InjectEave eavesdrops, ex‑AT&T employee jailed, Glasswing gaps
InjectEave can extract audio via RF from consumer devices; ex‑AT&T employee Kenneth Carter jailed 16 months for SIM swaps; VulnCheck found 202 of 26,153 Glasswing entries fixed.
Researchers have demonstrated InjectEave, a radio‑frequency side‑channel technique that can force hardware components in consumer devices to emit low‑frequency analog signals carrying audio and appliance‑state information.
The team tested 11 commercial products, including headphones, VoIP phones, smart fans and lamps. By injecting tuned RF signals they induced nonlinear responses in components and recovered intelligible audio from headphones and phones and detected patterns that revealed whether appliances were on or off. The experiments did not require physical access to the devices or changes to their software.
In a separate legal case, former AT&T employee Kenneth Carter was sentenced to 16 months in federal prison for performing unauthorized SIM swaps. Court filings show three victims faced intended losses totaling nearly $600,000. The filings list payments to Carter of between $1,000 and $2,000 for each fraudulent SIM swap. The court documents describe that the swaps allowed criminals to receive calls and text messages tied to victims’ accounts and to access banking accounts.
VulnCheck reviewed Anthropic’s Project Glasswing ledger and recorded the status of 26,153 reported findings. After almost five months, 202 entries were marked fixed and 245 were withdrawn. The review compared severity labels from Anthropic’s Claude model with maintainer ratings for a sample: Claude labeled 91.5% of those findings high or critical, while maintainers labeled 51.3% at those levels.
Side‑channel attacks like InjectEave rely on physical and electromagnetic properties of hardware rather than software flaws. SIM swapping is a fraud method that transfers a victim’s phone number to a device controlled by an attacker, enabling interception of SMS or voice‑based codes. Project Glasswing is a public ledger that records external security reports to coordinate disclosure and remediation.
The three developments report an RF injection technique that can expose audio, a sentencing in an insider‑enabled SIM swap scheme, and a review of remediation rates in a vulnerability ledger.







