Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities SC Media

NASA ground control software vulnerability could allow spacecraft access

A critical vulnerability in NASA's AMMOS Instrument Toolkit (AIT-GUI) versions up to 2.5.1 allows unauthenticated remote attackers to issue spacecraft commands and potentially execute server-side scripts due to a lack of authentication, authorization, and CSRF protection on its web server interface. The attack vector can be via an exposed network port or by tricking an operator into visiting a malicious webpage. Administrators must upgrade to AIT-GUI version 2.5.2, check console ports, and review command history.
Read Full Article →

Government security NASA ground control software vulnerability could allow spacecraft access August 21, 2026 Share By SC Staff NASA's ground control software has a critical vulnerability that could allow third-party access to spacecraft, with further coverage provided by Tech Radar. A browser-based variant of NASA's AMMOS Instrument Toolkit (AIT), specifically versions up to 2.5.1, has a critical vulnerability that could allow an unauthenticated attacker to issue commands to spacecraft and instruments, and potentially execute server-side scripts, as discovered by Cycode researchers. The flaw, disclosed on August 18, 2026, stems from the AIT-GUI running as a web server with an open network interface and lacking authentication, authorization, or cross-site request forgery (CSRF) protection. This allows attackers to exploit basic access-control failings, potentially enabling them to upload files, including malware, directly to NASA craft via a vulnerable browser session. The attacker does not need to be on the same network, as access can be gained through an exposed port or by tricking an operator into visiting a malicious webpage. Cycode advises administrators to upgrade AIT-GUI to version 2.5.2, check console ports, and review command history. Source: Tech Radar SC Staff Related Critical Infrastructure Security US autonomous systems policy struggles to keep pace with drones SC Staff August 21, 2026 U.S. policymakers race to keep drone and autonomous systems rules aligned with rapidly advancing technology. Government security CISA explores single contract for cybersecurity software purchases SC Staff August 19, 2026 CISA is currently acquiring these tools through the Continuous Diagnostics and Mitigation program and its Capacity Building arm. Ransomware CISA confirms 2025 Windows Task Host flaw exploited by ransomware groups Steve Zurier August 18, 2026 Experts say teams should make this a priority, noting that the patch has been available since last November. Related Events Webcast Public sector security: Achieving resilience in the AI age Tue Sep 8 Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article