Malicious SIM Cards Can Run Attacker Code in EV Chargers and Routers

August 11
3 mins

Episode Description

Here is your briefing for Tuesday, August 11, 2026.  Malicious SIM Card Can Run Attacker Code Inside Modems Behind Cellular IoT Devices. Researchers showed that a malicious SIM card can force certain cellular modules to execute attacker-supplied commands. The flaw affects machine-to-machine hardware in EV chargers, industrial routers, and vehicle telematics units. Tests on twenty-six devices found the capability active in nine, including five Quectel modules pulled from real deployments. Only three phones were affected, and no iPhones or Pixels. The attack requires physical insertion of the rogue SIM, but once in place it gives remote control without needing the victim's phone number. That's the headline from The Hacker News, and it is a reminder that the cellular stack in embedded devices still ships with assumptions that were never stress-tested at IoT scale.  Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo. Mozilla revoked the cryptographic key used to sign Linux builds of Firefox and Thunderbird after an unencrypted copy was accidentally committed to a private internal repository. The revocation means older signed tarballs will no longer verify for users who import the revocation list. Mozilla says audit logs show no external access and the repo was private, but the key is burned anyway. Most users will notice nothing. Distributors and anyone doing signature verification will have to adjust. That's the headline from The Hacker News, and it is another data point in the long-running lesson that even careful organizations still make simple mistakes with high-value secrets. Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers. Security researchers created a fictitious cryptocurrency company, posted developer jobs, and successfully hired three individuals they assess as North Korean operatives. The onboarding process included doctored documents with AI-generated artifacts, including SynthID watermarks and metadata from Google Gemini. Every virtual machine issued to the hires was instrumented.  A successful placement would have given the operatives real corporate access and source code. That's the headline from The Hacker News, and it shows that the labor market for remote developers remains an effective vector even when the targets are sophisticated enough to use generative AI for their cover documents. Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets] A malicious Model Context Protocol server can trick AI coding assistants into exfiltrating SSH keys, environment variables, and source code by splitting the request across tool descriptions and results so that no single fragment looks overtly malicious. The agent stitches the pieces together in context and performs the action anyway. The attack works against agents that connect to external tool servers over MCP. That's the headline from The Hacker News, and it is the predictable next step after we started giving agents persistent tool access without equivalent judgment. Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine] Attackers compromised a Polish combined heat and power plant through the private cellular APN used by the grid operator to reach remote sites. They shut down a steam turbine and the process-water treatment system. The plant serves roughly fifty thousand residents. Recovery started while the intruders were still inside

Support the show

See all episodes