Cybersecurity News, Analysis and Market Intelligence
SearchTrack cybersecurity news alongside market analysis, provider activity, and connected mobility intelligence from PAVE Insight.

Connected-vehicle rules raise market-access and compliance stakes for automakers
The US Connected Vehicle Rule restricts certain China- and Russia-linked vehicle software and hardware, while European rules focus on cybersecurity, data governance and type approval. The article examines how regulation is prompting automakers to reassess regional strategies, platforms and supply chains.

5GAA and GSMA assess post-quantum cryptography for connected vehicles
A 5GAA and GSMA report examines how post-quantum cryptography could affect V2X and network communications, including performance, legacy fleets, standardisation and the transition to quantum-resilient vehicle security.


NMFTA opens anonymous cyber-threat reporting portal to the industry
NMFTA’s Threat Report Portal is now fully operational, allowing registered organisations to submit cyber incidents and near misses anonymously. NMFTA vets and anonymises reports before sharing them with the community.


Kigen automotive eSIM gains GSMA eSA certification
Kigen says its automotive eSIM is the first certified to GSMA’s SGP.32 v1.3 specification. Developed with Infineon’s automotive security controller, it supports connected-vehicle connectivity and is planned for OEM sampling from October 2026, including for Chinese automakers.


AUTOCRYPT establishes Plug&Charge PKI system in South Korea
AUTOCRYPT has established a public-key infrastructure for Plug&Charge services in South Korea, enabling compatible vehicles and charging operators to use a shared authentication framework. It was validated with vehicles from six global brands.


MFA guidance for protecting trucking fleet accounts
The article explains how multi-factor authentication can reduce risks from stolen credentials and recommends prioritising fleet administrator, remote-access, financial and telematics accounts. It also advises fleets to use phishing-resistant MFA where possible.

Targa Telematics details cybersecurity measures for its platform
Targa Telematics outlines its cybersecurity programme, including ISO and TISAX certifications, employee training, supplier audits and penetration testing. It says it invests just under 10% of revenue in cybersecurity annually.

Q-Free launches cybersecurity-focused ramp metering software
Q-Free has launched Dynamic Metering, software for freeway ramp control featuring encrypted communications, user-access controls and web-based management. It is the third module in the company’s Dynamic Software suite.


Kigen certifies automotive eSIM supporting SGP.32 v1.3
Kigen has secured GSMA eUICC Security Assurance certification for an automotive eSIM supporting SGP.32 v1.3. Built with Infineon’s TEGRION SLI22 security controller, it is designed to support remote profile management and long vehicle lifecycles; samples are expected from October.


OmniAir approves mandatory V2X misbehaviour detection certification tests
OmniAir has approved certification specifications requiring misbehaviour detection and reporting tests for future PC5-based C-V2X onboard and roadside units. The tests, aligned with SAE J3287, aim to identify inaccurate or malicious communications and support connected-vehicle security.


Atsign and Intel report 88-fold encrypted edge-AI performance gain
Atsign and Intel have collaborated on a secure edge-AI solution for smart transportation, combining trusted identity management with Intel hardware security. They report encrypted agent-to-agent communication gains of up to 88-fold on Xeon processors and have published a supporting solution brief.


ZF showcases software-defined commercial-vehicle technology
ZF will showcase software-defined commercial-vehicle technologies at IAA Transportation 2026, including secure over-the-air updates, diagnostics, condition monitoring and its Truck Trailer Link for real-time truck-trailer data exchange.


Targa Telematics details cybersecurity architecture for telematics platform
Targa Telematics describes its telematics platform security measures, including redundant EU data centres, continuous SOC monitoring, AI-supported incident response and ISO-certified processes. It also outlines NIS2 obligations following its 2026 designation as an essential entity in Italy.


AUTOCRYPT partners with Elektrobit to strengthen SDV cybersecurity
AUTOCRYPT has partnered with Elektrobit to align automotive software platforms and cybersecurity engineering across the software-defined vehicle lifecycle. AUTOCRYPT will provide access to Elektrobit solutions in South Korea as an authorised partner.


Public Wi-Fi attack risks prompt cybersecurity advice for trucking fleets
Heavy Duty Trucking details how the Storm-2945 threat group used public Wi-Fi captive portals to steal credentials and distribute malware, and outlines safeguards including cellular connections, phishing-resistant MFA, VPNs and conditional access controls for trucking fleets.


AUTOCRYPT wins DEF CON 34 automotive hacking competition
AUTOCRYPT’s red team won DEF CON 34’s Car Hacking Village CTF in Las Vegas, beating 83 teams. Researchers used AI agents alongside human expertise to identify vulnerabilities and attack vectors, supporting the company’s automotive cybersecurity services.


Cargo theft losses hit $304.6m as criminals target higher-value freight
CargoNet recorded 677 cargo thefts in the US and Canada in Q2 2026, down 26% year on year, but estimated losses more than doubled to $304.6m as organised groups targeted high-value metals and technology shipments through cyber-enabled fraud.


USDOT seeks partners to advance cooperative driving automation
The US Department of Transportation is seeking industry teams to advance cooperative driving automation prototypes from laboratory research to pre-production systems. The work will validate secure, reliable vehicle-to-infrastructure data exchange and support a national deployment strategy.


Iran traffic-camera hack exposes cybersecurity risks for connected transport
Iran’s compromised traffic-camera network highlights vulnerabilities in connected transport infrastructure. The feature examines centralised ITS architectures, AI-enabled threats and defences, and how EU NIS2 and Cyber Resilience Act requirements are reshaping cybersecurity responsibilities.


Fuel-card fraud drives stronger security and telematics controls for fleets
Commercial fuel-card fraud is prompting stronger fleet controls, including Petro-Canada’s one-time passcodes and Motive’s AI checks against vehicle location, fuel type and tank levels. Fleets are urged to monitor transactions and understand suppliers’ reimbursement policies.


US connected-vehicle rules raise technology supply-chain risks
US restrictions on connected-vehicle hardware and automated-driving software linked to China or Russia are forcing automakers to scrutinise technology provenance, ownership and supplier dependencies. Software restrictions begin for model year 2027, with hardware restrictions following from 2029 or 2030.


Zeekr explains 9X smart-feature restrictions after owner entered Kazakhstan
Zeekr said a location-triggered anti-theft mechanism restricted a 9X owner’s navigation and other smart features for more than 30 hours after he entered Kazakhstan. The vehicle was restored after cross-border travel was verified, although unlocking may need repeating in each region.


Connected fleets face rising ransomware and vehicle cyber risks
Upstream’s Yaniv Maimon outlines rising cyber risks for commercial fleets, including ransomware, digitally enabled cargo theft and vulnerabilities in connected vehicle ecosystems. He urges smaller fleets to assess resilience using the NIST Cybersecurity Framework.


US Senate panel advances bills on connected-vehicle security and staged crashes
The US Senate Commerce Committee approved a bill to block connected vehicles and related software and hardware linked to China, Russia, Iran or North Korea. Separate legislation would criminalise staged crashes involving commercial vehicles.


US Senate advances China auto bill that could affect Mercedes-Benz
The US Senate Commerce Committee advanced a bill restricting Chinese-linked vehicle technology and ownership. Mercedes-Benz could be affected because Chinese shareholders hold nearly 20% of the company; lawmakers said changes, a waiver or compliance by 2030 may apply.


MiTAC secures IEC 62443-4-1 cybersecurity certification
MiTAC Digital Technology has secured IEC 62443-4-1 certification from TÜV NORD Taiwan, validating secure product-development processes for its edge AI and industrial computing solutions. The company says the framework will strengthen lifecycle cybersecurity and support compliance with emerging regulations.


OTA vehicle updates raise cybersecurity concerns after bus investigations
Analysts and transport authorities warn that over-the-air vehicle updates could expose connected systems to cyberattacks. Investigations of Yutong buses in Norway, the UK and Denmark found potential routes to battery and power controls, while US experts urged tighter security reviews and data disclosures.


Standards challenge for interoperable digital car keys
The Car Connectivity Consortium has convened industry stakeholders and has expanded testing and certification to address interoperability, security and proximity authentication requirements for smartphone-based digital vehicle keys, while adoption and consumer acceptance have remained uneven.


Privacy4Cars launches connected-vehicle digital offboarding platform
Privacy4Cars has introduced DisconnectedCar, a platform that helps fleets delete in-vehicle data, disable data-sharing settings and revoke former users’ connected-service access. The tool supports 19 automakers and aims to make digital offboarding auditable and repeatable.


Hesai Technology Blacklisted by US over Security Concerns
Hesai Technology, a Shanghai lidar manufacturer, has been blacklisted by the US Defence Department and has expanded partnerships with US firms including Nvidia. Experts have raised cybersecurity and national-security concerns about potential data access and firmware vulnerabilities.


