Category: Cyber-Physical Security

Coverage of the convergence between IT/cybersecurity and physical security systems, including networked device risk, secure system integration and unified threat response.

  • DEF CON Franklin and National Rural Water Association Launch Water Watch Center for Small Utilities

    DEF CON Franklin and National Rural Water Association Launch Water Watch Center for Small Utilities

    DEF CON Franklin and the National Rural Water Association (NRWA) have launched the Water Watch Center, a program giving small water utilities direct access to cybersecurity support, the organizations announced at DEF CON 34 in Las Vegas.

    What’s New

    The Water Watch Center connects small water systems — those serving fewer than 10,000 people, which make up roughly 91% of the nation’s approximately 50,000 community water systems — with five managed detection and response providers: Defendify, Legato Security, L1 Secure, Rapid7 and Sentinel Technologies. The providers exchange threat information and patches through a shared collaboration mechanism and report findings to NRWA, which coordinates response for member utilities. DEF CON Franklin, a partnership between NRWA, the University of Chicago’s Cyber Policy Initiative and DEF CON, also offers a volunteer cyber task force that matches water systems with technologists who help harden OT and IT infrastructure.

    Why It Matters

    “NRWA is excited to establish the Water Watch Center to provide the tools our sector needs to assess, prepare for, and respond to cyberattacks,” said NRWA Chief Executive Officer Matthew Holmes. The launch follows what organizers described as one of the most widespread nation-state cyberattacks on U.S. water systems to date, and comes as small utilities with limited budgets and staff have struggled to access the kind of hands-on cybersecurity support larger utilities can afford.

  • White House Executive Order Sets Federal Post-Quantum Cryptography Deadlines

    White House Executive Order Sets Federal Post-Quantum Cryptography Deadlines

    June 22, 2026 — The White House issued Executive Order 14412, formally setting deadlines for federal agencies to migrate high-value systems to NIST-approved post-quantum cryptography.

    What happened

    The order requires federal civilian agencies to complete migration of key-establishment cryptography by December 31, 2030, and digital-signature cryptography by December 31, 2031, for high-value assets and high-impact systems. It also directs the FAR Council to propose a rule requiring covered federal contractors to meet the same NIST FIPS post-quantum standards, with agency migration leads due by late July 2026 and full migration plans due by late October 2026.

    Why it matters

    A binding federal deadline, rather than voluntary guidance, gives government contractors and critical-infrastructure operators a concrete planning horizon for a migration that touches nearly every system relying on current public-key cryptography.

    Security and infrastructure impact

    Organizations supplying software, hardware or managed services to federal agencies should begin cryptographic inventory and migration planning now, since the multi-year runway to 2030–2031 is short relative to the scope of systems that need updating across large, distributed infrastructure.

    Sources

    ← Back to Technology News

  • CISA Orders Emergency Patching After Ivanti Sentry Flaw Added to KEV

    CISA Orders Emergency Patching After Ivanti Sentry Flaw Added to KEV

    June 11, 2026 — CISA confirmed active exploitation of a maximum-severity vulnerability in Ivanti’s Sentry gateway appliance and added it to its Known Exploited Vulnerabilities catalog, triggering a new binding patch deadline for federal agencies.

    What happened

    The flaw, an OS command-injection weakness in Ivanti’s security gateway appliance formerly known as MobileIron Sentry, was confirmed as actively exploited and catalogued by CISA. Under newly issued Binding Operational Directive 26-04, CISA ordered federal civilian agencies to patch the flaw within three days.

    Why it matters

    A three-day emergency patch window for a maximum-severity, actively exploited edge-appliance vulnerability underscores how little time defenders now have between public disclosure and mandated remediation for internet-facing management infrastructure.

    Security and infrastructure impact

    Organizations running Ivanti gateway appliances outside the federal directive’s direct scope should still treat the finding as an urgent patch signal, given that KEV entries reliably indicate active, opportunistic exploitation rather than theoretical risk.

    Sources

    ← Back to Technology News

  • Anthropic Launches Project Glasswing to Share AI Vulnerability-Finding With Industry

    Anthropic Launches Project Glasswing to Share AI Vulnerability-Finding With Industry

    April 9, 2026 — Anthropic announced Project Glasswing, giving a group of major technology and finance companies early access to Claude Mythos Preview, a model it says can find and exploit software vulnerabilities at a level that rivals skilled human researchers.

    What happened

    Partners in the program included Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, Nvidia and Palo Alto Networks. Anthropic said Mythos Preview had already identified thousands of high-severity vulnerabilities across every major operating system and web browser, and it kept the model unreleased to the public, citing misuse concerns.

    Why it matters

    An AI model capable of automated, human-competitive vulnerability discovery is a double-edged development: it can dramatically accelerate defensive patching, but the same capability could eventually be misused for offensive exploit development if it reaches less careful actors.

    Security and infrastructure impact

    Critical-infrastructure operators and software vendors should watch how programs like Glasswing scale, since AI-assisted vulnerability research at this level will likely change both the speed of patch cycles and the sophistication expected of future exploit attempts.

    Sources

    ← Back to Technology News

  • Ransomware Attack on Dutch Health-IT Vendor ChipSoft Disrupts Hospitals

    Ransomware Attack on Dutch Health-IT Vendor ChipSoft Disrupts Hospitals

    April 7, 2026 — A ransomware attack on ChipSoft, a software vendor used by roughly 80 percent of hospitals in the Netherlands, forced parts of its digital infrastructure offline and disrupted hospital operations.

    What happened

    The Embargo ransomware group was linked to the attack, which took ChipSoft’s public website and several patient-facing platforms — including Zorgportaal and HiX Mobile — offline. Eleven hospitals took their ChipSoft-dependent systems offline as a precaution, and the company later confirmed that medical personal data had been stolen, though it said the stolen data was subsequently destroyed.

    Why it matters

    The incident illustrates concentration risk in healthcare IT: a single software vendor’s compromise can simultaneously disrupt patient care across a large share of a country’s hospital system, a pattern increasingly common as healthcare consolidates around a small number of electronic health-record platforms.

    Security and infrastructure impact

    Hospital IT and physical-security teams should treat vendor-concentration risk as a resilience planning priority, including tested downtime procedures for core clinical software, not only for ransomware directly targeting the hospital’s own network.

    Sources

    ← Back to Technology News

  • CISA Adds Six Actively Exploited Fortinet, Microsoft and Adobe Flaws to KEV

    CISA Adds Six Actively Exploited Fortinet, Microsoft and Adobe Flaws to KEV

    April 6, 2026 — CISA added six actively exploited vulnerabilities spanning Fortinet, Microsoft and Adobe products to its Known Exploited Vulnerabilities catalog in a single batch update.

    What happened

    The additions included Fortinet FortiClient EMS and FortiSandbox flaws that allow improper access control and unauthenticated OS command injection respectively, alongside vulnerabilities in Microsoft and Adobe software. CISA’s catalog entries require affected federal agencies to remediate on a defined schedule.

    Why it matters

    Batch KEV updates spanning multiple, unrelated vendors in the same week illustrate how broadly distributed exploitation activity has become across common enterprise software rather than concentrated in a single product line.

    Security and infrastructure impact

    Security teams should treat multi-vendor KEV batches as a prompt to review patch status across their full software inventory, not just the specific products named, since KEV additions often reflect exploitation trends that spread quickly to adjacent, similarly configured systems.

    Sources

    ← Back to Technology News

  • NVIDIA Expands AI-Powered Cybersecurity Partnerships for OT and ICS

    NVIDIA Expands AI-Powered Cybersecurity Partnerships for OT and ICS

    February 23, 2026 — NVIDIA detailed integrations with Akamai, Forescout, Palo Alto Networks, Siemens and Xage Security for operational technology and industrial control security.

