Anything that is connected to the internet, can be at risk of a hack.
In the days where ordinary objects can be made smart by turning them into Internet of Things (IoT) devices, those objects become part of the internet itself, and can be hacked by those halfway across the globe.
This time, 25 Tesla cars from 13 different countries have been hacked by David Colombo, a 19-year-old cybersecurity researcher from Germany.
Colombo accidentally came across a vulnerability that allowed him to control the many Teslas.
After doing some more researches, he found hundreds of cars in Germany, Belgium, Finland, Denmark, the UK, the U.S., Canada, and China, that were also at risk from this vulnerability.
To confirm his finding, Colombo contacted some Tesla owners whose cars he managed to hack using the personal information the car owners had shared with their cars. One of the owners helped him confirm his findings.

The issue came from a third-party software used by the Tesla owners.
The things hackers could do when exploiting this vulnerability is limited to disabling the anti-theft system, remotely opening the doors and windows, accessing the radios, flash the headlights, honk, and start the engine and begin “keyless driving.”
Fortunately, the vulnerability doesn't allow hacker access to the car's steering, acceleration or braking functions.
Regardless, Colombo thinks it is still significant to cause harm if the hacker has malicious intent.
"I think it can also lead to some potentially somewhat dangerous situations on the road, if you're like driving on the highway, and then randomly, someone starts blasting music at max volume or stuff like this," he said.
And obviously, the biggest risk here is for someone to abuse the vulnerability to locate a Tesla, go to its location, and unlock it via the vulnerable third-party application.
Colombo has stressed that the flaw is not with Tesla's systems and that he is working with the makers of the third-party app, which only some Tesla owners use to fix the issues.
According to Colombo, the vulnerability was "not a vulnerability in Tesla’s infrastructure" but rather "it’s the owners faults."
The only Teslas that were exposed were those whose owners used a specific third-party app.
Because the issue is huge, Colombo decided to publicly disclose this information since he could not find the contact details of all of the affected car owners.

When he was first interviewed, Colombo declined to reveal all the details about his findings - such as the name of the third-party app - given that some of the vulnerabilities he discovered are yet to be fixed.
David Colombo claimed to have started coding since he was 10 years old, and attended school only for two days a week while spending the rest of this time doing jobs as a cybersecurity consultant dealing with cybersecurity issues. According to his LinkedIn profile, his company’s goal is to “help every business to get protected from the ever-evolving and dangerous threat actors in the cyber space.”
And this vulnerability in Tesla was discovered when he was performing a security audit for a French company, when he noticed a software program on the company's network that exposed all the data about the Chief Technology Officer's Tesla vehicle.
Elon Musk, CEO of Tesla, pledged that he would work with regulators on ensuring that electric car drivers’ personal data is protected from the threat of hackers.
"With the rapid growth of autonomous driving technologies, data security of vehicles is drawing more public concerns than ever before," he once said in an electric vehicle conference in China.
As more internet-connected cars hit the road, the more of these vehicles expose user data.
Matters can go from bad to worse, or worst, if hackers find ways to remotely control the vehicles.
















































































































































































































































































































































































