The UK government has launched an investigation into whether over 2,500 Chinese-manufactured Yutong electric buses operating in the country could be remotely disabled by their manufacturer. This probe was initiated after authorities in Norway and Denmark discovered that similar Yutong buses in their countries had SIM-enabled telematics systems, which allowed for remote control of critical functions such as battery and power, raising concerns that the vehicles could be stopped or rendered inoperable from afar. The Department for Transport and the National Cyber Security Centre are leading the assessment to determine if UK buses are exposed to the same vulnerabilities.
The investigation follows reports that Norwegian and Danish authorities found remote diagnostic and control capabilities in these buses, potentially exposing vehicle controls to unauthorized access. The UK is now evaluating the risk that these remote-access features could pose to public safety and national infrastructure, particularly if exploited by a malicious actor or during geopolitical tensions. The findings could have significant implications for the security of critical transportation assets and the procurement of foreign-manufactured vehicles with embedded telematics technology.

Track how attackers are adapting to this technology.
7 events from the most recent confirmed update back to the earliest known activity.
The UK government began investigating whether telematics vulnerabilities in more than 2,500 Chinese-made Yutong electric buses could allow them to be remotely disabled. The probe followed similar concerns previously raised in Norway and Denmark.
North Korean APT group Konni, also known as APT37, was reported to be using spear-phishing and KakaoTalk malware propagation to abuse Google's Find Hub feature and remotely wipe Android devices in South Korea. The disclosure added new technical detail on the group's tactics.
OWASP published an updated Top 10 list of web application risks that adds categories covering software supply chain failures and vulnerability disclosure failures. The revision reflects changing priorities in application security.
Microsoft released security updates for 63 vulnerabilities, including a critical zero-day tracked as CVE-2025-62215. The release highlighted ongoing patch-management risks for defenders.
Hyundai AutoEver America disclosed a breach that may have exposed the data of approximately 2.7 million individuals. The roundup cites the incident as a newly reported large-scale exposure.
Authorities in Norway and Denmark previously found vulnerabilities in Chinese-made Yutong electric buses that raised concerns they could be remotely disabled. These findings preceded the UK's review of similar risks.
Conduent disclosed that it experienced a breach in January 2025. The company later said the incident is expected to cost at least $50 million and has triggered lawsuits and regulatory investigations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.