{"id":169076,"date":"2025-09-11T07:58:04","date_gmt":"2025-09-11T07:58:04","guid":{"rendered":"https:\/\/teknomers.com\/en\/some-of-the-most-advanced-satellites-in-the-world-appeared-to-be-secure-and-untouchable-however-two-hackers-demonstrated-that-they-could-be-hacked\/"},"modified":"2025-09-11T07:58:06","modified_gmt":"2025-09-11T07:58:06","slug":"some-of-the-most-advanced-satellites-in-the-world-appeared-to-be-secure-and-untouchable-however-two-hackers-demonstrated-that-they-could-be-hacked","status":"publish","type":"post","link":"https:\/\/teknomers.com\/en\/some-of-the-most-advanced-satellites-in-the-world-appeared-to-be-secure-and-untouchable-however-two-hackers-demonstrated-that-they-could-be-hacked\/","title":{"rendered":"Some of the most advanced satellites in the world appeared to be secure and untouchable. However, two hackers demonstrated that they could be hacked."},"content":{"rendered":"\n<p>As we sail deeper into the \u00a0digital age\u00a0, our reliance on \u00a0satellite technology\u00a0 continues to grow, impacting everything from communication to navigation. Yet, the underlying software that governs these systems often lacks comprehensive \u00a0security scrutiny\u00a0. Alarmingly, recent demonstrations have illuminated vulnerabilities that could make \u00a0Remote Space Systems Control\u00a0 a feasible threat. This isn&#8217;t merely an isolated incident; it&#8217;s a \u00a0wake-up call\u00a0 highlighting the urgent need for thorough security assessments before we face dire consequences.<\/p>\n<p>At the \u00a0Black Hat USA\u00a0 and \u00a0Defcon\u00a0 conferences held in Las Vegas in August, researchers unveiled concerning findings related to two significant pieces of software: the \u00a0Core Flight System (CFS)\u00a0, used in multiple NASA missions including the \u00a0James Webb telescope\u00a0, and the \u00a0Yamcs\u00a0, a control system developed by the European company \u00a0Space Applications Services\u00a0. The vulnerabilities identified were swiftly corrected before they could be publicized, emphasizing both the severity and the urgency of the issues at hand.<\/p>\n<h2><strong>The Finding Reopening the Debate on Cybersecurity in Space<\/strong><\/h2>\n<p>Leading the charge were \u00a0Andrzej Olchawa\u00a0 and \u00a0Milenko Starcik\u00a0, cybersecurity experts from \u00a0Visionspace\u00a0, who approached open-source software with the mindset of an adversary. Within just a few hours, they uncovered a staggering \u00a037 vulnerabilities\u00a0 that could potentially manipulate critical systems in controlled environments. Their proactive collaboration with developers allowed for timely patches of the software before the dissemination of their findings.<\/p>\n<div class=\"article-asset-image article-asset-normal article-asset-center\">\n<div class=\"asset-content\">\n<p>   <img decoding=\"async\" alt=\"Antennas\" class=\"centro_sinmarco\" src=\"https:\/\/teknomers.com\/en\/wp-content\/uploads\/2025\/09\/Some-of-the-most-advanced-satellites-in-the-world-appeared.jpeg\"\/>\n <\/div>\n<\/div>\n<p>The \u00a0Core Flight System (CFS)\u00a0 is crucial for NASA missions, yet exploiting its vulnerabilities is not straightforward. Doing so would require \u00a0physical proximity to a land station\u00a0 and the capability to operate at frequencies designated for space communications. Nonetheless, researchers caution that a state actor with the required resources could feasibly execute such attacks. Their demonstrations illustrated how a sufficiently capable organization could send unauthorized commands, thereby altering satellite behavior.<\/p>\n<p>The \u00a0Yamcs\u00a0, however, presents a different scenario. Attackers could easily infiltrate this system with a successful \u00a0phishing campaign\u00a0, enabling them to upload malicious configurations to the control center. This vector not only allows arbitrary commands but also facilitates file alterations from any location with an Internet connection, broadening the attack surface significantly.<\/p>\n<div class=\"article-asset article-asset-normal article-asset-center\">\n<div class=\"desvio-container\">\n<div class=\"desvio\">\n<div class=\"desvio-figure js-desvio-figure\">\n     <img loading=\"lazy\" decoding=\"async\" alt=\"Asteroid Defense Mission\" width=\"375\" height=\"142\" src=\"https:\/\/teknomers.com\/en\/wp-content\/uploads\/2025\/09\/1757577484_944_Some-of-the-most-advanced-satellites-in-the-world-appeared.jpeg\"\/>\n   <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<p>During his talk at \u00a0Black Hat USA 2025\u00a0, Olchawa provided deeper insights into the vulnerabilities they exploited. He emphasized that \u00a0all maneuvers were conducted in simulated environments\u00a0, ensuring that no real satellites were jeopardized. This context is vital for understanding the potential risks that exist, especially for actors with the requisite expertise and access to systems.<\/p>\n<blockquote><p>&#8220;In some cases, we were able to send arbitrary commands to the satellites through the mission control system. In others, we managed to take control of the entire control center,&#8221; Olchawa explained. &#8220;If you can send commands to the satellite, it&#8217;s possible to execute remote code directly.&#8221;<\/p><\/blockquote>\n<p>The security landscape has transformed considerably; previously, private networks and localized stations were the norm, but now we face \u00a0cloud services\u00a0, \u00a0remote control\u00a0, and \u00a0home connections\u00a0. According to researchers, this evolution exponentially increases attack possibilities, thus making once-theoretical vulnerabilities immediate concerns. A case that underscores this alarm is the \u00a02022 attack on Viasat\u00a0, which disrupted thousands of users and coincided with the onset of the Ukraine conflict, indicating that space systems are not immune to global turmoil.<\/p>\n<p>Fortunately, timely updates have addressed vulnerabilities in open projects, mitigating the risks highlighted in the laboratory tests. Nonetheless, a critical challenge remains: \u00a0closed systems\u00a0 are less accessible for external experts to evaluate, complicating the review process and raising security concerns.<\/p>\n<p>As we traverse further into \u00a0space technology\u00a0, safeguarding our satellites against vulnerabilities must become a priority. Continuous vigilance, thorough assessments, and proactive collaborations can help us prevent potential crises before they escalate into headlines.<\/p>\n<p><br \/>\n<br \/><a href=\"https:\/\/teknomers.com\/category\/general\/\" rel=\"dofollow\">General News &#8211; 2<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As we sail deeper into the \u00a0digital age\u00a0, our reliance on \u00a0satellite technology\u00a0 continues to grow, impacting everything from communication to navigation. Yet, the underlying software that governs these systems often lacks comprehensive \u00a0security scrutiny\u00a0. Alarmingly, recent demonstrations have illuminated vulnerabilities that could make \u00a0Remote Space Systems Control\u00a0 a feasible threat. This isn&#8217;t merely an [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":169077,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[36399],"tags":[3418,6514,10142,4135,3474,3694,4432,41354,110],"class_list":["post-169076","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-advanced","tag-appeared","tag-demonstrated","tag-hacked","tag-hackers","tag-satellites","tag-secure","tag-untouchable","tag-world"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/posts\/169076","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/comments?post=169076"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/posts\/169076\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/media\/169077"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/media?parent=169076"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/categories?post=169076"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/tags?post=169076"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}