IoT & ICS Security - Security Boulevard https://securityboulevard.com/category/blogs/iot-ics-security/ The Home of the Security Bloggers Network Tue, 26 Mar 2024 16:04:05 +0000 en-US hourly 1 https://wordpress.org/?v=6.4.3 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png IoT & ICS Security - Security Boulevard https://securityboulevard.com/category/blogs/iot-ics-security/ 32 32 133346385 Security Vulnerability in Saflok’s RFID-Based Keycard Locks https://securityboulevard.com/2024/03/security-vulnerability-in-safloks-rfid-based-keycard-locks/ https://securityboulevard.com/2024/03/security-vulnerability-in-safloks-rfid-based-keycard-locks/#respond Wed, 27 Mar 2024 11:01:08 +0000 https://www.schneier.com/?p=68655 It’s pretty devastating:

Today, Ian Carroll, Lennert Wouters, and a team of other security researchers are revealing a hotel keycard hacking technique they call Unsaflok. The technique is a collection of security vulnerabilities that would allow a hacker to almost instantly open several models of Saflok-brand RFID-based keycard locks sold by the Swiss lock maker Dormakaba. The Saflok systems are installed on 3 million doors worldwide, inside 13,000 properties in 131 countries. By exploiting weaknesses in both Dormakaba’s encryption and the underlying RFID system Dormakaba uses, known as MIFARE Classic, Carroll and Wouters have demonstrated just how easily they can open a Saflok keycard lock. Their technique starts with obtaining any keycard from a target hotel—say, by booking a room there or grabbing a keycard out of a box of used ones—then reading a certain code from that card with a $300 RFID read-write device, and finally writing two keycards of their own. When they merely tap those two cards on a lock, the first rewrites a certain piece of the lock’s data, and the second opens it...

The post Security Vulnerability in Saflok’s RFID-Based Keycard Locks appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2024/03/security-vulnerability-in-safloks-rfid-based-keycard-locks/feed/ 0 2013133
Unsafelok Threat Highlights It’s About Both IoT Devices and Applications https://securityboulevard.com/2024/03/unsafelok-threat-highlights-its-about-both-iot-devices-and-applications/ https://securityboulevard.com/2024/03/unsafelok-threat-highlights-its-about-both-iot-devices-and-applications/#respond Sat, 23 Mar 2024 01:06:22 +0000 https://www.viakoo.com/?p=12831 IoT devices and applications exist all over the place, and in high volume.  Today’s news brought yet another example of how the scale of IoT systems leads to the conclusion that their security is deeply dependent on automation.  Security researchers announced a hotel keycard hacking technique called “Unsafelok” which enables over 3 million doors worldwide […]

The post Unsafelok Threat Highlights It’s About Both IoT Devices and Applications appeared first on Viakoo, Inc.

The post Unsafelok Threat Highlights It’s About Both IoT Devices and Applications appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2024/03/unsafelok-threat-highlights-its-about-both-iot-devices-and-applications/feed/ 0 2012800
EPA and White House Raise Alarm on Water Cybersecurity https://securityboulevard.com/2024/03/water-cybersecurity-richixbw/ Wed, 20 Mar 2024 16:22:50 +0000 https://securityboulevard.com/?p=2012433 Public washroom faucets

Iran and China fingered: Biden admin. chides governors: Water infra. lacks “even basic cybersecurity precautions.”

The post EPA and White House Raise Alarm on Water Cybersecurity appeared first on Security Boulevard.

]]>
2012433
Drones and the US Air Force https://securityboulevard.com/2024/03/drones-and-the-us-air-force/ https://securityboulevard.com/2024/03/drones-and-the-us-air-force/#respond Mon, 18 Mar 2024 11:03:14 +0000 https://www.schneier.com/?p=68618 Fascinating analysis of the use of drones on a modern battlefield—that is, Ukraine—and the inability of the US Air Force to react to this change.

The F-35A certainly remains an important platform for high-intensity conventional warfare. But the Air Force is planning to buy 1,763 of the aircraft, which will remain in service through the year 2070. These jets, which are wholly unsuited for countering proliferated low-cost enemy drones in the air littoral, present enormous opportunity costs for the service as a whole. In a set of comments posted on LinkedIn...

The post Drones and the US Air Force appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2024/03/drones-and-the-us-air-force/feed/ 0 2012211
Google Splashes the Cash in Bug Bounty Bonanza: $59 Million to Date https://securityboulevard.com/2024/03/google-bug-bounty-vrp-richixbw/ Wed, 13 Mar 2024 16:57:09 +0000 https://securityboulevard.com/?p=2011800 Two stacks of money on top of a white table.

Wanna be a VRP VIP? Last year, $GOOG paid $10 million to ethical hackers for finding vulnerabilities.

The post Google Splashes the Cash in Bug Bounty Bonanza: $59 Million to Date appeared first on Security Boulevard.

]]>
2011800
Irony of Ironies: CISA Hacked — ‘by China’ https://securityboulevard.com/2024/03/cisa-ivanti-china-richixbw/ Mon, 11 Mar 2024 17:17:53 +0000 https://securityboulevard.com/?p=2011528 Director of the Cybersecurity and Infrastructure Security Agency, Jen Easterly

Free rides and traffic jams: U.S. Cybersecurity and Infrastructure Security Agency penetrated in February, via vuln in Ivanti.

The post Irony of Ironies: CISA Hacked — ‘by China’ appeared first on Security Boulevard.

]]>
2011528
Emerging Trends in Embedded Linux IoT Security https://securityboulevard.com/2024/03/emerging-trends-in-embedded-linux-iot-security/ https://securityboulevard.com/2024/03/emerging-trends-in-embedded-linux-iot-security/#respond Fri, 08 Mar 2024 08:00:09 +0000 https://tuxcare.com/?p=16359 Mitigating potential vulnerabilities requires proactive measures due to the complexity of embedded Linux IoT devices The use of containerization and virtualization reduces the attack surface and minimizes the impact of security breaches KernelCare IoT automates security patching for Linux-based IoT devices without taking them out of production to restart them Embedded Linux systems play a […]

The post Emerging Trends in Embedded Linux IoT Security appeared first on TuxCare.

The post Emerging Trends in Embedded Linux IoT Security appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2024/03/emerging-trends-in-embedded-linux-iot-security/feed/ 0 2011405
Cloudflare Unveils a Firewall Designed to Keep LLMs Safe https://securityboulevard.com/2024/03/cloudflare-unveils-a-firewall-designed-to-keep-llms-safe/ Tue, 05 Mar 2024 16:59:48 +0000 https://securityboulevard.com/?p=2010990 LLM firewall AI

Cloudflare wants to help organizations wall off their large-language models (LLMs) from cyberthreats and give enterprises an AI framework to ward off risks, many of which are themselves based on the emerging technology. The cloud connectivity and cybersecurity company this week introduced the Firewall for AI, another layer of protection for LLMs that are foundational..

The post Cloudflare Unveils a Firewall Designed to Keep LLMs Safe appeared first on Security Boulevard.

]]>
2010990
CISA Warns Phobos Ransomware Groups Attacking Critical Infrastructure https://securityboulevard.com/2024/03/cisa-warns-phobos-ransomware-groups-attacking-critical-infrastructure/ Mon, 04 Mar 2024 17:03:23 +0000 https://securityboulevard.com/?p=2010860 Phobos ransomware CISA

Phobos, a complex ransomware-as-a-service (RaaS) operation that has been around for five years and is includes multiple variants, continues to target a range of critical infrastructure in the United States, including education, healthcare, and emergency services, according to federal agencies. The FBI and Cybersecurity and Infrastructure Security Agency (CISA) issued a warning with a list..

The post CISA Warns Phobos Ransomware Groups Attacking Critical Infrastructure appeared first on Security Boulevard.

]]>
2010860
Cheap Video Doorbell Cams: Tools of Stalkers and Thieves https://securityboulevard.com/2024/03/video-doorbell-eken-richixbw/ Fri, 01 Mar 2024 16:43:56 +0000 https://securityboulevard.com/?p=2010690 An extreme closeup of a human eye

EKEN IoT FAIL: Amazon, Sears and Shein still sell security swerving stuff.

The post Cheap Video Doorbell Cams: Tools of Stalkers and Thieves appeared first on Security Boulevard.

]]>
2010690