// iot vulnerability

All signals tagged with this topic

Android Car Malware Marks Vehicles as Primary Attack Target

Researchers discovered the first malware explicitly targeting Android Automotive OS, moving car hacking from theoretical vulnerability research into active exploitation. Vehicles are no longer collateral damage in broader Android compromises—attackers have developed car-specific code, signaling a large enough installed base and economic incentive to justify dedicated development. As automakers ship millions of Android-powered dashboards and infotainment systems, similar threats are likely to follow.

How Keyboard Backlights Become a Data Exfiltration Channel

Researchers have demonstrated that LED keyboard backlights can be modulated to encode and transmit data from air-gapped systems—machines intentionally isolated from networks to prevent breaches. The attack exploits a genuine security blind spot: while IT teams lock down network interfaces and USB ports, peripheral LEDs remain largely unmonitored and controllable through standard operating system drivers, creating an invisible exfiltration path that existing detection tools don't flag. The attack expands the attack surface from intentional data channels (USB, network) to any device with visible light output, forcing security teams to either disable hardware features wholesale or implement far more granular peripheral controls.

Student halted Taiwan trains using unchanged 19-year-old crypto keys

A university student used static cryptographic credentials to falsify safety signals across Taiwan's high-speed rail network. The operator had never rotated authentication keys in two decades. The breach shows that networked systems with poor credential management create vast attack surface—one person with basic technical knowledge can trigger cascading failures affecting millions of passengers. Legacy systems pose active danger when they inherit authentication practices predating modern threat modeling.