The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Automotive
Breach intelligence, attack campaigns, and threat reports targeting the Automotive sector.
Explore Other Sectors
Automotive Threat Reports
Critical WebSocket Vulnerabilities in SWITCH EV's Platform Threaten EV Infrastructure Security
In February 2026, multiple critical vulnerabilities were identified in SWITCH EV's swtchenergy.com platform, affecting all versions. These vulnerabilities include missing authentication for critical functions (CVE-2026-27767), improper restriction of excessive authentication attempts (CVE-2026-25113), insufficient session expiration (CVE-2026-25778), and insufficiently protected credentials (CVE-2026-27773). Exploitation of these flaws could allow attackers to impersonate charging stations, hijack sessions, suppress or misroute legitimate traffic, and manipulate data sent to the backend, potentially leading to large-scale denial of service and unauthorized control over charging infrastructure. ([cvedetails.com](https://www.cvedetails.com/cve/CVE-2026-27767/?utm_source=openai)) The increasing reliance on electric vehicle (EV) infrastructure underscores the critical need for robust cybersecurity measures. These vulnerabilities highlight the potential risks associated with inadequate authentication and session management in critical infrastructure systems, emphasizing the importance of implementing comprehensive security protocols to safeguard against such threats.
6 months ago
Kill Chain
EV2GO 2026 Authentication Vulnerabilities: A Wake-Up Call for Critical Infrastructure Security
In February 2026, multiple critical vulnerabilities were identified in EV2GO's ev2go.io charging management platform, affecting all versions. These flaws include missing authentication for critical functions (CVE-2026-24731), improper restriction of excessive authentication attempts (CVE-2026-25945), insufficient session expiration (CVE-2026-20895), and insufficiently protected credentials (CVE-2026-22890). Exploitation could allow attackers to impersonate charging stations, hijack sessions, misroute traffic causing large-scale denial of service, and manipulate backend data. ([therealistjuggernaut.com](https://therealistjuggernaut.com/2026/02/26/trj-cybersecurity-ev2go-charging-platform-exposed-authentication-failures-create-high-risk-entry-points-across-global-ev-infrastructure/?utm_source=openai)) The absence of vendor response and lack of available patches heighten the urgency for organizations to implement immediate defensive measures. This incident underscores the critical need for robust authentication mechanisms and proactive vulnerability management in infrastructure systems to prevent potential exploitation and operational disruptions.
6 months ago
Kill Chain
EV Energy's 2026 Security Flaws: A Wake-Up Call for EV Infrastructure
In February 2026, multiple critical vulnerabilities were identified in EV Energy's ev.energy platform, a UK-based provider of electric vehicle charging software. These vulnerabilities include missing authentication for critical functions (CVE-2026-27772), improper restriction of excessive authentication attempts (CVE-2026-24445), insufficient session expiration (CVE-2026-26290), and insufficiently protected credentials (CVE-2026-25774). Exploitation of these flaws could allow attackers to gain unauthorized control over charging stations, disrupt services, and compromise data integrity. ([beyondmachines.net](https://beyondmachines.net/event_details/critical-vulnerabilities-in-ev-energy-charging-platform-allow-remote-hijacking-b-x-t-d-l?utm_source=openai)) The increasing integration of electric vehicle infrastructure with the power grid underscores the urgency of addressing these security gaps. As cyberattacks on EV charging stations rise, ensuring robust authentication and session management mechanisms is critical to prevent potential disruptions and maintain trust in the EV ecosystem. ([yahoo.com](https://www.yahoo.com/news/cyberattacks-ev-charging-stations-rise-120000365.html?utm_source=openai))
6 months ago
Kill Chain
Critical Vulnerabilities in CloudCharge's Platform Threaten Global EV Charging Networks
In February 2026, multiple critical vulnerabilities were identified in CloudCharge's cloudcharge.se platform, which manages electric vehicle (EV) charging infrastructure globally. These vulnerabilities include missing authentication for critical functions (CVE-2026-20781), improper restriction of excessive authentication attempts (CVE-2026-25114), insufficient session expiration (CVE-2026-27652), and insufficiently protected credentials (CVE-2026-20733). Exploitation of these flaws could allow attackers to impersonate charging stations, hijack sessions, suppress or misroute legitimate traffic, and manipulate data sent to the backend, potentially leading to large-scale denial of service and unauthorized control over charging infrastructure. ([therealistjuggernaut.com](https://therealistjuggernaut.com/2026/02/26/trj-cybersecurity-cloudcharge-platform-vulnerabilities-open-global-ev-charging-networks-to-session-hijack-and-impersonation-risk/?utm_source=openai)) The discovery of these vulnerabilities underscores the urgent need for robust authentication and session management mechanisms in critical infrastructure systems. As the adoption of EVs continues to rise, ensuring the security of charging networks is paramount to prevent potential disruptions and maintain public trust in these technologies.
6 months ago
Kill Chain
Critical Security Flaws in Mobility46's EV Charging Platform Expose Infrastructure to Unauthorized Access
In February 2026, multiple critical vulnerabilities were identified in Mobility46's charging station management platform, mobility46.se. These vulnerabilities include missing authentication for critical functions (CVE-2026-27028), improper restriction of excessive authentication attempts (CVE-2026-26305), insufficient session expiration (CVE-2026-27647), and insufficiently protected credentials (CVE-2026-22878). Exploitation of these flaws could allow attackers to gain unauthorized administrative control over charging stations or disrupt services through denial-of-service attacks. ([cvefeed.io](https://cvefeed.io/vuln/detail/CVE-2026-27028?utm_source=openai)) The increasing reliance on electric vehicle (EV) infrastructure underscores the importance of securing such platforms. These vulnerabilities highlight the need for robust authentication mechanisms and session management to prevent unauthorized access and ensure the integrity of critical infrastructure services.
6 months ago
Kill Chain
Critical Security Flaws in Chargemap's EV Charging Platform Uncovered
In February 2026, multiple critical vulnerabilities were identified in Chargemap's platform, a widely used electric vehicle charging service. These flaws include missing authentication for critical functions (CVE-2026-25851), improper restriction of excessive authentication attempts (CVE-2026-20792), insufficient session expiration (CVE-2026-25711), and insufficiently protected credentials (CVE-2026-20791). Exploitation of these vulnerabilities could allow attackers to gain unauthorized administrative control over charging stations or disrupt services through denial-of-service attacks. ([beyondmachines.net](https://beyondmachines.net/event_details/multiple-vulnerabilities-discovered-in-chargemap-platform-z-y-h-q-j?utm_source=openai)) The absence of vendor patches and Chargemap's lack of response to coordination requests from CISA highlight the urgency for organizations to implement immediate mitigations. This incident underscores the critical need for robust security measures in EV charging infrastructure, especially as the adoption of electric vehicles continues to rise globally. ([beyondmachines.net](https://beyondmachines.net/event_details/multiple-vulnerabilities-discovered-in-chargemap-platform-z-y-h-q-j?utm_source=openai))
6 months ago
Kill Chain
Jaguar Land Rover 2025 Cyberattack: Lessons in Industrial Cybersecurity
In August 2025, Jaguar Land Rover (JLR) experienced a significant cyberattack that led to a complete halt in vehicle production across its global facilities, including those in the UK, Slovakia, China, India, and Brazil. The attack, attributed to the hacking group 'Scattered Lapsus$ Hunters,' resulted in the shutdown of production lines starting August 31, 2025, with operations remaining suspended until at least October 1, 2025. This disruption caused substantial financial losses, with JLR reporting a pre-tax loss of £485 million for the quarter ending September 30, 2025, marking a stark contrast to the £398 million profit recorded in the same period the previous year. The incident also had a ripple effect on the UK automotive industry, impacting JLR's extensive supply chain and leading to significant economic repercussions. ([theguardian.com](https://www.theguardian.com/business/2025/nov/14/jaguar-land-rover-loss-cyber-attack?utm_source=openai)) The JLR cyberattack underscores the escalating threat of sophisticated cyber incidents targeting critical infrastructure and major corporations. The involvement of 'Scattered Lapsus$ Hunters,' a group comprising elements from notorious hacking collectives like Scattered Spider, Lapsus$, and ShinyHunters, highlights the evolving tactics of cybercriminals who exploit social engineering and known vulnerabilities to infiltrate organizations. This incident serves as a stark reminder for industries worldwide to bolster their cybersecurity measures, enhance incident response strategies, and ensure robust supply chain security to mitigate the risks posed by such advanced persistent threats. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/jaguar-land-rover-shuts-down-production-due-to-ransomware-attack-scattered-lapsus-usd-hunters-takes-responsibility?utm_source=openai))
7 months ago
Kill Chain
CarGurus Data Breach 2026: A Wake-Up Call for Cybersecurity
In February 2026, CarGurus, a prominent online automotive marketplace, experienced a significant data breach orchestrated by the ShinyHunters hacking group. The attackers employed sophisticated voice phishing (vishing) techniques to deceive employees into providing access credentials, leading to the exfiltration of approximately 12.5 million customer records. The compromised data included names, email addresses, phone numbers, physical addresses, user account IDs, finance pre-qualification application data, finance application outcomes, dealer account details, and subscription information. This breach underscores the persistent threat posed by social engineering attacks and highlights the critical need for robust cybersecurity measures and employee training to prevent unauthorized access to sensitive information. The incident also reflects a broader trend of cybercriminals targeting large-scale databases through advanced social engineering tactics, emphasizing the importance of vigilance and proactive security strategies in safeguarding organizational and customer data.
7 months ago
Kill Chain
Advantest 2026 Ransomware Attack: A Wake-Up Call for Semiconductor Cybersecurity
In February 2026, Advantest Corporation, a leading Japanese semiconductor test equipment manufacturer, detected unauthorized access within its IT environment, indicating a ransomware attack. The company promptly activated incident response protocols, isolated affected systems, and engaged third-party cybersecurity experts to investigate and contain the incident. Preliminary findings suggest that an unauthorized third party may have gained access to portions of the company's network and deployed ransomware. The full extent of the impact, including potential compromise of customer or employee data, is under active investigation. ([advantest.com](https://www.advantest.com/en/news/2026/20260219.html?utm_source=openai)) This incident underscores the escalating threat of ransomware attacks targeting critical infrastructure within the semiconductor industry. As adversaries increasingly focus on high-value targets, organizations must enhance their cybersecurity measures to protect sensitive data and maintain operational continuity.
7 months ago
Kill Chain
Siemens Simcenter Femap and Nastran 2026 File Parsing Vulnerabilities
In February 2026, Siemens disclosed multiple vulnerabilities in its Simcenter Femap and Nastran products, specifically affecting versions prior to V2512. These vulnerabilities, identified as CVE-2026-23715 through CVE-2026-23720, involve out-of-bounds read and write errors, as well as heap-based buffer overflows, which can be exploited by attackers through specially crafted NDB and XDB files. Successful exploitation could lead to application crashes or arbitrary code execution within the context of the current process. Siemens has released version V2512 to address these issues and recommends users update to this latest version. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-965753.html?utm_source=openai)) The disclosure of these vulnerabilities underscores the persistent risks associated with file parsing mechanisms in critical engineering software. Organizations utilizing Simcenter Femap and Nastran should prioritize updating to the patched version to mitigate potential exploitation. This incident highlights the importance of regular software updates and vigilance against malicious file-based attacks in industrial environments.
7 months ago
Kill Chain
Delta Electronics ASDA-Soft Vulnerability Exposes Critical Systems to Risk
In January 2026, Delta Electronics disclosed a critical stack-based buffer overflow vulnerability (CVE-2026-1361) in their ASDA-Soft software, versions up to 7.2.0.0. This flaw allows attackers to write arbitrary data beyond the bounds of a stack-allocated buffer, potentially leading to the corruption of a structured exception handler (SEH). Exploitation requires local access and user interaction, but no prior authentication, posing significant risks to confidentiality, integrity, and availability. Delta Electronics has released version 7.2.2.0 to address this issue. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1361?utm_source=openai)) This incident underscores the persistent threat of buffer overflow vulnerabilities in industrial control systems, emphasizing the need for rigorous input validation and timely software updates to mitigate potential exploits.
7 months ago
Kill Chain
Critical Vulnerability in Open62541: Immediate Action Required
In February 2026, a medium-severity vulnerability (CVE-2026-1301) was identified in o6 Automation GmbH's Open62541, an open-source OPC UA stack widely used in industrial automation. The flaw, present in versions from 1.5-rc1 to before 1.5-rc2, allows unauthenticated attackers to send crafted JSON PubSub messages, leading to out-of-bounds writes, process crashes, and potential memory corruption. This vulnerability poses significant risks to industrial control systems, potentially causing operational disruptions and compromising system integrity. ([windowsforum.com](https://windowsforum.com/threads/cve-2026-1301-open62541-json-pubsub-memory-safety-bug-upgrade-to-v1-5-0.400263/?utm_source=openai)) The discovery of this vulnerability underscores the critical importance of rigorous security practices in industrial automation software. Organizations utilizing Open62541 should promptly upgrade to the stable release v1.5.0 to mitigate this risk. Additionally, implementing network segmentation and minimizing exposure of control systems to external networks are essential steps to enhance security posture. ([windowsforum.com](https://windowsforum.com/threads/cve-2026-1301-open62541-json-pubsub-memory-safety-bug-upgrade-to-v1-5-0.400263/?utm_source=openai))
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports