#Team82
"Team82 obtained a sample of a custom-built IoT/OT malware called IOCONTROL used by the Iran-affiliated attackers to attack Israel- and U.S.-based OT/IoT devices."

claroty.com/team82/resea...
December 10, 2024 at 7:30 PM
June 3, 2026 at 1:00 PM
Hack The Emulated Planet : Vulnerability Hunting on Planet WGS-804HPT Industrial Switches : claroty.com/team82/resea...
March 16, 2025 at 2:18 PM
Security analysis of a Allen-Bradley (Rockwell Automation) PowerMonitor 1000 device

claroty.com/team82/resea...

#infosec
July 1, 2025 at 11:03 AM
Analysis of capabilities and communication channels used by IOCONTROL IoT/OT malware

claroty.com/team82/resea...

Credits @Claroty

#cybsersecurity
December 15, 2024 at 11:27 AM
🏢 Team82’s research found that attackers can potentially reach data center assets through indirect pathways, including interconnected IT systems, third-party remote access, and trusted network relationships.

🔎 Read more: claroty.com/blog/data-ce...
Data Center Exposures and the Pathways Putting Data Center Assets at Risk
Secure data centers require remediation and mitigation of data center asset and infrastructure exposures. Claroty Team82’s latest research report dives into the riskiest data center exposures, and how...
claroty.com
September 24, 2026 at 8:38 PM
From Exploits to Forensics : Unraveling the Unitronics Attack : claroty.com/team82/resea...
November 23, 2024 at 3:31 PM
🚨 Team82 uncovered vulnerabilities in the Danfoss AK-SM 800A refrigeration controller platform, including a hidden “code-of-the-day” authentication mechanism that could bypass normal authentication. Danfoss has addressed them in a recent firmware version. claroty.com/team82/resea...
Freeze the Controller, Defrost the Food: Uncovering Vulnerabilities in Danfoss Refrigeration Controllers
Team82 researched the attack surface of the Danfoss AK-SM 800A refrigeration controller platform and identified multiple vulnerabilities affecting the embedded web management interface. Team82 disclos...
claroty.com
September 2, 2026 at 6:12 PM
Today in the SUN we feature an article from @claroty.bsky.social on Team82 uncovering two vulnerabilities in EnOcean’s SmartServer IoT platform.

Read more below:
claroty.com/team82/resea...

#cybersecurity
@andyjabbour.bsky.social
Exploiting EnOcean SmartServer to Attack Connected Building Management Systems
Team82 uncovered two vulnerabilities in EnOcean’s SmartServer IoT platform and i.LON devices that connect building management systems to the internet. An attacker exploiting these vulnerabilities can ...
claroty.com
April 30, 2026 at 4:01 PM
Attack surface and security analysis of a Allen-Bradley (Rockwell Automation) PowerMonitor 1000 device

claroty.com/team82/resea...

#infosec #embedded
May 29, 2025 at 10:53 AM
🔬 New from #Team82: Read about the research accompanying their #BlackHatEurope presentation on the insecure #IoT cloud. Ten vulnerabilities were uncovered in Ruijie Networks devices—many of them related to poor device authentication. All 10 have been fixed by the vendor. claroty.com/team82/resea...
The Insecure IoT Cloud Strikes Again: RCE on Ruijie Cloud-Connected Devices
Team82's research of Ruijie Networks’ cloud and device ecosystem uncovered 10 vulnerabilities that would allow an attacker to execute arbitrary code on every cloud-connected device. Team82 also develo...
claroty.com
December 13, 2024 at 1:15 AM
🚨Team82 looked into the alleged backdoor in Contec CMS8000 patient monitors and concluded that may not be the case. Read more here: claroty.com/team82/resea... #healthcare #cybersecurity
Do the CONTEC CMS8000 Patient Monitors Contain a Chinese Backdoor? The Reality is More Complicated…
Team82 investigated what CISA labeled a backdoor in the Contec CMS8000 patient monitoring system and concluded that instead, the decision to include a hardcoded IP address is instead an insecure and r...
claroty.com
February 4, 2025 at 12:44 AM
#Team82 rocks ! 🤘
December 28, 2025 at 11:54 AM
#Team82 ici 😁
April 22, 2026 at 4:55 PM
🔬 Read #Team82's analysis of a new cyberweapon called #IOCONTROL that's been uncovered and used in attacks against the U.S. and Israel. The weapon is custom-built and its modular configuration allows it to be used against #IoT, #OT, and #SCADA systems. claroty.com/team82/resea...
December 14, 2024 at 12:23 AM
⚠️ Team82 has uncovered six vulnerabilities in Samsung's HVAC DMS, a building management systems data management server. The vulnerabilities can lead to unauthenticated remote code execution. More info on #Team82's Disclosure Dashboard: claroty.com/team82/discl...
August 5, 2025 at 5:07 AM
Simplicité rime avec insécurité ? Dit-on de #Synology 🤔 Découvrez la vulnérabilité récente et comment ils y répondent. Curieux ? 💡 #Cybersécurité #TechNews
Vulnérabilité Synology – Quand simplicité rime avec insécurité
Les chercheurs de Team82 ont découvert une vulnérabilité chez Synology, où l’utilisation de Math.random() pour générer des mots de passe administrateur n’est pas cryptographiquement séc…
korben.info
October 19, 2023 at 5:00 AM
⚠️ Medixant recommends users update implementations of the RadiAnt #DICOM Viewer to address a certificate validation vulnerability disclosed by #Team82. More info: claroty.com/team82/discl...
February 25, 2025 at 8:38 PM
Protecting Building Management Systems (#BMS) is more critical than ever. In #Team82's recent analysis, our researchers examined over 🔎 467,000 devices across 529 organizations and uncovered some alarming trends. 🚨

📙 Download the full report here: claroty.com/resources/re...
October 17, 2025 at 10:51 PM
Claroty Team82 warns of growing cybersecurity risks in legacy LonTalk protocols across BMS deployments industrialcyber.co/threat-lands...
Claroty Team82 warns of growing cybersecurity risks in legacy LonTalk protocols across BMS deployments - Industrial Cyber
New research from Claroty’s Team82 warns of growing cybersecurity risks in legacy LonTalk protocols across BMS deployments.
industrialcyber.co
February 24, 2026 at 1:12 PM
Inside a New OT/IoT Cyberweapon: IOCONTROL
Inside a New OT/IoT Cyberweapon: IOCONTROL
Team82 obtained a sample of a custom-built IoT/OT malware called IOCONTROL used by the Iran-affiliated attackers to attack Israel- and U.S.-based OT/IoT devices.
buff.ly
December 13, 2024 at 7:00 AM
⚠️ MicroDicom fixed a certificate validation vulnerability (CVSS v3: 5.7) in its #DICOM viewer that #Team82 disclosed. MicroDicom advises updating to version 2025.1. More info: claroty.com/team82/discl...
February 28, 2025 at 8:22 AM
New #Team82 research uncovers a 1-click remote-code execution vulnerability affecting IDIS Cloud Manager viewer that could allow attackers to view live video feeds, recordings, and search images on the video surveillance system. Read more: claroty.com/team82/resea...
January 27, 2026 at 2:45 PM
New research from @claroty.bsky.social Team82 on device authentication weaknesses affecting cloud-managed IoT devices. claroty.com/team82/resea...
This research was also presented today at #BHEU
The Insecure IoT Cloud Strikes Again: RCE on Ruijie Cloud-Connected Devices
Team82's research of Ruijie Networks’ cloud and device ecosystem uncovered 10 vulnerabilities that would allow an attacker to execute arbitrary code on every cloud-connected device. Team82 also develo...
claroty.com
December 12, 2024 at 12:51 PM
⚠️ METZ Connect has provided firmware updates for 5 vulnerabilities disclosed by #Team82 in Metz's EWIO2 Ethernet I/O Controller. These vulnerabilities could allow an attacker to control the device remotely or remote code execution. Read more: claroty.com/team82/discl...
November 24, 2025 at 7:46 PM