Illustration of the drone swarm system that uses multi-view imaging for 3D smoke plume characterization. Credit: arXiv (2025). DOI: 10.48550/arxiv.2505.06638
Plumes of smoke drifted up from a fire steadily taking over a 30-acre prairie at Cedar Creek Ecosystem Science Reserve, north of the Twin Cities. Amid the haze, five black drones zipped around.
More than 150 feet below the flying robots, research student Nikil Krishnakumar raised the controller in the air. The work has been published on the arXiv preprint server.
“It’s all autonomous now,” he said. “I’m not doing anything.”
The aerial robotic team’s mission: examine the smoke from the prescribed burn and send the data to a computer on the ground. The computer then analyzes the smoke data to understand the fire’s flow patterns, Krishnakumar said.
The University of Minnesota project is the latest research into using artificial intelligence to detect and track wildfires. The work has become more urgent as climate change is expected to make wildfires, like those that devastated Manitoba this summer, larger and more frequent.
NOAA’s Next-Generation Fire System consists of two satellites 22,000 miles above the equator that detect new sources of heat and report them to local National Weather Service stations and its online dashboard. Earlier this year, the satellites were credited with spotting 19 fires in Oklahoma and preventing $850 million in structure and property damage, according to the agency.
In Minnesota, Xcel has installed tower-mounted, AI-equipped high-definition cameras near power lines in Mankato and Clear Lake. Thirty-six more are planned. When a fire is detected, local fire departments are notified.
Krishnakumar and other members of the U’s research team performed their 11th trial at the U’s field station in East Bethel on Friday, with notable improvements from their previous attempts.
The first-generation drones crashed several times during previous field tests, Krishnakumar said. The team upgraded sensors for better data collecting and autonomous steering, and improved the drones’ propulsion by making them bigger and fitting them with better propellers.
“The big picture is one day these drones can be used to understand where the wildfires go, how they behave and to perform large-scale surveillance of wildfires,” Krishnakumar said. “The major challenge we’re trying to understand is how far these smoke particles can be transported and the altitude at which they can go.”
Understanding the behavior of particles like embers can help firefighters prevent wildfires from spreading, said Yue Weng, another researcher on the team.
Though the project has a way to go before it can be used for large-scale wildfires, the research represents a significant step toward using fully autonomous drone systems for emergency response and scientific research missions, said Jiarong Hong, professor at the University of Minnesota’s Department of Mechanical Engineering.
This year, 1,200 wildfires have been recorded in Minnesota so far, according to the state Department of Natural Resources. On a smaller scale, the technology could also be used to better manage prescribed burns, Hong said. Between 2012 and 2021, prescribed burns that went out of control caused 43 wildfires nationwide, according to the Associated Press.
“To characterize and measure particle transport in the real field is very challenging. Traditionally, people do small-scale lab experiments and study this at a fundamental level,” Hong said. “Such an experiment doesn’t capture the complexity involved in the real field environment.”
Smoke changes direction with the wind. Deploying multiple drones—with one at the center managing the four around it—enables them to navigate in the air without human intervention, Hong said.
The 11-pound drones were custom-built by the students to autonomously collect particle data. Future improvements to the project include collecting more data and extending the battery life of the drones. The drones are currently able to operate in the air for about 25 minutes, less in colder temperatures, Hong said.
“We have drones flying out at different heights, so we can actually measure the particle composition at different elevations at the same time,” Hong said.
“Particles are in a very irregular shape and some of them are porous and have varying levels of density. But we have been able to characterize their morphology and shape for the very first time.”
More information:
Nikil Krishnakumar et al, 3D Characterization of Smoke Plume Dispersion Using Multi-View Drone Swarm, arXiv (2025). DOI: 10.48550/arxiv.2505.06638
2025 The Minnesota Star Tribune. Distributed by Tribune Content Agency, LLC
Citation:
Researchers launch smoke-sensing drones that one day could fight wildfires (2025, November 3)
retrieved 3 November 2025
from https://techxplore.com/news/2025-11-drones-day-wildfires.html
This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no
part may be reproduced without the written permission. The content is provided for information purposes only.
Setup was relatively quick and painless. You just have to unbox four speakers, a soundbar, and a subwoofer, attach their power cables, and plug in everything. Pairing happens through the LG ThinQ app, which allows you to set up the Sound Suite system and tune it to exactly where you’re sitting in the room using your cell phone’s microphone.
You can also set up each speaker to play music and group it with any other LG smart speakers you might have around your home, like the more affordable $250 M5 bookshelf speaker, to create a whole-home system.
Once all the components were synced, I plugged the soundbar into the C5 OLED via HDMI, and was able to easily control everything via the TV remote’s volume and mute buttons. More in-depth settings had to happen in the app, but if you’re anything like me, this won’t become a regular chore. You’ll set it how you like it once and move on. While the pairing functionality with the LG TV was nice, it’s not required–the eARC port lets the Sound Suite work perfectly with any modern TV.
The bar itself runs the show, with a black-and-white display on the far left that shows your mode and volume, among other settings. In the center of the bar and below each speaker, an LED light strip that also shows you the volume when you change it, which is a nice touch.
Getting Musical
Photograph: Parker Hall
The sound of the LG Sound Suite is full and cinematic, thanks in no small part to the extra dedicated speakers. Most competitors lack front left and right, simply opting to use the soundbar for these channels. As such, the width and breadth of the soundstage were bigger than most competitors I’ve tried, with only Samsung’s flagship HW-Q990F as a real contender. Even the Samsung lacked the lower-frequency audio quality that these LG speakers provide.
On 27 April, the government backed security certification scheme, Cyber Essentials v3.3, takes effect and multi-factor authentication (MFA) becomes a pass-or-fail requirement for the first time.
If a cloud service your organisation uses offers MFA and you have not enabled it, you fail. No discretion, no partial credit, no route to remediate inside the assessment cycle.
This is the right call. I want to say that clearly, because what follows is a problem with the implementation, not the policy. MFA is the single most effective control against credential-based attacks, and the scheme has needed to stop tolerating its absence for a long time. The National Cyber Security Centre (NCSC), part of GCHQ, which developed Cyber Essentials and certification company, IASME have got this decision right.
But in the assessments we have conducted this year, I have seen two organisations that will hit a wall on 27 April, and I do not think they are unusual.
Train company could not deploy MFA
The first is a train operating company in the South East. Station operations rooms run on shared terminals where staff rotate through shifts in time-critical conditions. A transport union raised formal concerns that MFA would introduce delays at the keyboard that could affect train operations and, in their view, the safety of train movements.
The company listened and chose not to enable MFA in those environments. Under v3.2 they passed, with the relevant questions marked as non-compliant but not fatal. Under Cyber Essentials v3.3 they will fail.
Charity run by volunteers faces MFA hurdle
The second is a nationally known charity with hundreds of high street shops. The shops are staffed largely by volunteers many of whom work a few hours a week, and staff turnover is high.
The cost and management overhead of enrolling every volunteer onto MFA, using personal phones they may not have and authenticator apps they would not keep, was considered prohibitive. So MFA was never switched on. Same story: they passed under v3.2. Under v3.3 they fail.
Neither of these organisations is ignoring security. Both made considered decisions based on how their people actually work. The problem is not that they do not want to comply. It is that the standard toolkit of MFA methods, including SMS codes, authenticator apps on personal phones, and push notifications, does not fit a six-person shared terminal that has to be available in seconds, or a volunteer workforce that changes every week.
FIDO2 could offer solutions
The frustrating part is that there is a solution, and it is already proven in healthcare, manufacturing and retail. FIDO2 authentication delivered through NFC badge-taps lets a staff member authenticate in under two seconds: tap a badge, enter a short PIN, session opens.
It satisfies the MFA requirement by combining possession of the badge with knowledge of the PIN. It is faster than typing a password. Crucially, it is compliant, because each badge is enrolled as that individual’s unique FIDO2 credential, so the Cyber Essentials requirement for unique user accounts is met. Shared keys or shared PINs would not work. Individual badges do.
Need for better guidance
v3.3 explicitly recognises FIDO2 authenticators and passkeys as valid MFA methods. The compliance path is clear. What is missing is anyone telling the organisations most affected that this path exists.
That is the gap that must close. The NCSC and IASME have made the right policy decision; the scheme would be weaker without it.
But implementation guidance for shared-terminal, shift-based and high-turnover environments is thin, and these organisations are running out of time to find their way through it. Many of them hold Cyber Essentials because it is required for government contracts or in their supply chains; losing certification has a direct commercial cost.
The answer is not to soften the requirement. The answer is to make sure no one fails for lack of information about how to meet it.
Jonathan Krause is Founder and Managing Director of Forensic Control
Over the four-day Easter weekend of 18 to 21 April 2025, customers of British high street fixture Marks & Spencer (M&S) took to social media in droves to lament an apparent outage that was causing disruption to in-store contactless payments.
At first glance, the disruption appeared to be the result of a run-of-the-mill IT glitch that happens from time to time, but by Tuesday 22 April, it was starting to become apparent that something far more sinister was going on. M&S shut down multiple public-facing services, such as online shopping and in-store click and collect, and CEO Stuart Machin made the rounds of the morning news studios to confirm that the retailer had been hit by a cyber attack.
The incident was the first in a series of damaging attacks against UK retailers – all orchestrated in similar fashion via the systems of an unwitting third-party tech supplier – to come to light.
As the likes of Co-op and even Harrods were drawn in, Scattered Spider – the English-speaking hacking collective behind the attack – and associated groups such as Lapsus$ and ShinyHunters became household names.
Over the summer of 2025, the teen hackers turned their attention to other targets, hitting organisations operating in multiple verticals all over the world. The cyber crime spree arguably hit its zenith – or nadir depending on your point of view – with the August 2025 attack on carmaker Jaguar Land Rover (JLR), the repercussions of which continue to reverberate around the UK economy nearly eight months on.
But the chaos kicked off at M&S, with shelves left empty as store managers struggled with downed ordering systems, and homes across the nation going without upmarket picky teas, pig-shaped gummy sweets and caterpillar-themed cakes.
Third-party vulnerabilities: it started with a phone call
“A year on from the M&S attack, the numbers tell a stark story. Retail cyber attacks grew around 34% last year, and the trajectory since then suggests that figure has only climbed further,” says Check Point UK and Ireland head of enterprise, Charlotte Wilson.
“What the incident made clear is how the nature of the attack itself should be understood. The initial entry point at M&S, and at others like Jaguar Land Rover … was a phone call. Someone convinced a helpdesk operative to hand over system access by impersonating an employee. That was the door in, and it opened onto hundreds of millions of pounds of damage. The most expensive cyber attack in British retail history began with a conversation.”
Muhammad Yahya Patel, Huntress virtual chief information security officer (vCISO) and EMEA cyber security adviser, says it is precisely this relatively unsophisticated origin story that marks the M&S breach as a case study that every security team – whether working in retail or not – should have printed out and stuck on the wall.
“The attackers didn’t find a zero-day. They didn’t bypass a next-gen firewall. They picked up the phone, pretended to be an M&S employee and asked a third-party service desk to reset a password. That was it,” says Patel.
“Everything that followed, the Active Directory database exfiltration, the credential cracking, the ransomware deployment across VMware hosts – all of it flowed from lack of service desk processes.
“Perhaps the most sobering detail [is] the four individuals arrested by the NCA in July were aged 17 to 20. These weren’t nation-state actors with deep pockets and government backing. They were young, English speaking and highly effective at finding the gap between an organisation’s technical controls, people and processes.”
The lasting effect on boardroom conversations
But significantly, says Check Point’s Wilson, the M&S attack seems to have served as a much-needed alarm call for the retail industry, and many of her customers have started scrutinising their supply chains as a result.
“The attack exposed a hard truth: your security posture is only as strong as the weakest link in your vendor ecosystem, and for many retailers, that link had never been seriously stress-tested. The supply chain conversations happening in boardrooms today simply weren’t happening 18 months ago,” she says.
“Cyber risk is now seen as a board-level issue in a way it simply wasn’t before. That cultural shift may prove to be the attack’s most important legacy.”
Dominic Mortimer, who leads the red team at Bulletproof from WorkNest, agrees that security leaders seem to be more alert to the dangers of social engineering.
“The M&S breach accounted for a massive and direct uptick in organisations wanting to include similar breach scenarios in their tests,” Mortimer tells Computer Weekly. “I think like 80% of the latest red teams we’ve done following that breach announcement have all included help desk [or] vishing simulation scenarios to ensure the organisation’s resilience and defences extend to these third-party areas.
“It very much shone a light on an area that had previously been neglected by organisations and many reconsidered or approached with greater scrutiny their reliance on outsourced third-party entities. So, it’s very much become a warning tale that organisations have taken to heart, which is a massive positive despite the bad times had by M&S.”
Post-breach lessons
This said, cyber security in retail remains an uphill battle, and Wilson highlights some structural factors that still make shops harder to protect than, for example, financial services companies, or business-to-business publishing houses.
These factors include – but are not limited to – more public-facing contact points that lead to significantly higher volumes of phishing attempts, frequent frontline staff turnover and historically lower average security maturity. This all adds up to a threat environment that is hard to harden. Furthermore, Wilson adds, retailers operate on such tight margins that cyber security faces chronic underinvestment
It is perhaps not much of a surprise then that Check Point’s most recent cyber attack statistics for March 2025 reveal that the consumer goods and services sector was one of the most heavily targeted in the UK.
Huntress’ Patel says he is now seeing a wave of multi-channel approaches by hackers using email, phone calls, SMS and even Microsoft Teams to build trust with employees before delivering the killer blow. This, he says, makes them hard to stop with any single method of control.
“It requires a culture of verification and education, not just a stack of tools,” he says. “The organisations that come out of this period strongest won’t necessarily be the ones who spent the most. They’ll be the ones who were honest about where their real gaps were and closed them.
“At Huntress, we continuously see attackers inside business as we step in to stop them in their tracks. We are witnessing a professionalised scaling of the identity theft ecosystem. Adversarial efficiency is at an all time high. By transforming unauthorised access into reliable, long-term footholds, attackers are treating networks like a marketplace.
Our collective ability to recognise and resist that kind of secondary exploitation simply hasn’t improved. The attackers know it, and they’re counting on it Charlotte Wilson, Check Point
“Organisations must pivot their strategy if you are only watching the ‘break-in’, you are missing the breach. The priority must shift to rigorous, post-authentication visibility and anomaly detection,” he says.
Wilson reflects that the M&S incident seems to have prompted the government to start to act with more urgency. She notes the National Cyber Security Centre (NCSC), in its most recent annual report, says it dealt with 204 “nationally significant” cyber attacks from September 2024 to September 2025, more than doubling the previous record of 89. She also points out the progress made on the Cyber Security and Resilience Bill (CSBR), and Westminster’s Cyber Action Plan and proposed £210m centralised cyber unit.
“We are finally starting to see government not just understand but actively communicate the societal and economic cost of cyber threats. That is progress,” she says. “What hasn’t changed, though, is individual behaviour. Consumers going about their daily lives aren’t taking meaningfully more care with their personal data.
“And there’s a chapter of this story that hasn’t been told nearly loudly enough: the wave of class-action scams that followed the breaches. They’re still out there on social media: deepfake videos asking whether you were affected, whether you might be entitled to compensation, harvesting the details of the very people who were already victims once.
“The original breach made the headlines, but the scams that fed on it didn’t. And from a societal perspective, our collective ability to recognise and resist that kind of secondary exploitation simply hasn’t improved. The attackers know it, and they’re counting on it,” she warns.