Kaspersky researchers reported that internet-exposed Global Navigation Satellite System (GNSS) receivers remain accessible worldwide, creating a direct security risk to organizations that rely on precise positioning, navigation, and timing data. The exposed devices can often be reached remotely through web interfaces and management services, raising the possibility of unauthorized access, configuration changes, service disruption, or manipulation of timing and location data used by critical infrastructure, telecommunications, transportation, and industrial environments.
The findings indicate that weak exposure controls and poor hardening leave GNSS receivers vulnerable to compromise at scale, with potentially significant downstream effects for dependent systems. Security teams were urged to identify publicly reachable receivers, restrict management access, segment these assets from broader networks, and review authentication and monitoring controls to reduce the risk of tampering with systems that depend on trusted satellite-derived data.

Map this exposure pattern across your cloud, code, and identities.
1 event from the most recent confirmed update back to the earliest known activity.
Securelist published a report describing the global security threat posed by internet-exposed GNSS receivers. No additional dated real-world events are provided in the reference content.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.