Kaspersky Finds Security Flaws that Threaten Vehicle Safety
Kaspersky recently revealed the findings of a comprehensive security audit that uncovered a critical vulnerability enabling unauthorised access to all connected vehicles of a leading automotive manufacturer. The investigation found that attackers could potentially compromise both the manufacturer’s internal infrastructure and the connected vehicles themselves.
On the manufacturer’s side, Kaspersky discovered a zero-day SQL injection vulnerability in the company’s wiki application, which allows users to collaboratively create, edit and manage content. This flaw provided access to internal systems, including files containing hashed passwords and sensitive configuration data related to connected vehicles. Such access could potentially expose vital information such as vehicle speed, geolocation and data transmission details.
On the vehicle side, researchers uncovered a misconfigured firewall that exposed internal servers. Using a previously acquired service account password, they accessed the server’s file system and discovered credentials for another contractor, granting full control over the vehicle’s telematics system.
As Malaysia targets 20 per cent of annual new vehicle sales from xEVs by 2030, this discovery highlights the urgent need for automotive manufacturers to strengthen cybersecurity measures and ensure robust protection across all connected and electric vehicle systems.
*SQL Injection: A common attack vector that uses malicious Structured Query Language (SQL) code for backend database manipulation to access information that was not intended to be displayed.
*Hashed Password: A one-way, scrambled version of a user’s actual password, created by a cryptographic algorithm
Read More News on Latest Malaysia
Read More News on Business News Malaysia
Read More News on SG Business News
Read More News on World Future TV
Malaysia's inflation rose slightly, with analysts forecasting CPI at +2.4% YoY. They expect cost-push factors…
Designed for modern living, Habitation Plus+ will offer practical, well-designed homes inspired by IKEA’s approach
Xero integrates Claude AI, enabling real-time financial insights for 4.5m users worldwide, strengthening small business…
Loan demand softens, property overhang hits three-year high; MBSB keeps NEUTRAL view, highlights Mah Sing,…
Padini Holdings maintains stability despite the Malaysian Anti-Corruption Commission's investigation, with strong fundamentals supporting investor…
99 Speed Mart's outlet expansion strategy enhances accessibility, drives sales growth, and strengthens its competitive…
This website uses cookies.