Category: Cyber-Physical Security

Coverage of the convergence between IT/cybersecurity and physical security systems, including networked device risk, secure system integration and unified threat response.

  • Insider Threat Programs: Merging Physical and Cyber Risk Signals

    Insider Threat Programs: Merging Physical and Cyber Risk Signals

    Insider threat programs have traditionally lived in one of two silos: a physical security team tracking badge swipes, visitor logs and after-hours building access, or a cybersecurity team monitoring data exfiltration, privileged account misuse and anomalous network activity. Neither view alone tells a complete story. An employee who badges into a facility outside normal hours, then downloads an unusually large volume of files from a file share twenty minutes later, is a pattern that only becomes visible when physical access data and IT activity logs are correlated in the same timeline.

    The technical foundation for merging these signals is not exotic. Access control systems already generate structured, timestamped event logs; user and entity behavior analytics (UEBA) platforms already ingest authentication, file access and network telemetry. The harder problem is organizational: physical security, IT security, HR and legal typically operate under different reporting lines, different data retention policies and different thresholds for what counts as suspicious. A mature insider threat program has to establish a cross-functional governance structure before it can meaningfully fuse the underlying data streams, because badge data and endpoint telemetry both carry privacy and labor-law implications that vary significantly by jurisdiction.

    Once governance is in place, the technical architecture generally follows a hub-and-spoke pattern: a central risk-scoring engine ingests event feeds from access control platforms, video management systems, HR systems (departures, role changes, disciplinary actions), and IT security tools (DLP alerts, privileged access management logs, endpoint detection and response), then applies weighted rules or machine-learning models to flag combinations of behavior that individually would not trigger an alert. A single late-night badge entry is unremarkable. A late-night badge entry combined with access to a server room outside an employee’s normal work area, followed by an unusual outbound data transfer, is a materially different risk signal.

    False positives are the central operational challenge. Programs that alert on every anomaly quickly overwhelm the analysts responsible for triage, and organizations that overcorrect by raising thresholds risk missing genuine indicators. Most mature programs address this with tiered alerting: low-confidence signals feed a baseline risk score that adjusts an individual’s overall standing without generating an immediate case, while high-confidence combinations of physical and digital indicators generate a case for human review. This tiering also matters for legal defensibility, since insider threat investigations that lead to termination or law enforcement referral need an evidentiary trail that shows proportionate, policy-driven escalation rather than surveillance triggered by a single ambiguous event.

    Departure workflows are one of the highest-value integration points. Employees who have resigned or been notified of termination represent a statistically elevated period of insider risk, and organizations increasingly automate a coordinated response across systems: access control credentials are scheduled for deactivation at a specific time, video retention policies for the individual’s typical work areas are extended, and IT security tooling temporarily lowers the alert threshold for that user’s accounts. Coordinating this sequence requires access control, HR information systems and IT identity platforms to share a common employee identifier and event bus, which is often the most significant integration project in standing up a converged program.

    Vendor tooling in this space spans several categories: dedicated insider risk management platforms that specialize in behavioral analytics across HR, IT and physical data; broader security information and event management (SIEM) platforms extended with physical access connectors; and unified physical security platforms that have added behavioral analytics modules on top of existing access control and video management functionality. Organizations evaluating these options should weigh not just detection capability but data governance: how long behavioral profiles are retained, who can access risk scores, and what due-process protections exist for employees flagged by an automated system, since insider threat programs that lack clear governance can create legal exposure and erode workforce trust even when the underlying technology performs as intended.

  • Over 100 Tech Companies Including OpenAI, Anthropic, Google and Microsoft Sign Letter on Defending Against AI-Driven Cyber Threats

    Over 100 Tech Companies Including OpenAI, Anthropic, Google and Microsoft Sign Letter on Defending Against AI-Driven Cyber Threats

    More than 100 technology companies, including OpenAI, Anthropic, Google and Microsoft, signed an open letter published August 27, 2026 urging closer cooperation between the private and public sectors to defend against AI-related cyber threats, according to TechCrunch. The letter calls for coordinated action as increasingly capable AI models are used both to accelerate cyberattacks and, in parallel, to help defenders detect and respond to them faster.

    TechCrunch reported that several of the signatories are, in the same period, continuing to develop more advanced frontier AI models even as they promote defensive programs built on that same technology, including OpenAI’s Daybreak program, Anthropic’s Mythos initiative, and a newly introduced cyber-defense platform from Microsoft called Perception. The report characterized this as a “conflicted position” for labs simultaneously advancing capability and warning about the risks that capability can pose in the hands of attackers.

    The initiative follows a series of disclosures throughout 2026 in which security researchers and AI labs described attackers using large language models to accelerate reconnaissance, vulnerability discovery and exploit development, alongside separate efforts by AI companies to formalize responsible-disclosure and defensive-use programs for their own models. The letter does not, according to the report, set out binding commitments, but frames the current moment as one requiring shared standards and cooperation between AI developers, security vendors, and government agencies as both offensive and defensive uses of AI systems mature.

    For security teams evaluating AI-enabled defensive tools, the emergence of vendor-specific programs from major model developers adds a new category of capability alongside established security operations center analytics platforms, though it also raises procurement questions about how defensive AI programs from foundation model vendors will integrate with, or compete against, existing security information and event management and extended detection and response tooling already deployed across enterprise and critical infrastructure environments.

  • CISA Publishes New Round of ICS Advisories Covering Industrial Test, Fleet and IoT Devices

    CISA Publishes New Round of ICS Advisories Covering Industrial Test, Fleet and IoT Devices

    The Cybersecurity and Infrastructure Security Agency published a new batch of industrial control system advisories on August 27, 2026, covering vulnerabilities in products used across manufacturing, transportation and utility test environments. Among the advisories was one for Rockwell Automation’s OTTO Fleet Manager, tagged to the Critical Manufacturing and Transportation Systems sectors, which CISA said contains a flaw (CVE-2026-75112) that could reduce the computational cost required for an attacker to carry out offline brute-force attacks against stored password hashes in versions up to V2.36.2.

    A separate advisory covered the Applied Systems Engineering ASE2000 V2 Communications Test Set, a tool used to test IEC 60870-5-104 protocol communications common in electric utility SCADA environments. According to the advisory and a technical writeup published by Trout Software, the affected versions (2.25 through 2.37) carry two flaws: a legacy XML external entity issue tied to an outdated bundled Apache log4net library, and an improper certificate validation weakness in the product’s IEC 60870-5-104 TLS client that could allow an attacker to intercept and impersonate a trusted peer during protocol testing. CISA credited researcher Enoch Wang with the report and noted the vendor has released version 2.38 as a fix.

    CISA also published advisories for the Xiiaozet LK100W device, warning that successful exploitation of the flaws it identified could allow an attacker to take control of the device, and for the All-Line Equipment Company Fuel-Boss and Ebyte NA111-M products. As with its standard ICS advisory practice, CISA’s guidance recommends that asset owners minimize network exposure of control system devices, ensure they are not directly reachable from the internet, and place control system networks behind firewalls, isolated from business IT networks.

    The advisories arrive amid a broader pattern industry researchers have flagged this year: security vendor Forescout reported that ICS advisory volume topped 500 for the first time in 2025, with a growing share of vulnerabilities affecting field controllers, remote terminal units and other Purdue Model Level 1 devices that directly interface with physical processes. CISA continues to publish advisories on a rolling weekly basis covering vendors ranging from major industrial automation suppliers to smaller niche device manufacturers used in specific utility and manufacturing test workflows.

  • CISA Adds ownCloud, Linux Kernel and JFrog Artifactory Flaws to Known Exploited Vulnerabilities Catalog

    CISA Adds ownCloud, Linux Kernel and JFrog Artifactory Flaws to Known Exploited Vulnerabilities Catalog

    The Cybersecurity and Infrastructure Security Agency added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 27, 2026, citing evidence of active exploitation. The additions are CVE-2023-49105, an improper authentication vulnerability in ownCloud; CVE-2026-53362, an unspecified vulnerability in the Linux Kernel; and CVE-2026-66384, an improper limitation of a pathname to a restricted directory vulnerability affecting JFrog Artifactory, according to CISA’s alert.

    CISA’s advisory notes that vulnerabilities of this type are “a frequent attack vector for malicious cyber actors” and pose significant risk to federal networks. Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies are required to remediate KEV catalog entries within CISA-specified timeframes, though the directive does not legally bind private-sector organizations.

    The JFrog Artifactory path traversal flaw is notable given the platform’s widespread use as a binary and package repository in enterprise software development pipelines; a pathname restriction bypass in that context can potentially allow an attacker to read or write files outside intended directories, a class of vulnerability that has previously been leveraged for both data exfiltration and remote code execution in build and artifact-management systems. The ownCloud authentication flaw, tracked since 2023, affects a self-hosted file-sharing platform used by organizations that manage sensitive document storage internally rather than through commercial cloud providers.

    CISA said it “will continue to add vulnerabilities to the catalog that meet the specified criteria” and encouraged all organizations, not just federal agencies, “to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.” The agency’s KEV catalog has become a widely used reference point across the security industry for prioritizing patch management amid a growing volume of disclosed vulnerabilities.

  • ATF Confirms Data Breach After Ransomware Group Claims Access to Investigation Data

    ATF Confirms Data Breach After Ransomware Group Claims Access to Investigation Data

    The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a cyberattack affected a system containing information about the targets of its investigations, following claims by a ransomware group that it had gained access to the agency’s data, Reuters reported.

    What’s New

    According to court documents and public reporting, the ransomware group gained access to a computer system holding information related to ATF investigative targets. The agency confirmed the breach but has not disclosed the full scope of the data involved or attributed the intrusion to a specific threat actor.

    Why It Matters

    A breach touching active investigation data raises risks beyond typical data-exposure incidents, potentially compromising ongoing law enforcement operations and the safety of investigative targets and personnel if the information is misused or leaked. The incident adds to a string of confirmed breaches at U.S. federal agencies this year and comes weeks after the Justice Department and FBI moved to disrupt state-sponsored hacking infrastructure targeting other parts of the federal government.

  • Australian Police Charge Two Men Over TeamPCP Hacking Group Linked to Open-Source Supply Chain Breaches

    Australian Police Charge Two Men Over TeamPCP Hacking Group Linked to Open-Source Supply Chain Breaches

    The Australian Federal Police, working with the FBI and the Western Australia Police Force, arrested and charged two Perth-area men on August 26, 2026 over their alleged roles in TeamPCP, a cybercrime group blamed for a string of high-profile breaches this year. Louis Michael Gaebler, 23, of Mandurah, and Ruben Ian Thomson, 21, of Cottesloe, appeared in Perth Magistrates Court on August 27 facing a combined 14 charges, according to the AFP and reporting from TechCrunch, The Hacker News and Help Net Security.

    Investigators allege the pair were principal participants in a syndicate that planted malicious code in popular open-source software projects, which was then unwittingly incorporated by developers and organizations worldwide, according to the AFP statement cited by ABC News Australia. The Hacker News reported that TeamPCP has been tied to the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS, as well as the AI gateway LiteLLM, while TechCrunch reported the group has also been blamed for hacks affecting Mercor and OpenAI.

    According to Help Net Security’s account of the charges, the Cottesloe man faces eight offenses including possessing and supplying data for use in computer offenses, unauthorized modification of data, failing to comply with a data-access order, and dealing with proceeds of crime worth more than AU$100,000; the maximum penalties involved range from three to twenty years’ imprisonment. Investigators searched properties in Cottesloe, Hamilton Hill and Mandurah, seizing electronic devices now undergoing forensic examination.

    The AFP said the investigation began in April 2026 after it and the FBI received tips about a syndicate inserting malicious code into open-source packages used by other developers, and that “further arrests and charges have not been ruled out” as the forensic review of seized data continues, per SecurityWeek’s reporting.

    The case highlights the continuing risk that open-source software supply chains pose as a vector for widescale compromise: a single tampered dependency or scanning tool can propagate into the environments of every organization that pulls it into a build pipeline, a dynamic security teams have increasingly had to account for in software composition analysis and dependency-vetting programs.

  • Johnson Controls Metasys Building Automation Platform Patches Persistent XSS Vulnerability

    Johnson Controls Metasys Building Automation Platform Patches Persistent XSS Vulnerability

    Crafted URL Can Hijack Administrator Sessions

    CISA published ICS advisory ICSA-26-225-14 on August 13, 2026, disclosing a cross-site scripting vulnerability in Johnson Controls Metasys, a building automation and management platform used across critical manufacturing, commercial facilities, government facilities, transportation systems and energy sites worldwide. Tracked as CVE-2026-34491 and rated CWE-79, the flaw carries a CVSS v3 base score of 8.0.

    According to CISA, a low-privilege user can inject a malicious payload into the Metasys web interface through a crafted URL. The payload persists across logins and executes in the browser context of other users who view the affected page, including administrators, which could lead to session hijacking and unauthorized access to building systems. The advisory lists Metasys 12 and 13 as affected in all versions, and Metasys 14 before v14.1.5 and Metasys 15 before v15.0.1.

    Mitigation

    Johnson Controls has released patched versions for the affected Metasys 14 and 15 branches and published mitigation guidance for the platform. CISA recommends operators apply the available updates, restrict Metasys web interface access to trusted networks, and follow standard input-validation and session-management hardening for building management system deployments.

    Sources

  • Siemens Patches Critical Remote Code Execution Flaw in Siveillance Video Management Servers

    Siemens Patches Critical Remote Code Execution Flaw in Siveillance Video Management Servers

    Command Injection Rated Critical

    CISA published ICS advisory ICSA-26-225-09 on August 13, 2026, describing a critical vulnerability in Siemens Siveillance Video, a video management platform deployed worldwide across the critical manufacturing, communications and commercial facilities sectors. Tracked as CVE-2026-3014 and rated CWE-78 (OS Command Injection), the flaw affects Siveillance Video V2023 R3 versions before 23.3.27, V2024 R1 versions before 24.1.16, and V2025 versions before 25.1.15, with a CVSS v3 base score of 9.1.

    According to the advisory, a user with edit permissions on the Management Server can exploit the flaw to execute arbitrary code in the context of the Management Server service, which could allow an attacker to take control of connected video management infrastructure.

    Updates Available for All Affected Branches

    Siemens has released fixed versions for each affected release branch: V23.3 HotfixRev27 or later, V24.1 HotfixRev16 or later, and the V25.1.15 update for the 2025 branch. CISA and Siemens recommend that operators update to the corrected versions as soon as practical and, in line with general ICS hardening guidance, restrict Management Server edit permissions to trusted administrators and segment video management infrastructure from untrusted networks.

    Sources

  • UK and Ukraine Sign AI Defense Partnership Granting Access to Ukraine’s Avengers AI Labs

    UK and Ukraine Sign AI Defense Partnership Granting Access to Ukraine’s Avengers AI Labs

    Britain and Ukraine signed a partnership in Kyiv on Monday, August 24, 2026, to jointly develop artificial intelligence tools for defense and security, with the UK becoming the first international partner granted access to Ukraine’s Avengers AI Labs battlefield-data platform, according to Reuters and a UK government statement.

