πŸ“° Enterprise Security Blog

Expert insights on IoT security, physical security, compliance, and risk management.

Twenty-Four Days: What the CRA's Reporting Clock Actually Changes for Offices That Buy Devices

Twenty-Four Days: What the CRA's Reporting Clock Actually Changes for Offices That Buy Devices

On 11 September the EU Cyber Resilience Act's reporting obligations switch on: 24 hours for an early warning, 72 for a full notification, 14 days after a fix for the final report. Almost every guide is written for manufacturers. If you buy and operate devices rather than make them, here is what actually changes β€” and the six questions to add to procurement this month.

Fifteen Advisories and 296,000 Bots: The Week the Building Stack Got Its Bill

Fifteen Advisories and 296,000 Bots: The Week the Building Stack Got Its Bill

In one 48-hour window: fifteen CISA advisories covering the HVAC controllers, video servers and secure-networking appliances that run modern buildings, and a Shadowserver report putting nearly 300,000 routers and cameras into a botnet that now doubles as a residential proxy network. The two halves are the same story from opposite ends.

Disarmed by a Replay: CVE-2026-27871 and the Cryptography Holding Up Your Intrusion Alarm

Disarmed by a Replay: CVE-2026-27871 and the Cryptography Holding Up Your Intrusion Alarm

A proof of concept replayed a captured disarm packet and the panel disarmed β€” no user code, no key. The flaw is in the communicator that carries your intrusion alarm to the monitoring station, the fix is months out, and the underlying problem is that alarm signalling protocols were designed for phone lines.

The Tool That Manages Everything: N-central Hits the KEV List, and Your Smart Office Has an MSP Problem

The Tool That Manages Everything: N-central Hits the KEV List, and Your Smart Office Has an MSP Problem

An authentication bypass in N-able N-central β€” itself an incomplete patch of an earlier flaw β€” went to CISA's exploited-vulnerabilities list after real customer compromises. If a managed service provider runs your office IT, the RMM console is the single most powerful thing pointed at your building, and it is almost never in your threat model.

Six Weeks, Six KEV Entries, One Pattern: The Edge Appliance Is the Smart Office Perimeter

Six Weeks, Six KEV Entries, One Pattern: The Edge Appliance Is the Smart Office Perimeter

Four KEV alerts across July, and not one of them was an end-user application. VPN appliances, sandboxes, SD-WAN orchestrators, firewall managers β€” a hard-coded password here, a command injection there. In a building full of devices that will never be patched, these appliances are the only control actually holding the line.

The Door System Is a Windows Server: Cβ€’CURE 9000, CVE-2026-21655, and the Deserialization Bug on Port 8999

The Door System Is a Windows Server: Cβ€’CURE 9000, CVE-2026-21655, and the Deserialization Bug on Port 8999

Your badge system runs on a Windows Server that facilities bought, an integrator installed, and IT has never patched. CISA's advisory for Cβ€’CURE 9000 and victor is a reminder that a physical access control server is an ordinary enterprise attack surface with an extraordinary blast radius β€” it opens doors.

Root Before Login: A Camera Zero-Day, a One-Year Disclosure Timeline, and the OEM Firmware Nobody Owns

Root Before Login: A Camera Zero-Day, a One-Year Disclosure Timeline, and the OEM Firmware Nobody Owns

A format string bug in a camera's JSON parser gives an unauthenticated attacker root. The vendor took a year and still had no fix when the advisory dropped. The uncomfortable part isn't the bug β€” it's that the vulnerable binary was written by a different company than the one on the box, and nobody in your office knows which brands share it.

Linux Laptops vs Windows in the Smart Office: Sovereignty, Telemetry, and the Machines That Hold Your Building's Keys

Linux Laptops vs Windows in the Smart Office: Sovereignty, Telemetry, and the Machines That Hold Your Building's Keys

Every smart-office admin console gets managed from a workstation, and in most offices that workstation ships with telemetry, cloud sync, and AI screenshotting turned on. Here's the Linux-vs-Windows decision for the machines that hold your building's keys β€” and the EU-built hardware to run it on.

The Passwordless Smart Office: FIDO2 Hardware Keys for the Consoles That Run Your Building

The Passwordless Smart Office: FIDO2 Hardware Keys for the Consoles That Run Your Building

Your smart office has dozens of admin consoles β€” access control, HVAC, cameras, room booking β€” and most of them are one phished password from a stranger's hands. Hardware keys fix this for about the price of a keyboard per employee.

The Credential Reckoning: Smart Office Security in the First Half of June 2026

The Credential Reckoning: Smart Office Security in the First Half of June 2026

In two weeks, CISA published three IoT advisories covering smart doorbells, cameras and a yard robot β€” every headline flaw a hardcoded or default credential. Acer shipped fixes for two CVSS 10.0 mesh-router zero-days, Cisco confirmed active exploitation of an SD-WAN Manager flaw, and a multi-agency advisory warned of attacks on internet-exposed fuel-tank gauges. All of it lands as the EU Cyber Resilience Act's 24-hour reporting clock counts down to September 11.

Three Advisories, One Root Cause: CISA Flags Hardcoded and Default Credentials in Office IoT

Three Advisories, One Root Cause: CISA Flags Hardcoded and Default Credentials in Office IoT

On a single day, CISA published advisories for a smart doorbell and camera platform, a line of network cameras, and a connected outdoor robot. The CVEs differ; the root cause does not. Hardcoded cryptographic keys, default passwords, and credentials served up to anyone who asks β€” across devices that quietly accumulate on office networks, two of them with no patch coming.

Ninety Days to the Clock: What the EU Cyber Resilience Act's 24-Hour Reporting Rule Means for Connected Offices

Ninety Days to the Clock: What the EU Cyber Resilience Act's 24-Hour Reporting Rule Means for Connected Offices

From September 11, 2026, manufacturers of connected products sold in the EU must report actively exploited vulnerabilities to ENISA within 24 hours. The obligation reaches routers, cameras, smart-building devices and OT, carries fines up to €15 million or 2.5% of global turnover, and reshapes how buyers should evaluate vendors. With roughly 90 days to go, two-thirds of vendors say they are still unfamiliar with the regulation.

Ask Sage πŸ€–