Your Car Is Talking to Big Tech, Plus 3 Stories
Cars have been computers on wheels for years. The part that keeps getting stranger is how many other computers they talk to and how much of that connected car privacy has very little to do with getting you from one place to another.
Your car may be telling Big Tech more than you think
Researchers at Northeastern University, working with Consumer Reports, tested 21 late-model vehicles and 30 companion apps to see where their data actually went. This was not a survey asking people whether they trusted their car company. The researchers put cars on controlled networks, built a Faraday enclosure to isolate traffic, and watched the connections.
The result is worth paying attention to. Consumer Reports says 28 of the 30 mobile apps contacted at least one outside advertising or analytics company. Seven sent at least one piece of personally identifiable information: a name, vehicle identification number, or precise location to an outside company. Several apps paired a VIN with an email address or location data. That matters because a VIN is a durable identifier. It is not a cookie you clear on Friday afternoon because you finally got annoyed enough.
Who’s receiving the data?
The outside recipients included companies such as Google, Amazon, Meta, Microsoft, Pinterest, Reddit, Adobe Analytics, and other advertising, analytics, and data services. That does not automatically mean each company was selling the information. Several automakers told Consumer Reports that service providers are contractually barred from independently using or selling the data they receive. That distinction matters.
So does another one: the researchers could see which domains the cars themselves contacted. But much of the vehicle traffic was encrypted. They had better visibility into the companion apps because they controlled the phones. In other words, this study gives us unusually good evidence about the ecosystem. It does not prove the contents of every encrypted packet leaving every car.
Still, I think the basic consumer problem is hard to dodge. When you buy a car, you are buying a machine that increasingly comes with an account, a phone app, cellular connectivity, location services, analytics, and third-party infrastructure attached. We have already seen that car dashboards have become ordinary networked computers. Now we are getting a clearer picture of the data exhaust that comes with them.
If you own a newer connected vehicle, spend five minutes in the manufacturer’s app and privacy portal. Look for data-sharing, advertising, location, driver-behavior, and deletion controls. If you do not use a feature that needs precise location or a companion app at all, consider whether it needs that permission. You may lose some convenience. That is a real tradeoff. What should not be a real tradeoff is pretending that accepting a 9,000-word privacy policy while trying to activate remote start is meaningful informed consent when it comes to connected car privacy.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
Two Zammad flaws are being exploited — and they chain badly
If you self-host Zammad for customer support, this is the item that needs action today.
The Dutch Institute for Vulnerability Disclosure, or DIVD, says two newly disclosed Zammad vulnerabilities were used to breach DIVD itself on September 21. The first, CVE-2026-102489, can lead to remote code execution as the lower-privileged zammad service user in affected 6.x installations. DIVD says the flaw is also present in Zammad 7.0.0 through 7.1.3 but is not exploitable there under the relevant environment conditions.
The second flaw, CVE-2026-102490, is local privilege escalation. Once an attacker has code execution as the zammad user, that weakness can let the attacker become root. Put the two together and a helpdesk application that is supposed to receive support tickets can become a path from the internet to full control of its host.
Recording the vulnerabilities doesn’t fix them
Both vulnerabilities are now in CISA’s Known Exploited Vulnerabilities catalog, and October 5 is the federal remediation deadline. That deadline legally applies to covered federal agencies, not every private business running Zammad. I would not use that distinction as a reason to wait. CISA puts vulnerabilities on KEV because exploitation is known to be happening, not because somebody produced an impressive slide deck about what might happen someday.
DIVD’s current recommendation is to upgrade to Zammad 7 or take the affected service offline. If your system was exposed while vulnerable, patching is step one, not the entire incident response plan. Preserve logs, check for unexpected processes and persistence, review authentication and session activity, and assume you need to prove the system was not compromised rather than assuming the update erased history.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
Honda wants the road to charge electric trucks while they move
Honda, Taisei, and Taisei Rotec say they have developed the underlying technology for a road that wirelessly charges electric vehicles while they are driving. The technical name is dynamic wireless power transfer, or DWPT, and the basic idea is much less mystical than it sounds: power-transfer units are embedded in the pavement, a receiving unit is mounted on the vehicle, and magnetic coupling moves energy across the gap without a cable.
Honda is initially aiming at logistics and transportation, where charging downtime and battery size become expensive very quickly. The companies say their development work is aimed at passenger vehicles through roughly 20-ton commercial vehicles. Testing will include durability under repeated heavy loads, electromagnetic-field leakage, high-speed operation, and eventually output of up to 150 kilowatts. A public-road demonstration in Japan is planned for fiscal 2027 or later.
This is the part where a shiny technology announcement usually turns into a claim that charging stations are obsolete. They are not. Honda has demonstrated underlying engineering and laid out a testing path. It has not demonstrated that digging up enough highway to build this infrastructure is cheaper than fast chargers, larger batteries, depot charging, or some combination of all three. Reuters asked about that comparison, and a Honda engineer said the economics still have to be evaluated.
That is exactly why this is interesting. Electric trucking is not just a battery problem. It is a utilization problem, a grid problem, and an infrastructure problem. Charging a truck while it is already doing the thing you bought the truck to do could be enormously useful. First we have to find out whether electrifying the pavement makes economic sense outside a test track.
Technology is rarely just about the technology
Some of the most important technology stories aren’t product launches at all. They’re about health, privacy, education, law, accessibility, work, and what happens when technology reaches ordinary people. Browse more Raymond Tec News for the stories worth understanding without the hype.
Google’s AI problem is now too many fake bug reports
Here is a delightfully ordinary problem for the AI era: Google says automation made it too cheap to submit bad work.
Google has paused new product vulnerability submissions to its Open Source Software Vulnerability Rewards Program after what it called a “significant rise” in automated submissions, the vast majority of which were invalid. The pause took effect October 1, and Google says it expects to provide an update in the first quarter of 2027.
The wording matters. Google did not shut down every bug bounty it operates, nor did it stop accepting every possible open-source security report. Some Google Cloud repositories can still go through the Cloud VRP, supply-chain reports are unaffected, and the Patch Rewards Program remains available. This is a specific intake channel being reworked because human maintainers were spending too much time sorting machine-generated noise from useful findings.
There is a larger lesson here for anyone adding AI to a workflow. Automation can make producing an answer dramatically cheaper without making checking that answer any cheaper at all. If one person with a model can generate 500 plausible-looking vulnerability reports, somebody still has to determine whether report number 417 describes an exploitable bug or a confident paragraph about code that does not exist.
That applies well beyond bug bounties. Support tickets, code review, sales leads, resumes, security alerts, customer complaints — if AI increases the volume entering a system, the receiving side needs better evidence requirements, triage, deduplication, and rate limits. “We added AI” is not a capacity plan.
Put today’s stories together and the theme is not really AI, privacy, cars, or security. It is verification. Verify:
- What your car is sending.
- Whether a patched server was already compromised.
- Whether a futuristic road works economically, not merely technically.
And if a machine can generate a report in three seconds, verify that the report deserves three minutes of a human being’s time.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Consumer Reports: Your Car Is Sharing Data With Big Tech Companies, Study Finds
- Northeastern University: Connected-car privacy research
- DIVD CSIRT: CVE-2026-102489
- DIVD CSIRT: CVE-2026-102490
- DIVD CSIRT: Zammad vulnerability case file
- Honda: In-motion wireless charging technology
- Reuters: Honda plans highway test of wireless charging for moving trucks
- TechCrunch: Google pauses open-source bug bounty submissions
- Help Net Security: AI submissions overwhelm Google’s OSS VRP
Photo by the Amritdev on Pexels.
