The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Automotive
Breach intelligence, attack campaigns, and threat reports targeting the Automotive sector.
Explore Other Sectors
Automotive Threat Reports
Psychedelic Stealer Targets Ukraine Through Fake Cloudflare ClickFix Campaign
In September 2026, threat actors compromised legitimate Ukrainian business websites to inject fake Cloudflare verification pages as part of a ClickFix campaign distributing Psychedelic Stealer malware. The attack targeted various Ukrainian businesses including healthcare facilities, retailers, and manufacturers, using social engineering to trick victims into executing malicious MSI installers that harvested browser credentials, cryptocurrency wallets, and account tokens. Arctic Wolf Labs documented 557 views with 426 clicks across the campaign, primarily targeting Ukrainian users but also affecting victims in the US, Poland, Germany, Canada, and the Netherlands. This incident highlights the growing sophistication of information stealer campaigns that exploit trusted brand impersonation and legitimate website compromise to bypass security controls. The emergence of new stealer families like Psychedelic, combined with advanced evasion techniques and modular malware ecosystems, represents an escalating threat to credential security and highlights the urgent need for enhanced egress filtering and behavioral monitoring capabilities.
7 hours ago
Kill Chain
Critical Path Traversal Flaw Exposes Siemens Industrial Systems to Remote File Access
Siemens SIMOVE Fleetmanager and SIPLANT industrial management systems contain a critical path traversal vulnerability (CVE-2026-67367) with a CVSS score of 8.6. The flaw allows unauthenticated remote attackers to read arbitrary files from the underlying operating system through improper validation of directory traversal sequences in the embedded HTTP server's file-serving endpoint. Affected systems span multiple product versions deployed worldwide in critical manufacturing sectors, potentially exposing sensitive data including credential stores, private keys, and configuration secrets. This vulnerability highlights the persistent security challenges in industrial control systems and operational technology environments. As organizations increasingly digitize their manufacturing operations and connect OT systems to corporate networks, path traversal vulnerabilities in critical infrastructure components represent a growing attack surface that demands immediate attention and systematic security controls.
2 days ago
Kill Chain
Critical Authentication Bypass in Mitsubishi Electric GX Works3 Exposes Industrial Control Systems
In September 2026, CISA disclosed CVE-2026-15688, a critical authentication bypass vulnerability in Mitsubishi Electric's GX Works3 and Motion Control Settings software used in industrial control systems worldwide. The vulnerability, scored 8.8 (CVSS v3.1) and 9.2 (CVSS v4.0), allows local attackers to bypass block password authentication by modifying executable modules in memory, enabling unauthorized access to view, tamper with, destroy, or delete control programs in critical manufacturing environments. This incident highlights the growing threat landscape targeting industrial control systems as cyber adversaries increasingly focus on critical infrastructure. With ICS environments becoming more connected and the rise of sophisticated state-sponsored attacks on manufacturing facilities, authentication vulnerabilities in widely-deployed engineering software represent significant risks to operational technology security and industrial resilience.
6 days ago
Kill Chain
APT37 Embeds Malware in Load Balancers to Spy on South Korean Industries
A North Korean advanced persistent threat group, likely APT37, conducted sophisticated espionage operations against South Korean media and automotive companies throughout 2025-2026. The attackers compromised HAProxy load balancers to deploy a custom Linux toolkit called 'TED', gaining access to decrypted communications and conducting long-term surveillance operations. The group harvested credentials, modified log files to hide their tracks, and maintained persistent access to target networks for intelligence collection on media sources and manufacturing technology. This incident represents a significant evolution in APT tactics, demonstrating how threat actors are embedding malicious code directly into production infrastructure rather than deploying traditional malware. The targeting of critical industrial sectors and the sophisticated load balancer compromise technique highlight the growing threat to network appliances and the need for enhanced infrastructure security.
1 week ago
Kill Chain
Critical XSS Vulnerability in Siemens Teamcenter Exposes Manufacturing Systems to Web-Based Attacks
A reflected cross-site scripting (XSS) vulnerability (CVE-2026-58113) was discovered in Siemens Teamcenter's authentication redirect flow, affecting multiple versions across V2412, V2506, V2512, and V2606 product lines. The vulnerability allows unauthenticated remote attackers to inject malicious JavaScript into authenticated user sessions through crafted URLs, potentially enabling data theft and unauthorized actions within victims' Teamcenter sessions. Siemens has released patches for all affected versions and recommends immediate updates to mitigate the CVSS 6.1 rated vulnerability. This incident highlights the persistent threat of web application vulnerabilities in critical manufacturing systems, particularly as organizations increasingly rely on web-based PLM platforms for sensitive industrial operations and intellectual property management.
1 week ago
Kill Chain
IDScan Breach Exposes 153 Million Driver's Licenses: A Wake-Up Call for Identity Verification Security
In September 2026, identity verification company IDScan confirmed a significant data breach affecting over 153 million driver's license scans and personal identification documents. Threat actors gained unauthorized access to IDScan's cloud platform, compromising customer data including full names, driver's license numbers, and scanned copies of government-issued IDs. The stolen data was subsequently advertised on a dark web platform called 'Nexus' before being taken offline following FBI investigation. IDScan provides identity verification services to car rental companies, financial institutions, cannabis dispensaries, and hospitality businesses across the US and Canada. This incident highlights the growing threat to identity verification infrastructure as cybercriminals increasingly target centralized repositories of sensitive personal data. The breach demonstrates how third-party service providers handling critical identity documents have become high-value targets, creating cascading privacy risks across multiple industries that rely on these verification services.
2 weeks ago
Kill Chain
Microsoft Warns of Critical Security Gaps in Edge AI Deployments
Microsoft published a comprehensive security advisory in September 2024 addressing critical vulnerabilities in Edge AI deployments where machine learning models execute on customer-owned infrastructure. The advisory highlights fundamental security model changes when AI systems move from centralized cloud services to edge environments, exposing organizations to prompt injection attacks, model tampering, and malicious firmware updates. Customer-owned Edge AI deployments face increased attack surfaces as models, credentials, and sensitive data operate in potentially hostile environments outside cloud providers' direct security controls. This advisory emerges as organizations rapidly adopt Edge AI for cost optimization, data sovereignty, and reduced latency, creating new attack vectors that traditional software security controls cannot adequately address.
2 weeks ago
Kill Chain
Critical Vulnerabilities Expose Rockwell Automation Industrial Control Systems to Remote Attacks
CISA disclosed two critical vulnerabilities (CVE-2026-19471, CVE-2026-19472) affecting Rockwell Automation's ArmorStart LT motor protection devices version 2.001 and earlier. CVE-2026-19471 involves stored cross-site scripting (XSS) vulnerabilities that allow attackers to inject malicious scripts executed when users access affected web pages. CVE-2026-19472 is a denial-of-service vulnerability triggered by crafted HTTP PUT requests that can disable the embedded web server. Both vulnerabilities require no authentication and can be exploited remotely, potentially compromising industrial control systems used in critical manufacturing worldwide. These vulnerabilities highlight the growing attack surface of industrial IoT devices and the critical need for secure-by-design principles in operational technology environments, especially as industrial systems become increasingly connected to enterprise networks.
2 weeks ago
Kill Chain
Ted Backdoor Reveals Critical Gap in Load Balancer Security
In September 2026, North Korean state-sponsored actors deployed a sophisticated backdoor called 'Ted' by compromising HAProxy load balancers at two South Korean organizations in the automotive and media sectors. The attackers replaced legitimate HAProxy binaries with trojanized versions containing embedded malware that intercepted web traffic and served altered pages to selected visitors. The implant operated covertly by handling command-and-control requests without reaching backend servers, erasing traces from connection logs and statistics. The attack toolkit included additional trojans targeting system binaries like sshd and crond, along with a companion remote access trojan called curlRAT that maintained persistent access to compromised systems. This incident highlights the evolving sophistication of supply chain attacks where legitimate infrastructure components are weaponized to establish persistent footholds in critical networks. The attack demonstrates advanced techniques for traffic manipulation and steganographic communication that bypass traditional security controls focused on network perimeter defense.
2 weeks ago
Kill Chain
Critical Privilege Escalation Flaw Exposes Industrial Control Systems to Complete Compromise
A critical privilege escalation vulnerability (CVE-2026-16675) was discovered in Rockwell Automation's FactoryTalk Activation Manager V5.02 and below, affecting industrial control systems worldwide. The vulnerability allows authenticated attackers to hijack console windows during installation or repair operations, escalating from standard user privileges to SYSTEM-level access with complete control over affected systems. This poses significant risks to critical manufacturing infrastructure, as attackers can access all files, processes, and system resources once exploited. This vulnerability highlights the ongoing security challenges facing industrial control systems as manufacturing environments become increasingly digitized and interconnected, making them attractive targets for cybercriminals and nation-state actors seeking to disrupt critical infrastructure operations.
3 weeks ago
Kill Chain
Critical Privilege Escalation Vulnerabilities Discovered in Rockwell Automation Industrial Systems
In September 2026, CISA disclosed two critical privilege escalation vulnerabilities (CVE-2026-9633 and CVE-2026-9634) in Rockwell Automation's Redundancy Module Configuration Tool affecting versions 9.00.00 through 10.00.00. The vulnerabilities stem from incorrect default permissions that allow the tool's executables to search for required DLLs in directories writable by standard users. If exploited, local attackers can place malicious DLLs in these directories, which are then loaded with Administrator/SYSTEM privileges when the tool is run by an administrator. Rockwell Automation has released version 10.01.00 to address these issues, affecting critical manufacturing infrastructure worldwide. This incident highlights the persistent threat of DLL hijacking attacks in industrial control systems, particularly as organizations modernize their operational technology environments. With increasing convergence of IT and OT networks, such privilege escalation vulnerabilities pose significant risks to critical infrastructure security and operational continuity.
3 weeks ago
Kill Chain
Critical DoS Vulnerability Exposes Rockwell Automation Industrial Controllers to Remote Attack
A critical denial-of-service vulnerability (CVE-2026-9637) affects multiple Rockwell Automation Logix Platform controllers including ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380 systems. The vulnerability stems from improper validation of input length during Common Industrial Protocol (CIP) message processing, allowing remote attackers to trigger a major nonrecoverable fault (MNRF) that requires a complete power cycle to restore operations. Affected versions span firmware releases up to V33 and specific ranges in V34-V36 branches, impacting critical manufacturing infrastructure worldwide. This vulnerability highlights the ongoing targeting of industrial control systems and the critical need for robust OT security measures. As industrial networks become increasingly connected and Nation-state actors continue to probe critical infrastructure, vulnerabilities in widely-deployed platforms like Rockwell's Logix controllers represent significant national security and operational continuity risks that require immediate attention.
3 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports