Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Your phone doesn’t block SIM swapping attacks by default: Turn on these carrier settings now

    August 7, 2026

    New WordPress Pre-Auth XSS Could Lead to PHP Code Execution

    August 7, 2026

    Crypto Business Converges With Traditional Banking

    August 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Your phone doesn’t block SIM swapping attacks by default: Turn on these carrier settings now
    • New WordPress Pre-Auth XSS Could Lead to PHP Code Execution
    • Crypto Business Converges With Traditional Banking
    • Sensing the Poles’ Hidden Heat
    • A banana byproduct transforms farm waste into profits in Bangladesh
    • Enbridge adding strategic LNG infrastructure to US Gulf Coast growth pipeline
    • A Drying Danube River Reveals Nazi-Era Vessels, and Hazards of Heat
    • Gianni Infantino: Norway call for Fifa president to resign but Mexico and Argentina show support
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, August 7
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 7, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Black Hat — The National Motor Freight Traffic Association (NMFTA) says a 2024 safety recall for Bendix’s EC80 heavy-truck brake controller quietly fixed a set of serious vulnerabilities, including a wirelessly reachable remote code execution flaw, alongside the memory corruption issue Bendix publicly disclosed. 

    The findings were detailed by NMFTA senior cybersecurity research engineer Ben Gardiner on Thursday at the Black Hat USA 2026 conference.

    The EC80 electronic control unit (ECU) handles anti-lock braking, traction control and stability functions on heavy commercial vehicles. It communicates over J2497, also known as PLC4TRUCKS, a powerline databus that has served since 2001 as the only industry-standard way to meet federal trailer ABS warning-light requirements. 

    SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity

    In late 2024, three OEMs that integrate the EC80 issued recalls — covering an estimated 450,000 units — after Bendix identified memory corruption issues that could take the ECU offline. Bendix attributed the issue to line noise on J2497 and shipped a fix. 

    Gardiner said he reverse-engineered pre- and post-update firmware from three EC80 units, one from each affected OEM, and found that the update deleted dozens of functions.

    Advertisement. Scroll to continue reading.

    Inside that deleted code the researcher identified several vulnerabilities, including buffer-handling flaws that could crash the ECU and enable remote code execution, a hardcoded password that could disable traction control, and a flaw offering a theoretical path to both a crash and code execution.

    Security implications and potential real-world impact

    J2497 can be reached remotely — a technique tied to a vulnerability disclosed by NMFTA in 2022 — or through a compromised trailer telematics device. 

    NMFTA researchers tested the potential impact of the new vulnerabilities in a bench environment and, for closed-track road tests, used a software-defined radio to inject signals through a truck’s diagnostic port, simulating a wireless attack. 

    Driving below 5 mph and around 9 mph, they observed that CAN bus traffic stopped entirely once the crash was triggered, and that recovering the ECU always required disconnecting the battery. This denial-of-service (DoS) state consistently caused loss of speedometer, steering assist, and shifting, as well as ABS pulsing.

    Asked whether those real-world effects could put a driver at risk of a crash or be used to immobilize a truck, for example during a cargo theft operation, NMFTA told SecurityWeek the outcome depends heavily on context. 

    Driver agreements would likely bar operating a truck in the affected state, with NMFTA noting that recovery needs a battery disconnect and, in one case, a dealer tool. However, causing a crash directly isn’t clear-cut because the attacks don’t take away the driver’s control of the vehicle. 

    Nevertheless, NMFTA noted the impacts were serious enough for Bendix to issue a recall. On the other hand, Gardiner noted that none of the vulnerabilities received a CVE identifier despite being fixed, arguing that this may obscure the security significance of what was framed publicly as a safety-only update. 

    NMFTA contacted Bendix and briefed two of the three affected OEMs, along with NHTSA and Transport Canada, before making its findings public.

    On whether the fix has actually reached affected trucks, NMFTA pointed to NHTSA’s public recall-completion tracker, which on July 16 showed recall completion rates ranging between 0 and 99% for identifiers associated with this recall. NMFTA believes that recall completion rates commonly plateau around 80% industry-wide due to factors like lost equipment and underreporting.

    After the Black Hat talk, NMFTA published a 179-page technical whitepaper detailing the findings.

    Bendix has not responded to SecurityWeek’s request for comment. 

    Related: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

    Related: Free Wi-Fi Leaves Buses Vulnerable to Remote Hacking

    brake controllers doubled fix hidden Recall safety Security truck
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    New WordPress Pre-Auth XSS Could Lead to PHP Code Execution

    Sensing the Poles’ Hidden Heat

    The exploit window is shrinking. Most security workflows are not

    You’re only as secure as your last evaluation

    Vishing Extortion Group UNC6671 Rebrands After Making Millions

    What is the cost of a data breach cost?

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Your phone doesn’t block SIM swapping attacks by default: Turn on these carrier settings now

    August 7, 2026

    New WordPress Pre-Auth XSS Could Lead to PHP Code Execution

    August 7, 2026

    Crypto Business Converges With Traditional Banking

    August 7, 2026

    Sensing the Poles’ Hidden Heat

    August 7, 2026
    Latest Posts

    Angela Rayner rules out rent controls in England

    July 24, 2026

    Merz names Nina Warken chancellery chief in Cabinet reshuffle – POLITICO

    July 24, 2026

    US attacks Iran as Houthis allow Chinese ships to pass: What’s the latest? | US-Israel war on Iran News

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Your phone doesn’t block SIM swapping attacks by default: Turn on these carrier settings now

    August 7, 2026

    New WordPress Pre-Auth XSS Could Lead to PHP Code Execution

    August 7, 2026

    Crypto Business Converges With Traditional Banking

    August 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.