Researchers have recently demonstrated that it is possible to imitate the signals used to instruct trains to slow down or stop, revealing serious weaknesses in long-standing railway safety systems. Modern trains rely not only on the human conductor but also on automated mechanisms that intervene during emergencies. However, many of these systems were designed decades ago, long before cybersecurity threats existed, making them vulnerable to interference. In Spain, for example, the ASFA protection system still follows principles established in the 1960s, a time when digital attacks were not part of the threat landscape. Driven by curiosity and concern, two Spanish researchers recreated how trains communicate with track-side components by examining publicly available documents and experimenting with simple materials. Their tests showed that the inductive beacons beneath the rails — known as balises — could be imitated with basic homemade circuitry. Because ASFA relies on analog signaling without any authentication, a spoofed balise tuned to the right frequency could mislead a passing train, triggering abrupt stops, false speed instructions, or other unsafe behaviors. They also noted that tampering with real balises would require minimal effort, as their wiring is often exposed and lightly protected. The pair extended their study to legacy railway systems across Europe and beyond, finding similar patterns of outdated design and insufficient safeguards. While newer standards like the European Rail Traffic Management System (ERTMS) introduce more advanced, digital signaling, those improvements also expand the attack surface. Digital communication between train and track opens the door to jamming, spoofing, relay manipulation, and even data interception, especially if operators fall back to older systems during faults or emergencies. Although modernizing railway infrastructure would require substantial investment and political will, the researchers emphasize that the risks can no longer be ignored. As rail networks grow more interconnected and threats evolve, strengthening signaling security is essential to protect passengers, operators, and national transport systems.
A critical security issue has been identified in Google Cloud’s Vertex AI platform that allows low-privileged users to escalate privileges and compromise high-permission service ...
A set of critical vulnerabilities has been identified in CrewAI, a widely used platform for building multi-agent AI systems. These flaws expose environments to prompt injection att...
A critical security flaw in Oracle WebLogic Server has rapidly become a prime target for attackers worldwide. Identified as CVE-2026-21962, the issue carries the highest possible s...