✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Construction
Breach intelligence, attack campaigns, and threat reports targeting the Construction sector.
Explore Other Sectors
Construction Threat Reports
Bearlyfy's Custom GenieLocker Ransomware: A New Threat to Russian Enterprises
In March 2026, the pro-Ukrainian hacking group Bearlyfy, also known as Labubu, launched over 70 cyberattacks against Russian companies, primarily targeting the manufacturing sector. The group deployed a custom-built Windows ransomware strain named GenieLocker, marking a significant evolution from their previous use of third-party encryptors like LockBit 3 and Babuk. These attacks involved exploiting external services and vulnerable applications to gain access, followed by the deployment of tools such as MeshAgent for remote access and encryption. Ransom demands escalated to hundreds of thousands of dollars, with approximately 20% of victims reportedly paying. ([thehackernews.com](https://thehackernews.com/2026/03/bearlyfy-hits-70-russian-firms-with.html?utm_source=openai)) This incident underscores the increasing sophistication and boldness of hacktivist groups in leveraging custom malware to achieve both financial gain and strategic sabotage. The development and deployment of proprietary ransomware like GenieLocker highlight a trend where threat actors are investing in bespoke tools to enhance their operational effectiveness and evade detection. ([thehackernews.com](https://thehackernews.com/2026/03/bearlyfy-hits-70-russian-firms-with.html?utm_source=openai))
1 week ago
Kill Chain
Critical Vulnerabilities Discovered in Johnson Controls' C-CURE 9000 and Victor Application Servers
In July 2026, multiple critical vulnerabilities were identified in Johnson Controls' C-CURE 9000 and Victor application servers, widely used in physical security management. These vulnerabilities, including CVE-2026-21655, CVE-2026-21653, and CVE-2026-34496, could allow unauthenticated attackers to execute arbitrary code, perform server-side request forgery, and escalate privileges, potentially compromising physical security systems and sensitive data. ([johnsoncontrols.com](https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories?utm_source=openai)) The discovery of these vulnerabilities underscores the increasing targeting of critical infrastructure by cyber threats. Organizations must prioritize patching and implementing robust security measures to protect against such exploits, as the exploitation of these flaws could lead to significant operational disruptions and security breaches.
2 weeks ago
Kill Chain
Ransomware Surge in 2026: Understanding the 25% Increase and Its Implications
Between April 2025 and March 2026, ransomware incidents surged by 25%, with 7,551 known victims worldwide. This escalation was driven by the emergence of over 60 new ransomware groups and a significant increase in attacks targeting small and medium-sized businesses (SMBs). Notably, the Qilin ransomware group experienced a 443% year-over-year increase in activity, operating across more than 50 countries. The manufacturing sector remained the top target, accounting for 1,660 victims. ([gbhackers.com](https://gbhackers.com/2026-ransomware-report/?utm_source=openai)) This trend underscores the evolving threat landscape, where ransomware groups are becoming more operationalized, and the barriers to entry are lowering. Organizations must enhance their cybersecurity measures, focusing on patching known vulnerabilities, strengthening vendor oversight, and preparing for AI-driven threats. ([mbtmag.com](https://www.mbtmag.com/cybersecurity/news/22970998/report-addresses-evolving-state-of-ransomware?utm_source=openai))
2 weeks ago
Kill Chain
FBI Issues Warning on Fake Permit Fee Phishing Scam
In March 2026, the FBI issued a public alert regarding a sophisticated phishing campaign where cybercriminals impersonated city and county planning officials to defraud property owners. By leveraging publicly accessible permit records, these actors sent emails to individuals with active applications, demanding payments for fictitious permit fees via wire transfers, peer-to-peer transfers, or cryptocurrency. The emails were meticulously crafted, incorporating real permit details to enhance credibility, leading victims to authorize payments that bypassed traditional fraud detection mechanisms. This scheme resulted in significant financial losses and highlighted vulnerabilities in existing payment verification processes. The urgency of this issue is underscored by the rapid escalation of government impersonation scams, which nearly doubled in reported losses to approximately $798 million in 2025. The increasing sophistication of these attacks, particularly their ability to exploit publicly available data and evade standard fraud detection systems, necessitates immediate attention and the development of more robust security measures to protect individuals and businesses from such fraudulent activities.
3 weeks ago
Kill Chain
Iranian Hackers Target U.S. Industrial Control Systems in 2026
In early 2026, Iranian state-sponsored hackers launched a series of cyberattacks targeting U.S. critical infrastructure, focusing on industrial control systems (ICS) such as Rockwell Automation's Allen-Bradley programmable logic controllers (PLCs). These attacks exploited vulnerabilities in internet-exposed devices, leading to operational disruptions and potential safety hazards across sectors like water treatment and energy. ([nextgov.com](https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/?oref=ng-homepage-river&utm_source=openai)) This incident underscores the escalating threat landscape for ICS environments, highlighting the urgent need for organizations to secure operational technology assets against sophisticated nation-state actors. ([cybersecuritydive.com](https://www.cybersecuritydive.com/news/critical-infrastucture-plcs-iran-hacking-censys/817209/?utm_source=openai))
1 month ago
Kill Chain
Kubota Data Breach 2026: A Wake-Up Call for Industrial Cybersecurity
In early 2026, Kubota North America Corporation experienced a significant data breach where unauthorized actors accessed its network systems from March 16 to April 20. The intrusion led to the exposure of sensitive personal information belonging to employees and their dependents, including full names, Social Security numbers, dates of birth, taxpayer IDs, driver's license numbers, direct deposit bank account details, corporate payment card information, and benefits enrollment data. Kubota has since notified affected individuals and offered identity protection services to mitigate potential risks. This incident underscores the escalating threat landscape targeting industrial manufacturers, emphasizing the critical need for robust cybersecurity measures. The breach highlights the importance of proactive security protocols and continuous monitoring to safeguard sensitive employee data against unauthorized access and potential misuse.
1 month ago
Kill Chain
ARToken: The Next Evolution in BEC-as-a-Service Platforms
In April 2026, Cisco Talos identified ARToken, a sophisticated phishing platform linked to the EvilTokens phishing-as-a-service operation. ARToken is designed to bypass multi-factor authentication and compromise Microsoft 365 accounts, featuring advanced capabilities such as inbox rule manipulation and shared access links. The platform employs a seven-layer anti-analysis system to evade detection, and its phishing lures are highly targeted, often impersonating legitimate vendor communications to deceive accounts-payable staff into processing fraudulent invoices. The emergence of ARToken underscores a significant evolution in business email compromise (BEC) tactics, highlighting the increasing sophistication and accessibility of phishing-as-a-service platforms. This development poses a heightened risk to organizations, emphasizing the need for enhanced email security measures and employee vigilance against such targeted attacks.
1 month ago
Kill Chain
NetSPI's Social Engineering Assessment: Reporter Impersonation Phishing Attack
In a recent social engineering assessment, NetSPI's team simulated a targeted phishing attack against a client's executive leadership. By impersonating a journalist inquiring about alleged environmental violations, the team crafted a compelling pretext that led an executive to engage with a malicious link. This engagement not only compromised the executive but also extended to external contractors, highlighting the cascading risks of such attacks. The incident underscores the effectiveness of sophisticated social engineering tactics in bypassing traditional security measures and the critical need for comprehensive employee training and clear protocols for handling unsolicited inquiries. As social engineering attacks become increasingly sophisticated, organizations must prioritize regular security awareness training and establish clear procedures for verifying external communications to mitigate the risk of such breaches.
1 month ago
Kill Chain
'Lorem Ipsum' Malware Shifts to ClickFix Delivery in 2026
In May 2026, the operators of the 'Lorem Ipsum' malware campaign transitioned from using Trojanized Microsoft Teams installers to employing ClickFix lures hosted on compromised WordPress sites. This shift followed Microsoft's takedown of the Fox Tempest infrastructure, which had previously supplied the attackers with fraudulent Microsoft Trusted Signing certificates. The new delivery method involves fake browser update notifications that prompt users to execute malicious PowerShell commands, leading to the silent installation of the malware. This change significantly broadens the potential victim pool, as any visitor to the compromised sites is now at risk. The 'Lorem Ipsum' campaign is now believed to be linked to the Vice Society ransomware group, also known as Rapid Brigantine or Vanilla Tempest. Vice Society has a history of targeting sectors such as education, healthcare, and manufacturing, employing double extortion tactics by encrypting data and threatening to leak it unless a ransom is paid. The group's ability to rapidly adapt its delivery methods in response to disruptions underscores the evolving nature of cyber threats and the importance of robust, adaptive cybersecurity measures.
1 month ago
Kill Chain
Yarbo Mobile App Vulnerabilities Expose Robot Fleet to Remote Control
In June 2026, critical vulnerabilities were identified in Yarbo's Android and iOS mobile applications and cloud infrastructure. These flaws included hard-coded MQTT broker credentials and inadequate authorization controls, allowing unauthorized access to telemetry data and remote command execution on Yarbo's robotic devices. Exploitation of these vulnerabilities could lead to unauthorized control over the robot fleet and exposure of sensitive user information. Yarbo has since released updates to address these issues, urging users to update their applications to version 3.17.4 or later. This incident underscores the persistent risks associated with hard-coded credentials and misconfigured cloud services in IoT devices. As the adoption of connected devices continues to rise, ensuring robust security measures and regular updates is crucial to prevent unauthorized access and potential exploitation.
1 month ago
Kill Chain
OceanLotus Targets Vietnamese Investors via FireAnt Metakit Supply Chain Attack
Between mid-2024 and March 2026, the Vietnam-aligned threat actor OceanLotus (APT32) conducted cyber espionage campaigns targeting domestic entities. Notably, from October 2025 to March 2026, they executed a supply chain attack by compromising the update mechanism of FireAnt Metakit, a widely used stock investment platform in Vietnam. This allowed them to distribute the SPECTRALVIPER backdoor to a select group of investors, facilitating unauthorized access and data exfiltration. This incident underscores a strategic shift by OceanLotus towards domestic targets, highlighting the evolving threat landscape where nation-state actors exploit trusted software supply chains to infiltrate critical sectors. Organizations must enhance their software supply chain security and implement robust monitoring to detect such sophisticated attacks.
2 months ago
Kill Chain
Critical Vulnerability in ABB EIBPORT Devices Disclosed
In May 2026, ABB disclosed a critical vulnerability in its EIBPORT V3 KNX and KNX GSM devices, versions prior to 3.9.2. The flaw, identified as CVE-2021-22291, is a cross-site scripting (XSS) vulnerability that could allow attackers to access sensitive information and alter device configurations. ABB has released firmware updates to address this issue and recommends immediate application to mitigate potential risks. This incident underscores the persistent threat of web-based vulnerabilities in industrial control systems, emphasizing the need for continuous monitoring and timely patch management to protect critical infrastructure from evolving cyber threats.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports