pwshub.com

Critical flaws in Kia’s remote system could have allowed hackers to control vehicles

Connected vehicles continue to increase in popularity with features such as remote access and start, but what if a hacker could access those same features to gain access to a car?

A group of security researchers have revealed that it was able to gain access via critical flaws on Korean car maker Kia Corp.’s dealer portal, which could have been exploited to control any Kia vehicle equipped with remote hardware. Additionally, the flaws allowed access to any Kia vehicle with the hardware, regardless of whether the user had an active Kia Connect subscription.

As detailed Friday by Sam Curry, one of the researchers who discovered the flaw, the researchers found a set of vulnerabilities on the portal on June 11 that allowed remote control over key functions of Kia vehicles using only their license plates. The attacks could be executed remotely on any hardware-enabled vehicle in under 30 seconds.

Along with accessing and being able to remotely control Kia vehicles, the vulnerabilities could also be used to obtain the personal information of the vehicle’s owner, including name, phone number, email address and physical address. The access could have also allowed attackers to add themselves as an invisible second user on the victim’s vehicle without their knowledge.

The researchers built a tool to demonstrate the impact of the vulnerabilities, as demonstrated in the video below. Before going public, the researchers did inform Kia of the vulnerabilities and they have been fixed, but the fact that they existed in the first place is concerning in and of itself. Kia is one of many manufacturers providing remote connections, so the question arises: How safe are connected cars? Internal combustion engine cars without such connections do not have the same risk exposure.

Akhil Mittal, senior manager of cybersecurity strategy and solutions at the Synopsys Software Integrity Group, told SiliconANGLE via email that the “Kia vulnerability isn’t just a technical flaw — it’s a red flag for the entire auto industry.”

The report “shows how modern cars have become prime targets for cybercriminals, shifting from physical theft to digital exploitation,” Mittal explained. “The idea that a hacker could unlock, track, or even start your car using just a license plate number sounds like science fiction, but it’s happening today.”

Mittal said Kia’s quick patch is encouraging, but the situation raises a bigger question: Is the auto industry ready for these high-tech threats? “This wasn’t just about controlling a car – it exposed personal data too,” he said. “In a few simple steps, a hacker could access sensitive information, change ownership and take control of the vehicle without the owner’s knowledge.”

Source: siliconangle.com

Related stories
1 month ago - The good news in the cybersecurity world is that wider deployment of artificial intelligence has not yet opened a massive security hole in the world’s computer systems. The bad news: Flaws and vulnerabilities are beginning to appear that...
1 month ago - Application security startup Contrast Security Inc. today introduced Application Detection and Response, a new service that identifies and blocks attacks and zero-day or previously unknown vulnerabilities on applications in production....
2 weeks ago - Everyone dreams of financial independence and passive income that grows over time. One of the more reliable methods for achieving this goal is dividend investing. The idea of receiving regular income from stock investments is enticing,...
1 month ago - Did you know that just one company was responsible for more than 30% of the S&P 500's growth for the first half of this year? Take a wild guess...
1 month ago - Google LLC’s Mandiant has published details of a critical privilege escalation vulnerability found in Microsoft Corp.’s Azure Kubernetes service that, while having since been patched by Microsoft, could have allowed attackers to gain...
Other stories
57 minutes ago - Airtable Inc., creator of a no-code platform for building applications and workflows, is expanding on its investments in artificial intelligence with the launch of new tools that will enable every organization to start taking advantage of...
57 minutes ago - The organizations behind two popular privacy technologies are merging to advance their product development efforts. The Tails Project and the Tor Project announced the move today. According to Ars Technica, the merger follows a...
1 hour ago - Super Micro Computer is gearing up for a stock split on Oct. 1, but investors are feeling jittery following recent reports.
1 hour ago - (Bloomberg) -- The former contestants on Donald Trump’s TV show The Apprentice who co-founded his media startup wasted no time offloading millions of shares in the company after restrictions that prevented selling were lifted.Most Read...
1 hour ago - United Atlantic Ventures LLC (UAV) has divested over 7.5 million shares of Trump Media’s stock, according to a 13G regulatory filing made with the Securities and Exchange Commission (SEC) on Thursday.