โŒ

Normal view

There are new articles available, click to refresh the page.
Today โ€” 11 August 2026Main stream

Cyber vulnerability sweep picks up Royal Navy drones sending data to China

10 August 2026 at 08:25
Cameras aboard Royal Navy drone boats were found phoning home to an IP address in China during a routine cyber vulnerability assessment. The UK Ministry of Defence confirmed the discovery, describing it as "an issue affecting a Kraken Unmanned Surface Vessel sub-system used by the Royal Navy." The Register understands that the data consisted of a "heartbeat" signalling that the camera was online and functioning normally. Even so, an unexpected transmission from military equipment to an IP address in China will rattle nerves. We contacted unmanned surface vessel supplier Kraken for more information, but have yet to receive a reply. An MoD spokesperson told The Reg: "A thorough investigation found no evidence of MoD data or systems being accessed, compromised or transmitted externally." "Our assurance and testing processes are designed to identify and address potential vulnerabilities early, and we continue to undertake routine security activity across our systems and equipment." According to reports, the talkative components were cameras sourced by Kraken from a third-party supplier. The incident raises questions about supply chains, audits, and cybersecurity in the British armed forces. The spokesperson said: "The first duty of government is national security, and we take the security of our equipment, networks, and data extremely seriously." Concerns about China-linked cyber activity have risen sharply in recent years. In April, the National Cyber Security Centre issued a security advisory regarding covert networks, built from compromised routers and other edge devices. Beijing is also rarely far from the headlines when spying and covert operations are involved. In January, a China-linked group was accused of spying on the phones of aides to UK prime ministers. An unexpected connection from military hardware to China is therefore concerning, even if it carried little more than an "I'm alive!" heartbeat. The incident also demonstrates why every component in a defense supply chain needs testing rather than relying on a supplier's assurances. ยฎ

Before yesterdayMain stream

New Whitepaper: Exploiting Cellular-based IoT Devices

24 March 2026 at 16:00

Rapid7 has released a whitepaper titled โ€œThe Weaponization of Cellular Based IoT Technology,โ€ by Deral Heiland, principal security researcher, IoT, at Rapid7, and Carlota Bindner, lead product security researcher at Thermo Fisher Scientific. The paper examines how attackers with physical access can exploit cellular modules in Internet of Things (IoT) devices to move into cloud and backend environments, exfiltrate data, and conceal command channels within expected device traffic. Heiland presented their findings at the RSAC 2026 conference in San Francisco.

The research focuses on how these attacks work in practice. It details how interchip communications such as USB and universal asynchronous receiver-transmitter (UART) can be observed and manipulated. It also shows how hardware modifications can replace a device host, allowing an external system to assume control of the cellular module. The authors developed proof-of-concept tools, including a TCP port scanner using AT commands, an S3 bucket enumerator, a SOCKS5 proxy that routes traffic through the cellular module, and a Metasploit proxy module. These examples demonstrate how attackers can take advantage of trusted relationships between devices and connected services.

The findings highlight consistent risks across tested devices. Cellular modules often expose multiple interfaces, and unused UART or USB paths can provide direct access. With targeted printed circuit board modifications, an attacker can reroute traffic through the cellular interface. Many modules accept AT commands that support raw sockets, HTTP requests, and TCP tunnels, which can enable reconnaissance and lateral movement. All cellular devices the researchers examined lacked tamper protections and most did not encrypt sensitive data before transmission, increasing exposure in environments that use private access point names (APNs).

Organizations should treat cellular-enabled devices as privileged entry points into their networks as well as their critical data storage and management environments. This includes disabling or removing unused interchip interfaces, enforcing end-to-end encryption before data is transmitted through the cellular modules, and applying monitoring and outbound controls within APN architectures. Hardware-level security testing should be part of standard product security practices.To read the whitepaper, click here.

Internet of Things Exploration: 2016 Ford Flex

By: BHIS
31 August 2017 at 09:43

David Fletcher// My wife and I recently purchased a 2016 Ford Flex to replace an aging version of the same make and model that met an untimely fate. During the [โ€ฆ]

The post Internet of Things Exploration: 2016 Ford Flex appeared first on Black Hills Information Security, Inc..

Creating the Next Generation of Interns

By: BHIS
5 October 2016 at 10:28

Chevy Swanson // I got my start in InfoSec through a few competitions during my time in high school. My team and I were fortunate to have aย supportive school and [โ€ฆ]

The post Creating the Next Generation of Interns appeared first on Black Hills Information Security, Inc..

โŒ
โŒ