✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Automotive
Breach intelligence, attack campaigns, and threat reports targeting the Automotive sector.
Explore Other Sectors
Automotive Threat Reports
Jaguar Land Rover 2025 Cyberattack: Lessons in Industrial Cybersecurity
In August 2025, Jaguar Land Rover (JLR) experienced a significant cyberattack that led to a complete halt in vehicle production across its global facilities, including those in the UK, Slovakia, China, India, and Brazil. The attack, attributed to the hacking group 'Scattered Lapsus$ Hunters,' resulted in the shutdown of production lines starting August 31, 2025, with operations remaining suspended until at least October 1, 2025. This disruption caused substantial financial losses, with JLR reporting a pre-tax loss of £485 million for the quarter ending September 30, 2025, marking a stark contrast to the £398 million profit recorded in the same period the previous year. The incident also had a ripple effect on the UK automotive industry, impacting JLR's extensive supply chain and leading to significant economic repercussions. ([theguardian.com](https://www.theguardian.com/business/2025/nov/14/jaguar-land-rover-loss-cyber-attack?utm_source=openai)) The JLR cyberattack underscores the escalating threat of sophisticated cyber incidents targeting critical infrastructure and major corporations. The involvement of 'Scattered Lapsus$ Hunters,' a group comprising elements from notorious hacking collectives like Scattered Spider, Lapsus$, and ShinyHunters, highlights the evolving tactics of cybercriminals who exploit social engineering and known vulnerabilities to infiltrate organizations. This incident serves as a stark reminder for industries worldwide to bolster their cybersecurity measures, enhance incident response strategies, and ensure robust supply chain security to mitigate the risks posed by such advanced persistent threats. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/jaguar-land-rover-shuts-down-production-due-to-ransomware-attack-scattered-lapsus-usd-hunters-takes-responsibility?utm_source=openai))
4 months ago
Kill Chain
CarGurus Data Breach 2026: A Wake-Up Call for Cybersecurity
In February 2026, CarGurus, a prominent online automotive marketplace, experienced a significant data breach orchestrated by the ShinyHunters hacking group. The attackers employed sophisticated voice phishing (vishing) techniques to deceive employees into providing access credentials, leading to the exfiltration of approximately 12.5 million customer records. The compromised data included names, email addresses, phone numbers, physical addresses, user account IDs, finance pre-qualification application data, finance application outcomes, dealer account details, and subscription information. This breach underscores the persistent threat posed by social engineering attacks and highlights the critical need for robust cybersecurity measures and employee training to prevent unauthorized access to sensitive information. The incident also reflects a broader trend of cybercriminals targeting large-scale databases through advanced social engineering tactics, emphasizing the importance of vigilance and proactive security strategies in safeguarding organizational and customer data.
5 months ago
Kill Chain
Advantest 2026 Ransomware Attack: A Wake-Up Call for Semiconductor Cybersecurity
In February 2026, Advantest Corporation, a leading Japanese semiconductor test equipment manufacturer, detected unauthorized access within its IT environment, indicating a ransomware attack. The company promptly activated incident response protocols, isolated affected systems, and engaged third-party cybersecurity experts to investigate and contain the incident. Preliminary findings suggest that an unauthorized third party may have gained access to portions of the company's network and deployed ransomware. The full extent of the impact, including potential compromise of customer or employee data, is under active investigation. ([advantest.com](https://www.advantest.com/en/news/2026/20260219.html?utm_source=openai)) This incident underscores the escalating threat of ransomware attacks targeting critical infrastructure within the semiconductor industry. As adversaries increasingly focus on high-value targets, organizations must enhance their cybersecurity measures to protect sensitive data and maintain operational continuity.
5 months ago
Kill Chain
Siemens Simcenter Femap and Nastran 2026 File Parsing Vulnerabilities
In February 2026, Siemens disclosed multiple vulnerabilities in its Simcenter Femap and Nastran products, specifically affecting versions prior to V2512. These vulnerabilities, identified as CVE-2026-23715 through CVE-2026-23720, involve out-of-bounds read and write errors, as well as heap-based buffer overflows, which can be exploited by attackers through specially crafted NDB and XDB files. Successful exploitation could lead to application crashes or arbitrary code execution within the context of the current process. Siemens has released version V2512 to address these issues and recommends users update to this latest version. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-965753.html?utm_source=openai)) The disclosure of these vulnerabilities underscores the persistent risks associated with file parsing mechanisms in critical engineering software. Organizations utilizing Simcenter Femap and Nastran should prioritize updating to the patched version to mitigate potential exploitation. This incident highlights the importance of regular software updates and vigilance against malicious file-based attacks in industrial environments.
5 months ago
Kill Chain
Delta Electronics ASDA-Soft Vulnerability Exposes Critical Systems to Risk
In January 2026, Delta Electronics disclosed a critical stack-based buffer overflow vulnerability (CVE-2026-1361) in their ASDA-Soft software, versions up to 7.2.0.0. This flaw allows attackers to write arbitrary data beyond the bounds of a stack-allocated buffer, potentially leading to the corruption of a structured exception handler (SEH). Exploitation requires local access and user interaction, but no prior authentication, posing significant risks to confidentiality, integrity, and availability. Delta Electronics has released version 7.2.2.0 to address this issue. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1361?utm_source=openai)) This incident underscores the persistent threat of buffer overflow vulnerabilities in industrial control systems, emphasizing the need for rigorous input validation and timely software updates to mitigate potential exploits.
5 months ago
Kill Chain
Critical Vulnerability in Open62541: Immediate Action Required
In February 2026, a medium-severity vulnerability (CVE-2026-1301) was identified in o6 Automation GmbH's Open62541, an open-source OPC UA stack widely used in industrial automation. The flaw, present in versions from 1.5-rc1 to before 1.5-rc2, allows unauthenticated attackers to send crafted JSON PubSub messages, leading to out-of-bounds writes, process crashes, and potential memory corruption. This vulnerability poses significant risks to industrial control systems, potentially causing operational disruptions and compromising system integrity. ([windowsforum.com](https://windowsforum.com/threads/cve-2026-1301-open62541-json-pubsub-memory-safety-bug-upgrade-to-v1-5-0.400263/?utm_source=openai)) The discovery of this vulnerability underscores the critical importance of rigorous security practices in industrial automation software. Organizations utilizing Open62541 should promptly upgrade to the stable release v1.5.0 to mitigate this risk. Additionally, implementing network segmentation and minimizing exposure of control systems to external networks are essential steps to enhance security posture. ([windowsforum.com](https://windowsforum.com/threads/cve-2026-1301-open62541-json-pubsub-memory-safety-bug-upgrade-to-v1-5-0.400263/?utm_source=openai))
5 months ago
Kill Chain
Mitsubishi Electric's 2026 PLC Vulnerability: A Wake-Up Call for Industrial Network Security
In February 2026, Mitsubishi Electric disclosed a critical vulnerability (CVE-2025-15080) in its MELSEC iQ-R Series programmable logic controllers (PLCs). This flaw allows unauthenticated attackers to read or modify device data and control programs, or to cause a denial-of-service condition by sending specially crafted packets. The affected models include R08PCPU, R16PCPU, R32PCPU, and R120PCPU with firmware versions up to 48. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-15080?utm_source=openai)) This incident underscores the persistent risks in industrial control systems, particularly those exposed to untrusted networks. Organizations must prioritize securing network access to critical infrastructure to prevent unauthorized exploitation of such vulnerabilities.
5 months ago
Kill Chain
Critical Vulnerability in iba Systems ibaPDA Exposes Industrial Systems to Unauthorized Access
In January 2026, a critical vulnerability (CVE-2025-14988) was identified in iba Systems' ibaPDA software, version 8.12.0. This flaw allowed unauthorized actions on the file system, potentially compromising the confidentiality, integrity, and availability of affected systems. The vulnerability was reported by Siemens and disclosed by CISA on January 27, 2026. ([iba-ag.com](https://www.iba-ag.com/en/security/iba-2025-04?utm_source=openai)) Given ibaPDA's widespread use in critical manufacturing sectors worldwide, this vulnerability posed significant risks to industrial operations. Organizations were urged to update to version 8.12.1 or later to mitigate potential exploitation. ([iba-ag.com](https://www.iba-ag.com/en/security/iba-2025-04?utm_source=openai))
5 months ago
Kill Chain
Rockwell Automation's ArmorStart LT Vulnerabilities: A Wake-Up Call for Industrial Security
In January 2026, Rockwell Automation disclosed multiple vulnerabilities in its ArmorStart® LT motor control devices, specifically models 290D, 291D, and 294D up to and including version V2.002. These vulnerabilities, identified as CVE-2025-9464 through CVE-2025-9283, can lead to denial-of-service conditions. Exploitation methods include fuzzing of CIP classes, execution of Achilles Comprehensive grammar tests, and active scanning with tools like Burp Suite, causing devices to become unresponsive or reboot unexpectedly. ([rockwellautomation.com](https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html?utm_source=openai)) The affected devices are widely used in the critical manufacturing sector globally. As of the disclosure, no patches or upgrades were available. Rockwell Automation recommends applying security best practices to mitigate risks, such as minimizing network exposure, placing devices behind firewalls, and using secure remote access methods like VPNs. ([rockwellautomation.com](https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html?utm_source=openai))
5 months ago
Kill Chain
Critical Privilege Escalation Vulnerability Discovered in Iconics Suite
In early 2024, a security assessment revealed a vulnerability in the Iconics Suite, a SCADA system used across various industries. Tracked as CVE-2025-0921, this flaw allows local authenticated attackers to exploit privileged file system operations, potentially leading to a denial-of-service (DoS) condition by corrupting critical system binaries. The vulnerability affects all versions of GENESIS64, MC Works64, and GENESIS version 11.00. Mitsubishi Electric has released advisories detailing measures to address the issue. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/?utm_source=openai)) This incident underscores the critical importance of securing SCADA systems, especially given their role in industrial operations. The discovery of CVE-2025-0921 highlights the need for continuous security assessments and prompt application of vendor-released patches to mitigate potential threats.
5 months ago
Kill Chain
Researchers Disclose Widespread Automotive and EV Vulnerabilities at Pwn2Own 2026
In January 2026, security researchers at the Pwn2Own Automotive World competition uncovered and exploited dozens of critical vulnerabilities in modern vehicle infotainment systems and EV (electric vehicle) chargers from multiple manufacturers. By chaining flaws across network interfaces and poorly secured APIs, attackers demonstrated the ability to remotely compromise vehicle systems, extract sensitive data, and gain unauthorized control over critical vehicle functions. While these attacks were conducted in a controlled, ethical hacking contest, they highlighted the substantial risks posed by connected automotive platforms, which often lack robust segmentation and encryption for internal and external communications. This incident underscores the rapidly escalating threat landscape facing the automotive industry as vehicles integrate more digital and cloud-connected components. The research-driven breach foreshadows what real-world adversaries may attempt, making it urgent for OEMs and suppliers to adopt zero trust, comprehensive monitoring, and proactive vulnerability management.
6 months ago
Kill Chain
Pwn2Own Automotive 2026: Hackers Expose Record 76 Zero-Days in Cars, Chargers & Tesla
Between January 21–23, 2026, the Pwn2Own Automotive competition in Tokyo saw security researchers demonstrate a record-breaking 76 zero-day vulnerabilities across in-vehicle infotainment systems (IVIs), electric vehicle chargers, and automotive operating systems, including high-profile exploits against Tesla, Alpitronic, Autel, Kenwood, and other leading manufacturers. Teams leveraged physical and remote attack vectors, with notable attacks including USB-based chaining to breach Tesla’s infotainment system. The event awarded $1,047,000 in prizes, underscoring significant risks within connected automotive infrastructure. Vendors now have 90 days to issue security patches before public disclosure. This incident highlights a concerning rise in exploitable vulnerabilities within rapidly digitalizing automotive ecosystems. As vehicles integrate more software-driven services and connected devices, adversaries and researchers alike are increasingly shifting focus toward automotive cyberattacks—driving new urgency for robust segmentation, secure update mechanisms, and continuous monitoring.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports