The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Automotive
Breach intelligence, attack campaigns, and threat reports targeting the Automotive sector.
Explore Other Sectors
Automotive Threat Reports
Critical Denial of Service Vulnerability Exposes Rockwell Automation Industrial Controllers
Rockwell Automation disclosed CVE-2021-42260, a high-severity denial of service vulnerability affecting ControlLogix, CompactLogix, GuardLogix, and Compact GuardLogix controllers. The vulnerability, with a CVSS score of 7.5, allows attackers to trigger an infinite loop condition through corrupt crafted data, causing major nonrecoverable faults (MNRF) in safety controllers and requiring program downloads for recovery. The flaw impacts multiple firmware versions across the 34.x, 35.x, 36.x, and 37.x series, affecting critical manufacturing infrastructure deployed worldwide. This vulnerability highlights the ongoing risks to operational technology environments where denial of service attacks can cause significant operational disruption. As industrial control systems become increasingly connected and targeted by threat actors, vulnerabilities like CVE-2021-42260 demonstrate the critical need for robust OT security measures and timely patch management in manufacturing environments.
3 weeks ago
Kill Chain
Critical DOS Vulnerabilities Threaten Rockwell Automation RSLinx Classic Industrial Systems
Four critical denial-of-service vulnerabilities (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) were discovered in Rockwell Automation's RSLinx Classic versions 4.50 and earlier. These vulnerabilities allow attackers to crash the RSLinx Classic service by sending specially crafted CIP packets, exploiting integer overflow, integer underflow, and buffer overflow conditions. The vulnerabilities affect critical manufacturing infrastructure worldwide and require service restarts to recover, potentially disrupting industrial operations and production systems. These vulnerabilities highlight the growing threat landscape facing industrial control systems as cybercriminals increasingly target critical infrastructure. With the rise of nation-state actors and ransomware groups focusing on OT environments, securing industrial communication protocols like CIP has become paramount for operational resilience.
3 weeks ago
Kill Chain
Critical Password Hash Vulnerability Exposes Rockwell Automation Fleet Management Systems
Rockwell Automation's OTTO Fleet Manager versions 2.36.2 and earlier contain a critical vulnerability (CVE-2026-75112) involving insufficient computational effort in bcrypt password hashing implementation. This weakness reduces the computational cost for attackers to perform offline brute-force attacks against stored password hashes if they gain access to unencrypted system backups. The vulnerability affects industrial fleet management systems used worldwide in critical manufacturing and transportation sectors, with Rockwell Automation releasing version 2.36.3 to address the issue. This incident highlights the growing threat to industrial control systems and the critical importance of proper cryptographic implementations in operational technology environments, particularly as threat actors increasingly target industrial infrastructure with sophisticated attack techniques.
3 weeks ago
Kill Chain
CVE-2025-3511 Exposes Critical Flaws in Industrial Network Security
In May 2025, CISA disclosed CVE-2025-3511, a critical denial-of-service vulnerability affecting over 45 Mitsubishi Electric factory automation (FA) products including CC-Link IE TSN modules, MELSEC iQ-R/iQ-F series controllers, and Ethernet interface modules. The vulnerability stems from improper validation of UDP packet quantities, allowing remote attackers to send specially crafted UDP packets that cause system crashes, communication delays, or timeout errors requiring manual system resets for recovery. This vulnerability highlights the growing threat surface in industrial control systems as manufacturers increasingly adopt networked automation technologies. With a CVSS score of 7.5, the flaw demonstrates how input validation failures in industrial protocols can create significant operational disruptions in critical manufacturing environments.
4 weeks ago
Kill Chain
First Android Malware Targeting Car Head Units Discovered in MoYu Group Campaign
In August 2026, Kaspersky researchers discovered JarService, the first documented Android malware specifically targeting automotive head units. The malware, attributed to the MoYu Group behind the notorious BadBox botnet, infected DoFun-manufactured car head units by exploiting vulnerabilities in the TWCore firmware update system. The multistage downloader spreads through legitimate update functionality and ultimately deploys click-fraud malware and reverse-proxy modules to recruit infected vehicles into a botnet for ad fraud purposes. While the infected infotainment systems pose no direct physical safety risks to drivers, this represents a significant expansion of botnet operations into connected vehicle infrastructure. This incident highlights the growing threat surface as cybercriminals increasingly target IoT and connected vehicle ecosystems. With automotive systems becoming more interconnected and the rise of software-defined vehicles, securing update mechanisms and embedded systems has become critical for preventing botnet recruitment and protecting connected infrastructure from exploitation.
4 weeks ago
Kill Chain
Critical Bendix EC80 Brake ECU Vulnerabilities Threaten Vehicle Safety Systems
In August 2026, CISA disclosed critical vulnerabilities in Bendix EC80 Brake ECU systems used across transportation infrastructure in the United States and Canada. The vulnerabilities include a stack-based buffer overflow (CVE-2026-67560), an out-of-bounds write (CVE-2026-68967), and hard-coded credentials (CVE-2026-71396). Successful exploitation could allow attackers to disable critical safety systems including ABS functions, steering assist, speedometer, automatic traction control, and shifting capabilities, potentially causing catastrophic vehicle safety failures. The vulnerabilities were discovered by Ben Gardiner of NMFTA and affect multiple EC80ESP+ and EC80ESP variants across different firmware versions. This incident highlights the growing threat landscape targeting industrial control systems and critical transportation infrastructure, as nation-state actors and cybercriminals increasingly focus on operational technology vulnerabilities that can cause physical harm and disrupt essential services.
4 weeks ago
Kill Chain
Critical TSN Protocol Flaws Expose Industrial Control Systems to Manipulation
In August 2026, cybersecurity researchers from Nozomi Networks disclosed critical vulnerabilities in Time-Sensitive Networking (TSN) protocols, specifically targeting Mitsubishi Electric's CC-Link IE TSN implementation. The research demonstrated how attackers could exploit Layer 2 security weaknesses and TSN switch management interface flaws to inject malicious traffic into industrial control systems. Successful exploitation allows complete manipulation of operational technology processes, including starting and stopping robotic arms, tampering with synchronization clocks, and disrupting safety-critical communications in manufacturing environments. This research highlights the growing security challenges as industrial automation increasingly adopts TSN protocols for deterministic communication. With nation-state actors targeting critical infrastructure and the convergence of IT and OT networks accelerating, these vulnerabilities expose fundamental weaknesses in emerging industrial protocols that prioritize availability over security.
1 month ago
Kill Chain
First-Ever Android Car Head Unit Malware: MoYu Group's Supply Chain Attack Analysis
In August 2026, Kaspersky researchers discovered a sophisticated supply-chain attack by the MoYu threat group targeting Android-based car head units manufactured by DoFun, a Chinese automotive software provider. The attackers compromised the legitimate TWCore system app to deliver JarService malware, which established command-and-control communication and downloaded additional payloads. The malware transformed infected head units into proxy botnet nodes and conducted advertising fraud operations, marking the first documented malware infection chain specifically designed for automotive head units. While the malware did not interfere with critical vehicle systems, it demonstrated a new attack vector in the expanding Internet of Things landscape. This incident highlights the growing security risks in connected vehicle ecosystems as automotive manufacturers increasingly integrate internet-connected Android systems. The attack underscores vulnerabilities in automotive supply chains and the emergence of vehicles as new targets for cybercriminal monetization schemes.
1 month ago
Kill Chain
Automotive Cybersecurity Alert: First Android Head Unit Malware Targets Connected Vehicles
In June 2026, Kaspersky researchers discovered the first documented case of Android malware specifically targeting automotive head units. The MoYu Group, linked to the BADBOX botnet, exploited legitimate update mechanisms in DoFun head unit firmware to distribute multi-stage malware through the TWCore system application. The attack chain deployed a sophisticated dropper that ultimately created a proxy botnet for ad fraud operations. The malware spread through built-in firmware updaters without user knowledge, establishing command and control infrastructure to recruit infected vehicles into their botnet network. This incident represents a critical expansion of botnet operations into automotive systems, highlighting the growing threat surface as vehicles become increasingly connected. With automotive head units now proven vulnerable to the same malware techniques used against smartphones and IoT devices, the automotive industry faces new cybersecurity challenges requiring immediate attention.
1 month ago
Kill Chain
First Android Car Malware Campaign Targets Vehicle Head Units Through Update Compromise
In June 2026, Kaspersky discovered the first documented malware specifically targeting Android-based vehicle head units, marking a significant expansion of cybercriminal operations into automotive systems. The malware, attributed to the MoYu Group behind the BADBOX botnet, infected DoFun-powered head units through compromised legitimate update mechanisms. Attackers weaponized the TWCore system app's MQTT-based update channel to deliver JarService dropper malware, enabling ad fraud and proxy botnet creation. The sophisticated attack chain demonstrates how threat actors are adapting traditional mobile malware techniques for automotive platforms, exploiting SIM-enabled connectivity in modern vehicle infotainment systems. This incident highlights the emerging threat landscape as connected vehicles become mainstream targets, with automotive cybersecurity gaps creating new attack vectors for established cybercriminal groups seeking to monetize vehicle connectivity infrastructure.
1 month ago
Kill Chain
Clop Ransomware's Targeted Attack on PTC Windchill via CVE-2026-12569
In August 2026, the Clop ransomware group exploited a critical vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM servers, deploying a custom JavaServer Pages (JSP) web shell. This sophisticated implant enabled attackers to decrypt stored credentials, map sensitive engineering data, and execute arbitrary code, facilitating remote access, data exfiltration, and potential ransomware deployment. The attack underscores the evolving tactics of threat actors in targeting enterprise Product Lifecycle Management (PLM) software to access proprietary information and credentials. Organizations utilizing such platforms must prioritize timely patching and robust security measures to mitigate the risk of similar exploits.
1 month ago
Kill Chain
Critical Vulnerability in Siemens Simcenter Nastran: CVE-2026-59086
In August 2026, Siemens disclosed a critical stack overflow vulnerability (CVE-2026-59086) in Simcenter Nastran versions prior to V2606. This flaw allows attackers to execute arbitrary code by exploiting the application's argument parsing mechanism. If a user is tricked into running the affected application with a malicious string, the vulnerability can be leveraged to perform remote code execution within the current process context. Siemens has released updated versions to address this issue and recommends users upgrade to V2606 or later. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-965753.html?utm_source=openai)) This incident underscores the persistent risk of stack overflow vulnerabilities in critical engineering software, highlighting the importance of timely software updates and vigilant security practices to prevent potential exploitation.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports