Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Federal authorities intensify investigation into Tesla’s Full Self-Driving (Supervised) software

New court filing reveals Pentagon told Anthropic the two sides were nearly aligned — a week after Trump declared his relationship

DoorDash Launches New ‘Tasks’ App That Pays Couriers to Submit Videos to Train AI

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    New court filing reveals Pentagon told Anthropic the two sides were nearly aligned — a week after Trump declared his relationship

    21 March 2026

    Microsoft is retiring some of the Copilot AI bloat on Windows

    21 March 2026

    The best AI investment may be in energy technology

    20 March 2026

    Bot traffic to overtake human traffic by 2027, says Cloudflare CEO

    20 March 2026

    Multiverse Computing is pushing its compressed AI models into the mainstream

    19 March 2026
  • Apps

    DoorDash Launches New ‘Tasks’ App That Pays Couriers to Submit Videos to Train AI

    21 March 2026

    Google is introducing a new way for users to download Android apps that still protects against fraud

    21 March 2026

    Meta launches new AI content enforcement systems while reducing reliance on third-party vendors

    20 March 2026

    Bluesky Announces $100M Series B After CEO Transition

    20 March 2026

    Amazon is bringing Alexa+ to the UK

    19 March 2026
  • Crypto

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025
  • Fintech

    Amid legal turmoil, Kalshi is temporarily banned in Nevada

    20 March 2026

    Nominations for the Startup Battlefield 200 are still open

    19 March 2026

    Kalshi’s legal woes pile up as Arizona files first criminal charges for ‘illegal gambling operation’

    17 March 2026

    Fuse raises $25M to disrupt legacy loan origination systems used by US credit unions

    16 March 2026

    India neobank Fi removes banking services on its platform

    11 March 2026
  • Hardware

    Amazon is working on a new smartphone with Alexa at its core, the report says

    20 March 2026

    CEO Carl Pei says nothing about smartphone apps disappearing as they’re replaced by artificial intelligence agents

    18 March 2026

    MacBook Neo, AirPods Max 2, iPhone 17e and everything else Apple announced this month

    18 March 2026

    Oura enters India’s smart ring market with Ring 4

    17 March 2026

    Apple quietly launches AirPods Max 2

    17 March 2026
  • Media & Entertainment

    Tubi joins forces with popular TikTokers to create original streaming content

    19 March 2026

    Patreon CEO calls AI companies’ fair use argument ‘bogus’, says creators should be paid

    18 March 2026

    Meet Vurt, the first mobile streaming platform for indie filmmakers embracing vertical video

    18 March 2026

    BuzzFeed debuts AI applications for new revenue

    17 March 2026

    Facebook makes it easy for creators to report copycats

    14 March 2026
  • Security

    The US accuses the Iranian government of operating a hacktivist group that hacked the Stryker

    20 March 2026

    CISA Urges Companies to Secure Microsoft Intune Systems After Hackers Mass Wipe Stryker Devices

    20 March 2026

    FBI seizes websites of pro-Iranian hacker group after devastating Stryker attack

    19 March 2026

    FBI is buying location data to track US citizens, director confirms

    19 March 2026

    Russians caught stealing personal data from Ukrainians with new advanced iPhone hacking tools

    18 March 2026
  • Startups

    Microsoft hires Sequoia-backed AI collaboration platform team Cove

    21 March 2026

    Consumer-focused privacy firm Cloaked raises $375 million as it expands into the enterprise

    20 March 2026

    Tools for founders to navigate and move past conflicts

    20 March 2026

    Anori, Alphabet’s new X spinout, faces one of the world’s most expensive bureaucratic nightmares

    19 March 2026

    This startup wants to make enterprise software more like a prompt

    19 March 2026
  • Transportation

    Federal authorities intensify investigation into Tesla’s Full Self-Driving (Supervised) software

    21 March 2026

    Cyberattack on vehicle breathalyzer company leaves drivers stranded in US

    21 March 2026

    Arc expands into electric commercial and defense vessels with $50M raise

    20 March 2026

    Rivian Sacrifices 2027 Profit Target to Push Deeper into Autonomy

    20 March 2026

    K2 will launch its first high-powered computing satellite into space

    19 March 2026
  • Venture

    AI startups are eating up the venture industry, and the returns, so far, are good

    21 March 2026

    Sequen raised $16 million to bring TikTok-style personalization technology to any consumer company

    19 March 2026

    AI ‘boys club’ could widen wealth gap for women, says Rana el Kaliouby

    18 March 2026

    Billionaires made a promise – now some want to leave

    17 March 2026

    Antonio Gracias Says He Longs For ‘Pre-Entropic’ Startups – Those Built To Survive Chaos

    17 March 2026
  • Recommended Essentials
TechTost
You are at:Home»Transportation»Security Security Independence at Web Carmaker Gate let a hacker unlock from anywhere from anywhere
Transportation

Security Security Independence at Web Carmaker Gate let a hacker unlock from anywhere from anywhere

techtost.comBy techtost.com11 August 202505 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Security Security Independence At Web Carmaker Gate Let A Hacker
Share
Facebook Twitter LinkedIn Pinterest Email

One security researcher said the defects on the electronic dealership portal of an automotive industry exposed the private information of its customers ‘information and vehicles and could allow hackers to enter any of its customers’ vehicles.

Eaton Zveare, who works as a security researcher at the software delivery company, told TechCrunch that the defect he discovered allowed the creation of an administrator account that “unlimited access” to the UNAMPED CARMAKER Web Central Gate.

With this access, a malicious hacker could have seen the personal and financial data of automotive customers, monitor vehicles and register customers in features that allow owners – or hackers – to check some of their car functions from anywhere.

Zveare said he was not planning to name the seller, but said he was a widely known car industry with several popular sub-brakes.

In an interview with TechCrunch before his discussion at the Def Con Security Conference in Las Vegas on Sunday, Zveare said the errors have put the focus of the security of these dealership systems, which are granted to their employees and linking wide access to customer information.

Zveare, who found errors Car customer systems and Vehicle Management Systems Before, he found the defect earlier this year as part of a weekend project, he told TechCrunch.

He said that while the security defects in the portal connection system was a challenge to find himself, as soon as he found it, the errors let him bypass the connection mechanism as a whole by allowing him to create a new “national manager” account.

The defects were problematic because the Buggy code was loaded on the user’s browser when opening the gate connection page, allowing the user – in this case, zveare – to modify the code to bypass the login checks. Zveare told TechCrunch that the automotive industry had found no information on the previous exploitation, suggesting that he was the first to find it and reports it in the automotive industry.

When logged in, the account issued access to more than 1,000 of car representatives in all the United States, he told TechCrunch.

“No one even knows that you are just looking silently at all these dealers’ data, all their finances, all their private things, all their pencils,” Zveare said, describing access.

Zveare said that one of the things he found inside the dealership gate was a national consumer search tool that allowed users associated with registered gates to search for vehicle and driver’s driver’s data.

In a real example, Zveare received the unique vehicle identification number from the windshield of a car in a public parking lot and used the number to identify the car owner. Zveare said the tool could be used to search for someone who only uses the first and last name of the customer.

With access to the gate, Zveare said it was also possible to combine any vehicle with a mobile account, which allows customers to remotely control some of their car functions from an application, such as unlocking their cars.

Zveare said he tried it in a real example using a friend’s account and their consent. By transferring property to an account controlled by Zveare, he said that the gate requires only one certainty – essentially a pinky promise – that the user who executes the account transfer is legal.

“For my purposes, I just got a friend who agreed to take over his car and ran with it,” Zveare told TechCrunch. “But [the portal] He could actually do this to anyone only knowing his name-his kind of fooling me a little or I could just look at a car in parking. ”

Zveare said he did not consider whether he could be removed, but said that the exploitation could be abused by thieves to enter and steal objects from vehicles, for example.

Another key problem with access to the gateway to this automotive industry was that it was possible to access the systems of other representatives associated with the same gate through a single connection, a feature that allows users to connect to multiple systems or applications with only one set of connectors. Zveare said car systems for delegates are all interconnected, so it is easy to jump from one system to another.

With that, he said, the gate also had a feature that allowed managers, such as the user account it created, to “mimic” other users, effectively allowing access to other dealers as if they were the user without the need for their connections. Zveare said this was similar to a feature found on a toyota dealer gate Discovered in 2023.

“They are just security nightmares waiting to happen,” Zveare said, talking about the user’s feature.

Once at the Zveare gate, he found personal recognizable customer data, some financial information and telematics systems that allowed real-time monitoring of rental or courtesy cars, as well as cars sent across the country and the choice to cancel them-if Zveare did not.

Zveare said the errors took about a week to be corrected in February 2025 shortly after its disclosure in the automotive industry.

“The takeaway is that only two simple API vulnerabilities threw the doors open and is always related to authentication,” Zveare said. “If you are going to take these mistake then everything falls.”

car insurance Carmaker cyberspace Def Con 2025 gate hacker independence privacy Remote control security Unlock web
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleTinder explores a redesign, ways dating from ways, and the characteristics specifically for college to boost commitment
Next Article Why investors bet just $ 85 million for Indian company drug strategy
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Federal authorities intensify investigation into Tesla’s Full Self-Driving (Supervised) software

21 March 2026

Cyberattack on vehicle breathalyzer company leaves drivers stranded in US

21 March 2026

Consumer-focused privacy firm Cloaked raises $375 million as it expands into the enterprise

20 March 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Federal authorities intensify investigation into Tesla’s Full Self-Driving (Supervised) software

21 March 2026

New court filing reveals Pentagon told Anthropic the two sides were nearly aligned — a week after Trump declared his relationship

21 March 2026

DoorDash Launches New ‘Tasks’ App That Pays Couriers to Submit Videos to Train AI

21 March 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Amid legal turmoil, Kalshi is temporarily banned in Nevada

20 March 2026

Nominations for the Startup Battlefield 200 are still open

19 March 2026

Kalshi’s legal woes pile up as Arizona files first criminal charges for ‘illegal gambling operation’

17 March 2026
Startups

Microsoft hires Sequoia-backed AI collaboration platform team Cove

Consumer-focused privacy firm Cloaked raises $375 million as it expands into the enterprise

Tools for founders to navigate and move past conflicts

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.