Skip to main content
All Sectors

Transport

eu

European transport sector - NIS2 essential entity

NIS2 Essential Entity

Compliance tags are AI-generated and should not be cited as regulatory evidence without independent review.

Total (30d)

8

Critical

0

High

3

Medium

5

8 threats in last 30 days( 53% vs prior period)
Top Threat Actors
Top ATT&CK Techniques
T1190Exploit Public-Facing Application9x

Deploy WAF rules, patch public-facing apps within 48h of CVE disclosure, segment DMZ from internal networks, and run authenticated vulnerability scans weekly.

T1486Data Encrypted for Impact3x

Maintain offline/immutable backups tested monthly, enable ASR rules against ransomware, and deploy behavioural detection for mass file encryption patterns.

T1078.001Valid Accounts1x

Enforce MFA on all accounts, implement conditional access policies, audit privileged accounts quarterly, and monitor for impossible-travel logins.

T1110Brute Force1x

Enforce account lockout after 5 failed attempts, require MFA, adopt NIST 800-63B password guidelines (length over complexity), and block known-breached passwords.

T1204User Execution1x

Block execution of downloaded files via Mark-of-the-Web + SmartScreen, train users on social engineering, and sandbox browser downloads.

T1498Network Denial of Service1x

Deploy upstream DDoS mitigation (Cloudflare/AWS Shield), configure rate limiting on public endpoints, and maintain a DDoS response runbook.

T1566.001Spearphishing Attachment1x

Block macros in Office docs from the internet (ASR rules), detonate attachments in a sandbox before delivery, and strip active content from inbound email.

T1021Remote Services1x

Disable RDP on internet-facing hosts, enforce MFA on all remote access, use bastion/jump hosts, and monitor lateral movement via remote service logs.

T1567Exfiltration Over Web Service1x

Deploy DLP policies on cloud storage uploads, block unauthorised file-sharing services at the proxy, and alert on anomalous outbound data volumes.

T1078Valid Accounts1x

Enforce MFA on all accounts, implement conditional access policies, audit privileged accounts quarterly, and monitor for impossible-travel logins.

Compliance Exposure
NIS2-Art21-2e(14)NIS2-Art21-2b(9)GDPR-Breach(1)NIS2-Art21-2a(1)DORA-Art17-23(1)NIS2-Art21-2c(1)NIS2-Art21-2d(1)DORA-Art5-16(1)
Technologies
ADS-BECDISAISSCADA

Recent Intelligence

Elixir-Tesla Compression Vulnerability

A vulnerability was discovered in elixir

2/6/2026Medium

AI Expands Travel Tech Threat Model

The travel industry's interconnected ecosystem is at increased risk due to AI-powered threats, including prompt injection and shadow AI adoption. This affects companies in the travel and hospitality sectors, as well as their customers. To mitigate these risks, organizations should reassess their threat models and implement AI-specific security measures.

21/5/2026Medium

Train, Lawnmower Hacks Exposed

A radio enthusiast used a £300 device to disrupt high-speed trains, while owners of a $4,000 robot lawnmower are vulnerable to hijacking and data theft. Those affected include train passengers and lawnmower owners who have not changed default passwords. Users should prioritize changing default passwords and monitoring firmware updates.

20/5/2026Medium

AI-Powered App Attacks Rise

A recent report by Digital.ai warns that AI-powered attacks on mobile apps are becoming faster, more frequent, and harder to stop, affecting all industries. These attacks can occur within hours of an app's release, erasing the distinction between emerging and primary targets. Users and developers should be vigilant and take proactive measures to secure their apps.

20/5/2026High

Vulnerability Exploitation Tops DBIR

According to the 2026 Verizon Data Breach Investigations Report, vulnerability exploitation has become the most common initial access vector, surpassing stolen credentials. This shift affects organizations of all sizes and industries, emphasizing the need for robust vulnerability management. To mitigate this risk, prioritize vulnerability patching and implement a comprehensive security strategy.

20/5/2026High

BYD Atto3 Auth Key Disclosure

A vulnerability in the BYD Atto3 allows attackers to obtain an authentication key through brute force attacks, potentially enabling unauthorized access to the Electronic Parking Break (EPB) and Supplemental Restoration System (SRS) related ECUs. This affects BYD Atto3 owners and users. Users should monitor for updates and patches from the manufacturer to address this issue.

19/5/2026High

Cyber-Enabled Cargo Theft

Cybercrime groups are using phishing emails and stolen credentials to steal freight from supply chains, affecting transportation and logistics companies. This shift in tactics allows thieves to reroute shipments without physical hijackings. Companies should review their security protocols to prevent such attacks.

14/5/2026Medium

Š

Škoda's online shop was breached due to a software vulnerability, allowing attackers temporary unauthorized access. The company has taken the shop offline, fixed the vulnerability, and reported the incident to authorities. Customers who have used the online shop should monitor their accounts for suspicious activity.

12/5/2026Medium

phpVMS Authorization Bypass

A critical vulnerability in phpVMS, a PHP application for simulating airlines, allows unauthenticated access to a legacy import feature, potentially causing full database wipe. Users of phpVMS versions prior to 7.0.6 are affected. To mitigate this vulnerability, users should update to version 7.0.6 as soon as possible. KEY

9/5/2026Critical

Taiwan Rail Hack

A 23-year-old student triggered an emergency alarm on Taiwan's high-speed rail system, disrupting service and exposing a security gap. The incident affected four trains, causing nearly an hour of delays during a holiday period. Users of critical infrastructure systems should review their security protocols to prevent similar incidents.

6/5/2026Medium

GPS Interference Detector Developed

Researchers at Oak Ridge National Laboratory have created a portable detector kit to identify GPS interference, including spoofing and jamming attacks. This development can help mitigate the growing threat of GPS interference, which affects various industries relying on GPS technology. Users of GPS-dependent systems should be aware of this development and consider implementing similar detection measures.

29/4/2026Medium

E-Motorcycles, Scooters Vulnerable

Vulnerabilities in electric motorcycles and scooters have been discovered, posing physical security and safety risks to riders. Affected models include Zero Motorcycles and Yadea electric scooters. Riders and owners should be aware of these risks and take precautions to secure their vehicles.

28/4/2026Medium

SQL Injection in Courier Mgmt System

A vulnerability in the itsourcecode Courier Management System allows for SQL injection attacks via the edit_branch.php file. Users of this system are at risk of data exposure and potential system compromise. To mitigate, apply patches or updates as soon as possible.

27/4/2026High

Public

A security vulnerability in public EV chargers has been demonstrated, allowing attackers to disable all chargers in a city. This affects cities with public EV charging infrastructure, potentially disrupting transportation. Users and administrators should review security protocols to prevent such attacks.

24/4/2026Medium

SpiceJet Booking System Vulnerability

A vulnerability has been reported in the SpiceJet Online Booking System, allowing for authorization bypass through remote manipulation. This issue affects users of the online booking system. No exploit is

23/4/2026Medium

SpiceJet Booking System Vulnerability

A critical vulnerability has been discovered in the SpiceJet Online Booking System, affecting its authentication process. This issue allows for remote exploitation, potentially impacting users of the system. Users are advised to exercise caution when using the system until a patch is available.

23/4/2026Critical

Zero Motorcycles Firmware Vulnerability

A vulnerability in Zero Motorcycles firmware versions 44 and prior allows an attacker to forcibly pair a device with the motorcycle via Bluetooth, potentially leading to malicious firmware uploads. The motorcycle must be in Bluetooth pairing mode and the attacker must be in proximity. Users should update their firmware to a version later than 44 to mitigate this risk.

21/4/2026Medium

Gentlemen Ransomware Exp

The Gentlemen ransomware-as-a-service (RaaS) has experienced rapid growth, with an increasing number of affiliates and multi-platform attacks. This expansion affects organizations across various sectors, potentially leading to widespread infections and data breaches. To mitigate the risk, organizations should prioritize robust security measures and regular system updates.

21/4/2026High

Cargo Theft via Cyber Attacks

Hackers are infiltrating logistics firms to steal cargo and divert payments, with attacks linked to organized crime and rising losses. Trucking and logistics companies are primarily affected, and should take immediate action to secure their systems. Proofpoint researchers observed coordinated remote access campaigns to steal cargo and divert payments.

19/4/2026High

Coast Guard Cybersecurity Rules

The US Coast Guard has introduced new cybersecurity rules under the Maritime Transportation Security Act (MTSA)

17/4/2026Medium