Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: automotive (4 articles)Clear

Researcher remotely controls BYD Shark 6 lights locks and cabin audio in authorised test

In an authorised test reported by ABC Four Corners on September 21, automotive security researcher Dan Hreszczuk remotely locked doors, operated wipers and washers, toggled headlights while the vehicle moved slowly, and played media through the infotainment system of a BYD Shark 6, while also tracking it and accessing in-cabin audio. He said the access path his team used had no password. He could not reach brakes or cameras and considered those well protected, and found no control over steering or acceleration. ABC did not publish the model year, software build, initial access method, affected versions, or a vulnerability identifier, so fleet-wide reproducibility remains unestablished.

Check
Treat this as a single prepared-vehicle demonstration, not a fleet-wide exploit, and track for a vendor advisory, affected builds, or independent replication before acting.
Affected
One BYD Shark 6 allowed remote control of lights, locks, wipers, and infotainment plus location tracking and cabin audio through an access path reportedly lacking a password.
Fix
For connected fleets, review remote-access authentication on comfort and telematics functions, segment them from safety systems, and press vendors for disclosure detail.

First car head unit malware spreads through built-in Android updaters

Kaspersky documented what it calls the first malware found on a car head unit with an infection chain built specifically for that kind of device. The malware spreads through the built-in software updaters of certain Android-based automotive head unit firmware, then pulls a multi-stage downloader that runs ad fraud and enrolls the unit into a reverse-proxy botnet. Researchers attribute it with high confidence to a group tied to the BADBOX ad-fraud and residential-proxy operation. A head unit is the central console that handles media and, on many vehicles, some vehicle functions, so malware delivered through its own update mechanism is a notable expansion of automotive supply-chain risk.

Check
For fleets and connected-vehicle programs, ask head unit and firmware suppliers about the integrity of their built-in updaters, and monitor automotive and IoT devices for proxy or ad-fraud traffic.
Affected
Vehicles using affected Android automotive head unit firmware whose built-in updater delivered the malware; infected units run ad fraud and act as reverse-proxy nodes, and the head unit has partial vehicle-function access.
Fix
Treat the firmware update channel as a supply-chain trust boundary, source head units from vendors with signed verified updates, monitor connected vehicles for anomalous outbound traffic, and track this actor's proxy infrastructure.

Automotive marketplace Edmunds added to Have I Been Pwned with 177,860 breached accounts; expect car-buying-themed phishing

Have I Been Pwned has added the US automotive marketplace Edmunds to its breach corpus with 177,860 unique email addresses. Edmunds is a widely used car-research and shopping platform offering pricing, reviews, and dealer listings. As is typical for HIBP additions, the underlying breach source and disclosure details are not published alongside the entry, but the listing lets individuals and organizations check whether their accounts appear in the leaked dataset. Affected users should anticipate car-buying-themed phishing such as financing offers, dealer-contact lures, or vehicle-quote follow-ups, and should rotate any reused passwords. The addition continues a steady run of mid-size US consumer-platform breaches surfacing in HIBP.

Check
Check whether your @company emails appear in HIBP's Edmunds corpus. Warn affected staff about car-buying-themed phishing (financing offers, dealer contacts) over the next 30-60 days.
Affected
177,860 unique email addresses tied to Edmunds accounts. Reused passwords are the primary downstream risk; expect automotive-themed phishing and credential-stuffing against other services.
Fix
Affected individuals: rotate Edmunds passwords and any reused elsewhere, enable MFA. Organizations: add Edmunds to breach-monitoring watchlists and brief staff on car-shopping-themed social engineering.

Skoda Auto's German online shop breached via e-commerce software flaw - customer names, addresses, phones, and password hashes exposed; server logs cannot confirm full exfiltration

Skoda Auto, the Volkswagen Group's Czech-built carmaker with 34,000 employees and 27 billion euros in annual sales, disclosed that attackers exploited a flaw in its German online shop software to access customer data. The breach hit shop.skoda-auto.de, not Skoda's global systems or the Skoda Connect portal. Exposed information includes names, addresses, email addresses, phone numbers, order history, account data, and password hashes. Payment card details were not stored on the affected system. Skoda took the shop offline, patched the flaw, and engaged external forensics, but admitted its server logs cannot retrospectively confirm exactly what data was copied out during the intrusion window.

Check
Check the email account used for any past Skoda online shop orders, search your password manager for credentials reused across Skoda and other services, and watch for German-language phishing referencing real order numbers.
Affected
Customers who created an account or placed an order on shop.skoda-auto.de (Skoda Auto Germany's online store). The Skoda Connect Portal and Skoda's global systems are not affected per the company.
Fix
Change the Skoda online shop password and any other service using the same credentials, and enable MFA where available. Do not click links in emails or texts about Skoda orders; verify directly through the shop website.