Category: Cyber-Physical Security

Coverage of the convergence between IT/cybersecurity and physical security systems, including networked device risk, secure system integration and unified threat response.

  • Check Point Patches Critical VPN Vulnerabilities in Security Gateway and Spark Firewall

    Check Point Patches Critical VPN Vulnerabilities in Security Gateway and Spark Firewall

    Check Point has patched two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a CVSS score of 9.8, in the VPN functionality of its Security Gateway and Spark Firewall products, SecurityWeek reported. The flaws stem from a certificate-validation issue and an ASN.1 heap overflow bug that together could allow unauthenticated remote code execution.

    Check Point said its own researchers discovered both vulnerabilities internally, and the company has not confirmed any in-the-wild exploitation to date. Fixes are available in versions R82.10, R82, and R81.20.

    Why it matters: VPN gateways sit at the network perimeter for a large share of enterprise and critical-infrastructure networks, making unauthenticated RCE flaws in this class of product a high-priority patch item regardless of whether active exploitation has been observed yet — the same category of flaw was exploited in the wild within days at other vendors this quarter.

    Source: SecurityWeek, September 11, 2026.

  • CISA Updates Advisory on Critical Flaws in ST Engineering iDirect Satellite Terminals

    CISA Updates Advisory on Critical Flaws in ST Engineering iDirect Satellite Terminals

    CISA issued Update A to advisory ICSA-26-183-01, covering four vulnerabilities in ST Engineering iDirect iQ-series satellite (VSAT) terminals, with CVSS scores up to 8.8 and one flaw rated 9.4 on the CVSS 4.0 scale. The advisory was originally released July 2, 2026.

    The flaws include missing authentication on REST API endpoints that expose device identity and cryptographic material, a cross-site request forgery vulnerability that can trigger a remote reboot or denial of service, a local privilege-escalation path via a factory-default low-privilege account, and exposure of password hashes. CISA lists Communications, Defense Industrial Base, Energy, Government and Transportation as affected sectors.

    Why it matters: VSAT terminals from vendors like ST Engineering iDirect provide connectivity for maritime vessels, remote energy sites, and defense operations where terrestrial networks are unavailable. Authentication bypasses on internet-facing satellite terminal management interfaces are a persistent, underappreciated risk category for organizations with remote or offshore infrastructure.

    Source: CISA ICS Advisory ICSA-26-183-01 (Update A), September 10, 2026.

  • CISA Advisory: Hard-Coded Cryptographic Key Found in AVEVA Pipeline Integrity Monitor

    CISA Advisory: Hard-Coded Cryptographic Key Found in AVEVA Pipeline Integrity Monitor

    CISA published advisory ICSA-26-253-01 describing four vulnerabilities in AVEVA Pipeline Integrity Monitor, with CVSS scores up to 8.4 (CVE-2026-81821 through CVE-2026-81824). The flaws include a hard-coded cryptographic key, use of a broken or risky cryptographic algorithm, missing authorization checks, and a stored cross-site scripting vulnerability.

    According to CISA, successful exploitation could allow an attacker to disclose sensitive project data, brute-force password hashes, or execute arbitrary code in a victim’s browser session. The advisory identifies the Critical Manufacturing sector as affected. AVEVA has released a fix in the 2025 SP1 P2 release.

    Why it matters: Pipeline integrity monitoring software is used to track the structural and operational health of oil, gas and other pipeline infrastructure. Vulnerabilities that expose project data or credential material in this class of software are a direct concern for critical-infrastructure operators, even where exploitation requires network access rather than being remotely trivial.

    Source: CISA ICS Advisory ICSA-26-253-01, September 10, 2026.

  • Vecna Robotics Raises $31 Million as FCC Foreign-Robot Restrictions Boost US-Built Warehouse Automation

    Vecna Robotics Raises $31 Million as FCC Foreign-Robot Restrictions Boost US-Built Warehouse Automation

    Waltham, Massachusetts-based Vecna Robotics raised $31 million led by Unless, DC Velocity reported, citing surging demand tied to a July 2026 Federal Communications Commission policy restricting purchases of certain foreign-made robots on cybersecurity grounds. The company builds case and pallet automation systems for warehouses.

    Vecna said the funding will be used to scale deployment teams and expand its automation capabilities as US-based logistics operators shift purchasing toward domestically built robotics platforms.

    Why it matters: The FCC’s restriction treats foreign-made warehouse and logistics robots as a potential cybersecurity and supply-chain risk category, similar to earlier restrictions on foreign-made telecom and video surveillance equipment — a signal that physical automation hardware is increasingly being evaluated through the same national-security lens as networking gear and cameras.

    Source: DC Velocity, September 10, 2026, corroborated by GlobeNewswire press release and Boston Business Journal.

  • New PivotC2 RAT Delivered via Exploited Fortinet FortiOS Heap Overflow, Infects 178 Devices

    New PivotC2 RAT Delivered via Exploited Fortinet FortiOS Heap Overflow, Infects 178 Devices

    CISA added CVE-2025-25249, a heap-overflow vulnerability in Fortinet FortiOS, to its Known Exploited Vulnerabilities catalog after identifying active exploitation, The Hacker News reported. Attackers are using the flaw to deliver a newly identified Node.js-based remote access trojan dubbed PivotC2, which has infected 178 devices to date, the majority located in the United States.

    The disclosure was part of a broader CISA KEV update covering multiple actively exploited network-perimeter vulnerabilities, with a federal patch deadline tied to the update.

    Why it matters: FortiOS underpins firewall and VPN infrastructure across a large share of small and mid-sized enterprise and critical-infrastructure networks. A newly identified, purpose-built RAT delivered through an actively exploited perimeter flaw is a strong signal that organizations running FortiOS should treat this patch as time-sensitive rather than routine.

    Source: The Hacker News, September 10, 2026, citing CISA KEV catalog update.

  • UK Moves to Give Ministers Power to Block High-Risk Tech Suppliers From Critical Infrastructure

    UK Moves to Give Ministers Power to Block High-Risk Tech Suppliers From Critical Infrastructure

    The UK government has tabled late amendments to its Cyber Security and Resilience Bill that would give ministers new powers to block critical-sector organizations from using technology suppliers considered a national security risk, as concern grows over supply-chain vulnerabilities feeding attacks on critical infrastructure.

    A Response to a Recent Energy Sector Attack

    The government tabled the amendments on August 24, 2026, underscoring what officials describe as an urgent need to give ministers explicit authority to prevent critical infrastructure operators from engaging technology suppliers deemed high risk. The move follows a cyberattack, reportedly linked to a nation-state actor, that took a UK energy generator offline for four days, an incident that industry commentators say sharpened political attention on supply-chain exposure across the country’s critical infrastructure. Once passed, the legislation is expected to be referred to as the Cyber Security and Resilience Act.

    Targeting the Supply Chain, With SMEs in the Middle

    The Cyber Security and Resilience Bill is designed to give the UK stronger enforcement tools against the weak points that enable supply-chain attacks, extending obligations further down the vendor chain than earlier UK cybersecurity legislation. Security industry commentators have noted that while the bill’s blocking power targets specific high-risk suppliers, the practical burden falls heavily on smaller technology vendors serving critical infrastructure operators, who will need to demonstrate stronger security practices or risk being excluded from the market entirely once the provisions take effect.

    Scrutiny Alone Is Not a Complete Fix, Critics Say

    Industry reaction has been mixed: while cybersecurity professionals broadly welcomed greater scrutiny of high-risk suppliers, some cautioned that blocking individual vendors cannot substitute for broader supply-chain security improvements across the sector. Commentators pointed to the energy sector incident as evidence that nation-state-linked attacks on critical infrastructure increasingly exploit third-party and supply-chain relationships rather than targeting operators directly, a pattern the new ministerial powers are intended to address but cannot fully eliminate on their own.

  • Schneider Electric, Siemens and AVEVA Patch Critical Industrial Control System Flaws in September Patch Cycle

    Schneider Electric, Siemens and AVEVA Patch Critical Industrial Control System Flaws in September Patch Cycle

    Industrial automation vendors Schneider Electric, Siemens and AVEVA published their September 2026 Patch Tuesday advisories, disclosing and fixing a batch of vulnerabilities across products used to run and monitor industrial and critical infrastructure operations.

    A Critical Flaw in Widely Deployed Safety Controllers

    The most severe issue disclosed, tracked as CVE-2026-3869 with a CVSS score of 9.2, is a critical authentication vulnerability affecting Schneider Electric’s Modicon M580 and Modicon M580 Safety programmable controllers, hardware widely used to control physical processes in manufacturing and critical infrastructure environments. Schneider Electric published four new security advisories and updated four others, including one originally issued in 2019, and separately resolved high-severity flaws in its PowerLogic T300 platform (formerly Easergy T300) and EcoStruxure IT Data Center Expert product, along with a medium-severity issue in its SCADAPack x70 line.

    Denial-of-Service Risk in Rockwell’s Historian Software

    Rockwell Automation separately disclosed CVE-2026-12661, a high-severity denial-of-service vulnerability in FactoryTalk Historian Machine Edition, in which a network-adjacent, authenticated attacker can send crafted requests to the web interface to trigger a buffer overflow that crashes the device. AVEVA’s FactoryTalk Historian SE product, which is built on the AVEVA PI Server, carries a related issue that lets an unauthenticated attacker remotely crash or exhaust memory on the PI Message Subsystem, requiring a power cycle to recover affected systems.

    Part of a Broader Monthly Cadence Across the Sector

    Since the previous month’s patch cycle, CISA has separately published advisories covering additional industrial and IoT vulnerabilities from vendors including Inductive Automation, Hitachi Energy, Furuno, Johnson Controls and others, underscoring how large and continuous the flow of disclosed operational technology vulnerabilities has become. None of the newly disclosed Schneider, Siemens, AVEVA or Rockwell flaws in this cycle have been reported as under active exploitation, but organizations running the affected controllers and historian software are advised to apply vendor patches and review network segmentation between control systems and general IT networks.

  • Four Espionage Groups Used the Same New Exploit Kit Against Chrome and Windows Within a Week

    Four Espionage Groups Used the Same New Exploit Kit Against Chrome and Windows Within a Week

    At least four separate espionage-motivated threat groups, most with suspected links to Chinese state intelligence, deployed a previously undocumented exploit kit within the same week to break into government, defense, NGO and financial-sector targets across the United States and Southeast Asia, according to research published by security firm Proofpoint.

    Chaining a Patch Gap Into a Working Exploit

    Proofpoint named the kit BlueMoon, describing it as a chain combining two zero-day flaws in Chromium-based browsers with a Microsoft Windows privilege-escalation bug, letting an attacker escape Chrome’s V8 sandbox and gain elevated access on a victim’s machine. The underlying Chrome flaw, CVE-2026-85046, was fixed in Chromium’s source code on August 7 but did not reach the stable Chrome release until September 3, nearly four weeks later; researchers say that gap between the public fix and the downstream browser update gave attackers a window to reverse-engineer the patch and build a working exploit before most users were protected. The companion Windows flaw, CVE-2026-85880, was addressed as part of Microsoft’s September 2026 Patch Tuesday updates.

    Four Campaigns, Multiple Payloads, One Shared Toolkit

    The first confirmed use came from TA412, a China-nexus group also tracked as APT31 or Violet Typhoon, which began targeting US NGOs, mining companies and physical commodity trading firms on August 28 using phishing emails posing as university outreach. Proofpoint identified three additional clusters using the same kit in the following days, including a group tracked as UNK_DoubleCheck that targeted a Vietnamese manufacturing firm from a compromised Southeast Asian government email account, and UNK_QuietRacket, which used lures referencing Indonesian conferences to target government, consulting and financial organizations in Indonesia and Singapore. Payloads delivered through the kit included the GemStone and ShadowPad malware families.

    Patching Alone Does Not Remove Existing Footholds

    CISA added the exploited Chrome flaw to its Known Exploited Vulnerabilities catalog on September 4, giving US federal civilian agencies until September 18 to patch. Researchers caution that updating the browser closes the initial infection route but does not remove malicious components, such as the GemStone extension or scheduled tasks, that earlier-compromised systems may already be running, meaning organizations that may have been targeted need to actively check for signs of persistence rather than relying on patching alone.

  • Cisco Warns of Firewall Management Zero-Day Exploited With Built-In Static Credentials

    Cisco Warns of Firewall Management Zero-Day Exploited With Built-In Static Credentials

    Cisco is warning customers that a vulnerability in its Secure Firewall Management Center (FMC) software, caused by static credentials built into a low-privilege account, was actively exploited in zero-day attacks before a fix was available.

    Hard-Coded Credentials in a Low-Privilege Account

    The flaw, tracked as CVE-2026-20316, stems from static credentials embedded in a low-privilege account within Cisco Secure FMC Software, the centralized platform organizations use to manage and monitor their Cisco firewall deployments. An unauthenticated remote attacker who knows or discovers those credentials can log in to an affected device using that account, gaining a foothold on infrastructure that is meant to be tightly restricted. Cisco says the attack surface is reduced when the FMC management interface is not exposed directly to the public internet, though the company has not disclosed how many organizations had internet-facing management interfaces at the time of exploitation.

    Cisco Learned of Active Exploitation in July, Disclosed in September

    Cisco said it became aware of active exploitation of the flaw in July 2026 but has not shared when the attacks actually began, who is behind them, or which organizations were targeted. The vulnerability was reported by Jimi Sebree of Horizon3.ai. Cisco has released hot fixes addressing CVE-2026-20316, alongside a related flaw tracked as CVE-2026-20079 that the company says can achieve root access on affected devices without relying on the static credentials at all. No workarounds fully address either vulnerability short of applying the fixed software, and Cisco is urging FMC administrators to patch immediately and review whether their management interfaces are unnecessarily exposed to the internet.

  • ‘DoppelCart’ Fraud Network Runs 119,000 Fake Online Stores to Steal Payment Card Data

    ‘DoppelCart’ Fraud Network Runs 119,000 Fake Online Stores to Steal Payment Card Data

    German cybersecurity company Nebty has identified a fraud operation dubbed DoppelCart, describing it as the largest publicly documented fake-shop network by domain count, spanning almost 119,000 domains built to mimic real retailers and harvest payment card data from bargain-hunting shoppers.

    A Cluster Built Almost Entirely on One Top-Level Domain

    Nebty’s scans identified 118,787 domains in the cluster, the large majority registered under the .shop top-level domain and accounting for roughly 2.72% of all sites on that TLD. As of the researchers’ latest scans, more than 105,000 of the fake shops remained active. The sites mimic more than 44,000 real brands, with a typical brand cloned around twice, though some brands, including SodaStream, Velasca, CurrentBody, Daniel Wellington and Dreame, were impersonated by more than 30 separate shops each. The fake storefronts typically advertise discounts of up to 65% to lure shoppers searching for deals.

    Shared Infrastructure Behind Thousands of Storefronts

    Despite the scale of the operation, the underlying infrastructure is comparatively narrow: researchers found that 96% of confirmed DoppelCart shops shared identical build files and ran on just 27 distinct e-commerce backends, suggesting a small number of template kits power the vast majority of the cluster. When testing checkout pages across the network, Nebty found code specifically built to collect payment card numbers and cardholder information at the point of sale, rather than simply taking payment through a legitimate processor and never delivering goods.

    The New Largest Fake-Shop Network on Record

    DoppelCart significantly surpasses the previously largest documented fake-shop cluster, “BogusBazaar,” a network of roughly 75,000 sites tied to an estimated 850,000 fraudulent transactions. Researchers advise shoppers to check unfamiliar retail URLs carefully for odd domain extensions, verify a business has visible customer reviews and contact information, and treat unusually steep discounts on well-known brands as a warning sign rather than an opportunity.