Pwn2Own Automotive 2025: Tesla EV Charger Exploits Take the Spotlight on Day Two
January 23, 2025Day two of Pwn2Own Automotive 2025 was a “Tesla EV charger kind of day,” with four Tesla Wall Connectors targeted. The day closed with an impressive haul of 23 unique zero-day vulnerabilities, surpassing the 16 uncovered on day one.
VicOnePwn2Own Automotive 2025: Day One Uncovers 16 Unique Zero-Day Vulnerabilities
January 22, 2025A total of 16 unique zero-day vulnerabilities were discovered on day one of Pwn2Own Automotive 2025, the world’s largest zero-day vulnerability discovery contest focused on connected cars and software-defined vehicles.
VicOnePlaying Doom on an IVI System: More Alpine Halo9 Vulnerabilities From Pwn2Own Automotive 2024
January 14, 2025We examine the NCC Group’s two-bug chain during Pwn2Own Automotive 2024, which enabled the team to play Doom on the Alpine Halo9 iLX-F509 IVI system. We underscore the more serious implications once attackers gain root access and recommend countermeasures to mitigate the risks.
CyberThreat Research LabSoftware-Defined Vehicles: Navigating Innovation and Cybersecurity Challenges
January 8, 2025SDVs are reshaping mobility, but innovation brings risks. Our 2024 cybersecurity analysis and review of the past decade reveal key challenges and industry responses to safeguard safety and trust.
VicOneUnder Pressure: Exploring a Zero-Click RCE Vulnerability in Tesla’s TPMS
December 18, 2024We examine a zero-click remote code execution (RCE) vulnerability in Tesla’s tire pressure monitoring system (TPMS), uncovered by Synacktiv researchers at Pwn2Own Vancouver 2024, and highlight its implications for connected vehicle security.
CyberThreat Research LabDriving Innovation in Automotive Cybersecurity: VicOne at CES 2025
December 13, 2024VicOne and our partners will showcase how we secure the evolving automotive ecosystem at CES 2025, the global stage for breakthrough technologies and innovations.
VicOneFrom Pwn2Own Automotive: A Critical Zero-Click RCE Bluetooth Vulnerability in the Alpine Halo9 IVI System
December 12, 2024The Pwn2Own Automotive 2024 competition uncovered a critical zero-click RCE Bluetooth vulnerability in the Alpine Halo9 IVI system, highlighting the risks of proprietary implementations in connected vehicles. We explore the discovery, exploitation techniques, and key takeaways for securing automotive technologies against emerging threats.
CyberThreat Research LabGenAI Takes the Wheel: Can Automotive Cybersecurity Keep Up?
November 25, 2024Qualcomm has taken a significant step toward bringing GenAI to vehicles by integrating its next-generation Oryon processor into in-car systems. We explore the technology powering GenAI, highlighting what makes it so transformative — and the security challenges it introduces.
CyberThreat Research LabSecurity Mitigations for the Multiple Zero-Day Vulnerabilities Discovered in an IVI System
November 18, 2024The ZDI has identified six zero-day vulnerabilities in an in-vehicle infotainment (IVI) system. As these vulnerabilities remain unpatched, we recommend security best practices to minimize their potential risks and fortify connected vehicles’ IVI systems.
CyberThreat Research LabExploiting the Emporia EV Charger: A Hacker’s Point of View
November 13, 2024Exposed serial interfaces in electric vehicle (EV) chargers present a significant vulnerability, enabling attackers to tamper with hardware and firmware. This creates opportunities for malicious activities, highlighting the need for strong security measures to prevent such exploits.
CyberThreat Research LabAI-Powered Defense and Beyond: Harnessing Intelligence to Uncover and Address Automotive Zero-Day Vulnerabilities
November 8, 2024Google’s Project Zero recently identified a zero-day vulnerability using an AI-assisted framework, marking a promising breakthrough in vulnerability detection. We examine the importance of AI technologies and other strategies in ensuring a more comprehensive approach to automotive cybersecurity.
VicOneWhy Container Security Matters in the Software-Defined Vehicle Landscape
November 8, 2024Software containers streamline the development of software-defined vehicles (SDVs), but they also bring new security risks. Addressing these risks is essential to ensure the integrity of SDV systems.
VicOne