Headline
NCC Alerts Nigerians On New Ways Hackers Unlock, Steal Vehicle, Android Apps

The Nigerian Communications Commission (NCC) says it wishes to alert telecom consumers and members of the public on an ongoing cyber-vulnerability that allows a nearby hacker to unlock vehicles, start their engines wirelessly and make away with the cars.
It said that the fact that car remotes are categorized short range devices that make use of radio frequency (RF) to lock and unlock cars informed the need for the Commission to alert the general public on this danger, where hackers take advantage to unlock and start a compromised car.
According to the latest advisory released by the Computer Security Incident Response Team (CSIRT), the Cybersecurity Centre for the telecom sector established by the NCC, the vulnerability is a Man-in-the-Middle (MitM) attack or, more specifically, a replay attack, in which an attacker intercepts the RF signals normally sent from a remote key fob to the car, manipulates these signals, and re-sends them later to unlock the car at will.
READ ALSO: 5G: Exciting Opportunities Await Firms, Digitally-inclined Nigerians – NCC
The Commission said that with this latest type of cyber-attack, it is also possible to manipulate the captured commands and re-transmit them to achieve a different outcome altogether.
“Multiple researchers disclosed a vulnerability, which is said to be used by a nearby attacker to unlock some Honda and Acura car models and start their engines wirelessly.
“The attack consists of a threat actor capturing the radio frequency (RF) signals sent from your key fob to the car and resending these signals to take control of your car’s remote keyless entry system,” the advisory stated emphatically.
However, the NCC-CSIRT, in the advisory, has offered some precautionary measures that could be adopted by car owners to prevent falling victim to the attack.
According to the cyber-alert unit of the Commission, “When affected, the only mitigation is to reset your key fob at the dealership. Besides, the affected car manufacturer may provide a security mechanism that generate fresh codes for each authentication request, this makes it difficult for an attacker to ‘replay’ the codes thereafter.”
It said that vulnerable car users should store their key fobs in signal-blocking ’Faraday pouches’ when not in use.
Importantly, the Commission said that car owners in the stated categories are advised to choose Passive Keyless Entry (PKE) as opposed to Remote Keyless Entry (RKE), which would make it harder for an attacker to read the signal due to the fact that criminals would need to be at close proximity to carry out their nefarious acts.
READ ALSO: NCC Discovers New Ways Hackers Steal Banking Details From Phone, Warns Nigerians
It explained that the PKE is an automotive security system that operates automatically when the user is in proximity to the vehicle, unlocking the door on approach or when the door handle is pulled, and also locking it when the user walks away or touches the car on exit.
The RKE system, according to the Commission, on the other hand, represents the standard solution for conveniently locking and unlocking a vehicle’s doors and luggage compartment by remote control.
Additionally, in a related advisory, the NCC, based on another detection by CSIRT, informed the general public about the resurgence of Joker Trojan-Infected Android Apps on Google Play Store.
This arose due to the activities of criminals who intentionally download legitimate apps from the Play Store, modify them by embedding the Trojan malware and then uploading the app back to the Play Store with a new name.
It said that the malicious payload is only activated once the apps goes live on the Play Store, which enables the apps to scale through Google’s strict evaluation process.
Once installed, these apps request for permissions that once granted, enable the apps to have access to critical functions such as text messages and notifications.
As a consequence, it explained further that a compromised device will subscribe unwitting users to premium services, billing them for services that do not exist. A device like this can also be used to commit Short Messaging Service (SMS) fraud while the owner is unaware.
“It can click on online ads automatically and even use SMS One Time password (OTPs) to secretly approve payments. Without checking bank statements, the user will be unaware that he or she has subscribed to an online service. Other actions, such as stealing text messages, contacts, and other device data, are also possible,” the Commission said.
It warned that to avoid falling victim to the manipulation of hackers deploying Joker Trojan-Infected Android Apps, Android users must avoid downloading unnecessary apps or installing apps from unofficial sources.
READ ALSO: NCC Alerts Nigerians On Flubot Malware, Lists Measures To Guard Against Attack
The NCC also said it wishes to advise telecom consumers to ensure that apps installed from the Google Play Store are heavily scrutinized by reading reviews, assessing the developers, perusing the terms of use and only granting the necessary permissions.
The NCC recommended that unauthorised transactions be checked against any installed app, DAILY POST reports.
“Indeed, any apps not in use should be deleted while users are also advised to ensure that a device is always patched and updated to the latest software,” the Commission said in a statement signed by Dr. Ikechukwu Adinde, its Director of Public Affairs.
Headline
South Korea, Japan Protest China, Russia Aircraft Incursions

South Korea and Japan reacted furiously on Wednesday after Chinese and Russian military aircraft conducted joint patrols around the two countries, with both Seoul and Tokyo scrambling jets.
South Korea said it had protested with representatives of China and Russia, while Japan said it had conveyed its “serious concerns” over national security.
According to Tokyo, two Russian Tu-95 nuclear-capable bombers on Tuesday flew from the Sea of Japan to rendezvous with two Chinese H-6 bombers in the East China Sea, then conducted a joint flight around the country.
The incident comes as Japan is locked in a dispute with China over comments Prime Minister Sanae Takaichi made about Taiwan.
READ ALSO:China Backs Nigeria, Warns Against Foreign Interference
The bombers’ joint flights were “clearly intended as a show of force against our nation, Defence Minister Shinjiro Koizumi wrote on X Wednesday.
Top government spokesman Minoru Kihara said that Tokyo had “conveyed to both China and Russia our serious concerns over our national security through diplomatic channels”.
Seoul said Tuesday the Russian and Chinese warplanes entered its air defence zone and that a complaint had been lodged with the defence attaches of both countries in the South Korean capital.
“Our military will continue to respond actively to the activities of neighbouring countries’ aircraft within the KADIZ in compliance with international law,” said Lee Kwang-suk, director general of the International Policy Bureau at Seoul’s defence ministry, referring to the Korea Air Defence Identification Zone.
READ ALSO:Trial For South Korean Woman Accused Of ‘Suitcase Murders’ Starts Today
South Korea also said it deployed “fighter jets to take tactical measures in preparation for any contingencies” in response to the Chinese and Russian incursion into the KADIZ.
The planes were spotted before they entered the air defence identification zone, defined as a broader area in which countries police aircraft for security reasons but which does not constitute their airspace.
Japan’s defence ministry also scrambled fighter jets to intercept the warplanes.
Beijing later Tuesday confirmed it had organised drills with Russia’s military according to “annual cooperation plans”.
READ ALSO:South Korean Actress Kim Sae-ron Found Dead In Seoul Apartment
Moscow also described it as a routine exercise, saying it lasted eight hours and that some foreign fighter jets followed the Russian and Chinese aircraft.
Since 2019, China and Russia have regularly flown military aircraft into South Korea’s air defence zone without prior notice, citing joint exercises.
In November last year, Seoul scrambled jets as five Chinese and six Russian military planes flew through its air defence zone.
Similar incidents occurred in June and December 2023, and in May and November 2022.
READ ALSO:Russia Insists Ukraine Must Cede Land Or Face Continued Military Push
Meanwhile, Tokyo said Monday it had scrambled jets in response to repeated takeoff and landing exercises involving fighter jets and military helicopters from China’s Liaoning aircraft carrier as it cruised in international waters near Japan.
It also summoned Beijing’s ambassador after military aircraft from the Liaoning locked radar onto Japanese jets, the latest incident in the row ignited by Takaichi’s comments backing Taiwan.
Takaichi suggested last month that Japan would intervene militarily in any Chinese attack on the self-ruled island, which Beijing claims as its own and has not ruled out seizing by force.
AFP
Headline
Thousands Reported To Have Fled DR Congo Fighting As M23 Closes On Key City

Fierce fighting rocked the eastern Democratic Republic of Congo on Tuesday as the Rwanda-backed M23 militia rapidly advanced towards the strategic city of Uvira, with tens of thousands of people fleeing over the nearby border into Burundi, sources said.
The armed group and its Rwandan allies were just a few kilometres (miles) north of Uvira, security and military sources told AFP.
The renewed violence undermined a peace agreement brokered by US President Donald Trump that Kinshasa and Kigali signed less than a week ago, on December 4.
Trump had boasted that the Rwanda-DRC conflict was one of eight he has ended since returning to power in America in January.
READ ALSO:Ambassadorial Nominees: Ndume Asks Tinubu To Withdraw List
With the new fighting, more than 30,000 people have fled the area around Uvira for Burundi in the space of a week, a UN source and a Burundian administrative source told AFP.
The Burundian source told AFP on condition of anonymity he had recorded more than 8,000 daily arrivals over the past two days, and 30,000 arrivals in one week. A source in the UN refugee agency confirmed the figure.
The Rwanda-backed M23 offensive comes nearly a year after the group seized control of Goma and Bukavu, the two largest cities in eastern DRC, a strategic region rich in natural resources and plagued by conflict for 30 years.
Local people described a state of growing panic as bombardments struck the hills above Uvira, a city of several hundred thousand residents.
“Three bombs have just exploded in the hills. It’s every man for himself,” said one resident reached by telephone.
READ ALSO:South Africa Beat DR Congo In shootout To Finish Third At AFCON
“We are all under the beds in Uvira — that’s the reality,” another resident said, while a representative of civil society who would not give their name described fighting on the city’s outskirts.
Fighting was also reported in Runingo, another small locality some 20 kilometres (12 miles) from Uvira, as the M23 and the Rwandan army closed in.
Burundi views the prospect of Uvira falling to Rwanda-backed forces as an existential threat, given that it sits across Lake Tanganyika from Burundi’s economic capital Bujumbura.
The city is the main sizeable locality in the area yet to fall to the M23 and its capture would essentially cut off the zone from DRC control.
READ ALSO:Stampede Kills 37 During Army Recruitment In Congo Capital
Burundi deployed about 10,000 soldiers to eastern DRC in October 2023 as part of a military cooperation agreement, and security sources say reinforcements have since taken that presence to around 18,000 men.
The M23 and Rwandan forces launched their Uvira offensive on December 1.
Rich in natural resources, eastern DRC has been choked by successive conflicts for around three decades.
Violence in the region intensified early this year when M23 fighters seized the key eastern city of Goma in January, followed by Bukavu, capital of South Kivu province, a few weeks later.
– Regional risk –
The peace deal meant to quell the fighting was signed last Thursday in Washington by Congolese President Felix Tshisekedi and his Rwandan counterpart Paul Kagame, with Trump — who called it a “miracle” deal — also putting his signature to it.
READ ALSO:FULL LIST: US To Review Green Cards From 19 ‘Countries Of Concern’ After Washington Shooting
The agreement includes an economic component intended to secure US supplies of critical minerals present in the region, as America seeks to challenge China’s dominance in the sector.
But even on the day of the signing, intense fighting took place in South Kivu, where Uvira is located, which included the bombing of houses and schools.
Witnesses and military sources in Uvira said that Congolese soldiers fleeing the fighting had arrived in the city overnight Monday and shops were looted at dawn.
Several hundred Congolese and Burundian soldiers had already fled to Burundi on Monday, according to military sources, since the M23 fighters embarked on their latest offensive from Kamanyola, some 70 kilometres north of Uvira.
Since the M23’s lightning offensive early this year, the front had largely stabilised over the past nine months.
Burundian President Evariste Ndayishimiye warned in February there was a danger of the conflict escalating into a broader regional war, a fear echoed by the United Nations.
Headline
‘Santa Claus’ Arrested For Possessing, Distributing Child Sexual Abuse Material

A 64-year-old man from Hamilton Township has been arrested in the United States after investigators linked him to the possession and distribution of child sexual abuse material.
The suspect, identified as Mark Paulino, had been working as a “Santa for hire” at holiday events, a role that placed him in repeated contact with children.
Mercer County officials said the investigation began on 4 December when detectives were alerted to suspicious online activity involving the uploading of child pornography from a residence in Hamilton Township. The probe quickly identified Paulino, a retired elementary school teacher, as the person involved.
READ ALSO:Nigerian Ringleader Of Nationwide Bank Fraud, Money Laundering Jailed In US, Says FBI
Police stated that Paulino had presented himself online as a retired teacher and had recently performed as Santa Claus for photographs and private, corporate, and organisational events. “Because this role involved direct, repeated contact with children, detectives worked around the clock to secure a search warrant,” authorities explained.
The warrant was executed on 5 December, during which police seized multiple items regarded as evidentiary. Paulino was taken into custody without incident and charged with possession and distribution of child sexual abuse materials, as well as endangering the welfare of a child.
Prosecutors have filed a motion to detain him pending trial. The investigation remains ongoing, and authorities have urged members of the public with relevant information to come forward.
News10 hours agoI’m Not Distracted By Anti-Niger Delta Elements, Says PAP Boss, Otuaro
Metro9 hours agoSuspected Kidnappers Abduct 18 Passengers On Benin-Akure Road
News18 hours agoEdo Assembly Charges Contractor Handling Ekekhuan Road To Accelerate Work
News8 hours agoOPINION: Time For The Abachas To Rejoice
News10 hours agoOkpebholo Pledges To Clear Inherited Salary Arrears, Gratuities At AAU
News10 hours agoEx-Nigerian Amb., Igali, To Deliver Keynote Address As IPF Holds Ijaw Media Conference
Metro9 hours agoNDLEA Seizes 457kg of Cannabis, Arrests Suspected Trafficker In Edo












