Breaking Down the Pioneer IVI System 3-Bug Exploit Chain From Pwn2Own Automotive 2024
March 31, 2025We analyze the three-bug exploit chain demonstrated by security researchers against the Pioneer DMH-WT7600NEX IVI system at Pwn2Own Automotive 2024. We map it to the Automotive Threat Matrix and highlight industry best practices for mitigating similar exploits.
CyberThreat Research LabFrom Compliance to Continuity: Why Cybersecurity Is a Cornerstone of EV Fleet Asset Utilization
March 25, 2025As EV fleets become more connected, cybersecurity is playing an increasingly critical role in ensuring long-term performance, compliance, and asset utilization. We explore the most pressing cyber risks facing modern fleets and present actionable strategies to help organizations keep their vehicles secure, operational, and productive.
VicOneShifting Gears for 2025: The Next Generation of Automotive Cybersecurity Challenges
March 19, 2025As AI, EVs, and SDVs reshape the automotive industry, cyberthreats are evolving in tandem. Drawing from VicOne’s 2025 automotive cybersecurity report, this article offers key insights into the industry’s threat landscape and outlines the strategies automakers need to stay ahead.
CyberThreat Research LabHow Subaru’s IVI System Admin Panel Vulnerability Could Have Enabled Vehicle Tracking and Control
March 13, 2025Security researchers uncovered a vulnerability in Subaru’s in-vehicle infotainment (IVI) system admin panel, enabling unauthorized access to personal information, GPS records, and vehicle controls. We examine the findings and emphasize the need for automotive manufacturers to adopt a security-first approach throughout the vehicle lifecycle.
CyberThreat Research LabStop Wasting Hours on Manual Attack Path Identification — Let Automation Do the Heavy Lifting
March 10, 2025Effective attack path identification enables automotive manufacturers and suppliers to stay ahead in an increasingly complex threat landscape. Learn how VicOne xZETA combines AI and curated automotive threat intelligence to streamline product security risk assessment, minimize manual efforts, and deliver actionable insights.
VicOneSpate of Ransomware Attacks Targets Automotive Industry in Early 2025
February 26, 2025In the first several weeks of 2025 alone, a surge of ransomware attacks hit the automotive industry. We examine recent cases and their broader implications for automotive cybersecurity.
CyberThreat Research LabAI Smart Cockpits: The Future of Driving, the Reality of Cyberthreats
February 10, 2025AI smart cockpits are transforming the driving experience, but their reliance on AI also opens new attack surfaces. We explore how risks like data leaks and prompt injection threaten vehicle security — and what’s needed to defend against them.
Peter YangFrom Pwn2Own Automotive: 2 RCE Vulnerabilities in the Phoenix Contact CHARX SEC-3100 EV Charging Controller
February 7, 2025We discuss the two vulnerabilities discovered in the Phoenix Contact CHARX SEC-3100 EV charging controller at Pwn2Own Automotive 2024, highlighting their impact and possible mitigations.
CyberThreat Research LabDriving Intelligence: How Edge AI Is Transforming Vehicle Threat Detection
January 28, 2025As the automotive industry accelerates toward AI-driven, software-defined vehicles, the need for smarter, more efficient cybersecurity has never been greater. VicOne’s innovative xCarbon Edge AI transforms vehicles into proactive defenders, reducing costs, enhancing efficiency, and safeguarding drivers from emerging cyberthreats.
VicOnePwn2Own Automotive 2025: New Master of Pwn Crowned and Other Day Three Highlights
January 24, 2025The final day of Pwn2Own Automotive 2025 saw eight unique zero-day vulnerabilities, bringing the total haul for the three-day event to 49. Finishing with 30.5 “Pwn points,” Sina Kheirkhah was crowned this year’s Master of Pwn.
VicOnePwn2Own Automotive 2025: Tesla EV Charger Exploits Take the Spotlight on Day Two
January 23, 2025Day two of Pwn2Own Automotive 2025 was a “Tesla EV charger kind of day,” with four Tesla Wall Connectors targeted. The day closed with an impressive haul of 23 unique zero-day vulnerabilities, surpassing the 16 uncovered on day one.
VicOnePwn2Own Automotive 2025: Day One Uncovers 16 Unique Zero-Day Vulnerabilities
January 22, 2025A total of 16 unique zero-day vulnerabilities were discovered on day one of Pwn2Own Automotive 2025, the world’s largest zero-day vulnerability discovery contest focused on connected cars and software-defined vehicles.
VicOne