The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Chemical

Breach intelligence, attack campaigns, and threat reports targeting the Chemical sector.

20 threat reports
Page 1 of 2

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Chemical Threat Reports

Showing 1–12 / 20 reports
Critical lwIP MQTT Vulnerability Threatens Global Critical Infrastructure
Impact· HIGH

Critical lwIP MQTT Vulnerability Threatens Global Critical Infrastructure

A critical out-of-bounds write vulnerability (CVE-2026-87121) was discovered in the lwIP TCP/IP Stack MQTT Client Application versions 2.0.1 through 2.2.1, affecting industrial control systems across multiple critical infrastructure sectors worldwide. The vulnerability carries a CVSS score of 9.8 and enables remote attackers to achieve full code execution without authentication, potentially compromising devices in chemical, energy, healthcare, transportation, and water systems. The flaw was discovered by Shahriyar Jalayeri of ByteRay Ltd. and reported to CISA, with fixes available through the lwIP repository. This vulnerability highlights the growing threat landscape facing industrial IoT devices and embedded systems, as attackers increasingly target foundational networking components to gain persistent access to critical infrastructure networks.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical Copy Fail Vulnerability Exposes Siemens Industrial Control Systems
Impact· HIGH

Critical Copy Fail Vulnerability Exposes Siemens Industrial Control Systems

In September 2026, CISA disclosed CVE-2026-31431, known as the "Copy Fail" vulnerability, affecting multiple Siemens SIPLUS and SIMATIC industrial control products. The vulnerability stems from incorrect resource transfer between spheres in the Linux kernel's crypto subsystem, specifically in the algif_aead component. With a CVSS score of 7.8, the flaw allows local attackers with low privileges to potentially achieve high confidentiality, integrity, and availability impacts on affected systems. Siemens has released patches for most affected products, updating them to version 21.2.1 or later, while recommending specific countermeasures for products where fixes are not yet available. This incident highlights the growing sophistication of attacks targeting industrial control systems and the critical importance of maintaining updated security patches in operational technology environments. As industrial networks become increasingly connected and digitized, vulnerabilities like Copy Fail demonstrate the urgent need for comprehensive security frameworks that can protect critical infrastructure from both known and emerging threats.

4 days ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
AI Weaponizes PLC Exploits: How Claude Ported Critical Infrastructure Attacks
Impact· CRITICAL

AI Weaponizes PLC Exploits: How Claude Ported Critical Infrastructure Attacks

In September 2026, Forescout's Vedere Labs demonstrated how Anthropic's Claude AI successfully ported a pre-authentication remote code execution exploit targeting CVE-2021-31886 from one WAGO programmable logic controller model to another. The research consumed $535.74 in API costs over 8.5 hours to adapt an existing 750-852 exploit for the 750-831 controller, exploiting a stack-based buffer overflow in the Nucleus FTP server with a CVSS score of 9.8. The AI-assisted exploit development achieved code execution by sending network packets, though a subsequent attempt to create a command-and-control implant permanently bricked the target PLC by writing to flash memory. This research highlights the evolving threat landscape where AI tools are lowering the technical barriers for developing industrial control system exploits, coinciding with recent warnings from NSA, CISA, and FBI about AI-generated scripts targeting Siemens PLCs and ongoing attacks against water utility infrastructure.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Vulnerability in AVEVA Enterprise SCADA: CVE-2025-7639
Impact· HIGH

Critical Vulnerability in AVEVA Enterprise SCADA: CVE-2025-7639

In August 2026, AVEVA disclosed a critical vulnerability (CVE-2025-7639) in its Enterprise SCADA software, affecting versions up to 2025. This flaw allows authenticated users with 'DNA Authority - Operator' privileges to tamper with serialized data, potentially leading to code execution during deserialization under the 'DNA Apps' security group. Exploitation could result in unauthorized control over SCADA systems, posing significant risks to industrial operations. The vulnerability underscores the persistent threat of deserialization flaws in industrial control systems. Organizations are urged to assess their SCADA deployments, apply the recommended patches, and implement robust access controls to mitigate potential exploitation.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities in MZ Automation's lib60870: CVE-2026-61893 and CVE-2026-63033
Impact· MEDIUM

Critical Vulnerabilities in MZ Automation's lib60870: CVE-2026-61893 and CVE-2026-63033

In July 2026, MZ Automation's lib60870 library, widely used in industrial control systems, was found to have critical vulnerabilities identified as CVE-2026-61893 and CVE-2026-63033. These flaws, present in version 2.4.0, could be exploited by attackers to crash the parsing process, leading to a denial of service. The vulnerabilities stem from out-of-bounds read errors triggered by specially crafted IEC 60870-5-104 I-frames, allowing unauthorized access to memory beyond allocated buffers. ([windowsforum.com](https://windowsforum.com/security-alerts.84/cve-2026-16002-lib60870-2-4-1-fixes-scada-denial-of-service-risk.440185/?utm_source=openai)) Given the widespread deployment of lib60870 in critical infrastructure sectors such as energy, water, and manufacturing, these vulnerabilities pose significant operational risks. Organizations are urged to update to version 2.4.1 or later to mitigate potential threats. ([windowsforum.com](https://windowsforum.com/security-alerts.84/cve-2026-16002-lib60870-2-4-1-fixes-scada-denial-of-service-risk.440185/?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Schneider Electric IGSS Vulnerability CVE-2026-12927: Critical Update Required
Impact· HIGH

Schneider Electric IGSS Vulnerability CVE-2026-12927: Critical Update Required

In July 2026, Schneider Electric disclosed a high-severity out-of-bounds write vulnerability (CVE-2026-12927) in its IGSS Definition module, versions 18.0.0.26124 and prior. Exploitation of this flaw could allow attackers to execute arbitrary code by importing a malicious CGF file, potentially leading to data loss and loss of control over the SCADA system. The vulnerability was reported by Michael Heinzl and has been addressed in version 18.0.0.26125 of the IGSS Definition module. ([se.com](https://www.se.com/ww/en/work/support/cybersecurity/security-notifications/?utm_source=openai)) This incident underscores the critical importance of timely software updates in industrial control systems. As cyber threats targeting SCADA systems become more sophisticated, organizations must prioritize patch management and adhere to cybersecurity best practices to safeguard operational technology environments.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in MZ Automation's lib60870: CVE-2026-16002
Impact· HIGH

Critical Vulnerability in MZ Automation's lib60870: CVE-2026-16002

In July 2026, a critical out-of-bounds read vulnerability, identified as CVE-2026-16002, was discovered in MZ Automation's lib60870 versions up to and including 2.4.0. This flaw allows attackers to send specially crafted IEC 60870-5 messages, causing the parsing process to crash and resulting in a denial of service. The vulnerability is particularly concerning for industrial control systems in sectors like energy and water, where such disruptions can have significant operational impacts. ([vuldb.com](https://vuldb.com/cve/CVE-2026-16002?utm_source=openai)) The release of lib60870 version 2.4.1 addresses this vulnerability, emphasizing the importance of timely software updates in critical infrastructure. This incident underscores the ongoing need for robust security measures in industrial environments to prevent potential exploitation and service disruptions. ([lib60870.com](https://www.lib60870.com/?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Authentication Bypass in Frangoteam FUXA SCADA/HMI Software (CVE-2026-13207)
Impact· HIGH

Critical Authentication Bypass in Frangoteam FUXA SCADA/HMI Software (CVE-2026-13207)

In June 2026, a critical authentication bypass vulnerability (CVE-2026-13207) was identified in Frangoteam's FUXA SCADA/HMI software versions 1.3.1 and earlier. This flaw allows unauthenticated remote attackers to access sensitive user and role data by exploiting improper path normalization in the REST API. By manipulating URL paths with dot-segment sequences, attackers can bypass authentication checks and retrieve confidential information without credentials. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-13207?utm_source=openai)) This incident underscores the persistent risks associated with authentication bypass vulnerabilities in industrial control systems. As SCADA environments increasingly integrate web-based interfaces, ensuring robust authentication mechanisms becomes paramount to prevent unauthorized access and potential operational disruptions.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in Yokogawa FAST/TOOLS and CI Server Exposes Sensitive Information
Impact· HIGH

Critical Vulnerability in Yokogawa FAST/TOOLS and CI Server Exposes Sensitive Information

In June 2026, a critical vulnerability (CVE-2026-11833) was identified in Yokogawa's FAST/TOOLS and Collaborative Information Server (CI Server). The web server component of these systems could return HTTP responses containing sensitive configuration information without requiring authentication. This flaw, present in FAST/TOOLS versions R9.01 through R10.04 and CI Server versions R1.01 through R1.04, exposes system settings that attackers could exploit for further attacks. The vulnerability has been assigned a CVSS 4.0 score of 8.2, indicating high severity. This incident underscores the ongoing risks associated with cleartext transmission of sensitive information in industrial control systems. Organizations utilizing these Yokogawa products should prioritize applying the recommended updates to mitigate potential exploitation and enhance their cybersecurity posture.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in ABB AC500 V2 PLCs: CVE-2025-7745
Impact· MEDIUM

Critical Vulnerability in ABB AC500 V2 PLCs: CVE-2025-7745

In July 2025, a buffer over-read vulnerability, identified as CVE-2025-7745, was discovered in ABB's AC500 V2 programmable logic controllers (PLCs), affecting versions up to and including 2.5.2. This flaw could allow unauthorized access to fragments of previously transmitted Modbus telegrams, potentially exposing sensitive information. The vulnerability was reported by Reid Wightman of Dragos, Inc., and ABB released firmware version 2.5.3 to address the issue. The incident underscores the critical importance of timely patch management in industrial control systems (ICS). As cyber threats targeting ICS environments continue to evolve, organizations must remain vigilant in updating and securing their operational technology to prevent potential exploitation of such vulnerabilities.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ABB Automation Builder Gateway Vulnerability Exposes Industrial Control Systems
Impact· MEDIUM

ABB Automation Builder Gateway Vulnerability Exposes Industrial Control Systems

In February 2026, ABB disclosed a vulnerability (CVE-2024-41975) in its Automation Builder Gateway for Windows, affecting versions prior to 2.9.0. The gateway, by default, listens on all network adapters on port 1217, allowing unauthenticated remote access. This configuration enables attackers to scan for connected Programmable Logic Controllers (PLCs). While PLC user management typically prevents unauthorized access, if disabled, attackers could potentially interact with the PLCs. ABB addressed this issue in version 2.9.0 by restricting the gateway's default access to local connections. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-25-133-04?utm_source=openai)) This incident underscores the critical importance of secure default configurations in industrial control systems. As cyber threats targeting operational technology environments increase, organizations must ensure that default settings do not expose systems to unnecessary risks. Regularly updating software and reviewing default configurations are essential steps in mitigating such vulnerabilities.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Unveiling 'fast16': The Pre-Stuxnet Malware Targeting Engineering Software
Impact· HIGH

Unveiling 'fast16': The Pre-Stuxnet Malware Targeting Engineering Software

In April 2026, SentinelOne researchers uncovered 'fast16,' a previously undocumented Lua-based malware framework dating back to 2005. This sophisticated tool targeted high-precision engineering and physics simulation software, subtly altering calculations to introduce systematic errors. Unlike typical malware of its era, fast16 was engineered for strategic sabotage, potentially undermining scientific research and engineering projects without immediate detection. The discovery of fast16 highlights the advanced capabilities of state-sponsored cyber operations predating known incidents like Stuxnet. It underscores the long-standing use of cyber tools for covert sabotage, emphasizing the need for vigilance in protecting critical infrastructure and sensitive research from such sophisticated threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports