Thieves Can Steal Modern Cars By Tapping Into a Headlight Wire

https://jalopnik.com/car-thieves-hack-can-bus-headlight-wire-bluetooth-1850307214

Hackers can inject malicious code into a car’s electronic network via headlight or taillight wires, fooling the car into thinking the key is present.

Android app from China executed 0-day exploit on millions of devices - Ars Technica

https://arstechnica.com/information-technology/2023/03/android-app-from-china-executed-0-day-exploit-on-millions-of-devices/

Fast-growing e-commerce app Pinduoduo had an EvilParcel stow-away.

Android apps digitally signed by China’s third-biggest e-commerce company exploited a zero-day vulnerability that allowed them to surreptitiously take control of millions of end-user devices to steal personal data and install malicious apps, researchers from security firm Lookout have confirmed.

Google finds 18 zero-day vulnerabilities in Samsung Exynos chipsets

https://www.bleepingcomputer.com/news/security/google-finds-18-zero-day-vulnerabilities-in-samsung-exynos-chipsets/

experienced attackers could easily create an exploit capable of remotely compromising vulnerable devices without triggering the targets’ attention.

Darknet drug market BlackSprut openly advertises on billboards in Moscow - The Record

https://therecord.media/blacksprut-darknet-drug-market-billboards-moscow/

The fact that BlackSprut was openly advertising its services in the Russian capital could mean several things: Either the billboard owners did not know about the platform’s illegal activity, or the billboards were hacked, or no one in a position of authority simply cared.

A post from Jeremi M Gosney on the 7th LastPass breach - Infosec Exchange

https://infosec.exchange/@epixoip/109585049354200263

You see, I’m not simply recommending that users bail on LastPass because of this latest breach. I’m recommending you run as far way as possible from LastPass due to its long history of incompetence, apathy, and negligence. It’s abundantly clear that they do not care about their own security, and much less about your security.

So, why do I recommend Bitwarden and 1Password? It’s quite simple:

Car hackers discover vulnerabilities that could let them hijack millions of vehicles

https://www.cyberscoop.com/car-hackers-vulnerabilities-research/

The vulnerabilities could let attackers remotely track, stop or control a car — even an entire fleet of emergency vehicles. Another could give hackers access to some 15.5 million automobiles, allowing them to send commands to control braking systems.

In total, a group of ethical car hackers discovered at least 20 vulnerabilities within the application programming interfaces, or APIs, that automakers rely on so technology inside cars can interact. The vulnerabilities affected Ford, Toyota, Mercedes, BMW, Porsche, Ferrari and others.

The findings underscore the security risks for consumers and automakers alike as car manufacturers continue to increase the amount of software in vehicles and provide owners with apps to connect with their cars. It also shows that while automakers have done more to focus on cybersecurity, much remains to be done.

Egypt’s COP27 summit app is a cyber weapon, experts warn – POLITICO

https://www.politico.eu/article/cop-27-climate-change-app-cybersecurity-weapon-risks/

Western security advisers are warning delegates at the COP27 climate summit not to download the host Egyptian government’s official smartphone app, amid fears it could be used to hack their private emails, texts and even voice conversations.

Cyberattacks against U.S. hospitals mean higher mortality rates, study finds

https://www.nbcnews.com/tech/security/cyberattacks-us-hospitals-mean-higher-mortality-rates-study-finds-rcna46697

Two-thirds of respondents in the Ponemon study who had experienced ransomware attacks said they disrupted patient care, and 59% of them found they increased the length of patients’ stays, straining resources. Almost one-quarter said they led to increased mortality rates at their facilities.

Albania cuts diplomatic ties with Iran over July cyberattack - AP News

https://apnews.com/article/nato-technology-iran-middle-east-6be153b291f42bd549d5ecce5941c32a

Albania cut diplomatic ties with Iran and expelled the country’s embassy staff over a major cyberattack nearly two months ago that was allegedly carried out by Tehran on Albanian government websites, the prime minister said Wednesday.

The move by NATO member Albania was the first known case of a country cutting diplomatic relations over a cyberattack.

A New Jailbreak for John Deere Tractors Rides the Right-to-Repair Wave - WIRED

https://www.wired.com/story/john-deere-tractor-jailbreak-defcon-2022/

FARMERS AROUND THE world have turned to tractor hacking so they can bypass the digital locks that manufacturers impose on their vehicles. Like insulin pump “looping” and iPhone jailbreaking, this allows farmers to modify and repair the expensive equipment that’s vital to their work, the way they could with analog tractors. At the DefCon security conference in Las Vegas on Saturday, the hacker known as Sick Codes is presenting a new jailbreak for John Deere & Co. tractors that allows him to take control of multiple models through their touchscreens.

Anonymous poop gifting site hacked, customers exposed

https://www.bleepingcomputer.com/news/security/anonymous-poop-gifting-site-hacked-customers-exposed/

ShitExpress, a web service that lets you send a box of feces along with a personalized message to friends and enemies, has been breached

Microsoft: Bug in Janet Jackson’s “Rhythm Nation” could crash a laptop - The Record by Recorded Future

https://therecord.media/microsoft-bug-in-janet-jacksons-rhythm-nation-could-crash-a-laptop/

the vulnerability comes from a phenomenon discovered by Microsoft where playing “Rhythm Nation” would cause any laptop with a certain hard drive to crash.

