Post by : Bianca Qureshi
Dubai, UAE –
At the Security Analyst Summit 2025, global cybersecurity firm Kaspersky revealed alarming findings from its latest security audit, uncovering vulnerabilities in the telematics systems of a major automotive manufacturer. The flaw, found through a contractor’s exposed application, could have allowed attackers to take remote control of vehicles — posing serious risks to driver and passenger safety.
The investigation revealed that by exploiting a zero-day vulnerability in a publicly accessible wiki platform used by one of the manufacturer’s contractors, attackers could gain entry into sensitive systems. Through this breach, Kaspersky’s experts managed to access the contractor’s issue-tracking platform, which contained confidential configuration details and hashed passwords for users connected to the manufacturer’s telematics servers.
Telematics systems are the digital nervous system of connected vehicles, enabling real-time data exchange such as location, speed, and engine diagnostics. Gaining control of this system means gaining control of critical vehicle functions.
On the manufacturer’s side, researchers identified weak password policies, unencrypted data storage, and lack of two-factor authentication. These weaknesses, combined with misconfigured firewalls, opened a pathway for intruders to move laterally across networks. Using stolen credentials, the researchers accessed the telematics servers and discovered a firmware update command that allowed unauthorized uploads to the Telematics Control Unit (TCU). This exposed the CAN (Controller Area Network) bus, which connects and controls core systems like the engine, transmission, and braking — potentially enabling an attacker to cut the engine or force gear shifts while the car was moving.
According to Artem Zinenko, Head of Kaspersky ICS CERT Vulnerability Research and Assessment, “The vulnerabilities we found are not unique to one company. They highlight systemic cybersecurity issues across the automotive industry — weak access controls, poor contractor security practices, and a lack of robust network isolation. One weak link in a third-party system can compromise an entire fleet of vehicles.”
Kaspersky stressed the need for stronger cybersecurity governance across both manufacturers and contractors.
For contractors, Kaspersky recommends:
Restricting internet access to web services via VPN
Isolating external systems from corporate networks
Enforcing strong password policies and 2FA
Encrypting all sensitive data
Integrating real-time SIEM monitoring
For automotive manufacturers, the company suggests:
Segregating telematics platforms from vehicle networks
Using allowlists for authorized network interactions
Disabling SSH password authentication
Running services with minimal privileges
Verifying command authenticity in all firmware updates
This case serves as a stark reminder that as vehicles become smarter, cybersecurity becomes as vital as mechanical safety. Kaspersky urges the global automotive sector to treat digital infrastructure with the same diligence applied to physical safety systems, ensuring a secure future for connected mobility.
US Lawmakers Urge Prince Andrew to Face Epstein Inquiry
US lawmakers push Prince Andrew to testify on Jeffrey Epstein links as pressure mounts following los
Venezuela’s Opposition Divides as U.S. Tensions Escalate
Venezuela’s opposition splits over U.S. military actions as pressure mounts on Maduro and divisions
Tech Titans Boost AI Spending Beyond $380 Billion in 2025
Alphabet, Meta, Microsoft, and Amazon push AI investments beyond $380 billion in 2025, signaling mas
Zukti Jewelry Opens Grandly at Dubai Outlet Mall
Zukti Jewelry opens at Dubai Outlet Mall with a grand celebration featuring live violin, Tanoura dan
Shalky Unveils ‘Whispers of Dawn & Sunset Glow’ Cruise Line
Shalky Fashion House introduces its Cruise Collection “Whispers of Dawn & Sunset Glow” — a poetic fu
Swisslog Leads Food Automation at Gulfood 2025
Swisslog to showcase smart warehouse automation at Gulfood 2025, boosting efficiency, safety, and su
Dubai Duty Free hits record AED805.6 million in October sales
Dubai Duty Free posts record-breaking October sales of AED805.6 million, marking its eighth record m
Fabien Marchand — The Infinite Brushstroke of Freedom
French artist Fabien Marchand explores freedom, color, and emotion through his evolving art — bridgi
Dubai’s Healthy Food Revolution 5 Global Wellness Trends Transforming the City
Discover how Dubai is embracing a global wellness wave with plant based diets organic food and smart
Start Your Day with Chia Seeds for Stronger Healthier Hair Naturally
Discover how morning chia seeds boost hair growth add shine and strengthen roots naturally with easy
The Power of SPF Why Daily Sunscreen Use Protects Your Skin from Damage
Discover why daily sunscreen matters Learn SPF basics how to choose the right type and protect your
Simple Hydration Hacks to Help You Drink More Water Every Day
Stay refreshed with easy hydration hacks Learn fun natural ways to drink more water daily boost ener
The Healthy Side of Dubai Exploring the Nutritious Essence of Emirati Cuisine
Explore the healthy side of Dubai through Emirati cuisine Discover natural ingredients balanced flav
Affordable Makeup Dupes Discover Luxury Beauty Looks for Less
Discover the best affordable makeup dupes that match luxury brands in quality and style Get stunning
The Magic of Oils A Simple Guide to Choosing the Right One for Your Skin
Find the best natural oil for your skin type Learn how to hydrate balance and glow with the perfect