logo

Truck-to-truck worm could infect – and disrupt – entire US commercial fleet

ID: 75d6ab56-1d5d-5686-ab5d-ac1bfd83c4e5

STIX ID: report--75d6ab56-1d5d-5686-ab5d-ac1bfd83c4e5

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-03-22

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Researchers at Colorado State University disclosed that many Electronic Logging Devices (ELDs) mandated in US trucks have insecure defaults (exposed OTA APIs, enabled Wi‑Fi/Bluetooth with weak/predictable credentials) allowing attackers within wireless range to connect, send arbitrary CAN messages, re-flash firmware, and deploy a self-propagating truck-to-truck worm; the team demonstrated a 14‑second drive-by compromise and warned of potential large-scale disruption to commercial fleets while coordinating disclosure with vendors and CISA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.