In its CVE page, the MITRE organization said the 5400 RPM OEM hard drives were shipped primarily with many laptop PCs around 2005. If played near these laptops, the song causes “a denial of service (device malfunction and system crash) via a resonant-frequency attack.”

North Korea-backed hackers have a clever way to read your Gmail - Ars Technica

https://arstechnica.com/information-technology/2022/08/north-korea-backed-hackers-have-a-clever-way-to-read-your-gmail/

The malware, dubbed SHARPEXT by researchers from security firm Volexity, uses clever means to install a browser extension for the Chrome and Edge browsers, Volexity reported in a blog post. The extension can’t be detected by the email services, and since the browser has already been authenticated using any multifactor authentication protections in place, this increasingly popular security measure plays no role in reining in the account compromise. The extension isn’t available in Google’s Chrome Web Store, Microsoft’s add-ons page, or any other known third-party source and doesn’t rely on flaws in Gmail or AOL Mail to get installed.

Volexity President Steven Adair said in an email that the extension gets installed “by way of spear phishing and social engineering where the victim is fooled into opening a malicious document.

Scammers Created an AI Hologram of Me to Scam Unsuspecting Projects - Binance Blog

https://www.binance.com/en/blog/community/scammers-created-an-ai-hologram-of-me-to-scam-unsuspecting-projects-6406050849026267209

Over the past month, I’ve received several online messages thanking me for taking the time to meet with project teams regarding potential opportunities to list their assets on Binance.com. This was odd because I don’t have any oversight of or insight into Binance listings, nor had I met with any of these people before.

It turns out that a sophisticated hacking team used previous news interviews and TV appearances over the years to create a “deep fake” of me. Other than the 15 pounds that I gained during COVID being noticeably absent, this deep fake was refined enough to fool several highly intelligent crypto community members. 

The Hacking of Starlink Terminals Has Begun - WIRED

https://www.wired.com/story/starlink-internet-dish-hack/

It cost a researcher only $25 worth of parts to create a tool that allows custom code to run on the satellite dishes.

Report: Mercenary spyware exploited Google Chrome zero-day to target journalists - The Record by Recorded Future

https://therecord.media/report-mercenary-spyware-exploited-google-chrome-zero-day-to-target-journalists/

A zero-day vulnerability in Google Chrome was discovered when attackers exploited it to target users in the Middle East, including journalists, cybersecurity firm Avast said Thursday. 

The company attributed the attacks to a secretive Israeli firm known as Candiru — named after a notorious parasitic fish — that sells spyware to governments. 

Hackers Say They Can Unlock and Start Honda Cars Remotely

https://www.vice.com/en/article/z34xnw/hackers-say-they-can-unlock-and-start-honda-cars-remotely

The Honda models that Kevin2600 and his colleagues tested the attack on use a so-called rolling code mechanism, which means that—in theory—every time the car owner uses the keyfob, it sends a different code to open it. This should make it impossible to capture the code and use it again. But the researchers found that there is a flaw that allows them to roll back the codes and reuse old codes to open the car, Kevin2600 said.

How mercenary hackers sway litigation battles

https://www.reuters.com/investigates/special-report/usa-hackers-litigation/

A trove of thousands of email records uncovered by Reuters reveals Indian cyber mercenaries hacking parties involved in lawsuits around the world – showing how hired spies have become the secret weapon of litigants seeking an edge.

Reuters identified 35 legal cases since 2013 in which Indian hackers attempted to obtain documents from one side or another of a courtroom battle by sending them password-stealing emails.

The messages were often camouflaged as innocuous communications from clients, colleagues, friends or family. They were aimed at giving the hackers access to targets’ inboxes and, ultimately, private or attorney-client privileged information.

Why Passkeys Will Be Simpler and More Secure Than Passwords - TidBITS

https://tidbits.com/2022/06/27/why-passkeys-will-be-simpler-and-more-secure-than-passwords/

Apple has unveiled its version of passkeys, an industry-standard replacement for passwords that offers more security and protection against hijacking while simultaneously being far simpler in nearly every respect.

Tesla cars, Bluetooth locks, vulnerable to hackers, researchers say - Reuters

https://www.reuters.com/technology/tesla-cars-bluetooth-locks-vulnerable-hackers-researchers-2022-05-17/

Millions of digital locks worldwide, including on Tesla cars, can be remotely unlocked by hackers exploiting a vulnerability in Bluetooth technology, a cybersecurity firm said on Tuesday.

In a video shared with Reuters, NCC Group researcher Sultan Qasim Khan was able to open and then drive a Tesla using a small relay device attached to a laptop which bridged a large gap between the Tesla and the Tesla owner’s phone.

“This proves that any product relying on a trusted BLE connection is vulnerable to attacks even from the other side of the world,” the UK-based firm said in a statement, referring to the Bluetooth Low Energy (BLE) protocol – technology used in millions of cars and smart locks which automatically open when in close proximity to an authorised device.

NCC Group said such a vulnerability was not like a traditional bug which could be fixed with a software patch and added BLE-based authentication was not originally designed for use in locking mechanisms.