The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Automotive
Breach intelligence, attack campaigns, and threat reports targeting the Automotive sector.
Explore Other Sectors
Automotive Threat Reports
Critical Vulnerabilities in Siemens SINEMA Remote Connect Server Expose Manufacturing Networks
In December 2025, Siemens disclosed two vulnerabilities impacting SINEMA Remote Connect Server versions prior to V3.2 SP4, designated as CVE-2025-40818 and CVE-2025-40819. The flaws involved incorrect permission assignments for SSL/TLS private keys and improper authorization controls over license management within the server's database. An authenticated attacker could exploit these weaknesses to impersonate trusted servers, decrypt or intercept sensitive communications, and bypass licensing restrictions, exposing critical manufacturing environments worldwide to unauthorized access and operational risk. This incident underscores the persistent importance of robust permission management and encryption key protection in industrial control systems. With increased targeting of operational technology environments, organizations must prioritize patching, secure configurations, and risk assessments to maintain both compliance and resilience against escalating threats.
8 months ago
Kill Chain
Siemens SALT Toolkit Flaw Leaves Industrial Systems Exposed to MITM Attacks
In December 2025, Siemens disclosed a critical vulnerability (CVE-2025-40801) in its Advanced Licensing (SALT) Toolkit, affecting multiple industrial software products such as COMOS, NX, Simcenter, and Tecnomatix. The flaw—improper certificate validation in the SALT SDK when establishing TLS connections—could enable unauthenticated remote attackers to launch man-in-the-middle attacks. With a CVSS v4 score of 9.2, exploitation risk is high, potentially allowing attackers to intercept or manipulate sensitive industrial data and processes in critical manufacturing environments globally. Patches have been released for some products, but others remain without a fix. This incident is significant as it highlights ongoing challenges in implementing secure communication protocols within the industrial sector. The vulnerability underscores a wider trend of attackers exploiting flaws in authentication and encryption controls, emphasizing the urgent need for robust zero trust segmentation, encrypted traffic policies, and active vulnerability management as industries modernize.
8 months ago
Kill Chain
Japan’s 2024 Ransomware Surge: How Long-Tail Attacks Crippled Key Sectors
In early 2024, a wave of ransomware attacks swept through major Japanese organizations, targeting manufacturers, retailers, and segments of the Japanese government. Threat actors exploited vulnerable remote access points and unpatched software, using techniques such as lateral movement and data exfiltration before deploying ransomware payloads that encrypted business-critical systems. The operational disruption was immediate—many impacted organizations required months for full recovery, facing prolonged outages, loss of proprietary data, customer service challenges, and significant reputational harm. The attacks demonstrated sophisticated attacker persistence and exposed deficiencies in traffic segmentation and visibility into east-west movements within enterprise networks. This incident underscores the sophistication and persistence of modern ransomware operators in targeting essential sectors. As ransomware actors increasingly leverage stealthy, multi-stage attacks, organizations globally must reassess their east-west traffic security, incident response, and data protection programs to guard against extended, damaging outages.
8 months ago
Kill Chain
Clop Ransomware Hits University of Pennsylvania in Oracle EBS Supply Chain Attack
In August 2023, the University of Pennsylvania became one of nearly 100 organizations targeted in a sweeping data theft and extortion campaign by the Clop ransomware group. Exploiting previously unknown vulnerabilities in Oracle E-Business Suite (EBS), attackers gained unauthorized access to sensitive university systems over several days. Personal data, including names, Social Security numbers, and financial information, was exposed for thousands of individuals, primarily detected when Clop issued extortion demands and Oracle disclosed the vulnerability late September. Patch deployment followed, with no public evidence of further data misuse. The mass exploitation of Oracle EBS by Clop highlights a rising trend of sophisticated ransomware groups targeting widely used enterprise applications through zero-day attacks. This incident underscores renewed urgency for robust patch management, vigilant monitoring, and segmentation in response to evolving ransomware tactics and large-scale supply chain risks.
8 months ago
Kill Chain
Critical Buffer Overflow Flaws in Ashlar-Vellum Software Threaten Industrial Security
In November 2025, Ashlar-Vellum disclosed two critical software vulnerabilities—an Out-of-Bounds Write (CVE-2025-65084) and a Heap-based Buffer Overflow (CVE-2025-65085)—impacting its Cobalt, Xenon, Argon, Lithium, and Cobalt Share products (version 12.6.1204.207 and prior). Identified by security researcher Michael Heinzl and published via CISA, these flaws could allow local attackers to gain information disclosure or execute arbitrary code on affected engineering systems, primarily used in the Critical Manufacturing sector worldwide. The vulnerabilities are rated high (CVSS v4 score 8.4), but no exploitation has been reported to date. This incident reinforces the urgent need for robust vulnerability management and regular software patching within industrial control environments. Manufacturers and operators face increasing regulatory and operational pressure to proactively address new threats in their digital supply chains and critical OT infrastructure.
8 months ago
Kill Chain
Rockwell Automation Arena Simulation Buffer Overflow (2025): Risks to Industrial Control Systems
In November 2025, Rockwell Automation disclosed a stack-based buffer overflow vulnerability (CVE-2025-11918) in its Arena Simulation software (versions 16.20.10 and earlier). The flaw, reported by security researcher Michael Heinzl, enables local attackers to execute arbitrary code by tricking users into opening a malicious DOE file. While the vulnerability is not exploitable remotely, it presents a significant risk to organizations leveraging Arena for critical manufacturing automation, especially when adequate segmentation and endpoint security controls are lacking. No public exploitation has been reported to date, and the vendor has released a security update to address the issue. This incident is a reminder of the persistence of file parsing vulnerabilities in industrial software, which continue to enable initial compromise via local vectors like engineered files or insider threats. The increase in similar vulnerabilities and the possibility of operational technology (OT) system breaches intensify the call for zero-trust and defense-in-depth strategies within the manufacturing sector.
8 months ago
Kill Chain
Festo ICS Hidden Function Flaw Raises Global Manufacturing Security Stakes
In November 2025, Festo SE & Co. KG disclosed a critical security vulnerability (CVE-2023-3634) in its MSE6-C2M/D2M/E2M industrial control modules. The flaw, caused by hidden functionality accessible to remote, low-privileged authenticated users, could enable attackers to trigger undocumented test modes leading to a complete loss of confidentiality, integrity, and availability across affected devices. Operations worldwide in the critical manufacturing sector were potentially exposed due to this vulnerability, rated CVSS 8.8, though no evidence of active exploitation was reported. The issue prompted coordinated advisories from CERT@VDE and CISA, highlighting the systemic risk to industrial automation environments. This incident highlights ongoing threats to operational technology (OT) and industrial control systems, as the trend of exploiting hidden or undocumented features grows. With manufacturing and critical infrastructure increasingly interconnected, such vulnerabilities pose a greater risk of targeted disruptions and underscore the urgent need for proactive cybersecurity and compliance safeguards in OT environments.
8 months ago
Kill Chain
Schneider Electric 2025 SCADA Cryptography Flaw: What It Means for Industrial Cybersecurity
In November 2025, Schneider Electric disclosed a critical vulnerability (CVE-2025-9317) in its EcoStruxure Machine SCADA Expert and Pro-face BLUE Open Studio platforms, widely used across energy, manufacturing, and commercial sectors. The flaw involved the use of a broken or risky cryptographic algorithm within an AVEVA-supplied component, allowing local attackers with read access to project or cache files to reverse-engineer user passwords by brute-forcing weak password hashes. This could result in loss of confidentiality and integrity within impacted environments. No remote exploitation was identified, and there are no public reports of in-the-wild attacks as of the advisory date. This incident underscores persistent risks in ICS/OT software supply chains, where cryptographic weaknesses can enable privilege escalation and lateral movement by adversaries. With global regulators increasingly pressuring critical infrastructure providers on cyber hygiene and segmentation, this advisory highlights the urgency for supply chain and password management reforms.
8 months ago
Kill Chain
Jaguar Land Rover 2023 Ransomware Attack: $220 Million in Damages
In Q3 2023, Jaguar Land Rover (JLR) suffered a disruptive ransomware attack that severely impacted its global operations. The company reported in its financial results that the cyber incident, which occurred between July and September 2023, incurred costs amounting to £196 million ($220 million). Attackers leveraged ransomware to compromise JLR systems, reportedly targeting critical IT infrastructure essential for production and distribution. While business continuity was maintained post-incident, the supply chain faced significant disruptions, and the company responded promptly by activating its incident response protocols and collaborating with cybersecurity authorities. This incident is emblematic of the rising financial and operational toll ransomware inflicts on the automotive sector and large manufacturers globally. Increasingly sophisticated cybercriminals are actively targeting organizations with complex supply chains, amplifying the need for robust east-west security, visibility, and segmentation to protect critical assets in line with emerging compliance and regulatory expectations.
8 months ago
Kill Chain
Rockwell Automation 2025 ICS Vulnerabilities: Studio 5000 Path Traversal & SSRF Risks
In November 2025, Rockwell Automation disclosed critical vulnerabilities affecting its Studio 5000 Simulation Interface used across chemical and manufacturing sectors. The issues—Improper Limitation of a Pathname to a Restricted Directory (CVE-2025-11696) and Server-Side Request Forgery (CVE-2025-11697)—allowed local attackers to execute arbitrary scripts with administrator privileges and capture NTLM hashes via outbound SMB requests. The vulnerabilities impacted versions 2.02 and earlier, and, if exploited, could grant attackers lateral movement or privileged control within industrial environments, threatening operational integrity and sensitive data. These vulnerabilities highlight ongoing threats to industrial control systems (ICS) and the continued focus of adversaries on exploiting misconfigurations and overlooked APIs. With increasing regulatory pressure for critical infrastructure resilience and the evolution of ICS-specific ransomware and supply chain attacks, such vulnerabilities remain a potent risk requiring constant attention and timely remediation.
8 months ago
Kill Chain
Critical Authorization Flaw Exposes Rockwell Automation Verve Asset Manager (2025)
In November 2025, Rockwell Automation disclosed a critical vulnerability (CVE-2025-11862) in multiple versions of its Verve Asset Manager platform, widely used in industrial control system cybersecurity. The flaw, present from versions 1.33 up to 1.41.3, arises from an incorrect authorization configuration that allows unauthorized read-only users to perform privileged API operations, such as reading, updating, and deleting user accounts. The vulnerability, which is remotely exploitable with low attack complexity, exposes critical manufacturing environments to potential data breaches or sabotage until properly patched. Rockwell addressed the issue in version 1.41.4 and subsequent releases, urging all customers to update immediately. This incident underscores the growing risk baseline facing operational technology (OT) and ICS environments as attackers increasingly target authorization misconfigurations and API exposures. Regulatory pressure and rising sophistication in adversary tactics make strong access controls and rapid patch management more essential than ever for organizations managing critical infrastructure.
8 months ago
Kill Chain
2025 Rockwell FactoryTalk Policy Manager DoS Vulnerability Exposes Critical Manufacturing
In November 2025, Rockwell Automation disclosed a critical vulnerability (CVE-2024-22019) affecting versions 6.51.00 and earlier of its FactoryTalk Policy Manager, a tool widely deployed in industrial and manufacturing environments for policy enforcement and network segmentation. The flaw—tied to improper resource shutdown or release in the Node.js HTTP server—enables remote attackers to send specially crafted chunked HTTP requests that exhaust CPU and network resources, resulting in denial-of-service (DoS) conditions. While no active exploitation was reported as of publication, the vulnerability posed operational risks to OT systems globally, especially in critical manufacturing sectors. The incident underscores the risks posed by third-party software dependencies in industrial control system environments, especially as attackers target resource exhaustion vectors that bypass conventional safeguards. The disclosure highlights the increasing urgency for proactive vulnerability management and defense-in-depth strategies, given the essential role of OT in critical infrastructure.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports