The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Transportation
Breach intelligence, attack campaigns, and threat reports targeting the Transportation sector.
Explore Other Sectors
Transportation Threat Reports
Automotive Cybersecurity Alert: First Android Head Unit Malware Targets Connected Vehicles
In June 2026, Kaspersky researchers discovered the first documented case of Android malware specifically targeting automotive head units. The MoYu Group, linked to the BADBOX botnet, exploited legitimate update mechanisms in DoFun head unit firmware to distribute multi-stage malware through the TWCore system application. The attack chain deployed a sophisticated dropper that ultimately created a proxy botnet for ad fraud operations. The malware spread through built-in firmware updaters without user knowledge, establishing command and control infrastructure to recruit infected vehicles into their botnet network. This incident represents a critical expansion of botnet operations into automotive systems, highlighting the growing threat surface as vehicles become increasingly connected. With automotive head units now proven vulnerable to the same malware techniques used against smartphones and IoT devices, the automotive industry faces new cybersecurity challenges requiring immediate attention.
1 month ago
Kill Chain
Johnson Controls Fire Safety System Exposes Credentials in Memory: CVE-2026-27875 Analysis
Johnson Controls Simplex Incident Manager versions 2.01 and earlier contain a critical vulnerability (CVE-2026-27875) that stores user credentials including passwords and authentication tokens in unencrypted form within system memory. This cleartext storage vulnerability allows local attackers with low privileges to extract sensitive authentication data using memory-dumping tools, potentially leading to unauthorized access to fire safety systems and connected critical infrastructure. The vulnerability affects fire safety management systems deployed worldwide across critical manufacturing, commercial facilities, government services, transportation systems, and energy sectors. Johnson Controls has released patched version 2.01.01 to address this security flaw and recommends immediate upgrades along with enhanced access controls and endpoint monitoring. This incident highlights the growing concern over insecure credential management in industrial control systems as threat actors increasingly target OT environments. With fire safety systems being critical infrastructure components, credential exposure vulnerabilities pose significant risks to facility security and emergency response capabilities.
1 month ago
Kill Chain
GeoServer Zero-Day SQL Injection Vulnerability Leads to RCE
In August 2026, a critical zero-day SQL injection vulnerability was discovered in GeoServer's 'jsonArrayContains' function, potentially leading to remote code execution (RCE). The flaw was publicly disclosed on August 12, 2026, by researcher @q1uf3ng, and active exploitation attempts were observed within hours. Attackers probed vulnerable systems, triggering errors without further action, but the risk of full exploitation remained high. GeoServer released patches on August 14, 2026, addressing the issue in versions 3.0.1, 2.28.5, and 2.27.6. Organizations were advised to update immediately to mitigate the risk. This incident underscores the persistent threat posed by SQL injection vulnerabilities in widely used open-source platforms. The rapid exploitation attempts highlight the need for prompt patching and vigilant monitoring of geospatial data servers to prevent potential RCE attacks.
1 month ago
Kill Chain
Critical Vulnerabilities in Siemens RUGGEDCOM APE1808 Devices with Fortinet FortiOS
In August 2026, Siemens disclosed multiple vulnerabilities in its RUGGEDCOM APE1808 devices, specifically those integrated with Fortinet's FortiOS. The identified vulnerabilities include CVE-2026-23573, an improper neutralization of input during web page generation (cross-site scripting), and CVE-2026-59839, an improper limitation of a pathname to a restricted directory (path traversal). These flaws could allow authenticated remote users to execute arbitrary code or commands and enable privileged authenticated attackers with physical access to delete the file system via crafted CLI commands. Siemens has released updates to address these issues and recommends users update to the latest versions to mitigate potential risks. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-975644.html?utm_source=openai)) This incident underscores the critical importance of timely software updates and vigilant monitoring of industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, organizations must prioritize the implementation of robust security measures and maintain awareness of emerging vulnerabilities to safeguard operational integrity.
1 month ago
Kill Chain
Critical Vulnerabilities in Siemens LOGO! Soft Comfort Software
In August 2026, Siemens disclosed multiple vulnerabilities in its LOGO! Soft Comfort software, specifically CVE-2026-57262 and CVE-2026-57263. These flaws involve the use of a hard-coded cryptographic key and unsalted password hashes, respectively. Exploitation could allow local attackers to decrypt project files or perform efficient offline attacks against password hashes, leading to unauthorized access or modification of sensitive project configurations. Siemens has released version 9 to address these issues and recommends users update promptly. This incident underscores the critical importance of robust cryptographic practices in industrial control systems. The vulnerabilities highlight the need for organizations to regularly review and update their security measures to protect against evolving threats, especially in software managing sensitive operational data.
1 month ago
Kill Chain
Critical Vulnerabilities in Johnson Controls' Airwall: CVE-2026-64887 and CVE-2026-34492
In August 2026, Johnson Controls Inc. disclosed two critical vulnerabilities in their Airwall product, identified as CVE-2026-64887 and CVE-2026-34492. CVE-2026-64887 involves the use of a hard-coded cryptographic key, potentially allowing attackers to decrypt sensitive data across all installations. CVE-2026-34492 is an arbitrary file read vulnerability, enabling unauthorized access to system files. Both vulnerabilities affect Airwall versions up to and including 4.0.4. Johnson Controls has released patches in version 4.1.0 to address these issues. The disclosure underscores the persistent risks associated with hard-coded credentials and inadequate input validation in critical infrastructure systems. Organizations are urged to apply the provided patches promptly and review their security practices to prevent similar vulnerabilities.
1 month ago
Kill Chain
Gunra Ransomware's 2026 Exploitation of Fortinet Vulnerabilities: A Wake-Up Call for Cybersecurity
In early 2026, the Gunra ransomware group, a Ransomware-as-a-Service (RaaS) operation, exploited known vulnerabilities in Fortinet products, notably CVE-2026-24858, to bypass multi-factor authentication (MFA) and gain unauthorized access to critical infrastructure and government organizations worldwide. Utilizing the leaked Conti ransomware code, Gunra executed double-extortion attacks, encrypting data and threatening to publish stolen information unless ransoms were paid. The group's operations expanded through a structured affiliate program, targeting sectors such as healthcare, finance, manufacturing, transportation, and government services. ([shellcodex.com](https://shellcodex.com/ransomware/group/gunra?utm_source=openai)) This incident underscores the persistent threat posed by ransomware groups leveraging known vulnerabilities and the importance of timely patching and robust security measures. The exploitation of Fortinet flaws highlights the need for organizations to prioritize vulnerability management and implement comprehensive security protocols to mitigate such risks. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-22572/?utm_source=openai))
1 month ago
Kill Chain
Head Mare Group Exploits TrueConf Vulnerabilities to Deploy Backdoors
In August 2026, the Head Mare hacktivist group exploited vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions containing backdoors. By leveraging flaws identified as KLCERT-26-057 and KLCERT-26-058, attackers achieved remote code execution, escalated privileges to NT AUTHORITY\SYSTEM, and deployed web shells for persistent access. This allowed them to collect sensitive information, access databases, and distribute trojanized client installers embedded with the PhantomCore backdoor. Users downloading these installers inadvertently installed malware, granting attackers further access to organizational networks. This incident underscores the critical importance of timely patch management and the risks associated with supply chain attacks. Organizations must ensure that all software, especially communication tools like TrueConf, are regularly updated to mitigate vulnerabilities. The rise of such sophisticated attacks highlights the need for comprehensive security strategies that encompass both technical defenses and user awareness training.
1 month ago
Kill Chain
Citrix NetScaler CVE-2025-7775: Critical Vulnerability Exploited in the Wild
On August 26, 2025, Citrix disclosed a critical vulnerability (CVE-2025-7775) in NetScaler ADC and NetScaler Gateway products, which was actively exploited in the wild. This memory overflow flaw allows unauthenticated remote code execution and denial of service attacks on unpatched devices. The vulnerability affects versions 14.1 before 14.1-47.48, 13.1 before 13.1-59.22, 13.1-FIPS/NDcPP before 13.1-37.241-FIPS/NDcPP, and 12.1-FIPS/NDcPP up to 12.1-55.330-FIPS/NDcPP. Citrix released security updates to address this issue and urged immediate patching due to the lack of available mitigations. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/citrix-fixes-critical-netscaler-rce-flaw-exploited-in-zero-day-attacks/amp/?utm_source=openai)) The active exploitation of CVE-2025-7775 underscores the persistent targeting of critical infrastructure by threat actors. Organizations relying on NetScaler products must prioritize patching to mitigate potential risks. This incident highlights the importance of timely vulnerability management and the need for robust security practices to defend against evolving cyber threats.
1 month ago
Kill Chain
Cyberattack Disrupts North Carolina Ports Operations in August 2026
In early August 2026, the North Carolina Ports Authority experienced a cyberattack that disrupted IT systems across the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. The incident, detected on August 4, led to a system-wide outage, causing operational delays and affecting cargo handling. The authority activated its cybersecurity contingency plan, initiating recovery efforts on August 5. While operations began returning to normal by August 7, residual delays persisted as system restoration continued. The specific nature of the attack, the threat actor involved, and whether sensitive data was compromised remain undisclosed. This incident underscores the escalating cyber threats targeting critical infrastructure, particularly in the maritime sector. Ports are increasingly becoming focal points for cyberattacks, highlighting the need for robust cybersecurity measures and contingency planning to mitigate operational disruptions and safeguard sensitive data.
1 month ago
Kill Chain
Critical Vulnerability in Johnson Controls TL280 Devices: CVE-2026-27871
In August 2026, a critical vulnerability (CVE-2026-27871) was identified in Johnson Controls' TL280 devices, affecting versions prior to 5.63. This flaw involves the use of a broken or risky cryptographic algorithm, potentially allowing unauthorized access to sensitive information. The vulnerability impacts sectors such as Critical Manufacturing, Commercial Facilities, Government Services, Transportation Systems, and Energy, with deployments worldwide. Johnson Controls has released firmware update 5.63 to address this issue and recommends restricting network access to trusted management VLANs, monitoring device access logs, rotating shared credentials, implementing network segmentation, and using secure remote access methods like VPNs. ([johnsoncontrols.com](https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories?utm_source=openai)) The discovery of CVE-2026-27871 underscores the ongoing challenges in securing industrial control systems against evolving cyber threats. Organizations are urged to promptly apply the recommended mitigations and stay vigilant against potential exploitation attempts targeting this vulnerability.
1 month ago
Kill Chain
Cyberattack Disrupts Operations at North Carolina Ports in 2026
In early August 2026, a cyberattack targeted the North Carolina State Ports Authority, disrupting gate operations at the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port. The breach led to delays in gate openings and necessitated a shift to manual processing as the authority worked to contain the intrusion. The U.S. Coast Guard, along with other state and federal agencies, is actively investigating the incident to determine the nature and extent of the attack. This incident underscores the escalating cyber threats facing critical infrastructure sectors, including maritime transportation. The attack on North Carolina's ports highlights the urgent need for enhanced cybersecurity measures and collaboration among federal and state agencies to protect essential services from sophisticated cyber adversaries.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports