A car alarm vendor’s coding mistake has left millions of vehicles vulnerable to theft and location tracking. Thanks to the way dealers sell car alarms, many affected drivers don’t even know they have one installed.
The device is the KARR Security System, a Bluetooth-enabled aftermarket alarm built by Acrisure Protection Group. It’s installed by dealers, primarily at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California.
Aftermarket car alarms are a strange corner of the auto industry. Dealers install them in your car before you ever see the vehicle, then try to sell you the subscription afterward. Say no and the hardware still stays put. According to researchers at the University of California San Diego, KARR systems are installed in about 2.2 million American vehicles, and around half of owners don’t even know they’re there.
Read more…
Source: MalwareBytes Labs
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- Self-Driving Cars Can Be Hacked By Just Putting Stickers On Street Signs
August 8, 2017
Car Hacking is a hot topic, though it’s not new for researchers to hack cars. Previously they had demonstrated how to hijack a car remotely, how to disable car’s crucial functions like airbags, and even how to steal cars. But the latest car hacking trick doesn’t require any extra ordinary skills to accomplished. All it takes is a simple sticker onto ...
- UK Government issues cyber security guidelines for driverless cars
August 7, 2017
As vehicles get smarter, cyber security in the automotive industry is becoming an increasing concern. As a result, the UK government has issued new, relevant cyber security guidelines for connected and driverless cars. Cars are now becoming connected Wi-Fi hotspots, and are well on their way to autonomy. But, this leaves them vulnerable to hacking and ...
- Hacking cars: cybersecurity regulations needed for new vehicles
July 16, 2017
Imagine driving your pickup truck off-road and suddenly having your airbags and seat belts malfunction because of an object striking the undercarriage. That causes a software error in your smart vehicle, causing the computer to incorrectly turn off critical equipment that protects you. Sounds far fetched? It shouldn’t. It’s part of a recall notice that affected more than 200,000 ...
- Autonomous car cyber security consortium awarded funding
April 11, 2017
An autonomous car cyber security group will receive government funding as part of a plan to make the UK a hub for the development of self-driving cars, it has been announced. The 5*Stars consortium, which incorporates HORIBA MIRA, Ricardo, Thatcham Research, Roke and Axillium Research, will get grants to develop defences against cyber attacks on autonomous ...
- Senators reintroduce a bill to improve cybersecurity in cars
March 23, 2017
Senators Ed Markey of Massachusetts and Richard Blumenthal of Connecticut have reintroduced the Security and Privacy in Your Car (SPY Car) Act of 2017. They first introduced the bill, along with a similar bill for aircraft, during the last session. The SPY Car Act places the onus for automotive cybersecurity and privacy standards on the shoulders ...
- Popular hacker warkit Metasploit now hacks hardware and cars
February 3, 2017
Popular offensive hacking toolkit Metasploit now works on hardware, including cars, after a major update to the 13-year old platform. The free-or-paid modular hacking machine now sports plenty of CVE-specific exploitation components that security professionals have long-used for penetration tests and research. An update to the Hardware Bridge API means the platform will now work on variety ...
