Utopia Tech
▸ Engineering & Strategy Journal

Field notes from the edge.

What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT DevicesAI
Security

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

Security researchers from the University of Birmingham and Fuzzware have discovered that malicious SIM cards can execute attacker-controlled commands on cellular modems, potentially compromising IoT devices including EV chargers, industrial routers, and vehicle telematics systems. Testing across 26 phones and cellular modules confirmed this vulnerability exists in critical infrastructure component

UTUtopia Tech·1 min
Vulnerabilities in Car Anti-Theft DeviceAI
Strategy

Vulnerabilities in Car Anti-Theft Device

Security researchers at UC San Diego discovered critical vulnerabilities in the KARR Security System, an aftermarket car alarm installed in an estimated 2 million vehicles across the US. The flaws allow attackers within Bluetooth range to remotely unlock vehicles, disable alarms, control lights and horn, and even disable ignition systems, leaving drivers stranded.

UTUtopia Tech·1 min
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into ProxiesAI
Security

Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

Security researchers at Bitsight have identified a malicious operation called Fuyao affecting cheap Android TV boxes that ship with pre-installed apps masquerading as legitimate smartphone brands. These devices, linked to Chinese company Zhejiang Fengwo IoT Technology Co., Ltd., fraudulently click ads while simultaneously converting owners' broadband connections into proxy networks without consent

UTUtopia Tech·1 min
Read This Before You Buy That TV Streaming StickAI
Security

Read This Before You Buy That TV Streaming Stick

Security researchers at Bitsight have uncovered a sophisticated ad fraud operation embedded in popular H96 TV streaming devices that spoofs mobile phones to click ads on AI-generated websites while simultaneously renting out users' internet connections as residential proxies. The operation, traced to mainland China-based Zhejiang Fengwo IoT Technology Ltd, uses Google's Blockly visual programming

UTUtopia Tech·4 min
Enhanced License Plate TrackingAI
Strategy

Enhanced License Plate Tracking

Surveillance company Leonardo is developing SignalTrace technology that augments automatic license plate readers (ALPRs) with Bluetooth sensors to capture unique identifiers from mobile phones and wearables in passing vehicles. This enhancement transforms ALPRs from vehicle-tracking devices into tools capable of identifying and tracking specific individuals, significantly expanding law enforcement

UTUtopia Tech·1 min
China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber ReconnaissanceAI
Security

China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance

Cybersecurity researchers have identified a significant expansion of the JDY botnet, a China-linked covert network that has grown to over 1,500 compromised SOHO and IoT devices. The botnet operates as a centrally controlled scanning infrastructure designed to discover, fingerprint, and continuously map exposed services at scale for cyber reconnaissance purposes.

UTUtopia Tech·1 min
Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AIAI
Security

Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI

Security research has revealed that Bright Data, a major web-scraping proxy provider targeting the AI industry, embeds SDKs in free consumer apps that convert users' devices—including always-on smart TVs—into proxy exit nodes without clear disclosure. The company, formerly known as Luminati, operates what it claims is the world's largest residential proxy network by leveraging these consumer devic

UTUtopia Tech·1 min
Dutch Authorities Dismantle Botnet Linked to 17 Million Infected DevicesAI
Security

Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices

Dutch law enforcement, in collaboration with the National Cyber Security Center, successfully dismantled a massive botnet comprising at least 17 million compromised devices including computers, mobile devices, and IoT equipment. The operation targeted over 200 command-and-control servers located within the Netherlands that were orchestrating malicious attacks through the infected device network.

UTUtopia Tech·1 min
Skip to main content