Pwn2Own Automotive Day 1: A 3-Bug Chain Against a Tesla, a Remote Attack Demo, and Other Highlights
January 24, 2024US$722,500 in prizes was awarded for 24 unique exploits during the first day alone of the inaugural edition of Pwn2Own Automotive, the world’s first and only event focusing on vulnerabilities in technologies for connected cars.
VicOneAdvancing Vulnerability Discovery Amid Automotive Innovation: An API Attack From Halfway Across the World
January 22, 2024We examine the impact of vulnerabilities and the security implications of advancing technologies on vehicles in VicOne’s walkthrough of an API attack scenario.
CyberThreat Research LabAdvancing Vulnerability Discovery Amid Automotive Innovation: A Tale of Two EV Charger Vulnerabilities
January 19, 2024We delve into two scenarios that highlight the significance of vulnerability discovery as we detail the work of researchers from Zero Day Initiative, who have identified and examined two distinct flaws in the realm of electric vehicle (EV) chargers.
VicOneWhy Today’s VSOC Platforms Fall Short in Providing Sufficient Protection
January 19, 2024As the automotive cybersecurity landscape expands beyond the confines of the cloud to include in-vehicle components and infrastructure, reliance solely on today’s cloud-based VSOC platforms might prove inadequate for ensuring robust protection. In this article, we dive into a real-world scenario to shed light on why it’s time to rethink VSOC platforms.
VicOneCactus Ransomware Group Claims Responsibility for Cyberattack on CIE Automotive
January 12, 2024A recent ransomware attack on an automotive supplier is a stark reminder of the frequent and varied cyberthreats that industries face, especially those utilizing internet technologies. In this article, we explore typical scenarios in industries reliant on internet technologies and highlight the unique vulnerabilities and challenges that the automotive industry faces amid the rising tide of cyberattacks.
VicOneFrom Information Leakage to Command Injection: Common Vulnerabilities in the Automotive Industry
December 22, 2023We highlight common vulnerabilities affecting modern connected vehicles, including those involving denial of service, hard-coded credentials, and stack overflow.
CyberThreat Research LabDriving Into the Future: VicOne Automotive Cybersecurity Predictions and Recommendations for 2024
December 15, 2023We recently explored the current state of automotive cybersecurity in the VicOne Automotive Cyberthreat Landscape Report 2023. In this blog entry, we present the automotive cybersecurity predictions and recommendations that decisions-makers in the automotive industry should be cognizant of in 2024.
CyberThreat Research LabSafeguarding Tomorrow’s Mobility: The Imperative of Cybersecurity in the Automotive Industry
December 7, 2023In the fast-paced evolution of the automotive industry, technological innovation has become synonymous with progress. However, this era of transformation also demands an unwavering commitment to robust cybersecurity measures.
CyberThreat Research LabBeating Zero-Day Vulnerabilities at a Game: Pwn2Own Automotive
December 6, 2023Pwn2Own Automotive specifically focuses on the increasing cyberthreats to connected cars worldwide, addressing a critical area of modern automotive security. It is the first global competition dedicated to discovering and solving connected car technology vulnerabilities.
CyberThreat Research LabThe Cybersecurity Terrain of 2023: A Review of the Automotive Threat Landscape
December 5, 2023In our annual automotive cybersecurity report, we review the past year to see how far the industry has come in its compliance journey, what challenges it has been facing, and where it can expect to find itself amid the threat landscape ahead.
VicOneBig Brother Is in Your Passenger Seat: The Privacy Risks of Modern Connected Cars
November 15, 2023How much does your car know about you? Our study highlights the need to look into how we can protect the large amount of data that cars now produce and use — before threats to privacy and security become serious problems.
VicOneTesla Jailbreak Unlocks Features via Firmware Patching and Voltage Glitching
September 12, 2023Researchers from the Technical University of Berlin recently unveiled a hardware-based attack designed to jailbreak Tesla’s AMD-based in-vehicle infotainment (IVI) system. In this blog entry, we delve into the methodology of the attack and explore its implications for automotive cybersecurity.
CyberThreat Research Lab