VendorsPCA Cyber Security
PCA Cyber Security
Cybersecurity reports and statistics published by PCA Cyber Security
8 categories2 reports
Research Reports
Reports and publications from PCA Cyber Security
Recent Statistics & Reports
Synacktiv chained an information leak with an out-of-bounds write to achieve a full win against Tesla infotainment via USB at Pwn2Own Automotive 2026
5/27/2026•
Automotive CybersecurityTeslaPwn2Own
Most EVs in DrainDead testing allowed indefinite battery siphoning with repeated session resets; only some (e.g. Volkswagen group) halted discharging after around 60 seconds
5/27/2026•
Automotive CybersecurityEV ChargingDrainDead
Ultra-Fast Wireless Charging hack drew 76%+ of the power intended for a legitimate EV from inductive chargers
5/27/2026•
Automotive CybersecurityEV ChargingWireless
US SELF DRIVE Act of 2026 requires the Secretary of Commerce to brief Congress on connected vehicle supply chain security within 180 days
5/27/2026•
Automotive CybersecurityRegulationSELF DRIVE Act
ChargePoint Home Flex flaw (ZDI-26-197) allows unauthenticated network-adjacent remote code execution as root via OCPP message handling
5/27/2026•
Automotive CybersecurityEV ChargingChargePoint
Around 60% of automotive vendors had already adopted IDS at time of Automotive Cyber Security Connectivity and SDV Week 2025 survey
5/27/2026•
Automotive CybersecurityIDSAdoption
265 unique automotive-specific vulnerabilities identified in Q1 2026
5/27/2026•
Automotive CybersecurityCVEsQ1 2026
28% increase in automotive vulnerabilities in Q1 2026 compared to Q4 2025
5/27/2026•
Automotive CybersecurityCVEsQuarter-on-Quarter
102% year-on-year increase in automotive vulnerabilities (Q1 2026 vs Q1 2025)
5/27/2026•
Automotive CybersecurityCVEsYear-on-Year
Q1 2026 automotive vulnerabilities span 77 unique CWEs
5/27/2026•
Automotive CybersecurityCWEsQ1 2026
Q1 2026 automotive vulnerabilities map to 25 distinct TTPs in the Auto-ISAC Automotive Threat Matrix
5/27/2026•
Automotive CybersecurityTTPsAuto-ISAC ATM
Web and Local Shell combined for 33% of Q1 2026 automotive attack vectors
5/27/2026•
Automotive CybersecurityWebLocal Shell
In-vehicle and Backend systems accounted for more than 81% of Q1 2026 automotive vulnerability targets
5/27/2026•
Automotive CybersecurityIn-VehicleBackend
PCA identified 14 unique methods of entry in the Q1 2026 automotive threat landscape
5/27/2026•
Automotive CybersecurityAttack Vectors
77 distinct CWEs mapped in Q1 2026, up from 64 in Q4 2025
5/27/2026•
Automotive CybersecurityCWEs
Pwn2Own Automotive 2026 had a record 73 entries
5/27/2026•
Automotive CybersecurityPwn2Own
Quarkslab's audit of EVerest open-source EV charging stack found 6 high-severity, 6 medium-severity, 5 low-severity and 3 informational issues
5/27/2026•
Automotive CybersecurityEV ChargingEVerest
Ultra-Fast Wireless Charging hack drained 76% of EV power on the Alpitronic HYC50 commercial DC fast charger
5/27/2026•
Automotive CybersecurityEV ChargingAlpitronic
DefenseWeaver multi-agent LLM identified 11 critical attack paths across four automotive projects in TARA testing
5/27/2026•
Automotive CybersecurityAI/LLMTARA
Quarkslab bypassed the 16-byte RH850 debug password protection using voltage fault injection
5/27/2026•
Automotive CybersecurityHardwareFault Injection
Showing 21-40 of 57 results