Forescout Vedere Labs analyzed 47,700 network segments encompassing more than 2.5 million devices at 209 organizations and found extensive mixing of enterprise IT, operational technology (OT), IoT, and internet-of-medical-things (IoMT) assets. Only 13% of segments containing OT devices were dedicated exclusively to OT, while only 6% of IoMT-containing segments were limited to medical devices; IP cameras and point-of-sale environments were among the most frequently co-segmented with workstations and servers.
The mixed and oversized segments increase the potential blast radius of a single compromised device, enabling lateral movement from exposed or weakly secured connected assets into corporate or critical operational systems. Forescout cited ransomware and camera compromises as examples of this risk and urged organizations to maintain continuous asset inventories, identify risky device-convergence zones, isolate critical OT and IoMT assets in smaller purpose-built segments, restrict unnecessary inter-segment traffic, and monitor for segmentation drift.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
The pro-Russian hacktivist group NoName057(16) conducted examples of exposed IP-camera compromises against Estonian and Canadian targets in late August and early September.
Forescout tracked more than 300 instances of hacktivist groups gaining control of exposed IP cameras at targeted organizations.
The Akira ransomware group used poorly segmented IP cameras to bypass endpoint detection and response controls, demonstrating how camera access could provide a route into corporate networks.
Forescout Vedere Labs analyzed 47,700 network segments across 209 organizations, finding that OT, IoMT, IoT, and enterprise IT devices were frequently co-segmented. The study found that only 13% of OT-containing segments and 6% of IoMT-containing segments were exclusively dedicated to those device categories.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
itsecurityguru.org
Open sourcesecurityweek.com
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.