Connect with us

Published

on

Picture Alliance | Picture Alliance | Getty Images

American Water, the largest water utility in the U.S., disclosed that it had been hit by a cyberattack.

The Camden, New Jersey-based company said in a security statement on its website that it had learned of “unauthorized activity in our computer networks and systems” last Thursday, which it determined “to be the result of a cybersecurity incident.”

The company said on Tuesday that it shut down its customer service portal, and as a result, its billing function “until further notice” and will not charge any late fees or other fees related to billing as long as the system is down.

Some recent hacks of major U.S. companies have brought key online systems to a halt and created chaos for consumers and businesses, such as the hack of UnitedHealth which led to nationwide difficulty among patients needs prescriptions filled and health-care professionals needing to be paid for services.

Hacks targeting U.S. water infrastructure, in particular, have been increasing, with some of the attacks linked to geopolitical rivals of the U.S., including Iran, Russia and China.

Taking out critical national infrastructure has become a top priority for foreign-linked cybercriminals. “All drinking water and wastewater systems are at risk — large and small, urban and rural,” an EPA spokesman recently told CNBC.

American Water provides drinking water and wastewater services to more than 14 million people with regulated operations in 14 states and on 18 military installations.

One recent Russian-linked hack in January of a water filtration plant in a small Texas town, Muleshoe was located near a U.S. Air Force base. “Water is among the least mature in terms of security,” Adam Isles, head of cybersecurity practice for Chertoff Group, recently told CNBC.

The FBI warned Congress in February that Chinese hackers had penetrated deeply into United States’ cyber infrastructure in an attempt to cause damage, targeting water treatment plans, the electrical grid, transportation systems and other critical infrastructure.

America Water said it remains early in the investigation and “currently believes” that no water or wastewater facilities or operations have been impacted and water remains safe to drink.

Law enforcement and third-party cybersecurity experts are now involved, the company said.

American Water did not immediately respond to a request for additional comment.

The rising cybercrime wave targeting key water infrastructure led the Environmental Protection Agency to issue an enforcement alert warning that 70% of water systems it inspected do not fully comply with requirements in the Safe Drinking Water Act. Without quantifying an exact number, the EPA said some have “alarming cybersecurity vulnerabilities” — default passwords that have not been updated, vulnerable single login setups and former employees who retained systems access.

American Water said it first learned of the unauthorized computer access on October 3, and was subsequently able to determine it was a cyberattack. It said turning off customer systems was intended to protect data, though it added that it is too soon to know whether any customer information is at risk.

An American Water spokesman declined to comment beyond the official security statement.

Service hacking by China is meant to create 'panic and chaos', says Fmr. CISA Director Chris Krebs

Continue Reading

Environment

Hackers turn Nissan LEAF into full-scale RC car, record drivers’ conversations [video]

Published

on

By

Hackers turn Nissan LEAF into full-scale RC car, record drivers' conversations [video]

A team of white hat European hackers using their brains, keyboards, and a couple of bits and baubles from eBay managed to take control of a 2020 Nissan LEAF and violate just about every privacy and safety regulation in the process.

The best part: they recorded the whole thing.

Budapest-based cybersecurity experts PCAutomotive were able to exploit a number of vulnerabilities in a 2020 Nissan LEAF that enabled the white hat team to geolocate and track the car, record the texts and conversations happening inside the car, playing media back through the car’s speakers, and even (this is the genuinely terrifying dangerous part) turning the steering wheel while the car was moving. (!?)

Maybe the scariest part of this hack, however, is how seemingly easy it was to pull off by starting with a “test bench simulator” built using parts from eBay and exploiting a vulnerability in the LEAF’s DNS C2 channel and Bluetooth protocol.

Advertisement – scroll for more content

The PCAutomotive team gave a hugely detailed 118-page presentation of their exploit at black hat Asia 2025, which we’ve included at the bottom of this post, in case the original link goes dead. If you’re into that sort of thing, the fun stuff starts around page 27. And, if you’re not, just know that all the vulnerabilities were disclosed to Nissan and its suppliers between 02AUG2023 and 12SEP2024 (p. 116/118), and the “attack” itself can be seen in the video below that. Enjoy!

Summary of vulnerabilities

  • CVE-2025-32056 – Anti-Theft bypass
  • CVE-2025-32057 – app_redbend: MiTM attack
  • CVE-2025-32058 – v850: Stack Overflow in CBR processing
  • CVE-2025-32059 – Stack buffer overflow leading to RCE [0]
  • CVE-2025-32060 – Absence of a kernel module signature verification
  • CVE-2025-32061 – Stack buffer overflow leading to RCE [1]
  • CVE-2025-32062 – Stack buffer overflow leading to RCE [2]
  • PCA_NISSAN_009 – Improper traffic filtration between CAN buses
  • CVE-2025-32063 – Persistence for Wi-Fi network
  • PCA_NISSAN_012 – Persistence through CVE-2017-7932 in HAB of i.MX 6

Remote exploitation of Nissan LEAF



Electrek’s Take


Nissan-Bolt-EV-LEAF
2024 Nissan LEAF; via Nissan.

This is one of those posts that, on the bright side, does a great job explaining how a remote operator can “log in” to a vehicle and steer it out of trouble when a weird or edge-case-type situation pops up.

Unfortunately, this is also one of those posts that some of the more clueless anti-EV hysterics will point to and say, “See!? EVs can get hacked!” But the reality is that virtually any car with electric power steering (EPS), electronic throttle controls, brake-by-wire, etc. can be hacked in a similar way. But, while steering a target’s car into an oncoming semi might be a great way to pull off a covert CIA assassination, the more worrying issue here is the breach of privacy and recording – unless you want to spend some time in El Salvadoran prison, I guess.

Remember, kids: Big Brother is watching you.

SOURCE | IMAGES: black hat.


If you’re considering going solar, it’s always a good idea to get quotes from a few installers. To make sure you find a trusted, reliable solar installer near you that offers competitive pricing, check out EnergySage, a free service that makes it easy for you to go solar. It has hundreds of pre-vetted solar installers competing for your business, ensuring you get high-quality solutions and save 20-30% compared to going it alone. Plus, it’s free to use, and you won’t get sales calls until you select an installer and share your phone number with them. 

Your personalized solar quotes are easy to compare online and you’ll get access to unbiased Energy Advisors to help you every step of the way. Get started here.

FTC: We use income earning auto affiliate links. More.

Continue Reading

Environment

A vast new UK battery plant just secured £1B to power 100k EVs

Published

on

By

A vast new UK battery plant just secured £1B to power 100k EVs

A major new EV battery factory is being built in Sunderland, bringing 1,000 new jobs with it. AESC, Nissan’s battery partner, is behind the £1 billion ($1.33 billion) plant, which will boost the UK’s EV battery production by six times, enough to power 100,000 electric cars annually.

The 12 GWh capacity plant, AESC’s second battery plant in Sunderland, will be powered by 100% net-zero carbon energy. That big jump in capacity helps position Britain as a global player in EV manufacturing while pushing forward the country’s net-zero goals.

The investment is getting a serious financial lift from the British government. Through a combination of support from the National Wealth Fund and UK Export Finance, the project is unlocking £680 million in financing from major banks, including HSBC, Standard Chartered, SMBC Group, Societe Generale, and BBVA, that covers the construction and operation of the battery factory. Another £320 million is coming from private investment and fresh equity from AESC. On top of all that, the government’s Automotive Transformation Fund is pitching in with £150 million in grant funding.

This deal follows closely on the heels of the new UK-US trade agreement announced a day earlier, which cuts car export tariffs from 27.5% down to 10% for up to 100,000 UK-made vehicles – nearly the total number exported last year. That move could save car companies hundreds of millions of pounds and help protect good-paying jobs in manufacturing hubs like Sunderland.

Advertisement – scroll for more content

Chancellor of the Exchequer Rachel Reeves visited AESC in Sunderland, where she met with staff and local leaders to discuss what this means for the Northeast and the British car industry.

“This investment follows hot on the heels of yesterday’s landmark economic deal with the US, which will save thousands of jobs in the industry,” Reeves said.

Read more: UK unveils largest curbside EV charger installation of 6,000 ports


Now is a great time to begin your solar journey so your system is installed in time for those longer sunny days. If you want to make sure you find a trusted, reliable solar installer near you that offers competitive pricing, check out EnergySage, a free service that makes it easy for you to go solar. They have hundreds of pre-vetted solar installers competing for your business, ensuring you get high-quality solutions and save 20 to 30% compared to going it alone. Plus, it’s free to use and you won’t get sales calls until you select an installer and share your phone number with them.

Your personalized solar quotes are easy to compare online and you’ll get access to unbiased Energy Advisors to help you every step of the way. Get started here. –trusted affiliate partner

FTC: We use income earning auto affiliate links. More.

Continue Reading

Environment

Ford is facing a worker strike at its EV plant in Germany: Here’s why

Published

on

By

Ford is facing a worker strike at its EV plant in Germany: Here's why

It’s about the future of their jobs. Ford workers at two plants in western Germany are set to go on strike on Wednesday, their works council chief said on Monday.

Ford is facing a worker strike in Germany

In November, Ford announced it would cut around 4,000 jobs in Europe by 2027 as part of a restructuring, primarily in Germany and the UK. That’s still about 14% of its European workforce.

The American automaker said the move comes after it has incurred “significant losses” in recent years and a “highly disruptive market” with new EVs quickly gaining market share.

Ford blamed slower-than-expected demand for electric vehicles and a weak economic situation. It also plans to slow production at its Cologne EV plant, where the electric Explorer and Capri are built.

Advertisement – scroll for more content

Last week, IG Metall members voted in favor of “industrial action” with 93.5% of votes in favor of a strike. “Ford must act now—otherwise, we will go through with it,” said Kerstin D. Klein, Chief Representative of IG Metall Cologne-Leverkusen.

Ford-worker-strike
Ford Explorer EV production in Cologne (Source: Ford)

Ford is facing an influx of new competition, including Chinese EV makers like BYD. BYD’s overseas sales are surging with a fifth straight month of growth in April.

BYD even outsold Tesla in Germany last month, with 1,566 vehicles registered. In comparison, Tesla had just 855, and Ford saw 9,534 registrations.

Ford-worker-strike
Ford’s electric vehicles in Europe from left to right: Puma Gen-E, Explorer, Capri, and Mustang Mach-E (Source: Ford)

On top of this, Ford, like most of the industry, is preparing for more disruption with Trump’s auto tariffs. After releasing Q1 earnings last week, Ford warned that the tariffs could cost up to $2.5 billion this year.

During Ford’s earnings call, CFO Sherry House said that recent EV launches in Europe, including the Explorer, Capri, and Puma Gen-E, helped more than double Model e’s wholesale volume in Q1.

After early success in the US, Ford also launched its “Power Promise” promotion in Europe, offering EV buyers a free home charger and several other perks.

Source: Reuters

FTC: We use income earning auto affiliate links. More.

Continue Reading

Trending