[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5hf6j8N9X9Niu_jRLMghPOmE_WxBhsgr2NfSlXSsTM8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"c442cfc7-3f89-46ed-81c2-73c7c79e1bc8","hidden-car-alarm-flaw-exposes-2m-vehicles-to-remote-hijacking","8ffd82ce-9173-44ba-9a01-6fb9d6271fc3","Hidden Car Alarm Flaw Exposes 2M Vehicles to Remote Hijacking","The KARR Security System contained a severe Bluetooth vulnerability that allowed attackers within proximity to unlock vehicles, disable alarms, and immobilize ignitions — all without the owner's knowledge. A critical compounding factor is that dealerships frequently installed this device without explicit customer consent, meaning millions of vehicle owners were unknowingly exposed to risk. This highlights the dangerous intersection of supply chain opacity and poor patch management: consumers cannot defend against threats they don't know exist. The delayed or absent firmware update process left a massive attack surface open across over 2 million vehicles nationwide. This case underscores that aftermarket IoT devices embedded in physical infrastructure carry the same — if not greater — risk as traditional network-connected devices.","**Immediate Actions:**\n- Apply the KARR firmware update immediately if the device is installed in your vehicle or fleet.\n- Audit all aftermarket telematics and IoT devices installed across your vehicle fleet to confirm what hardware is present.\n\n**Supply Chain & Procurement Controls:**\n- Require explicit customer\u002Fowner consent and a documented security review before installing any third-party telematics or IoT device.\n- Evaluate vendor security posture, including patch cadence and vulnerability disclosure policies, before onboarding aftermarket hardware suppliers.\n- Maintain an up-to-date inventory of all embedded devices across managed assets, including vehicles.\n\n**Detection & Long-Term Improvements:**\n- Implement continuous vulnerability monitoring for all IoT and embedded devices, including automotive aftermarket systems.\n- Establish a coordinated disclosure and emergency patching procedure specifically for physical\u002FIoT device vulnerabilities.\n- Educate vehicle owners and fleet managers on how to identify installed aftermarket devices and where to check for security advisories.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 1 – Inventory and Control of Enterprise Assets","CIS Control 7 – Continuous Vulnerability Management","CIS Control 15 – Service Provider Management","NIST SP 800-82 – Guide to ICS\u002FOT Security","NIST CSF ID.AM-1 – Physical device inventory","NIST CSF RS.MI-3 – Vulnerability mitigation","NIST SP 800-161 – Supply Chain Risk Management","ISO\u002FIEC 27001 A.12.6.1 – Management of Technical Vulnerabilities","GDPR Article 25 – Data Protection by Design and by Default (consent for device installation)","GDPR Article 7 – Conditions for Consent","published","2026-07-21T12:21:30.915092+00:00","2026-07-21T12:21:30.602+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.wired.com\u002Fstory\u002Fa-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-paralysis-patch-it-now\u002F","a-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-para-b35b11","A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[49],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"44b66cc6-63dd-44b3-ac9e-57923a09da37","2026-07-21","afternoon","ThreatNoir Afternoon Brief — July 21","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-21\u002Fthreatnoir-afternoon-brief-2026-07-21.mp3"]