PCA Cyber Security

57 stats2 reports

All Statistics

ShinyHunters vishing attack against an online automotive marketplace help desk exfiltrated 12.4 million user records (6.1 GB) in mid-February 2026

Automotive CybersecurityShinyHuntersVishingHelp Desk

Quarkslab bypassed the 16-byte RH850 debug password protection using voltage fault injection

Automotive CybersecurityHardwareFault InjectionRenesas

China's amended Cybersecurity Law took effect on 1 January 2026 (passed 28 October 2025) with raised penalties and extraterritorial reach

Automotive CybersecurityRegulationChina

BEAST threat actor leaked 700 GB of internal data from a large Chinese automotive group in late February 2026

Automotive CybersecurityData BreachChina

3.7 million of the 12.4 million records exposed in the ShinyHunters automotive marketplace breach were previously unseen in other breaches

Automotive CybersecurityShinyHuntersData Breach

DefenseWeaver multi-agent LLM identified 11 critical attack paths across four automotive projects in TARA testing

Automotive CybersecurityAI/LLMTARANDSS 2026

Ethernet represented over 25% of all automotive attack vector entries in Q1 2026

Automotive CybersecurityEthernetAttack Vectors

Incransom ransomware group published a 200 GB leak from a Tier-1 electronics component supplier in January 2026

Automotive CybersecurityIncransomTier-1 Supplier

88% of Q1 2026 automotive vulnerabilities require Low Attack Complexity

Automotive CybersecurityAttack Complexity

Pwn2Own Automotive 2026 in Tokyo produced 76 unique zero-days and $1.047 million in payouts

Automotive CybersecurityPwn2OwnZero-DaysEV Chargers

160 Medium, 75 High, and 16 Critical automotive vulnerabilities identified in Q1 2026

Automotive CybersecurityCVSSSeverity

Synacktiv chained an information leak with an out-of-bounds write to achieve a full win against Tesla infotainment via USB at Pwn2Own Automotive 2026

Automotive CybersecurityTeslaPwn2OwnUSB

An automotive parts marketplace database with over 7.7 million records was exposed via a misconfigured Elasticsearch instance in January 2026

Automotive CybersecurityAftermarketMisconfiguration

US SELF DRIVE Act of 2026 requires the Secretary of Commerce to brief Congress on connected vehicle supply chain security within 180 days

Automotive CybersecurityRegulationSELF DRIVE Act

2024 SafePay ransomware breach at a global BPO provider exposed nearly 17,000 employees and customers of a major commercial vehicle manufacturer, disclosed in January 2026 after a 14-month notification delay

Automotive CybersecurityBPOSafePayHR/Payroll

Kenwood DNR1007XR aftermarket head unit exposes a Linux login prompt over UART at 115200 bps via a hidden board-edge connector

Automotive CybersecurityInfotainmentKenwood

265 unique automotive-specific vulnerabilities identified in Q1 2026

Automotive CybersecurityCVEsQ1 2026

28% increase in automotive vulnerabilities in Q1 2026 compared to Q4 2025

Automotive CybersecurityCVEsQuarter-on-Quarter

In-vehicle and Backend systems accounted for more than 81% of Q1 2026 automotive vulnerability targets

Automotive CybersecurityIn-VehicleBackend

PCA identified 14 unique methods of entry in the Q1 2026 automotive threat landscape

Automotive CybersecurityAttack Vectors

Pwn2Own Automotive 2026 had a record 73 entries

Automotive CybersecurityPwn2Own

Quarkslab's audit of EVerest open-source EV charging stack found 6 high-severity, 6 medium-severity, 5 low-severity and 3 informational issues

Automotive CybersecurityEV ChargingEVerestQuarkslab

Ransomware group exfiltrated nearly 1 TB of data from a major Asian vehicle manufacturer's customer and dealership environment in early January 2026 via a third-party vendor

Automotive CybersecurityRansomwareThird-Party Vendor

Delta Alarm cyberattack disabled mobile-app vehicle controls for hundreds of thousands of Russian vehicle owners for up to two weeks in late January 2026

Automotive CybersecurityTelematicsCloud HijackCyber-Physical

Delta Alarm took approximately five days to restore partial functionality and nearly two weeks to fully recover from the cloud control plane attack

Automotive CybersecurityTelematicsIncident Response

US Commerce Department rule prohibits Chinese and Russian connected-vehicle software starting Model Year 2027

Automotive CybersecurityRegulationUS CommerceConnected Vehicles

US connected vehicle hardware restrictions arrive for Model Year 2030 or January 1, 2029 for non-model-year components

Automotive CybersecurityRegulationHardware

US connected vehicle rule covers vehicles under 10,001 pounds

Automotive CybersecurityRegulationConnected Vehicles

Q1 2026 automotive vulnerabilities map to 25 distinct TTPs in the Auto-ISAC Automotive Threat Matrix

Automotive CybersecurityTTPsAuto-ISAC ATM

77 distinct CWEs mapped in Q1 2026, up from 64 in Q4 2025

Automotive CybersecurityCWEs

102% year-on-year increase in automotive vulnerabilities (Q1 2026 vs Q1 2025)

Automotive CybersecurityCVEsYear-on-Year

Q1 2026 automotive vulnerabilities span 77 unique CWEs

Automotive CybersecurityCWEsQ1 2026

Web and Local Shell combined for 33% of Q1 2026 automotive attack vectors

Automotive CybersecurityWebLocal ShellAttack Vectors

Ultra-Fast Wireless Charging hack drained 76% of EV power on the Alpitronic HYC50 commercial DC fast charger

Automotive CybersecurityEV ChargingAlpitronic

ChargePoint Home Flex flaw (ZDI-26-197) allows unauthenticated network-adjacent remote code execution as root via OCPP message handling

Automotive CybersecurityEV ChargingChargePointRCE

Q4 2025 automotive vulnerabilities mapped to 19 distinct TTPs in the Auto-ISAC Automotive Threat Matrix

Automotive CybersecurityTTPsAuto-ISAC ATM

Q4 2025 severity breakdown: 146 Medium, 54 High and 2 Critical automotive vulnerabilities

Automotive CybersecurityCVSSSeverity

Local Shell was the most frequent attack vector in Q4 2025, representing over 62% of total automotive entries

Automotive CybersecurityLocal ShellAttack Vectors

In-vehicle and Virtualization target types accounted for 95%+ of Q4 2025 automotive vulnerabilities

Automotive CybersecurityIn-VehicleVirtualization

14 different attack methods observed in Q4 2025 automotive vulnerabilities

Automotive CybersecurityAttack Vectors

DrainDead portable EV battery siphoning rig was built for approximately €1,200 using a solar inverter and CCS adapter

Automotive CybersecurityEV ChargingDrainDead

Ultra-Fast Wireless Charging attack synchronises with the charger's signal within only three cycles, defeating frequency hopping countermeasures

Automotive CybersecurityEV ChargingWireless

Most EVs in DrainDead testing allowed indefinite battery siphoning with repeated session resets; only some (e.g. Volkswagen group) halted discharging after around 60 seconds

Automotive CybersecurityEV ChargingDrainDead

Ethernet and Wi-Fi combined accounted for more than 18% of Q4 2025 automotive attack vectors

Automotive CybersecurityEthernetWi-FiAttack Vectors

Q4 2025 automotive vulnerabilities span 64 unique CWEs

Automotive CybersecurityCWEsQ4 2025

Ultra-Fast Wireless Charging hack drew 76%+ of the power intended for a legitimate EV from inductive chargers

Automotive CybersecurityEV ChargingWireless

206 unique automotive vulnerabilities identified in Q4 2025, a 19% increase over Q3 2025

Automotive CybersecurityCVEsQ4 2025

64 distinct CWEs mapped in Q4 2025, down from 82 in Q3 2025

Automotive CybersecurityCWEs

Over 100 advertised leaks and ransomware breaches targeted the automotive supply chain on the dark web in Q4 2025

Automotive CybersecurityDark WebRansomwareSupply Chain

UK SI 2025/1110 mandates UN R155 and R156 for type-approval effective 13 November 2025

Automotive CybersecurityRegulationUNECE R155UK