❌

Reading view

There are new articles available, click to refresh the page.

TP-Link Zero-Touch Provisioning Flaws Could Expose Enterprise Networks, Warns Forescout

Forescout Vedere Labs research has uncovered 15 previously unknown vulnerabilities affecting TP-Link’s Omada Zero-Touch Provisioning (ZTP) ecosystem, warning that weaknesses in automated device deployment could allow attackers to compromise not just individual devices, but the management infrastructure responsible for entire networks.

The research highlights an emerging security challenge as organisations increasingly rely on Zero-Touch Provisioning to simplify the deployment and management of routers, switches, gateways and wireless access points across distributed environments. While ZTP reduces operational overhead, Forescout argues that it also creates highly trusted relationships between devices, controllers and cloud services that, if exploited, could significantly increase the scale of an attack.

Rather than exploiting a single network device, Vedere Labs researchers demonstrated how multiple vulnerabilities can be chained together to move from device onboarding to compromising controllers, cloud services and managed infrastructure. The vulnerabilities span client-side code execution, credential disclosure, device spoofing and weaknesses in cryptographic trust.

Daniel dos Santos, VP of Research at Forescout, said: β€œAs organisations adopt Zero-Touch Provisioning to automate deployment and management, weaknesses in those systems can create entirely new attack scenarios. Our findings underscore the importance of visibility not only into connected devices, but also into the management systems and trust relationships that control them.”

What it means for organisations

The findings emphasise the need for a mindset change when it comes to infrastructure security. Traditionally, security teams have focused on protecting endpoints and individual network devices. However, as provisioning and lifecycle management become increasingly automated, the management platforms themselves are becoming attractive targets.

A successful compromise of a provisioning system could allow attackers to deploy malicious configurations, steal credentials or gain access to multiple devices simultaneously, amplifying the impact of a single breach. This is particularly relevant for organisations managing large estates of network infrastructure across branch offices, warehouses, retail locations or industrial environments where ZTP has become commonplace.

The research also highlights that the risk extends beyond TP-Link Omada, with some vulnerabilities affecting related TP-Link ecosystems including Festa, VIGI, Tapo and Kasa, demonstrating how weaknesses in shared provisioning technologies can have wider implications.

Reducing the risk

Forescout is urging organisations using affected products to install available updates for devices, controllers and associated applications as soon as possible. Beyond patching, the company recommends reviewing provisioning processes to ensure default credentials are replaced with strong, unique passwords, enabling multi-factor authentication for TP-Link accounts, rotating exposed credentials, segmenting provisioning infrastructure from the wider network, and continuously monitoring communications between devices, controllers and cloud services. Applying Zero Trust principles to device management workflows can also help limit the impact if a provisioning platform is compromised.

The research serves as a reminder that as organisations embrace automation to improve operational efficiency, they must apply the same level of scrutiny to the systems managing infrastructure as they do to the infrastructure itself. Protecting the chain of trust underpinning automated deployment is becoming just as important as securing the devices being deployed.

The full research is available here: Zero Day Provisioning: Chaining TP-Link ZTP Vulnerabilities to Infiltrate Networks

The post TP-Link Zero-Touch Provisioning Flaws Could Expose Enterprise Networks, Warns Forescout appeared first on IT Security Guru.

Forescout Report Reveals Surge in AI-Driven Cyber Threats

The Forescout 2026 H1 Threat Review found that more than 37,000 vulnerabilities were published during the first six months of the year, representing a 51% increase year on year. More than half were classified as high or critical severity, while ransomware attack claims rose by 25% to 4,544 incidents, averaging 25 attacks every day.

The report, published by Forescout Research – Vedere Labs, analysed more than 37,000 vulnerabilities, over 1,000 tracked threat actors and thousands of cyberattacks observed between January and June 2026. Researchers found that rapid advances in AI, alongside growing geopolitical tensions, are increasing the pressure on security teams already struggling to prioritise risk.

Among the reportβ€˜s key findings, researchers discovered that nearly half of all additions to CISA’s Known Exploited Vulnerabilities (KEV) catalogue related to vulnerabilities published before 2026, reinforcing the continued risk posed by older, unpatched flaws. The number of active ransomware groups also increased to 103, while China, Russia and Iran collectively accounted for almost a third of tracked threat actors with significant activity during the reporting period.

The research also highlights the growing use of AI by threat actors to accelerate attacks, alongside increasingly sophisticated software supply chain compromises. At the same time, attackers continue to focus on network infrastructure, operational technology, IoT and IoMT devices, many of which receive less security oversight than traditional endpoints.

β€œAI is dramatically increasing the speed and scale of cyberattacks,” said Daniel dos Santos, VP of Research at Forescout.

β€œIn observing attack patterns and threat actor activity, we can see that AI is helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them. At the same time, geopolitical conflicts are fuelling waves of opportunistic and state-aligned cyber activity, with organisations in critical infrastructure sectors increasingly at risk.”

He added that organisations need a better understanding of the assets connected to their networks so they can prioritise risk and contain threats before attackers can move laterally into critical systems.

The report also examines the evolution of Iranian cyber operations, noting that the distinction between state-sponsored actors, hacktivist groups and cybercriminal organisations is becoming increasingly blurred. Researchers found these groups are using a mix of espionage campaigns, ransomware and attacks targeting critical infrastructure and operational technology.

Barry Mainz, CEO of Forescout, said organisations must extend their focus beyond traditional endpoints to address unmanaged assets and connected devices.

β€œAs attack surfaces continue to expand, security teams can no longer focus exclusively on traditional endpoints,” he said.

β€œMany organisations still have significant blind spots across unmanaged assets and IoT, OT, and IoMT devices. Threat actors understand this and are increasingly exploiting those gaps.”

The report recommends that organisations should continuously identify vulnerable assets, strengthen network segmentation, prioritise the highest-risk systems and accelerate response capabilities to reduce exposure across increasingly complex environments.

The post Forescout Report Reveals Surge in AI-Driven Cyber Threats appeared first on IT Security Guru.

❌