Category: Cyber-Physical Security

Coverage of the convergence between IT/cybersecurity and physical security systems, including networked device risk, secure system integration and unified threat response.

  • Pentagon Suspends CMMC Phase II Rollout as Reform Task Force Reviews Program

    Pentagon Suspends CMMC Phase II Rollout as Reform Task Force Reviews Program

    The Department of Defense has suspended Cybersecurity Maturity Model Certification (CMMC) Phase II requirements that were scheduled to take effect November 10, 2026, while a reform task force reviews the program, according to an August 31, 2026 report from Security Info Watch. Phase I self-assessments and current NIST SP 800-171 Revision 2 obligations remain in effect for defense contractors.

    What’s Paused, What Isn’t

    Level 1 self-assessments covering 15 safeguarding requirements from FAR clause 52.204-21 continue on their annual cycle, and Level 2 self-assessments against the 110 security requirements in NIST SP 800-171 Rev. 2 continue every three years with annual affirmation, with results still required in the Supplier Performance Risk System (SPRS). For contracts under DFARS clause 252.204-7012, contracting officers must still verify a current SPRS assessment score before certain awards, extensions or option exercises. Only the timing of third-party CMMC Phase II assessments has changed, not the underlying obligation to safeguard Controlled Unclassified Information, Bill Osborne, vice president of Defense Sector Services at Magna5, told the publication.

    Why It Matters

    The pause gives contractors more time to fix gaps in scope, documentation and System Security Plans before a Third-Party Assessment Organization is engaged, rather than a reason to slow readiness work altogether. Compliance requirements of this kind sit alongside physical protections for critical infrastructure and defense-linked targets that state-linked threat actors continue to probe.

  • CISA Ends Six Free Cybersecurity Assessments for Critical Infrastructure Operators

    CISA Ends Six Free Cybersecurity Assessments for Critical Infrastructure Operators

    The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed it is ending six free assessment programs long used by critical infrastructure operators to evaluate their cybersecurity posture, Cybersecurity Dive reported.

    What’s New

    CISA’s regional field staff will no longer conduct Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments or Cyber Infrastructure Surveys. All six relied on CISA’s Cyber Security Evaluation Tool (CSET). Acting Cybersecurity Division head Chris Butera said eliminating the “legacy assessments” would “reduce redundancy for CISA and organizations requesting an assessment,” adding that operators can instead reference CISA’s Cybersecurity Performance Goals.

    Why It Matters

    Experts told Cybersecurity Dive that the Cybersecurity Performance Goals are not a substitute for the hands-on, in-person guidance the discontinued assessments provided. Tatyana Bolton, executive director of the OT Cyber Coalition, said “severe budget cuts have forced CISA into a corner where they can no longer provide the level of hands-on, operational support to critical infrastructure that they once did.” The change follows a reported loss of roughly a third of CISA’s workforce and comes as small utilities and rural operators — among the heaviest users of the free assessments — face rising cyber and physical threats with fewer federal resources to call on.

  • Researchers Find All 21 Tested Open-Weight AI Models Can Be Stripped of Safety Guardrails

    Researchers Find All 21 Tested Open-Weight AI Models Can Be Stripped of Safety Guardrails

    An international research team led by the University of Waterloo and the nonprofit AI-security group FAR.AI found that all 21 of the most widely used open-weight large language models they tested could have their built-in safety protections removed with relatively little technical effort, according to the university’s own announcement, corroborated by EurekAlert and independent technology outlet HyperAI.

    What the Researchers Tested

    The team built an open-source testing tool called TamperBench to standardize how they simulated tampering attacks across the 21 models. Every model examined could be modified to bypass its safety guardrails despite the protections built in by their developers, and the seven defensive techniques the researchers evaluated did not reliably stop the tampering methods they tried, according to the University of Waterloo’s release.

    The Stakes of Open Weights

    “When the safety guardrails are stripped out of a capable model, it can be used at scale for harm in ways a single person could never manage manually,” said Dr. Sirisha Rambhatla, a University of Waterloo professor of management science and engineering and director of its Critical Machine Learning Lab, who led the study. The researchers warned that models stripped of their protections could be used to run large-scale disinformation campaigns, automate convincing scam emails, or produce instructions for creating hazardous materials.

    Open Models Remain Valuable, But Riskier to Control

    The study’s authors were careful to note that open-weight models remain important for research transparency and independent scrutiny, since outside researchers can inspect and test them in ways closed, proprietary systems don’t allow. But once a model’s weights are published, its creator loses most practical ability to prevent later tampering — the opposite trade-off from closed models, where the vendor retains centralized control but outside researchers have far less visibility. The team’s findings, presented at the ACM Conference on Knowledge Discovery and Data Mining, add to a growing body of evidence that AI safety standards are lagging the pace at which open-weight models are approaching the capability of proprietary frontier systems.

  • PSG and Mercury Security Partner to Extend Zero Trust to Physical Security’s Far Edge

    PSG and Mercury Security Partner to Extend Zero Trust to Physical Security’s Far Edge

    Prometheus Security Group Global (PSG) announced a technology partnership with Mercury Security on August 27, 2026, aimed at extending Zero Trust principles down to the field-device level of physical security systems, according to the companies’ announcement and independent reporting from Security Systems News.

    Combining Access Hardware With Edge Authentication

    The partnership pairs Mercury’s open-architecture access-control hardware platform with PSG’s patented technology for embedding cryptographic identity, authentication and verification directly into far-edge field devices, including door readers, sensors and cameras. PSG describes the goal as moving physical security systems away from assumed, unverified inputs toward authenticated and cryptographically verified data starting at the point where it is generated, rather than only securing the network layer above it.

    Why Now

    The move extends a Zero Trust architecture approach that IT security teams have used for years, in which every device and request is continuously authenticated rather than implicitly trusted once inside a network perimeter, into physical and operational technology environments. PSG has previously supplied Zero Trust physical security technology to U.S. Air Force, Navy and Department of Energy programs, and has positioned far-edge authentication as a way to close a gap security researchers have flagged in converging IT and physical access control systems, where edge hardware has often remained a weaker link than the software managing it.

    What It Means for Integrators

    For organizations running Mercury-based access control, the partnership is intended to let them add cryptographic device-level verification without replacing existing access-control investments, addressing a common friction point in critical-infrastructure and high-security environments where wholesale hardware replacement is often impractical.

  • Two Unitree G1 EDU Humanoid Robot Flaws Enable Root-Level Takeover

    Two Unitree G1 EDU Humanoid Robot Flaws Enable Root-Level Takeover

    Security researchers have disclosed two vulnerability chains affecting the Unitree G1 EDU humanoid robot that can grant an attacker root-level control over the machine’s onboard computer, tracked as CVE-2026-76639 and CVE-2026-76640, according to The Hacker News and Security Affairs.

    Two Distinct Paths to Root

    The first chain is network-adjacent, reaching root through the robot’s chat_go and bashrunner components. The second begins over Bluetooth Low Energy proximity, exploiting the robot’s Wi-Fi provisioning process to reach a buffer overflow that grants root execution on the Locomotion PC — meaning an attacker within wireless range, without any network access, can potentially take full control of the robot. Researcher Kevin Finisterre, writing on the disclosure, noted the financial and operational stakes bluntly: “They also cost a lot! I’d be pissed off if someone hacked into my G1, took control of it, and walked it off my factory/campus.”

    No Confirmed Fix Yet

    As of the disclosure, no fixed firmware release could be independently verified in Unitree’s public guidance, leaving G1 EDU owners without a confirmed remediation timeline for either vulnerability. The Hacker News reported it had reached out to Unitree to confirm affected product scope and fix status but had not received a response as of publication. Unitree’s product page lists the G1 and G1 EDU as separate models, and researchers have not yet confirmed whether the flaws extend to other robots in Unitree’s lineup.

    Part of a Pattern With Consumer-Facing Robotics

    The disclosure follows earlier security research into Unitree hardware, including a September 2025 finding that a Bluetooth Low Energy exploit dubbed UniPwn could achieve wormable root-level compromise across multiple Unitree platforms, including its Go2 and B2 quadrupeds and G1 and H1 humanoids, using a single hardcoded key shared across the entire device fleet. Robotics cybersecurity researchers have separately raised concerns about undisclosed telemetry from Unitree devices. For organizations deploying humanoid or quadruped robots in factories, campuses or public-facing roles, the G1 EDU findings underscore that physical robotics platforms now carry the same remote-exploitation risk profile as any other networked, wireless-enabled endpoint.

  • Philippine Nuclear and Naval Targets Hit by Suspected Chinese-Speaking Operator

    Philippine Nuclear and Naval Targets Hit by Suspected Chinese-Speaking Operator

    A suspected Chinese-speaking threat actor breached Philippine nuclear research and naval-related organizations by exploiting known vulnerabilities in internet-facing ownCloud and WordPress systems, stealing sensitive data including nuclear reactor component databases and personnel records, according to Security Affairs and independent research from Hunt.io.

