The Desk · The Wire · Hacked Today? · Data Center RSS
The Perimeter Site

Why Are We Building Rockets Without Locks?

The Perimeter Desk
2026-08-20
# Why Are We Building Rockets Without Locks? The Technology sector is currently the primary target of every meaningful campaign on the wire, clocking 193 stories this week alone. That’s not a coincidence or a sudden surge in attacker creativity. It's a reflection of how we're building things right now: fast, loud, and with an almost pathological disregard for the plumbing. When you look at the Government sector—the second most targeted with 149 stories—you see traditional espionage and state-level friction. But in Tech, the incentive is different. We aren't just seeing data theft; we're seeing the collapse of "innovation" as a shield for negligence. Take the current CISA warning regarding MLflow. For those who don't live in the weeds, MLflow is a cornerstone for managing the lifecycle of machine learning models. It’s where the blueprints for the AI revolution are kept. CISA isn't issuing a theoretical advisory here; they're flagging an exploit already active in the wild. The incentive loop is obvious: companies are terrified of being second to the AI party. They deploy these pipelines with a "move fast and break things" mentality, but they forget that when you move fast in a pipeline, you're just accelerating the delivery of your crown jewels to whoever finds the open door first. The security team doesn't get a bonus for a stable pipeline; the product lead gets a promotion for a deployed model. Then we have NASA. Security researchers at Cycode found that the AIT-GUI operator console—the thing used to actually communicate with spacecraft—had a chain of vulnerabilities that could let an unauthenticated attacker issue commands. Think about that. We've reached a point where you can potentially tell a piece of orbital hardware to do something, and the system doesn't even ask who you are first. This isn't a failure of encryption or a complex zero-day; it's a fundamental failure of trust architecture. It’s the digital equivalent of leaving the keys in the ignition of a rocket because "it's in a secure hangar." The assumption that the perimeter is enough is a ghost we keep chasing, even when the perimeter is practically non-existent. Viasat provides the retrospective punchline. They're now using an AI-assisted tool called Argo to harden their satellite communications network. Why? Because they spent years reeling from a Russian hacking incident back in 2022. There’s a certain irony in using AI to fix the holes created by the same culture of haste that likely left those holes open in the first place. It's recovery theater. We use the new shiny tool to patch the old broken one, hoping the auditors will be impressed by the "AI-driven" nature of the remediation rather than asking why the basic hardening wasn't done a decade ago. The second-order effect here is where it gets truly ugly. When a tool like MLflow is popped, the victim isn't just the company running the server. It's every customer whose data was used to train that model and every downstream application relying on those weights. We're building an entire economic layer on top of AI infrastructure that is being bolted together with digital duct tape. If the foundation is porous, the entire house is a liability. The common defense for this is "complexity." Executives love this word. They'll tell you that modern tech stacks are too complex to be perfectly secure and that we have to accept some level of risk to remain competitive. That’s a lie. Complexity is an excuse used to justify the omission of basics. There is nothing "complex" about requiring authentication before allowing someone to command a spacecraft or modify a machine learning model. Those are binary choices: you either verify identity, or you don't. Choosing not to isn't a trade-off for innovation; it's a conscious decision to accept a catastrophic failure mode in exchange for a slightly faster deployment cycle. The defenders in this sector aren't actually fighting attackers. They're fighting their own internal KPIs. They are battling against a corporate culture that views security as a speed bump rather than a steering wheel. When the CISO warns that the pipeline is leaky, they're told to "manage the risk." In corporate-speak, "manage the risk" usually means "wait until it breaks and then write a press release about our commitment to security." This leads us to the only question that actually matters right now: At what point does "innovation" stop being a business strategy and start being a legal euphemism for gross negligence? We can keep adding AI-powered shields to our satellite arrays and updating our MLflow patches, but as long as the reward goes to the person who launches first rather than the person who launches safely, we're just building more expensive targets. The attackers know exactly whose incentives are being served. They aren't looking for a magic door; they're just waiting for us to leave the keys in the ignition again.
◼

Sources

The reporting this analysis was built from. Follow the originals before acting on anything here.

  1. CISA warns of hackers exploiting critical MLflow vulnerability BleepingComputer
  2. NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands The Hacker News
  3. 40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets The Hacker News
  4. ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud The Hacker News
  5. AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking SecurityWeek
  6. Kenya and UK Review Cybersecurity Partnership to Strengthen Digital Resilience - TechAfrica News Google News Security

How stories are selected and rated

← More from the Desk Live Wire →

About · Methodology · Contact · Privacy

Tracking a CVE from this story? Hazard shows which vulnerabilities are confirmed exploited in the wild — and what the resulting breaches have cost UK organisations.

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.