✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Construction
Breach intelligence, attack campaigns, and threat reports targeting the Construction sector.
Explore Other Sectors
Construction Threat Reports
Cybercriminals Exploit Government Data in Latin America: The 2026 Antel Breach
In May 2026, the cybercriminal group La Pampa Leaks claimed to have breached Uruguay's government-sponsored identity service, TuID, managed by the state-owned telecommunications company Antel. The attackers alleged prolonged access to the platform's infrastructure, potentially exposing sensitive personal data of Uruguayan citizens, including identification numbers, full names, birth dates, email addresses, phone numbers, residential addresses, biometric information, and digital signature data. Antel confirmed the cyberattack but stated that authentication credentials and highly sensitive data remained uncompromised. Immediate containment measures were implemented, and the incident was reported to the relevant authorities. This incident underscores a growing trend in Latin America, where cybercriminals increasingly target government agencies to monetize citizen data. The public-administration sector in the region has become the most-breached industry in the past year, highlighting the urgent need for enhanced cybersecurity measures and regulatory compliance to protect sensitive information.
2 months ago
Kill Chain
Critical Vulnerability in Carlson VASCO-B GNSS Receiver (CVE-2026-3893)
In April 2026, a critical vulnerability (CVE-2026-3893) was identified in Carlson Software's VASCO-B GNSS Receiver versions prior to 1.4.0. This flaw, due to missing authentication mechanisms, allows remote attackers to alter system configurations and disrupt device operations without requiring credentials. The vulnerability has a CVSS score of 9.4, indicating its severity, and primarily affects the Critical Manufacturing sector globally. ([socdefenders.ai](https://www.socdefenders.ai/item/3f9fa938-de90-494a-99b5-bc0ba05499a8?utm_source=openai)) The incident underscores the importance of securing GNSS receivers, which are integral to infrastructure operations. Organizations are advised to update to version 1.4.0 or later, minimize network exposure of control systems, implement firewalls, and use secure remote access methods like VPNs to mitigate potential risks. ([socdefenders.ai](https://www.socdefenders.ai/item/3f9fa938-de90-494a-99b5-bc0ba05499a8?utm_source=openai))
3 months ago
Kill Chain
Unveiling 'fast16': The Earliest Known Cyber Sabotage Tool
In April 2026, SentinelOne researchers uncovered 'fast16,' a previously undocumented malware framework dating back to 2005. This sophisticated tool was designed to subtly corrupt high-precision mathematical computations in engineering and scientific software by introducing near-imperceptible errors. The malware employed a 'cluster munition' delivery mechanism, deploying multiple 'wormlets' to propagate the main payload across target environments by exploiting vulnerabilities. This discovery predates the infamous Stuxnet by at least five years, marking 'fast16' as the earliest known cyber weapon aimed at sabotaging critical infrastructure through data integrity manipulation. The revelation of 'fast16' underscores the longstanding and evolving nature of state-sponsored cyber sabotage. It highlights the necessity for organizations, especially those handling sensitive and high-precision computations, to implement robust security measures and maintain vigilance against sophisticated threats that may have been active undetected for extended periods.
3 months ago
Kill Chain
Black Basta Affiliates Resurface with Targeted Social Engineering Attacks in 2026
In April 2026, a group of former Black Basta affiliates initiated a sophisticated social engineering campaign targeting over 100 employees across multiple organizations. The attackers employed mass email bombing and impersonated IT support via Microsoft Teams to gain unauthorized access to networks, aiming for data theft, ransomware deployment, and extortion. Notably, approximately 75% of the targets were senior executives, directors, and managers, indicating a strategic focus on high-privilege accounts. ([cyberscoop.com](https://cyberscoop.com/black-basta-affiliates-senior-executives-reliaquest/?utm_source=openai)) This resurgence underscores the persistent threat posed by disbanded cybercriminal groups reassembling or reusing effective tactics. The campaign's rapid execution and automation highlight the evolving sophistication of social engineering attacks, emphasizing the need for organizations to bolster their cybersecurity defenses and employee awareness programs. ([cyberscoop.com](https://cyberscoop.com/black-basta-affiliates-senior-executives-reliaquest/?utm_source=openai))
3 months ago
Kill Chain
FBI Issues Warning on Phishing Attacks Impersonating Local Government Officials
In March 2026, the FBI issued a warning about a phishing campaign where criminals impersonated U.S. city and county officials to target individuals and businesses applying for land-use permits. The attackers used publicly available information to craft convincing emails, instructing victims to pay fraudulent fees via wire transfer, peer-to-peer payment, or cryptocurrency. This scheme exploited the victims' trust in official communications, leading to financial losses and potential exposure of sensitive information. This incident underscores a growing trend of cybercriminals leveraging publicly accessible data to enhance the credibility of their phishing attacks. The increasing sophistication of such schemes highlights the urgent need for heightened vigilance and robust verification processes in all interactions involving sensitive transactions.
4 months ago
Kill Chain
ManoMano Data Breach 2026: Lessons in Third-Party Risk Management
In January 2026, French DIY e-commerce giant ManoMano experienced a significant data breach affecting approximately 38 million customers. The breach occurred when hackers compromised a third-party customer service provider, leading to unauthorized access to personal data, including full names, email addresses, phone numbers, and customer service communications. Notably, account passwords and financial information remained secure, as they were not stored with the subcontractor. Upon discovery, ManoMano promptly disabled the compromised account, initiated an internal investigation, and notified relevant authorities, including CNIL and ANSSI. The company also established a dedicated helpline for affected customers and issued warnings about potential phishing attempts leveraging the stolen data. This incident underscores the critical importance of securing third-party service providers, as supply chain vulnerabilities can lead to substantial data breaches. Organizations must rigorously assess and monitor the security practices of their subcontractors to prevent similar incidents. Additionally, customers are advised to remain vigilant against phishing attempts and verify the authenticity of communications purportedly from ManoMano or its partners.
