What You Should Know About the Honda Key Fob Vulnerability

As a cybersecurity writer, I’m more aware than the average person of the security risks with any connected device. So when I sat in my new car for the first time and saw all the different ways it linked to my phone or my home WiFi, more than a few red flags went up. I […]

The post What You Should Know About the Honda Key Fob Vulnerability appeared first on Security Intelligence.

Continue reading What You Should Know About the Honda Key Fob Vulnerability

Autonomous Vehicle Security Needs From A Hacker’s Perspective

With connected cars becoming more common, the industry has more standards and options when it comes to autonomous vehicle security.  Adam Laurie, known in hacker circles as Major Malfunction, leads X-Force Red’s automotive testing practice. He has seen firsthand how easy it can be to compromise an autonomous vehicle if strong security processes and controls […]

The post Autonomous Vehicle Security Needs From A Hacker’s Perspective appeared first on Security Intelligence.

Continue reading Autonomous Vehicle Security Needs From A Hacker’s Perspective

Top 5 Threat Vectors in Connected Cars and How to Combat Them

Plug-in electric and at least partially autonomous connected cars are a common sight on roads around the world.  The software and electronic component market for those vehicles is projected to grow from $238 billion to $469 billion between 2020 and 2030. Both cybersecurity and ‘privacy by design and default’ have been holistically embedded into operations across many […]

The post Top 5 Threat Vectors in Connected Cars and How to Combat Them appeared first on Security Intelligence.

Continue reading Top 5 Threat Vectors in Connected Cars and How to Combat Them

Automotive Cybersecurity: New Regulations in the Auto Industry

Connected car data security becomes key as automakers enable advanced communications and safety features. With this increased connectivity comes greater automotive cybersecurity risks, too. In fact, the number of automotive cyberattacks has risen sharply. The average car today contains up to 150 electronic control units and about 100 million lines of software code. That number is […]

The post Automotive Cybersecurity: New Regulations in the Auto Industry appeared first on Security Intelligence.

Continue reading Automotive Cybersecurity: New Regulations in the Auto Industry

Connected Car Security Is a New Kind of Mobile Security Risk

With so much pessimism surrounding the threat landscape in the automobile industry, it’s encouraging to hear that manufacturers are embracing connected car security concepts more than ever before.

The post Connected Car Security Is a New Kind of Mobile Security Risk appeared first on Security Intelligence.

Continue reading Connected Car Security Is a New Kind of Mobile Security Risk

Toyota data breach affects up to 3.1 million customers

Automotive maker Toyota said Friday that a data breach had hit its sales offices in Japan, exposing information on up to 3.1 million customers. The breach affected Toyota Tokyo Sales Holding Inc. and its affiliated enterprises, and possibly three other independent dealers in Japan, according to Toyota Motor Corp.’s statement, which described “unauthorized access” to the company’s network. “We take this situation seriously, and will thoroughly implement information security measures at dealers and the entire Toyota Group,” the statement said. It was the second cybersecurity incident affecting Toyota in as many months. In February, Toyota’s Australia branch announced it had been “the victim of an attempted cyberattack.” The company’s security woes come in the wake of reports that a Vietnamese hacking group, APT32, had last month launched a spearphishing campaign against multinational car companies. The Southeast Asian country is trying to develop its domestic car industry, and data stolen by […]

The post Toyota data breach affects up to 3.1 million customers appeared first on CyberScoop.

Continue reading Toyota data breach affects up to 3.1 million customers

Tesla Model 3’s onboard browser attacked successfully at Pwn2Own

A prolific duo of white-hat hackers exploited a previously unknown flaw in the web browser for the Tesla Model 3’s infotainment system on the third and final day of the Pwn2Own competition in Vancouver, demonstrating the first automotive zero-day in the event’s history. Team “Flouroacetate” — aka Amat Cama and Richard Zhu — used the Tesla hack on Friday to cap off a dominant run in the competition, which takes place annually during the CanSecWest security conference. Cama and Zhu successfully demonstrated zero-day exploits on popular web browsers and widely used virtualization software during the first two days. The Zero Day Initiative (ZDI), the organization that runs Pwn2Own, didn’t release many details about the Tesla hack. Given the sensitivity of any flaws in automotive software, it’s hardly surprising. But the value of Cama and Zhu’s research to Tesla is clear: Not only did they win cash for their demonstration, they […]

The post Tesla Model 3’s onboard browser attacked successfully at Pwn2Own appeared first on CyberScoop.

Continue reading Tesla Model 3’s onboard browser attacked successfully at Pwn2Own

Vietnam’s premier hacking group ramps up targeting of global car companies

A Vietnamese hacking group has been aggressively targeting multinational automotive companies in an apparent bid to support the country’s domestic auto industry, researchers who closely track the group told CyberScoop. Since February, the group known as APT32 sent malicious lures to between five and 10 organizations in the automotive sector, according to Nick Carr, senior manager at cybersecurity company FireEye. FireEye “assesses with moderate confidence” that APT32’s latest activity is in support of “the Vietnamese government’s stated domestic vehicle and auto part manufacturing goals,” Carr said. It is unclear how successful the operation has been. Carr declined to say whether the lures led to compromises of the automotive organizations’ networks. What is clear is that FireEye mobilized resources in response to the threat. “This is a little bit uncommon for [APT32] to do the industry-wide targeting,” he told CyberScoop. “And so, as a company we’ve been putting out more intelligence on our […]

The post Vietnam’s premier hacking group ramps up targeting of global car companies appeared first on CyberScoop.

Continue reading Vietnam’s premier hacking group ramps up targeting of global car companies

It’s Time for an Automotive Cybersecurity Wake-Up Call

The car of today — and especially tomorrow — relies on countless lines of software code to get those wheels moving, a reality that has placed increasing importance on automotive cybersecurity.

The post It’s Time for an Automotive Cybersecurity Wake-Up Call appeared first on Security Intelligence.

Continue reading It’s Time for an Automotive Cybersecurity Wake-Up Call