Blog

Is the Automotive Industry Prepared to Navigate API Security Risks in Software-Defined Vehicles?

Is the Automotive Industry Prepared to Navigate API Security Risks in Software-Defined Vehicles?

The proliferation of APIs in software-defined vehicles (SDVs) has significantly expanded the attack surface, posing serious security risks to the entire automotive ecosystem. In this article, we provide insights into the evolving threat landscape of automotive APIs, tackling vulnerabilities associated with SDVs and recommending a systematic approach for effectively mitigating the risks.

Strengthening Resilience in Today’s Interconnected Age: VicOne’s Approach

Strengthening Resilience in Today’s Interconnected Age: VicOne’s Approach

A large-scale outage resulting from a single content update recently affected computers across multiple industries, including financial institutions, hospitals, and airlines. This incident highlights the challenges faced by organizations and the crucial need for enhanced system resilience in our increasingly interconnected world.

Securing the Automotive Supply Chain: Lessons From the Ransomware Attack on a Car Dealership Software Provider

Securing the Automotive Supply Chain: Lessons From the Ransomware Attack on a Car Dealership Software Provider

A software provider for automotive dealerships recently fell victim to a ransomware attack, causing widespread outages and crippling operations for thousands of car dealers. We examine the far-reaching implications of this incident on the automotive supply chain, outline critical lessons learned, and provide strategic security recommendations for automotive stakeholders.

From Key Fob to UWB: Explaining and Securing Ultra-Wideband in Vehicles

From Key Fob to UWB: Explaining and Securing Ultra-Wideband in Vehicles

In this second part of our series on vehicle entry system technology, we focus on its most recent iteration, the ultra-wideband (UWB) protocol. We cover its advantages, the potential vulnerabilities it carries, and the measures that will help secure its integration into vehicles.

Harnessing Python and ChatGPT for Automotive Security Research

Harnessing Python and ChatGPT for Automotive Security Research

A VicOne researcher demonstrates how automotive security researchers can take advantage of Python and ChatGPT, especially in scripting proofs of concept of known attacks and exploring novel vulnerabilities in automotive systems.

Understanding the Impact of NIST IR 8473 on EV Charging Infrastructure Security

Understanding the Impact of NIST IR 8473 on EV Charging Infrastructure Security

The NIST IR 8473 cybersecurity framework profile marks a shift in scope from individual chargers to the entire charging infrastructure. This expanded scope suggests that electric vehicle supply equipment manufacturers and charge point operators need to consider cybersecurity from an industry-level risk-based approach rather than focusing solely on individual IoT devices.