“With great power comes great responsibility” – the Peter Parker principle.
A certain car company (that will not be named for no reason at all) that produces electric cars and related software ecosystem with service revenues including e.g., vehicle service, insurance, and software updates, have recently been hacked. Last month (Sept 2021) the...
New Bluetooth Classic Vulnerabilities Affecting Automotive Systems
Bluetooth (BT) has been under fire in recent years as a result of the revelation of many significant flaws. A novel family of commercial BT stack security vulnerabilities that range from denial of service (DoS) via firmware failures and deadlocks in commodity hardware...
New Standard For Cybersecurity In Cars
New cybersecurity standards that proposes cybersecurity measures for the development lifecycle of road vehicles has recently been released. The SAEJ3061, “Cybersecurity Guidebook for Cyber-Physical Vehicle Systems” that was release in August 2016 by ISO has been...
Replay-based attack in Honda
A significant vulnerability was discovered in the Honda HR-V 2017. Some unknown processing of the component radio frequency (RF) communication is impacted by this vulnerability. A weak authentication vulnerability results from modification as part of a Request, with a...
Six Months For Ford To Address Vulnerability In Their Servers That Could Have Exposed Sensitive Internal Documents And Databases
Some weeks ago, a group of researchers disclosed a vulnerability that they had found on Ford’s website. The vulnerability, CVE-2021-27653, stemmed from a misconfigured instance of Pega Infinity customer engagement system running on Ford's servers. According to the...
Critical flaws found in CODESYS industrial automation software
Multiple security flaws have been discovered in CODESYS automation software and the WAGO programmable logic controller (PLC) platform that may be remotely abused to take control of a company's cloud operational technology (OT) infrastructure, according to...