/
    Zpět na blog
    Security Sunday

    Waze Is Watching You

    image

    Waze started as an open project with an ambitious goal — to create the world’s most accurate navigation system using data from drivers themselves. Today, the app has tens of millions of users who voluntarily share their locations, report accidents, and traffic jams. What many don’t realize: this very model has turned Waze into one of the most extensive surveillance systems of our time.

    The first serious problems were uncovered in 2019 by security researcher Peter Gasper, who discovered critical vulnerabilities in the Waze API. Gasper demonstrated that through the Waze web interface, he could obtain GPS coordinates of nearby drivers along with their unique identification numbers, which remained constant over time. This made it possible to track specific users in real-time throughout their entire journey. Even worse was the discovery that when a user confirmed an obstacle on the road or a police patrol, the API returned not only their ID but also their username. Google fixed the vulnerability and paid the researcher a bounty of $1,337.

    In February 2025, an even more serious security risk came to light. Israeli security expert Amitay Dan warned that Waze reveals the exact locations of IDF military bases, strategic facilities, and even military patrol routes. “This is the deadliest mass intelligence gathering system in Israel,” Dan told Israeli outlet Calcalist. The problem lies in soldiers using Waze while on patrol or traveling to their bases. Map editors, who can be virtually anyone after registration, can see these routes and mark them. Even more dangerous is the fact that all raw user movement data is accessible through the Waze editing platform.

    February 2025 brought yet another alarming report — 7.687 million Waze user records appeared for sale on the dark web, including usernames, unique IDs, and real-time GPS locations. The combination of GPS data with personal identifiers creates dangerous potential for stalking.

    Tesla Hacked at Pwn2Own Automotive 2026

    The global ethical hacking competition Pwn2Own Automotive 2026, held from January 21–23 in Tokyo, revealed alarming findings about the security of modern automotive technologies. On the very first day, security researchers demonstrated a total of 37 previously unknown vulnerabilities (zero-days) and took home rewards totaling $516,500. Media and professional attention focused primarily on a successful attack against the Tesla vehicle infotainment system.

    French security team Synacktiv became the main hero of the first day when they successfully gained full root access to the Tesla infotainment system through a USB-based attack. The researchers chained two critical vulnerabilities — an information leak and an out-of-bounds write bug that allows data to be written outside the allocated memory area. This combination of exploits gave attackers complete control over the system.

    The technical complexity of the attack on the Tesla infotainment system lay in careful preparation and precise exploit chaining. The attack was designed to be executed through a standard USB interface that drivers use every day to connect their devices. This makes the attack particularly dangerous because, in a real-world scenario, it could be exploited through an infected USB flash drive.

    However, Tesla wasn’t the only target of security researchers at this year’s Pwn2Own Automotive. Significant attention was also paid to electric vehicle charging infrastructure.

    Team Fuzzware.io, which ultimately became the overall winner of the competition with total rewards of $215,000, demonstrated vulnerabilities in Alpitronic HYC50 and Autel charging stations, as well as the Kenwood DNR1007XR navigation receiver. Other teams, including PetoWorks and DDOS, successfully compromised chargers from Phoenix Contact, ChargePoint, and Grizzl-E.

    VoidLink: A New Era of AI-Generated Malware

    Researchers at Check Point Research have uncovered an advanced Linux malware called VoidLink, whose 88,000 lines of code were created by AI.

    The framework recognizes major cloud platforms including AWS, Google Cloud, Microsoft Azure, Alibaba, and Tencent Cloud, and can adapt its behavior when it detects it’s running inside a Docker container or Kubernetes pod.

    The malware features more than 30 modular plugins covering a wide spectrum of functions — from reconnaissance and credential harvesting through lateral movement to anti-forensic tools and rootkit capabilities. Thanks to its architecture inspired by Cobalt Strike Beacon, VoidLink represents a significantly more sophisticated threat than typical Linux malware.

    VoidLink’s origins in artificial intelligence might have remained hidden if not for operational security mistakes by its creator. Researchers discovered development artifacts that clearly point to AI-driven development. Key indicators included systematic formatting of debug outputs, the use of placeholder data typical of language model training examples, and uniform API versioning. Additionally, the attacker accidentally exposed internal planning documents written in Chinese that bore all the characteristics of large language model output.

    Fortinet Confirms FortiCloud SSO Vulnerability Patch Is Incomplete

    Fortinet is facing a serious security situation after it emerged that the critical vulnerability CVE-2025–59718 in the FortiCloud SSO system was not fully patched. Attackers are actively exploiting this flaw to penetrate fully updated FortiGate firewalls.

    The situation escalated in mid-January 2026 when administrators worldwide began reporting unauthorized access to their FortiGate devices. Arctic Wolf warned that the campaign began on January 15, with attackers creating VPN access accounts and stealing firewall configurations within seconds. These attacks show clear signs of automation.

    Vulnerability CVE-2025–59718, originally disclosed in early December 2025 with a critical CVSS score of 9.1 and which we reported on in a previous Security Sunday, stems from improper cryptographic signature verification. This flaw allows remote attackers to bypass authentication via FortiCloud Single Sign-On and gain administrator privileges. The issue affects FortiOS, FortiProxy, and FortiSASE products. Although Fortinet released patches, it appears that attackers have found a way to bypass these fixes.

    Carl Windsor, Fortinet’s Chief Information Security Officer, confirmed that cases have been identified where exploitation occurred on devices running the latest firmware version. The company is now working on a complete fix for the vulnerability and warns that the problem affects not only FortiCloud SSO but all SAML SSO implementations.

    © 2026 Patrik Žák. Všechna práva vyhrazena.