The Containment Era is here. →Explore

Industry Category

Automotive

Breach intelligence, attack campaigns, and threat reports targeting the Automotive sector.

146 threat reports
Page 4 of 13

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Automotive Threat Reports

Showing 3748 / 146 reports
Critical DoS Vulnerability in Rockwell Automation RSLinx Classic: CVE-2020-13573
Impact· HIGH

Critical DoS Vulnerability in Rockwell Automation RSLinx Classic: CVE-2020-13573

In November 2020, a denial-of-service (DoS) vulnerability, identified as CVE-2020-13573, was discovered in Rockwell Automation's RSLinx Classic software, version 2.57.00.14 CPR 9 SR 3. This vulnerability resides in the Ethernet/IP server functionality and can be exploited by remote attackers sending specially crafted network requests, leading to a DoS condition. The vulnerability was reported by Cisco Talos and has a CVSS v3.0 base score of 7.5, indicating high severity. ([talosintelligence.com](https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1184?utm_source=openai)) The relevance of this vulnerability persists due to the widespread deployment of RSLinx Classic in industrial control systems. Exploitation could disrupt critical manufacturing, energy, and water sectors, emphasizing the need for timely patching and adherence to cybersecurity best practices to mitigate potential threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Check Point VPN Zero-Day Exploited by Qilin Ransomware
Impact· CRITICAL

Check Point VPN Zero-Day Exploited by Qilin Ransomware

In early May 2026, Check Point identified a critical authentication bypass vulnerability, CVE-2026-50751, in its Remote Access VPN and Mobile Access products configured with the deprecated IKEv1 protocol. This flaw allows unauthenticated remote attackers to establish VPN connections without valid credentials. Exploitation began on May 7, 2026, affecting a limited number of organizations globally, with at least one incident linked to the Qilin ransomware group. Check Point has released patches and mitigation measures to address this vulnerability. The exploitation of CVE-2026-50751 underscores the risks associated with using outdated protocols like IKEv1. Organizations are urged to update their systems promptly and transition to more secure configurations to prevent unauthorized access and potential ransomware attacks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Vulnerability in ABB's PPT30 Operating System: CVE-2025-11482
Impact· HIGH

Critical Vulnerability in ABB's PPT30 Operating System: CVE-2025-11482

On May 26, 2026, ABB disclosed a vulnerability (CVE-2025-11482) in its PPT30 Operating System versions prior to 1.8.0. This flaw resides in the OPC-UA Server component, where an unauthenticated attacker can exploit resource allocation issues to cause a denial-of-service condition, rendering the server unresponsive and disrupting industrial control processes. The vulnerability has a CVSS v3.1 base score of 7.5, indicating a high severity level. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-11482?utm_source=openai)) The disclosure underscores the critical need for timely patching in industrial control systems to prevent potential operational disruptions. Organizations are advised to upgrade to version 1.8.0 or later and implement network segmentation to mitigate risks associated with this vulnerability. ([feed.craftedsignal.io](https://feed.craftedsignal.io/briefs/2026-05-abb-ppt30-cve-2025-11482/?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Security Flaws Discovered in XCharge C6 EV Chargers
Impact· CRITICAL

Critical Security Flaws Discovered in XCharge C6 EV Chargers

In May 2026, multiple critical vulnerabilities were identified in XCharge's C6 electric vehicle charging controllers, including CVE-2026-9037, CVE-2026-9038, and CVE-2026-9039. These flaws could allow attackers to gain administrative rights or execute unauthorized code on affected devices. The vulnerabilities encompass issues such as unverified firmware updates, stack-based buffer overflows, and insecure default configurations. Exploitation of these vulnerabilities could lead to significant control over critical infrastructure in transportation systems worldwide. ([windowsforum.com](https://windowsforum.com/threads/cisa-warns-xcharge-c6-ev-chargers-have-3-critical-flaws-cvss-9-8.420545/?utm_source=openai)) The increasing integration of IoT devices in critical infrastructure highlights the urgency of addressing such vulnerabilities. Ensuring robust security measures and timely updates is essential to prevent potential disruptions and maintain the integrity of essential services.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Enhancing Industrial Security: AI-Assisted Sparkplug B Protocol Fuzzer Released
Impact· HIGH

Enhancing Industrial Security: AI-Assisted Sparkplug B Protocol Fuzzer Released

In May 2026, Bishop Fox released a security fuzzer for the Sparkplug B protocol, a dominant MQTT-based protocol in industrial control and SCADA environments. This tool systematically tests all nine message types, 19 data types, and over 87 unique field paths defined by the Eclipse Sparkplug specification. The fuzzer was developed with AI assistance, specifically utilizing Claude Code to identify coverage gaps and Python defects, resulting in a hardened, self-contained tool with CLI, logging, and passive network discovery capabilities. This development is crucial for ICS and SCADA operators, device vendors, and defenders, as it enables the identification of crashes, protocol violations, and state-handling bugs in Sparkplug B endpoints before attackers can exploit them. The tool is available on GitHub for immediate use.

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in ABB Terra AC Wallbox Chargers: CVE-2025-5517
Impact· MEDIUM

Critical Vulnerability in ABB Terra AC Wallbox Chargers: CVE-2025-5517

In October 2025, ABB disclosed a heap-based buffer overflow vulnerability (CVE-2025-5517) affecting multiple models of its Terra AC wallbox electric vehicle chargers. This flaw could allow attackers to execute arbitrary code, cause denial-of-service conditions, or gain unauthorized access. Exploitation requires either a man-in-the-middle position with unencrypted communication or a compromised Charging Station Management System (CSMS). ABB has released firmware updates to address this issue and recommends users update their devices promptly. This incident underscores the critical importance of securing industrial control systems, especially as electric vehicle infrastructure becomes more widespread. Organizations should ensure encrypted communications and regularly update firmware to mitigate such vulnerabilities.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities in ABB B&R Automation Runtime Threaten Industrial Systems
Impact· MEDIUM

Critical Vulnerabilities in ABB B&R Automation Runtime Threaten Industrial Systems

In October 2025, ABB B&R Automation Runtime versions prior to 6.4 were found to have multiple vulnerabilities, including CVE-2025-3449, CVE-2025-3448, and CVE-2025-11498. These flaws could allow unauthenticated attackers to hijack sessions, execute arbitrary JavaScript in users' browsers, and inject malicious formulas into CSV files. Exploitation required network access and user interaction, posing significant risks to industrial control systems. The discovery of these vulnerabilities underscores the critical need for robust security measures in industrial automation environments. As cyber threats targeting operational technology increase, organizations must prioritize timely updates and comprehensive security practices to safeguard against potential exploits.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities Discovered in ABB Terra AC Wallbox EV Chargers
Impact· MEDIUM

Critical Vulnerabilities Discovered in ABB Terra AC Wallbox EV Chargers

In September 2025, ABB identified multiple buffer overflow vulnerabilities in its Terra AC Wallbox electric vehicle chargers, specifically affecting firmware versions up to 1.8.33. These vulnerabilities, cataloged as CVE-2025-10504, CVE-2025-12142, and CVE-2025-12143, could allow attackers with adjacent network access and high privileges to execute arbitrary code, potentially leading to unauthorized control over the device. ABB promptly released firmware version 1.8.36 to address these issues and recommended immediate updates to mitigate potential risks. The discovery of these vulnerabilities underscores the critical importance of securing IoT devices, especially those connected to critical infrastructure like energy distribution. As the adoption of electric vehicle chargers grows, ensuring robust cybersecurity measures is essential to prevent potential exploitation that could disrupt services and compromise user safety.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Critical Vulnerability in Universal Robots' PolyScope 5: CVE-2026-8153
Impact· CRITICAL

Critical Vulnerability in Universal Robots' PolyScope 5: CVE-2026-8153

In May 2026, a critical command injection vulnerability (CVE-2026-8153) was discovered in the Dashboard Server interface of Universal Robots' PolyScope 5 software. This flaw allowed unauthenticated attackers with network access to execute arbitrary commands on the robot's operating system, potentially leading to full system compromise. Universal Robots promptly addressed the issue by releasing version 5.25.1, which patches the vulnerability. Organizations utilizing affected versions are strongly advised to update immediately to mitigate potential risks. This incident underscores the growing cybersecurity challenges in operational technology (OT) environments, particularly as industrial systems become more interconnected. The exploitation of such vulnerabilities can lead to significant operational disruptions and safety hazards, highlighting the need for robust security measures and timely software updates in critical infrastructure.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Update: Siemens ROS# Path Traversal Vulnerability (CVE-2026-41551)
Impact· CRITICAL

Critical Update: Siemens ROS# Path Traversal Vulnerability (CVE-2026-41551)

In May 2026, Siemens disclosed a critical path traversal vulnerability (CVE-2026-41551) in ROS# versions prior to 2.2.2. This flaw allows remote attackers to access arbitrary files on the host system due to improper sanitization of user input. Exploitation requires network access and can lead to unauthorized reading and writing of files with the privileges of the user running the service. Siemens has released version 2.2.2 to address this issue and recommends immediate updates. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-357982.html?utm_source=openai)) This incident underscores the importance of robust input validation in software development, especially in industrial automation systems. The vulnerability's high CVSS score of 9.1 highlights the severe risk posed to organizations using affected versions of ROS#. Prompt patching and adherence to security best practices are essential to mitigate such threats.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Škoda Online Shop Data Breach: A Wake-Up Call for E-Commerce Security
Impact· MEDIUM

Škoda Online Shop Data Breach: A Wake-Up Call for E-Commerce Security

In May 2026, Škoda Auto disclosed a data breach affecting its online shop, where attackers exploited a software vulnerability to gain unauthorized access. The compromised data includes customer names, addresses, email addresses, phone numbers, order details, and login credentials. Notably, financial information remained secure as it was processed by external payment service providers. Upon detection, Škoda promptly addressed the vulnerability, reported the incident to authorities, and initiated a forensic investigation. This incident underscores the critical importance of robust cybersecurity measures in e-commerce platforms. With the increasing frequency of such breaches, organizations must prioritize regular security assessments, timely patching of vulnerabilities, and comprehensive incident response plans to protect customer data and maintain trust.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability in ABB B&R Automation Studio: CVE-2025-11043
Impact· HIGH

Critical Vulnerability in ABB B&R Automation Studio: CVE-2025-11043

In January 2026, ABB disclosed a critical vulnerability (CVE-2025-11043) in its B&R Automation Studio software versions prior to 6.5. This flaw involves improper certificate validation in the OPC-UA and ANSL over TLS clients, potentially allowing unauthenticated attackers to intercept and manipulate data exchanges. Such exploitation could lead to unauthorized access and control over industrial automation systems, posing significant risks to operational integrity. The increasing reliance on secure communication protocols in industrial control systems underscores the importance of robust certificate validation mechanisms. This incident highlights the necessity for organizations to promptly update affected systems and implement comprehensive security measures to mitigate similar vulnerabilities.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports