ZeroHour

Search: “iot-security”

31 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

New Italian unicorn Exein rides the physical AI wave

Italian IoT-security startup Exein raised $270 million at a $1.7 billion valuation to build a security layer for physical AI and edge devices.

Rome-based Exein raised a $270 million round led by Headline at a $1.7 billion valuation, becoming Italy's new unicorn, with plans for M&A and US/APAC expansion. The company claims over 2 billion connected devices secured across aerospace, industrial automation, automotive, energy, healthcare, and semiconductors using its Photon kernel-level runtime protection. Exein is training a foundational model for physical AI security on machine telemetry, targeted for Q1 2027, and reports 400% year-on-year growth. The EU Cyber Resilience Act, whose reporting obligations began last week, is expected to further boost demand.

TechCrunch · Security · 1d agoIndustry

Risks in IoT Supply Chain

Unit 42 analyzes multilayer IoT supply chain risks across hardware, firmware, and software, citing counterfeit Cisco switches and OpenWrt attacks.

Unit 42 examines weaknesses in the IoT supply chain ecosystem across hardware, firmware, operation, and vulnerability layers, noting that 89% of IT decision-makers reported IoT device growth and IDC forecast 41.6 billion connected IoT devices by 2025. Examples include counterfeit Cisco Catalyst 2960-X switches with possible backdoor access (F-Secure, July 2020), a March 2020 OpenWrt flaw enabling malicious update impersonation, and threat actor interest in TeamViewer remote support software. The report stresses that untracked third-party components and missing device inventories make it hard to assess vulnerability impact across vendors.

Palo Alto Unit 42 · 28d agoResearch

Quantifying IIoT Sensor Node Criticality by Fusing its Data Criticality and Security Vulnerability

Researchers propose a Dempster–Shafer framework fusing IIoT sensor data criticality with CVSS 4.0/3.1 vulnerability scores to rank node criticality.

The paper introduces a framework that evaluates Industrial IoT sensor node criticality by fusing data criticality and cybersecurity vulnerability scores using Dempster–Shafer (D-S) theory. It was validated on a dataset from red wine production and is claimed to generalize to other industrial settings with minimal modification. Results show criticality rankings derived from CVSS 4.0 scores differ significantly from those derived from CVSS 3.1, underscoring how vulnerability scoring methodology affects security prioritization.

arXiv cs.CR · 7d agoResearch

Iot Security

Vendor product-category page for Palo Alto Unit 42 IoT security content, published with no article text available.

The URL points to Palo Alto Unit 42's 'IoT Security' product category listing rather than a research article. No article body was available, so no incident, vulnerability, or research findings can be extracted from this item.

Palo Alto Unit 42 · 28d agoIndustry

How an Emerging Industrial Protocol Family Could Put OT at Risk

New research shows unprotected Time-Sensitive Networking industrial protocols could let attackers disrupt or manipulate physical processes in OT environments.

Research covered by Dark Reading examines an emerging family of industrial protocols based on Time-Sensitive Networking (TSN) and finds that unprotected implementations could be attacked to disrupt or manipulate physical processes. The findings highlight growing OT risk as these protocols proliferate in industrial deployments; no confirmed exploitation is reported.

Dark Reading · 25d agoResearch

New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks

Nozomi details KATARU, an IoT botnet that brute-forces Telnet, exploits public Linux kernel flaws for root access, and launches multi-protocol DDoS attacks.

KATARU, discovered after honeypot Telnet brute-force activity from a Vietnamese IP, downloads an ARM payload (vlxx.arm) and attempts privilege escalation by editing /etc/passwd or exploiting CVE-2026-46300 (Fragnesia), CVE-2026-43284 (Dirty Frag), and CVE-2026-31431 (Copy Fail). It combines Mirai-style TCP, UDP, ICMP, HTTP, QUIC and DNS floods with application attacks against Minecraft, FiveM, OpenVPN and WireGuard. The malware uses X25519 and ChaCha20-Poly1305 encrypted C2, unusually broad persistence across systemd, cron, init frameworks, and Android hooks, plus anti-debugging and decoy traffic to hinder analysis. Implementers copied x86 shellcode into the ARM binary and reused an RFC 7748 test-vector key, indicating low-quality but rapidly evolving commodity development.

GBHackersupdated · 5d agofirst · 5d agoMalware in the wild 2 sourcesCVE-2026-46300CVE-2026-43284CVE-2026-31431

IoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits

Unit 42 tracks a Mirai botnet campaign exploiting over 20 IoT vulnerabilities in routers, cameras and DVRs to build DDoS botnets since March 2023.

Since March 2023, Unit 42 has tracked threat actors exploiting more than 20 IoT vulnerabilities to spread a Mirai botnet variant, first seen downloading payloads from zvub.us on March 14, 2023. Exploited flaws span CVE-2023-1389 (TP-Link Archer), CVE-2022-30525 (Zyxel), CVE-2022-31499 (Nortek) and many router, camera and DVR bugs. The variant decrypts configuration strings with an XOR key derived from 0xDEADBEEF and lacks built-in credential brute forcing, so spreading relies on manual operator exploitation. Two campaigns observed since October 2022 share infrastructure and near-identical samples.

Palo Alto Unit 42 · Aug 17, 2026Malware in the wildCVE-2019-12725CVE-2019-17621CVE-2019-20500+13 CVEs1

Cybersecurity in Power Grids: Standards and Research Challenges

Survey contrasts IT and OT security in smart grids, reviewing IEC 62351, IEC 62443, ISO 27001 standards and AI-driven detection trends.

The paper examines Smart Grid cybersecurity, emphasizing critical distinctions between IT and OT environments. It analyzes grid architecture, substation threats, and key international standards including IEC 62351, IEC 62443, and ISO 27001. It concludes with an overview of recent research trends such as AI-driven threat detection.

arXiv cs.CR · 1d agoResearch

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

Weekly ThreatsDay bulletin details a ShinyHunters-style social engineering hit on ReliaQuest, the 296,000-device Dysphoria IoT botnet, and several new malware families.

ReliaQuest confirmed a social engineering attack on August 22, 2026, in which an attacker used a fake SSO page and MFA push approval to gain brief view-only access to an identity dashboard, with tactics matching ShinyHunters, which has since listed the firm on its leak portal. The Shadowserver Foundation reported the Dysphoria botnet has compromised nearly 296,000 IoT devices for DDoS attacks and recently added residential proxy capability. Cisco Talos documented JWR, an operator-driven phishing-as-a-service framework linked to The Outsider that harvests credentials, identity documents, and 2FA codes over an encrypted WebSocket. New malware coverage includes the Octagon Android fraud bot ($1,400/month), the C2Looper Rust backdoor delivered via ClickFix, and the Aeternum loader that moved C2 to the Polygon blockchain.

The Hacker News · 15d agoMalware in the wild

Php Servers And Iot Devices Cyber

Infosecurity Magazine headline reports a cyber campaign targeting PHP servers and IoT devices; no further details available.

The Infosecurity Magazine headline indicates a cyber campaign against PHP servers and IoT devices. Article text was unavailable, so techniques, scale and attribution are unknown.

Infosecurity Magazine · Aug 16, 2026Malware1

Weekly Update 519: Breaches & Data Integrity

Troy Hunt's weekly update mentions new breach data dumps, IoT door lock research, and conference preparations.

Troy Hunt's Weekly Update 519 notes that attackers have again dumped more stolen data, and discusses ongoing work including IoT door lock testing and mapping network hardware in Ubiquiti's design tool. It also references upcoming talks in Oslo and Copenhagen. The post is a routine personal update with no new vulnerability, breach details, or research findings.

Troy Hunt · 14d agoIndustry

Towards Tackling Application Logic Flaws through Autonomous Formal-Logic Modeling and Automated Reasoning

LL-Verifier combines LLMs with logic model checking to automatically discover logic flaws, uncovering vulnerabilities in 27 IoT access-control protocols.

Researchers present LL-Verifier, a framework that uses LLMs to autonomously convert natural-language protocol descriptions and security goals into formal logic models in a new logic language built on Maude, then applies logic model checking for exhaustive verification. The framework targets application-logic flaws that are tied to business semantics and hard to scale with manual analysis. Evaluation on 27 access-control protocols of widely used IoT devices uncovered a range of sophisticated logic vulnerabilities with security and privacy implications.

arXiv cs.CR · 7d agoResearch1

CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do

CISA urged water utilities to secure internet-exposed PLCs after July 2026 attacks compromised over 100 US water and wastewater systems, suspected Iran-linked.

CISA's exposure-reduction guidance, published August 21, follows July 2026 attacks in which threat actors remotely accessed PLCs connected directly through cellular modems, changed device IP addresses and passwords, and in some cases disabled alarms and shutdown processes without notifying operators. Iran is the suspected actor, though officials stopped short of formal attribution. CISA recommends routing remote access through centrally managed secure gateways, phishing-resistant MFA, unique credentials, and external scanning of industrial protocols such as Modbus, EtherNet/IP, DNP3, BACnet and OPC UA.

Security Affairs · 20d agoExploit / PoC in the wild

Analyzing a Go-Based IoT Self-Propagating DDoS Botnet

Akamai researchers published an analysis of a Go-based, self-propagating IoT botnet used for DDoS attacks.

Akamai's security research team published an analysis of a self-propagating DDoS botnet written in Go that targets IoT devices. Detailed technical findings were not available in the provided source text, which included only the title.

Akamai Blog · 13d agoMalware in the wild

Deep Packet Inspection challenges for telecom and security vendors

Enea's DPI survey of telecom and security vendors finds traffic visibility is increasingly critical yet harder as 5G, cloud, IoT, and TLS 1.3 spread.

Enea's survey of high-tech product managers at telecom and security vendors found that real-time application-level traffic visibility is considered essential as cloud adoption, 5G, remote work, and IoT dissolve traditional network perimeters. Abnormal traffic detection was the top DPI use case, 70% of respondents require classification of connected devices in enterprise and IoT/industrial networks, and TLS 1.3 (mandatory in 5G) threatens payload-based visibility. Most vendors report having or developing cloud solutions, with half planning SASE offerings integrating security and networking.

Help Net Security · 20d agoIndustry

Bipartisan Senate bill aims to prepare energy sector for Q

Bipartisan Senate bill would direct FERC to factor quantum computing threats and post-quantum cryptography into US electric grid cybersecurity reliability standards.

The Quantum Grid Utility Assurance and Resilient Defense (Quantum-GUARD) Act, introduced by Senators Mike Rounds and Chris Coons, would require FERC to consider quantum computing threats when reviewing electric reliability standards and to explore post-quantum cryptography use in both IT and OT systems, plus a technical sandbox to study quantum impacts. It aligns with NIST's post-quantum algorithm work, and a June executive order moved the federal PQC migration deadline from 2035 to 2030. Industry experts noted the hard part is upgrading infrastructure such as SCADA communications and software update integrity ahead of those deadlines.

CyberScoop · 23d agoPolicy & legal

Crytica's RDAi detects OT device tampering from within

Crytica Security announces RDAi, a deterministic in-device integrity monitoring system detecting unauthorized tampering of OT and IoT devices.

Crytica Security's Rapid Detection, Alert and isolation (RDAi) system installs a sub-100 KB Probe agent inside each protected OT or IoT device to monitor instruction set integrity and provide deterministic evidence of unauthorized changes. The high-fidelity alerts augment SOC, SIEM, XDR and AI-assisted workflows without replacing existing security investments. The company targets critical infrastructure, utility, healthcare and federal environments, with additional integrations and collaborations planned.

Help Net Security · Aug 12, 2026Tools

Webinar: How malicious OAuth apps can lead to Google Workspace breaches

BleepingComputer webinar will dissect two Google Workspace breaches caused by malicious OAuth apps and social engineering, hosted September 23 with Material Security.

On September 23, 2026, BleepingComputer will host a webinar with Material Security examining two real attacks that used malicious OAuth applications and social engineering to breach Google Workspace environments. Rather than stealing credentials, attackers persuaded users to authorize malicious apps, gaining access to data through the granted permissions. The session covers first-hour response decisions and which security controls provide the greatest value for fast-growing organizations.

BleepingComputer · 2d agoPhishing & fraud

What the Data Says About AI in Security Operations in 2026

Prophet Security's 2026 survey of 250+ security pros: 40% use AI daily; AI users report 25%+ faster investigations and rising AI-driven attacks.

Prophet Security's State of AI in Security Operations 2026 report, based on a survey of 250+ cybersecurity professionals, found 40% of security teams use AI daily and only 4% have no adoption plans. Teams average 100 daily alerts (up to 1,000 at large firms), leave 28% of alerts uninvestigated, and 60% of respondents said missed alerts led to breaches or downtime. Among AI adopters, 72% report at least 25% faster investigations, 56% observed increased AI-driven attacks, and no respondents grant AI full unsupervised autonomy. Data privacy (44%) and explainability (41%) top the adoption hurdles.

The Hacker News · 20d agoIndustry

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

CISA and NIST published NIST IR 8587, final guidance for protecting identity tokens from forgery, theft, replay, and signing-key compromise.

NIST Interagency Report 8587 (September 15, 2026) expands the IA-13 'Identity Providers and Authorization Servers' control from NIST SP 800-53 R5.1.1, guiding federal agencies and cloud providers on SSO, identity federation, and machine-to-machine authentication. It requires hardware-backed signing-key storage for moderate-impact systems, 90-day key rotation for high-impact systems, token lifetimes under one hour, and sender-constrained mechanisms such as mutual TLS and DPoP. The report cites incidents including forged SAML assertions that exposed over 60,000 emails from a federal agency. It also extends guidance to agentic AI systems using signed tokens and urges post-quantum cryptography migration planning.

Cyber Security News · 1d agoAdvisory1

Security Data Isn’t the Problem. Security Context Is.

Horizon3 blog argues security context, not data volume, is the SOC bottleneck, promoting its NodeZero integration with CrowdStrike Falcon Next-Gen SIEM.

Horizon3.ai published a vendor blog explaining how its NodeZero Proactive Security Platform integration with CrowdStrike Falcon Next-Gen SIEM brings validated exposure findings into existing security operations workflows. The post argues SOCs are now limited by confidence rather than visibility, needing context to decide which issues matter. It cites a global chemical manufacturer that validated exploitable exposures with NodeZero before completing a $2 billion merger.

Horizon3.ai · 1d agoTools

Frequently asked questions about the active threat to Siemens S7 Series PLCs

US government agencies warn that unattributed actors using AI-generated exploit scripts are targeting internet-exposed Siemens S7 PLCs in critical infrastructure.

A joint advisory from multiple U.S. government agencies warns that threat actors are exploiting known weaknesses and unnecessary internet exposure of Siemens S7 Series PLCs for reconnaissance and possible pre-positioning for future disruptive attacks. The attackers use AI to generate and refine exploit scripts faster than manual development would allow, lowering the technical bar for ICS attacks. There is no single patch, so defenders must reduce internet exposure and improve monitoring of ICS environments.

Tenable Blog · 27d agoExploit / PoC in the wild

Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices

Unit 42 analyzed the Mirai IZ1H9 botnet variant exploiting Tenda, LB-Link, DCN and Zyxel flaws to build DDoS-capable IoT botnets.

Unit 42 observed the Mirai IZ1H9 variant on April 10, 2023, using a shell script downloader lb.sh from 163.123.143.126 to infect exposed Linux servers and networking devices. Campaigns running since November 2021 share infrastructure, near-identical bot functions and the XOR key 0xBAADF00D. The malware exploits CVE-2023-27076 (Tenda G103), CVE-2023-26801 (LB-Link), CVE-2023-26802 (DCN DCBI-Netlog-LAB) and a Zyxel RCE flaw. Compromised devices join a botnet used for DDoS attacks, and the downloader deletes logs and modifies iptables to block SSH, Telnet and HTTP recovery.

Palo Alto Unit 42 · Aug 17, 2026Malware in the wildCVE-2023-27076CVE-2023-26801CVE-2023-26802

LiteLLM Supply-Chain Attack - Technology, Banking and Healthcare the Most Affected

TeamPCP planted the SANDCLOCK credential stealer in LiteLLM PyPI releases, exposing credentials across 2,038 repositories at 898 organizations including Microsoft and NVIDIA.

Threat actor TeamPCP compromised LiteLLM maintainer credentials and published malicious versions 1.82.7 and 1.82.8 to PyPI around March 2026, creating an exposure window of several months. The SANDCLOCK credential stealer exposed full credential sets across 898 GitHub owners and 2,038 repositories, including Microsoft, Azure, IBM, NVIDIA, PayPal, Deloitte, Bosch, and S&P Global. Stolen material includes GitHub CI/CD identities, AWS/GCP/Firebase credentials, SSH keys, Kubernetes secrets, and OpenAI and Anthropic API keys; Resecurity acquired a 150GB archive with 2,146 credential records. Technology, banking/finance, and healthcare organizations are the most affected sectors, and victims must rotate all exposed credentials.

Security Affairs · Aug 17, 2026Malware in the wild

NIST Warns of Unique Security Risks in Multi-Cloud Environments

NIST catalogued 23 novel security challenges unique to multi-cloud environments and urged the community to develop solutions.

NIST published an analysis identifying 23 distinct security challenges that arise specifically in multi-cloud environments. The agency explicitly encouraged the cybersecurity community to work on solutions for these gaps. The publication reflects growing official concern that spanning multiple cloud providers creates risk patterns not covered by single-cloud security models.

Infosecurity Magazine · 23d agoAdvisory

Cyberattack encrypts systems at Bavarian municipal utility

Hackers encrypted the central IT network of Bavarian utility Stadtwerke Landsberg, disrupting office systems but not electricity or water services.

Stadtwerke Landsberg said hackers encrypted its central IT network overnight on Sept. 1, prompting disconnection from the internet, crisis-team activation and external forensic support. Essential electricity and water services were unaffected, but staff availability was limited and customer data such as names, addresses and bank details may have been accessed. No ransomware group was named and no extortion demand was confirmed. The attack follows a similar late-June encryption incident at a North Rhine-Westphalia municipal utility, and the BSI consistently ranks ransomware among Germany's most serious cyber threats.

The Record · 8d agoRansomware in the wild

NSA, CISA, FBI, DOE, and EPA Warn of Active AI

Five US agencies warn of active AI-assisted attacks on internet-exposed Siemens S7 PLCs across critical infrastructure, using disguised snap7 scripts for pre-positioning reconnaissance.

NSA, CISA, FBI, DOE, and EPA issued joint advisory CISA AA26-231A warning of an active hacking campaign against Siemens S7-series PLCs, from S7-200 through S7-1500 F-series, across US critical infrastructure. Threat actors use internet scanning services such as Censys and ZoomEye to locate exposed controllers, then perform read operations over S7comm on TCP port 102 using the legitimate snap7.dll and python-snap7 libraries, disguising AI-generated exploitation scripts as monitoring tools. The agencies assess the activity as pre-positioning ahead of possible process disruption, equipment damage, or safety incidents in Energy, Water, Critical Manufacturing, Chemical, Food and Agriculture, and Commercial Facilities sectors.

Security Affairs · 27d agoExploit / PoC in the wild

Threat landscape for industrial automation systems. Q2 2026

Kaspersky's Q2 2026 report tracks ransomware, miners, and spyware detected on industrial control systems worldwide.

Kaspersky Securelist published statistics on threats blocked on industrial automation systems during Q2 2026. The report covers ransomware, cryptocurrency miners, spyware, and other malware detected on ICS environments. The quarterly telemetry gives OT defenders a view of threat trends affecting industrial infrastructure.

Kaspersky Securelist · 20d agoResearch

Has anybody seen my keys? A key-hierarchy strategy for rack-level security

Oxide's RFD 0301 proposes a rack-level key hierarchy using Shamir secret sharing and a trust quorum to protect data-at-rest keys.

Oxide's request for discussion (RFD 0301) lays out a key-hierarchy strategy for rack-level security, deriving keys from a rack secret protected by Shamir secret sharing across a trust quorum of sleds, with keys exchanged over authenticated sprockets sessions. The document maps which keys protect control-plane data, metrics, Crucible extents, and authentication tokens, and defines open questions on key lifecycle, locality, and compromise handling. Future work includes sealing shares with the root of trust so an attacker would need to steal K whole sleds to reconstruct the rack secret.