Category: Cyber-Physical Security

Coverage of the convergence between IT/cybersecurity and physical security systems, including networked device risk, secure system integration and unified threat response.

  • Maximum-Severity SAP Commerce Cloud Flaw Targeted Days After Patch

    Maximum-Severity SAP Commerce Cloud Flaw Targeted Days After Patch

    A maximum-severity vulnerability in SAP Commerce Cloud is facing active exploitation attempts, according to threat intelligence firm Defused and reporting by Cybersecurity Dive and The Hacker News, only days after SAP issued a fix.

    A Default-Authentication Bypass Rated CVSS 10.0

    The flaw, tracked as CVE-2026-58231, is described by SAP and CVE.org as an improper authorization issue in the Commerce Cloud Data Hub Adapter that allows an unauthenticated attacker to abuse a default authentication client and submit crafted input to functions that lack sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, according to CVE.org’s description, affecting confidentiality, integrity and availability. SAP Commerce Cloud is an enterprise e-commerce platform widely used by retailers to run online storefronts.

    From Patch to Exploitation in Days

    SAP shipped the fix, detailed in Security Note 3771065, as part of its August 2026 Security Patch Day on August 11, 2026. Defused CEO Simo Kohonen told Cybersecurity Dive that the firm’s honeypots began recording exploitation activity just three days after the patch was released, and that, as of the firm’s report, only one threat actor appeared to have attempted exploitation, suggesting the activity is not yet widespread. Defused said no proof-of-concept had circulated publicly before this exploitation was observed.

    Why It Matters

    No specific breached retailer had been publicly confirmed as of the most recent reporting; coverage has focused on exploitation attempts and defensive urgency. Prior SAP vulnerabilities, including CVE-2025-31324 in NetWeaver, have previously been weaponized by China-nexus espionage groups and ransomware actors such as BianLian and RansomExx, according to The Hacker News, underscoring the importance of applying SAP’s patch immediately rather than waiting for a confirmed incident.

  • Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Records

    Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Records

    Thomson Reuters disclosed on September 2, 2026 that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in an intrusion the company says occurred in March 2026, according to Thomson Reuters’ own disclosure and reporting by Reuters and The Hacker News.

    Scope: 11 States, the U.S. Virgin Islands and Ontario

    West Publishing said it discovered the unauthorized activity on June 30, 2026 and notified affected courts and Ontario’s Ministry of the Attorney General between July 23 and July 27. According to the company’s notice, a subset of affected court records could contain individuals’ names, Social Security numbers, driver’s license numbers, dates of birth, medical information and health insurance information. Some states reported that only backup data was involved, while Ohio said its production platform was accessed; Montana and Minnesota said court documents themselves were not part of the accessed data, though the vendor’s notice indicates sealed material may have been affected for certain courts.

    Coordinated, Delayed Public Disclosure

    Public disclosure came more than two months after the affected courts and Ontario were notified. Montana officials said the September 2 disclosure date was chosen so that the vendor and the various affected states could issue simultaneous announcements. Thomson Reuters said it has found no evidence to date that the exposed data has been misused.

    Why It Matters

    Court case management platforms sit at a sensitive intersection of physical and information security: they hold sealed records, victim and witness information, and identity data whose exposure carries legal as well as privacy consequences. The incident underscores the exposure created by shared third-party software used across many independent government bodies, where a single vendor compromise can cascade into simultaneous notifications across multiple jurisdictions.

  • Maximum-Severity SonicWall SMA 1000 Flaws Under Active Exploitation, CISA Warns

    Maximum-Severity SonicWall SMA 1000 Flaws Under Active Exploitation, CISA Warns

    SonicWall disclosed on September 1, 2026 that two vulnerabilities in its SMA 1000 series secure remote access appliances are being actively exploited in the wild, according to the vendor’s own advisory, SNWLID-2026-0016, and confirmed by CISA, Rapid7 and Qualys Threat Protect.

    A Chainable Path to Unauthenticated RCE

    The more severe flaw, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) vulnerability in the SMA 1000 Appliance Work Place interface, carrying the maximum possible CVSS score of 10.0. According to SonicWall’s advisory, an unintended alternate access path causes the appliance to act as an unintended forward proxy, letting a remote unauthenticated attacker reach sensitive functionality. Rapid7’s analysis found that this SSRF flaw can be chained with a second, high-severity OS command injection vulnerability in the Appliance Management Console, CVE-2026-83549, which normally requires authenticated administrator access, to achieve full unauthenticated remote code execution.

