Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIA Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
Security researchers from the University of Birmingham and Fuzzware have discovered that malicious SIM cards can execute attacker-controlled commands on cellular modems, potentially compromising IoT devices including EV chargers, industrial routers, and vehicle telematics systems. Testing across 26 phones and cellular modules confirmed this vulnerability exists in critical infrastructure component
Vulnerabilities in Car Anti-Theft Device
Security researchers at UC San Diego discovered critical vulnerabilities in the KARR Security System, an aftermarket car alarm installed in an estimated 2 million vehicles across the US. The flaws allow attackers within Bluetooth range to remotely unlock vehicles, disable alarms, control lights and horn, and even disable ignition systems, leaving drivers stranded.
AICheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
Security researchers at Bitsight have identified a malicious operation called Fuyao affecting cheap Android TV boxes that ship with pre-installed apps masquerading as legitimate smartphone brands. These devices, linked to Chinese company Zhejiang Fengwo IoT Technology Co., Ltd., fraudulently click ads while simultaneously converting owners' broadband connections into proxy networks without consent
AIRead This Before You Buy That TV Streaming Stick
Security researchers at Bitsight have uncovered a sophisticated ad fraud operation embedded in popular H96 TV streaming devices that spoofs mobile phones to click ads on AI-generated websites while simultaneously renting out users' internet connections as residential proxies. The operation, traced to mainland China-based Zhejiang Fengwo IoT Technology Ltd, uses Google's Blockly visual programming
Enhanced License Plate Tracking
Surveillance company Leonardo is developing SignalTrace technology that augments automatic license plate readers (ALPRs) with Bluetooth sensors to capture unique identifiers from mobile phones and wearables in passing vehicles. This enhancement transforms ALPRs from vehicle-tracking devices into tools capable of identifying and tracking specific individuals, significantly expanding law enforcement
AIChina-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
Cybersecurity researchers have identified a significant expansion of the JDY botnet, a China-linked covert network that has grown to over 1,500 compromised SOHO and IoT devices. The botnet operates as a centrally controlled scanning infrastructure designed to discover, fingerprint, and continuously map exposed services at scale for cyber reconnaissance purposes.
AIFree Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI
Security research has revealed that Bright Data, a major web-scraping proxy provider targeting the AI industry, embeds SDKs in free consumer apps that convert users' devices—including always-on smart TVs—into proxy exit nodes without clear disclosure. The company, formerly known as Luminati, operates what it claims is the world's largest residential proxy network by leveraging these consumer devic
AIDutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices
Dutch law enforcement, in collaboration with the National Cyber Security Center, successfully dismantled a massive botnet comprising at least 17 million compromised devices including computers, mobile devices, and IoT equipment. The operation targeted over 200 command-and-control servers located within the Netherlands that were orchestrating malicious attacks through the infected device network.
