EILMELDUNGEN LIVE
🕵️ SicherheitslückenUSN-8643-5: Linux kernel vulnerabilities(27.08.2026 um 23:29 Uhr)
🕵️ SicherheitslückenUSN-8658-4: Linux kernel (Azure CVM) vulnerabilities(27.08.2026 um 23:32 Uhr)
🔧 AI Nachrichten This New SECRET LLM Is Taking The World By Storm 0x Alpha(25.08.2026 um 18:45 Uhr)
🕵️ SicherheitslückenUSN-8661-3: Linux kernel vulnerabilities(27.08.2026 um 23:36 Uhr)
🕵️ SicherheitslückenUSN-8644-3: Linux kernel (Azure) vulnerabilities(27.08.2026 um 23:39 Uhr)
🔧 AI Nachrichten LLM & AI Agent Benchmarks vs Reality: Why AI Applications Break(27.08.2026 um 13:00 Uhr)
🕵️ SicherheitslückenUSN-8666-3: Linux kernel (GCP FIPS) vulnerabilities(27.08.2026 um 23:41 Uhr)
🕵️ SicherheitslückenUSN-8643-5: Linux kernel vulnerabilities(27.08.2026 um 23:29 Uhr)
🕵️ SicherheitslückenUSN-8658-4: Linux kernel (Azure CVM) vulnerabilities(27.08.2026 um 23:32 Uhr)
🔧 AI Nachrichten This New SECRET LLM Is Taking The World By Storm 0x Alpha(25.08.2026 um 18:45 Uhr)
🕵️ SicherheitslückenUSN-8661-3: Linux kernel vulnerabilities(27.08.2026 um 23:36 Uhr)
🕵️ SicherheitslückenUSN-8644-3: Linux kernel (Azure) vulnerabilities(27.08.2026 um 23:39 Uhr)
🔧 AI Nachrichten LLM & AI Agent Benchmarks vs Reality: Why AI Applications Break(27.08.2026 um 13:00 Uhr)
🕵️ SicherheitslückenUSN-8666-3: Linux kernel (GCP FIPS) vulnerabilities(27.08.2026 um 23:41 Uhr)

6 🕛 kürzlich 2 Min Lesezeit 29 Leser online ️ CVE-RADAR
0

Black Hat Asia 2026 | Mass Scale Hijacking of Shared Mobility and EV-Charging Fleets

↗ Quelle (YouTube · Black Hat)
🗣️ Stimme:
📺
YouTube · Black Hat
30 YouTube-Aufrufe
Rentable IoT infrastructures—such as e-scooters, EV chargers, shared bicycles, laundry machines, and public tools—are now deployed at city scale and controlled through cellular IoT backends. However, our research reveals that these systems systematically rely on weak resource identifiers, inconsistent authentication models, and insecure backend APIs, enabling attackers to remotely manipulate thousands of devices without physical access.

In this talk, we will present the first large-scale, cross-vendor security study of the rentable IoT ecosystem, covering 17 hardware devices and 92 mobile/mini-program apps. By reverse-engineering firmware, extracting cellular traffic from insecure modem debug channels, re-implementing binary protocols as "phantom clients," and performing black-box API testing, we uncovered 57 previously unknown vulnerabilities across 28 products. These issues enable attackers to:
• Force all rentable devices offline (city-wide DoS)
• Remotely lock, unlock, or disable mobility devices
• Obtain free charging, free rides, or unrestricted device usage
• Hijack user accounts and leak sensitive personal data
• Spoof device states to mislead operators and trigger operational failures

To scale these attacks, we introduce IDScope, an automated enumeration engine capable of inferring all valid device serial numbers or user IDs within minutes, bypassing rate limits and enabling exploitation of every device in a vendor's fleet.

We will demonstrate end-to-end attacks on real devices—turning thousands of EV chargers into free power stations, remotely stopping active e-bikes, unlocking shared devices, and impersonating entire device fleets. The talk will conclude with practical mitigations for both vendors and cities seeking to protect smart-mobility infrastructure.

Hetian Shi | Hardware and IoT Security Researcher, Tsinghua Univeristy

https://blackhat.com/asia-26/briefings/schedule/?#the-rentable-iot-meltdown-mass-scale-hijacking-of-shared-mobility-and-ev-charging-fleets-50304
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
72 Fachleser & IT-Security Experten haben diesen Report heute geteilt
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 53%
🟡 In Evaluierung 22%
🟢 Keine Auswirkung 15%
Spannende Innovation 10%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
4 Quellen
Security: Zwei Probleme in cockpit (Debian)
3 Quellen
Distribution Release: Vanilla OS 3
1 Quelle
LSN-0121-1: Kernel Live Patch Security Notice