Connect with us

Infosecurity

Fixing the Internet of Broken Things: An Open, Hardware-Led Approach

Published

on

Fixing the Internet of Broken Things: An Open, Hardware-Led Approach

Our world is now woven with connected devices. They monitor our health, fly our planes, and drive our cars. Yet, beneath this convenience lies a critical flaw: the security of the Internet of Things is broken. This isn’t a theoretical risk. Vulnerabilities discovered by researchers aren’t just about stolen data; they have the potential for catastrophic, real-world harm.

The Failure of Security-by-Obscurity

For too long, many IoT manufacturers have operated on a dangerous assumption. They believe that hiding their code—security-by-obscurity—is enough. It’s a strategy that has repeatedly failed in the software world. Look at the legacy of proprietary systems like Windows, Java, or Flash. They became prime targets precisely because their closed nature didn’t guarantee safety; it often hid flaws from everyone but the attackers.

The tools available to reverse engineer device firmware are incredibly sophisticated. Malicious actors can extract code directly from hardware or find it in online updates. The idea that obscurity provides protection is a myth that needs to be retired. What’s the alternative? We must embrace openness.

Building on Open Source and Open Standards

Open source software offers a fundamentally different security model. Instead of a handful of developers scrutinizing code, you have thousands of expert eyes worldwide. Flaws are found and fixed with astonishing speed, often within hours. The community’s focus is on quality and utility, not corporate politics or commercial feature sets.

This transparency also addresses another shadowy concern: nation-state interference. History is littered with reports of governments pressuring companies to build secret backdoors into proprietary products. Such concerns rarely, if ever, touch the open-source community at large, where the code is open for all to inspect.

Open standards are equally crucial, especially for networking. Implementing complex protocols like TCP/IP is difficult. When a device engineer, unfamiliar with networking, is tasked with adding connectivity, mistakes are inevitable. Global, interoperable open standards encapsulate this complexity. They allow hardware developers to rely on robust, expert-maintained frameworks, outsourcing the trickiest security work to those who know it best.

Containing Risk with Hardware-Assisted Separation

Many embedded systems are designed as a single, monolithic environment. If a hacker breaches one component—say, the infotainment system in a car—they can often ‘move laterally’ to more critical systems like steering or brakes. This design flaw is a gift to attackers.

The solution is security by separation, enforced by hardware. Using hardware-assisted virtualization, a secure hypervisor can create isolated containers for each software function. The radio runs in one virtual box; the engine management system runs in another. From a risk perspective, assuming any software can be compromised is prudent. This architecture ensures that a breach in one container is contained, preventing it from becoming a stepping stone to the entire system.

Of course, systems need to communicate. The volume might need to increase as the car accelerates. This is managed through strictly controlled, secure channels between containers. This model isn’t just for safety; it’s essential for business. A smart TV without this separation could allow a rogue app to steal a protected video stream from Netflix, causing significant financial damage.

The Practical Path Forward

The ideal of a hardware-rooted, open security framework is the destination. Reaching it requires a journey. Not all chips today support advanced virtualization. However, progress can start now.

Manufacturers can begin with intermediate steps like Linux containers to isolate applications. Even without a dedicated ‘root of trust’ chip, firms can and must encrypt and cryptographically sign their firmware. They must commit to providing timely security patches. Waiting for perfect hardware is not an option when the vulnerabilities are present today.

The stakes couldn’t be higher. We built an internet of things without a foundation of security. To fix it, we must collectively move away from secrecy and toward openness, and away from monolithic designs and toward hardware-enforced separation. The journey is necessary, and it starts with a decision to change our approach.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

China and India ran separate spying campaigns against the same Pakistani police force

Published

on

Pakistani police spying

Two rivals, one target: Balochistan Police

For more than two years, hacking groups tied to China and India ran separate, unconnected espionage operations against the same Pakistani police force. Sometimes they even broke into the exact same systems.

That’s the finding from cybersecurity firm SentinelOne, which published research Thursday detailing the parallel campaigns. The activity ran between February 2024 and April 2026, according to the company’s SentinelLabs research arm.

The target: the Balochistan Police, the force responsible for Pakistan’s southwestern province. That region has been the site of a long-running separatist insurgency, making its police networks a rich prize for intelligence agencies.

Why police networks are such a tempting target

Police networks concentrate a government’s internal-security data in one place. That’s the core insight from SentinelLabs. The compromised systems held criminal records, biometric and fingerprint data, personnel files, hotel and tenant registrations linked to national identity records, and citizen complaints.

Think about what that means. Anyone with access to those systems could identify police officers, track their movements, and potentially compromise them. They could also monitor the local population in a province already simmering with unrest.

The China connection: protecting CPEC interests

The researchers assess that the China-nexus interest was driven primarily by protecting Beijing’s nationals in Pakistan tied to the China-Pakistan Economic Corridor. That’s the massive infrastructure project that’s a cornerstone of Chinese influence in the region.

The report cites a March 2024 suicide bombing and an October 2024 attack near Karachi’s airport as incidents affecting Chinese workers. Those attacks highlighted the security risks facing Chinese nationals in Pakistan.

According to SentinelLabs, the intrusions reflect an effort to assess the threat independently rather than rely on Pakistani security guarantees. In other words, Beijing wanted its own picture of the danger, not just Islamabad’s assurances.

The India angle: rivalry and insurgency

The India-linked activity was likely tied to the rivalry between the two countries, the report assessed. That’s a fraught relationship, to say the least.

Islamabad accuses New Delhi of backing the Baloch insurgency and describes the Balochistan Liberation Army as an “Indian proxy.” India makes parallel accusations over Kashmir. Both governments deny the other’s claims.

SentinelLabs said access to Balochistan Police data would provide visibility into that conflict. For India, that could mean insight into insurgent activities and Pakistan’s counterinsurgency efforts.

How the hacks worked

The report describes the compromise of the Balochistan Police Complaint Management System, a portal used by officers behind a login and by citizens checking the status of complaints.

Here’s where it gets clever. A China-linked operator planted malware disguised as a portal update. The executable displayed a fake “update complete” message while infecting the visitor’s device.

Because both police and members of the public use the site, the tampered portal exposed both groups. That’s a wide net, catching everyone from officers to ordinary citizens filing complaints.

The researchers said forensic traces in the code, including Chinese-language log strings and developer artifacts, indicated a Chinese-speaking author. That’s a pretty strong signal.

Attribution: clusters, not names

Rather than name specific groups, SentinelLabs sorted the activity into clusters by toolset. That’s a more cautious approach than some firms take.

Backdoors shared among Chinese groups, including PlugX and ShadowPad, anchored the China-nexus assessments. The victim pattern also spanned Asian governments and, in one case, Tibetan organizations in Taiwan.

The India-nexus intrusions were tied with lower confidence to an actor the researchers track as TAG-179. That overlaps with clusters others call Bitter and Mysterious Elephant. Part of the evidence: a lure document themed around the repatriation of undocumented foreigners.

The bigger picture: Pakistan’s digitization push

The researchers noted that as Pakistan centralizes and digitizes its policing, supported in part by European modernization programs, it will continue to concentrate high-value data that adversaries may target.

That’s a worrying trend. The more data gets digitized and centralized, the bigger the prize for hackers. And with two nuclear-armed rivals both running espionage campaigns, the stakes are enormous.

Both Pakistan and India are alleged to have conducted cyber espionage campaigns against each other, with attacks targeting Indian government, academic and strategic institutions, as well as Pakistani government agencies and critical infrastructure operators. This latest report shows that the espionage isn’t just about governments — it’s about police forces on the front lines of internal security.

For anyone tracking cyber espionage in South Asia, this is a significant development. It shows that even a provincial police force isn’t off-limits when national rivals are involved.

Continue Reading

Infosecurity

ICO Tells Police Forces to Tighten Data Governance as Facial Recognition Rollouts Accelerate

Published

on

data governance in facial recognition

A Watchdog’s Warning

The UK’s data protection regulator has a blunt message for police forces embracing live facial recognition: your paperwork isn’t keeping up with your technology.

In an article published on August 18, Emily Keaney, deputy commissioner for regulatory policy at the Information Commissioner’s Office (ICO), noted that a growing number of forces are deploying the tech with zero prior experience of using it in public. Some are even experimenting with operator-initiated facial recognition — where officers stop someone on the street and instantly cross-check their face against a watchlist.

That’s a powerful tool, but it’s also a risky one. As Keaney put it: “A false match can have serious consequences for people, including wrongful intervention, accusation or arrest.”

What the Audits Found

To gauge how forces are handling these risks, the ICO audited five police forces across England and Wales. The results, published this week, paint an uneven picture.

“Our audits reveal inconsistencies in data protection compliance across the five forces audited,” Keaney said. “While there was some good practice, significant improvements are still needed.”

Compliance rates were actually higher for live facial recognition (LFR) than for retrospective facial recognition (RFR), which involves scanning stored images after the fact. But in both cases, the ICO flagged several recurring gaps:

  • Insufficient senior oversight, accountability, and training for staff using the technology
  • Poor record-keeping about what personal data is used, where it comes from, and who it’s shared with
  • RFR images sometimes sourced from questionable places and kept longer than necessary
  • Inadequate checks on system accuracy and bias

The last point stings, given a Home Office report on police facial recognition bias published in December 2025. That report found that, in certain situations, the algorithm was more likely to incorrectly include some demographic groups in its search results. Keaney said at the time that the ICO required “urgent clarity on this matter.”

Why Governance Matters

You might wonder: why is the ICO so focused on administrative details like record-keeping? Because, as the regulator argues, public trust is the foundation for any sustainable use of facial recognition in policing. If people believe the system is sloppy or biased, they won’t accept it — no matter how effective it is at catching criminals.

There’s also a legal dimension. The EU AI Act largely prohibits police use of live facial recognition in public spaces, and while the UK has its own path, the ICO’s guidance signals that British regulators expect similar caution.

Next Steps for Police

The ICO says forces have been “willing to engage and make changes” based on the audit findings. That’s encouraging, but the regulator is clear that more work is needed before LFR becomes a standard policing tool.

For forces looking to get ahead of the curve, the ICO’s recommendations boil down to a few practical actions:

  1. Appoint a senior officer responsible for FRT oversight and ensure all staff are properly trained
  2. Maintain clear, auditable records of every use of the technology
  3. Source RFR images only from approved channels and delete them promptly
  4. Regularly test systems for accuracy and bias, and document the results

These aren’t glamorous tasks, but they’re the difference between a tool that protects the public and one that undermines civil liberties. As the ICO’s Keaney put it, strong data protection governance is essential to fostering the trust that facial recognition needs to flourish as a policing tool.

For more context on how these issues are playing out elsewhere, read about the landmark court ruling on police facial recognition and the Home Office’s findings on racial bias in RFR systems.

Continue Reading

Infosecurity

Medusa Ransomware Breaches 500+ Critical Infrastructure Organizations, FBI Warns

Published

on

Medusa ransomware

Medusa Ransomware Expands Its Reach

The FBI, CISA, and the Department of Health and Human Services have issued a joint advisory revealing that Medusa ransomware has now impacted over 500 critical infrastructure organizations as of April 2026. That’s a significant jump from the 300 organizations reported in a March 2025 advisory, which covered activity through February 2025.

The updated warning, published August 18, singles out healthcare as a particularly frequent target. The advisory notes that Medusa actors have been opportunistic, going after victims with unpatched software rather than focusing on specific sectors. But the numbers suggest healthcare has borne the brunt.

Medusa first appeared in June 2021 as a closed operation, then shifted to an affiliate model by early 2023. Since then, it’s evolved into one of the more active ransomware-as-a-service (RaaS) groups around.

Exploiting Vulnerabilities at Breakneck Speed

Unpatched vulnerabilities remain Medusa’s primary entry point. What’s changed is the speed. The advisory says the group has been observed using exploits within 24 hours of public disclosure — often before victims even have a chance to patch.

In some cases, Medusa actors have leveraged exploits up to a week before the vulnerability is publicly announced. That’s a troubling timeline for defenders.

There’s no evidence Medusa develops its own zero-days. Instead, they’re fast followers, weaponizing known flaws quickly and moving on.

Nick Tausek, lead security automation architect at Swimlane, says this speed is creating real problems for security teams. “Shrinking windows put far more pressure on defenders to identify and remediate exposed systems before Medusa can take advantage. Dangerous levels of speed can turn a newly disclosed flaw into an active intrusion before many security teams have even finished assessing their exposure,” he commented.

Interactsh and Verification Tactics

The group has also adopted Interactsh dynamic URLs to verify successful exploitation. This lets them identify compromised hosts and confirm their foothold before moving deeper.

Stealthier Post-Exploitation and Lateral Movement

Medusa’s post-exploitation game has improved significantly. The advisory describes multiple PowerShell stealth techniques of increasing complexity, used to obfuscate payloads. They even delete PowerShell command history to cover their tracks.

New tools are in play for command and control (C2) and stealth. Publicly available tools like Nezha, an operations and maintenance server monitoring tool, give them backdoor visibility into compromised hosts. GSocket allows workstations on different private networks to connect and bypass firewalls.

The group also deploys legitimate remote monitoring and management (RMM) software, often selecting tools already present in the victim’s environment to avoid detection. These are used to move laterally and identify files for exfiltration.

Credential theft has gotten more aggressive. The advisory notes the use of Windows Task Manager Mimikatz to harvest credentials directly from the LSA authentication mechanism, recording plaintext passwords to a log file.

Andrew Costis, engineering manager at AttackIQ, highlighted the implications. “The group is blending legitimate remote management tools into its operations while using new credential theft methods and overriding security policies to maintain access,” he said.

“Stolen Active Directory files are especially concerning because they can be used to forge Kerberos tickets. At that point, Medusa isn’t just encrypting systems. It can potentially impersonate trusted users and move through an entire domain with far fewer obstacles.”

Exfiltration and the Double-Extortion Model

Medusa’s exfiltration playbook is well-established. They use Bandizip to create archives of stolen files and Rclone to move data to their C2 servers, obfuscating rclone.exe and related .conf files by renaming them.

Secure file transfer protocol (SFTP) is used to deliver the encryptor to victim machines. Encrypted files get a .medusa extension. The malware terminates all services, deletes shadow copies, and drops a ransom note.

This enables a double-extortion model: victims pay to restore systems and data, and to prevent stolen data from being published online. The ransom note demands contact within 48 hours. If victims don’t respond, Medusa actors often reach out directly via phone or email.

Ransom demands are posted on Medusa’s leak site, complete with direct hyperlinks to Medusa-affiliated cryptocurrency wallets.

FBI Urges Incident Response Readiness

Beyond prevention, the advisory stresses the need for effective incident response. Security teams should be ready to act when an intrusion occurs, not just before.

Recommended actions include:

  • Use threat hunting to scope the intrusion, including logs left behind by threat actor tooling
  • Remove C2 software like Nezha or any other remote access method used by the organization
  • Remove local administrator accounts and rotate credentials for service accounts and domain administrator accounts
  • Ensure the initial intrusion CVE is patched
  • Use CISA’s Eviction Strategies Tool to assemble countermeasures for a systematic eviction plan

For organizations worried about their exposure, the advisory is a reminder that patch management alone isn’t enough. Speed matters, but so does having a plan for when defenses fail. The FBI’s latest Medusa ransomware advisory offers concrete steps, and security teams should review it closely.

If you’re in healthcare, the stakes are especially high. The sector’s reliance on legacy systems and connected medical devices makes it a prime target. Reviewing healthcare ransomware defense strategies could help close gaps before attackers find them.

And for those tracking broader trends, the rise of ransomware-as-a-service operations shows no signs of slowing. Medusa is just one example of how these groups evolve, adapt, and keep pressure on defenders.

Continue Reading

Trending