✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Automotive
Breach intelligence, attack campaigns, and threat reports targeting the Automotive sector.
Explore Other Sectors
Automotive Threat Reports
Pwn2Own Automotive 2026: 29 Zero-Days Unmasked in Next-Gen Vehicle Tech
At Pwn2Own Automotive 2026 in Tokyo, security researchers exploited 29 zero-day vulnerabilities on the second day alone, targeting fully patched electric vehicle (EV) chargers, in-vehicle infotainment systems (IVI), and automotive operating systems. Over $439,000 in prizes was awarded for these findings, impacting vendors like Phoenix Contact, ChargePoint, Grizzl-E, Kenwood, Alpine, and Alpitronic HYC50. Notably, researcher teams used advanced exploit chains to achieve root access, demonstrating how attackers could potentially compromise critical automotive technology with little or no prior warning. The event underscores the growing attack surface in connected vehicles and the persistent risk posed by unreported vulnerabilities. This incident highlights a significant surge in automotive cybersecurity threats, especially as EV and smart vehicle adoption accelerates. The frequency and sophistication of these exploits illustrate the urgency for automakers and suppliers to prioritize vulnerability management, rapid patch deployment, and layered defense strategies to protect both consumer safety and data integrity.
6 months ago
Kill Chain
Tesla and Leading Automakers Hacked at Pwn2Own Automotive 2026: 37 Zero-Days Uncovered
In January 2026, security researchers at the Pwn2Own Automotive competition in Tokyo successfully exploited 37 zero-day vulnerabilities across flagship automotive technologies, including Tesla's infotainment system, multiple EV chargers, and in-vehicle digital receivers. The Synacktiv team achieved root access on the Tesla Infotainment System through chained vulnerabilities involving an information leak and out-of-bounds write flaw via USB. Other researchers compromised systems from Sony, Alpitronic, Autel, Kenwood, and Phoenix Contact. The event demonstrates the breadth of exploitable attack surfaces even in patched, production automotive hardware and highlights coordinated vulnerability disclosure processes wherein vendors have 90 days to issue fixes. This incident underscores how automotive technology—including electric vehicles and charging infrastructure—remains a top target for advanced security researchers, with new zero-day vulnerabilities continually emerging. As vehicle software stacks grow in complexity and interconnectivity, the imperative for proactive, industry-wide security controls and coordinated patch processes is increasingly urgent.
6 months ago
Kill Chain
Rockwell Automation Verve Asset Manager Vulnerabilities: 2026 Lessons for Critical Infrastructure
In January 2026, Rockwell Automation disclosed two significant vulnerabilities (CVE-2025-14376, CVE-2025-14377) in its Verve Asset Manager product. These flaws were rooted in insecure and cleartext storage of sensitive data within the legacy ADI server and Ansible playbook components, impacting versions 1.33 through 1.41.3. Exploitation could have allowed attackers with system or network access to retrieve confidential data from environment variables and process files, potentially facilitating lateral movement or further compromises. The issues were addressed in version 1.42, and vulnerable components were made optional in newer releases. This incident is particularly relevant amid heightened attention to supply chain risk and critical infrastructure cybersecurity. As industrial control vendors face rising regulatory pressure and expansion of zero-trust mandates, unencrypted data storage flaws highlight the urgent need for comprehensive data-in-transit and at-rest protections.
6 months ago
Kill Chain
Black Basta Ransomware Boss Named, Placed on Interpol Red Notice in Major 2026 Crackdown
In January 2026, international law enforcement, led by Ukraine and Germany, identified Oleg Evgenievich Nefedov as the leader of the Black Basta ransomware-as-a-service (RaaS) gang. Authorities added Nefedov to Interpol's 'Red Notice' and Europol's 'Most Wanted' lists, following coordinated raids that apprehended affiliates specializing in breaching corporate systems, cracking passwords, and escalating privileges to facilitate attacks. Black Basta has been attributed to over 600 global cyber incidents targeting enterprises in sectors from defense to healthcare, employing ransomware and data extortion to extract payments and exfiltrate sensitive information. This incident is significant as it marks one of the first times a major ransomware operation's leadership was officially unmasked and targeted with international warrants. The Black Basta takedown reflects increasing sophistication and coordination in responses to organized cybercrime, underscoring the persistent threat posed by ransomware groups and their rapid evolution post-Conti.
6 months ago
Kill Chain
Critical Authorization Bypass Hits Siemens Industrial Edge in 2026
In January 2026, Siemens disclosed a critical vulnerability (CVE-2025-40805) affecting the Industrial Edge Device Kit line for both arm64 and x86-64 architectures. The flaw, present in numerous firmware versions, allows unauthenticated remote attackers to bypass user authentication on specific API endpoints by exploiting an authorization weakness. An attacker who learns a legitimate user’s identity could leverage this to impersonate that user and gain illicit control or visibility within industrial environments. Siemens promptly released security updates and mitigation guidance for impacted devices, urging organizations to update or restrict network access as a preventive measure. This incident highlights increasing risks to operational technology (OT) and critical infrastructure, as authentication flaws in widely deployed industrial solutions can expose factories and utilities globally. The CVE underscores growing threats facing manufacturing, regulatory pressure for timely patching, and ongoing urgency for zero trust controls in industrial systems.
6 months ago
Kill Chain
Siemens 2026: Denial-of-Service Flaw Impacts SIMATIC & SIPLUS ICS Devices
In January 2026, Siemens publicly disclosed a denial-of-service vulnerability (CVE-2025-40944) impacting multiple SIMATIC and SIPLUS products used widely in critical manufacturing environments. The flaw allows an attacker to send a specially crafted S7 protocol Disconnect Request (COTP DR TPDU) over TCP port 102, which causes affected devices to become unresponsive, requiring a physical power cycle to restore service. While some products have received security updates, many still await permanent fixes. Incident response measures include network segmentation and port filtering to mitigate risk, as exploitation could disrupt operational technology and industrial control systems worldwide. This incident is especially relevant amid the ongoing focus on industrial cyber defenses, as threat actors increasingly target operational technology. The vulnerability highlights persistent risks from protocol weaknesses and layered third-party supply chains, underscoring the importance of proactive risk management, segmentation, and maintaining up-to-date mitigations in ICS environments.
6 months ago
Kill Chain
Rockwell Automation ICS Devices Exposed by Critical DoS Vulnerability (CVE-2025-9368)
In January 2026, Rockwell Automation disclosed a critical vulnerability (CVE-2025-9368) affecting its 432ES-IG3 Series A industrial Ethernet/IP interface. The flaw, classified as a resource allocation vulnerability (CWE-770), can be exploited remotely to cause a denial-of-service (DoS) condition, rendering the device unresponsive and requiring manual power cycling to restore operations. The vulnerability affects version V1.001 of the device, widely deployed in critical manufacturing environments worldwide. No evidence of active exploitation has been reported as of the initial CISA advisory, but the risk of service disruption in operational technology (OT) networks is significant. This incident underscores the persistent threat posed by resource exhaustion flaws in industrial control systems, as attackers continue to seek low-complexity, high-impact vulnerabilities to disrupt critical infrastructure. With global regulatory focus increasing and ICS-targeted attacks on the rise, addressing resource and availability issues has become a pressing operational and compliance priority for manufacturers and critical infrastructure operators.
6 months ago
Kill Chain
Rockwell Automation DataMosaix SQL Injection Exposes Critical Manufacturing Systems
In January 2026, Rockwell Automation disclosed a critical vulnerability in its FactoryTalk DataMosaix Private Cloud platform affecting versions 7.11, 8.00, and 8.01. Identified as CVE-2025-12807, this SQL Injection flaw allows low-privilege users to execute unauthorized sensitive database operations through exposed API endpoints. While no public exploitation has been reported, successful attacks could significantly compromise critical manufacturing infrastructure worldwide by enabling attackers to access or manipulate sensitive industrial data. The incident highlights ongoing risks to industrial control environments from common vulnerabilities like SQL Injection, especially in products globally deployed across critical infrastructure sectors. With attackers increasingly targeting OT platforms, organizations face renewed urgency to review security controls and ensure compliance with updated defensive best practices.
6 months ago
Kill Chain
Spanish Police Disrupt Black Axe BEC Ring, Arresting Key Leaders in 2024 Crackdown
In early June 2024, Spanish National Police, supported by Europol and German authorities, arrested 34 individuals—among them top leaders of Black Axe, a notorious Nigerian-backed cybercrime syndicate. The tightly coordinated operation targeted Black Axe’s business email compromise (BEC) activities, which since September 2023 exploited corporate email channels to orchestrate multi-million-dollar fraud, money laundering, and shell company schemes across Europe. Authorities seized $77,000 in cash, froze $139,000 in bank accounts, and confiscated electronic devices and vehicles used for illicit activities. Black Axe’s operations were sophisticated and involved extensive networks of money mules and international laundering techniques. This disruption is highly relevant as BEC attacks grow in frequency, scale, and organizational complexity. Recent law enforcement action highlights the evolving threats posed by criminal syndicates who weaponize digital channels and exploit human and technical vulnerabilities, prompting urgent review of security controls and detection capabilities.
6 months ago
Kill Chain
Jaguar Land Rover Hit by Devastating 2025 Ransomware Attack: Supply Chains & Data at Risk
In September 2025, Jaguar Land Rover (JLR) suffered a devastating ransomware and extortion attack attributed to the Scattered Lapsus$ Hunters collective, a group comprising threat actors from Lapsus$, Scattered Spider, and ShinyHunters. The attackers breached JLR’s systems, forcing the automaker to halt production and send staff home. The resulting multi-week operational disruption led to a 43% drop in wholesale volumes in the third quarter, significant delays in fulfilling orders, and the confirmed theft of sensitive data. The financial toll exceeded £196 million ($220 million), prompting emergency UK government intervention to support JLR’s supply chain recovery. This incident underscores the evolving risk faced by global manufacturers from sophisticated, identity-centric ransomware actors employing both operational disruption and data theft for extortion. It highlights a broader trend of targeted attacks against critical supply chains, compounding economic impacts and regulatory scrutiny across industries.
6 months ago
Kill Chain
Nissan Customer Data Exposed After Red Hat Supply Chain Breach
In September 2023, Nissan Motor Co. Ltd. confirmed that the personal information of thousands of its customers was compromised due to a supply chain data breach at Red Hat, a leading software vendor. The breach stemmed from unauthorized access to customer data managed by Red Hat, which affected Nissan’s customer records, including names and contact information. While there is no current evidence of financial or highly sensitive information being lost, Nissan has notified the individuals impacted and is working with Red Hat to further assess and contain the breach’s full scope. This incident highlights the ongoing risk posed by third-party vendors in the automotive and technology sectors, as organizations increasingly rely on external service providers for software and infrastructure. The Nissan-Red Hat breach underscores the rising threats targeting supply chains, emphasizing the urgent need for robust vendor security controls and visibility into partner ecosystems.
6 months ago
Kill Chain
Critical OS Command Injection Vulnerability Hits Mitsubishi Electric Iconics Products (2025)
In December 2025, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric Products disclosed a critical vulnerability (CVE-2025-11774) affecting GENESIS64, ICONICS Suite, MobileHMI, and MC Works64 software. This OS command injection flaw resides in the software keyboard (keypad) function, enabling local attackers to execute arbitrary executable files (.EXE) by tampering with configuration files. If successfully exploited, adversaries could trigger denial-of-service (DoS), information tampering, and unauthorized information disclosure or destruction on systems running these products. A fix is available for most products by upgrading to GENESIS64 v10.97.3 or higher, but MC Works64 users must migrate as no patch is planned. The incident is significant for the critical manufacturing sector, highlighting persistent risks tied to ICS software supply chains. As attackers increasingly exploit software flaws in operational technology, prompt patching and network segmentation remain vital. This vulnerability’s disclosure underscores the necessity for maintaining robust controls on critical infrastructure endpoints and monitoring for lateral movement threats.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports