M_CAN in dark web
On July 13, the until then unknown D1R cybergang claimed to have stolen CAN VHDL files owned by Bosch through an alleged breach of Synopsys, a silicon design partner of the German automotive supplier.
In the meantime, Synopsys stated, it has found no evidence of a data breach as claimed by the ransomware group. The cybercriminals listed both companies on its leak site, alleging exploitation of a vulnerability in Synopsys' website to access a corporate client database. The cybergang gave an eleven-day ultimatum before publishing the alleged stolen files.
Bosch confirmed that M_CAN implementation details are temporarily on the dark web. The dark web is an encrypted, hidden part of the internet, intentionally unindexed by search engines such as Googe, for example. It requires specialized software (such as the Tor browser) to access and utilizes encrypted overlay networks. While often associated with illicit activity and cybercrime, it also provides vital privacy for whistleblowers and journalists. It is both, a platform for illegal business and criminals as well as for opponents of authoritarian regimes.
Bosch’s CAN experts stated that there is no risk to use M_CAN implementations in new or existing applications, supporting CAN CC (classic) and CAN FD protocols. There are no security vulnerabilities, because of the illegal publication of M_CAN implementation details. Anyway, nobody knows (except Bosch’s engineers), if the illegally published documents were modified by the hackers or provide the original content.
Contact
CAN in Automation (CiA)
Kontumazgarten 3
DE-90429 Nuremberg
Tel.: +49-911-928819-0
Fax: +49-911-928819-79
E-mail: marketing(at)can-cia.org