IC Technology & Surveillance — 2026-05-10

CISA Flags Data-Theft Vulnerability in NSA-Built OT Networking Tool

CISA issued an advisory on April 29 warning of an XML parsing vulnerability in GRASSMARLIN, an open-source network-mapping tool the NSA built for ICS and SCADA environments and retired in 2017. According to CISA's advisory as reported by SDxCentral, crafted session data triggers improper XML handling that can expose sensitive information; SecurityWeek described the exploitation method as out-of-band file exfiltration. Security researcher Anna Quinn detailed in a GitHub post that the parser's insufficient hardening allows malicious requests when opening stored sessions. CISA confirmed no patches will be issued and recommended isolating control-system networks from business networks and minimizing device exposure.

Analysis
GRASSMARLIN session files contain device inventories, IP schemas, and communication baselines that give any adversary conducting OT reconnaissance a ready-made target package, compressing the targeting timeline for networks otherwise opaque from outside the perimeter. CISA's confirmed no-patch position, corroborated across three secondary outlets with SDxCentral citing advisory language directly, transforms this into a permanent condition. The recommended mitigations require architectural changes most legacy OT environments cannot implement quickly. Any adversary capable of exploiting an XXE flaw in a retired tool likely already holds superior network mapping intelligence, making session-file exfiltration a redundant collection target. Community-contributed fixes represent the most plausible remediation path, and whether any resolution materializes by approximately 8 August 2026 is genuinely uncertain.
1 sources
  1. CISA flags data-theft bug in NSA-built OT networking tool - The Register

View in full brief →

UNCLASSIFIED // OPEN SOURCE