✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Government Facilities
Breach intelligence, attack campaigns, and threat reports targeting the Government Facilities sector.
Explore Other Sectors
Government Facilities Threat Reports
Critical Vulnerabilities in Johnson Controls iSTAR Devices Expose Critical Infrastructure—What You Need to Know
In December 2025, Johnson Controls disclosed two critical vulnerabilities (CVE-2025-43875, CVE-2025-43876) affecting its iSTAR Ultra and Edge G2 access control devices worldwide. These vulnerabilities—improper neutralization of special elements used in OS commands (CWE-78)—can be exploited remotely with low complexity and limited privileges, potentially granting attackers unauthorized access to devices deployed across critical sectors, including commercial facilities, manufacturing, energy, transportation, and government. There are currently no reports of active exploitation, but if leveraged, these flaws could compromise physical security and facility operations. This incident underscores the persistent cybersecurity challenges in operational technology and building automation environments. The disclosure highlights an urgent need for regular patching, segregation of critical controls, and adoption of defensive measures, especially as threat actors increasingly target industrial and physical security systems with potentially far-reaching consequences.
5 months ago
Kill Chain
Johnson Controls iSTAR Certificate Expiry Flaw: 2025 ICS Vulnerability Explained
In December 2025, Johnson Controls disclosed a critical vulnerability (CVE-2025-61736) affecting its iSTAR series access control panels. The flaw, classified as improper validation of certificate expiration, could cause affected devices to lose communication with their C•CURE Server once the default certificate expires. This disruption, impacting multiple critical infrastructure sectors worldwide, stems from older panel versions utilizing TLS versions prior to 1.2, thereby exposing systems to operational risk and service interruptions. While no public exploitation has been reported, timely mitigation is necessary to prevent outages. This incident highlights the ongoing importance of robust certificate management and timely upgrades in the face of tightening compliance demands and evolving threat landscapes. With operational technology environments increasingly targeted, companies must address outdated encryption protocols to maintain business continuity and regulatory alignment.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports