Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Saturday, 6 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Forescout Uncovers New Security Risks in Widely Used Industrial Networking Devices

Thousands of Devices Potentially Exposed Online

by Guru Writer
April 21, 2026
in Editor's News, News, Research
Forescout Uncovers New Security Risks in Widely Used Industrial Networking Devices
Share on FacebookShare on Twitter

Cybersecurity firm Forescout has identified 22 previously unknown vulnerabilities in serial-to-IP converters, devices commonly used to connect legacy industrial equipment to modern networks. The company warns that thousands of these systems are currently exposed online, potentially increasing the risk of cyberattacks across critical infrastructure sectors.

The findings are part of a new research initiative called BRIDGE:BREAK, which focuses on hardware produced by Lantronix and Silex. These devices are widely deployed in industries such as utilities, manufacturing, healthcare, and telecommunications, where they play a key role in maintaining operations by bridging older systems with newer digital infrastructure.

Serious Risks: Disruption, Data Tampering, and Device Takeover

According to the report, the vulnerabilities could allow attackers to disrupt operations, move laterally across networks, tamper with sensitive data, or even take control of affected devices. Some of the identified weaknesses include the potential for remote code execution, authentication bypass, firmware manipulation, denial of service, and exposure of confidential information.

Forescout researchers also discovered that tens of thousands of these devices are accessible over the internet. While exposure alone does not mean the devices are vulnerable to the newly identified flaws, it significantly broadens the attack surface and makes it easier for threat actors to identify and target them.

Human Expertise Still Critical in an AI Driven Landscape

Daniel dos Santos, Vice President of Research at Forescout, said the findings highlight a persistent gap in how organizations secure operational technology environments.

“Serial-to-IP converters sit directly between operators and physical processes, yet they are often overlooked by traditional security monitoring,” dos Santos said. “Advances in artificial intelligence will accelerate how quickly vulnerabilities are discovered, but understanding which risks truly matter still requires human insight into how devices behave and communicate in real world environments.”

Publicly Available Information Aids Attackers

The research also emphasizes that attackers can leverage publicly available information, such as technical documentation and images, to identify specific device models and deployment environments. This type of intelligence can help adversaries prioritize targets and refine their attack strategies.

In addition, the analysis of firmware from multiple vendors revealed outdated software components, known vulnerabilities, and inconsistent security protections. These factors can make exploitation easier and increase the likelihood of successful attacks.

Real World Impact on Critical Infrastructure

Forescout outlined several potential consequences if the vulnerabilities are exploited. These include operational disruptions caused by interference with communications between systems, the ability to move within a network to access other critical assets, and manipulation of sensor data. In testing scenarios, researchers demonstrated how altered data could produce false readings in monitoring systems, potentially leading to incorrect decisions or unsafe conditions.

Recommended Steps to Reduce Risk

The company is urging organizations to take immediate action to reduce risk. Recommended steps include applying vendor patches as soon as they are available, removing default credentials, enforcing strong authentication, and ensuring that devices are not directly exposed to the internet. Additional measures such as network segmentation and monitoring internal traffic for unusual activity can also help limit the impact of potential attacks.

As industries continue to rely on legacy equipment integrated into modern networks, the report underscores the importance of securing the devices that serve as bridges between the two. 

Forescout’s findings suggest that these often overlooked components could become a critical entry point for attackers if not properly managed.

You can download the full BRIDGE:BREAK report here.

Tags: cybersecurityForescoutthreat researchvulnerabilities
ShareTweet
Previous Post

What to do When Your AI Guardrails Fail

Next Post

Bridewell Among First to Achieve Level 2 Defence Cyber Certification

Recent News

Frontline Workers Twice as Likely to Use Unapproved AI

Frontline Workers Twice as Likely to Use Unapproved AI

June 4, 2026
Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
data-cloud-security

Building a Digital Fortress: Why Cyber Security Matters More Than Ever

June 5, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol