{"id":13049,"date":"2025-08-12T08:43:13","date_gmt":"2025-08-12T15:43:13","guid":{"rendered":"https:\/\/jasonsblog.ddns.net\/?p=13049"},"modified":"2025-08-12T09:43:38","modified_gmt":"2025-08-12T16:43:38","slug":"security-expert-reveals-hacker-could-remote-control-cars-through-major-automakers-dealership-portal","status":"publish","type":"post","link":"https:\/\/jasonsblog.ddns.net\/index.php\/2025\/08\/12\/security-expert-reveals-hacker-could-remote-control-cars-through-major-automakers-dealership-portal\/","title":{"rendered":"Security Expert Reveals Hacker Could Remote Control Cars Through Major Automaker&#8217;s &#8216;Dealership Portal&#8217;"},"content":{"rendered":"\n<p>These modern connected cars are <a href=\"https:\/\/jasonsblog.ddns.net\/index.php\/2025\/07\/29\/what-has-your-car-been-secretly-recording-about-you\/\" target=\"_blank\" rel=\"noreferrer noopener\">worse spying devices than smartphones<\/a>, and car manufacturers and their developers are not proficient enough with security. And if you remove the sim or disable the connection leading to not implementing firmware updates, they&#8217;ll <a href=\"https:\/\/jasonsblog.ddns.net\/index.php\/2025\/08\/02\/skipping-over-the-air-updates-for-your-car-could-be-a-costly-mistake\/\" target=\"_blank\" rel=\"noreferrer noopener\">void your warranty<\/a>. Everything is being turned into a sneaky data collection device so the OCGFC, Owners and Controllers of Global Financialized Capital, can form extremely detailed profiles on you to profit from now through their data brokers, but eventually lock you into a digital Panopticon where you&#8217;ll be imprisoned and possibly killed if you&#8217;re not deemed useful. Just look at what they got away with during the COVID scamdemic with experimental mRNA gene therapies killing a maiming, and now profiting off people by giving them <a href=\"https:\/\/jasonsblog.ddns.net\/index.php\/2024\/09\/12\/pharmaceutical-drugs-kill-intestine\/\" target=\"_blank\" rel=\"noreferrer noopener\">Gila monster venom based pharmaceuticals<\/a>. With digital ID and vaccine passports brought on by a future scamdemic, you won&#8217;t be able to escape whatever pharmaceuticals they want to give you, probably with hot lots of death, and they&#8217;re even working on delivering pharmaceuticals through aerosols, self-spreading vaccines, mosquitos&#8230;<\/p>\n\n\n\n<p><a href=\"https:\/\/www.zerohedge.com\/technology\/security-expert-reveals-hacker-could-remote-control-cars-through-major-automakers\">https:\/\/www.zerohedge.com\/technology\/security-expert-reveals-hacker-could-remote-control-cars-through-major-automakers<\/a><\/p>\n\n\n<div class=\"wp-block-ub-divider ub_divider ub-divider-orientation-horizontal\" id=\"ub_divider_7740e522-d612-4783-a40f-a2b6941902c4\"><div class=\"ub_divider_wrapper\" style=\"position: relative; margin-bottom: 2px; width: 100%; height: 2px; \" data-divider-alignment=\"center\"><div class=\"ub_divider_line\" style=\"border-top: 2px solid #ccc; margin-top: 2px; \"><\/div><\/div><\/div>\n\n\n<p>By Tyler Durden<\/p>\n\n\n\n<p>In a shocking cyber security incident that should terrify every American, <strong>a top security researcher has revealed how he gained &#8220;unfettered access&#8221; to a major carmaker&#8217;s dealership portal<\/strong> &#8211; potentially allowing hackers to remotely hijack any customer vehicle from anywhere in the world.<\/p>\n\n\n\n<figure class=\"wp-block-image alignright is-resized\"><img decoding=\"async\" src=\"https:\/\/assets.zerohedge.com\/s3fs-public\/inline-images\/images_80.jpg?itok=VbmDx3oQ\" alt=\"\" style=\"width:304px;height:auto\"\/><\/figure>\n\n\n\n<p>Eaton Zveare, a security researcher at software delivery company Harness, made the alarming disclosure to TechCrunch, explaining how<strong> the devastating flaw could have enabled cybercriminals to access victims&#8217; personal and financial data, track their vehicles in real-time, and even seize complete control of vehicle<\/strong>s from any location globally.<\/p>\n\n\n\n<p>While Zveare refused to name the vulnerable automaker, he confirmed it&#8217;s a popular car company operating multiple brands under its corporate umbrella, meaning millions of Americans could have been at risk.<\/p>\n\n\n\n<p><a href=\"https:\/\/techcrunch.com\/2025\/08\/10\/security-flaws-in-a-carmakers-web-portal-let-one-hacker-remotely-unlock-cars-from-anywhere\/?_bhlid=788945e078a23fe81a581499eca15226b61bdc38\">TechCrunch<\/a> reports:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>Zveare, who has found bugs in <a href=\"https:\/\/eaton-works.com\/2023\/03\/06\/toyota-c360-hack\/\">carmakers\u2019 customer systems<\/a> and <a href=\"https:\/\/eaton-works.com\/2023\/02\/06\/toyota-gspims-hack\/\">vehicle management systems<\/a> before, found the flaw earlier this year as part of a weekend project, he told TechCrunch.<\/em><\/p>\n\n\n\n<p><em>He said while the security flaws in the portal\u2019s login system was a challenge to find, once he found it, <strong>the bugs let him bypass the login mechanism altogether <\/strong>by permitting him to create a new \u201cnational admin\u201d account.<\/em><\/p>\n\n\n\n<p><em><strong>The flaws were problematic because the buggy code loaded in the user\u2019s browser when opening the portal\u2019s login page<\/strong>, allowing the user \u2014 in this case, Zveare \u2014 to modify the code to bypass the login security checks.<\/em><\/p>\n<\/blockquote>\n\n\n\n<p>&#8220;<strong>No one even knows that you&#8217;re just silently looking at all of these dealers&#8217; data, all their financials, all their private stuff, all their leads<\/strong>,&#8221; Zveare told the news outlet in his explosive interview.<\/p>\n\n\n\n<p>The researcher demonstrated the hack&#8217;s terrifying potential, explaining: &#8220;For my purposes, I just got a friend who consented to me taking over their car, and I ran with that. But [the portal] could basically do that to anyone just by knowing their name \u2014 which kind-of freaks me out a bit \u2014 or I could just look up a car in the parking lots.&#8221;<\/p>\n\n\n\n<p>&#8220;<strong>They&#8217;re just security nightmares waiting to happen<\/strong>,&#8221; he added, highlighting the industry-wide vulnerabilities that could leave American families exposed to cyber attacks.<\/p>\n\n\n\n<p>Fortunately, the carmaker acted swiftly after being notified, with Zveare confirming that the critical vulnerabilities were patched within one week in February 2025.<\/p>\n\n\n\n<p>&#8220;The takeaway is that only two simple API vulnerabilities blasted the doors open, and it&#8217;s always related to authentication,&#8221; said Zveare. &#8220;If you&#8217;re going to get those wrong, then everything just falls down.&#8221;<\/p>\n\n\n\n<p>The revelation underscores the growing threat of cyber warfare targeting America&#8217;s critical infrastructure, raising serious questions about whether our automotive industry is doing enough to protect Americans from hackers.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>These modern connected cars are worse spying devices than smartphones, and car manufacturers and their developers are not proficient enough with security. And if you remove the sim or disable the connection leading to not implementing firmware updates, they&#8217;ll void your warranty. Everything is being turned into a sneaky data collection device so the OCGFC, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,7],"tags":[],"class_list":["post-13049","post","type-post","status-publish","format-standard","hentry","category-tech","category-world"],"blocksy_meta":[],"featured_image_src":null,"author_info":{"display_name":"Jason","author_link":"https:\/\/jasonsblog.ddns.net\/index.php\/author\/jturning\/"},"_links":{"self":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/13049","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/comments?post=13049"}],"version-history":[{"count":3,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/13049\/revisions"}],"predecessor-version":[{"id":13060,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/13049\/revisions\/13060"}],"wp:attachment":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/media?parent=13049"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/categories?post=13049"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/tags?post=13049"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}