The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Transportation

Breach intelligence, attack campaigns, and threat reports targeting the Transportation sector.

173 threat reports
Page 1 of 15

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Transportation Threat Reports

Showing 1–12 / 173 reports
2025 Industrial Automation Breach Exposes Critical Infrastructure Through Supply Chain Attack
Impact· HIGH

2025 Industrial Automation Breach Exposes Critical Infrastructure Through Supply Chain Attack

Between March and April 2025, foreign cyber actors infiltrated a U.S. industrial automation solutions company providing SCADA programming and system integration services to critical infrastructure entities including power utilities and transportation systems. The attackers conducted reconnaissance using search terms like 'customers' and 'SCADA,' subsequently creating nine ZIP files containing approximately 800 exfiltrated files including customer SCADA information, ICS device specifications, and operational schematics. This supply chain compromise exposed sensitive infrastructure data that could enable future disruptive attacks against operational technology environments. This incident highlights the growing threat to critical infrastructure through third-party integrator compromises, occurring amid increased focus on ICS security following recent nation-state campaigns targeting operational technology systems and growing regulatory emphasis on supply chain risk management in critical sectors.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Vulnerabilities Expose Botslab Dashcams to Complete Remote Takeover
Impact· MEDIUM

Critical Vulnerabilities Expose Botslab Dashcams to Complete Remote Takeover

CISA published advisory ICSA-26-267-01 detailing 13 critical vulnerabilities in Botslab G980H dashcams affecting two firmware versions worldwide. The vulnerabilities include authentication bypass, session hijacking, predictable session identifiers, hard-coded credentials, unencrypted communications, and path traversal flaws with CVSS scores up to 8.8. Attackers with adjacent network access can gain unauthorized device control, access sensitive recordings and location data, intercept WiFi credentials, and potentially install malicious firmware. Botslab has not responded to CISA's coordination efforts, leaving users without official patches or remediation guidance. This incident highlights the growing security risks in IoT devices within transportation infrastructure, as dashcams increasingly capture sensitive location data and connect to corporate networks through fleet management systems.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Corp MDM Android Spyware Campaign Exposes Critical Mobile Security Gaps in Logistics Sector
Impact· HIGH

Corp MDM Android Spyware Campaign Exposes Critical Mobile Security Gaps in Logistics Sector

In September 2026, a sophisticated Android spyware campaign dubbed Corp MDM targeted logistics firms including CEVA and TKW Logistics through fake Google Play Store pages. The malware, distributed via fraudulent APK files disguised as system services, enabled attackers to intercept SMS messages, redirect calls, and maintain persistent device access. The campaign utilized cleartext HTTP communications to exfiltrate sensitive data including one-time passwords, transaction notifications, and delivery updates, with command-and-control infrastructure hosted at IP address 69.55.61.82. The operation appears to be orchestrated by Russian-Armenian threat actors and represents part of a broader multi-platform assault on the logistics sector involving credential phishing and Windows-based malware. This incident highlights the escalating sophistication of mobile-targeted supply chain attacks as threat actors increasingly weaponize AI-assisted development and exploit the logistics sector's heavy reliance on mobile communications for operational coordination.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical lwIP Vulnerability Exposes Industrial Control Systems to Memory Corruption Attacks
Impact· HIGH

Critical lwIP Vulnerability Exposes Industrial Control Systems to Memory Corruption Attacks

A critical double free vulnerability (CVE-2026-91018) has been discovered in lwIP (Lightweight IP), a widely-used TCP/IP stack implementation found in embedded systems and IoT devices across critical infrastructure sectors including energy, healthcare, manufacturing, and transportation. The vulnerability affects lwIP API versions 2.0.1 through 2.2.1 and could allow attackers to crash systems, cause denial of service, corrupt memory, or potentially execute arbitrary code on vulnerable devices. With a CVSS score of 8.8, this flaw poses significant risks to industrial control systems and critical infrastructure worldwide, though exploitation requires adjacent network access. This vulnerability highlights the growing security challenges facing critical infrastructure as operational technology becomes increasingly connected and internet-accessible, while many organizations struggle with patching embedded systems that were never designed for regular security updates.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical XSS Vulnerability in OpenPLC Runtime v3 Threatens Industrial Control Systems
Impact· MEDIUM

Critical XSS Vulnerability in OpenPLC Runtime v3 Threatens Industrial Control Systems

A critical cross-site scripting (XSS) vulnerability (CVE-2026-88020) was discovered in OpenPLC Runtime v3, an open-source programmable logic controller platform used across critical infrastructure sectors including manufacturing, energy, transportation, and water systems. The vulnerability allows attackers to hijack session cookies and issue state-changing requests as operators, potentially enabling unauthorized control of industrial processes and physical systems. With a CVSS score of 6.1, the flaw stems from improper input neutralization in the web interface's query string parameter handling, affecting the end-of-life OpenPLC v3 platform deployed worldwide. This vulnerability highlights the growing cybersecurity risks facing industrial control systems as they become increasingly connected to corporate networks and the internet. The convergence of IT and OT security challenges continues to expand the attack surface for critical infrastructure, making legacy industrial systems attractive targets for nation-state actors and cybercriminals seeking to disrupt essential services.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Flock Safety Camera Breach Exposes Critical Flaws in Smart City Surveillance Security
Impact· MEDIUM

Flock Safety Camera Breach Exposes Critical Flaws in Smart City Surveillance Security

In 2026, security researchers successfully reverse-engineered Flock Safety's automatic license plate reader (ALPR) cameras, exposing critical security vulnerabilities in the widely-deployed surveillance infrastructure. The analysis revealed that while most sensitive data remained encrypted, poor security architecture left encryption keys stored on unencrypted partitions, allowing researchers to access extensive surveillance logs containing over one million captured images. The investigation uncovered that the cameras' computer vision software actively detects and catalogs people, vehicles, bicycles, and even specific details like bumper stickers and patches, generating dozens of images per passing vehicle. This breach of a major surveillance technology provider highlights significant privacy and security concerns in municipal and law enforcement surveillance systems. This incident demonstrates the growing vulnerability of IoT surveillance infrastructure as researchers and malicious actors increasingly target physical devices that municipalities and businesses rely on for security operations.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
FamousSparrow's Latin America Campaign: When Cyber Espionage Meets Geopolitical Competition
Impact· HIGH

FamousSparrow's Latin America Campaign: When Cyber Espionage Meets Geopolitical Competition

In July 2025, the Chinese APT group FamousSparrow pivoted to exclusively target Latin American government organizations using a new custom backdoor called SparroWocky. The campaign focuses on countries with significant Chinese Belt and Road Initiative investments including Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group deployed sophisticated evasion techniques including stack spoofing, in-memory execution, encrypted C2 communications, and Beacon Object File compatibility to maintain persistent access while monitoring government responses to US pressure on Chinese regional influence. This incident represents the new reality of cyber espionage in geopolitical competition, as nation-state actors increasingly use targeted surveillance to gain strategic intelligence about economic and political developments that affect their global investments and sphere of influence.

1 week ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Bransys ELD Vulnerabilities Expose Transportation Fleet Data Through Hardcoded Credentials
Impact· HIGH

Critical Bransys ELD Vulnerabilities Expose Transportation Fleet Data Through Hardcoded Credentials

In September 2026, CISA disclosed critical vulnerabilities in Bransys Electronic Logging Device (ELD) systems affecting both Android and iOS versions. The vulnerabilities included hardcoded MQTT and FTP credentials (CVE-2026-86520, CVE-2026-77960) and cleartext transmission of sensitive information (CVE-2026-86689). These flaws could allow unauthorized attackers to access real-time telemetry data from active devices across multiple transportation carriers, potentially compromising driver location data, vehicle diagnostics, and compliance records. The vendor has released patches requiring users to update to Android version 11.00.00 or iOS version 1.1.54. This incident highlights the growing security risks in critical transportation infrastructure as IoT devices become more interconnected. With increasing regulatory scrutiny on supply chain security and the recent focus on transportation system vulnerabilities following nation-state attacks on critical infrastructure, organizations must prioritize secure development practices and regular security assessments of embedded systems.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
How Iranian Cyber Operations Target the Hidden Infrastructure Behind U.S. Military Power
Impact· HIGH

How Iranian Cyber Operations Target the Hidden Infrastructure Behind U.S. Military Power

Iranian cyber operations are increasingly targeting the interconnected civilian infrastructure that supports U.S. military operations, including commercial railroads, ports, utilities, and defense contractors. Rather than pursuing catastrophic single attacks, Iranian threat groups are conducting persistent, volume-based campaigns across multiple smaller targets to strain response capabilities and disrupt military logistics chains. Recent attacks on water utilities across 12 states and a four-day power plant outage in the UK demonstrate this strategy of imposing cumulative operational strain rather than seeking headline-grabbing breaches. This threat model reflects Iran's adaptation to prolonged conflict scenarios, where creating sustained disruption across military-supporting infrastructure becomes more strategically valuable than traditional espionage or single-point failures.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Coast Guard and FBI Investigate Maritime Cyberattacks on Foreign Tankers
Impact· MEDIUM

Coast Guard and FBI Investigate Maritime Cyberattacks on Foreign Tankers

In August 2024, the U.S. Coast Guard and FBI conducted joint offshore security boardings of two foreign commercial tankers in the Gulf of Mexico following cyberattacks that compromised their networks. The first vessel, carrying oil and natural gas, was hacked while transiting the Strait of Gibraltar and lost communications for over 30 hours. Authorities investigated potential Iranian involvement or threat actors exploiting U.S.-Iran tensions, as part of broader concerns about 'dark fleets' carrying sanctioned oil using digital masking techniques. This incident highlights the growing convergence of cybersecurity threats with critical infrastructure and supply chain security, particularly as nation-state actors increasingly target maritime operations to disrupt global commerce and energy transportation networks.

1 week ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical Hardcoded Key Vulnerabilities Expose Maritime Infrastructure in Wärtsilä FOS-Onboard Systems
Impact· HIGH

Critical Hardcoded Key Vulnerabilities Expose Maritime Infrastructure in Wärtsilä FOS-Onboard Systems

Critical vulnerabilities CVE-2026-78225 and CVE-2026-81855 were discovered in Wärtsilä FOS-Onboard version 5.07.0923.01, affecting maritime transportation systems worldwide. Both vulnerabilities involve hardcoded cryptographic keys - one in the deployer-ng Update Controller component and another in the robot testing framework component. With CVSS scores of 9.0 and 9.1 respectively, successful exploitation could allow attackers to deliver unauthorized updates, execute arbitrary code, or extract credentials to impersonate privileged clients. Wärtsilä has developed security patches and states the vulnerabilities are not exploitable when the product is installed according to recommendations. This incident highlights the growing threat to maritime critical infrastructure as operational technology systems become increasingly connected and targeted by sophisticated adversaries seeking to disrupt global supply chains.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CVE-2025-10478: Rockwell Automation ICS Module Vulnerability Threatens Critical Infrastructure
Impact· MEDIUM

CVE-2025-10478: Rockwell Automation ICS Module Vulnerability Threatens Critical Infrastructure

A critical denial-of-service vulnerability (CVE-2025-10478) has been discovered in Rockwell Automation's 1756-ENBT ControlLogix EtherNet/IP bridge modules, affecting all versions deployed across critical infrastructure sectors worldwide. Attackers can exploit this flaw by sending crafted CIP packets to crash the module, requiring a manual restart to restore operations. The vulnerability impacts manufacturing, food and agriculture, transportation, and water treatment facilities that rely on these industrial control systems for operational continuity. This incident highlights the growing threat landscape targeting industrial control systems as critical infrastructure becomes increasingly digitized and interconnected. The vulnerability demonstrates how network-accessible ICS components remain vulnerable to simple but effective attacks that can disrupt essential services.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports