Summaries
Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.
Showing 1-2 of 2 results
| Date | Provider | Score | Summary |
|---|---|---|---|
| 11 Aug 2026, 8:05 PM | The Hacker News | 5.5 | A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
Researchers from the University of Birmingham and Fuzzware found that a malicious SIM card can execute attacker-chosen code on cellular modems via a 'RUN AT' interface, present in 9 of 26 devices tested. Six of eight cellular modules accepted the command—including five Quectel parts pulled from an EV charger, industrial router, and car telematics unit—while only 3 of 18 phones did (OPPO Find X5, OPPO Reno 14 F 5G, ASUS Zenfone 9). All nine vulnerable devices run Qualcomm communication processors; Qualcomm has built a hardened config that disables the interface by default for future devices, but neither Qualcomm nor Quectel has published a public advisory. Why: If you ship or operate cellular IoT fleets—EV chargers, industrial routers, telematics—ask your module supplier today whether RUN AT is enabled in the firmware they ship, since there is no central patch and Quectel's vulnerability portal is login-walled. The attack requires physical SIM access, so unattended devices with accessible SIM trays and few other interfaces are the highest-risk targets. |
| 11 Aug 2026, 5:37 PM | The Register | 5.5 | Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G
Researchers from the University of Birmingham and Fuzzware presented a toolkit called CATANA at USENIX WOOT that exploits proactive SIM functionality—specifically the RUN AT command—to hijack cellular modems. Testing 26 devices (18 smartphones, 8 IoT modems), they found 9 exposed an AT command interface to the SIM, enabling code execution, file theft, denial of service, and forced 2G downgrades. Demonstrated attacks include code execution on an Autel EV charger via a Quectel EC25-AFX module and 198 AT commands accessible on an Oppo Reno14 F 5G, including one that forced a stubborn downgrade to 2G that couldn't be reversed by toggling airplane mode or changing network settings. Why: If you ship IoT devices with cellular modules (especially Quectel modems, which are common in Malaysian IoT and fleet deployments), audit whether your modem exposes the AT command interface to the SIM and whether you can disable proactive SIM commands. The Oppo Reno14 F 5G is a consumer device sold in Malaysia, so the 2G-downgrade and shutdown attacks are directly relevant to local mobile users—worth flagging if you build mobile apps or advise on device security. |