News: 0184506640

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Are There Cybersecurity Risks in Over-the-Air Tech Used in Autos? (cnbc.com)

(Sunday July 19, 2026 @11:34AM (EditorDavid) from the air-on-the-side-of-caution dept.)


[1]CNBC reports :

> The automotive industry's increasing use of over-the-air technology to update vehicle systems makes it more susceptible to cyberattacks, analysts say, urging more intervention in the sector... Its use represents "a unique national security concern," Gabriel Lim, senior analyst at the S. Rajaratnam School of International Studies in Singapore, told CNBC. "Aside from data privacy concerns, the potential of a foreign actor sabotaging the controls of a moving vehicle is a possibility that countries like Norway, Denmark, and Britain have expressed concerns about," Lim added.

>

> In May, the American Enterprise Institute warned that safeguarding the automotive sector was crucial to limit foreign governments' espionage capabilities. "To protect against foreign espionage threats, the US should consider additional security reviews, implement restrictions on certain foreign-made hardware and software in vehicles, and mandate increased data-collection disclosures," the report [2]said . The concerns come as real-life tests reveal vulnerabilities. Late last year, Norwegian bus company Ruter conducted tests on two buses and found that one had potential risks linked to OTA technology. "There is access to the control system for battery and power supply via mobile network through a Romanian SIM card. In theory, therefore, this bus can be stopped or rendered inoperable by the manufacturer," the company [3]said . The investigation by Ruter then sparked the U.K. and Denmark to conduct their own investigations...

>

> While these investigations were conducted on buses made by Chinese firm Yutong, [Siraj Ahmed Shaikh, systems security professor at the UK's Swansea University] said the issue goes beyond one manufacturer or country, as the technology becomes more pervasive. "Other sectors adopting OTA include other transport modes [such as] maritime and rail, aerospace (particularly drones), industrial machinery and robotics," he said.



[1] https://www.cnbc.com/2026/07/18/over-the-air-tech-in-vehicles-poses-cybersecurity-risks.html

[2] https://www.aei.org/research-products/report/connected-and-autonomous-cars-security-risks-from-chinese-components/

[3] https://ruter.no/en/ruter-with-extensive-security-testing-of-electric-buses



Hmmm.... (Score:5, Insightful)

by SlashbotAgent ( 6477336 )

Are there security vulnerabilities in a computer that allows the remote access and reprogramming in a car that can see(video, radar...), hear(audio), remote-start, and drive(lane keeping, cruise control, automatic braking, summon, full self-drive)?

You bet your fucking ass there are. It's been proven. Repeatedly.

Re: (Score:3)

by Teun ( 17872 )

Don't forget GPS.

Re: (Score:1)

by orangesquid ( 79734 )

We're entering the exciting age of AI-powered cybersecurity attacks. I imagine it won't be too long before something like a malware worm which polymorphs to evade detection and adapts itself as new CVEs get published, able to utilize tuned edge models, shows up. Wireless IoT could mean we end up with physical "e-quarantine" zones, wherein devices keep attacking anything in radio range...

When has networking not increased security risks? (Score:2)

by drnb ( 2434720 )

When has networking not increased security risks?

Yes (Score:1)

by gweihir ( 88907 )

Next stupid question?

Yes, of course! (Score:2)

by aglider ( 2435074 )

By definition of "automotive e-tech".

Obviously, yes. (Score:4, Informative)

by sinij ( 911942 )

Miller and Valasek remotely took over Jeep in 2015. The response to these demos was not to fix auto security, but to add what is ISP-level firewall rules.

Here is what they have to say about this in 2025. [1]Ten Years After the Jeep Hack: A Retrospective on Automotive Cybersecurity [usenix.org]

[1] https://www.usenix.org/conference/vehiclesec25/presentation/miller-valasek-keynote

Can't wait (Score:1)

by nospam007 ( 722110 ) *

...until some jokester bricks all the cars and even damages them permanently.

How we will laugh.

Re: (Score:2)

by vyvepe ( 809573 )

... or makes the battery to catch fire. With a bit of bad luck also a nearby house will burn down.

Disabling connectivity in hardware (Score:2)

by sinij ( 911942 )

Anyone remotely tech-savvy should be disabling any remote connectivity a modern car has. This means finding the module (DCM, Starlink, On-Star, etc.) and disabling the cell modem. Especially with AI democratizing ability to attack IT systems, your connected car is one TicsTok video away from being someone else's "for the Lulz".

Re:Disabling connectivity in hardware (Score:4, Interesting)

by sound+vision ( 884283 )

Do you have a resource explaining how to do this, or is the idea to have everyone disassemble, reverse-engineer, then re-assemble each vehicle they purchase?

Re: (Score:2)

by lucifuge31337 ( 529072 )

The resource is a search engine. I assume you've heard of such a technology before.

What is being suggest is not a novel idea. It's trivial to find the information for just about any modern vehicle simp[ly by searching for it.

Re: (Score:2)

by ArchieBunker ( 132337 )

Disconnect the cell antenna. Works for every model.

Just Red Team the heck out of it (Score:2)

by LindleyF ( 9395567 )

Security is possible if you hire competent people whose job it is to care about security.

Re: (Score:2)

by HiThere ( 15173 )

I think you're quite optimistic. I'd go with "Security can be vastly strengthened", but even BSD has had bugs.

Re: Just Red Team the heck out of it (Score:3)

by LindleyF ( 9395567 )

Security is multilayered. Bugs in the OS don't matter if the attacker can't get past the interface. Using MTLS for all connections (even post-quantum if you like) goes a long way.

Re: (Score:3)

by znrt ( 2424692 )

or just stop checking for subscription to get the ac to work?

what is even the necessity for any remote control of vehicles other than maintenance that could be performed at (user's) explicit request? i only see greed and control. weird reason to open a huge can of security worms you then would have to "hire competent people whose job it is to care about security" for ...

101 of "competent security": avoid unnecessary risks.

Re: Just Red Team the heck out of it (Score:2)

by LindleyF ( 9395567 )

Remote control should not be a thing. Over the air upgrades should. In this age, it shouldn't take a trip to the garage for a software patch.

Re: (Score:2)

by frdmfghtr ( 603968 )

I'd also be OK with upgrades via USB. Let me download the update from the manufacturer's website and install (or not) at my leisure.

Re: (Score:2)

by phantomfive ( 622387 )

Security isn't something that can be tacked on afterwards, otherwise Microsoft Windows wouldn't have vulnerabilities.

Security has to be a main design requirement from the beginning. If your software engineers don't know how to write secure code, then they won't write secure code.

Re: (Score:2)

by drinkypoo ( 153816 )

> Security is possible

Security is not a boolean.

For a compelling scenario (Score:2)

by umopapisdn69 ( 6522384 )

See the opening episode of "Zero Day"

Valasek's friend (Score:1)

by PetiePooo ( 606423 )

> Charlie Miller is perhaps best known as being Chris Valasek’s friend.

Ha ha! Yeah, right.

Is Betteridge law always valid? (Score:1)

by jdha ( 1422319 )

Betteridge's law of headlines states that any headline ending in a question mark can be answered with "no."

"In those days spirits were brave, the stakes were high,
men were real men, women were real women, and small furry
creatures from Alpha Centauri were real small furry
creatures from Alpha Centauri. "