Skip to main content
System Status
Critical 18
|
High 70
|
Medium 1
|
Feed Online
UPDATED: 2026-06-11 00:00 UTC

CISA ICSA-26-237-07: Hardcoded Credentials and Missing Authentication in FURUNO FA-50 AIS Transponders — No Patch Coming

CISA and JPCERT disclosed two vulnerabilities in the discontinued FURUNO FA-50 Class B AIS Transponder — hardcoded credentials (CVSS 9.1) and missing authentication on configuration functions (CVSS 7.5). With production ended in 2020 and no firmware update planned, mitigation falls entirely on vessel network segmentation.

Maritime OT Security 2026: ECDIS Vulnerabilities, AIS Spoofing, and the Threat to Port Systems

Maritime operational technology spans navigation systems, ship management platforms, and port infrastructure — all increasingly networked, poorly patched, and targeted by both state and criminal actors. This sector briefing covers the current maritime threat landscape, key vulnerability classes in ECDIS and AIS, GPS/GNSS spoofing in contested regions, and the IMO and DNV frameworks guiding the sector's security response.