Security News

Thieves Using AirTags to “Follow” Cars
2021-12-06 16:25

Since September 2021, officers have investigated five incidents where suspects have placed small tracking devices on high-end vehicles so they can later locate and steal them. Brand name "Air tags" are placed in out-of-sight areas of the target vehicles when they are parked in public places like malls or parking lots.

Pandemic-Influenced Car Shopping: Just Use the Manufacturer API
2021-12-03 20:09

Jason Kent, hacker-in-residence at Cequence, found a way to exploit a Toyota API to get around the hassle of car shopping in the age of supply-chain woes. First, some background: Many outlets have widely reported that manufacturers are putting 99 percent of a vehicle together, parking it in a lot somewhere and assuming the missing parts, like computer chips, will be available soon and they'll be able to make the engines run so the vehicles can be sold.

Some Tesla owners unable to unlock cars due to server errors
2021-11-19 22:30

Some Tesla owners worldwide are unable to unlock or communicate with their cars using the app due to an outage of the company's servers. Starting around 4 PM EST, Tesla owners have taken to social media reporting that the Tesla app is returning a "500 server error" when attempting to communicate with the car.

Intel chip flaw could enable attacks on laptops, cars, medical devices (CVE-2021-0146)
2021-11-15 16:30

Researchers uncovered a vulnerability in Intel Processors that could affect laptops, cars and embedded systems. The flaw enables testing or debugging modes on multiple Intel processor lines, which could allow an unauthorized user with physical access to obtain enhanced privileges on the system.

Today’s cars are mobile data centers, and that data needs to be protected
2021-10-01 05:30

The integration of mobile communications, infotainment, geo-location, and emergency monitoring systems render cars as a connected device within a distributed mesh of different data services. As manufacturers increase levels of system automation on the journey to fully autonomous vehicles, the volume of data generated and consumed by our vehicles will grow exponentially, as will the complexity of the code base on which the car depends.

Financial Cybercrime: Why Cryptocurrency is the Perfect ‘Getaway Car’
2021-09-09 17:51

This is part one of a two-part series on how hackers stole $2 million in cryptocurrency. There is one strong commonality with all these incidents and attacks: The hackers want the funds in cryptocurrency.

Top 5 autonomous car roadblocks
2021-08-31 18:15

Tom Merritt tells us the things that are getting in the way of autonomous car adoption. Here are five autonomous car road blocks we need to overcome.

Chinese auto-maker accused of altering data after fatal autonomous car accident
2021-08-24 08:02

Police are investigating an electrical vehicle company in China following claims that car data was tampered with following a fatal collision. On August 12, 31 year old Lin Wenqin was using the driver assistance feature on his Nio ES8 when he was involved in a fatal car crash.

BadAlloc Flaw Affects BlackBerry QNX Used in Millions of Cars and Medical Devices
2021-08-20 08:22

A major vulnerability affecting older versions of BlackBerry's QNX Real-Time Operating System could allow malicious actors to cripple and gain control of a variety of products, including cars, medical, and industrial equipment. BlackBerry QNX technology is used worldwide by over 195 million vehicles and embedded systems across a wide range of industries, including aerospace and defense, automotive, commercial vehicles, heavy machinery, industrial controls, medical, rail, and robotics.

After reportedly dragging its feet, BlackBerry admits, yes, QNX in cars, equipment suffers from BadAlloc bug
2021-08-19 01:35

BlackBerry this week issued a critical security advisory for past versions of its QNX Real Time Operating System, used in more than 175m cars, medical equipment, and industrial systems. BlackBerry QNX Software Development Platform version 6.5.0SP1 and earlier, QNX OS for Medical 1.1 and earlier, and QNX OS for Safety 1.0.1 are affected by an integer overflow vulnerability in the calloc() function of the C runtime library.