Welcome to Security Breaks, the go-to podcast for professionals, enthusiasts, and anyone interested in the intersection of automotive technology and security. In an era where vehicles are not just modes of transportation but sophisticated networks on wheels, understanding and safeguarding against potential threats is more critical than ever. In each episode, we dive deep into the latest trends, technologies, and challenges facing the automotive security industry. From cybersecurity measures and innovative safety technologies to regulatory updates and best practices, our expert guests share their insights and experiences to help you stay ahead of the curve. Join us on Security Breaks as we accelerate the exchange of knowledge and information, empowering our community to drive forward with confidence. Because in the world of automotive security, the more we know, the better we can prepare. Tune in, and let's gear up for a safer future on the roads.

Security Breaks
Claim This Podcastby Automotive Security Research Group
Podcast Overview
Welcome to Security Breaks, the go-to podcast for professionals, enthusiasts, and anyone interested in the intersection of automotive technology and security. In an era where vehicles are not just modes of transportation but sophisticated networks on wheels, understanding and safeguarding against potential threats is more critical than ever. In each episode, we dive deep into the latest trends, technologies, and challenges facing the automotive security industry. From cybersecurity measures and innovative safety technologies to regulatory updates and best practices, our expert guests share their insights and experiences to help you stay ahead of the curve. Join us on Security Breaks as we accelerate the exchange of knowledge and information, empowering our community to drive forward with confidence. Because in the world of automotive security, the more we know, the better we can prepare. Tune in, and let's gear up for a safer future on the roads.
Language
🇺🇲
Publishing Since
4/17/2024
Reach the team behind Security Breaks
Verified contact details for this show aren't on file yet — sign up to get notified when they land.
Recent Episodes

October 27, 2025
Security Breaks – Weekly News Edition
<p>In this episode, Kate dives into the latest <strong>automotive cybersecurity headlines</strong> — from wireless tire pressure monitoring vulnerabilities to supplier ransomware and SBOM validation breakthroughs. She unpacks critical issues affecting OEMs, Tier 1 suppliers, and dealerships, while highlighting the real-world implications of Bluetooth Low Energy attacks, supply chain risks, and continuous software validation.</p><p>Whether you’re an engineer, cybersecurity practitioner, or dealership IT lead, this episode delivers a fast-paced, expert breakdown of what’s shaping the automotive security landscape right now.</p><h3><strong>Key Takeaways</strong></h3><ul><li><strong>TPMS (Tire Pressure Monitoring Systems)</strong> still transmit unencrypted signals, leaving room for spoofing and tracking vulnerabilities.</li><li><strong>Supplier cyber incidents</strong>, such as those impacting Jaguar Land Rover, show how attacks ripple through the entire automotive supply chain.</li><li><strong>Bluetooth Low Energy (BLE)</strong> weaknesses continue to expose vehicles to unauthorized access — secure pairing and token rotation are essential.</li><li><strong>Ransomware groups</strong> like Akira are increasingly targeting distributors and service providers within the automotive ecosystem.</li><li><strong>Continuous SBOM validation</strong> and integration with threat intelligence are key to proactive risk management under ISO/SAE 21434 and UNECE R155.</li><li><strong>Machine learning intrusion detection systems (IDS)</strong> show promise but require realistic datasets and careful tuning to avoid false positives.</li></ul><br/><h3><strong>Quotes</strong></h3><blockquote>“Safety signaling that can be faked is a problem. When drivers start to ignore warnings, we’ve already lost the battle.” </blockquote><blockquote><br></blockquote><blockquote>“If your dealer network still relies on flat networks because printers — this is your sign to fix that.” </blockquote><blockquote><br></blockquote><blockquote>“Your SBOM program isn’t about paperwork. It’s about knowing what’s in your software so you can fix what matters.” </blockquote><h3><br></h3><h3><strong>Timestamps</strong></h3><p>(01:29) Wireless threats to tire pressure monitoring systems (TPMS)</p><p>(06:00) Supplier cyberattacks disrupting Jaguar Land Rover’s production</p><p>(08:30) Pen Test Partners’ guide to hacking Bluetooth Low Energy</p><p>(11:00) Ransomware attack on Harbor Diesel & Equipment</p><p>(13:42) Advances in SBOM validation and continuous vulnerability management</p><p>(17:25) Machine learning intrusion detection for the Internet of Vehicles</p><p>(20:32) Practical takeaways for OEMs, suppliers, and dealerships</p><p>(23:50) Community questions and call for industry collaboration</p><h3><strong>Referenced Links</strong></h3><ul><li><a href="https://www.iso.org/standard/70918.html" rel="noopener noreferrer" target="_blank">Automotive Cybersecurity Standards: ISO/SAE 21434</a></li><li><a href="https://unece.org/transport/documents/2021/03/standards/un-regulation-no-155-cyber-security-and-cyber-security" rel="noopener noreferrer" target="_blank">UNECE Regulation No. 155 – Cybersecurity and Cybersecurity Management Systems</a></li><li><a href="https://unece.org/transport/documents/2021/03/standards/un-regulation-no-156-software-update-and-software-update" rel="noopener noreferrer" target="_blank">UNECE Regulation No. 156 – Software Updates</a></li><li><a href="https://www.pentestpartners.com" rel="noopener noreferrer" target="_blank">Pen Test Partners – Practical Guide to Hacking BLE</a></li><li><a href="https://ransomware.live" rel="noopener noreferrer" target="_blank">Ransomware.live – Akira Group Listing</a></li><li><a href="https://ics-cert.kaspersky.com/publications/reports/" rel="noopener noreferrer" target="_blank">Kaspersky: A Decade of Vehicle Hacks Report</a></li></ul><br/><h3><strong>Please Leave Us a Rating and Review</strong></h3><p>If you enjoyed this

June 5, 2024
Digging deeper into the VicOne Threat Landscape Report: The Story Behind the Numbers
<h3>Episode Summary:</h3><p>In this episode, John speaks with a cybersecurity expert Karl Schlaugh about the rising cyber threats in the automotive industry, the challenges of securing vehicles, and the impact of regulations on automotive cybersecurity. They discuss various attack vectors, the importance of patch management, and the role of regulations in enhancing vehicle security.</p><h3>Key Takeaways:</h3><ul><li>Cybercriminals target the automotive supply chain to amplify their reach.</li><li>The automotive industry's long patch lifecycle makes it a lucrative target for cybercriminals.</li><li>Regulations like UN ECE 155 and 156 are positively impacting automotive cybersecurity by requiring vulnerability management and encouraging transparency.</li><li>The rise in cyber attacks on the automotive industry underscores the need for improved security measures and continuous monitoring.</li></ul><br/><h3>Quotes:</h3><ol><li>"Cybercriminals always follow money. If you have malware running in a supplier, then you amplify your targets." - Karl Schlaugh</li><li>"The patch lifecycle in automotive is a hell of a lot longer, which is a good thing for cybercriminals." - Karl Schlaugh</li><li>"Regulations like UN ECE 155 and 156 are encouraging vulnerability management and transparency, which is very positive." - Karl Schlaugh</li></ol><br/><h3>Timestamps:</h3><ul><li>(10:35) The long patch lifecycle in the automotive industry</li><li>(16:50) Impact of regulations on automotive cybersecurity</li><li>(24:10) Addressing cybersecurity in older vehicles</li><li>(28:30) Key takeaways from the cybersecurity threat landscape report</li><li>(36:17) Discussion on industry trends and future outlook</li><li>(41:53) Monetary impact of cyber attacks on the automotive industry</li><li>(43:31) Importance of reputation management for OEMs</li></ul><br/><h3>Referenced Links:</h3><ul><li>UN ECE 155 Regulation</li><li>UN ECE 156 Regulation</li><li><a href="https://documents.vicone.com/reports/automotive-cyberthreat-landscape-report-2023.pdf" rel="noopener noreferrer" target="_blank">Automotive Cyber Threat Landscape Report 2023</a></li></ul><br/><p>Please leave us a rating and a review on Apple Podcast.</p><h3>Connect With Karl (Kalli) Schlauch:</h3><ul><li><a href="https://ie.linkedin.com/in/karlschlauch" rel="noopener noreferrer" target="_blank">LinkedIn</a></li></ul><br/><h3>Connect With ASRG:</h3><ul><li><a href="https://asrg.io/" rel="noopener noreferrer" target="_blank">ASRG</a></li><li><a href="https://www.linkedin.com/company/automotive-security-research-group/posts/?feedView=all" rel="noopener noreferrer" target="_blank">LinkedIn</a></li></ul><br/>

May 8, 2024
Exploring Upstream's Cybersecurity Report with Giuseppe Serio
<p>In this episode of the Security Breaks podcast, host John Heldreth welcomes Giuseppe Serio from Upstream Cybersecurity, a leading expert in automotive cybersecurity. The episode explores the latest developments in automotive cybersecurity, focusing on the <a href="https://info.upstream.auto/hubfs/Security_Report/Security_Report_2024/Upstream_2024_Gl[…]c2-85b6-f0158ad2a14a%7C708f280d-d13d-450b-a8d4-b4c9ea0ece08" rel="noopener noreferrer" target="_blank">Upstream Cybersecurity Threat Report for 2024.</a></p><p><strong>Key Takeaways:</strong></p><ul><li><strong>Upstream Cybersecurity Threat Report 2024:</strong> The report provides a comprehensive overview of the latest threats in automotive cybersecurity, using data from VSOCs and external sources like the dark web. It serves as a key resource for industry professionals.</li><li>The episode emphasizes the importance of responsible disclosure in cybersecurity research, focusing on safety and proper communication when dealing with sensitive information.</li></ul><br/><p><strong>Quotes:</strong></p><ul><li> "VSOCs play a crucial role in monitoring, detecting, and responding to cyber threats in real-time. They're essential for maintaining the security and safety of connected vehicles."</li><li>"Responsible disclosure is key in the cybersecurity industry. It’s not just about finding vulnerabilities; it's about ensuring that the information is handled properly to avoid potential risks to public safety."</li></ul><br/><p><strong>Timestamp:</strong></p><p><strong>(1:55 - 2:21):</strong> Discussion about Upstream's annual automotive cybersecurity threat report, which details the threats faced by the industry and its impact on the safety of vehicles and their operations.</p><p><strong>(2:31 - 2:40):</strong> John discusses the length and comprehensiveness of the report, emphasizing its importance in providing insights into threats and the potential challenges facing the automotive industry.</p><p><strong>(5:19 - 5:34):</strong> Giuseppe elaborates on the shift from calling it "Automotive SOC" to "VSOC," emphasizing that the concept has evolved from focusing on individual vehicles to the broader fleet and ecosystem.</p><p><strong>(12:23 - 12:40):</strong> Discussion of the internal and external sources Upstream uses for research and threat intelligence, including their dedicated research team and the various sources used to compile the report.</p><p><strong>(13:07 - 13:41):</strong> Giuseppe outlines the process of compiling the cybersecurity threat report, mentioning the significant effort and resources involved in gathering and analyzing the data to ensure accurate and comprehensive insights into the automotive cybersecurity landscape.</p><p><strong>About the Guest: </strong></p><p>Giuseppe is a cybersecurity expert specializing in the automotive industry. He brings a deep understanding of cybersecurity issues specific to the automotive sector, discussing topics like over-the-air (OTA) updates, electric vehicles (EVs), and autonomous driving technologies. Giuseppe's insights reflect a comprehensive grasp of current trends and emerging threats in automotive cybersecurity.</p><p><strong>Connect with Giuseppe Serio:</strong></p><p>LinkedIn: <a href="https://www.linkedin.com/in/giuseppe-serio/" rel="noopener noreferrer" target="_blank">Giuseppe Serio</a></p><p>Website: <a href="https://upstream.auto/" rel="noopener noreferrer" target="_blank">Upstream</a></p><p><strong>Connect With ASRG:</strong></p><ul><li><a href="https://www.asrg.io/" rel="noopener noreferrer" target="_blank">ASRG Website</a></li><li><a href="https://www.facebook.com/AutoSecResGroup/" rel="noopener noreferrer" target="_blank">ASRG Facebook Page</a></li><li><a href="https://www.linkedin.com/company/automotive-security-research-group/" rel="noopener noreferrer" target="_blank">ASRG LinkedIn</a></li></ul><br/><p><strong>Download report here:</strong></p><ul><li><a...
4 total episodes available
Deep-dive analytics for Security Breaks
Frequently asked questions
Have a different question and can't find the answer you're looking for? Reach out to our support team by sending us an email and we'll get back to you as soon as we can.
- What is Security Breaks?
- How often does this podcast release new episodes?
This podcast updates weekly.
- Where can I listen to this podcast?
This podcast is available on 9 platforms including Apple Podcasts, Spotify, and more. You can also use the RSS feed directly.
- Does this podcast accept guests?
Yes, this podcast regularly features guests.
Legal Disclaimer
Pod Engine is not affiliated with, endorsed by, or officially connected with any of the podcasts displayed on this platform. We operate independently as a podcast discovery and analytics service.
All podcast artwork, thumbnails, and content displayed on this page are the property of their respective owners and are protected by applicable copyright laws. This includes, but is not limited to, podcast cover art, episode artwork, show descriptions, episode titles, transcripts, audio snippets, and any other content originating from the podcast creators or their licensors.
We display this content under fair use principles and/or implied license for the purpose of podcast discovery, information, and commentary. We make no claim of ownership over any podcast content, artwork, or related materials shown on this platform. All trademarks, service marks, and trade names are the property of their respective owners.
While we strive to ensure all content usage is properly authorized, if you are a rights holder and believe your content is being used inappropriately or without proper authorization, please contact us immediately at hey@podengine.ai for prompt review and appropriate action, which may include content removal or proper attribution.
By accessing and using this platform, you acknowledge and agree to respect all applicable copyright laws and intellectual property rights of content owners. Any unauthorized reproduction, distribution, or commercial use of the content displayed on this platform is strictly prohibited.
