AGP Picks
View all

VicOne and CYMETRIS link vulnerability intelligence to vehicle risk decisions

Sep. 23, 2026
By AI, Created 08:57 UTC, Sep 23, 2026, AGP -

VicOne and CYMETRIS have integrated xZETA and the CYMETRIS platform to help automakers and suppliers decide which newly disclosed vulnerabilities affect specific vehicle programs. The bidirectional setup connects SBOM and vulnerability intelligence with vehicle architecture and TARA records as AI speeds up disclosure volume.

Why it matters: - Automotive security teams are facing more vulnerability disclosures and need to separate relevant threats from noise. - The integration is designed to turn generic CVE data into vehicle-specific risk decisions. - The workflow aims to reduce manual handoffs between vulnerability management, PSIRT, and engineering teams. - The setup also supports traceable evidence for ISO/SAE 21434 and UN R155 work.

What happened: - VicOne and CYMETRIS announced an integration of VicOne xZETA and the CYMETRIS platform. - The announcement came Tuesday in Munich, Germany. - The companies said the integration helps automotive OEMs and suppliers identify which newly disclosed vulnerabilities matter to a specific vehicle program. - The system also helps teams understand vulnerability impact in the vehicle architecture and revisit risk decisions as software and threats change.

The details: - VicOne xZETA provides continuous automotive vulnerability and SBOM intelligence. - CYMETRIS evaluates relevant findings against the vehicle architecture. - The combined process reassesses attack paths, controls, damage scenarios, and risk ratings. - A bidirectional API bridge sends relevant findings from xZETA to linked CYMETRIS projects. - CYMETRIS maps those findings to affected assets and electronic control units, or ECUs. - CYMETRIS also assesses whether existing controls could be bypassed. - The platform maintains a traceable record of treatment decisions. - Architecture context flows back to xZETA so findings can be evaluated against the system model instead of a flat component list. - VicOne xZETA generates and maintains SBOMs in standard formats. - VicOne xZETA identifies vulnerabilities beyond generic CVE feeds. - VicOne Vulnerability Impact Rating, or VVIR, prioritizes findings using the customer’s software inventory and automotive context. - VVIR is supported by VicOne research and zero-day intelligence from TrendAI Zero Day Initiative. - CYMETRIS maps assets, threats, attack paths, and controls to system architecture. - The CYMETRIS platform supports visual attack-path analysis, circumvent-path modeling, continuous risk analysis, and vertical TARA collaboration between OEMs and suppliers. - The companies said the combined workflow can filter non-applicable vulnerabilities before they reach engineering teams. - The workflow can also identify affected vehicle programs, ECUs, attack paths, and damage scenarios. - The integration helps teams see where shared components appear across multiple vehicle programs. - The companies said the system helps maintain a documented basis for prioritization and treatment decisions. - The workflow can align PSIRT and cybersecurity engineering around one data model. - The integration supports evidence management for ISO/SAE 21434 and UN R155 activities. - Organizations can update and version the risk model when a relevant vulnerability or architecture change occurs while retaining traceability across development, start of production, and field operations.

Between the lines: - The push reflects a broader shift from vulnerability counting to vulnerability triage based on real vehicle exposure. - The companies are positioning Live TARA as a practical response to faster-moving software and threat updates. - VicOne and CYMETRIS are betting that automotive security workflows need architecture-aware automation, not spreadsheet-based coordination. - VicOne pointed to broader disclosure growth, citing an Epoch AI analysis that 21 major technology organizations disclosed about 2,500 high- and critical-severity CVEs in July 2026, about 60% more than June and roughly five times the monthly high before April 2026.

What's next: - VicOne and CYMETRIS will jointly demonstrate the integration at ELIV 2026 on Oct. 14-15 in Baden-Baden, Germany. - The companies will also demo the setup at it-sa Expo&Congress 2026 on Oct. 27-29 in Nuremberg. - Attendees can see the integration at it-sa in Hall 7, Booth 7-402.

The bottom line: - The partnership tries to make vulnerability response more precise by tying new CVEs to the actual vehicle architecture, not just the software bill of materials.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

Central Europe

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Central Europe

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.