The Containment Era is here. →Explore

Industry Category

Transportation

Breach intelligence, attack campaigns, and threat reports targeting the Transportation sector.

131 threat reports
Page 5 of 11

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Transportation Threat Reports

Showing 4960 / 131 reports
Zero Motorcycles Firmware Vulnerability Exposes Riders to Potential Attacks
Impact· MEDIUM

Zero Motorcycles Firmware Vulnerability Exposes Riders to Potential Attacks

In April 2026, a vulnerability identified as CVE-2026-1354 was discovered in Zero Motorcycles' firmware versions 44 and earlier. This flaw allows an attacker in close proximity to forcibly pair a device with the motorcycle via Bluetooth. Once paired, the attacker can exploit the over-the-air firmware update functionality to potentially upload malicious firmware, compromising the motorcycle's integrity. The attack requires the motorcycle to be in Bluetooth pairing mode, and the attacker must maintain proximity throughout the firmware update process. ([securityvulnerability.io](https://securityvulnerability.io/vulnerability/CVE-2026-1354?utm_source=openai)) This incident underscores the growing cybersecurity risks associated with connected vehicles, particularly in the transportation sector. As vehicles become increasingly integrated with wireless technologies, vulnerabilities like this highlight the urgent need for robust security measures to prevent unauthorized access and ensure user safety.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical Vulnerabilities in Hardy Barth Salia EV Charge Controllers Expose Infrastructure Risks
Impact· HIGH

Critical Vulnerabilities in Hardy Barth Salia EV Charge Controllers Expose Infrastructure Risks

In April 2026, CISA disclosed two critical vulnerabilities in Hardy Barth's Salia EV Charge Controller firmware versions up to 2.3.81. Identified as CVE-2025-5873 and CVE-2025-10371, these flaws allow remote attackers to upload malicious files via the web interface, potentially leading to remote code execution. Despite public proof-of-concept exploits being available, Hardy Barth has not responded to coordination requests, leaving systems at risk. This incident underscores the growing cybersecurity challenges in the EV infrastructure sector. The lack of vendor response highlights the need for proactive security measures and vigilant monitoring to protect critical energy and transportation systems from emerging threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in Siemens RUGGEDCOM SAM-P: Immediate Action Required
Impact· HIGH

Critical Vulnerability in Siemens RUGGEDCOM SAM-P: Immediate Action Required

In April 2026, a critical privilege escalation vulnerability (CVE-2026-27668) was identified in Siemens RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) versions prior to V5.8. This flaw allows authenticated User Administrators to modify their own group memberships, potentially granting themselves elevated access across device groups. Siemens has addressed this issue by releasing version V5.8 and recommends immediate updates to mitigate the risk. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-741509.html?utm_source=openai)) This incident underscores the importance of stringent access controls and regular software updates in industrial control systems. Organizations should review their administrative privileges and ensure that all systems are updated to prevent unauthorized access and maintain operational integrity.

3 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
BRIDGE:BREAK Vulnerabilities Threaten Critical Infrastructure Security
Impact· MEDIUM

BRIDGE:BREAK Vulnerabilities Threaten Critical Infrastructure Security

In April 2026, Forescout Technologies identified 22 vulnerabilities in serial-to-IP converters from Lantronix and Silex, devices integral to connecting legacy industrial equipment to modern networks. These vulnerabilities, collectively named BRIDGE:BREAK, could allow attackers to disrupt operations, move laterally across networks, tamper with sensitive data, or take control of affected devices. The flaws include remote code execution, authentication bypass, firmware manipulation, denial of service, and exposure of confidential information. Notably, tens of thousands of these devices are accessible over the internet, significantly broadening the attack surface for potential cyberattacks. This discovery underscores the persistent security challenges in operational technology environments, especially concerning devices that bridge legacy systems with modern infrastructure. The prevalence of these vulnerabilities highlights the need for organizations to reassess their security postures, particularly in sectors like utilities, manufacturing, and healthcare, where such devices are commonly deployed.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Eurail 2025 Data Breach: A Wake-Up Call for Travel Industry Cybersecurity
Impact· HIGH

Eurail 2025 Data Breach: A Wake-Up Call for Travel Industry Cybersecurity

In late December 2025, Eurail B.V., a Netherlands-based travel company, experienced a significant data breach when unauthorized actors accessed its network and exfiltrated files containing sensitive customer information. The breach, which occurred on December 26, 2025, was discovered on January 5, 2026, and confirmed on February 25, 2026. Approximately 308,777 individuals were affected, with compromised data including names, passport numbers, dates of birth, email addresses, postal addresses, phone numbers, bank account references (IBANs), and health-related information. ([claimdepot.com](https://www.claimdepot.com/data-breach/eurail-2026?utm_source=openai)) This incident underscores the escalating threat landscape targeting the travel industry, where personal data is highly valuable. The breach highlights the critical need for robust cybersecurity measures, including regular system audits, employee training, and comprehensive incident response plans to mitigate potential risks and protect customer information.

3 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Beware: QR Code Phishing Scams Targeting Drivers in 2026
Impact· MEDIUM

Beware: QR Code Phishing Scams Targeting Drivers in 2026

In early 2026, a sophisticated phishing campaign emerged across multiple U.S. states, including New York, California, and Texas. Scammers sent fraudulent text messages impersonating state courts, alleging recipients had outstanding traffic violations. These messages included images of fake court notices embedded with QR codes, urging immediate payment of fines to avoid severe penalties. Scanning the QR codes redirected victims to phishing websites designed to steal personal and financial information. This method, known as 'quishing' (QR code phishing), represents an evolution in cybercriminal tactics, leveraging QR codes to bypass traditional security measures and exploit the trust users place in official-looking communications. The widespread nature of this scam underscores the need for heightened vigilance and public awareness regarding unsolicited messages containing QR codes.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Surge in Cyberattacks Targets Latin American Governments in 2026
Impact· CRITICAL

Surge in Cyberattacks Targets Latin American Governments in 2026

In early 2026, Latin American governments faced a significant surge in cyberattacks targeting critical infrastructure and sensitive data. Notably, Colombia's health ministry reported over 23 million cyberattacks and probes in March, while Mexico's government agencies suffered breaches compromising millions of identities and tax records. Puerto Rico's Department of Transportation also experienced disruptions due to cyber incidents. These attacks were primarily driven by financially motivated cybercriminals, with a notable increase in nation-state espionage and politically motivated hacktivism. The region's rapid digitalization, coupled with legacy systems and a shortage of cybersecurity professionals, has exacerbated vulnerabilities, making government networks prime targets for cyber adversaries. ([darkreading.com](https://www.darkreading.com/cyber-risk/latin-american-confidence-cyber-defenses-skills?utm_source=openai)) This escalation underscores the urgent need for Latin American governments to bolster their cybersecurity defenses. The convergence of AI acceleration, geopolitical fragmentation, and cyber-enabled fraud is reshaping the global risk landscape, necessitating enhanced threat intelligence, public-private cooperation, and investment in cybersecurity infrastructure to mitigate the growing threats. ([weforum.org](https://www.weforum.org/stories/2026/01/geopolitics-ai-fraud-global-cyber-cybersecurity-2026/?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability in Anritsu Remote Spectrum Monitors: CVE-2026-3356
Impact· CRITICAL

Critical Vulnerability in Anritsu Remote Spectrum Monitors: CVE-2026-3356

In March 2026, a critical vulnerability (CVE-2026-3356) was identified in Anritsu's Remote Spectrum Monitor series, including models MS27100A, MS27101A, MS27102A, and MS27103A. This flaw allows attackers with network access to bypass authentication mechanisms, enabling unauthorized alteration of operational settings, access to sensitive signal data, and potential disruption of device availability. Anritsu has acknowledged the issue but has no plans to release a fix, recommending that users deploy these devices within secure network environments to mitigate risks. This incident underscores the persistent challenges in securing networked measurement instruments, especially those integral to critical infrastructure sectors such as communications, defense, emergency services, and transportation. The lack of a planned fix highlights the importance of proactive security measures and the need for organizations to assess and fortify their network defenses against such vulnerabilities.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Security Alert: PX4 Autopilot MAVLink Vulnerability (CVE-2026-1579)
Impact· CRITICAL

Critical Security Alert: PX4 Autopilot MAVLink Vulnerability (CVE-2026-1579)

In March 2026, a critical vulnerability (CVE-2026-1579) was identified in the PX4 Autopilot's MAVLink communication protocol. This flaw allows unauthenticated attackers with access to the MAVLink interface to execute arbitrary shell commands, potentially leading to full system compromise. The vulnerability stems from the protocol's default lack of cryptographic authentication, enabling malicious actors to send unauthorized messages, including those granting interactive shell access. ([thehackerwire.com](https://www.thehackerwire.com/vulnerability/CVE-2026-1579/?utm_source=openai)) This incident underscores the importance of implementing robust authentication mechanisms in communication protocols, especially in critical systems like unmanned aerial vehicles. Organizations utilizing PX4 Autopilot are urged to enable MAVLink 2.0 message signing to mitigate this risk and prevent potential exploitation.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Vulnerabilities in WAGO Industrial Managed Switches Expose Systems to Remote Attacks
Impact· CRITICAL

Critical Vulnerabilities in WAGO Industrial Managed Switches Expose Systems to Remote Attacks

In early 2026, multiple critical vulnerabilities were discovered in WAGO GmbH & Co. KG's Industrial Managed Switches, notably models 852-1322 and 852-1328. These flaws, including stack buffer overflows and authentication bypasses, allowed unauthenticated remote attackers to execute arbitrary code, potentially leading to full system compromise. The vulnerabilities stemmed from unsafe input handling in the devices' web-based management interfaces, which utilized modified lighttpd servers and custom CGI binaries. Exploitation could result in denial-of-service conditions and unauthorized access to sensitive configurations. ([certvde.com](https://certvde.com/en/advisories/VDE-2026-004/?utm_source=openai)) This incident underscores the persistent risks associated with industrial control systems (ICS) and the critical need for robust security measures. The vulnerabilities highlight the importance of regular firmware updates, secure coding practices, and comprehensive network segmentation to protect against unauthorized access and potential operational disruptions.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Mazda's 2025 Data Breach: A Wake-Up Call for Supply Chain Security
Impact· LOW

Mazda's 2025 Data Breach: A Wake-Up Call for Supply Chain Security

In December 2025, Mazda Motor Corporation identified unauthorized access to a warehouse management system associated with parts procured from Thailand. The breach exposed 692 records containing user IDs, full names, email addresses, company names, and business partner IDs. No customer data was involved. Mazda promptly reported the incident to Japan's Personal Information Protection Commission and implemented enhanced security measures, including reducing internet exposure, applying security patches, increasing monitoring for suspicious activity, and introducing stricter access policies. This incident underscores the persistent threat of cyberattacks targeting supply chain systems. Organizations must remain vigilant, as such breaches can lead to phishing attacks and scams targeting exposed individuals. Implementing robust security protocols and continuous monitoring is essential to mitigate these risks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Exposing the Vulnerabilities in Facial Recognition Systems: A 2026 Analysis
Impact· CRITICAL

Exposing the Vulnerabilities in Facial Recognition Systems: A 2026 Analysis

In March 2026, cybersecurity expert Jake Moore demonstrated multiple methods to bypass facial recognition systems, highlighting significant vulnerabilities in this widely adopted technology. Utilizing modified smart glasses, Moore identified individuals in public spaces by matching their faces to online data sources in real-time. He also successfully opened a bank account using an AI-generated image, which was accepted by the bank's facial recognition and eKYC platform. Additionally, by employing real-time face swap software, Moore evaded detection by a facial recognition watchlist at a London train station. These experiments underscore the ease with which facial recognition systems can be deceived using readily available tools and techniques. The increasing reliance on facial recognition for security and authentication purposes necessitates a critical evaluation of its robustness. Moore's findings serve as a wake-up call for organizations to reassess the effectiveness of their biometric security measures and to consider implementing additional safeguards to mitigate potential exploitation.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports