:

MILLIONS OF CARS VULNERABLE TO HACKING VIA DEALER-INSTALLED ALARMS

SECURITY DESK2 MIN READ
TUE, JUL 21, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Researchers have identified a critical security flaw in aftermarket alarm systems installed by dealerships across millions of US vehicles. The devices can be hacked to unlock cars, enable tracking, and disable engine functionality.

Security researchers have discovered that alarm systems covertly installed in millions of vehicles sold by US dealerships contain vulnerabilities that allow remote attackers to compromise vehicle security and safety. The alarms were installed by dealerships without buyer consent or awareness in many cases. Even customers who explicitly declined the devices found them operational in their vehicles, buried in electrical systems and difficult to locate or remove. According to the research, hackers exploiting these vulnerabilities could: - Unlock vehicle doors remotely - Activate GPS tracking to monitor location - Disable engines, effectively immobilizing cars - Bypass factory security systems The flaws stem from weak security protocols in the alarm systems' wireless communication and lack of encryption on critical functions. Researchers identified multiple entry points that require minimal technical expertise to exploit. Affected vehicles span multiple years and manufacturers, though specific models have not been publicly disclosed to prevent immediate widespread exploitation. The vulnerability impacts both luxury and standard vehicle segments. Dealerships have been contacted about deploying patches and firmware updates to address the security gaps. However, widespread implementation remains unclear given the distributed nature of dealership networks and varying technical capabilities. Vehicle owners are advised to contact their dealerships immediately to determine if their cars contain these systems and request patches. Those unable to locate the devices should request professional inspection and removal if they choose not to keep the alarm functionality. Manufacturers are being pressured to implement stronger security standards for aftermarket systems and improve oversight of dealership installation practices. The incident highlights broader concerns about connected vehicle security as cars become increasingly networked.

■ SOURCES

Wired

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The Qilin ransomware gang is actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks' PAN-OS GlobalProtect to breach corporate networks. Arctic Wolf disclosed the active exploitation campaign.

JUST NOWSecurity Desk

Meta's Ray-Ban smartglasses can record video without obvious indicators, raising child safety concerns. The company places responsibility on users to avoid 'actively exploiting' the technology rather than implementing technical safeguards.

2H AGOAI Desk

The FCC is preparing to use its newly granted power to retroactively ban previously approved DJI gadgets imported into the United States. The action targets suspected front companies created to circumvent the foreign drone ban on the Chinese manufacturer.

8H AGOIndustry Desk

Flock Safety, a major license plate recognition camera company, has repeatedly provided misleading information to city councils, police departments, and the public, according to an ACLU investigation. The findings raise questions about the accuracy of claims made by the surveillance technology provider.

8H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.