Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Security Concerns Emerge for Electric Bikes and Scooters

Security Concerns Emerge for Electric Bikes and Scooters

Posted on April 28, 2026 By CWS

Electric motorcycles manufactured by Zero Motorcycles and scooters from Yadea have been found to contain vulnerabilities that could affect both security and rider safety. Recent advisories from the Cybersecurity and Infrastructure Security Agency (CISA) highlight these risks, drawing attention to potential real-world consequences.

Vulnerabilities in Zero Motorcycles

Zero Motorcycles, a US-based manufacturer, has been identified with a Bluetooth vulnerability in its electric motorcycles. This flaw, cataloged as CVE-2026-1354, affects firmware versions up to 44. Researchers from Bureau Veritas Cybersecurity have discovered that an attacker could exploit this weakness to gain unauthorized access and upload malicious firmware to the motorcycle.

The vulnerability is classified as ‘medium severity’ by CISA due to the complexity involved in executing an attack. Dinesh Shetty, who leads security engineering at Bureau Veritas, explained that an attacker must be within Bluetooth range and understand the device’s pairing process to succeed. This allows the attacker to pair their device and potentially control critical functions of the motorcycle.

Potential Impacts of Bluetooth Exploitation

Once the malicious firmware is installed, the attacker can manipulate various safety-critical functions, such as torque output and braking systems, posing significant risks at high speeds. Even more concerning is the possibility of remote command-and-control through the bike’s cellular modem, which adds a layer of complexity to the potential threat.

In response, CISA has advised users to pair their motorcycles in secure locations while waiting for a firmware patch expected in May. Despite these developments, Zero Motorcycles has yet to issue a public response.

Yadea T5 Scooter Vulnerability

Another noteworthy vulnerability affects the T5 scooter by Yadea, a Chinese company. This issue, identified as CVE-2025-70994 and deemed ‘high severity’, allows attackers to intercept commands sent between the scooter and its key fob. By capturing a legitimate command, such as locking the scooter, attackers can generate unauthorized commands to unlock or even start the scooter.

Researcher Ashen Chathuranga has demonstrated that such attacks can be executed quickly, enabling potential theft with ease. As of now, Yadea has not released a patch or provided an official comment regarding the vulnerability.

These findings underscore the need for heightened security measures in the design and operation of electric vehicles, as the potential for cyber threats continues to grow.

Security Week News Tags:Bluetooth hacking, Bluetooth security, CISA advisories, cyber threats, cybersecurity risks, electric motorcycles, firmware vulnerabilities, hacking threats, scooter vulnerabilities, technology news, transportation security, vehicle safety, wireless communication, Yadea scooters, Zero Motorcycles

Post navigation

Previous Post: Checkmarx Data Leak on Dark Web After Security Breach
Next Post: Silver Fox Threat Group Launches New Malware Campaign

Related Posts

Corma Secures M to Enhance Cybersecurity with AI Corma Secures $60M to Enhance Cybersecurity with AI Security Week News
SAP’s January 2026 Security Updates Patch Critical Vulnerabilities SAP’s January 2026 Security Updates Patch Critical Vulnerabilities Security Week News
New Campaigns Distribute Malware via Open Source Hacking Tools New Campaigns Distribute Malware via Open Source Hacking Tools Security Week News
Several Code Execution Flaws Patched in Veeam Backup & Replication Several Code Execution Flaws Patched in Veeam Backup & Replication Security Week News
AirSnitch Exposes Vulnerabilities in Wi-Fi Client Isolation AirSnitch Exposes Vulnerabilities in Wi-Fi Client Isolation Security Week News
Cisco Acquires WideField to Enhance Splunk’s SOC Cisco Acquires WideField to Enhance Splunk’s SOC Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Misuse in Yemen: Houthis Attempt Advanced Weapon Development
  • Critical Flaw in CSF on cPanel Allows Remote Command Execution
  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Misuse in Yemen: Houthis Attempt Advanced Weapon Development
  • Critical Flaw in CSF on cPanel Allows Remote Command Execution
  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark