Industrial Robots IoT Cybersecurity Nightmare

Industrial Robots IoT Cybersecurity Nightmare

Nearly 50 vulnerabilities have been found in industrial collaborative robots which can be configured enable the robots to spy on their surroundings or cause physical harm to workers

Nearly 50 vulnerabilities have been found in industrial collaborative robots ­– machines that work side-by-side with humans in manufacturing settings – which can be configured enable the robots to spy on their surroundings or possibly cause physical harm to workers.

The researchers at IOActive who discovered the vulnerabilities, Cesar Cerrudo and Lucas Apal, said the collaborative robots, or “cobots,” can be remotely tampered with to alter safety configurations that, for example, prevent them from operating outside a designated safety boundary.

Cobots can learn movements, “see” through built-in cameras and “hear” through microphones, which the researchers said can all be accessed, opening up possibilities for commercial espionage.

“These new collaborative robots are smarter and can do a lot of different things. There, the threat is different,” Cerrudo said. “Once they are hacked, they have a lot of people around them; you’re talking about really powerful robots that can lift a lot of weight. It’s very possible they can end up seriously hurting a person.”

In their initial research published in February, titled “Hacking Robots Before Skynet,” Cerrudo and Apa studied publicly available firmware and software to learn how these machines work, learning their ecosystem, how they connect to local networks, including other robots, as well as to their respective vendors, including to cloud-based update systems.

IOActive published a paper this week building on the initial cobot research, further explaining technical details on the vulnerabilities and proof-of-concept exploits. They also included demonstrations and called out Universal Robots for failing to patch their machines’ major problems, including authentication, memory corruption and insecure communication vulnerabilities, since the company was privately contacted by the researchers in January.

“Right now, [cobots] are very insecure. If we don’t do anything about it and improve the security, then it will be a complete mess,” Cerrudo said. “They can end up doing really nasty things. The same problems you are seeing right now with IoT that are causing losses and being hacked every day will be 10 times worse with robots. They can move around, grab things, damage property, have camera, microphones, so the threat is a lot bigger.”

Featured

  • Cloud Security Alliance Brings AI-Assisted Auditing to Cloud Computing

    The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today introduced an innovative addition to its suite of Security, Trust, Assurance and Risk (STAR) Registry assessments with the launch of Valid-AI-ted, an AI-powered, automated validation system. The new tool provides an automated quality check of assurance information of STAR Level 1 self-assessments using state-of-the-art LLM technology. Read Now

  • Report: Nearly 1 in 5 Healthcare Leaders Say Cyberattacks Have Impacted Patient Care

    Omega Systems, a provider of managed IT and security services, today released new research that reveals the growing impact of cybersecurity challenges on leading healthcare organizations and patient safety. According to the 2025 Healthcare IT Landscape Report, 19% of healthcare leaders say a cyberattack has already disrupted patient care, and more than half (52%) believe a fatal cyber-related incident is inevitable within the next five years. Read Now

  • AI Is Now the Leading Cybersecurity Concern for Security, IT Leaders

    Arctic Wolf recently published findings from its State of Cybersecurity: 2025 Trends Report, offering insights from a global survey of more than 1,200 senior IT and cybersecurity decision-makers across 15 countries. Conducted by Sapio Research, the report captures the realities, risks, and readiness strategies shaping the modern security landscape. Read Now

  • Analysis of AI Tools Shows 85 Percent Have Been Breached

    AI tools are becoming essential to modern work, but their fast, unmonitored adoption is creating a new kind of security risk. Recent surveys reveal a clear trend – employees are rapidly adopting consumer-facing AI tools without employer approval, IT oversight, or any clear security policies. According to Cybernews Business Digital Index, nearly 90% of analyzed AI tools have been exposed to data breaches, putting businesses at severe risk. Read Now

  • Software Vulnerabilities Surged 61 Percent in 2024, According to New Report

    Action1, a provider of autonomous endpoint management (AEM) solutions, today released its 2025 Software Vulnerability Ratings Report, revealing a 61% year-over-year surge in discovered software vulnerabilities and a 96% spike in exploited vulnerabilities throughout 2024, amid an increasingly aggressive threat landscape. Read Now

New Products

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities