Blog

How a Credential Phishing Attack Could Lead to Tesla Car Theft and How to Mitigate It

How a Credential Phishing Attack Could Lead to Tesla Car Theft and How to Mitigate It

The automotive industry has entered an era when cyberattacks and social engineering tactics can have direct consequences on connected vehicles. Researchers have demonstrated another such scenario, involving a man-in-the-middle (MITM) credential phishing attack on a Tesla car. We share our security insights and solution recommendations.

Extending the Lessons From Pwn2Own Automotive

Extending the Lessons From Pwn2Own Automotive

With the close of the first-ever Pwn2Own Automotive, the challenge now is to make the most out of the discoveries and insights from the event. We summarize here our own impressions of the event, homing in on emergent security gaps and industry trends.

How to Avoid Source Code Breaches: Lessons From the Mercedes-Benz GitHub Token Leak

How to Avoid Source Code Breaches: Lessons From the Mercedes-Benz GitHub Token Leak

Researchers discovered a GitHub token leaked by a Mercedes-Benz employee, potentially exposing the automaker’s internal coding infrastructure, intellectual property, and other sensitive data. This breach stemmed from a sequence of avoidable errors, highlighting the importance of robust security measures in safeguarding digital assets.