The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Automotive

Breach intelligence, attack campaigns, and threat reports targeting the Automotive sector.

188 threat reports
Page 14 of 16

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Automotive Threat Reports

Showing 157–168 / 188 reports
Mitsubishi Electric 2025: Denial-of-Service Vulnerability Impacts Industrial Control Systems
Impact· high

Mitsubishi Electric 2025: Denial-of-Service Vulnerability Impacts Industrial Control Systems

In November 2025, a denial-of-service (DoS) vulnerability (CVE-2025-10259) impacting Mitsubishi Electric MELSEC iQ-F Series programmable logic controllers was publicly disclosed. Researchers from Zhongguancun Laboratory and Tsinghua University identified that improper validation in the TCP communication module allowed remote attackers to send specially crafted TCP packets, causing affected devices to disconnect and become temporarily unresponsive. The vulnerability (CVSS 5.3) requires no authentication and can be exploited remotely, posing a notable risk to industrial control systems in the critical manufacturing sector worldwide. This incident highlights persistent cybersecurity weaknesses in industrial IoT and critical infrastructure devices, which attackers increasingly target to disrupt operations. As regulatory expectations and threat actor sophistication rise, even moderate-severity flaws in ICS environments must be prioritized and mitigated decisively.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Rockwell Automation FactoryTalk DataMosaix: 2025 ICS Cloud Vulnerabilities Expose Industrial Risk
Impact· low

Rockwell Automation FactoryTalk DataMosaix: 2025 ICS Cloud Vulnerabilities Expose Industrial Risk

In November 2025, Rockwell Automation disclosed two critical vulnerabilities in its FactoryTalk DataMosaix Private Cloud platform, widely used across critical manufacturing sectors. The flaws include a weak authentication mechanism (CVE-2025-11084) that enables attackers to bypass MFA and gain unauthorized access, and a persistent cross-site scripting bug (CVE-2025-11085) that could facilitate account takeover, credential theft, or redirecting users to malicious sites. Rockwell and CISA jointly warned that attackers could exploit these remotely and potentially take control of sensitive ICS data or operations globally, demanding urgent updates. These vulnerabilities underscore rising risks tied to identity-driven attacks and web-based threats targeting industrial control environments. With Ransomware-as-a-Service and supply chain attacks escalating, organizations in critical sectors face mounting pressure to implement multi-layered controls and update legacy authentication practices.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Siemens Solid Edge 2025: Improper Certificate Validation Exposes Critical Manufacturing to MITM Attacks
Impact· low

Siemens Solid Edge 2025: Improper Certificate Validation Exposes Critical Manufacturing to MITM Attacks

In November 2025, Siemens disclosed a critical vulnerability in its Solid Edge SE2025 product, identified as CVE-2025-40744. This software flaw, stemming from improper certificate validation in the License Service endpoint, allows unauthenticated remote attackers to perform man-in-the-middle (MITM) attacks by intercepting or manipulating encrypted traffic. The issue, rated 8.7 (CVSS v4), affects all versions of Solid Edge SE2025 prior to V225.0 Update 11, putting global critical manufacturing environments at risk of credential interception and data exposure. This incident reflects increasing attacker focus on exploiting certificate validation weaknesses in supply chain and industrial environments. With industrial control systems often at the core of large enterprises' operations, such vulnerabilities demand swift patching and ongoing vigilance in authentication and encrypted traffic controls.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Siemens 2025: Critical DLL Hijacking Flaw Exposes Manufacturing Software
Impact· low

Siemens 2025: Critical DLL Hijacking Flaw Exposes Manufacturing Software

In November 2025, Siemens disclosed a vulnerability (CVE-2025-40827) in its Software Center and Solid Edge products, affecting versions prior to 3.5 and V225.0 Update 10, respectively. The flaw, rooted in uncontrolled search path element (CWE-427), allows local attackers to execute arbitrary code via DLL hijacking—placing crafted DLLs on vulnerable systems. Although exploitation requires local access and some user interaction, compromise could lead to full system takeover in manufacturing environments globally. Siemens responded by advising immediate updates and enhanced network protections. This incident underscores the ongoing risks posed by software supply chain vulnerabilities and underscores the importance of timely patching in industrial environments. It highlights how attackers continue targeting widely deployed engineering software with low-complexity, high-impact exploits, especially as operational technology environments see increased convergence with IT infrastructures.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Hyundai AutoEver America Breach: SSN & ID Data Exposed in Latest 2024 Attack
Impact· high

Hyundai AutoEver America Breach: SSN & ID Data Exposed in Latest 2024 Attack

In early 2024, Hyundai AutoEver America suffered a significant data breach after cyber attackers gained unauthorized access to the company's IT environment. Sensitive personal information, including Social Security Numbers and driver's license details, belonging to customers and employees was exposed over the course of the intrusion. The breach was detected and disclosed following internal investigations and third-party forensics, with impacted individuals promptly notified. While the company did not report operational disruptions, the exposure of such regulated data poses risks of identity theft and regulatory scrutiny. This incident underscores the growing trend of threat actors targeting organizations in the automotive sector for high-value personal data. It spotlights the importance of strong data-in-transit controls and proactive east-west traffic monitoring, as regulators and attackers alike escalate pressure on firms entrusted with sensitive consumer information.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Fuji Electric HMI 2025: Buffer Overflow Exposes Critical Manufacturing Risks
Impact· medium

Fuji Electric HMI 2025: Buffer Overflow Exposes Critical Manufacturing Risks

In November 2025, vulnerabilities were disclosed in the Fuji Electric Monitouch V-SFT-6 HMI software (version 6.2.7.0), exposing critical manufacturing environments worldwide to potential compromise. Security researchers discovered both heap-based and stack-based buffer overflow flaws, which could allow a malicious user, via specially crafted project files, to crash targeted devices or execute arbitrary code. While there has been no evidence of active exploitation or remote attacks reported, these vulnerabilities highlight the exposed attack surface for industrial control system (ICS) operators. Following responsible disclosure, Fuji Electric addressed the issues in the October update, urging all users to upgrade immediately. This incident underscores the growing risk posed by supply chain and software vulnerabilities in critical infrastructure. With attackers increasingly targeting ICS and operational technology (OT) environments, prompt patching and layered defense strategies are more important than ever.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Siemens 2025: Type Confusion RCE Threatens HyperLynx & Industrial Edge Security
Impact· medium

Siemens 2025: Type Confusion RCE Threatens HyperLynx & Industrial Edge Security

In October 2025, Siemens disclosed a critical vulnerability (CVE-2025-6554) affecting HyperLynx and Industrial Edge App Publisher products. The flaw, rooted in type confusion within the V8 JavaScript engine (Google Chrome), enables remote attackers to execute arbitrary code via malicious HTML, particularly impacting vulnerable product versions used in worldwide critical manufacturing environments. For HyperLynx, exploitation requires local access, while Industrial Edge App Publisher is exploitable remotely with low complexity, posing a substantial risk to integrity and confidentiality. Siemens and CISA jointly advised immediate updates and best-practice mitigations. This incident highlights a growing trend of supply chain and third-party component vulnerabilities impacting industrial control systems, particularly as attackers increasingly target embedded web technologies. The Siemens disclosure underlines ongoing regulatory and operational pressure to address software dependencies and enforce proactive patch management in critical infrastructure.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Siemens 2025 ICS Vulnerabilities Expose Critical Manufacturing to Remote Disruption
Impact· high

Siemens 2025 ICS Vulnerabilities Expose Critical Manufacturing to Remote Disruption

In October 2025, Siemens disclosed high-severity vulnerabilities in its SIMATIC S7-1200 CPU V1/V2 Devices, a critical component used in manufacturing automation worldwide. Security researchers found that improper input validation and authentication bypass by capture-replay allowed unauthenticated remote attackers to either cause a denial-of-service state or remotely execute recorded engineering commands on exposed controllers, regardless of security passwords. The vulnerabilities, affecting devices shipped globally, could let on-path attackers disrupt operations or halt production lines if exploited. Siemens and CISA issued urgent advisories and released patches to mitigate risks. This incident highlights the ongoing vulnerability of industrial control systems (ICS) to remote exploits and session replay attacks. As critical infrastructure faces increasing threats from both sophisticated threat actors and opportunistic attacks, organizations operating legacy or unpatched automation hardware must rapidly recalibrate their cyber defenses in light of persistent risks and global attack surface expansion.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical DoS Vulnerability in Rockwell Compact GuardLogix 5370 Exposes Manufacturing Operations
Impact· high

Critical DoS Vulnerability in Rockwell Compact GuardLogix 5370 Exposes Manufacturing Operations

In October 2025, Rockwell Automation disclosed a critical remotely exploitable vulnerability (CVE-2025-9124) affecting Compact GuardLogix 5370 industrial controllers, stemming from an uncaught exception flaw. Attackers could trigger a denial-of-service by sending crafted CIP unconnected explicit messages, resulting in a major, non-recoverable device fault. The vulnerability, reported by Rockwell itself, exposes impacted controllers to significant operational disruptions, particularly concerning for organizations within critical manufacturing sectors worldwide. Immediate device upgrades and network segmentation were recommended to mitigate risk. This vulnerability highlights persistent gaps in OT security as attackers increase their focus on industrial control systems. The incident underscores the urgency surrounding real-time vulnerability management and emphasizes the rising threat surface presented by remotely accessible critical infrastructure.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical Vulnerabilities in Rockwell Automation 1783-NATR Threaten Global Industrial Operations
Impact· high

Critical Vulnerabilities in Rockwell Automation 1783-NATR Threaten Global Industrial Operations

In October 2025, Rockwell Automation disclosed three critical vulnerabilities in its 1783-NATR network address translation devices, primarily affecting industrial environments worldwide. The flaws included missing authentication checks on critical functions, a stored cross-site scripting (XSS) vulnerability, and a cross-site request forgery (CSRF) flaw. Remote attackers could exploit these to compromise administrative accounts, alter device configurations, and disrupt network traffic flow, potentially causing denial-of-service or the exposure of sensitive data vital to manufacturing operations. The vulnerabilities impacted all devices running firmware version 1.006 and earlier, with no public exploitation reported at the time of disclosure. This incident highlights the persistent security risks in operational technology (OT) and industrial control systems, particularly as threat actors increasingly target publicly exposed or poorly segmented infrastructure. The disclosure underscores the need for continuous patch management, robust network segmentation, and diligent monitoring to prevent widespread operational disruptions stemming from remote exploitation of critical vulnerabilities.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Veeder-Root TLS4B Vulnerabilities Expose Energy Sector to Remote Attacks in 2025
Impact· high

Veeder-Root TLS4B Vulnerabilities Expose Energy Sector to Remote Attacks in 2025

In October 2025, critical vulnerabilities were disclosed in the Veeder-Root TLS4B Automatic Tank Gauge System, widely deployed across the global energy sector. Security researcher Pedro Umbelino reported a severe command injection flaw (CVE-2025-58428) in the SOAP-based web service, enabling attackers with valid credentials to execute system-level commands, gain shell access, and potentially move laterally within targeted networks. A second vulnerability (CVE-2025-55067) affects time handling, potentially enabling attackers to cause authentication failures and denial of service by exploiting the Unix epoch rollover issue. Both vulnerabilities are remotely exploitable and threaten operational continuity, device functionality, and network integrity. This incident highlights the growing exposure of industrial control systems to sophisticated, remotely exploitable vulnerabilities. With the energy sector’s increasing reliance on interconnected OT devices, attackers are targeting control interfaces and authentication flaws to achieve deeper network access, reinforcing the urgent need for proactive risk assessments and robust segmentation strategies.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Delta Electronics ASDA-Soft 2025 Buffer Overflow: Securing Industrial Control Software
Impact· low

Delta Electronics ASDA-Soft 2025 Buffer Overflow: Securing Industrial Control Software

In October 2025, Delta Electronics disclosed critical buffer overflow vulnerabilities (CVE-2025-62579, CVE-2025-62580) affecting their ASDA-Soft automation software, widely used in the critical manufacturing sector. Identified by security researcher Guillaume Orlando via Trend Micro's Zero Day Initiative, the flaws allow attackers to execute code or corrupt memory by convincing users to open malicious project files, potentially leading to loss of control, data compromise, or disruption of industrial processes. Delta responded with a patched software release (v7.1.1.0+) and advisories to enhance network segmentation, firewall defenses, and conduct impact assessments. This incident highlights the ongoing exposure of operational technology (OT) in industrial environments to traditional software exploitation techniques. Regulatory scrutiny and the expansion of threat actor targeting of critical infrastructure elevate the urgency for timely patching, software supply chain validation, and segmented, zero-trust OT/IT network architectures.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports