Connect with us
MARE BALTICUM Gaming & TECH Summit 2024

Artificial Intelligence

Alias Robotics discovers numerous and dangerous vulnerabilities in the Robot Operating System’s (ROS) communications that can have “devastating consequences”

Published

on

 

A team of researchers led by the Spanish firm Alias Robotics – specialized in robotic cybersecurity – together with cybersecurity experts from several multinationals and cybersecurity professionals from various governments, have discovered about fifteen dangerous vulnerabilities, some critical, in the Robot Operating System (ROS) and the DDS communications protocols that affect industrial systems and robots that, if used by cybercriminals, could have “devastating consequences. In turn, they have detected that these vulnerabilities are present in almost 650 different devices exposed on the Internet and used not only in industry, but also in healthcare or in the military field.

Robotics and IT security professionals from the firm Alias Robotics in Spain have collaborated in recent months with security experts from around the world in the detection of security vulnerabilities in the Robot Operating System (ROS) and in the software communications middleware DDS (“Data Distribution Service”), present in many systems (autonomous cars, industrial robotic arms, aerospace systems, military equipment, critical infrastructure, …), as well as in industrial robots.

In particular, the vulnerabilities affect DDS, an ‘intermediate software’ (called middleware) that is the main communication bus between different robotic devices, that is, the core of ROS 2 (Robot Operating System ), which is used by the majority of robotics engineers for all types of present or future industrial robots, with applications in the business world, in the industrial field, but also in the world of health, as is the case of surgical robots. As per Victor Vilches studies suggests that the use of ROS will grow significantly over the next few years and that by 2024, 55% of commercialized robots will use ROS.

From Alias Robotics –specialized in robot cyber security– it is considered that “DDS is a middleware still largely insecure communications technology , used in areas where security is very important, so investment in cybersecurity is needed immediately“. They also consider that the response times of the DDS manufacturers are too long, “which greatly exposes these systems to cyber-attacks,” according to Víctor Mayoral-Vilches, a leading robot cybersecurity researcher from Alias Robotics and founder of the startup.

In his opinion, cybercriminals could today use these vulnerabilities to paralyze robots and critical infrastructures all over the world leveraging DDS”. The company from Vitoria warns that it is necessary for robotics and automation companies to invest in cybersecurity and cooperate “with qualified groups in robot cybersecurity”.

Summary of results

The results of this research derive from the collaboration of several researchers including Víctor Mayoral-Vilches (Alias Robotics), Federico MaggiMars ChengPatrick Kuo , Chizuru ToyamaRainer Vosseler, and Ta-Lun Yen (Trend Micro and TxOne) and Erik Boasson (ADLINK Labs).

Its impact in robotics has been led by Alias Robotics and a good part of these vulnerabilities “have not been patched or mitigated by the manufacturers serving robotics companies today”.

The team of researchers has come to detect up to 13 security vulnerabilities (some classified as “critical” by cybersecurity experts), which could affect both workers and users who handle industrial robots that include this DDS software. Based on the security-immaturity of DDS, the appearance of new vulnerabilities affecting DDS in the coming months is not ruled out.

One of the conclusions is that these vulnerabilities are present in almost 650 different devices used in across areas of application around the world. From Alias Robotics they have detected devices affected by these vulnerabilities in organizations such as NASA, but also in global data centers (Huawei Cloud Service), large industrial multinationals (Siemens), as well as hospitals, banks and universities in 34 countries, affecting 100 organizations through 89 Internet Service Providers (ISPs).

Key vulnerability findings

These detected vulnerabilities could lead to the loss of control of the robotic device, its complete loss of security, the denial of services through brute force, the possibility of facilitating access to the device through the exploitation of remote services, problems in the supply chain or the fact that attackers abuse the security protocols themselves to create an efficient command and control channel.

The authors of the study, have found that many of these security vulnerabilities – some even with the source code (proprietary) exposed to the public – have been open “for a long time, even years, so today cybercriminals could use them to paralyze critical infrastructure around the world” according to Víctor Mayoral-Vilches.

In his opinion, “many still robotic device manufacturers prioritize their business development and continue to ignore cybersecurity.” Mayoral-Vilches emphasizes that many of the manufacturers refuse to solve the problems “because if they did they would not comply with the DDS standard/specification“. This is a problem of magnitude” – emphasizes the founder of Alias Robotics – “since the revision of the DDS standard may take years to be properly revised“.

The report, which has been recently cited and published by the United States Agency for Security and Cybersecurity Infrastructurewas presented during 2021 in various forums including ‘Black Hat 2021’ from Las Vegas, the world’s largest annual cybersecurity forum – but also at the ROS-Industrial Conference 2021 and more recently at a session organized by the European Commission on safety, security and performance. His research will continue to be presented throughout 2022 at new conferences and industry forums.

Tools to identify ROS 2 and DDS vulnerabilities

In order to mitigate the threats found and train robotics engineers in security matters, the Alias Robotics team has led a second research effort that has contributed and released a series of extensions to tools under an open source license that allow detecting these vulnerabilities in ROS 2 and DDS.

The results of this effort have been summarized in the article “SROS2: Usable Cyber Security Tools for ROS 2” which has been sent to the International Conference on Robots and Systems (IROS 2022).

Artificial Intelligence

Computime announces the launch of one of the first true Matter thermostats

Published

on

computime-announces-the-launch-of-one-of-the-first-true-matter-thermostats

HONG KONG, May 27, 2024 /PRNewswire/ — Computime Group, a leading innovator in manufacturing, branded products and technology solutions, is proud to announce the upcoming launch of one of the first true Matter thermostats. This milestone highlights our commitment to pioneering smart home technology and providing our OEM and ODM customers with state-of-the-art solutions. 

Matter is set to revolutionize the Internet of Things (IoT) landscape as the next-generation standard for connected devices. Developed by the Connectivity Standards Alliance, Matter offers an open, universal protocol that is not bound to any single ecosystem, providing consumers with unparalleled freedom and flexibility. It ensures privacy-sensitive, secure, and reliable local controls without the need for cloud dependency, addressing the growing demand for enhanced privacy and security in smart home devices. 
The key principles driving Matter’s development include simplicity, reliability, interoperability, and security. By ensuring that all Matter-certified devices work seamlessly together, Matter eliminates the complexities often associated with smart home technology. This leads to greater compatibility, easier setup, and more robust user experiences across various device types, including thermostats.
Computime’s Matter thermostat represents a significant advancement in smart home technology, providing our customers with cutting-edge solutions and a short lead time to market, to meet the growing demand for interconnected and efficient home environments. We invite our customers to explore the capabilities of our new thermostat solutions. Computime’s extensive expertise in developing and manufacturing smart home devices ensures that our customers receive high-quality, reliable products with a short lead-time that stand out in the competitive market.
CONTACT: Computime Group, [email protected]

View original content:https://www.prnewswire.co.uk/news-releases/computime-announces-the-launch-of-one-of-the-first-true-matter-thermostats-302155918.html

Continue Reading

Artificial Intelligence

GVG featured on the 2024 Africa RegTech Horizon-100 list

Published

on

gvg-featured-on-the-2024-africa-regtech-horizon-100-list

MADRID, May 27, 2024 /PRNewswire/ — Global Voice Group (GVG) now features as one of the top 100 Africa-focused innovative RegTech organizations that are set to power Africa to a $1 billion market size by 2025. 

This acknowledgment bears witness to GVG’s compliance monitoring capabilities within the Mobile Money (MM) ecosystem. GVG developed the Mobile Money Monitoring (M3) solution, an intelligent data platform that supports East African regulatory authorities in monitoring the fast-expanding MM market. Through M3, the authorities can ensure the security and integrity of the related financial transactions, as well as transparency and compliance, for enhanced revenue assurance. M3 currently monitors approximately 25% of the financial flows passing through MM platforms in East Africa, verifying over 90 billion USD worth of transactions annually.
Moreover, the platform is also in use in Central and West Africa, in the Republic of Congo and in Ghana. In Congo, M3 has brought the local telecommunications regulator, the ARPCE, 100% visibility and control over all utility payments made via Mobile Money to the government. In Ghana, it has contributed to an average annual growth of 20% in revenue since its deployment. Overall, M3 has captured, verified and analyzed 1 trillion USD in MM transaction value since 2014.
After demonstrating the relevance, effectiveness, and innovation of the M3 solution to the jury, composed of recognized leaders of the Regtech industry, GVG was shortlisted and, following the voting phase, earned a place on the prestigious list. The M3 platform uses machine learning to ensure effective oversight of the MM market, ensure regulatory compliance and detect suspicious transactions. Since its first implementation in 2013, GVG’s M3 solution has provided the relevant regulatory authorities with reliable MM ecosystem metrics to support data-driven decision-making, promote compliance within the market, and reduce fraud and revenue leakage.
Responding to the announcement, James Claude, GVG’s CEO, declared: “It is with a great sense of achievement that I see GVG featuring among the 100 top RegTech providers in Africa. On behalf of the whole company, I sincerely thank Africa RegTech Horizon, as well as our voters, for supporting us in what we do best: providing governments and regulatory authorities with the market insights they need to address the challenges related to the fast-expanding financial ecosystem.”
The Africa RegTech Horizon-100 list is a directory of African RegTech companies and solution providers compiled to showcase the products and services of the latter, as well as assist financial institutions, regulators, and governments in identifying high-performing and trustworthy RegTech providers.
About GVG
Founded in 1998 and present in 11 countries, Global Voice Group is a global provider of ICT and RegTech solutions for governments and regulatory bodies. GVG assists governments and authorities, through Big Data analytics, in their digital transformation and the effective promotion of compliant and truly inclusive digital ecosystems. The company monitors, collects and analyses data from crucial economic sectors and turns it into actionable information. We promote data-driven decision-making.
Discover GVG’s website: www.globalvoicegroup.com
Photo – https://mma.prnewswire.com/media/2421578/Global_Voice_Group_2024.jpg

