CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Critical vulnerabilities in building automation systems affect global infrastructure

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Over 800 vulnerabilities, many zero-day, were found in building automation systems used in 30 countries and 220 cities. These systems, originally developed by American Auto-Matrix in 2008, were acquired by Cylon Controls and later by ABB. The vulnerabilities allow remote takeover of critical infrastructure, including hospitals, airports, and government buildings. The vulnerabilities stem from an 18-year-old codebase that has not undergone security reviews. The affected systems were embedded in facilities operated by major companies, including technology campuses, correctional institutions, and entertainment venues. The vendor, ABB, has made efforts to fix some issues but has not been transparent about the patches and has inconsistently scored the severity of the vulnerabilities.

Timeline

  1. 30.10.2025 23:37 1 articles · 11d ago

    Over 800 vulnerabilities discovered in building automation systems

    Security researcher Gjoko Krstic discovered over 800 vulnerabilities, many zero-day, in building automation systems used in 30 countries and 220 cities. The vulnerabilities stem from an 18-year-old codebase that has not undergone security reviews. The affected systems were embedded in facilities operated by major companies, including technology campuses, correctional institutions, and entertainment venues. The vendor, ABB, has made efforts to fix some issues but has not been transparent about the patches and has inconsistently scored the severity of the vulnerabilities.

    Show sources

Information Snippets