Skip to main content
Return to Investigación Profunda de TrendAI™
Attack surface managementIoT & endpoints

Rethinking the External Attack Surface: Managing the Growing Risk of Open Cyber-Physical Data

China-aligned operational relay box (ORB) infrastructure is harvesting open sensor data at scale, and most defenders can't see it. Our report dives into how these ORBs can use open telemetry for data collection and other purposes.

IoT & smart devicesASM ASRM

Key Takeaways

  • We observed nodes in suspected China-aligned operational relay box (ORB) networks repeatedly connecting to publicly exposed radio receivers, weather stations, cameras, and other cyber-physical telemetry sources. This shows how traffic relay infrastructures can also support open data collection at scale.
  • Individually benign data can reveal sensitive activity when correlated across sources and over time. Around Operation Epic Fury, commercial vendors showed how open data could be fused into detailed situational awareness without compromising a defended network.
  • The exposure extends beyond governments and defense organizations. For enterprises, open telemetry can reveal supply chain relationships, production activity, and other operational patterns, often through third-party systems that fall outside traditional asset inventories and risk models.
  • Organizations should treat open cyber-physical telemetry as an exposure class. External attack surface management (EASM), a cybersecurity approach for continuously discovering and assessing internet-facing assets, can help identify, monitor, and reduce risks created by externally accessible systems and technologies.

Operation Epic Fury, the U.S. military campaign against Iran’s military infrastructure launched on February 28, 2026, highlighted how openly available commercial data can be assembled into military intelligence. A Chinese commercial AI vendor, Jing’an Technology, published a 53-day timeline of the U.S. force’s buildup and the strike itself, using open-source intelligence (OSINT) to build situational awareness. A second vendor, MizarVision, posted annotated submeter imagery showing where U.S. forces were based and how they were positioned, which was released on social media both before and during the operation. The reconstructions drew on signals that included open flight and vessel telemetry, radio audio posted by hobbyists, and commercial satellite imagery. These signals were available to anyone who chose to collect them. Western intelligence later assessed that such data was operationally consumed by Iran’s Islamic Revolutionary Guard Corps (IRGC) Aerospace Force for targeting. This shows that open data is redefining the value of intelligence collection.

The sensors and disclosures that organizations and states made mandatory for safety, market efficiency, and scientific cooperation now form a continuous, machine-readable picture of cyber-physical activity. State-aligned commercial vendors fuse that picture into operational intelligence at scale. The security frameworks that most organizations rely on do not yet recognize the resulting exposure as risk they should also own.

In this research, we dive into how suspected China-aligned operational relay boxes (ORBs) use open telemetry for data collection and possibly other purposes. We have been monitoring some ORB networks for quite some time, as well as the activities of their nodes. Through this, we observed interesting behavior: many of the ORB nodes had repeated connections to software radio receivers, weather stations, and other sources of physical signals, including video cameras. We assess that this activity stands behind a larger-scale intelligence collection that could be part of a bigger operation.

Our recommendations

The full guidance is in the technical brief attached. The headline items, in priority order, are the following:

  1. Treat telemetry as an emission, not a record. A sensor reading a disclosure or publication without authentication is a security problem because more granular and detailed telemetry can lead to greater exposure risk. Organizations should build an open-telemetry exposure register alongside their existing IT asset register.
  2. Audit associated-asset emissions, not just the organization’s primary assets. The emissions of suppliers, contractors, escorts, regulatory disclosures of power purchases, and the cadence of commercial imagery over sites all are areas of exposure even when they are not directly the organization’s assets.
  3. Monitor ORB-style scraping of telemetry endpoints the organization operates or relies on. If the organization publishes transparency feeds of open signals data, monitor for increases in industry-scale scraping from identified residential-IP devices. Signatures for this behavior can be created.
  4. Treat OSINT-fusion vendors as a cyber threat intelligence (CTI) category. For organizations deemed at risk of such telemetry surveillance (commercial and public sector), maintain a watchlist of commercial fusion vendors operating in adversary-aligned jurisdictions. Monitor their public outputs and feed self-reported activity into the organization’s strategic risk function. Jing’an’s 53-day timeline was, for the organization it was tracking, a CTI feed that those organizations could consume themselves.

Find more technical details in our full report.