    A Battlefield Dataset Built From Ukraine’s War

    UK Prime Minister Andy Burnham and Ukrainian President Volodymyr Zelenskyy signed the agreement, which the UK government describes as part of the two countries’ “100 Year Partnership.” Avengers AI Labs is built around an annotated dataset of roughly 5 million battlefield images, according to Ukraine’s Defence Ministry, drawn largely from the DELTA combat management and situational-awareness system. The platform aggregates data from cameras and sensors deployed across Ukraine’s front lines, capturing tanks, artillery, air-defense systems, infantry and aerial targets including Shahed drones and reconnaissance UAVs, which is used to train AI models that the UK government says currently identify a majority of targets in real time.

    Under the deal, Britain will in turn back Ukraine with access to its universities, researchers and technology companies, which the UK government describes as the world’s third-largest AI ecosystem. The agreement initially focuses on defense and national-security applications, bringing together engineers, academics, businesses and military operational experts from both countries.

    Fiber-Optic Sensing and Low-Power AI Chips Among First Pilot Projects

    Three British startups — Bristol-based Sintela, Oxford-based Mind Foundry, and London-based Skyral — are involved in the initial pilot projects announced alongside the partnership. The first project turns buried fiber-optic cables into a distributed AI-enabled sensor system, initially being trialed at a UK defense site to detect protesters and hostile actors attempting to gather intelligence; UK officials say the same approach could later extend to protecting airports, prisons, railways and energy plants. A second pilot project will explore low-power AI chips designed for future drones, robotics and autonomous systems.

    The AI agreement was announced alongside a separate decision by the UK to let defense contractor MBDA release classified information on UK-made components for the SCALP long-range missile, enabling local assembly lines in Ukraine. UK Defence Secretary Wes Streeting and AI Minister Kanishka Narayan both framed the AI partnership as part of a broader push to convert Ukraine’s wartime operational data into long-term technology and national-security capability for both countries.

    Sources

  • DOJ and FBI Seize Domains Behind Chinese State-Sponsored QScan and QTRouter Hacking Platforms

    DOJ and FBI Seize Domains Behind Chinese State-Sponsored QScan and QTRouter Hacking Platforms

    The U.S. Department of Justice and FBI announced August 26, 2026 that they had executed court-authorized domain seizures to disable two linked hacking platforms, known as QScan and QTRouter, used by a China-based, state-sponsored group the department identified as QTFY. According to the DOJ’s press release, court documents unsealed in the Southern District of California name Nanjing Xinjiuwei Network Technology Company as the operator of QTFY, which the department said sells hacking services to clients including the Chinese Ministry of State Security and the People’s Liberation Army.

    Court filings describe QScan and QTRouter as complementary tools: QScan searches the internet and automatically infects vulnerable internet-of-things devices, such as home routers and security cameras, while QTRouter forms an obfuscation network from those compromised devices that lets operators route attack traffic through infected machines in more than 130 countries, concealing the true origin of intrusions, FBI Cyber Assistant Director Brett Leatherman said in a video statement released by the bureau.

    The DOJ said the disruption made both platforms inoperable because the seized domains were hard-coded into their communication and authentication functions, a technique reported by The Record based on court documents. According to the department, victims of QTFY’s activity since at least 2018 include NASA, the Federal Reserve, the Department of Energy, the Department of Justice itself, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate, as well as power companies, telecommunications providers, hospitals, financial institutions and defense contractors.

    Leatherman described the action as the disruption of “a global botnet used by a Chinese state-sponsored group … to target U.S. critical infrastructure,” adding that QTFY had “exploited software vulnerabilities to launch cyberattacks against U.S. government agencies, power companies, telcos, and major hospital systems” for nearly a decade. The FBI said QTFY’s services were also sold to customers beyond the Chinese government, though it did not name additional clients.

    The takedown is the latest in a series of U.S. actions targeting Chinese state-linked infrastructure-scanning and botnet operations, and underscores continuing concern among federal agencies about the use of compromised consumer and small-business IoT devices, including routers and security cameras, as staging infrastructure for espionage-linked intrusions into critical infrastructure networks.