IOActive Logo
  • BLOGS
  • contact us
  • SERVICES
    • FULL STACK SECURITY ASSESSMENTS
    • SECURE DEVELOPMENT LIFECYCLE
    • RED TEAM AND PURPLE TEAM SERVICES
    • AI/ML SECURITY SERVICES
    • SUPPLY CHAIN INTEGRITY
    • ADVISORY SERVICES
    • TRAINING
    • OCP SAFE
  • INDUSTRIES
    • CRITICAL INFRASTRUCTURE
    • ENERGY
    • FINANCIAL SERVICES
    • HEALTHCARE
    • MANUFACTURING
    • MEDIA & ENTERTAINMENT
    • RETAIL & CONSUMER PRODUCTS
    • TECHNOLOGY
    • TELECOMMUNICATIONS
    • TRANSPORTATION
      • AVIATION
      • MARITIME
      • RAIL
      • VEHICLE
  • RESOURCES
    • BLOGS
    • RESEARCH
    • DISCLOSURES
    • LIBRARY
    • TOOLS
  • CAREERS
  • WHO WE ARE
    • TEAM
    • EVENTS
    • PRESS
    • PHILANTHROPY
    • CORPORATE OVERVIEW
IOActive Logo
  • SERVICES
    • FULL STACK SECURITY ASSESSMENTS
    • SECURE DEVELOPMENT LIFECYCLE
    • RED TEAM AND PURPLE TEAM SERVICES
    • AI/ML SECURITY SERVICES
    • SUPPLY CHAIN INTEGRITY
    • ADVISORY SERVICES
    • TRAINING
    • OCP SAFE
  • INDUSTRIES
    • CRITICAL INFRASTRUCTURE
    • ENERGY
    • FINANCIAL SERVICES
    • HEALTHCARE
    • MANUFACTURING
    • MEDIA & ENTERTAINMENT
    • RETAIL & CONSUMER PRODUCTS
    • TECHNOLOGY
    • TELECOMMUNICATIONS
    • TRANSPORTATION
      • AVIATION
      • MARITIME
      • RAIL
      • VEHICLE
  • RESOURCES
    • BLOGS
    • RESEARCH
    • DISCLOSURES
    • LIBRARY
    • TOOLS
  • CAREERS
  • WHO WE ARE
    • TEAM
    • EVENTS
    • PRESS
    • PHILANTHROPY
    • CORPORATE OVERVIEW

Article Categories: ARTICLE

ARTICLE | January 16, 2025

Tom’s Hardware | Raspberry Pi’s RP2350 Hacking Challenge results announced — four winners are each awarded the full $20K prize

Tom’s Hardware | Check out this article from Tom’s Hardware highlighting IOActive’s recent win for ‘Extracting antifuse secrets from RP2350 by FIB/PVC’ during the RP2350 Hacking Challenge hosted by Raspberry Pi.

“Data bits stored in the RP2350’s OPT memories, based on antifuses, were extracted using a well-known semiconductor failure analysis technique leveraging passive voltage contrast (PVC) with a focused ion beam (FIB).

IOActive’s five-strong team reckons their unique attack vector is potent enough to apply to other systems using antifuse memory for confidentiality. Organizations using antifuse memory this way should therefore “immediately reassess their security posture,” says IOActive, and at least use chaffing techniques to make it harder for attackers to recover any data.”

ARTICLE | January 14, 2025

Forbes Exclusive | Raspberry Pi Confidential Data Hack Attack—What You Need To Know

Forbes | IOActive researchers recently applied a new technique during the RP2350 Hacking Challenge hosted by Raspberry Pi. This Forbes article highlights our team’s research, which secured a win during the challenge for “Extracting antifuse secrets from RP2350 by FIB/PVC.”

… “The fully-invasive antifuse memory reading technique we demonstrated with the example RP2350 can very likely be utilized against other types of antifuse memories,” IOActive’s senior vice president of research and strategy, John Sheehy, told me, “which are frequently used to store small amounts of infrequently changing data and may include sensitive data requiring confidentiality such as shared or private cryptographic keys.”

ARTICLE | December 16, 2024

Popular Science | Researchers hack digital license plates, demonstrating way to evade tolls and cops

Popular Science | Josep Pi Rodriguez, IOActive Principal Consultant, recently featured his discovery of a technique to ‘jailbreak’ digital license plates in this piece from Popular Science.

“… Cybersecurity researchers at from IOActive have demonstrated how a similar type of sleight of hand can potentially be performed in the real-world by hacking a popular brand of new digital driver’s license plates. By using a “fault injection” hardware attack, the researches have shown how a hacker could, hypothetically at least, essentially jailbreak a digital license display and replace the plate number with a custom message of the hacker’s choosing.”

ARTICLE |

WIRED | Hackers Can Jailbreak Digital License Plates to Make Others Pay Their Tolls and Tickets

WIRED | IOActive’s Josep Pi Rodriguez, Principal Security Consultant, was recently featured in a Wired article, ‘Hackers Can Jailbreak Digital License Plates to Make Others Pay Their Tolls and Tickets,’ where he discussed a technique that he discovered to “”jailbreak” digital license plates sold by Reviver, the leading vendor of those plates in the US with 65,000 plates already sold.”

“That susceptibility to jailbreaking, Rodriguez points out, could let drivers with the license plates evade any system that depends on license plate numbers for enforcement or surveillance, from tolls to speeding and parking tickets to automatic license plate readers that police use to track criminal suspects. “You can put whatever you want on the screen, which users are not supposed to be able to do,” says Rodriguez. “Imagine you are going through a speed camera or if you are a criminal and you don’t want to get caught.””

ARTICLE | November 20, 2024

Corporate Vision Award | IOActive: Research-Driven Cybersecurity Brilliance

Corporate Vision | IOActive was recently named ‘Best Research-Led Security Services Provider 2024 – USA‘ for the “ability to help its clients understand their vulnerabilities and risks.” Corporate Vision’s November issue expanded more into the award with a business spotlight highlighting the recent win and what makes IOActive unique.

“At the heart of IOActive is a deep understanding of the ‘attacker’s perspective’, something that has served as the foundation for the in-depth research it has carried out and the services it today offers to industries around the world. The company’s steadfast dedication to research is grounded in the knowledge that it must remain one step ahead of looming threats so as to protect everything- from industries and devices to governments- with maximum efficiency.”

ARTICLE | November 7, 2024

FORESIGHT: Smart buildings are on the rise. So are cyberattacks

FORESIGHT | John Sheehy, IOActive Senior Vice President, Research & Strategy, was recently featured in an article, ‘Smart buildings are on the rise. So are cyberattacks,’ discussing how the increase in technology in smart buildings has created an increased risk in potential for cyberattacks.

“… “These complex cyber-physical systems expose the building and occupants to new risks and threats that in the past required physical access to realise negative consequences,” says John Sheehy of IOActive, a cybersecurity firm based in the United States.

… Hackers can render buildings unliveable by intentionally manipulating the temperature and altering humidity and air quality, says Sheehy. Emergency systems designed to protect buildings could also be rendered useless.”

ARTICLE | October 1, 2024

CareerInfoSecurity: Gone in 30 Seconds: Kia Hack Unveiled

CareerInfoSecurity | Gunter Ollmann, IOActive Chief Technology Officer, was featured in a piece from CareerInfoSecurity discussing a recent breach in online services from carmaker Kia that allowed attackers to unlock doors & start engines in Kia automobiles.

‘Cars have been a favorite target for security researchers as software and electronic control units dominate what once were purely analog machines. Smartphone apps capable of controlling core vehicle functionality “expose those traditional physical functions to the communication and security frailties of internet protocols and applications,” said Gunter Ollmann, IOActive chief technology officer.’

ARTICLE | September 23, 2024

BankInfoSecurity: US Pushes Ban on Chinese, Russian Tech in Connected Vehicles

BankInfoSecurity | John Sheehy, IOActive Senior Vice President Research and Strategy, was recently featured in a piece from BankInfoSecurity discussing the White House administration’s decision to take steps “to ban Chinese connected vehicle hardware and software from reaching the U.S. market, warning Monday of escalating foreign threats to the information and communications technology supply chain.”

“The proposed regulation will significantly improve vehicle cybersecurity in the U.S. by mitigating supply chain threats from known adversaries like China, according to John Sheehy, senior vice president of research and strategy for the research security firm IOActive.”

ARTICLE | August 9, 2024

‘Sinkclose’ Flaw in Hundreds of Millions of AMD Chips Allows Deep, Virtually Unfixable Infections

WIRED | “Researchers warn that a bug in AMD’s chips would allow attackers to root into some of the most privileged portions of a computer—and that it has persisted in the company’s processors for decades.” Check out this piece from WIRED featuring research from IOActive Principal Security Consultants, Enrique Nissim and Krzysztof Okupski, on a vulnerability in AMD chips called Sinkclose.

ARTICLE | July 17, 2024

Not if, but when

Inflight Magazine | Our very own John Sheehy, IOActive Senior Vice President, Research & Strategy, recently shared his thoughts in this Inflight Magazine piece, ‘Not if, but when,’ discussing cybersecurity in aviation. “While there is a broader acceptance of the importance of cybersecurity in aviation and within aircraft themselves, there are still significant opportunities for improvement.”

Posts pagination

Page 1 Page 2 … Page 34 Next page
IOActive Logo
  • NEWSLETTER SIGN UP

  • COPYRIGHT AND AI WARNING 

  • ©2025 IOActive Inc. All Rights Reserved. This website, including all material, images, and data contained herein, are protected by copyright. All rights are reserved. Content may not be used, copied, reproduced, transmitted, or otherwise exploited in any manner, including without limitation, to train generative artificial intelligence (AI) technologies, without IOActive’s prior written consent. Without limiting IOActive’s exclusive rights under copyright laws, IOActive reserves all rights to license uses of this work for generative AI training and development of machine learning language models.

    • SERVICES
      • Full Stack Security Assessments
      • Secure Development Lifecycle
      • AI/ML Security Services
      • Red and Purple Team Services
      • Supply Chain Integrity
      • Advisory Services
      • Training
      • OCP SAFE
    • RESOURCES
      • Blogs
      • Research
      • Disclosures
      • Library
      • Tools
    • INDUSTRIES
      • Critical Infrastructure
      • Energy
      • Financial Services
      • Healthcare
      • Manufacturing
      • Media & Entertainment
      • Retail & Consumer Products
      • Technology
      • Telecommunications
      • Transportation
    • WHO WE ARE
      • Team
      • Philanthropy
      • Press
      • Events
      • Corporate Overview
    • CAREERS
    • CONTACT US
    ©2025 IOActive Inc. All Rights Reserved.
    • Privacy Policy
    • Cookie Policy
    • Terms of Use
    • Disclosure Policy