Carnegie Mellon U, University of Pennsylvania Partner To Secure Commercial Tech for DARPA

Researchers at Carnegie Mellon University's (CMU) CyLab and the University of Pennsylvania will explore ways to improve the security of commercial projects used by the United States Military, thanks to a four-year $3.9 million grant from the Defense Advanced Research Projects Agency (DARPA).

The United States Department of Defense uses commercial-off-the-shelf (COTS) technology, such as routers or printers, "for everything from information technologies to retrofitting the F-15E Fighter with new digital video recording equipment," according to a CMU news release.

"COTS consists of complex stacks where a weakness at any level can endanger the entire system," said CyLab Researcher David Brumley, in a prepared statement.

"For example, vendors or potentially malicious employees can remotely log in with the default backdoor passwords and hackers can break in via vulnerabilities," Brumley added. "We are working to identify the attack surface of the system, and we propose that achieving these goals requires a holistic systems approach."

Located in Carnegie Mellon University's College of Engineering, CyLab has campuses in Silicon Valley and Pittsburgh. CyLab "establishes public-private partnerships to develop new technologies for measurable, secure, available, trustworthy and sustainable computing and communications systems," according to information released by the program.

CyLab's areas of expertise are technology transfers to and from the public and private sectors, preparation of information assurance professionals, and awareness programs and tools.

More information about CyLab is available at cylab.cmu.edu.

About the Author

Joshua Bolkan is contributing editor for Campus Technology, THE Journal and STEAM Universe. He can be reached at [email protected].

Featured

  • abstract colored blocks

    OpenAI Drops Sora Short-Form AI Video Platform

    OpenAI is reportedly dropping Sora, its generative AI model that creates short video clips from text prompts, images, or existing video inputs. The move upends the company's December partnership with The Walt Disney Company.

  • digital lock on a virtual background

    Encryptionless Extortion on the Rise as Ransomware Groups Shift Tactics

    Ransomware attacks continued to climb in 2025 as attackers increasingly timed operations around year-end staffing gaps and shifted away from traditional file encryption, according to new research from NordStellar.

  • glowing brain above stacked coins

    The Higher Ed Playbook for AI Affordability

    Fulfilling the promise of AI in higher education does not require massive budgets or radical reinvention. By leveraging existing infrastructure, embracing edge and localized AI, collaborating across institutions, and embedding AI thoughtfully across the enterprise, universities can move from experimentation to impact.

  • A man stands at the threshold of a wide open door, looking outward into a glowing, abstract digital landscape filled with light and network‑like patterns

    Shadow AI Isn't a Threat: It's a Signal

    Unofficial AI use on campus reveals more about institutional gaps than misbehavior.