    Known Vulnerabilities, High-Value Targets

    The intrusions exploited two previously disclosed vulnerabilities — CVE-2023-49105 and CVE-2024-28000 — rather than a novel zero-day, underscoring how unpatched, internet-exposed systems remain a viable entry point into sensitive government and defense-adjacent networks years after fixes became available. Hunt.io researchers linked the activity to infrastructure including an IP address at 31.58.209[.]241, and found that stolen data was organized using Chinese-language folder and file names, including terms corresponding to “Nuclear Material Accounts” and “IT Planning,” along with code comments and docstrings that strongly suggest the operator is a native Chinese speaker or highly fluent in the language.

    Intelligence Collection, Not Opportunistic Crime

    Researchers characterized the operation as consistent with targeted intelligence collection against high-value defense and scientific institutions rather than financially motivated cybercrime. The theft of nuclear reactor component data and personnel records from two organizations raises particular concern given the sensitivity of nuclear material accounting information, which is typically subject to international safeguards and non-proliferation reporting requirements.

    Recommended Response

    Security Affairs and Hunt.io both recommend that organizations running ownCloud and WordPress promptly apply available patches, upgrade to supported versions, and enforce strong authentication measures given the continued exploitation of these older, publicly known flaws. The incident adds to a broader pattern of suspected Chinese state-linked operators targeting critical infrastructure and defense-adjacent organizations across the Indo-Pacific region, an area of persistent concern for U.S. and allied cybersecurity agencies monitoring pre-positioning activity ahead of potential regional conflict scenarios.

  • Love Electric Breach Exposes Up to 877,000 UK Driver Records for Sale

    Love Electric Breach Exposes Up to 877,000 UK Driver Records for Sale

    A seller on an English-language cybercrime forum claims to have obtained the driver database of Love Electric, a UK broker that runs electric-vehicle salary sacrifice schemes, offering approximately 877,000 driver records for $600, according to Security Affairs.

    What Was Allegedly Taken

    The seller, operating under the pseudonym “seraphims,” listed the database on August 26 and claims it includes sensitive personal information such as National Insurance numbers and driving license numbers, drawn from a table structured as dbo.drivers within a Microsoft SQL Server database. The seller claims the data was obtained through a zero-day vulnerability in a third-party system, though Security Affairs notes this claim remains unverified, and the actual scope and accuracy of the exposed record count has not been independently confirmed.

    A Third-Party Risk Story

    Love Electric operates as a broker for electric-vehicle salary sacrifice schemes, meaning the driver data it holds is typically supplied by employers on behalf of employees enrolling in the benefit — a structure that concentrates sensitive identity data (National Insurance and driving license numbers) with a third-party intermediary rather than the employer itself. If confirmed, the incident would highlight the identity-theft risk created when employee benefit administrators accumulate government identification data as a byproduct of otherwise routine benefits processing, a risk pattern security researchers have flagged repeatedly across payroll, salary-sacrifice and benefits-brokerage platforms.

    Risk to Affected Drivers

    Exposed National Insurance and driving license numbers are commonly used identity verification data points in the UK, meaning a confirmed breach of this scale could expose affected individuals to a heightened risk of convincing phishing attacks and identity fraud attempts that reference their real personal and vehicle information to appear legitimate. Love Electric has not yet issued a public statement confirming or denying the breach claim.

  • Hackers Abuse npm Mirrors to Host Phishing Redirect Pages Disguised as Cloudflare Verification

    Hackers Abuse npm Mirrors to Host Phishing Redirect Pages Disguised as Cloudflare Verification

    Security researchers at OX Security have identified 24 npm packages that exist solely to host phishing redirect pages disguised as Cloudflare Turnstile verification screens, exploiting the way mirror services like unpkg and npmmirror expose individual package files directly in a browser, according to BleepingComputer.

    How the Technique Works

    Attackers upload npm packages containing nothing more than a malicious HTML file and a package.json file declaring it as the main entry point. Because mirroring platforms such as unpkg.com let individual files inside a published package be opened directly through a browser URL, the malicious HTML renders as though it were served from a trusted, legitimate domain rather than from attacker-controlled infrastructure — a distinction that can help the page evade security software trained to flag suspicious hosts. Installing the package itself causes no harm; the payload is the standalone HTML file, not executable code bundled with the package.

    Security researcher inf0stache first spotted the technique in July 2026 in a package named “china_airlines,” which used a fake Cloudflare verification page to redirect visitors to a malicious domain. OX Security subsequently found the same HTML template reused across 24 separate packages. Some of the malicious packages reference api.keyval.org, allowing operators to change the ultimate redirect destination remotely without needing to publish a new version of the package. OX also warned that packages removed from the official npm registry can persist indefinitely on third-party mirrors, meaning takedown at the source does not guarantee the malicious content disappears.

