Skip to content

runZero 4.9: IT/OT Topology & Attack Path Mapping

In the world of security marketing, “visibility” has become an overused buzzword. But for defenders managing converged IT/OT environments, true visibility isn’t just a list of IPs—it is about decoding the functional DNA of your infrastructure.

For years, the industry has relied on the “segmentation illusion”—the comfortable but dangerous assumption that critical industrial assets remain safely air-gapped behind firewall layers. Today, geopolitical dynamics and AI-driven attacks target these exact operational boundaries, turning minor IT compromises into total factory shutdowns.

The release of runZero 4.9 shatters this illusion, delivering the high-fidelity security intelligence required to find lateral traversal vectors, harden critical choke points, and secure converged infrastructure before exposures are exploited.

1. Map the Unmappable: Sub-Asset Discovery

Most industrial security tools stop at the protocol gateway. runZero goes further, utilizing safe, protocol-native queries to peer behind gateways (including Modbus, BACnet, KNXnet, and EtherNet/IP) to unmask downstream PLCs and field-level devices sitting on serial or fieldbus networks.

  • Granular Field Topology: If a gateway masks 20 downstream PLCs, runZero enumerates the entire downstream infrastructure safely, without requiring endpoint agents or credentials.
  • Purpose-Built Safety: Validated by the U.S. Department of Energy’s National Renewable Energy Laboratory, our scan engine uses protocol-specific throttling to safely extract firmware versions, screenshots, and secondary interfaces.

2. Interactive Attack Path Mapping & Scalable Topology

Defenders can now visualize trajectories from initial corporate breach to core physical impact using dynamic 2D and 3D maps that comfortably scale to hundreds of thousands of active nodes.

Trace the Trajectory

Set explicit sources and targets to visualize the precise pivot points and bridging devices an adversary would use to traverse segmented zones.

Multi-Homed Detection

Automatically isolate and flag dual-nic systems, rogue laptops, or unmanaged assets bridging IT and production networks simultaneously.

Spot the Anomalies

Instantly flag out-of-place assets—like a standard corporate Windows machine sitting inside a highly segmented industrial production zone.

3. Deep Protocol Fingerprinting & Asset Classification

This release introduces an expanded library analyzing over 220 distinct protocols, providing comprehensive analysis across “insecure by design” industrial networks such as Siemens S7comm, Modbus, BACnet, and EtherNet/IP.

  • Geolocate Assets Instantly: Pinpoint hardware locations using public and egress IP data, adding adjacent environment context to remote facilities.
  • Real-World Prioritization: Focus engineering resources on true architectural exposures rather than non-critical vulnerabilities.
  • Sleek UI/UX Enhancements: Features a fully overhauled interface optimized for massive environments, complete with native dark and light modes to reduce strain during late-night SOC operations.

Technical Case Study: IT-Origin with OT Blast Radius

The greatest threat to industrial operations is rarely a highly customized exploit; it is a forgotten, multi-homed asset that shatters the segmentation illusion.

  1. Initial Foothold: An attacker exploits an internet-facing security camera running out-of-the-box port forwarding rules.
  2. The Pivot: The attacker discovers a technician’s laptop on that same wireless segment. The laptop is physically connected to the factory LAN for maintenance but leaves Wi-Fi and RDP enabled for external internet access.
  3. Lateral Traversal: Bypassing the core firewall completely through this active bridge, the attacker reaches the production subnet and enumerates a Rockwell Automation controller via EtherNet/IP (CIP).
  4. Operational Impact: The attacker sends an unauthorized “Stop” command through the gateway, halting a $100M production line.

The runZero Defensive Edge: runZero 4.9 maps this entire trajectory before it happens—flagging the multi-homed laptop as a critical choke point, identifying the active RDP vulnerability, and peering behind the protocol gateway to reveal the downstream field devices at risk.

The Statistical Reality: In recent representative assessments of large-scale manufacturing environments, runZero discovered that 30% of all OT assets reside only one hop away from an internet-exposed device, and 90% are within two hops.

Unified Truth for Converged Operations

Whether you manage a utility grid, a global manufacturing footprint, or a telecom network, runZero bridges the visibility gap between IT and OT security operations. We don’t just log nodes; we map reachability and clarify risk.

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Portnox AgentP: Real-Time Endpoint Enforcement

Mobile Device Management (MDM) provides an essential baseline for configuration, but it lacks the real-time capabilities required to secure network boundaries. Portnox AgentP bridges this operational gap, delivering immediate posture assessment and automated remediation on every network transmission.
Architectural Insight: AgentP does not replace Microsoft Intune or Jamf. It transforms their passive compliance snapshots into instantaneous, network-level access control.
 

Operational Architecture Pillars

Transmission-Triggered NAC
Evaluates system posture—including open listening ports, active registry keys, and running processes—the moment a device attempts network access.
Auditable Playbooks
Executes granular, admin-defined controls to automatically terminate forbidden processes, isolate ports, or disable unauthorized USB peripherals.
Abstracted 802.1X
Eliminates SCEP and complex MDM profile infrastructure by unifying certificate distribution and automatic renewal into a single engine.
 

Capability Matrix

Security VectorsStandard MDM CapabilityPortnox AgentP Capability
Enforcement CadenceScheduled intervals (Hours)Instantaneous / Per transmission
Automated RemediationAlerting / Software blockingActive script execution / Device isolation
Network IsolationApplication-level containerizationHardware and layer-2/3 network containment

 

Securing the BYOD Boundary

By bypassing the heavy management profiles required by traditional MDM deployments, AgentP ensures a clean cryptographic separation between corporate assets and personally owned devices, maximizing edge security without infringing on user privacy.

Introducing NordPass Authenticator for Business

Multi-factor authentication is a critical defense layer, but traditional secondary apps create massive operational friction. NordPass Authenticator embeds secure TOTP generation directly within your company’s password vault, backed by biometric enforcement.
Patented Innovation (US Patent No. 11,528,130): NordPass utilizes a unique Stateless System To Protect Data, delivering true multi-factor isolation (Knowledge + Possession + Inherence) within a single streamlined deployment.
 

Engineered for Modern Threat Surfaces

 

MFA Fatigue Immunity
Prevents blind approval loops by restricting token generation to explicit, user-initiated biometric unlocking events.
 
Biometric Enforcement
Unlike standard extensions that leak tokens on an unlocked desktop, NordPass requires Face ID or touch confirmation to reveal codes.
Secure Token Sharing
Enables seamless collaboration on shared corporate accounts without resorting to unencrypted chats or spreadsheets.
 

Operational Transparency

By consolidating credential storage and secondary validation tokens under a unified console, IT administrators gain absolute transparency over user security posture, making security compliance an enforceable habit rather than an assumption.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Leadership Spotlight: Jill Miracle | CRN 2026

Keepit, the leader in independent, cloud-native data protection, is proud to celebrate Jill Miracle, Director of Channel Sales for the Americas, for her recognition on the prestigious 2026 CRN Women of the Channel list.

Strategic Impact: “Jill has fearlessly stepped up to lead our efforts in the Americas. We are proud to see her impact recognized by the wider channel community.” — Jan Ursi, VP of Global Channels
 

Commitment to a 100% Channel Model

In 2026, Keepit has solidified its position as the world’s most partner-friendly IT vendor. By operating a 100% channel-led go-to-market model, we ensure that our global success is shared directly with our Managed Service Providers (MSPs), resellers, and strategic alliances.

“Each honoree has demonstrated exceptional leadership and a commitment to bold, innovative strategies that fuel transformation, growth, and success for their organizations and the broader channel.”
Jennifer Follett, VP of U.S. Content, CRN
 

About the Honoree

Jill Miracle brings over two decades of enterprise technology and cybersecurity expertise to Keepit. Having held senior roles at Dell Technologies, EMC, and Nasuni, Jill is a recognized expert in building resilient partner ecosystems and driving high-performance regional execution.

CISO Briefing: Recovery at Machine Speed

Prevention is necessary, but in 2026, it is no longer sufficient. As AI-powered exploits shrink the gap between vulnerability and breach, recovery has transitioned from a backup function to a critical security pillar.
“Hope is not a security strategy. In a world of autonomous attackers and internal ‘AI vandalism,’ your only real shield is the ability to restore integrity and trust instantly.”
 

The Four Pillars of Resilience

Independence
Reduce vendor-lock and cross-processor risk to simplify recovery.
Immutability
Backups must be tamper-proof, even against compromised admin credentials.
Detection
Identify anomalies and large-scale corruption before damage spreads.
Precision
Restore specific items or records without a full environment rollback.
 

Pressure-Test Your Strategy

  • Can you identify the last known-good state of your SaaS data with proof?
  • If your admin account is compromised, are your backups safe from deletion?
  • Can you restore only what was affected, quickly and granularly?

Clone Phishing: Cyber Resilience Briefing

Clone phishing is a surgical social engineering tactic where an attacker intercepts a legitimate email and creates a perfect replica. By replacing safe attachments with malware, they exploit the trust you’ve already established with colleagues and service providers.

Tactical Analysis: Clone phishing often succeeds because it mimics a “resend” or “correction.” Our psychological defenses are lower when we believe a trusted sender is simply fixing a corrupted file or an incorrect link.
 

Strategic Comparison

Attack TypePrimary FoundationExecution Style
Spear PhishingTargeted ResearchNew, bespoke email threads
Clone PhishingExisting TrustResends or “updated” links

 

The Zero Trust Checklist

  • Verify the Sender: Check the “Reply-To” field for technical inconsistencies.
  • The Hover Test: Always inspect destination URLs before clicking any link.
  • Credential Binding: Use NordPass to ensure credentials are only entered on verified domains.
  • Multi-Channel Confirmation: Verify suspicious “corrections” via Slack or phone.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Nord Security
The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

OpenClaw Security Guide

Security Alert: Prompt injection is no longer just a linguistic trick—it is a functional exploit that can trigger unintended system-level actions.
 

Core Security Pillars

1. Environment Isolation
Run agents in containerized sandboxes (Docker/VMs) to prevent host compromise.
2. Identity Governance
Deploy scoped “Burner” accounts for all API integrations to limit blast radius.
3. Human-in-the-Loop
Establish manual approval gates for high-impact system commands and financial actions.
 

Operational Checklist

Focus AreaSecurity Action
NetworkBind service to 127.0.0.1; restrict external exposure.
AccessEnforce Principle of Least Privilege (PoLP) for all file access.
MonitoringLog all agent commands and API interactions for real-time auditing.

By leveraging NordLayer, teams can apply network-level segmentation and device posture security to ensure their AI environments remain resilient against emerging agentic threats.

ESET Research uncovers CallPhantom scam on Google Play: Fake logs for real money

  • A new Android scam, CallPhantom, falsely claims to provide access to call logs, SMS records, and WhatsApp call history for any phone number in exchange for payment.
  • We identified and reported 28 separate CallPhantom apps on Google Play, cumulatively downloaded more than 7.3 million times.
  • Some CallPhantom apps sidestep Google Play’s official billing system, complicating victims’ refund efforts.

BRATISLAVA, KOŠICEMay 7, 2026 — ESET researchers have uncovered fraudulent apps on Google Play that claim to provide the call history “for any number.” The offending apps, which ESET named CallPhantom based on their false claims, purport to provide access to call histories, SMS records, and even WhatsApp call logs for any phone number. To unlock this supposed feature, users are asked to pay — but all they get in return is randomly generated data. ESET’s investigation identified 28 such fraudulent apps, cumulatively downloaded more than 7.3 million times. As an App Defense Alliance partner, we reported our findings to Google, which removed all of the apps identified in this report from Google Play. 

The CallPhantom apps mainly targeted Android users in India and the broader Asia Pacific region. Many of the apps came with India’s +91 country code preselected, and support UPI, a payment system used primarily in India.

“In November 2025, we came across a Reddit post discussing an app named Call History of Any Number, found on Google Play. Unsurprisingly, our analysis showed that the ‘call history’ data provided by this app is entirely fabricated — the app generates random phone numbers and matches them with fixed names, call times, and call durations, which were embedded directly in the code,” says ESET researcher Lukáš Štefanko, who uncovered the CallPhantom fraud.

In general, CallPhantom apps have a simple user interface and do not request any intrusive or sensitive permissions — they don’t need to. Coincidentally, they do not contain any functionality capable of retrieving actual call, SMS, or WhatsApp data.
In the CallPhantom apps ESET analyzed, researchers saw three different payment methods used, two of which are in violation of Google Play’s payments policy. Some of the apps relied on subscriptions via Google Play’s official billing system. Others relied on payments via a third party; in some cases, payment card checkout forms were included directly in the CallPhantom apps.

The fees requested for the fake service differ widely across the apps. The apps also appear to offer different subscription packages, such as weekly, monthly, or yearly services, with the highest requested price sitting at US$80. For the lowest “subscription tier,” the average requested price was €5.

In general, subscriptions purchased through the official Google Play billing system can be canceled. For the 28 apps described in this blog post, existing subscriptions were canceled when the apps were removed from Google Play. In some cases, refunds for Google Play purchases are possible.

If the purchase was made outside of Google Play — for example, by entering payment card details inside the app or by paying via third-party services — then Google cannot cancel the subscription or issue a refund, and users have to contact their payment provider.

For a more details about CallPhantom, check out the latest ESET Research blog post, “Fake call logs, real payments: How CallPhantom tricks Android users,” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

Examples of CallPhantom apps found on Google Play

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Simplifying Monitoring Architecture | Strategic Guide

The Elegance of Simplification

Strategic Architecture for Complex Monitoring Environments

In technology, we often mistake complexity for power. However, a monitoring platform that requires a dedicated team just to keep it alive has lost its way. Pandora FMS 800 LTS Aquarius introduces a streamlined architecture designed to reduce operational friction and maximize SRE agility.

“A tool that is complex to operate is, by definition, a fragile tool. Real power lies in intelligent consolidation, not infinite fragmentation.”

 

The Operational Trinity

Network Server
The versatile backbone. Consolidates WMI, remote scripts, and web UX into a single, agile role.
High Performance Server
The speed specialist. Engineered for 15-second polling intervals in large-scale centralized architectures.
Heavy Server
The data heavyweight. Manages inventory, vulnerability scans, and complex integrations without impacting core polling.

 

Maintainability as a Survival Requirement

Updating a critical system shouldn’t involve “tension and cold sweat.” The new Pandora_Supervisor acts as a conductor, managing updates and restarts transparently to ensure you never go blind during a maintenance window.

  • Efficiency: No CPU cycles wasted on redundant processes.
  • Scalability: Growth in nodes should not lead to growth in maintenance hours.
  • Resilience: Specialized servers allow for granular load balancing and high availability.

Saily Review: The Future of Global eSIM Connectivity

Managing mobile data during international travel has traditionally been a choice between overpriced roaming or the hassle of local SIM cards. Saily, the new eSIM solution from Nord Security, offers a third way: affordable, secure, and instant digital connectivity.

 

Why Saily Stands Out

  • Global Reach: Access high-speed data in over 200 destinations.
  • Security First: Includes built-in web protection and ad-blocking to preserve data and privacy.
  • User-Centric Plans: Flexible options ranging from 1GB starters to full Unlimited tiers.

Saily Ultra: The All-In-One Subscription

For the frequent globetrotter, Saily Ultra ($29.99/mo) bundles 30GB of data with premium travel perks like airport lounge access and the full Nord Security Suite (VPN, Pass, Locker, and Incogni).

 

Quick Summary

CategoryDetails
Platform SupportiOS, Android, 24/7 Live Chat
Entry PriceCountry plans from $2.99
Special FeaturesCredits & Referrals, Auto Top-up, Business Dashboard
Our Score4.6 / 5

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.