Skip to content
Search AI Powered

Latest Stories

Report: hackers target third-party suppliers in automakers’ supply chains

90% of cyberattacks in the sector are aimed at “less vigilant firms” instead of well-protected OEMs

VicOne_Automotive_Cyberthreat_Landscape_Report_2023.jpeg

Nine out of 10 cyberattacks launched at automotive manufacturers are not aimed at the original equipment manufacturers (OEMs) themselves, but at other companies in their supply chains, according to a study from cybersecurity software and service provider VicOne.

That trend means that third-party suppliers—including logistics providers, service providers, and companies engaged in the production of components, accessories or parts—have emerged as a growing focus of attacks, the company said in its “VicOne Automotive Cyberthreat Landscape Report 2023.”


One reason for rising attacks is the increasing complexity of vehicles and their integration of connectivity, automation, and advanced driver assistance systems (ADAS). Most of the security issues were found on chipsets or systems-on-chip (SoCs), followed by vulnerabilities in third-party management applications and in-vehicle infotainment (IVI) systems, the report said.

One problem in preventing such cyber attacks is the regulatory vacuum concerning vehicle data, the report said. However, VicOne said that a new United Nations cyber security policy known as UN R155 will mandate safety conditions for newly manufactured cars beginning in July, 2024.

But in the meantime, auto industry losses are growing from cyberattacks such as ransomware and exposure of leaked data or personally identifiable information (PII), as well as costs associated with system downtime.

“Alarmingly, over 90% of these attacks were not aimed at OEMs themselves but rather at other entities in the supply chain,” the report said. “Attackers often find it difficult to penetrate well-protected companies, so they target less vigilant firms instead. But OEMs are affected all the same, because of the supply chain disruptions. Consequently, defending systems against cyberattacks is no longer just about securing an individual firm; it is about strengthening the entire supply chain.”
 

 

 

The Latest

More Stories

Trucking industry experiences record-high congestion costs

Trucking industry experiences record-high congestion costs

Congestion on U.S. highways is costing the trucking industry big, according to research from the American Transportation Research Institute (ATRI), released today.

The group found that traffic congestion on U.S. highways added $108.8 billion in costs to the trucking industry in 2022, a record high. The information comes from ATRI’s Cost of Congestion study, which is part of the organization’s ongoing highway performance measurement research.

Keep ReadingShow less

Featured

From pingpong diplomacy to supply chain diplomacy?

There’s a photo from 1971 that John Kent, professor of supply chain management at the University of Arkansas, likes to show. It’s of a shaggy-haired 18-year-old named Glenn Cowan grinning at three-time world table tennis champion Zhuang Zedong, while holding a silk tapestry Zhuang had just given him. Cowan was a member of the U.S. table tennis team who participated in the 1971 World Table Tennis Championships in Nagoya, Japan. Story has it that one morning, he overslept and missed his bus to the tournament and had to hitch a ride with the Chinese national team and met and connected with Zhuang.

Cowan and Zhuang’s interaction led to an invitation for the U.S. team to visit China. At the time, the two countries were just beginning to emerge from a 20-year period of decidedly frosty relations, strict travel bans, and trade restrictions. The highly publicized trip signaled a willingness on both sides to renew relations and launched the term “pingpong diplomacy.”

Keep ReadingShow less
forklift driving through warehouse

Hyster-Yale to expand domestic manufacturing

Hyster-Yale Materials Handling today announced its plans to fulfill the domestic manufacturing requirements of the Build America, Buy America (BABA) Act for certain portions of its lineup of forklift trucks and container handling equipment.

That means the Greenville, North Carolina-based company now plans to expand its existing American manufacturing with a targeted set of high-capacity models, including electric options, that align with the needs of infrastructure projects subject to BABA requirements. The company’s plans include determining the optimal production location in the United States, strategically expanding sourcing agreements to meet local material requirements, and further developing electric power options for high-capacity equipment.

Keep ReadingShow less
map of truck routes in US

California moves a step closer to requiring EV sales only by 2035

Federal regulators today gave California a green light to tackle the remaining steps to finalize its plan to gradually shift new car sales in the state by 2035 to only zero-emissions models — meaning battery-electric, hydrogen fuel cell, and plug-in hybrid cars — known as the Advanced Clean Cars II Rule.

In a separate move, the U.S. Environmental Protection Agency (EPA) also gave its approval for the state to advance its Heavy-Duty Omnibus Rule, which is crafted to significantly reduce smog-forming nitrogen oxide (NOx) emissions from new heavy-duty, diesel-powered trucks.

Keep ReadingShow less
screenshots for starboard trade software

Canadian startup gains $5.5 million for AI-based global trade platform

A Canadian startup that provides AI-powered logistics solutions has gained $5.5 million in seed funding to support its concept of creating a digital platform for global trade, according to Toronto-based Starboard.

The round was led by Eclipse, with participation from previous backers Garuda Ventures and Everywhere Ventures. The firm says it will use its new backing to expand its engineering team in Toronto and accelerate its AI-driven product development to simplify supply chain complexities.

Keep ReadingShow less