based startup Bluecore Energy has raised $50 million in seed funding to develop compact nuclear reactors mounted on floating barges, targeting ports, AI data centers and other coastal facilities with rapidly growing power demands that outstrip what local electrical grids can reliably supply.

    A Reactor You Can Tow Rather Than Build

    The round, led by Silverton Partners and announced September 8, 2026, brings in several new investors and builds on $10 million in previously announced pre-seed funding. Bluecore’s approach centers on a compact, water-cooled small modular reactor design mounted on a floating platform, an architecture the company argues can reach a site far faster than permitting and constructing a fixed land-based nuclear plant, which typically takes the better part of a decade. The company plans to use the new capital to engineer and test its reactor system and pursue regulatory approval and maritime classification, working out of the Port of Long Beach, California.

    Targeting Ports, Data Centers and Disconnected Coastal Sites

    Bluecore is positioning its floating reactors to serve ports, AI data centers and coastal infrastructure, with units potentially deployed offshore and connected to onshore customers by subsea cable, and sees a secondary market in remote islands and coastal settlements that lack a practical connection to a wider electricity grid. The pitch follows a broader push by the US Department of Energy and the International Atomic Energy Agency to expand nuclear generating capacity for AI infrastructure and other energy-intensive industries, including the IAEA’s recent launch of an initiative focused on licensing nuclear technology for maritime applications.

    Regulatory Path Remains the Key Unknown

    Whether a mobile, barge-mounted reactor design can move through a meaningfully faster regulatory and licensing pathway than a conventional fixed nuclear plant remains untested, and industry observers have flagged that question, rather than the underlying reactor engineering, as the main risk to Bluecore’s timeline. The company was founded less than a year ago by former Uber Freight executive Kofi Asante, and its rapid progression from founding to a funded, physical hardware program has drawn attention from investors as data centers compete for gigawatt-scale power commitments faster than traditional grid expansion can deliver them.