From Key Fob to UWB: How Hackers Hijack Vehicle Entry Systems
June 7, 2024In this first installment, we examine the history of automotive entry technology and explore notable types of security breaches such as replay attacks, rolling attacks, and relay attacks.
CyberThreat Research LabHow Malicious Apps in Connected Vehicles Could Lead to Heightened Risks
May 28, 2024Apps play a significant role in enhancing the functionality and driving the evolution of software-defined vehicles (SDVs). However, their integration also introduces new risks, as we explore in this blog entry.
CyberThreat Research LabWhy the Rust Programming Language Is Not a Silver Bullet for Automotive Security
May 17, 2024Rust, a memory-safe programming language, is gaining traction as it is designed to address memory-related vulnerabilities. We discuss its potential impact on automotive cybersecurity.
CyberThreat Research LabHarnessing Python and ChatGPT for Automotive Security Research
May 6, 2024A VicOne researcher demonstrates how automotive security researchers can take advantage of Python and ChatGPT, especially in scripting proofs of concept of known attacks and exploring novel vulnerabilities in automotive systems.
CyberThreat Research LabOpen RAN: A Gateway to Improved V2X Communications and to New Security Risks
April 12, 2024Open RAN is said to usher advances in V2X communications for connected vehicles. Researchers have taken a closer look at this technology to see where vulnerabilities might slip through amid its anticipated advantages.
CyberThreat Research LabEmerging Threats to the Automotive Supply Chain From Ransomware Groups
February 22, 2024More automotive manufacturers and suppliers have fallen prey to ransomware groups in January 2024, further highlighting the need for more robust automotive cybersecurity amid a rapidly evolving threat landscape.
CyberThreat Research LabExtending the Lessons From Pwn2Own Automotive
February 15, 2024With the close of the first-ever Pwn2Own Automotive, the challenge now is to make the most out of the discoveries and insights from the event. We summarize here our own impressions of the event, homing in on emergent security gaps and industry trends.
CyberThreat Research LabHow to Avoid Source Code Breaches: Lessons From the Mercedes-Benz GitHub Token Leak
February 7, 2024Researchers discovered a GitHub token leaked by a Mercedes-Benz employee, potentially exposing the automaker’s internal coding infrastructure, intellectual property, and other sensitive data. This breach stemmed from a sequence of avoidable errors, highlighting the importance of robust security measures in safeguarding digital assets.
CyberThreat Research LabAdvancing Vulnerability Discovery Amid Automotive Innovation: An API Attack From Halfway Across the World
January 22, 2024We examine the impact of vulnerabilities and the security implications of advancing technologies on vehicles in VicOne’s walkthrough of an API attack scenario.
CyberThreat Research LabFrom Information Leakage to Command Injection: Common Vulnerabilities in the Automotive Industry
December 22, 2023We highlight common vulnerabilities affecting modern connected vehicles, including those involving denial of service, hard-coded credentials, and stack overflow.
CyberThreat Research LabDriving Into the Future: VicOne Automotive Cybersecurity Predictions and Recommendations for 2024
December 15, 2023We recently explored the current state of automotive cybersecurity in the VicOne Automotive Cyberthreat Landscape Report 2023. In this blog entry, we present the automotive cybersecurity predictions and recommendations that decisions-makers in the automotive industry should be cognizant of in 2024.
CyberThreat Research LabSafeguarding Tomorrow’s Mobility: The Imperative of Cybersecurity in the Automotive Industry
December 7, 2023In the fast-paced evolution of the automotive industry, technological innovation has become synonymous with progress. However, this era of transformation also demands an unwavering commitment to robust cybersecurity measures.
CyberThreat Research Lab