2026-08-09 · view entry permalink →
Critical-infrastructure exposure this week sat in things no IT patch cycle owns — a carrier link, a factory-shipped router backdoor, an unauthenticated aviation protocol — and four national cyber agencies published the isolation method that answers exactly that class
Four separate critical-infrastructure findings landed across 2026-W32 and none of them is fixed by a patch cycle, because in each case the vulnerable component is a device class or a communications link that the IT estate does not own, update, or in some cases even inventory.
CERT Polska supplied the incident evidence. Its follow-up forensic report on the 29 December 2025 attacks on Poland's energy sector traces an intrusion from a compromised wind-farm substation, over SSH through a cellular router, into the distribution system operator's private APN — a mobile network shared by the wind farm and a combined heat and power plant — and from there into a controller whose WAN-side interface answered on factory credentials, ending with three PLCs in STOP mode and a steam turbine offline (CERT Polska incident follow-up report, 2026-08-08). The published summary is explicit about the enabling condition: "the attack was made possible, among other factors, by a misconfiguration that allowed arbitrary devices within the private APN network to communicate with one another" (CERT Polska, 2026-08-08). A private APN is bought as a private network, appears on no external-attack-surface scan, and — as this case shows — can carry an attacker between two unrelated sites that merely share a carrier contract.
Two further disclosures move the vulnerable thing outside the software estate entirely. VulnCheck documented ENDLESSDOORS on 5 August, a pre-installed remote-access implant enabled by default on twenty Zbtlink router and CPE models including rebranded units sold through mainstream e-commerce: a customised build of an open-source remote-control tool, launched at boot by the vendor's own init script, masquerading as a kernel worker thread, which registers outbound to hardcoded hosts and passes whatever the server sends straight to a shell as uid 0 with no authentication of any kind (VulnCheck, 2026-08-05). Because this is a shipped component rather than a memory-corruption defect, VulnCheck's guidance is to replace the affected devices or at minimum place them behind strict egress control and treat their LAN as untrusted — and it did not notify the vendor, on the reasoning that there is no patch to coordinate. CISA's advisory ICSA-26-219-01 covers five vulnerabilities in Controller-Pilot Data Link Communications as implemented over ATN-B1, the worldwide standard for text instructions between air traffic control and the cockpit; all five are properties of the standard rather than one vendor's product, the link being clear-text and unauthenticated, and CISA records remediation as none-available while assessing exploitation unlikely outside a lab setting (CISA, 2026-08-07).
The published answer to this class arrived one week before the window, and had not been carried here. On 28 July, CISA, the Australian Signals Directorate's ACSC as lead author, the UK's NCSC and the Canadian Centre for Cyber Security jointly issued "CI Fortify — Advice for isolating vital systems," which "explains how organisations can isolate critical operational technology (OT) and supporting systems from other networks during cyber incidents or periods of increased cyber threat" (ASD ACSC, 2026-07-28). Two of its provisions read as though drafted against the Polish case. First, on carrier links: "CI operators must treat any carrier-provided service as untrusted and potentially hostile," with the corollary that operators should "not use encryption built into OT devices – always use a dedicated device to implement encryption over untrusted carrier links" (ASD ACSC, 2026-07-28). Second, on coupling: the guidance directs operators to build dedicated OT capability by eliminating cross-dependencies with non-OT systems, naming shared directory, name-resolution, address-assignment, virtualisation, certificate and time-synchronisation services as the usual silent links — the dependencies that decide, during an incident, whether the OT estate can actually be disconnected and keep running. CISA frames the purpose as maintaining "robust isolation and recovery plans so that essential services can continue under degraded conditions" (CISA, 2026-07-28).
This CI Fortify guide helps critical infrastructure organisations improve their cyber resilience. Developed with international partners, the guide explains how organisations can isolate critical operational technology (OT) and supporting systems from other networks during cyber incidents or periods of increased cyber threat.
CI operators must treat any carrier-provided service as untrusted and potentially hostile. Apply robust cyber security controls to protect the interface between the operator and the carrier... Do not use encryption built into OT devices – always use a dedicated device to implement encryption over untrusted carrier links.
The attack was made possible, among other factors, by a misconfiguration that allowed arbitrary devices within the private APN network to communicate with one another.
Builds on: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · 2026-08-06/endlessdoors-zbtlink-router-factory-shipped-root-backdoor · 2026-08-08/cpdlc-atn-b1-five-protocol-flaws-no-mitigation-available · 2026-08-05/thermo-fisher-genetic-analyzer-dna-file-integrity · 2026-08-09/thermo-fisher-genetic-analyzer-correction-patch-exists · 2026-08-06/water-plc-lockouts-twelve-states-named-utility-confirms