Habr•September 16, 2026•🇷🇺Translated from Russian

Vulnerability Management in Atypical Environments: ICS, Networks, IoT, Mobile, Hardware, and ML Systems

Vulnerability management follows the same fundamental cycle everywhere: discover assets, scan for weaknesses, assess severity, agree on remediation timelines, apply fixes or compensating controls, and verify closure. The devil lies in the details when these processes are applied to industrial control systems, network infrastructure, IoT devices, mobile endpoints, hardware, and machine-learning platforms.

ICS environments introduce the highest stakes because exploitation can cause physical harm rather than data loss. A dedicated process owner for SCADA and PLC systems must participate in every decision. Scanning must use authenticated audit mode rather than aggressive black-box techniques, exclude non-redundant systems, and follow narrowly scoped plans limited to specific IP addresses and profiles. Patches can only be applied during planned outages with tested rollback procedures, often after validation on a digital twin. CVSS 4.0 Safety metrics become essential for prioritization.

Network devices commonly suffer from missing or incorrect segmentation, overly permissive firewalls, and default SNMP community strings such as “public” and “private.” Legacy SNMPv1/v2c transmits data in clear text, allowing both reconnaissance and active configuration changes. Additional frequent issues include outdated Wi-Fi protocols, Telnet or HTTP management interfaces, weak passwords, and lack of multi-factor authentication. Recommended controls include strict least-privilege ACLs, VLAN segmentation with inter-VLAN routing only through firewalls, RBAC, and migration to SNMPv3 with encryption.

IoT devices remain a persistent source of large-scale botnets because vendors ship products with default credentials and rarely release firmware updates. The Mirai botnet, built on 61 hardcoded username-password pairs, famously disrupted DNS provider Dyn in 2016, taking down Twitter, Netflix, Reddit, and other major services. Later variants such as Reaper and VPNFilter shifted to known firmware vulnerabilities, infecting hundreds of thousands of routers and NAS devices. Defenses include immediate password changes, network segmentation, disabling unnecessary services such as Telnet and UPnP, and selecting vendors that publish updates. Tools like Shodan make both defensive auditing and attacker reconnaissance trivial.

Machine-learning systems face new attack classes documented in the OWASP Top 10 for LLM Applications. Prompt injection embeds malicious instructions inside legitimate-looking input, causing the model to ignore safety policies or leak secrets. Prompt leaking tricks the model into revealing its hidden system prompt, while jailbreaking bypasses built-in restrictions. Classic injection techniques such as SQL or command injection can also be delivered through prompts. Protections require input validation, output filtering, least-privilege model permissions, and continuous monitoring for anomalous behavior.

Mobile devices introduce fragmentation challenges. Historical examples include Stagefright (2015), Pegasus spyware, BlueBorne (2017), and QuadRooter (2016), all of which affected hundreds of millions of devices yet remained unpatched on many handsets for years. Corporate programs rely on MDM/EMM platforms for policy enforcement, application whitelisting, remote wipe, and centralized update monitoring, supplemented by encryption, VPN, and multi-factor authentication.

Hardware and firmware vulnerabilities demonstrate that risks exist below the operating system. Notable cases include BadUSB, which reprograms USB microcontrollers to emulate keyboards, Thunderstrike UEFI implants, and the Spectre and Meltdown speculative-execution flaws affecting Intel, AMD, and ARM processors. Additional silicon issues such as Rowhammer and Zombieload/MDS further illustrate the need for coordinated microcode, firmware, and software updates.

Related articles

BoletimSec•Vulnerabilities & Exploits

Microsoft Fixes CVE-2026-96940 in Exchange Server Allowing Authenticated Mailbox Access

Microsoft has patched CVE-2026-96940, a CVSS 8.8 vulnerability in Exchange Server that lets any authenticated user read other users' mailboxes without administrative rights. The flaw exposes full message content and attachments including contracts, spreadsheets, and sensitive documents. Affected on-premises versions include Exchange Server Subscription Edition RTM, Exchange 2016 CU23, Exchange 2019 CU15, and Exchange 2019 CU14. Exchange Online users are protected because the fix was applied server-side. Microsoft rates exploitation as likely but reports no confirmed attacks in the wild at disclosure time. The issue turns a single low-privilege credential into broad access to executive, legal, and financial correspondence.

Habr•Vulnerabilities & Exploits

New Spectre-v2 Variant Uses JIT Compiler Branch Target Reuse for Cross-Process Data Extraction

Researchers from the Netherlands and Italy have published a paper detailing a fresh Spectre-v2 attack that reuses branch predictor state instead of injecting new instructions. The technique leverages the JIT compiler cBPF inside the Linux kernel to train the branch target predictor, enabling speculative execution that leaks sensitive data such as hashed root passwords. Practical demonstrations extracted credentials from the su process in an average of three to five minutes on AMD, Intel, and ARM processors. Partial success was shown with SpiderMonkey in Firefox and GraalVM, although realistic end-to-end attacks were not achieved with those engines. The work also covers additional topics including forensic detection of attacks against 1C servers, a record Debian Linux kernel patch set, zero-day fixes in TeamViewer and Apple Core Graphics, and critical flaws in Dell Container Storage Modules.

Security NEXT•Vulnerabilities & Exploits

Critical CVE-2026-21589 Affects Eight Atlassian Products with CVSS 9.3 Score

Atlassian has disclosed a critical vulnerability tracked as CVE-2026-21589 that impacts eight of its products. The flaw allows unauthenticated access to specific files located in the web application's root directory when an attacker already knows the file name and path. Products affected include Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian rates the issue Critical with a CVSSv4.0 base score of 9.3 and warns that Data Center editions face elevated risk due to potential exposure of sensitive files. The company released patches for all affected products and urges immediate updates, while also providing mitigation steps and indicators of compromise for organizations unable to patch right away.

Security NEXT•Vulnerabilities & Exploits

Fortinet Releases FortiMail Updates to Patch Zero-Day CVE-2026-104286

Fortinet has begun distributing updates for its FortiMail email security product to address the zero-day vulnerability CVE-2026-104286. The flaw allows unauthenticated attackers to write arbitrary files to the system by sending specially crafted HTTP requests. The company first published a security advisory on October 1, 2026, confirming active exploitation and providing Indicators of Compromise while preparing fixes. On October 5, 2026, Fortinet updated the advisory and released patched versions including FortiMail 8.0.2, 7.6.7, and 7.4.9. Organizations still running the 7.2 branch are advised to migrate to the 7.4 branch or later to obtain protection. The advisory reference is FG-IR-26-175.