Skip to main content
VendorsPCA Cyber Security

PCA Cyber Security

Cybersecurity reports and statistics published by PCA Cyber Security

8 categories2 reports

Recent Statistics & Reports

Most EVs in DrainDead testing allowed indefinite battery siphoning with repeated session resets; only some (e.g. Volkswagen group) halted discharging after around 60 seconds

5/27/2026
Automotive CybersecurityEV ChargingDrainDead

206 unique automotive vulnerabilities identified in Q4 2025, a 19% increase over Q3 2025

5/27/2026
Automotive CybersecurityCVEsQ4 2025

An automotive parts marketplace database with over 7.7 million records was exposed via a misconfigured Elasticsearch instance in January 2026

5/27/2026
Automotive CybersecurityAftermarketMisconfiguration

Ethernet and Wi-Fi combined accounted for more than 18% of Q4 2025 automotive attack vectors

5/27/2026
Automotive CybersecurityEthernetWi-Fi

Ultra-Fast Wireless Charging hack drew 76%+ of the power intended for a legitimate EV from inductive chargers

5/27/2026
Automotive CybersecurityEV ChargingWireless

Q4 2025 automotive vulnerabilities span 64 unique CWEs

5/27/2026
Automotive CybersecurityCWEsQ4 2025

US SELF DRIVE Act of 2026 requires the Secretary of Commerce to brief Congress on connected vehicle supply chain security within 180 days

5/27/2026
Automotive CybersecurityRegulationSELF DRIVE Act

Kenwood DNR1007XR aftermarket head unit exposes a Linux login prompt over UART at 115200 bps via a hidden board-edge connector

5/27/2026
Automotive CybersecurityInfotainmentKenwood

265 unique automotive-specific vulnerabilities identified in Q1 2026

5/27/2026
Automotive CybersecurityCVEsQ1 2026

28% increase in automotive vulnerabilities in Q1 2026 compared to Q4 2025

5/27/2026
Automotive CybersecurityCVEsQuarter-on-Quarter

In-vehicle and Backend systems accounted for more than 81% of Q1 2026 automotive vulnerability targets

5/27/2026
Automotive CybersecurityIn-VehicleBackend

PCA identified 14 unique methods of entry in the Q1 2026 automotive threat landscape

5/27/2026
Automotive CybersecurityAttack Vectors

Pwn2Own Automotive 2026 had a record 73 entries

5/27/2026
Automotive CybersecurityPwn2Own

Quarkslab's audit of EVerest open-source EV charging stack found 6 high-severity, 6 medium-severity, 5 low-severity and 3 informational issues

5/27/2026
Automotive CybersecurityEV ChargingEVerest

Ransomware group exfiltrated nearly 1 TB of data from a major Asian vehicle manufacturer's customer and dealership environment in early January 2026 via a third-party vendor

5/27/2026
Automotive CybersecurityRansomwareThird-Party Vendor

Delta Alarm cyberattack disabled mobile-app vehicle controls for hundreds of thousands of Russian vehicle owners for up to two weeks in late January 2026

5/27/2026
Automotive CybersecurityTelematicsCloud Hijack

Delta Alarm took approximately five days to restore partial functionality and nearly two weeks to fully recover from the cloud control plane attack

5/27/2026
Automotive CybersecurityTelematicsIncident Response

US Commerce Department rule prohibits Chinese and Russian connected-vehicle software starting Model Year 2027

5/27/2026
Automotive CybersecurityRegulationUS Commerce

US connected vehicle hardware restrictions arrive for Model Year 2030 or January 1, 2029 for non-model-year components

5/27/2026
Automotive CybersecurityRegulationHardware

US connected vehicle rule covers vehicles under 10,001 pounds

5/27/2026
Automotive CybersecurityRegulationConnected Vehicles

Showing 21-40 of 57 results