Was that device designed to be on the internet at all?

Have you ever stopped to think about what lies beneath the sleek facade of modern buildings? Many of them harbor outdated systems just waiting to be exploited by cybercriminals.

Ever heard of “A City of a Thousand Zero Days”? It’s the title of a talk at Black Hat Europe 2025 that sheds light on the vulnerabilities lurking in building management systems. The speaker, Gjoko Krstic, uncovered over 1,000 buildings worldwide using a vulnerable BMS running on outdated software accessible via public IP addresses.

Gjoko’s findings revealed a concerning trend of neglecting security aspects during software mergers and acquisitions, leaving systems open to exploitation. The importance of conducting thorough code audits post-vulnerability disclosure cannot be overstated to address root causes effectively.

Similarly, the white paper accompanying the talk emphasizes the need for heightened security measures in critical infrastructure systems, echoing concerns raised in previous research on malware targeting Industrial Control Systems.

One key takeaway is the importance of securing public-facing systems like BMS behind VPNs to mitigate risks posed by malicious actors. Without adequate protection, critical building services could be compromised, leading to severe operational disruptions.

Ensuring Security Beyond Surface Level

While software vulnerabilities are a pressing issue, the broader challenge lies in securing systems effectively. Publicly accessible services like RDP servers without proper authentication mechanisms are ticking time bombs waiting to be exploited.

It’s crucial for companies to treat building services security with the same rigor as their cybersecurity protocols, implementing regular patches and audits to fortify defenses. Neglecting this aspect could leave organizations vulnerable to cyber threats with potentially disastrous consequences.

By proactively implementing additional security layers like VPNs, organizations can significantly reduce the risk of unauthorized access and data breaches, safeguarding their operations from potential cyberattacks.

Leave a Reply

Your email address will not be published. Required fields are marked *