Remove author sam-curry
article thumbnail

A flaw in the connected vehicle service SiriusXM allows remote car hacking

Security Affairs

Researcher Sam Curry shared details about his findings in a series of tweets, he demonstrated that a remote attacker can exploit the flaw in the service to unlock, start, locate, and honk a car by simply knowing the vehicle’s vehicle identification number (VIN). — Sam Curry (@samwcyo) November 30, 2022.

Hacking 119
article thumbnail

Vehicle Identification Numbers reveal driver data via telematics

Malwarebytes

Sam Curry (@samwcyo) November 30, 2022. — Sam Curry (@samwcyo) November 30, 2022. We took the authorization bearer and used it in an HTTP request to fetch the user profile. — Sam Curry (@samwcyo) November 30, 2022. — Sam Curry (@samwcyo) November 30, 2022.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Critical flaws found in Ferrari, Mercedes, BMW, Porsche, and other carmakers

Security Affairs

Cybersecurity researcher Sam Curry and his colleagues discovered many vulnerabilities in the vehicles manufactured by tens of carmakers and services implemented by vehicle solutions providers. ” reads the analysis published by Curry. Follow me on Twitter: @securityaffairs and Facebook and Mastodon.

article thumbnail

Researchers received $288,500 for 32 out of 55 issues reported to Apple

Security Affairs

A team of researchers composed of Sam Curry, Brett Buerhaus, Ben Sadeghipour, Samuel Erb and Tanner Barnes reported a total of 55 flaws to Apple as part of the company bug bounty program. The turn around for our more critical reports was only four hours between time of submission and time of remediation,” concludes Curry.

article thumbnail

Security vulnerabilities in major car brands revealed

Malwarebytes

These latest revelations come from the same researcher, Sam Curry, and his collective of car technology explorers and investigators. Update vehicle status to “stolen”, updating both license plate and notifying authorities. For sheer malicious troll value alone, what could match authorities flagging down your car?

article thumbnail

Teenager Hacks Uber by Social Engineering an Employee

SecureWorld News

Sam Curry, a security engineer at Yuga Labs who corresponded with the individual, said "they pretty much have full access to Uber. Sullivan was fired and charged with obstructing justice after failing to disclose the breach to appropriate authorities.

article thumbnail

Top 3 Cyber Predictions in 2023 and How You Can Prepare

ForAllSecure

For example, a recent article by Sam Curry found serious vulnerabilities in almost every major car company's tech stack. In 2022, Mayhem explored over 132 billion new code paths in those programs, automatically authored 2.24 ” Automotive cybersecurity is bad. million vehicles.