• Business
  • Politics
  • Health
  • Entertainment
  • Technology
  • Sports
    • Football
    • Cricket
  • Travel
Facebook Twitter Instagram
  • About
  • Advertise
Facebook Twitter Instagram
News Night
  • Business
  • Politics
  • Health
  • Entertainment
  • Technology
  • Sports
    1. Football
    2. Cricket
    3. View All

    Semi-Professional Football

    February 8, 2022

    How to Play Fantasy Football for Beginners

    February 8, 2022

    Four Different Baltimore Pro Football Teams Have Won Championships

    February 8, 2022

    The Premise of Fantasy Football

    February 8, 2022

    WATCH: Anrich Nortje delivers a rocket 152 km/hr delivery to dismiss Jason Roy in SA20 2023

    February 8, 2023

    ‘Thanks for everything. Legend’: Twitter bids farewell to retiring Aaron Finch

    February 7, 2023

    Ellyse Perry’s boyfriend: Is Australia women’s cricket great dating someone?

    February 6, 2023

    “Emphasis And Focus On Close-In Catching, Slip Fielding”- Rahul Dravid On Team India’s Preparations For The First Test

    February 5, 2023

    ‘I’m hoping for a good game….GOAL!’ | Darren Ambrose reacts to Leeds goal within seconds | Video | Watch TV Show

    February 8, 2023

    WATCH: Anrich Nortje delivers a rocket 152 km/hr delivery to dismiss Jason Roy in SA20 2023

    February 8, 2023

    Man City: Former captain Vincent Kompany questions motives of club’s critics after Premier League charges | Football News

    February 8, 2023

    ‘Thanks for everything. Legend’: Twitter bids farewell to retiring Aaron Finch

    February 7, 2023
  • Travel
Subscribe
News Night
Home»Technology»Researchers find serious vulnerabilities in cars and emergency vehicles, including BMW, Mercedes, Honda, Nissan, more
Technology

Researchers find serious vulnerabilities in cars and emergency vehicles, including BMW, Mercedes, Honda, Nissan, more

AdminBy AdminJanuary 7, 2023No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


A hot potato: Security researchers discovered severe vulnerabilities last fall that would let hackers steal vehicles and customer data from multiple manufacturers. In a new update, one of the researchers writes that the vulnerabilities are more wide-reaching and can even affect law enforcement and emergency services vehicles.

Multiple vulnerabilities could have let attackers remotely track and control police vehicles, ambulances, and consumer vehicles from various manufacturers, according to researcher Sam Curry’s latest report. The update follows a similar notice from November.

The weak point for the emergency services rigs is the website for the company controlling the GPS and Telematics for over 15 million devices, most of them vehicles –Spireon Systems. The researchers described Spireon’s website as outdated and could log into it with an administrator account with some ingenuity.

From there, they could remotely track and control fleets of police vehicles, ambulances, and business vehicles. Attackers could unlock the cars, start their engines, disable their ignition switches, dispatch navigation commands to entire fleets, and control firmware updates to potentially deliver malware.

Last year, Curry said that SiriusXM’s remote systems vulnerabilities could let hackers steal Acura, Honda, Infiniti, and Nissan vehicles using only each car’s Vehicle Identification Number. They could also access customers’ personal information. The new report reveals similar dangers with Kia, Hyundai, and Genesis models.

Furthermore, misconfigured single sign-on systems let the researchers access BMW, Mercedes Benz, and Rolls Royce internal corporate systems. The flaws didn’t grant direct vehicle access. Still, attackers could have breached internal communications at Mercedes Benz, accessed BMW dealership information, and hijacked any BMW or Rolls Royce employee account. Security holes at Ferrari’s websites also let researchers access administrative privileges and delete all customer information.

The researchers also found that most, if not all, California digital license plates were vulnerable to attackers. After the state legalized digital plates last year, a company called Reviver handled possibly all of them, and security faults emerged in Reviver’s internal systems. Digital license plate holders can use Reviver to update their plates and report them as stolen remotely. However, vulnerabilities allowed attackers to give ordinary Reviver accounts elevated privileges that could track, change, and delete any registrationo in the system.

Curry’s latest blog post extensively details the methodology behind these and other hacks for those interested in the nitty gritty. His team reported the vulnerabilities to the affected companies before disclosure. At least some of them confirmed issuing security patches.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Admin
  • Website

Related Posts

Microsoft’s AI-powered Bing is coming for Google’s Bard-infused search

February 8, 2023

Moonrock Labs brings together brands and developers for metaverse experiences

February 8, 2023

9 Expert Tips for Keeping Children Safe Online

February 7, 2023

Hackers are mass infecting servers worldwide by exploiting a patched hole

February 7, 2023
Add A Comment

Leave A Reply Cancel Reply

Search
© 2023 NewsNight. All Rights Reserved by News Night.

Type above and press Enter to search. Press Esc to cancel.