CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

PCA finds 345 auto vulnerabilities as high-severity flaws double

PCA Cyber Security's Q2 report counts 345 new automotive vulnerabilities as high-severity flaws more than double to 161.

CarThreat Staff
Last updated: August 1, 2026 9:54 am
By
ctadmin
2 Min Read
PCA finds 345 auto vulnerabilities as high-severity flaws double
SHARE

Automotive researchers catalogued 345 new vulnerabilities in the second quarter of 2026, with high-severity flaws more than doubling to 161, according to PCA Cyber Security’s quarterly threat intelligence report published July 29.

The Budapest-based firm said 94% of the quarter’s vulnerabilities carry low attack complexity, meaning they can be exploited without specialized tools or lengthy preparation. Fourteen entry methods were observed, but Local Shell access dominated, accounting for 28% of all findings. That technique uses diagnostic and debug interfaces to reach a vehicle’s onboard computers and extract data or compromise critical systems.

PCA also flagged a shift toward broader targets. White-hat research showed rentable EV chargers and shared e-bikes and e-scooters could be disabled remotely through hacked cloud-based authentication, opening the door to city-wide infrastructure outages. Separate research demonstrated how unencrypted data from a second-hand car head unit could reveal the previous owner’s driving history and personal details.

Supply chains are the new pressure point. An emerging extortion group claimed a Canadian regional automotive parts retailer on its leak site, while Qilin said it breached a large Japanese components manufacturer through subsidiaries in Europe and North Africa. The World Leaks group published more than 630 GB from an Indian electronics contract manufacturer, including engineering documents belonging to one of the world’s largest EV makers.

A ransomware incident at a UK-based automotive data and vehicle valuation provider caused what PCA called a regional valuation blackout, leaving dealers, insurers and OEMs without access to critical data.

The report argues that tracking CVEs is no longer enough. With attackers going after fleets, charging networks, cloud backends and suppliers, the industry needs to harden the ecosystem rather than individual vehicles.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Charging InfrastructureConnected VehiclesCybersecurityISO/SAE 21434Threat IntelligenceVehicle SoftwareVulnerabilities
SOURCES:PCA Cyber Security Q2 2026 reportopenPR press release
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

Nordic Regulators Block Tesla FSD Over Speed Limit Bypass Feature

By
ctadmin
June 30, 2026
CybersecurityIndustry & Culture

Tata Electronics breach leaks Apple and Tesla supply chain secrets

By
ctadmin
July 18, 2026
Car NewsCybersecurity

Pwn2Own automotive 2026 exposes NFC charger and USB infotainment risks

By
ctadmin
July 18, 2026
Cybersecurity

Stealthy camera delay attack fools self-driving object detection

By
ctadmin
August 12, 2026
Cybersecurity

Sharing camera feeds between cars opens up spoofing avenues

By
ctadmin
August 13, 2026
CybersecurityEV & Infrastructure

CISA warns of critical flaws in XCharge C6 EV charging stations

By
ctadmin
July 18, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?