    What happened

    NVIDIA announced that several security and industrial vendors were integrating its accelerated computing, AI and BlueField technology into OT and ICS security offerings. The company described architectures for visibility, policy enforcement and threat response at the infrastructure edge. Capabilities will vary by partner product and deployment, so the announcement should not be read as a single universally available solution.

    Why it matters

    OT environments often combine long-lived equipment, availability constraints and limited maintenance windows. Moving selected security functions closer to industrial workloads may improve visibility and response, but it also adds components that must be engineered and governed correctly.

    Security and infrastructure impact

    Operators should validate passive discovery, segmentation, fail-safe behavior, update procedures and the effect of automated containment on production. AI-generated detections must feed accountable incident workflows rather than making uncontrolled process decisions.

    Sources

    ← Back to Technology News

  • Ransomware Remains a Critical Infrastructure Risk in 2026

    Ransomware Remains a Critical Infrastructure Risk in 2026

    2026 — Government threat assessments continue to identify ransomware as a major threat to critical infrastructure and essential public services.

    What happened

    The Canadian Centre for Cyber Security’s 2025–2026 assessment calls ransomware the leading cybercrime threat to Canadian critical infrastructure. New Jersey’s 2026 assessment likewise expects ransomware groups to continue targeting critical infrastructure and widely deployed enterprise software. These are risk assessments, not a claim that every sector or country experiences the same incident rate.

    Why it matters

    Ransomware becomes a safety and continuity problem when it disrupts hospitals, utilities, municipalities or emergency communications. Restoration priorities, manual workarounds and dependencies on vendors matter as much as endpoint detection.

    Security and infrastructure impact

    Infrastructure operators need tested offline recovery, segmented IT and OT environments, protected identity systems and decision-ready incident playbooks. Exercises should include loss of a shared service and determine which physical operations can continue safely.

    Sources

    ← Back to Technology News

  • Third-Party Involvement in Data Breaches Doubles in Verizon’s 2025 DBIR

    Third-Party Involvement in Data Breaches Doubles in Verizon’s 2025 DBIR

    April 23, 2025 — Verizon’s 2025 Data Breach Investigations Report found that third-party involvement in breaches doubled to 30 percent.

    What happened

    Verizon reported that third-party involvement appeared in 30 percent of breaches analyzed for its 2025 DBIR, double the prior report’s share. The finding covers partners and supply-chain relationships across a large incident dataset; it does not mean every vendor has the same probability of compromise.

    Why it matters

    Organizations increasingly depend on SaaS platforms, managed services, software components and connected contractors. A compromise outside the direct network can still inherit trusted access, shared data or administrative integration and produce a wide blast radius.

    Security and infrastructure impact

    Vendor assessment should extend beyond an annual questionnaire. Security teams need inventories of integrations and service accounts, least-privilege access, contract notification requirements, token revocation procedures and recovery plans for the loss of a critical supplier.

    Sources

    ← Back to Technology News

  • FCC Escalates Enforcement Against Hikvision and Dahua Equipment

    FCC Escalates Enforcement Against Hikvision and Dahua Equipment

    October 2025 — The FCC moved to close loopholes in its Covered List rules and launched “Operation Clean Carts” against the illegal online sale of banned Hikvision and Dahua equipment.

    What happened

    On October 7, 2025, FCC Chairman Brendan Carr announced the agency would vote to extend Covered List restrictions to previously authorized equipment models and covered component parts, closing a gap that had applied only to new Huawei, Hikvision and similar gear. Days later, the FCC reported that its Operation Clean Carts effort had prompted major online retailers to remove several million listings for prohibited equipment, including Hikvision and Dahua security cameras.

    Why it matters

    Extending restrictions to previously authorized equipment and component-level parts closes a significant compliance gap that had allowed legacy-authorized Hikvision and Dahua products to remain in the US market despite the broader ban.

    Security and infrastructure impact

    Integrators and end users still operating legacy Hikvision or Dahua video systems in the US — including in schools and commercial facilities with federal funding ties — should reassess compliance exposure, since enforcement has moved from new-model bans toward broader supply-chain and resale restrictions.

    Sources

    ← Back to Technology News