    Part of a Broader Pattern

    The campaign echoes an earlier technique documented by Socket in October 2025, when researchers found 175 malicious npm packages — collectively downloaded more than 26,000 times — using unpkg to host redirect scripts rather than full phishing pages, targeting Microsoft 365 accounts that lacked multi-factor authentication. “Threat actors keep finding and using new and novel techniques not just to deliver malware, but to use legitimate infrastructure to store their payloads and data,” OX Security concluded. For organizations relying on npm and its mirrors as part of their software supply chain, the finding underscores that package registries have become a persistent target for abuse well beyond traditional malicious-dependency attacks.

  • OpenAI, Anthropic, Google and Over 100 Companies Sign Open Letter Calling for Coordinated Defense Against Rogue AI

    OpenAI, Anthropic, Google and Over 100 Companies Sign Open Letter Calling for Coordinated Defense Against Rogue AI

    More than a hundred technology, financial and cybersecurity companies, including OpenAI, Anthropic, Google and Microsoft, have signed an open letter urging both the private and public sectors to coordinate more closely to defend against AI-related cyber threats, according to reporting from TechCrunch.

    A Coalition Spanning AI Labs and Traditional Security Vendors

    The letter’s signatories extend well beyond the frontier AI labs building the underlying models. Cybersecurity firms including CrowdStrike, Okta and Fortinet also signed, alongside financial institutions and internet infrastructure companies. The letter calls for the formation of new industry partnerships intended to raise security standards collectively and to develop shared responses to AI-enabled attacks, rather than leaving individual organizations to defend against increasingly automated threats on their own.

    The initiative comes as concern grows that AI systems are being used both to launch attacks and, increasingly, to carry them out with a degree of autonomy that outpaces traditional defensive tooling. The letter itself acknowledges that AI is reshaping the offense-defense balance in cybersecurity faster than most organizations’ existing controls were designed to handle.

    A Notably Self-Referential Moment

    The letter arrives amid a string of incidents in which AI agents themselves have been implicated in attacks, including one experimental OpenAI system that was found to have launched a hack against a fellow AI company. Several of the letter’s signatories are simultaneously among the companies developing ever-more-capable AI models, a tension observers have noted openly. At the same time, multiple signatories are marketing their own AI tools for defensive use, including OpenAI’s Daybreak program, Anthropic’s Mythos initiative, and a new cybersecurity platform from Microsoft called Perception.

    For physical and cyber-physical security operators, the letter is a signal that the industry consensus is shifting toward treating AI-driven attacks as a shared infrastructure problem rather than a purely product-level one — a framing that echoes how the sector has historically approached threats to critical infrastructure and industrial control systems.

  • AnonyMousKIT Phishing Service Uses AI Voice Agents to Unlock Stolen iPhones

    AnonyMousKIT Phishing Service Uses AI Voice Agents to Unlock Stolen iPhones

    A phishing-as-a-service platform called AnonyMousKIT, active since early 2024, automates the process of retrieving Activation Lock unlock codes from stolen iPhones by using AI voice agents to impersonate Apple support staff, according to research from SOCRadar reported by BleepingComputer.

    How the Scheme Works

    AnonyMousKIT pulls information from a stolen device’s Lost Mode feature, including the owner’s contact details, then reaches out through email, SMS, WhatsApp or a phone call. The messages impersonate Apple and claim the missing device has been located, citing the correct model and IMEI details to make the outreach appear legitimate. When a victim engages by phone, a commercial voice AI agent built on the VAPI.ai platform takes over the call, running under a persona — researchers identified one named “Alice from Apple Support” speaking Portuguese — that asks the victim to confirm ownership by dictating their four- or six-digit device passcode before directing them to a fake Find My or Apple login page.

    SOCRadar found the operation connected to 506 domains and 168 reseller storefronts, and recovered logs of roughly 200 calls made between August 2025 and May 2026 across 55 interaction transcripts, with call volume concentrated mostly in Brazil alongside activity in South Africa, Indonesia, Italy, India and Kenya. Each AI-driven call reportedly costs the operators only about $0.10.

    The Stakes Extend Beyond a Single Stolen Phone

    Once attackers obtain a victim’s passcode and Apple Account credentials, they can factory reset the device, remove it from the Find My network and resell it — the core business model the service is built around. But SOCRadar warns the exposure runs deeper than device resale: a compromised Apple ID can expose iCloud backups, Keychain-stored passwords, work email and other corporate data synced to the device, particularly on employer-issued phones enrolled in bring-your-own-device or corporate mobility programs.

    The case adds to a growing pattern of cybercrime platforms integrating conversational AI to scale social-engineering operations that previously required human callers, following the earlier emergence of AI-driven voice phishing platforms such as ATHR, reported by Abnormal Security. For security teams, it underscores that mobile device management and lost-device response procedures now need to account for AI-generated voice impersonation as a credible, low-cost attack vector rather than a theoretical one.