< Back to all clusters
[TECHNOLOGY] · United States · 2 sources

started · updated

NASA urged to strengthen cybersecurity amid spacecraft software vulnerabilities

The U.S. Government Accountability Office (GAO) has urged NASA to strengthen its cybersecurity risk management following concerns regarding increasing threats to spacecraft and space systems. A GAO report highlights that NASA has yet to implement a priority recommendation to conduct an organization-wide cybersecurity risk assessment. The agency currently has 46 open recommendations, none of which have been implemented since August 2025.

Separately, NASA has patched a security vulnerability in its AIT-GUI software, an open-source ground control tool used to monitor spacecraft and transmit instructions. Cybersecurity researcher Yuval Elbar of Cycode discovered that the flaw allowed unauthenticated users to execute commands, run scripts, or launch command sequences on mission control systems. The vulnerability existed in versions up to 2.5.1 of the software and could be exploited without direct login access if the server was exposed beyond intended boundary controls.

Entities

Cycode · NASA · U.S. Government Accountability Office