Researchers have identified a critical security flaw in aftermarket alarm systems installed by dealerships across millions of US vehicles. The devices can be hacked to unlock cars, enable tracking, and disable engine functionality.
Security researchers have discovered that alarm systems covertly installed in millions of vehicles sold by US dealerships contain vulnerabilities that allow remote attackers to compromise vehicle security and safety.
The alarms were installed by dealerships without buyer consent or awareness in many cases. Even customers who explicitly declined the devices found them operational in their vehicles, buried in electrical systems and difficult to locate or remove.
According to the research, hackers exploiting these vulnerabilities could:
- Unlock vehicle doors remotely
- Activate GPS tracking to monitor location
- Disable engines, effectively immobilizing cars
- Bypass factory security systems
The flaws stem from weak security protocols in the alarm systems' wireless communication and lack of encryption on critical functions. Researchers identified multiple entry points that require minimal technical expertise to exploit.
Affected vehicles span multiple years and manufacturers, though specific models have not been publicly disclosed to prevent immediate widespread exploitation. The vulnerability impacts both luxury and standard vehicle segments.
Dealerships have been contacted about deploying patches and firmware updates to address the security gaps. However, widespread implementation remains unclear given the distributed nature of dealership networks and varying technical capabilities.
Vehicle owners are advised to contact their dealerships immediately to determine if their cars contain these systems and request patches. Those unable to locate the devices should request professional inspection and removal if they choose not to keep the alarm functionality.
Manufacturers are being pressured to implement stronger security standards for aftermarket systems and improve oversight of dealership installation practices. The incident highlights broader concerns about connected vehicle security as cars become increasingly networked.
A UNICEF survey of 21,000 internet-using children across 21 countries found nearly one in five experienced tech-facilitated sexual exploitation and abuse. The report reveals a critical gap in reporting, with less than 1% of cases reaching authorities.
A massive data breach at an unspecified car rental company exposed customer driver's licenses and personal information within hours of rental. The FBI is investigating the incident as data stolen from customers appears for sale online.
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin exposes WordPress sites to remote code execution and complete takeover by unauthenticated attackers.
An identity theft search site claimed to possess over 150 million driver's license photos stolen from a major ID verification service. The crime site has since been shut down.