Shifting Gears for 2025: The Next Generation of Automotive Cybersecurity Challenges
March 19, 2025As AI, EVs, and SDVs reshape the automotive industry, cyberthreats are evolving in tandem. Drawing from VicOne’s 2025 automotive cybersecurity report, this article offers key insights into the industry’s threat landscape and outlines the strategies automakers need to stay ahead.
CyberThreat Research LabHow Subaru’s IVI System Admin Panel Vulnerability Could Have Enabled Vehicle Tracking and Control
March 13, 2025Security researchers uncovered a vulnerability in Subaru’s in-vehicle infotainment (IVI) system admin panel, enabling unauthorized access to personal information, GPS records, and vehicle controls. We examine the findings and emphasize the need for automotive manufacturers to adopt a security-first approach throughout the vehicle lifecycle.
CyberThreat Research LabSpate of Ransomware Attacks Targets Automotive Industry in Early 2025
February 26, 2025In the first several weeks of 2025 alone, a surge of ransomware attacks hit the automotive industry. We examine recent cases and their broader implications for automotive cybersecurity.
CyberThreat Research LabFrom Pwn2Own Automotive: 2 RCE Vulnerabilities in the Phoenix Contact CHARX SEC-3100 EV Charging Controller
February 7, 2025We discuss the two vulnerabilities discovered in the Phoenix Contact CHARX SEC-3100 EV charging controller at Pwn2Own Automotive 2024, highlighting their impact and possible mitigations.
CyberThreat Research LabPlaying Doom on an IVI System: More Alpine Halo9 Vulnerabilities From Pwn2Own Automotive 2024
January 14, 2025We examine the NCC Group’s two-bug chain during Pwn2Own Automotive 2024, which enabled the team to play Doom on the Alpine Halo9 iLX-F509 IVI system. We underscore the more serious implications once attackers gain root access and recommend countermeasures to mitigate the risks.
CyberThreat Research LabUnder Pressure: Exploring a Zero-Click RCE Vulnerability in Tesla’s TPMS
December 18, 2024We examine a zero-click remote code execution (RCE) vulnerability in Tesla’s tire pressure monitoring system (TPMS), uncovered by Synacktiv researchers at Pwn2Own Vancouver 2024, and highlight its implications for connected vehicle security.
CyberThreat Research LabFrom Pwn2Own Automotive: A High-Severity Zero-Click RCE Bluetooth Vulnerability in the Alpine Halo9 IVI System
December 12, 2024The Pwn2Own Automotive 2024 competition uncovered a high-severity zero-click RCE Bluetooth vulnerability in the Alpine Halo9 IVI system, highlighting the risks of proprietary implementations in connected vehicles. We explore the discovery, exploitation techniques, and key takeaways for securing automotive technologies against emerging threats.
CyberThreat Research LabGenAI Takes the Wheel: Can Automotive Cybersecurity Keep Up?
November 25, 2024Qualcomm has taken a significant step toward bringing GenAI to vehicles by integrating its next-generation Oryon processor into in-car systems. We explore the technology powering GenAI, highlighting what makes it so transformative — and the security challenges it introduces.
CyberThreat Research LabSecurity Mitigations for the Multiple Zero-Day Vulnerabilities Discovered in an IVI System
November 18, 2024The ZDI has identified six zero-day vulnerabilities in an in-vehicle infotainment (IVI) system. As these vulnerabilities remain unpatched, we recommend security best practices to minimize their potential risks and fortify connected vehicles’ IVI systems.
CyberThreat Research LabExploiting the Emporia EV Charger: A Hacker’s Point of View
November 13, 2024Exposed serial interfaces in electric vehicle (EV) chargers present a significant vulnerability, enabling attackers to tamper with hardware and firmware. This creates opportunities for malicious activities, highlighting the need for strong security measures to prevent such exploits.
CyberThreat Research LabBreaking Into Tesla’s IVI System: Synacktiv’s Two-Bug Exploit Chain at Pwn2Own Automotive 2024
November 4, 2024We take a look at Synacktiv’s two-bug chain that successfully exploited Tesla’s in-vehicle infotainment (IVI) system at Pwn2Own Automotive 2024, highlighting security takeaways for enhancing automotive cybersecurity.
CyberThreat Research LabFrom Pwn2Own Automotive: More Stack-Based Buffer Overflow Vulnerabilities in Autel MaxiCharger
October 14, 2024We examine two more Autel MaxiCharger vulnerabilities discovered at Pwn2Own Automotive 2024: CVE-2024-23967 and CVE-2024-23957. Both are classified as a stack-based buffer overflow, a classic yet avoidable programming error that could lead to remote code execution.
CyberThreat Research Lab