Trending

Researchers Hacked EV Car Chargers To Execute Arbitrary Code

EVs face significant cyber risks due to their reliance on interconnected systems and the increasing number of public charging stations, which often lack robust security measures.  Vulnerabilities in EV software and charging infrastructure can expose vehicles to malware, unauthorized access, and potential control by hackers. During Pwn2Own Automotive 2024 in Tokyo, cybersecurity researchers hacked  EV car chargers  to execute arbitrary code. Researchers Hacked EV Car Chargers At the Pwn2Own Automotive 2024 event, researchers exploited three EV chargers:-  Autel MaxiCharger (MAXI US AC W12-L-4G) ChargePoint Home Flex JuiceBox 40 Smart EV Charging Station  They executed arbitrary code via Bluetooth while focusing on the Autel MaxiCharger, and this uncovered the “CVE-2024-23958,” “CVE-2024-23959,” and “CVE-2024-23967”  vulnerabilities . The features of the charger include WiFi, Ethernet, Bluetooth, 4G LTE, RFID, LCD touchscreen, RS485, and a USB-C port. Its har...

ILOVEYOU – 20 years ago – to the day!

                       I LOVE YOU is always more than just a phrase right? Well, two decades ago on May 4, it made a catastrophe in the form of worm that’s worth remembering


              The E-mail which is received from a friend or acquaintance, with the subject ILOVEYOU contains an attachment LOVE-LETTER-FOR-YOU, which is the worm script. Out of curiosity the receiver indulge to open the attachment which in turn sends the mail to every one of the person’s address book on behalf of the recipient. The spread rate was exponential (like the corona outbreak -_-) and infected almost 45 million Windows PCs within 4-5 May.


And also it downloads a Trojan which infects the victim and steals the internet login password (at the time, dial-up connections were used) and sends them to an address. The damage it made cost several million dollars!! And Microsoft patched the vulnerability, preventing the VBS scripts being launched by default. Well the reason is by default Windows hides the extension of known file formats and this tricked many as it seems like a text file.

The craziest part is that, Mr. Onel de Guzman the man behind the catastrophe was left unpunished!! He admitted that he did that to steal internet logins, so that he can use free internet :P but the Philippine law was not so strict. Even he didn’t thought that it may cause such a nightmare and it’s no surprise. If the worm was named something else other than ILOVEYOU, then it wouldn’t be such a menace Don’t you think? LoL. That’s a perfectly Social engineered attack happened two decades ago. 


That’s all for today. Comment your thoughts about the worm below. !!

 

Comments

Popular posts from this blog

Ninjutsu OS- Windows based pentesting distribution

Fog Ransomware

New PIXHELL Attack Exploits Screen Noise to Exfiltrates Data from Air-Gapped Computers