The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Transportation
Breach intelligence, attack campaigns, and threat reports targeting the Transportation sector.
Explore Other Sectors
Transportation Threat Reports
2025 Industrial Automation Breach Exposes Critical Infrastructure Through Supply Chain Attack
Between March and April 2025, foreign cyber actors infiltrated a U.S. industrial automation solutions company providing SCADA programming and system integration services to critical infrastructure entities including power utilities and transportation systems. The attackers conducted reconnaissance using search terms like 'customers' and 'SCADA,' subsequently creating nine ZIP files containing approximately 800 exfiltrated files including customer SCADA information, ICS device specifications, and operational schematics. This supply chain compromise exposed sensitive infrastructure data that could enable future disruptive attacks against operational technology environments. This incident highlights the growing threat to critical infrastructure through third-party integrator compromises, occurring amid increased focus on ICS security following recent nation-state campaigns targeting operational technology systems and growing regulatory emphasis on supply chain risk management in critical sectors.
1 day ago
Kill Chain
Critical Vulnerabilities Expose Botslab Dashcams to Complete Remote Takeover
CISA published advisory ICSA-26-267-01 detailing 13 critical vulnerabilities in Botslab G980H dashcams affecting two firmware versions worldwide. The vulnerabilities include authentication bypass, session hijacking, predictable session identifiers, hard-coded credentials, unencrypted communications, and path traversal flaws with CVSS scores up to 8.8. Attackers with adjacent network access can gain unauthorized device control, access sensitive recordings and location data, intercept WiFi credentials, and potentially install malicious firmware. Botslab has not responded to CISA's coordination efforts, leaving users without official patches or remediation guidance. This incident highlights the growing security risks in IoT devices within transportation infrastructure, as dashcams increasingly capture sensitive location data and connect to corporate networks through fleet management systems.
1 day ago
Kill Chain
Corp MDM Android Spyware Campaign Exposes Critical Mobile Security Gaps in Logistics Sector
In September 2026, a sophisticated Android spyware campaign dubbed Corp MDM targeted logistics firms including CEVA and TKW Logistics through fake Google Play Store pages. The malware, distributed via fraudulent APK files disguised as system services, enabled attackers to intercept SMS messages, redirect calls, and maintain persistent device access. The campaign utilized cleartext HTTP communications to exfiltrate sensitive data including one-time passwords, transaction notifications, and delivery updates, with command-and-control infrastructure hosted at IP address 69.55.61.82. The operation appears to be orchestrated by Russian-Armenian threat actors and represents part of a broader multi-platform assault on the logistics sector involving credential phishing and Windows-based malware. This incident highlights the escalating sophistication of mobile-targeted supply chain attacks as threat actors increasingly weaponize AI-assisted development and exploit the logistics sector's heavy reliance on mobile communications for operational coordination.
1 day ago
Kill Chain
Critical lwIP Vulnerability Exposes Industrial Control Systems to Memory Corruption Attacks
A critical double free vulnerability (CVE-2026-91018) has been discovered in lwIP (Lightweight IP), a widely-used TCP/IP stack implementation found in embedded systems and IoT devices across critical infrastructure sectors including energy, healthcare, manufacturing, and transportation. The vulnerability affects lwIP API versions 2.0.1 through 2.2.1 and could allow attackers to crash systems, cause denial of service, corrupt memory, or potentially execute arbitrary code on vulnerable devices. With a CVSS score of 8.8, this flaw poses significant risks to industrial control systems and critical infrastructure worldwide, though exploitation requires adjacent network access. This vulnerability highlights the growing security challenges facing critical infrastructure as operational technology becomes increasingly connected and internet-accessible, while many organizations struggle with patching embedded systems that were never designed for regular security updates.
3 days ago
Kill Chain
Critical XSS Vulnerability in OpenPLC Runtime v3 Threatens Industrial Control Systems
A critical cross-site scripting (XSS) vulnerability (CVE-2026-88020) was discovered in OpenPLC Runtime v3, an open-source programmable logic controller platform used across critical infrastructure sectors including manufacturing, energy, transportation, and water systems. The vulnerability allows attackers to hijack session cookies and issue state-changing requests as operators, potentially enabling unauthorized control of industrial processes and physical systems. With a CVSS score of 6.1, the flaw stems from improper input neutralization in the web interface's query string parameter handling, affecting the end-of-life OpenPLC v3 platform deployed worldwide. This vulnerability highlights the growing cybersecurity risks facing industrial control systems as they become increasingly connected to corporate networks and the internet. The convergence of IT and OT security challenges continues to expand the attack surface for critical infrastructure, making legacy industrial systems attractive targets for nation-state actors and cybercriminals seeking to disrupt essential services.
3 days ago
Kill Chain
Flock Safety Camera Breach Exposes Critical Flaws in Smart City Surveillance Security
In 2026, security researchers successfully reverse-engineered Flock Safety's automatic license plate reader (ALPR) cameras, exposing critical security vulnerabilities in the widely-deployed surveillance infrastructure. The analysis revealed that while most sensitive data remained encrypted, poor security architecture left encryption keys stored on unencrypted partitions, allowing researchers to access extensive surveillance logs containing over one million captured images. The investigation uncovered that the cameras' computer vision software actively detects and catalogs people, vehicles, bicycles, and even specific details like bumper stickers and patches, generating dozens of images per passing vehicle. This breach of a major surveillance technology provider highlights significant privacy and security concerns in municipal and law enforcement surveillance systems. This incident demonstrates the growing vulnerability of IoT surveillance infrastructure as researchers and malicious actors increasingly target physical devices that municipalities and businesses rely on for security operations.
4 days ago
Kill Chain
FamousSparrow's Latin America Campaign: When Cyber Espionage Meets Geopolitical Competition
In July 2025, the Chinese APT group FamousSparrow pivoted to exclusively target Latin American government organizations using a new custom backdoor called SparroWocky. The campaign focuses on countries with significant Chinese Belt and Road Initiative investments including Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group deployed sophisticated evasion techniques including stack spoofing, in-memory execution, encrypted C2 communications, and Beacon Object File compatibility to maintain persistent access while monitoring government responses to US pressure on Chinese regional influence. This incident represents the new reality of cyber espionage in geopolitical competition, as nation-state actors increasingly use targeted surveillance to gain strategic intelligence about economic and political developments that affect their global investments and sphere of influence.
1 week ago
Kill Chain
Critical Bransys ELD Vulnerabilities Expose Transportation Fleet Data Through Hardcoded Credentials
In September 2026, CISA disclosed critical vulnerabilities in Bransys Electronic Logging Device (ELD) systems affecting both Android and iOS versions. The vulnerabilities included hardcoded MQTT and FTP credentials (CVE-2026-86520, CVE-2026-77960) and cleartext transmission of sensitive information (CVE-2026-86689). These flaws could allow unauthorized attackers to access real-time telemetry data from active devices across multiple transportation carriers, potentially compromising driver location data, vehicle diagnostics, and compliance records. The vendor has released patches requiring users to update to Android version 11.00.00 or iOS version 1.1.54. This incident highlights the growing security risks in critical transportation infrastructure as IoT devices become more interconnected. With increasing regulatory scrutiny on supply chain security and the recent focus on transportation system vulnerabilities following nation-state attacks on critical infrastructure, organizations must prioritize secure development practices and regular security assessments of embedded systems.
1 week ago
Kill Chain
How Iranian Cyber Operations Target the Hidden Infrastructure Behind U.S. Military Power
Iranian cyber operations are increasingly targeting the interconnected civilian infrastructure that supports U.S. military operations, including commercial railroads, ports, utilities, and defense contractors. Rather than pursuing catastrophic single attacks, Iranian threat groups are conducting persistent, volume-based campaigns across multiple smaller targets to strain response capabilities and disrupt military logistics chains. Recent attacks on water utilities across 12 states and a four-day power plant outage in the UK demonstrate this strategy of imposing cumulative operational strain rather than seeking headline-grabbing breaches. This threat model reflects Iran's adaptation to prolonged conflict scenarios, where creating sustained disruption across military-supporting infrastructure becomes more strategically valuable than traditional espionage or single-point failures.
1 week ago
Kill Chain
Coast Guard and FBI Investigate Maritime Cyberattacks on Foreign Tankers
In August 2024, the U.S. Coast Guard and FBI conducted joint offshore security boardings of two foreign commercial tankers in the Gulf of Mexico following cyberattacks that compromised their networks. The first vessel, carrying oil and natural gas, was hacked while transiting the Strait of Gibraltar and lost communications for over 30 hours. Authorities investigated potential Iranian involvement or threat actors exploiting U.S.-Iran tensions, as part of broader concerns about 'dark fleets' carrying sanctioned oil using digital masking techniques. This incident highlights the growing convergence of cybersecurity threats with critical infrastructure and supply chain security, particularly as nation-state actors increasingly target maritime operations to disrupt global commerce and energy transportation networks.
1 week ago
Kill Chain
Critical Hardcoded Key Vulnerabilities Expose Maritime Infrastructure in Wärtsilä FOS-Onboard Systems
Critical vulnerabilities CVE-2026-78225 and CVE-2026-81855 were discovered in Wärtsilä FOS-Onboard version 5.07.0923.01, affecting maritime transportation systems worldwide. Both vulnerabilities involve hardcoded cryptographic keys - one in the deployer-ng Update Controller component and another in the robot testing framework component. With CVSS scores of 9.0 and 9.1 respectively, successful exploitation could allow attackers to deliver unauthorized updates, execute arbitrary code, or extract credentials to impersonate privileged clients. Wärtsilä has developed security patches and states the vulnerabilities are not exploitable when the product is installed according to recommendations. This incident highlights the growing threat to maritime critical infrastructure as operational technology systems become increasingly connected and targeted by sophisticated adversaries seeking to disrupt global supply chains.
1 week ago
Kill Chain
CVE-2025-10478: Rockwell Automation ICS Module Vulnerability Threatens Critical Infrastructure
A critical denial-of-service vulnerability (CVE-2025-10478) has been discovered in Rockwell Automation's 1756-ENBT ControlLogix EtherNet/IP bridge modules, affecting all versions deployed across critical infrastructure sectors worldwide. Attackers can exploit this flaw by sending crafted CIP packets to crash the module, requiring a manual restart to restore operations. The vulnerability impacts manufacturing, food and agriculture, transportation, and water treatment facilities that rely on these industrial control systems for operational continuity. This incident highlights the growing threat landscape targeting industrial control systems as critical infrastructure becomes increasingly digitized and interconnected. The vulnerability demonstrates how network-accessible ICS components remain vulnerable to simple but effective attacks that can disrupt essential services.
3 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports