Security News

FTC orders GM to stop collecting and selling driver’s data
2025-01-18 16:17

The Federal Trade Commission (FTC) has announced action against General Motors (GM) and its subsidiary, OnStar, for unlawful collection and sale of drivers' precise geolocation and driving...

GM parks claims that driver location data was given to insurers, pushing up premiums
2025-01-17 00:49

We'll defo ask for permission next time, automaker tells FTC General Motors on Thursday said that it has reached a settlement with the FTC "to address privacy concerns about our now-discontinued...

Texas sues GM for selling driver data to analytics, insurance companies
2024-08-14 18:06

Lone Star State alleges GM cashed in with "millions in lump sum payments" from the sale Texas has sued General Motors for what it said is a years-long scheme to collect and sell drivers' data to...

Texas Sues GM for Collecting Driving Data without Consent
2024-08-14 16:48

Texas is suing General Motors for collecting driver data without consent and then selling it to insurance companies: From CNN: In car models from 2015 and later, the Detroit-based car manufacturer...

Long Article on GM Spying on Its Cars’ Drivers
2024-04-26 11:01

About Bruce Schneier I am a public-interest technologist, working at the intersection of security, technology, and people. I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

SonicWall Issues Patch for Critical Bug Affecting its Analytics and GMS Products
2022-07-22 18:39

Network security company SonicWall on Friday rolled out fixes to mitigate a critical SQL injection vulnerability affecting its Analytics On-Prem and Global Management System products. The vulnerability, tracked as CVE-2022-22280, is rated 9.4 for severity on the CVSS scoring system and stems from what the company describes is an "Improper neutralization of special elements" used in an SQL command that could lead to an unauthenticated SQL injection.

GM, Zola customer accounts compromised through credential stuffing
2022-05-26 11:16

Customers of automaker General Motors and wedding planning company Zola have had customer accounts compromised through credential stuffing, and the criminals have used the access to redeem gift cards. Credential stuffing is a type of attack aimed at hijacking accounts.

Vehicle owner data exposed in GM credential stuffing attack
2022-05-25 15:41

Car manufacturer General Motors has confirmed the credential stuffing attack it suffered last month exposed customers' names, personal email addresses, and destination data, as well as usernames and phone numbers for family members tied to customer accounts. Other more personal information, including social security and credit card and bank account numbers, as well as drivers license data are not stored in customers' GM accounts and were not laid bare, GM officials said in a letter [PDF] sent to customers this month.

GM credential stuffing attack exposed car owners' personal info
2022-05-23 22:53

US car manufacturer GM disclosed that it was the victim of a credential stuffing attack last month that exposed some customers' information and allowed hackers to redeem rewards points for gift cards. Car owners can redeem GM rewards points towards GM vehicles, car service, accessories, and purchasing OnStar service plans.

NanoLock Security appoints David Stroud as GM of Europe and APAC
2021-07-07 22:15

Accelerating its push to aggressively grow global deployments and its market presence worldwide, NanoLock Security expanded its executive team to add deep utilities and security expertise with several new appointments including David Stroud who has joined NanoLock as GM of Europe and APAC. Stroud, who will be based in NanoLock's UK office, is an industry-recognized leader with over 15 years of deep international experience, along with direct expertise in the energy and metering sector - including through his successful tenure as executive director of EDMI Europe, a leading smart metering solution provider, and as general manager of Advanced Metering Services, New Zealand's largest metering provider. Stroud's presence in Europe and his highly relevant knowledge of this market will enable NanoLock to pursue further strategic partnerships in Europe and APAC with utilities and manufacturers.