Intelligent connected vehicles (ICVs) integrate dozens of electronic control units, advanced driver-assistance systems, and vehicle-to-everything (V2X) communication, creating an expanded attack surface that directly threatens functional safety. Automotive cybersecurity incidents numbered 422 CVEs in 2024 alone, with 60% affecting thousands to millions of assets simultaneously. Despite this growing risk, existing intrusion detection approaches share three structural gaps: reliance on single-source monitoring that misses coordinated multi-vector attacks; absence of formal coupling between cybersecurity threat severity and functional safety constraints; and dependence on reactive, externally commanded responses rather than endogenous self-organizing mechanisms.An Endogenous Threat Recognition and Hazard Mitigation (ETRHM) framework is proposed to address these gaps. A Polygene Threat Recognition Network (PTR-Net) fuses CAN bus traffic, V2X messages, and application-layer telemetry through hierarchical cross-source attention, enabling detection of coordinated attacks invisible to single-source methods. An Endogenous Adversarial Mechanism (EAM) couples detected threat severity to functional safety constraints through a Lyapunov-stable feedback loop, adapting defense strategies autonomously in real time. A Hazard Mitigation Maneuver (HMM) then executes a four-phase resilience protocol—prevention, resistance, recovery, and adaptation—to drive the vehicle to a Minimal Risk Condition (MRC). Formal proofs establish asymptotic stability of MRC and bound the recovery time.Experiments conducted on an NXP S32G399A ASIL-D automotive controller using real vehicle network traffic demonstrate an AUC of 0.953 and a 26.5% reduction in time-to-MRC (4.9s to 3.6s) relative to the strongest baseline, with an end-to-end detection-to-response latency of 8.1ms—within the 10ms automotive control cycle constraint.