Researchers find way to listen in on headphones from afar
Researchers unveiled InjectEave, an electromagnetic injection side-channel attack that recovers audio from headphones and landline phones up to 30 meters away through walls.
Researchers from HKUST and The Hong Kong Polytechnic University presented InjectEave at USENIX Security 2026, an active EM side-channel attack that injects 0-9 MHz RF signals into nonlinear components such as amplifiers, ADCs, and power converters to modulate and leak target audio. Tested on 11 off-the-shelf devices including Sony, HP, Philips, Apple, and Xiaomi products, the attack recovered intelligible headphone audio from up to 30 meters with an RF amplifier, generally 1-6 meters otherwise, including through walls. The attack uses commodity gear such as a USRP B210 SDR and a Siglent spectrum analyzer, is immune to digital defenses like encryption, and is only partially mitigated by shielding, twisted-pair wiring, and filtering.
Automobile Camouflage to Hide from Flock Cameras
Schneier on Security highlights a printed vehicle-camouflage pattern tested to defeat Flock surveillance cameras and Axon body cameras.
The post discusses covering cars with printed patterns designed to fool Flock automated license-plate recognition software, with testing reportedly done against Flock and Axon body cameras. Reader comments question effectiveness against other ALPR vendors, Flock's RF MAC-address upgrade, and whether such camouflage might become regulated. The page also contains off-topic comment threads about anti-bot over-blocking and privacy.
Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity
Researchers introduce InjectEave, using electromagnetic injection and hardware nonlinearity to induce side-channel leakage and eavesdrop on headphone audio from 30 meters.
An arXiv paper shows electromagnetic injection can actively amplify side-channel leakage: nonlinear hardware such as amplifiers, ADCs, and power converters modulates secret electrical signals onto an injected EM carrier, upconverting low-frequency secrets into measurable EM emissions. By tuning injection frequency and amplitude, an adversary can shape the effective spectrum and entropy of the resulting leakage. The InjectEave attack demonstrated eavesdropping on wired and wireless headphone audio from up to 30 meters and in through-wall scenarios using accessible RF equipment, plus leakage of smart home device power consumption and analog sensor inputs. Case studies show closed-loop eavesdropping and manipulation of landline phone conversations, and the paper discusses mitigations.