TL;DR too long, didn’t read

  • The Royal Navy found cameras on twenty of its uncrewed boats calling an IP address in China. Nothing reported it. Somebody scanned the boats.

  • More than a hundred thousand routers ship with a backdoor built in at the factory. It calls out every 35 seconds, so the firewall never sees it.

  • Clop published the names seven weeks after the patch deadline closed. Everyone still exposed made that choice with the warning already in hand.

Not one of these would have been found by reading a document.

Three things that matter this week

The paperwork said compliant. The camera called China.

Cameras fitted to twenty K3 Scout uncrewed surface vessels operated by the Royal Marines were sending automated heartbeat signals to an IP address in China. Heartbeats are status pings, the device confirming it is alive. Not data.

The vessels come under Project Beehive, a 12.3 million pound contract with Kraken Technology Group, a systems integrator in Hampshire. The Ministry of Defence cut internet connectivity to the affected cameras and stated that "a thorough investigation found no evidence of MoD data or systems being accessed, compromised or transmitted externally". Kraken said it was aware that some third-party cameras labelled NDAA-compliant contained "a small number of components originating from outside the UK", and that a later audit found nothing had left intended channels.

Here is the part worth the whole story.

The discovery came from a routine cyber vulnerability assessment. Not an incident. Not a tip-off from an agency. Not the supplier. Somebody scanned their own boats as a matter of course, and the boats turned out to be talking to someone.

An NDAA-compliance label refers to Section 889 of the 2019 US National Defense Authorization Act, which is a list of named Chinese manufacturers a component must not come from. It says nothing about what the component's firmware does once it is installed. A camera can clear that list on paper and still call an address in China every few seconds, and both things can be true at once without anybody lying.

Two things are being reported that are not established. The camera has been identified in one outlet as a Night Navigator 3000 made by a Canadian firm, but neither the original reporting nor the MoD confirmed it, and the supplier remains officially unnamed. Defence sources' concerns about exposure of Special Boat Service personnel, and about cameras staying live while vessels were powered down, are reported concern rather than fact. I am flagging both because the story is strong enough without them.

What to do: Take one network device that an integrator installed on a vessel or in a terminal in the last two years, and find out where its traffic goes when nobody is using it. Do not ask the supplier. Measure it. If you have no way to measure it, that is your finding.

A backdoor that arrived from the factory

VulnCheck disclosed ENDLESSDOORS on 6 August, distributed through WaterISAC. It is CVE-2026-66747, a backdoor built into the firmware of routers made by Zbtlink, a brand of Shenzhen Zhibotong Electronics, also sold under the Wiflyer name.

This is not the residue of a compromise. The implant ships in the firmware and is started at boot by the vendor's own init script. VulnCheck puts the deployed base at at least 100,000 units worldwide and confirmed the backdoor in 21 firmware images across more than 20 models.

Every device calls out roughly every 35 seconds to a small set of hardcoded endpoints, on a channel with no authentication and no encryption. Whoever controls the destination, or sits anywhere on the path to it, can run commands as root or open an interactive root shell.

The consequence people miss: because the connection is outbound, a unit sitting behind several layers of firewall is exactly as exposed as one with a public IP address. The firewall never sees an inbound request to block, because there isn't one.

This is the class of cheap cellular equipment that integrators install at remote sites, on terminal yards and on small craft. Bought for connectivity, never evaluated as attack surface, rarely inventoried once it is on the wall.

Readers of issue 22 will recognise the shape of it. That issue covered a CISA alert about intrusions at water utilities where the way in was undocumented cellular modems fitted by operators, vendors and integrators, equipment that was never on anyone's network diagram. This is the other half of the same problem: not the modem nobody documented, but the router whose documentation was complete and beside the point.

What to do: You cannot patch a factory backdoor with a firewall rule. The fix is inventory. Find every Zbtlink or Wiflyer branded router on your estate, and stop treating outbound-only connectivity as a form of protection.

Seven weeks between the deadline and the names

CVE-2026-12569 is a deserialisation flaw in PTC Windchill PDMLink and PTC FlexPLM. PTC scored it 9.3, NVD scored it 9.8. It was exploited as a zero-day from early June, patched on 17 June, confirmed exploited in the wild the following day, and added to CISA's Known Exploited Vulnerabilities catalogue on 25 June with an unusually short federal remediation deadline: three days, closing 28 June.

All of that is old news. What happened this month is the publishing.

Clop posted 88 listings in the first half of August, in two waves. Forty on 5 August with the victim names masked, each one citing the CVE by name alongside the categories of data taken: databases, projects, CAD files, engineering drawings, PDF drawings, software backups. Then forty-five on 12 August with names attached, among them Shell, GE, Philips, Fiserv and Zebra.

Shell's entry, printed as Clop wrote it: "Engineering drawings, photos of the facilities, scans of facility testing reports, project plans. Total size: 89 Gb."

No shipyard, owner, port or marine equipment maker has been named. I want to be plain about that, because the temptation in this business is to find a maritime victim and lead with it. There isn't one. The argument here is about exposure class, not membership.

PLM systems are where ship designers, yards and equipment makers keep their drawings, bills of materials and CAD files. That is the same category of data Shell just lost 89 gigabytes of. The KEV deadline closed seven weeks before those names became public, which means every organisation still exposed today made that choice with the warning already in hand and the patch already available.

One caution if you go looking yourself. The figure of "43 victims" circulating in press coverage is a relay of Clop's own claim, not an audited count, and it does not match what our own mirror of the leak site recorded. Attribute it to whoever is citing it.

What to do: Do not ask whether anyone in shipping is on Clop's list. Nobody is. Ask your yard, your design office or your equipment supplier whether they patched Windchill before 28 June. It is one question in one email and the answer is binary.

In case you missed it

  • The Netherlands switched on its Cyberbeveiligingswet on 15 August with no transition period at all. Around 8,000 organisations are in scope from day one, with maximum fines of 10 million euro or 2% of worldwide turnover for essential entities. Maritime sits in NIS2 Annex I as a high-criticality transport subsector, so Rotterdam-area port operators, terminals and maritime logistics firms are in scope. If your own member state is still finishing transposition, read the Dutch approach as the marker: nobody is offering a grace period as a courtesy.

  • India announced a Bureau of Port Security under its Merchant Shipping Act 2025, at a national conference with around 140 participants from the ports ministry, the home ministry, the Navy, the Coast Guard and state maritime boards. Indian coverage of the conference cited the North Carolina ports attack by name within 48 hours of it happening.

Coming up

  • Maritime Security West — San Diego, 31 August to 2 September. Port cyber, operational technology and Coast Guard cooperation.

  • DNV Maritime Cybersecurity Summit — Hamburg, 1 September, immediately before SMM Hamburg on 1–4 September.

  • Cybersecurity and Digital Risk Management in the Port Sector — online, 31 August to 25 September. An OAS Inter-American Committee on Ports course, running four weeks on a virtual platform. Worth a look if the honest answer to Story 2 is that nobody on your team currently owns the question.

  • ION GNSS+ — Orlando, 14–18 September. The technical GNSS conference rather than the maritime one, which is usually where the interference work gets presented first.

  • Uncrewed Naval Systems Conference — Tróia, Portugal, 13–14 October. After this week's first story, the supply chain behind uncrewed vessels is a more interesting question than the vessels.

Number of the week

  • 35 seconds — the interval at which a router with a factory-installed backdoor calls home, regardless of how many firewalls you put in front of it.

Resource of the week

CISA's Known Exploited Vulnerabilities catalogue
cisa.gov/known-exploited-vulnerabilities-catalog

Story 3 turns on a date. The PTC flaw entered this catalogue on 25 June with a three-day federal remediation deadline, and the victim names appeared seven weeks after it closed. The catalogue is where that warning lived, in public, the whole time.

It is free, it downloads as CSV and JSON, and it lists only vulnerabilities CISA has confirmed as exploited in the wild rather than everything with a high score. That makes it short enough to be useful. The practical move is not to read it yourself but to send it: pick your yard, your design office or your integrator, and ask whether anything in their stack appears on it.

Two limits worth knowing before you lean on it. The remediation deadlines bind US federal civilian agencies and nobody else, so for you they are a signal about severity, not an obligation. And confirmed exploitation is a high bar to clear, which means the catalogue is always behind reality rather than ahead of it. Something missing from the list has not been cleared. It has only not been caught yet.

Want more depth?

Maritime Cyber Intelligence Brief covers what the weekly cannot: full incident timelines, regulatory analysis, GNSS threat data, and OT advisory breakdowns. The latest issue is a free preview.

Read of the week

"Drift into Failure" by Sidney Dekker — Dekker's argument is that serious accidents in complex systems usually happen in organisations where nothing was broken, nobody was negligent, and every certificate was current. The failure is not a component. It is the slow, reasonable, well-documented drift of an organisation away from the reality it thinks it is describing. Read it after this week's first story, where a camera cleared its compliance paperwork and phoned an address in China, and both of those things were true at once without anyone lying.