Filter
Exclude
Time range
-
Near
π‘Ήπ’†π’Žπ’π’•π’† π‘¬π’™π’‘π’π’π’Šπ’•π’‚π’•π’Šπ’π’ 𝒐𝒇 π‘΅π’Šπ’”π’”π’‚π’ 𝑳𝒆𝒂𝒇: π‘ͺπ’π’π’•π’“π’π’π’π’Šπ’π’ˆ π‘ͺπ’“π’Šπ’•π’Šπ’„π’‚π’ π‘©π’π’…π’š π‘¬π’π’†π’Žπ’†π’π’•π’” π’‡π’“π’π’Ž 𝒕𝒉𝒆 𝑰𝒏𝒕𝒆𝒓𝒏𝒆𝒕 πŸš— Electric cars aren’t silent to hackers! At Black Hat Asia 2025 the PCA Cyber Security crew showed how 30 seconds of Bluetooth proximity is enough to jump from the infotainment system to full vehicle control of a 2020 Nissan Leaf. πŸ“Ά Attack chain in a nutshell β†’ Bluetooth HFP buffer-overflow (CVE-2025-32059) ➜ root on BlueDragon Evo ➜ Secure-Boot bypass ➜ covert DNS C2 over cellular ➜ CAN-gateway filter evasion ➜ doors, mirrors, wipers … even steering at highway speed! πŸ’₯ Why it matters The research proves that β€œinfotainment β‰  harmless” β€” once inside, attackers can eavesdrop on in-cabin audio, track GPS, and physically move the car from anywhere on the Internet. Nissan issued firmware fixes after coordinated disclosure. Update now! πŸ›‘οΈ πŸ”§ Key takeaways for defenders β€’Harden third-party Bluetooth stacks & eliminate fixed library load addresses. β€’Physically isolate safety-critical CAN traffic from consumer networks. β€’Treat every pairing request like a potential drive-by exploit. #AutomotiveSecurity #BluetoothHacking #CarHacking #CANBus #RemoteExploitation #Infosec #EmbeddedSecurity πŸŽ₯ Demo video: youtube.com/watch?v=56VreoKt… πŸ“„ Slides (PDF): i.blackhat.com/Asia-25/Asia-… 𝐹𝑒𝑒𝑙 π‘“π‘Ÿπ‘’π‘’ π‘‘π‘œ π‘ β„Žπ‘Žπ‘Ÿπ‘’ π‘‘β„Žπ‘–π‘  π‘€π‘–π‘‘β„Ž π‘¦π‘œπ‘’π‘Ÿ π‘π‘œπ‘™π‘™π‘’π‘Žπ‘”π‘’π‘’π‘ ! 𝐴𝑛𝑑 π‘Ÿπ‘’π‘šπ‘’π‘šπ‘π‘’π‘Ÿβ€¦ π‘†π‘‘π‘Žπ‘¦ π‘†π‘Žπ‘“π‘’ π‘Žπ‘›π‘‘ π»π‘Žπ‘π‘˜ π‘…π‘’π‘ π‘π‘œπ‘›π‘ π‘–π‘π‘™π‘¦! πŸ˜ŽπŸ΄β€β˜ οΈ
6
450
18 Sep 2024
🚨 Cyber Attack on Hezbollah through #Pager Devices: How It Has Been Done 🚨 Traditional pager devices receive signals from some main system over radio frequencies. However, security mechanisms like encryption or authentication of signals are not in place with these devices, which makes them very vulnerable to cyber attacks. Signals Interception and Manipulation: An attacker can use a device called Software Defined Radio to intercept the frequency on which the pager operates and send fake signals on the same frequency to manipulate the device's firmware remotely. This can be used to trigger explosive devices, known as IEDs. Explosive Consequences: Pager devices are based on very old technology and don't validate an incoming signal. An attacker can rather easily send a correct signal to use the device as a trigger. With only a signal at the right frequency, the attacker can ignite the explosive device from a distance and also at the most unexpected time for the enemy forces. Today's #cyberwar techniques even transform radio frequency devices into dangerous weapons. Beware of security vulnerabilities! #CyberSecurity #RFHacking #RemoteExploitation #DigitalWarfare #FirmwareExploitation #SignalHijacking
1
5
16
6,696