惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
月光博客
月光博客
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
阮一峰的网络日志
阮一峰的网络日志
博客园_首页
Last Week in AI
Last Week in AI
The Cloudflare Blog
IT之家
IT之家
Hugging Face - Blog
Hugging Face - Blog
美团技术团队
S
SegmentFault 最新的问题
量子位
大猫的无限游戏
大猫的无限游戏
Recent Announcements
Recent Announcements
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Microsoft Security Blog
Microsoft Security Blog
云风的 BLOG
云风的 BLOG
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
I
InfoQ
人人都是产品经理
人人都是产品经理
G
Google Developers Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Engineering at Meta
Engineering at Meta

WeLiveSecurity

Supply chain dependencies: Have you checked your blind spot? Recovery scammers hit you when you’re down: Here’s how to avoid a ‘second strike’ As breakout time accelerates, prevention-first cybersecurity takes center stage Digital assets after death: Managing risks to your loved one’s digital estate This month in security with Tony Anscombe – March 2026 edition RSAC 2026 wrap-up – Week in security with Tony Anscombe A cunning predator: How Silver Fox preys on Japanese firms this tax season Virtual machines, virtually everywhere – but not all protected Cloud workload security: Mind the gaps Move fast and save things: A quick guide to recovering a hacked account EDR killers explained: Beyond the drivers Face value: What it takes to fool facial recognition Cyber fallout from the Iran war: What to have on your radar Sednit reloaded: Back in the trenches What cybersecurity actually does for your business How SMBs use threat research and MDR to build a defensive edge Protecting education: How MDR can tip the balance in favor of schools This month in security with Tony Anscombe – February 2026 edition Mobile app permissions (still) matter more than you may think Faking it on the phone: How to tell if a voice call is AI or not PromptSpy ushers in the era of Android threats using GenAI Is Poshmark safe? How to buy and sell without getting scammed Is it OK to let your children post selfies online? Naming and shaming: How ransomware groups tighten the screws on victims Taxing times: Top IRS scams to look out for in 2026 OfferUp scammers are out in force: Here’s what you should know A slippery slope: Beware of Winter Olympics scams and other cyberthreats This month in security with Tony Anscombe – January 2026 edition DynoWiper update: Technical analysis and attribution Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan
Black Hat Europe 2025: Was that device designed to be on ...
Tony Anscombe · 2025-12-12 · via WeLiveSecurity

Business Security

Behind the polished exterior of many modern buildings sit outdated systems with vulnerabilities waiting to be found

12 Dec 2025  •  , 3 min. read

Black Hat Europe 2025: Was that device designed to be on the internet at all?

A City of a Thousand Zero Days” is the partial title of a talk at Black Hat Europe 2025. I am sure you will appreciate why these few words sparked my interest enough to dedicate time to the presentation; especially given that back in 2019 I delivered a talk on the evolving risk of smart buildings at Segurinfo in Argentina.

The talk at Black Hat, delivered by Gjoko Krstic of Zero Science Lab, focused on one vendor of building management systems and how the evolution of one of their products through various acquisitions caused it to end up being an incredibly vulnerable piece of software. In summary, the talk highlighted that there are over 1,000 buildings around the world that use the vendor’s building management system (BMS) running on a software platform with a long list of vulnerabilities. Compounding the issue, the software is hosted on public-facing IP addresses; thus, it’s accessible from the internet.

In one example, Gjoko explained the root cause of one vulnerability dates back to an 18-year-old firmware codebase. Through several company acquisitions and a lack of audit and due diligence during the merger and acquisition process on the security aspects of the software, vulnerabilities appear to have been largely ignored until recently.

Coordinated disclosure has prompted numerous fixes, but the process has resulted in fixing one problem while leaving the root cause intact, thus exposing further vulnerabilities later. The message here is clear: don’t just use a sticking plaster while ignoring the underlying cause. It’s essential that companies conduct full code audits after a vulnerability notification and release a patch to ensure the root cause is identified and resolved.

While the white paper that accompanies the talk offers several messages for software developers of critical infrastructure systems, there is one that I feel needs to pushed to the front. Back in 2017, my colleagues at ESET published details of one of the first known malware to target Industrial Control Systems (ICS) and the very first one to specifically target power grids. One comment I distinctly remember from the research is that the protocol used by the ICS device concerned was never designed to be connected to the internet.

The talk by Gjoko raised a similar concern: the building management system was not designed to be public facing on the internet, and the vendor recommends to secure it behind a virtual private network (VPN).

Asking for trouble

While vulnerabilities in software are, of course, an issue and I commend the detailed research, there is a wider issue: some systems available on public IP addresses should really be protected through additional security layers, such as a VPN.

Building management systems are one example of this. The issue here may stem from building ownership as opposed to tenant control: the landlord may not have the knowledge, resources or risk-averse approach to security that the tenant has; at the same time, the tenant may not realize the significant risk to their business being caused by a lack of security relating to the building services.

The potential risk is significant. For example, a malicious actor who can control and adjust the heat in a server room could cause operational disruption or, by using the fire controls to release all doors, they could let unauthorized people into the building (this sounds a bit Mission: Impossible, but is very plausible). All companies need to ensure the services that form the fabric of their buildings are secured to the same level as their own corporate systems, are patched regularly and audited on a similar cadence to their cybersecurity audits.

There are other types of systems that remain publicly accessible despite overwhelming reasons for them to be behind another security layer. An example is remote desktop protocol (RDP) servers, some without multi-factor-authentication, are still accessible on public IP addresses.

As a principle, if bypassing or compromising a login screen results in direct access to an application or corporate network, then there should be enhanced security using a VPN or similar technology. At some stage, a cybercriminal will find a vulnerability, socially engineer login credentials or brute force access to the system. It’s just a matter of time and is something that is easily avoidable.


Let us keep you
up to date

Sign up for our newsletters