Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Security Concerns Emerge for Electric Bikes and Scooters

Security Concerns Emerge for Electric Bikes and Scooters

Posted on April 28, 2026 By CWS

Electric motorcycles manufactured by Zero Motorcycles and scooters from Yadea have been found to contain vulnerabilities that could affect both security and rider safety. Recent advisories from the Cybersecurity and Infrastructure Security Agency (CISA) highlight these risks, drawing attention to potential real-world consequences.

Vulnerabilities in Zero Motorcycles

Zero Motorcycles, a US-based manufacturer, has been identified with a Bluetooth vulnerability in its electric motorcycles. This flaw, cataloged as CVE-2026-1354, affects firmware versions up to 44. Researchers from Bureau Veritas Cybersecurity have discovered that an attacker could exploit this weakness to gain unauthorized access and upload malicious firmware to the motorcycle.

The vulnerability is classified as ‘medium severity’ by CISA due to the complexity involved in executing an attack. Dinesh Shetty, who leads security engineering at Bureau Veritas, explained that an attacker must be within Bluetooth range and understand the device’s pairing process to succeed. This allows the attacker to pair their device and potentially control critical functions of the motorcycle.

Potential Impacts of Bluetooth Exploitation

Once the malicious firmware is installed, the attacker can manipulate various safety-critical functions, such as torque output and braking systems, posing significant risks at high speeds. Even more concerning is the possibility of remote command-and-control through the bike’s cellular modem, which adds a layer of complexity to the potential threat.

In response, CISA has advised users to pair their motorcycles in secure locations while waiting for a firmware patch expected in May. Despite these developments, Zero Motorcycles has yet to issue a public response.

Yadea T5 Scooter Vulnerability

Another noteworthy vulnerability affects the T5 scooter by Yadea, a Chinese company. This issue, identified as CVE-2025-70994 and deemed ‘high severity’, allows attackers to intercept commands sent between the scooter and its key fob. By capturing a legitimate command, such as locking the scooter, attackers can generate unauthorized commands to unlock or even start the scooter.

Researcher Ashen Chathuranga has demonstrated that such attacks can be executed quickly, enabling potential theft with ease. As of now, Yadea has not released a patch or provided an official comment regarding the vulnerability.

These findings underscore the need for heightened security measures in the design and operation of electric vehicles, as the potential for cyber threats continues to grow.

Security Week News Tags:Bluetooth hacking, Bluetooth security, CISA advisories, cyber threats, cybersecurity risks, electric motorcycles, firmware vulnerabilities, hacking threats, scooter vulnerabilities, technology news, transportation security, vehicle safety, wireless communication, Yadea scooters, Zero Motorcycles

Post navigation

Previous Post: Checkmarx Data Leak on Dark Web After Security Breach
Next Post: Silver Fox Threat Group Launches New Malware Campaign

Related Posts

Vibe Coding: When Everyone’s a Developer, Who Secures the Code? Vibe Coding: When Everyone’s a Developer, Who Secures the Code? Security Week News
Ransomware Attack Targets Advantest’s Network Ransomware Attack Targets Advantest’s Network Security Week News
Scattered Spider Suspect Arrested in US Scattered Spider Suspect Arrested in US Security Week News
Cybersecurity M&A Roundup: 41 Deals Announced in June 2025 Cybersecurity M&A Roundup: 41 Deals Announced in June 2025 Security Week News
Thirteen Romanians Arrested for Phishing the UK’s Tax Service Thirteen Romanians Arrested for Phishing the UK’s Tax Service Security Week News
Production at Steelmaker Nucor Disrupted by Cyberattack Production at Steelmaker Nucor Disrupted by Cyberattack Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitHub’s NPM 12 Blocks Script Execution to Enhance Security
  • China-Linked JDY Botnet Expands to Over 1,500 Devices
  • GitHub to Restrict npm Scripts by Default to Enhance Security
  • Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution
  • BugHunter Toolkit Enhances Vulnerability Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitHub’s NPM 12 Blocks Script Execution to Enhance Security
  • China-Linked JDY Botnet Expands to Over 1,500 Devices
  • GitHub to Restrict npm Scripts by Default to Enhance Security
  • Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution
  • BugHunter Toolkit Enhances Vulnerability Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark