Project Brainfog Unveils: Is Your Smart City Vulnerable to a Cyber Comedy of Errors?

Project Brainfog uncovers a staggering 800 vulnerabilities in building automation systems worldwide, revealing the real-world risks of dormant code and corporate mergers. Gjoko Krstic’s relentless research shows how forgotten lines of code have left modern cities vulnerable to remote takeovers, highlighting a cautionary tale of cybersecurity blind spots.

Pro Dashboard

Hot Take:

When pulling an all-nighter, most people settle for a cup of coffee and a blurry-eyed morning. But Gjoko Krstic? He dives into the Matrix and emerges with 800 zero-days. Who knew insomnia could be a cybersecurity superpower? Maybe next time, he’ll find the meaning of life hidden in code — or at least a hidden stash of cat memes.

Key Points:

  • Gjoko Krstic discovered over 800 vulnerabilities in building automation systems worldwide.
  • The systems, operating in over 30 countries, include critical infrastructure like hospitals and airports.
  • An 18-year-old codebase, passed through multiple corporate mergers, was at the heart of the vulnerabilities.
  • Vulnerabilities included backdoors, unencrypted firmware, and unauthenticated exploits.
  • The vendor’s response included inconsistent vulnerability scoring and silent fixes.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?