    Federal Deadline and Wide Exposure

    CISA added the flaw to its Known Exploited Vulnerabilities catalog and set a September 5, 2026 remediation deadline for federal civilian agencies. SonicWall SMA 1000 appliances are widely deployed as VPN and zero-trust access gateways by large enterprises, government agencies and managed service providers, making the appliance an attractive target given the level of internal network access it typically brokers.

    Response

    SonicWall has released a hotfix addressing CVE-2026-83548; the company states no workaround is available for organizations that cannot immediately patch. Security researchers recommend organizations apply the hotfix without delay, review SMA 1000 logs for signs of the unauthorized proxy behavior described in the advisory, and treat any indicators of compromise found before the patch was applied as a potential breach requiring further investigation.

  • UK Aviation Cyber Assessment Finds Suppliers Are the Sector’s Weakest Link

    UK Aviation Cyber Assessment Finds Suppliers Are the Sector’s Weakest Link

    A new assessment of UK aviation’s external cyber exposure has found that third-party suppliers, not airport operators, account for the overwhelming majority of the sector’s cyber security weaknesses, according to research firm MyDomainRisk and coverage published by International Airport Review on September 3, 2026.

    Scanning 43 Operators and 51 Suppliers From the Outside

    MyDomainRisk said it examined the public web estate of 43 UK airport operators, covering 54 airports, alongside 51 organizations those airports depend on, using only externally visible, unauthenticated scanning. The firm emphasized that no airport operational technology, air-traffic, airline, baggage-handling or screening system was accessed or tested as part of the work; the scope was limited to what is visible to anyone on the public internet.

    Exposure Is Concentrated in the Supply Chain

    Of 1,152 exposed employee credential records identified across both groups, only 10 belonged to airport operators, according to MyDomainRisk; the remainder sat with suppliers, which also accounted for three leak-site mentions. Ground-operations providers were flagged as the weakest supplier class, with the firm reporting that 92 percent of staff-credential exposure across the study sits within three airside supplier categories. Gabriel Higgins, writing for International Airport Review, said suppliers’ average security posture score badly trailed that of the operators they serve.

    The One Place Airports Underperform

    The assessment identified a single measure where airport operators scored worse than their suppliers: email authentication. Seventeen of the 43 airport operators studied, or 40 percent, cannot instruct receiving mail systems to reject an email forged in their name, according to the research. Higgins quoted the study’s author describing this as both one of the sector’s simplest fixes and one of its most consequential, since an airport’s own domain is a far more attractive identity for attackers to spoof than that of a lesser-known supplier.

  • Google Patches Actively Exploited Chrome V8 Zero-Day, Sixth of 2026

    Google Patches Actively Exploited Chrome V8 Zero-Day, Sixth of 2026

    Google released Chrome 152 security updates on September 3, 2026, patching 12 vulnerabilities including a high-severity flaw that attackers are already exploiting, according to Google’s own advisory and reporting from The Hacker News, SecurityWeek and BleepingComputer.

    A Type Confusion Bug in Chrome’s Core Engine

    The exploited flaw, tracked as CVE-2026-85046 and rated CVSS 8.8, is a type confusion vulnerability in V8, the JavaScript and WebAssembly engine that powers Chrome. Google’s advisory describes the bug as allowing a remote attacker to execute arbitrary code inside Chrome’s sandbox via a specially crafted HTML page. Google said it is aware that an exploit for the flaw exists in the wild but withheld technical details of the observed attacks to limit further exploitation while users update. Security researcher Salvatore Gulizia, credited with reporting the issue on August 4, 2026, received a $1,000 bug bounty for the disclosure.

    Sixth Exploited Chrome Zero-Day This Year

    CVE-2026-85046 is the sixth actively exploited Chrome zero-day Google has patched in 2026, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281 and CVE-2026-11645. The same update, which brings Chrome to version 152.0.7977.82/.83 on Windows and macOS and 152.0.7977.82 on Linux, also fixes nine other high-severity issues spanning Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools and Skia components.

    Why It Matters for Security Operators

    Chromium-based browsers sit behind a large share of enterprise workstations, control-room terminals and web-based video management and access-control clients, making browser zero-days a recurring entry point into otherwise segmented environments. Google is rolling out the fix gradually; users and IT administrators are advised to confirm they are running version 152.0.7977.82 or later via Chrome’s Settings > About Chrome menu and restart the browser to complete the update rather than waiting for automatic rollout.

  • Attackers Exploit MikroTik RouterOS Flaw Chain to Seize Routers Without Authentication

    Attackers Exploit MikroTik RouterOS Flaw Chain to Seize Routers Without Authentication

    Poland’s national CSIRT, CERT Polska, disclosed on September 5, 2026 that attackers are actively exploiting a chain of MikroTik RouterOS vulnerabilities to gain full administrative control of internet-exposed routers with no valid login and no private key required, according to CERT Polska’s advisory and reporting by The Hacker News and Security Affairs.

    Two Flaws Chained Into Full Takeover

    CERT Polska disclosed six RouterOS vulnerabilities in total, naming the exploited chain “MikroTrick.” The first, CVE-2026-67276 (CVSS 9.2), is an SSH authentication bypass rooted in how RouterOS verifies RSA public keys: an attacker who knows a valid username and the public portion of that user’s RSA key can forge a key and log in without possessing the corresponding private key. The second, CVE-2026-86060 (CVSS 9.2), is a privilege-escalation flaw triggered by a crafted username beginning with a disallowed character, which alters the trusted RouterOS policy mask and grants the resulting SSH session full administrative rights. Chained together, the two flaws let an attacker take over any internet-facing RouterOS device with SSH enabled.

    Exploitation Already Under Way

    CERT Polska said observed exploitation dates back to at least September 2, 2026, three days before public disclosure. Independent researcher Costin Raiu published a technical breakdown the same day as the advisory, writing that anyone running a MikroTik router with SSH exposed to the internet should treat the device as compromised until proven otherwise. Shodan scans referenced in coverage of the advisory show roughly 300,000 vulnerable devices still reachable from the public internet.

    Fixes and Recommended Response

    MikroTik has released patched builds: 6.49.21 for the long-term 6.x branch, 7.23.4 for the long-term 7.x branch, and 7.24.2 for the stable 7.x branch. CERT Polska is advising administrators to update immediately, restrict SSH management access to trusted networks rather than the open internet, and check devices for unknown users, unfamiliar scripts and other signs of compromise before assuming a device is clean.

  • Sangoma Switchvox Flaw Under Active Exploitation as CISA Sets Federal Patch Deadline

    Sangoma Switchvox Flaw Under Active Exploitation as CISA Sets Federal Patch Deadline

    Threat actors are actively exploiting a critical vulnerability in Sangoma’s Switchvox enterprise VoIP phone system, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog and order federal civilian agencies to remediate it on an accelerated timeline, according to Horizon3.ai, SecurityWeek and CISA’s own advisory.

    An Unauthenticated Path to Remote Code Execution

    Tracked as CVE-2026-9586 and rated CVSS 9.3, the flaw sits in Switchvox’s /pa endpoint, which processes XML content from supported IP phones. According to research published by Horizon3.ai, the endpoint concatenates a user-controlled PhoneIP value directly into PostgreSQL queries without sanitization or parameterization, allowing an unauthenticated remote attacker to execute arbitrary SQL with a single crafted HTTP request. Horizon3.ai reported that exploitation can be chained into full remote code execution, including database modification, privilege escalation within the application, operating-system command execution and extraction of authentication secrets.

    Patch Timeline and a Compressed Federal Deadline

    Horizon3.ai said it reported the flaw to Sangoma in April 2026, and Sangoma shipped a fix in Switchvox 8.4.0.2 on July 14, 2026. Security firm Field Effect reported that researchers began observing exploitation attempts in the wild on August 30, 2026, including reverse-shell deployment and post-exploitation reconnaissance on compromised systems. CISA added CVE-2026-9586 to its KEV catalog on September 2, 2026, and set a September 5, 2026 remediation deadline for federal civilian agencies under Binding Operational Directive 26-04.

    Why It Matters

    Shodan scans cited by researchers show roughly 4,000 Switchvox systems reachable from the open internet. Because Switchvox functions as a business’s core telephony and call-management platform, a successful compromise can expose call records, credentials and internal network access alongside the immediate database and code-execution impact. Organizations running on-premises Switchvox deployments are advised to apply version 8.4.0.2 or later immediately, restrict management interfaces from the public internet, and review logs for indicators of compromise identified by Horizon3.ai and Field Effect.

  • OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders

    OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders

    OpenAI is committing $1 billion to subsidize access to its cyber-capable AI models for critical infrastructure defenders and launching a center to train security professionals in the U.S. public sector, as part of an expansion of its Daybreak program, the company said.

    What’s New

    The Daybreak Defense Network will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about specific costs or eligibility criteria. The company has selected HackerOne as one of a limited group of cybersecurity vendors with early access to its frontier cyber capabilities through the network. OpenAI co-founder Greg Brockman has separately published a blog post describing the use of AI agents to find and fix security vulnerabilities.

    Why It Matters

    “There are a large amount of people and organizations that want to uplevel their security, but they don’t know how,” Brockman said, adding that without broader adoption of AI-assisted defense, “it’s possible we can expect critical infrastructure outages as part of normal life.” The pledge follows a separate letter signed by OpenAI, Anthropic, Google, Microsoft and more than 100 other companies calling for coordinated industry defense against AI-driven cyber threats, and reflects a wider push by frontier AI labs to position their models as tools for under-resourced defenders in sectors like water, energy and healthcare.

  • Report: Security Leaders Overconfident on Authentication Even as Modernization Stalls

    Report: Security Leaders Overconfident on Authentication Even as Modernization Stalls

    A new report from rf IDEAS and Wavelynx has found that most security leaders believe their organizations are more advanced than industry peers on authentication, even though barely a quarter describe their systems as largely modernized, according to the 2026 State of Authentication Modernization Report published August 31, 2026.

    Key Findings

    The survey of 500 IT and security leaders at mid-sized to enterprise organizations found 93% believe their authentication and security maturity outpaces their industry peers, yet only 24% said their systems are largely modernized and 53% have not significantly updated authentication systems in at least three years. While 78% called modernization a high priority for the next 12 months, only 72% of managers closer to day-to-day execution agreed it was a high priority, and 27% cited unclear return on investment as a barrier. Among organizations that do prioritize the work, 55% plan to allocate at least $500,000 to it, but credential and authentication upgrades ranked eighth among security initiatives overall, behind higher-profile priorities.

    Why It Matters

    Forty percent of respondents estimated that a breach involving unauthorized access would cost their organization less than $1 million, well below the $4.4 million global average cost of a data breach reported for 2025. rf IDEAS and Wavelynx said the gap between confidence and readiness underscores the need to treat physical and logical access control as a single modernization effort rather than two separate budgets.

  • LastPass Adds Mobile Smart Scanner and Expanded SaaS Monitoring to Business Security Suite

    LastPass Adds Mobile Smart Scanner and Expanded SaaS Monitoring to Business Security Suite

    LastPass rolled out a series of product updates on August 31, 2026 aimed at credential and access management, including what the company describes as the industry’s first Mobile Smart Scanner and expanded SaaS Monitoring capabilities for its Business Max customers, according to the company’s announcement carried by Security Info Watch.

    What’s New

    The Mobile Smart Scanner lets users scan passwords from printed lists, screenshots and handwritten notes through the LastPass Mobile app and convert them into encrypted, autofill-ready credentials. Persistent Monitoring, now fully released across all browser extensions, keeps SaaS visibility active through a permanent browser-extension connection even when a user is signed out of LastPass, and administrators can now set more granular SaaS Protect usage rules for specific users or groups. LastPass also completed its move from a Legacy Admin Console to a single Unified Admin Console, introduced a company-wide sign-up link for Teams, Business and Business Max customers, and is shifting Dark Web Monitoring for consumer accounts to automatic enrollment. The company said it passed independent SOC 2 and ISO 27001/27701 audits with zero findings for a second consecutive year.

    Why It Matters

    LastPass tied the updates to IBM’s 2026 Cost of a Data Breach Report, which found AI-driven attacks rose 56% year over year and added roughly $1 million to average breach costs, with 92% of organizations hit by AI-related breaches lacking adequate AI access controls. The emphasis on visibility and credential hygiene mirrors a broader push across the industry to close the kind of access gaps that groups exploit in AI-assisted phishing and credential-theft campaigns.