Black Hat Europe 2025: Vulnerabilities in Internet-Exposed Building Management Systems
At Black Hat Europe 2025, security researcher Gjoko Krstic from Zero Science Lab presented findings on critical vulnerabilities in building management systems (BMS). The presentation, titled 'Project Brainfog,' revealed that over 1,000 buildings globally utilize a specific vendor's BMS software hosted on public-facing IP addresses. These systems contain numerous security flaws, some stemming from an 18-year-old firmware codebase neglected during multiple corporate acquisitions. Although coordinated disclosure efforts have led to patches, the root causes often remain unaddressed, leaving systems exposed. The analysis highlights a fundamental design flaw: these industrial control systems were never intended for direct internet connectivity, yet they lack essential protective layers like Virtual Private Networks (VPNs). This exposure poses significant risks, including potential manipulation of heating systems or fire controls, which could disrupt operations or compromise physical security. The article emphasizes the need for comprehensive code audits and robust security measures, urging companies to treat building infrastructure security with the same rigor as corporate IT systems to prevent malicious exploitation.
Wire timeline
Black Hat Europe 2025: Vulnerabilities in Internet-Exposed Building Management Systems
At Black Hat Europe 2025, security researcher Gjoko Krstic from Zero Science Lab presented findings on critical vulnerabilities in building management systems (BMS). The presentation, titled 'Project Brainfog,' revealed that over 1,000 buildings globally utilize a specific vendor's BMS software hosted on public-facing IP addresses. These systems contain numerous security flaws, some stemming from an 18-year-old firmware codebase neglected during multiple corporate acquisitions. Although coordinated disclosure efforts have led to patches, the root causes often remain unaddressed, leaving systems exposed. The analysis highlights a fundamental design flaw: these industrial control systems were never intended for direct internet connectivity, yet they lack essential protective layers like Virtual Private Networks (VPNs). This exposure poses significant risks, including potential manipulation of heating systems or fire controls, which could disrupt operations or compromise physical security. The article emphasizes the need for comprehensive code audits and robust security measures, urging companies to treat building infrastructure security with the same rigor as corporate IT systems to prevent malicious exploitation.
WeLiveSecurity