Cohda MK6 Achieves CPOC Level 1 Approval in Europe
Cohda Wireless has passed CPOC Level 1 evaluation for its MK6 platform by TÜViT, confirming compliance with the EU security and trust framework for C-ITS and strengthening credentials for cross-border deployment.


AUTOCRYPT demonstrates CCC-compliant Digital Key test kit
AUTOCRYPT has demonstrated a CCC-compliant Digital Key self-testing toolkit in Budapest, enabling pre-production validation of digital key lifecycles and interoperability to reduce integration risk and development time for OEMs and tier suppliers.


US bars Polestar from selling new vehicles under Connected Vehicle Rule
The US Commerce Department has denied Polestar authorisation to sell new model-year 2027 vehicles in the country under its Connected Vehicle Rule, citing the brand’s links to Geely. Existing stock and customer servicing will continue.


AUTOCRYPT named Elektrobit's exclusive South Korea partner
AUTOCRYPT has become Elektrobit's exclusive business partner for software solutions in South Korea, combining AUTOCRYPT's automotive cybersecurity capabilities with Elektrobit's software-defined vehicle technologies and has announced plans to showcase joint technologies at the 2026 Automotive Innovation Day.


NMFTA highlights shared software and cybersecurity risks across ELDs
NMFTA research highlights shared software across large families of electronic logging devices, arguing that FMCSA revocations may not remove underlying compliance and cybersecurity risks from US trucking fleets.


CCC Digital Key Version 4: Interoperability and Security
The Car Connectivity Consortium has released Digital Key Version 4, has prioritised interoperability and certification, has strengthened NFC fallback testing, and has implemented rapid credential revocation and crypto agility to support long-term cross-vendor vehicle security.


University of Windsor Wins OmniAir V2X Hackathon
The University of Windsor team has won the inaugural OmniAir V2X Hackathon, which has convened student teams from multiple universities to develop and demonstrate detection and mitigation approaches for V2X misbehaviour affecting connected-vehicle systems.


End-to-End OTA V2X Misbehaviour Detection Demonstration
OmniAir consortium partners have demonstrated an end-to-end over-the-air V2X misbehaviour detection and enforcement workflow, validating standards-aligned reporting, SCMS processing and cross-vendor certificate revocation distribution across interoperable devices.


Manufacturers' Adoption of Digital Car Keys
Manufacturers have implemented digital keys across numerous models, allowing smartphones to unlock and start vehicles; availability, security technologies (UWB, BLE, NFC) and subscription requirements have varied by make, model and region.


OmniAir Plugfest demonstrates V2X tolling and security testing
OmniAir’s 2026 Maryland Plugfest featured real-world V2X testing, live tolling messages in production vehicles and validation of a misbehaviour message, highlighting progress towards interoperable connected-vehicle deployment.


GMV GNSS Cryptographic Module certified to EAL2
GMV's GNSS cryptographic module has been certified EAL2 under Common Criteria by Spain’s CCN and has been developed with security‑by‑design features for OSNMA, and the company has implemented a five‑year cybersecurity support and vulnerability‑disclosure programme.


NMFTA launches anonymous cybersecurity threat portal for trucking
NMFTA has launched a free, anonymous Threat Report Portal for trucking and transport organisations to report cyber incidents, cargo crime and suspicious activity, and access shared operational intelligence on emerging risks.


Q-Free launches Dynamic CV connected-vehicle module
Q-Free has launched Dynamic CV, a connected-vehicle software module that has enabled encrypted, authenticated edge communications for traffic controllers and has supported real-time SPaT, MAP, SSM and TIM exchanges and safety applications without central-system dependence.


AUTOCRYPT obtains WebTrust accreditation for V2X PKI
AUTOCRYPT has obtained WebTrust certification for its V2X PKI after an independent audit and has confirmed compliance with global PKI standards for certificate issuance, lifecycle management and security controls, and has indicated plans for further PKI expansion.

Zonar obtains SOC 2 Type 1 certification
Zonar has achieved SOC 2 Type 1 certification after an independent audit has verified its security controls and data‑protection practices, and has initiated pursuit of SOC 2 Type 2 for time‑based assurance.

Microlise conference survey highlights AI and cybersecurity priorities
Delegates at Microlise Transport Conference 2026 identified AI and automation as the biggest near-term influence on transport operations. Polling also highlighted fuel costs, electric-fleet infrastructure readiness, driver engagement and cybersecurity concerns across UK transport.




