Maritime Sector
2 articles covering maritime OT/ICS security
CISA ICSA-26-237-07: Hardcoded Credentials and Missing Authentication in FURUNO FA-50 AIS Transponders — No Patch Coming
CISA and JPCERT disclosed two vulnerabilities in the discontinued FURUNO FA-50 Class B AIS Transponder — hardcoded credentials (CVSS 9.1) and missing authentication on configuration functions (CVSS 7.5). With production ended in 2020 and no firmware update planned, mitigation falls entirely on vessel network segmentation.
Maritime OT Security 2026: ECDIS Vulnerabilities, AIS Spoofing, and the Threat to Port Systems
Maritime operational technology spans navigation systems, ship management platforms, and port infrastructure — all increasingly networked, poorly patched, and targeted by both state and criminal actors. This sector briefing covers the current maritime threat landscape, key vulnerability classes in ECDIS and AIS, GPS/GNSS spoofing in contested regions, and the IMO and DNV frameworks guiding the sector's security response.