✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Transportation
Breach intelligence, attack campaigns, and threat reports targeting the Transportation sector.
Explore Other Sectors
Transportation Threat Reports
Critical Vulnerabilities Discovered in ABB Terra AC Wallbox EV Chargers
In September 2025, ABB identified multiple buffer overflow vulnerabilities in its Terra AC Wallbox electric vehicle chargers, specifically affecting firmware versions up to 1.8.33. These vulnerabilities, cataloged as CVE-2025-10504, CVE-2025-12142, and CVE-2025-12143, could allow attackers with adjacent network access and high privileges to execute arbitrary code, potentially leading to unauthorized control over the device. ABB promptly released firmware version 1.8.36 to address these issues and recommended immediate updates to mitigate potential risks. The discovery of these vulnerabilities underscores the critical importance of securing IoT devices, especially those connected to critical infrastructure like energy distribution. As the adoption of electric vehicle chargers grows, ensuring robust cybersecurity measures is essential to prevent potential exploitation that could disrupt services and compromise user safety.
2 months ago
Kill Chain
Critical Vulnerability in Palo Alto Networks PAN-OS: CVE-2026-0300
In May 2026, a critical buffer overflow vulnerability (CVE-2026-0300) was identified in the User-ID™ Authentication Portal service of Palo Alto Networks PAN-OS software. This flaw allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. The vulnerability affects PAN-OS versions prior to 12.1.4-h5, 11.2.4-h17, 11.1.4-h33, and 10.2.7-h34. Exploitation has been observed in the wild, primarily targeting systems with the Authentication Portal exposed to untrusted networks. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0300?utm_source=openai)) The incident underscores the importance of securing network access to critical services and adhering to best practice guidelines. Organizations are advised to restrict access to the User-ID™ Authentication Portal to trusted internal IP addresses and apply the necessary software updates promptly to mitigate potential risks. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0300?utm_source=openai))
2 months ago
Kill Chain
Iranian Hackers Compromise U.S. Fuel Monitoring Systems in 2026
In May 2026, Iranian hackers reportedly breached automatic tank gauge (ATG) systems monitoring fuel levels at gas stations across multiple U.S. states. These systems, exposed online without password protection, allowed attackers to alter display readings without affecting actual fuel levels. While no physical damage occurred, the incident underscores vulnerabilities in critical infrastructure. ([abc17news.com](https://abc17news.com/politics/national-politics/cnn-us-politics/2026/05/15/exclusive-hackers-have-breached-tank-readers-at-us-gas-stations-officials-suspect-iran-is-responsible/?utm_source=openai)) This breach highlights the evolving nature of cyber warfare, where nation-state actors target essential services. The incident serves as a stark reminder for organizations to secure internet-facing operational technology systems to prevent potential disruptions and safety hazards.
2 months ago
Kill Chain
Taiwan High Speed Rail Radio Hack: A Wake-Up Call for Critical Infrastructure Security
In April 2026, a 23-year-old university student in Taiwan exploited vulnerabilities in the Taiwan High Speed Rail's (THSR) radio communication system, using software-defined radio equipment to transmit a false 'General Alarm' signal. This unauthorized transmission caused four high-speed trains to halt for 48 minutes, disrupting operations and highlighting significant security flaws in critical infrastructure. The student was arrested and released on bail, facing charges related to endangering public transportation safety. ([taipeitimes.com](https://www.taipeitimes.com/News/taiwan/archives/2026/05/05/2003856781?utm_source=openai)) This incident underscores the pressing need for robust cybersecurity measures in transportation systems, especially as similar vulnerabilities have been exploited in other countries. It serves as a wake-up call for infrastructure operators worldwide to reassess and fortify their communication protocols against potential cyber threats.
2 months ago
Kill Chain
Cyber-Enabled Cargo Theft: A $725 Million Wake-Up Call for the Transportation Industry
In 2025, cybercriminals orchestrated a series of sophisticated attacks targeting the transportation and logistics sectors, resulting in approximately $725 million in cargo theft losses across North America. These threat actors employed phishing emails, spoofed websites, and compromised carrier accounts to infiltrate freight brokers and carriers. Once inside, they posted fraudulent listings on load boards, deceiving legitimate carriers into transporting shipments to unauthorized destinations controlled by the criminals. This method allowed entire truckloads of goods, including pharmaceuticals and consumer products, to be rerouted and stolen without physical hijacking. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260430?utm_source=openai)) The surge in cyber-enabled cargo theft underscores the evolving tactics of organized crime, blending traditional theft with advanced cyber techniques. This trend highlights the urgent need for enhanced cybersecurity measures within the transportation industry to protect against such multifaceted threats.
2 months ago
Kill Chain
Critical Vulnerability in Johnson Controls CEM AC2000: CVE-2026-21661
In May 2026, a critical vulnerability (CVE-2026-21661) was identified in Johnson Controls' CEM AC2000 versions 10.6, 11.0, and 12.0. This flaw, stemming from an uncontrolled search path element, allows standard users to escalate privileges on the host machine via DLL hijacking. The vulnerability affects sectors such as Critical Manufacturing, Commercial Facilities, Government Services, Transportation Systems, and Energy. Johnson Controls has released specific updates to remediate this issue. The incident underscores the persistent risks associated with DLL hijacking vulnerabilities in critical infrastructure systems. Organizations are urged to promptly apply the recommended updates and review their security protocols to prevent potential exploitation.
2 months ago
Kill Chain
Student Exploits TETRA Vulnerabilities to Halt Taiwan High-Speed Trains
In April 2026, a 23-year-old university student in Taiwan exploited vulnerabilities in the Taiwan High Speed Rail Corporation's (THSRC) TETRA communication system. Utilizing software-defined radio (SDR) equipment and handheld radios, the student transmitted a forged 'General Alarm' signal, causing four high-speed trains to halt operations for 48 minutes. The attack was facilitated by the static nature of the system's parameters, which had remained unchanged for 19 years, allowing the student to bypass multiple verification layers. Authorities arrested the individual, who now faces charges under Article 184 of the Criminal Law, with potential imprisonment of up to 10 years. This incident underscores the critical need for regular security assessments and updates in communication systems, especially those integral to public safety and infrastructure. The exploitation of longstanding vulnerabilities in the TETRA protocol highlights the urgency for organizations to proactively address potential security gaps to prevent similar disruptions in the future.
2 months ago
Kill Chain
Surge in Cyber-Enabled Cargo Theft: A 2025 Analysis
In 2025, cargo theft losses in the United States and Canada surged by 60%, reaching an estimated $725 million. This increase is attributed to cybercriminals employing sophisticated tactics such as phishing, impersonation, and system compromises to hijack goods during transit. By infiltrating supply chain systems, these actors rerouted shipments, leading to significant financial and operational disruptions for businesses. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260430?utm_source=openai)) The FBI's April 30, 2026, public service announcement underscores the evolving nature of cargo theft, emphasizing the integration of cyber techniques into traditional theft methods. This trend highlights the urgent need for enhanced cybersecurity measures within the transportation and logistics sectors to mitigate the risks posed by these advanced threats. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260430?utm_source=openai))
2 months ago
Kill Chain
FBI Reports 60% Increase in Cyber-Enabled Cargo Thefts in 2025
In 2025, the FBI reported a 60% increase in cyber-enabled cargo thefts across the U.S. and Canada, totaling nearly $725 million in losses. Threat actors infiltrated freight brokers and carriers through phishing emails and fake web links, gaining unauthorized access to systems. They then posted fraudulent listings on online load boards, impersonated legitimate companies, and diverted high-value shipments for resale. The Diesel Vortex group, active since September 2025, targeted freight and logistics operators in the U.S. and Europe, compromising numerous platforms and stealing credentials. This surge underscores the evolving tactics of cybercriminals who exploit digital vulnerabilities to execute physical thefts. The transportation and logistics sectors must enhance cybersecurity measures to protect against such sophisticated attacks.
2 months ago
Kill Chain
SpiceJet Online Booking System Vulnerabilities Expose Passenger Data
In April 2026, two critical vulnerabilities were identified in SpiceJet's Online Booking System: CVE-2026-6375 and CVE-2026-6376. These flaws allowed unauthenticated users to access passenger name records (PNRs) and full booking details using only a PNR and last name, due to missing authorization checks and authentication mechanisms. This exposed sensitive personal and travel information to potential exploitation. ([securityvulnerability.io](https://securityvulnerability.io/vulnerability/CVE-2026-6376?utm_source=openai)) The incident underscores the importance of robust access controls in online systems, especially in the transportation sector. Organizations must prioritize securing sensitive customer data to prevent unauthorized access and potential misuse.
3 months ago
Kill Chain
BlackFile's Vishing Attacks: A Wake-Up Call for Retail and Hospitality Sectors
In early 2026, the BlackFile extortion group initiated a series of data theft and extortion attacks targeting retail and hospitality organizations. Employing voice phishing (vishing) tactics, they impersonated IT support staff to deceive employees into divulging credentials and one-time passcodes. With these credentials, BlackFile registered their own devices to bypass multi-factor authentication, escalated access to executive accounts, and exfiltrated sensitive data from platforms like Salesforce and SharePoint. The stolen data was then used to pressure victims into paying seven-figure ransoms, with threats of public disclosure on their dark web leak site. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang-targets-retail-and-hospitality-orgs/?utm_source=openai)) This incident underscores a significant shift in cybercriminal tactics, highlighting the increasing prevalence of vishing attacks that exploit human vulnerabilities rather than technical system flaws. The success of such social engineering methods emphasizes the need for organizations to enhance employee training and implement robust verification protocols to mitigate similar threats. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang-targets-retail-and-hospitality-orgs/?utm_source=openai))
3 months ago
Kill Chain
Critical Vulnerability in Siemens RUGGEDCOM CROSSBOW SAC: CVE-2025-6965
In April 2026, Siemens disclosed a critical vulnerability (CVE-2025-6965) in its RUGGEDCOM CROSSBOW Station Access Controller (SAC) versions prior to V5.8. This flaw, stemming from a numeric truncation error in the integrated SQLite component, could allow remote attackers to execute arbitrary code or cause a denial-of-service condition. The vulnerability affects systems deployed worldwide in critical manufacturing sectors. Siemens has released version V5.8 to address this issue and strongly recommends users update to this latest version. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-994087.html?utm_source=openai)) This incident underscores the persistent risks associated with third-party software components in industrial control systems. As attackers increasingly target vulnerabilities in widely used libraries, organizations must prioritize timely updates and rigorous security assessments to safeguard critical infrastructure.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports