Proprietary Failures
-
Critical vulnerability allowed attackers to remotely unlock, control Hyundai, Genesis vehicles
Curry explained that there appeared to be a ‘pre-flight’ check when JSON Web Tokens (JWTs) were generated during an app’s email/password credential check.
However, as the server did not require email address confirmation, it was possible to add a CRLF character to the end of an existing victim email address during registration and create an account that bypassed the JWT and email parameter check.
The app’s HTTP response returned the victim’s vehicle identification number (VIN) during testing. Curry then sent an HTTP request with the crafted account details, and after a few seconds, Specters confirmed his car had been remotely unlocked.
-
Cyberattack on top Indian hospital highlights security risk [iophk: Windows TCO]
"Digitizing an entire health care system without really safeguarding it can pretty much kill an entire hospital. It suddenly stops functioning," said Srinivas Kodali, a researcher with the Free Software Movement of India.
That is what happened to the hospital in New Delhi. Healthcare workers couldn't access patient reports because the servers that store laboratory data and patient records had been [breached] and corrupted.
-
Medibank Shutting All Branches, Going Offline, In Security Overhaul [iophk: Windows TCO]
During this window, all customer services branches will be closed and customers won’t be able to access Medibank or ahm services. HICAPS will not be available for on-the-spot claims.
Microsoft’s cybersecurity [sic] experts [sic] will oversee the upgrade.
-
Major cloud, email hosting provider blames ransomware attack for outage [iophk: Windows TCO]
Email hosting provider Rackspace Technology confirmed on Tuesday that a ransomware attack is behind an outage that has been disrupting its email service since Friday.
The company said it has retained a cyber defense firm to investigate the attack and has since discovered that the incident only impacted its Hosted Exchange business while its other products and services are fully operational.
-
Nest Audio update to continue Google’s smart home trend of replacing CastOS with Fuchsia
In a new Chromium Repository first discovered by 9to5Google (which is no longer available to the public, but you can see it above), Nest Audio is being discussed and the repo displays a ‘Fuchsia’ tag. This clearly denotes that the current operating system built into these devices is being ditched in favor of the shiny, new one.