Industrial Robots IoT Cybersecurity Nightmare

Industrial Robots IoT Cybersecurity Nightmare

Nearly 50 vulnerabilities have been found in industrial collaborative robots which can be configured enable the robots to spy on their surroundings or cause physical harm to workers

Nearly 50 vulnerabilities have been found in industrial collaborative robots ­– machines that work side-by-side with humans in manufacturing settings – which can be configured enable the robots to spy on their surroundings or possibly cause physical harm to workers.

The researchers at IOActive who discovered the vulnerabilities, Cesar Cerrudo and Lucas Apal, said the collaborative robots, or “cobots,” can be remotely tampered with to alter safety configurations that, for example, prevent them from operating outside a designated safety boundary.

Cobots can learn movements, “see” through built-in cameras and “hear” through microphones, which the researchers said can all be accessed, opening up possibilities for commercial espionage.

“These new collaborative robots are smarter and can do a lot of different things. There, the threat is different,” Cerrudo said. “Once they are hacked, they have a lot of people around them; you’re talking about really powerful robots that can lift a lot of weight. It’s very possible they can end up seriously hurting a person.”

In their initial research published in February, titled “Hacking Robots Before Skynet,” Cerrudo and Apa studied publicly available firmware and software to learn how these machines work, learning their ecosystem, how they connect to local networks, including other robots, as well as to their respective vendors, including to cloud-based update systems.

IOActive published a paper this week building on the initial cobot research, further explaining technical details on the vulnerabilities and proof-of-concept exploits. They also included demonstrations and called out Universal Robots for failing to patch their machines’ major problems, including authentication, memory corruption and insecure communication vulnerabilities, since the company was privately contacted by the researchers in January.

“Right now, [cobots] are very insecure. If we don’t do anything about it and improve the security, then it will be a complete mess,” Cerrudo said. “They can end up doing really nasty things. The same problems you are seeing right now with IoT that are causing losses and being hacked every day will be 10 times worse with robots. They can move around, grab things, damage property, have camera, microphones, so the threat is a lot bigger.”

Featured

  • Achieving Clear Audio

    In today’s ever-changing world of security and risk management, effective communication via an intercom and door entry communication system is a critical communication tool to keep a facility’s staff, visitors and vendors safe. Read Now

  • Beyond Apps: Access Control for Today’s Residents

    The modern resident lives in an app-saturated world. From banking to grocery delivery, fitness tracking to ridesharing, nearly every service demands another download. But when it comes to accessing the place you live, most people do not want to clutter their phone with yet another app, especially if its only purpose is to open a door. Read Now

  • Survey: 48 Percent of Worshippers Feel Less Safe Attending In-Person Services

    Almost half (48%) of those who attend religious services say they feel less safe attending in-person due to rising acts of violence at places of worship. In fact, 39% report these safety concerns have led them to change how often they attend in-person services, according to new research from Verkada conducted online by The Harris Poll among 1,123 U.S. adults who attend a religious service or event at least once a month. Read Now

  • AI Used as Part of Sophisticated Espionage Campaign

    A cybersecurity inflection point has been reached in which AI models has become genuinely useful in cybersecurity operation. But to no surprise, they can used for both good works and ill will. Systemic evaluations show cyber capabilities double in six months, and they have been tracking real-world cyberattacks showing how malicious actors were using AI capabilities. These capabilities were predicted and are expected to evolve, but what stood out for researchers was how quickly they have done so, at scale. Read Now

  • Why the Future of Video Security Is Happening Outside the Cloud

    For years, the cloud has captivated the physical security industry. And for good reasons. Remote access, elastic scalability and simplified maintenance reshaped how we think about deploying and managing systems. Read Now

New Products

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities