#AutomotiveSecurity
⚠️ Carmaker portal flaw grants full control over vehicles & data

A major automaker’s dealer portal had an auth bypass (CVE‑2025‑7742), allowing creation of a “national admin” account. This granted stealth access to customer data, vehicle tracking, remote unlocking.

#ransomNews #AutomotiveSecurity
August 12, 2025 at 3:37 PM
March 11, 2026 at 7:56 PM
With the rise of #connectedvehicles, automotive security has become the focus. Key trends include
🚘 Increased regulation
🔗 Software Supply Chain Security & a focus on 3rd party vulns
🤖 Integration of AI to detect anomalies in real time

#AutomotiveSecurity #Trends
February 10, 2025 at 2:34 PM
Big updates for VehicleSec ’26 this August in Baltimore!

🎤 Keynotes by Stefan Savage (UC San Diego) and André Weimerskirch (Block Harbor).

🤝 New collaboration with ESCAR.

Check our details here: www.linkedin.com/posts/vehicl...

#VehicleSec #USENIX #ESCAR #Cybersecurity #AutomotiveSecurity
February 4, 2026 at 4:37 PM
Blockchain Driving Automotive Security & Smart Sharing in 2025
#Blockchain #AutomotiveSecurity #CarPotatosecurity #SmartMobility
www.b-aigpt.xyz/blockchain-a...
July 24, 2025 at 10:58 AM
To the #automotivesecurity #carhacking community, the deadline for the Automotive Cyber Security Workshop (ACSW) in conjunction with IEEE EuroS&P 2025 is a couple of weeks away. We're waiting for your awesome submissions!

acsw.unimore.it #cybersecurity #eurosp25
ACSW'25 - Workshop on Automotive Cyber Security
acsw.unimore.it
January 14, 2025 at 7:47 AM
Just one month left until the paper submission deadline on Tuesday, February 24, 2026, 23:59 AoE (Anywhere on Earth) time!

Check our up-to-date CFP here: www.usenix.org/conference/v...

#CyberSecurity#VehicleSec #USENIX#USENIXSecurity#AutomotiveSecurity #VehicleSecurity #CPSecurity #AISecurity
VehicleSec '26 Call for Papers
*/ Sponsored by USENIX, the Advanced Computing Systems Association. The 4th USENIX Symposium on Vehicle Security and Privacy (VehicleSec '26) will be held on August 10–11, 2026, in conjunction with th...
www.usenix.org
January 30, 2026 at 5:26 PM
India’s automotive sector is evolving fast! We’re attending the ETAuto Connected Vehicle Summit 2025 in Chennai on Feb 20. Let’s connect! 🤝 #ETAutoSummit #ConnectedVehicles #AutomotiveSecurity #ETAutoSummit #ConnectedVehicles #CyberSecurity #WP29 #AutomotiveTech
February 17, 2025 at 7:34 PM
The automotive industry is undergoing a massive transformation, and security is at the heart of it.

Register for our webinar with @Microsoft and @Cyberark today: t.co/mpeDeNCIpU

#AutomotiveSecurity #WP29 #CyberSecurity #OTSecurity #IoTSecurity #ConnectedVehicles
https://hubs.ly/Q038m4JV0
t.co
February 26, 2025 at 11:48 AM
The auto industry is transforming fast, and security is key.

See how DA supports #WP29 & R155 compliance with secure OTA updates, identity management & more.

Watch the webinar with Microsoft & CyberArk: https://hubs.ly/Q0377R670
#AutomotiveSecurity #IoTSecurity #ConnectedVehicles
WP29 and R155: Driving Compliance in Automotive - Device Authority
hubs.ly
July 23, 2025 at 8:31 AM
Ever wondered what’s in a car hacker’s toolbox? 🚗🔐

Join @PD0WM at #hw_ioUSA2025 to learn how to leverage open source tools to perform an analysis of various aspects of the modern car.

Training Objective: hardwear.io/usa-2025/tra...

#carhacking #automotivesecurity #ECUs
January 7, 2025 at 9:21 AM
The automotive industry is undergoing a massive transformation, and security is at the heart of it.

Register for our webinar with @microsoft.com and @cyberark.bsky.social today: deviceauthority.com/wp29-and-r15...

#AutomotiveSecurity #WP29 #CyberSecurity #OTSecurity #IoTSecurity #ConnectedVehicles
WP29 and R155: Driving Compliance in Automotive - Device Authority
deviceauthority.com
February 18, 2025 at 4:08 PM
Headed to #escar this week?

​Catch Franziskus talking high assurance crypto. And don't miss Karthik's keynote at the "PQC Migration & Supply Chain Readiness" workshop.

Lets connect and talk #verification and #cryptography.

buff.ly/UPf2MiN

​#AutomotiveSecurity #PQC #Crypto #SupplyChain
escar Europe - The World's Leading Automotive Cyber Security
22. escar Europe - November 19 to 20, 2024, Dortmund (Germany)
escar.info
November 3, 2025 at 8:00 AM
Jaguar Land Rover shut down systems in response to a cyberattack. Downtime isn’t just a tech issue—it’s a business continuity test. #Cybersecurity #IncidentResponse #AutomotiveSecurity www.bleepingcomputer.com/news/securit...
Jaguar Land Rover says cyberattack ‘severely disrupted’ production
JLR also stated that it is "now working at pace to restart our global applications in a controlled manner."
www.bleepingcomputer.com
September 2, 2025 at 7:00 PM
Researchers show that lasers can disrupt vehicle microchips — proving that even light can be weaponized in the wrong hands. 🔦🚘 #AutomotiveSecurity #Resilience
Bombarding Cars With Lasers: Novel Auto Attacks Emerge
Hardware attacks using lasers against silicon chips are difficult but possible. A fresh microchip protection approach aims to make it harder.
buff.ly
October 22, 2025 at 10:05 AM
📣 New Podcast! "Hacking Volkswagen's Mobile App | A Car Security Breach" on @Spreaker #apisecurity #approov #automotivesecurity #carhacking #carsharing #connectedcars #cybersecurity #mobilesecurity #volkswagen
Hacking Volkswagen's Mobile App | A Car Security Breach
Hacking Your Ride: Unpacking Volkswagen's App Flaws & Fortifying Mobility Security In this episode of Upwardly Mobile, we delve into the alarming discovery of significant security flaws in the My Volkswagen mobile app and explore how robust mobile app protection is crucial for the evolving mobility sector. Join us as we dissect the vulnerabilities found and discuss solutions to safeguard connected vehicles and sensitive user data. What We Discussed: • The Volkswagen App Hack Explained: We explore how a security researcher, frustrated by not receiving an OTP for a pre-owned car's My Volkswagen app, discovered critical vulnerabilities12. By brute-forcing a four-digit OTP (One-Time Password), the researcher gained access to the app, which then revealed deeper security issues34. • Serious Vulnerabilities Uncovered: ◦ Internal Credentials Leaked: An API endpoint exposed passwords, tokens, and usernames for various internal services, including payment processing details and CRM tools like Salesforce, in cleartext45. ◦ Owner's Personal Details Exposed via VIN: Simply using a car's VIN (Vehicle Identification Number), an API endpoint revealed extensive customer information from service and maintenance packages. This included names, phone numbers, postal addresses, email addresses, car details (model, colour, registration number, chassis number, engine number), active service contracts, purchase dates, and payment amounts56. ◦ Vehicle Service History Accessible via VIN: The VIN also allowed access to a car's full service history, including details of work performed, customer personal information, and even customer survey results for each workshop visit78. ◦ Additional Data Exposure: Further API endpoints revealed vehicle telematics data, and in some cases, even education qualifications and driving licence numbers, demonstrating a serious scope of customer data exposure9. • The Alarming Impact of These Flaws: These vulnerabilities meant that anyone with just a car's VIN (which is often visible through the windshield) could access real-time vehicle location, engine health, fuel stats, tyre pressure, geo-fencing controls, and all personal details associated with the owner, including home address, phone number, email, and driving licence1011. This poses severe risks from stalkers, criminals, scammers, and hackers who could exploit this data for nefarious purposes, including selling it on the deep web or potentially accessing car systems in the future10. • Volkswagen's Response: The vulnerability was reported to Volkswagen's security team on 23 November 2024, leading to a responsive dialogue and eventual patching of the vulnerabilities by 6 May 2025. • Protecting Mobility Apps with Approov: The incident highlights the critical need for robust mobile app security in the rapidly growing pay-per-use mobility market14. Approov provides solutions that authenticate mobile apps and secure APIs, without impacting customer experience14. • How Approov Secures Mobility Services: ◦ Blocks Data Scraping: Ensures data is accessible only by legitimate mobile apps, blocking tampered apps and scraper bots15. ◦ Prevents Unauthorized Aggregation: Helps retain control of the customer journey by forcing all-in-one services to refer customers to the official app15. ◦ Stops Digital Key Extraction: Blocks malicious attempts to intercept key authorisation during vehicle unlock and start processes, even allowing access without internet connectivity for authentic apps16. ◦ Mitigates Denial or Delay of Service Attacks: Authenticates apps to ensure legitimate API requests come only from the mobile app, dropping malicious traffic before it reaches backend services17. ◦ Secures API Endpoints: Blocks API probing and improper usage by securing communications and locking down mobility APIs to authorized apps only. • BMW Group's Adoption of Approov: We discuss how the BMW Group has successfully integrated Approov into their car sharing platform to balance top-class security with excellent customer experience. This software-only solution provides a patented 'DNA test' to attest that API requests are coming from a genuine mobile app instance running in a safe environment, and has even been enhanced to work over Bluetooth for intermittent internet connectivity. Approov's SDK is already deployed in several thousand BMW Group vehicles. Why This Matters: As the transportation market transforms with shared-use models and connected vehicles, API security becomes even more critical to protect both customer data and vehicle systems. Relevant Links: • Read the full write-up on the Volkswagen security flaws: [Excerpts from "Hacking My Car, and probably yours— Security Flaws in Volkswagen’s App | by LoopSec | May, 2025 | InfoSec Write-ups"] • Learn more about mobile app protection for mobility apps: [Excerpts from "Mobile App Protection for Mobility Apps | Approov"] • Explore the BMW Group's case study with Approov: [Excerpts from "https://approov.io/download/Approov-BMW-Story.pdf"] • Sponsor: Protect your mobile apps and APIs. Visit https://www.google.com/url?sa=E&q=https%3A%2F%2Fapproov.io for more information and to request a demo or free trial! Keywords: mobile app security, car hacking, Volkswagen app, vehicle security, API security, cybersecurity, data privacy, mobility apps, car sharing, Approov, ethical hacking, digital key, automotive security, VIN number, information security, data breaches, connected cars, IoT security.
www.spreaker.com
June 4, 2025 at 5:10 PM
Hackers are turning Android car head units into proxy botnets - even the dashboard is now part of the attack surface. Connected mobility demands cyber resilience by design. 🚗⚠️ #AutomotiveSecurity #Botnet
Hackers infect Android car head units with proxy botnet malware
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud.
buff.ly
August 24, 2026 at 8:05 AM
Android car head units infected via updaters for ad fraud & proxy botnet. #AndroidSecurity #AutomotiveSecurity #Malware #ProxyBotnet #AdFraud #Cybersecurity thedailytechfeed.com/android-car-...
August 21, 2026 at 4:12 PM