Physical infrastructure security failures keep compounding
Three security stories ran in parallel today and they share a structure: nation-state or sophisticated actors compromising physical-world systems through software. Iranian hackers shut down a UK power plant for four days, almost certainly through an exposed SCADA system. Slovakia found a Russian backdoor in traffic speed camera firmware. And a separate thread covered Android malware pre-installed in automotive head unit firmware, which commenters noted is the logical endpoint of 'the car as software.'
The pattern here is that internet-connected physical infrastructure is being attacked, and the defenses haven't kept up with the connectivity. The SCADA thread's top comment is just 'Let me guess, SCADA system is somehow accessible from outside,' which is both funny and depressing because it's almost certainly correct. The car malware thread notes the attacker use case is probably botnet recruitment, since head units don't hold valuable data directly, but the psychological response from commenters was sharper than usual: the idea of malware in your car feels more threatening than malware on your phone.
Stuxnet came up in the power plant thread, which is the community's way of noting that this is reciprocal. Nations that pioneered infrastructure cyberattacks are now targets of the same playbook.
So what?
If you're building anything that touches physical infrastructure, connected devices, or automotive systems, the security bar just got raised by public example. Regulators will react to these stories. More immediately, your enterprise customers in energy, transport, or manufacturing are going to start asking harder questions about supply chain integrity and network segmentation. Get your answers ready before they ask.