從遊戲中攻克零日漏洞:Pwn2Own Automotive汽車資安漏洞競賽

VicOne 網路威脅研究實驗室VicOne 網路威脅研究實驗室

Pwn2Own Automotive 特別關注全球連網汽車安全,並希望解決真實世界日益增長的汽車資安威脅網路威脅。這是全球第一個致力發掘及解決連網汽車技術漏洞的比賽。

Pwn2Own Automotive
從遊戲中攻克零日漏洞:Pwn2Own Automotive汽車資安漏洞競賽

As we announced in October, VicOne will be holding the first-ever Pwn2Own Automotive during Automotive World at Tokyo Big Sight in Japan from January 24 to 26, 2024. The event is organized by the Zero Day Initiative (ZDI), a vulnerability discovery community operated by Trend Micro, with VicOne playing a central role.

Pwn2Own is a competition that challenges participants to find hidden, hard-to-detect vulnerabilities, effectively turning potential future threats into a game. The goal is to identify and address these vulnerabilities before they are exploited by harmful entities. This event has pioneered the vulnerability market by buying vulnerability research legally, thereby disrupting the underground market. This approach helps remove vulnerabilities from potential abusers, allowing vendors to rectify them before they become public knowledge.

Pwn2Own Automotive specifically focuses on the increasing cyberthreats to connected cars worldwide, addressing a critical area of modern automotive security. It is the first global competition dedicated to discovering and solving connected car technology vulnerabilities.

Tesla, the world’s most valuable car company, is partnering with us as the title sponsor of this event, which offers participants more than US$1 million in cash and prizes; Tesla has worked with us extensively for our Pwn2Own Vancouver event. ChargePoint is also partnering with us and will be providing their EV chargers to be used during the contest. VicOne researchers, in particular, have been essential in helping determine targets and providing technical guidance on EV attack surfaces.

For more information and updates on Pwn2Own Automotive, visit https://vicone.com/pwn2own-automotive.

About the Author

VicOne 網路威脅研究實驗室
VicOne 網路威脅研究實驗室

VicOne 資安威脅研究實驗室(CyberThreat Research Lab)致力於探索聯網車輛、軟體定義車輛(SDV)、電動車充電基礎設施(EV Charging Infrastructure)及 Physical AI 系統所面臨的新興威脅與風險。研究範疇涵蓋零日漏洞(Zero-Day Vulnerability)發掘、深網與暗網威脅情資分析、Auto-ISAC Automotive Threat Matrix(ATM)威脅模型對應,以及 AI 安全風險分析等領域。實驗室研究成果曾於 RSAC、ESCAR USA、ELIV 等國際產業論壇發表,並獲 Auto-ISAC 等國際組織引用與參考。透過持續的威脅研究與情資分析,VicOne 資安威脅研究實驗室協助汽車製造商(OEM)、供應商、產品安全事件應變團隊(PSIRT)及車聯網安全決策者,將技術洞察轉化為可執行的防禦策略與風險管理措施,提升整體資安韌性。