The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Automotive

Breach intelligence, attack campaigns, and threat reports targeting the Automotive sector.

188 threat reports
Page 12 of 16

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Automotive Threat Reports

Showing 133–144 / 188 reports
Rockwell Automation ICS Devices Exposed by Critical DoS Vulnerability (CVE-2025-9368)
Impact· high

Rockwell Automation ICS Devices Exposed by Critical DoS Vulnerability (CVE-2025-9368)

In January 2026, Rockwell Automation disclosed a critical vulnerability (CVE-2025-9368) affecting its 432ES-IG3 Series A industrial Ethernet/IP interface. The flaw, classified as a resource allocation vulnerability (CWE-770), can be exploited remotely to cause a denial-of-service (DoS) condition, rendering the device unresponsive and requiring manual power cycling to restore operations. The vulnerability affects version V1.001 of the device, widely deployed in critical manufacturing environments worldwide. No evidence of active exploitation has been reported as of the initial CISA advisory, but the risk of service disruption in operational technology (OT) networks is significant. This incident underscores the persistent threat posed by resource exhaustion flaws in industrial control systems, as attackers continue to seek low-complexity, high-impact vulnerabilities to disrupt critical infrastructure. With global regulatory focus increasing and ICS-targeted attacks on the rise, addressing resource and availability issues has become a pressing operational and compliance priority for manufacturers and critical infrastructure operators.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Rockwell Automation DataMosaix SQL Injection Exposes Critical Manufacturing Systems
Impact· medium

Rockwell Automation DataMosaix SQL Injection Exposes Critical Manufacturing Systems

In January 2026, Rockwell Automation disclosed a critical vulnerability in its FactoryTalk DataMosaix Private Cloud platform affecting versions 7.11, 8.00, and 8.01. Identified as CVE-2025-12807, this SQL Injection flaw allows low-privilege users to execute unauthorized sensitive database operations through exposed API endpoints. While no public exploitation has been reported, successful attacks could significantly compromise critical manufacturing infrastructure worldwide by enabling attackers to access or manipulate sensitive industrial data. The incident highlights ongoing risks to industrial control environments from common vulnerabilities like SQL Injection, especially in products globally deployed across critical infrastructure sectors. With attackers increasingly targeting OT platforms, organizations face renewed urgency to review security controls and ensure compliance with updated defensive best practices.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Spanish Police Disrupt Black Axe BEC Ring, Arresting Key Leaders in 2024 Crackdown
Impact· high

Spanish Police Disrupt Black Axe BEC Ring, Arresting Key Leaders in 2024 Crackdown

In early June 2024, Spanish National Police, supported by Europol and German authorities, arrested 34 individuals—among them top leaders of Black Axe, a notorious Nigerian-backed cybercrime syndicate. The tightly coordinated operation targeted Black Axe’s business email compromise (BEC) activities, which since September 2023 exploited corporate email channels to orchestrate multi-million-dollar fraud, money laundering, and shell company schemes across Europe. Authorities seized $77,000 in cash, froze $139,000 in bank accounts, and confiscated electronic devices and vehicles used for illicit activities. Black Axe’s operations were sophisticated and involved extensive networks of money mules and international laundering techniques. This disruption is highly relevant as BEC attacks grow in frequency, scale, and organizational complexity. Recent law enforcement action highlights the evolving threats posed by criminal syndicates who weaponize digital channels and exploit human and technical vulnerabilities, prompting urgent review of security controls and detection capabilities.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Jaguar Land Rover Hit by Devastating 2025 Ransomware Attack: Supply Chains & Data at Risk
Impact· high

Jaguar Land Rover Hit by Devastating 2025 Ransomware Attack: Supply Chains & Data at Risk

In September 2025, Jaguar Land Rover (JLR) suffered a devastating ransomware and extortion attack attributed to the Scattered Lapsus$ Hunters collective, a group comprising threat actors from Lapsus$, Scattered Spider, and ShinyHunters. The attackers breached JLR’s systems, forcing the automaker to halt production and send staff home. The resulting multi-week operational disruption led to a 43% drop in wholesale volumes in the third quarter, significant delays in fulfilling orders, and the confirmed theft of sensitive data. The financial toll exceeded £196 million ($220 million), prompting emergency UK government intervention to support JLR’s supply chain recovery. This incident underscores the evolving risk faced by global manufacturers from sophisticated, identity-centric ransomware actors employing both operational disruption and data theft for extortion. It highlights a broader trend of targeted attacks against critical supply chains, compounding economic impacts and regulatory scrutiny across industries.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Nissan Customer Data Exposed After Red Hat Supply Chain Breach
Impact· high

Nissan Customer Data Exposed After Red Hat Supply Chain Breach

In September 2023, Nissan Motor Co. Ltd. confirmed that the personal information of thousands of its customers was compromised due to a supply chain data breach at Red Hat, a leading software vendor. The breach stemmed from unauthorized access to customer data managed by Red Hat, which affected Nissan’s customer records, including names and contact information. While there is no current evidence of financial or highly sensitive information being lost, Nissan has notified the individuals impacted and is working with Red Hat to further assess and contain the breach’s full scope. This incident highlights the ongoing risk posed by third-party vendors in the automotive and technology sectors, as organizations increasingly rely on external service providers for software and infrastructure. The Nissan-Red Hat breach underscores the rising threats targeting supply chains, emphasizing the urgent need for robust vendor security controls and visibility into partner ecosystems.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical OS Command Injection Vulnerability Hits Mitsubishi Electric Iconics Products (2025)
Impact· high

Critical OS Command Injection Vulnerability Hits Mitsubishi Electric Iconics Products (2025)

In December 2025, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric Products disclosed a critical vulnerability (CVE-2025-11774) affecting GENESIS64, ICONICS Suite, MobileHMI, and MC Works64 software. This OS command injection flaw resides in the software keyboard (keypad) function, enabling local attackers to execute arbitrary executable files (.EXE) by tampering with configuration files. If successfully exploited, adversaries could trigger denial-of-service (DoS), information tampering, and unauthorized information disclosure or destruction on systems running these products. A fix is available for most products by upgrading to GENESIS64 v10.97.3 or higher, but MC Works64 users must migrate as no patch is planned. The incident is significant for the critical manufacturing sector, highlighting persistent risks tied to ICS software supply chains. As attackers increasingly exploit software flaws in operational technology, prompt patching and network segmentation remain vital. This vulnerability’s disclosure underscores the necessity for maintaining robust controls on critical infrastructure endpoints and monitoring for lateral movement threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Rockwell Automation PLC Flaws Put Industrial Control Systems at Risk in 2025
Impact· high

Rockwell Automation PLC Flaws Put Industrial Control Systems at Risk in 2025

In December 2025, Rockwell Automation disclosed multiple vulnerabilities affecting its Micro820, Micro850, and Micro870 programmable logic controllers (PLCs). The most critical issues (CVE-2025-13823, CVE-2025-13824) were found in the IPv6 stack and improper handling of malformed CIP packets, potentially allowing unauthenticated attackers to cause denial-of-service conditions. Successful exploitation could lead to systems becoming unresponsive and requiring physical intervention to restore operation. Affected product versions are widely deployed across critical manufacturing sectors worldwide, increasing the risk of operational disruptions. This incident highlights the growing exposure of operational technology (OT) devices to network-borne threats and the importance of promptly securing ICS environments. The prevalence of fuzzing-based vulnerability discovery and dependency on third-party components heighten the urgency to apply vendor-recommended mitigations and adopt defense-in-depth strategies.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical LabVIEW 2025 Vulnerabilities Expose Industrial Control Systems to Code Execution Risk
Impact· low

Critical LabVIEW 2025 Vulnerabilities Expose Industrial Control Systems to Code Execution Risk

In December 2025, multiple critical vulnerabilities (CVE-2025-64461 through CVE-2025-64469) were disclosed in National Instruments LabVIEW, a widely used industrial control software. The flaws, which include out-of-bounds write, out-of-bounds read, use-after-free, and stack-based buffer overflow, enable attackers to execute arbitrary code or exfiltrate information when a user opens a specially crafted VI file. Impacted versions span from LabVIEW 2021 up to 2025 Q3, affecting sectors such as critical manufacturing, defense, IT, and transportation globally. National Instruments released patches addressing these flaws, with older versions receiving limited or no support. Though there have been no reports of active exploitation, this incident highlights the persistent risk of supply chain and software vulnerabilities in critical ICS environments. Recent trends show a rise in sophisticated attacks leveraging user interaction and file-based exploits, emphasizing the growing need for robust patch management and secure software usage.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Unisoc Vehicle Modem Breach Exposes Automotive Risks in 2024
Impact· medium

Unisoc Vehicle Modem Breach Exposes Automotive Risks in 2024

In 2024, security researchers uncovered a critical hardware and firmware vulnerability (CVE-2024-39432, CVE-2024-39431) affecting Unisoc UIS7862A modems widely used in modern vehicle head units. Attackers exploited a stack-based buffer overflow in the 3G RLC protocol to achieve unauthenticated remote code execution on the modem, bypassing standard mobile network security. Through this initial access, researchers leveraged hardware vulnerabilities to pivot laterally within the SoC, ultimately gaining privileged control over the Android Application Processor and demonstrating full system compromise—including running arbitrary code on the vehicle's infotainment system. This exposure places vehicle safety, user data privacy, and potentially road safety at significant risk. The incident highlights the urgent and real-world impact of modem and embedded system vulnerabilities as vehicles become increasingly connected. With the proliferation of IoT in critical and mobile environments, attackers are targeting lower-level protocols and hardware integration points, complicating detection and remediation while amplifying the severity of breaches.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Mitsubishi Electric's GT Designer3 Vulnerability (2025): Cleartext Credentials Endanger Industrial Systems
Impact· medium

Mitsubishi Electric's GT Designer3 Vulnerability (2025): Cleartext Credentials Endanger Industrial Systems

In December 2025, Mitsubishi Electric disclosed a vulnerability (CVE-2025-11009) impacting their GT Designer3 software, widely used in industrial control panel applications. Security researchers at Red Alert Lab discovered that plaintext credentials were being stored in project files, exposing critical manufacturing assets worldwide to potential unauthorized access. Although successful exploitation requires local access and has a high attack complexity, an attacker could obtain plaintext credentials to operate GOT2000 or GOT1000 series devices maliciously, raising risks for organizations with misconfigured networks or insufficient access controls. This incident highlights the persistent risk of cleartext credential exposures in operational technology, an issue often underestimated in critical infrastructure. With incidents involving credential theft and unauthorized device control on the rise, compliance frameworks and supply chain partners are placing increased urgency on eliminating weak storage practices in industrial environments.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
700Credit 2024 Breach: 5.8 Million Dealership Customers' Data Exposed
Impact· high

700Credit 2024 Breach: 5.8 Million Dealership Customers' Data Exposed

In early 2024, 700Credit, a US-based fintech firm specializing in credit and compliance solutions for auto dealerships, disclosed a major data breach affecting over 5.8 million individuals. The breach was traced to a vulnerability in a third-party web application platform, resulting in unauthorized access to sensitive customer data submitted to vehicle dealerships across North America. Exposed data included names, addresses, Social Security Numbers, dates of birth, and driver’s license numbers. The breach forced 700Credit to rapidly contain the issue, engage forensic experts, and notify customers, while drawing regulatory scrutiny due to the significant privacy impact. This incident is especially important as it highlights the persistent risks presented by web application vulnerabilities and supply chain exposure across critical business platforms. Increased attacker focus on third-party dependencies and data-rich payment ecosystems continues to drive urgency around zero trust architectures and more proactive monitoring and response.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Siemens 2025 IAM Client TLS Flaw Exposes Industrial Environments
Impact· low

Critical Siemens 2025 IAM Client TLS Flaw Exposes Industrial Environments

In December 2025, Siemens disclosed a critical vulnerability (CVE-2025-40800) in the IAM Client component used across key products such as COMOS, NX, Simcenter, and Solid Edge. The flaw stemmed from improper validation of server certificates during TLS sessions, exposing organizations to potential Man-in-the-Middle (MitM) attacks by unauthenticated remote attackers. Impacting deployments globally within the critical manufacturing sector, the vulnerability received a CVSS v4 base score of 9.1, reflecting its high risk. While patches are available for most products, a fix for COMOS V10.6 was unavailable at disclosure. This incident highlights ongoing risks from certificate handling errors, which remain common initial access vectors. As industrial networks become more interconnected, failures in basic cryptographic hygiene, especially in authentication mechanisms, are increasingly targeted by sophisticated attackers leveraging supply chain or network-layer attacks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports