30+ Tesla Cars Compromised Due to TeslaLogger Vulnerability
Source: 30+ Tesla Cars Hacked Globally Using Third-Party Software (cybersecuritynews.com) Following up on our most recent blog post regarding the threat posed by misconfigurations, a recent incident impacting Tesla places those findings under a brighter spotlight. Due to vulnerabilities caused by misconfigurations in TeslaLogger, a third-party software used for data logging, security researcher Harish SG uncovered that its insecure default settings could be exploited to gain unauthorized access. After Harish discovered the issue, it was reported to the platform's maintainer, who is expected to have taken actions to mitigate or resolve that risk. It is essential to clarify that the vulnerability and potential remote access associated with it did not reside in Tesla's vehicles or in Tesla's infrastructure but rather stemmed from misconfigurations surrounding the use of default credentials and improper storage of API keys by TeslaLogger. Desp...