VicOne, an automotive cybersecurity solutions leader, today announced that it co-hosted with Trend Micro the world’s largest zero-day vulnerability discovery contest, Pwn2Own Automotive 2025, at Aut...
With automotive system complexity and attack surface both rapidly growing, VicOne set to release new report detailing sharp rise in vulnerabilities and industry recommendations
DETROIT & TOKYO: VicOne, an automotive cybersecurity solutions leader, today announced that it co-hosted with Trend Micro the world’s largest zero-day vulnerability discovery contest, Pwn2Own Automotive 2025, at Automotive World, which took place Jan. 22-24 in Tokyo. Top-tier security researchers performed real-world testing on cutting-edge automotive technologies, all within Trend Micro’s proven Zero Day Initiative (ZDI) platform, the world’s largest vendor-agnostic bug bounty program.
Pwn2Own Automotive is an annual competition designed to uncover and rectify vulnerabilities in technologies for connected cars. Automotive cybersecurity researchers from 13 countries came together on a global stage to discover 49 unique zero-day vulnerabilities across systems such as in-vehicle infotainment (IVI) systems and electric vehicle (EV) chargers. Sina Kheirkhah of Summoning Team was crowned the Pwn2Own Automotive 2025 Master of Pwn.
“As SDVs (software-defined vehicles) reshape the automotive industry, cybersecurity becomes critical to ensuring their safety and reliability,” said Max Cheng, chief executive officer of VicOne. “Platforms like Pwn2Own Automotive are instrumental to uncovering zero-day vulnerabilities and mitigating risks before they can escalate. By supporting initiatives like this, the industry can proactively strengthen vehicle security, paving the way for safer and more resilient advancements in mobility.”
The automotive industry is evolving with innovations such as SDVs, advanced driver-assistance systems (ADAS) and integration of artificial intelligence (AI). These developments promise enhanced functionality and efficiency but also introduce cybersecurity challenges, including risks from generative AI, supply-chain vulnerabilities and over-the-air (OTA) updates.
According to the forthcoming VicOne 2025 annual report, the total count of automotive-related vulnerabilities (“CVEs”) published in 2024 reached 530 vulnerabilities, another annual gain and just two short of twice as many as in 2019. The sharp rise in vulnerabilities highlights the rapid growth in both the automotive attack surface and automotive systems.
Cyberattacks in 2024 caused damages exceeding $22 billion, with $20 billion attributed to data breaches and personal information leaks, the VicOne annual report will show. Key areas impacted in 2024 included the automobile industry’s suppliers and dealers, who collectively account for the majority of targeted attacks.
Other insights in the report, which is to be released publicly available at vicone.com:
At Automotive World 2025, the world’s leading event for advanced automotive technologies convening more than 1,800 companies, VicOne showcased a range of its innovative solutions built from the ground up to protect the connected-car ecosystem:
The VicOne booth at Automotive World 2025 also featured the company’s collaborative initiatives with its partner companies. VicOne’s strategic partnerships include original equipment manufacturers (OEMs), hardware suppliers, semiconductor vendors, software developers and service providers.
Founded and singularly focused on spearheading innovation in vehicle cybersecurity, VicOne, the market leader of automotive cybersecurity, provides the most advanced and comprehensive solutions to the automotive industry and galvanizes collective expertise from the sector’s broadest cast of best-of-breed partners. OEMs and suppliers trust VicOne’s purpose-built solutions to stay ahead of evolving threats and safeguard vehicles, drivers and sensitive data.
For more information on VicOne’s holistic approach to cybersecurity—spanning software, hardware and supply-chain ecosystems—please visit https://vicone.com/blog/software-defined-vehicles-navigating-innovation-and-cybersecurity-challenges.
About VicOne
With a vision to secure the vehicles of tomorrow, VicOne delivers a broad portfolio of cybersecurity software and services for the automotive industry. Purpose-built to address the rigorous needs of automotive manufacturers and suppliers, VicOne solutions are designed to secure and scale with the specialized demands of the modern vehicle. As a Trend Micro subsidiary, VicOne is powered by a solid foundation in cybersecurity drawn from Trend Micro’s 30+ years in the industry, delivering unparalleled automotive protection and deep security insights that enable our customers to build secure as well as smart vehicles. For more information, visit vicone.com.
About Zero Day Initiative (ZDI)
The Zero Day Initiative (ZDI) was launched by Trend Micro in July 2005 to encourage the reporting of zero-day vulnerabilities privately to the affected vendors by financially rewarding researchers. Today, the ZDI represents the world’s largest vendor-agnostic bug bounty program. For more information, visit zerodayinitiative.com.
About Trend Micro
Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fueled by decades of security expertise, global threat research, and continuous innovation, Trend Micro's AI-powered cybersecurity platform protects hundreds of thousands of organizations and millions of individuals across clouds, networks, devices, and endpoints. As a leader in cloud and enterprise cybersecurity, Trend's platform delivers a powerful range of advanced threat defense techniques optimized for environments like AWS, Microsoft, and Google, and central visibility for better, faster detection and response. With 7,000 employees across 70 countries, Trend Micro enables organizations to simplify and secure their connected world. For more information, visit TrendMicro.com.
Fonte: Business Wire
Alaa Abdul Nabi, Vice President, Sales International at RSA presents the innovations the vendor brings to Cybertech as part of a passwordless vision for…
G11 Media's SecurityOpenLab magazine rewards excellence in cybersecurity: the best vendors based on user votes
Always keeping an European perspective, Austria has developed a thriving AI ecosystem that now can attract talents and companies from other countries
Successfully completing a Proof of Concept implementation in Athens, the two Italian companies prove that QKD can be easily implemented also in pre-existing…
#DASTechnology--DAS Technology, automotive’s leading consumer engagement SaaS AI technology company with the industry’s first and largest next-level Consumer…
#DASTechnology--DAS Technology, automotive’s leading consumer engagement SaaS AI technology company with the industry’s first and largest next-level Consumer…
#aerialimaging--CoreLogic®, a leader in global property information, analytics and data-enabled solutions, announced a new strategic alliance with Vexcel…
On Jan. 21, 2025, CSG learned that an external party gained unauthorized access to a single provider’s data residing on a CSG platform. We have no evidence…