View original content:https://www.prnewswire.co.uk/news-releases/gvg-featured-on-the-2024-africa-regtech-horizon-100-list-302155235.html

Continue Reading

Artificial Intelligence

Unlock an Exclusive Olympic Experience: Celebrating Live4Well’s Sold-Out Genesis NFT

Published

on

unlock-an-exclusive-olympic-experience:-celebrating-live4well’s-sold-out-genesis-nft

HONG KONG, May 25, 2024 /PRNewswire/ — The buzz surrounding Live4Well’s successful Genesis NFT membership launch on May 23 has captivated both traditional and web3 communities. Combining the power of AI technology and decentralized physical infrastructure (DePin) concept, Live4Well has infused new life into the NFT market. The overwhelming response to their first NFT sales, showcases the project’s immense potential. Renowned web3 community leaders from Azuki, Bored Ape, Pudgy Penguins, WELL3, etc have joined forces with Live4Well, propelling the Genesis NFT membership collection to its resounding success.

Live4Well aims to transform the wellness industry by creating a reward-based infrastructure that connects global fitness data, enhances their AI database, and drives the development of sports and wellness. Backed by a multi-billion family office, which recently invested $20 million in Live4Well, the project has gained support in both web3 and traditional spaces. The team believes that every drop of sweat and effort toward better health should be rewarded, fostering motivation and integrating exercise into daily lives for enhanced well-being.
Live4Well’s announcement of an Olympic-themed raffle for Genesis NFT holders reflects their commitment to connecting wellness between Web2 and Web3 platforms. This testament to Live4Well’s demand and innovative vision solidifies their position as a promising leader in the industry. Their integration of the Olympic signifies their determination to inspire a global audience, leveraging blockchain technology to create an immersive ecosystem that revolutionizes how individuals engage with fitness on a daily basis for better health. Live4Well’s dedication to bridging the gap between traditional practices and the digital landscape sets them apart as pioneers in promoting well-being on a global scale.
What is Genesis NFT membership?
The Genesis NFT unlocks a multitude of benefits for holders, including the opportunity to cash out their sportive income and access a range of exclusive physical products and services. In addition to future airdrops and angel round whitelist privileges, Genesis holders will receive VIP tailor-made product packs from an innovative German sportswear company, elevating their exercise performance to new heights. With over 400 million sweat points farmed by their users, they are eager to redeem through the Genesis NFT membership. These enticing incentives explain why there was a widespread eagerness to participate in this thrilling event.
Unlike typical projects that raise funds before launching products or services, Live4Well has already released its AI-powered app, amassing over 250,000 users as a community base actively engaging in daily exercise. This early success has fostered a promising community within the wellness industry, as users trust Live4Well’s roadmap and collaborative ventures. The growing traction from both ordinary individuals and web3 enthusiasts has intensified the demand for redeeming and cashing out sweat points, the project’s exercise-based rewards. Obtaining the Genesis NFT membership is now seen as an essential step for accessing the highest tier of benefits and cashing out sportive income.
What’s next for Live4Well?
Following the Genesis sales, Live4Well’s team will shift their focus to the upcoming token generation event (TGE) and a series of farming events. They also have exciting plans for partnerships and other collaborations in the global wellness and fitness industries. If you missed the initial launch, be sure to stay updated on Live4Well’s journey and join this extraordinary revolution.
Photo – https://mma.prnewswire.com/media/2421983/image.jpg
Photo – https://mma.prnewswire.com/media/2421640/Live4Well.jpg
Logo – https://mma.prnewswire.com/media/2421641/4725441/Live4Well.jpg
 
 

View original content:https://www.prnewswire.co.uk/news-releases/unlock-an-exclusive-olympic-experience-celebrating-live4wells-sold-out-genesis-nft-302155644.html

Continue Reading

Trending