Three years after discovering a vulnerability in Jacuzzi’s SmartTub interface, security researcher Eaton Zveare revealed flaws in a major carmaker’s dealership portal that exposed customer data and could allow hackers to remotely access vehicles. The vulnerabilities stemmed from simple API issues, granting unauthorized access to sensitive information and real-time vehicle tracking, which were fixed in February 2025.
Want More Context? 🔎
MixShell Malware Delivered via Contact Forms Targets U.S. Supply Chain Manufacturers
Cybersecurity researchers have identified a sophisticated social engineering campaign, codenamed ZipLine by Check Point Research, targeting critical manufacturing companies with an in-memory malware called MixShell. Attackers bypass traditional phishing methods by contacting victims through the company's public 'Contact Us' form, enhancing their deception efforts. Want More Context? 🔎
Read more