5 months ago
Kill Chain
Critical Vulnerability in RISS SRL MOMA Seismic Station Firmware (CVE-2026-1632)
In February 2026, a critical vulnerability (CVE-2026-1632) was identified in RISS SRL's MOMA Seismic Station firmware versions up to and including v2.4.2520. The flaw exposes the device's web management interface without requiring authentication, allowing unauthenticated attackers to modify configuration settings, access sensitive data, or remotely reset the device. This vulnerability poses significant risks to seismic monitoring operations, potentially leading to data manipulation, unauthorized data access, and operational disruptions. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1632?utm_source=openai)) The absence of authentication mechanisms in critical infrastructure devices underscores the urgent need for robust security measures in industrial control systems. As cyber threats targeting operational technology (OT) environments increase, organizations must prioritize securing their OT assets to prevent potential exploitation and ensure the integrity of essential services.
5 months ago
Kill Chain
Schneider Electric EcoStruxure Rapsody Software Vulnerabilities Threaten Critical Infrastructure in 2026
In January 2026, Schneider Electric disclosed multiple critical software vulnerabilities (CVE-2025-13844, CVE-2025-13845) in its EcoStruxure Power Build Rapsody platform, widely used in the energy, manufacturing, and commercial facilities sectors. The flaws—specifically double free and use after free issues—stem from improper memory management when importing malicious project files, enabling local attackers to potentially execute arbitrary code. Impacted product versions are deployed worldwide. Schneider Electric and independent security researchers reported these vulnerabilities, urging customers to upgrade immediately or apply mitigations to prevent unauthorized system access and memory corruption. This incident highlights the continued threat posed by software supply chain attacks and memory corruption vulnerabilities in critical infrastructure environments. As attackers shift towards exploiting insecure file imports and legacy software flaws, organizations must prioritize secure software lifecycle management and timely patching to counter emerging risks.
6 months ago
Kill Chain
Ukrainian Ransomware Operator Pleads Guilty in Global Nefilim Extortion Case
Between 2018 and 2021, Artem Aleksandrovych Stryzhak, a Ukrainian national, orchestrated a series of targeted ransomware attacks against high-revenue organizations in the United States and Europe using the Nefilim ransomware strain. The attacks involved gaining unauthorized access to victim networks, exfiltrating sensitive data, and deploying custom ransomware executables, each with unique ransom notes and decryption keys. Victims included companies across multiple sectors such as engineering, aviation, chemicals, insurance, construction, and energy. Stryzhak, arrested in Spain in June 2024 and extradited to the U.S., pleaded guilty to conspiracy to commit fraud and faces up to 10 years in prison. His accomplice, Volodymyr Tymoshchuk, remains at large amid ongoing law enforcement efforts. The incident underscores the operational sophistication of modern ransomware groups, particularly in tailoring attacks to maximize extortion and impact. With financial and reputational damages in the millions, this case highlights the persistent threat of ransomware and the necessity for robust east-west network security, multifactor identity controls, and anomaly detection across the enterprise attack surface.
6 months ago
Kill Chain
Cloud Atlas 2025: APT Espionage Hits Russian and Belarusian Organizations via Cloud-Based Implants
In the first half of 2025, the persistent threat group Cloud Atlas launched a series of sophisticated cyber-espionage campaigns targeting organizations in Russia and Belarus. Attackers employed spear-phishing emails with weaponized Microsoft Office documents exploiting CVE-2018-0802, initiating a complex multi-stage infection chain. Custom implants such as VBShower, VBCloud, CloudAtlas, and PowerShower enabled attackers to establish persistent access, exfiltrate sensitive data, steal credentials, and abuse cloud-based C2 channels. Multiple sectors were affected, including telecommunications, construction, government, and manufacturing, with operations characterized by stealthy lateral movement, DLL hijacking, and multi-layered payload delivery. This incident is significant due to Cloud Atlas's use of novel, previously undocumented toolsets and cloud service abuse, reflecting a trend among APT actors toward cloud-based, modular attacks. It highlights the urgent need for heightened east-west security, advanced threat visibility, and multi-layered cloud controls, amid continued evolution of state-sponsored threat tactics.
6 months ago
Kill Chain
How Zigbee Protocol Flaws Exposed Industrial IoT Networks in 2024
In early 2024, security researchers uncovered critical vulnerabilities affecting Zigbee-based industrial IoT and automation environments. By assessing real-world installations, attackers demonstrated how both spoofed packet injection and coordinator impersonation attacks could exploit application-layer protocol weaknesses and misconfigurations. Notably, exposed or hard-coded keys, absence of end-to-end encryption, and insecure default settings enabled adversaries to hijack communications, control relay devices, and ultimately compromise entire sensor networks. The attack techniques bypassed traditional network segmentation and leveraged custom wireless tools to overcome timing and profile mismatches. This incident highlights urgent gaps in IoT and industrial security — especially the risks posed by legacy or proprietary protocol deployments lagging on best-practice cryptographic implementation. With industrial sectors increasingly reliant on automated sensor networks, attackers are expanding TTPs to target low-power wireless protocols like Zigbee, making advanced monitoring and zero trust approaches more critical than ever.
6 months ago
Kill Chain
Siemens Building X Firmware Supply Chain Flaw: Risks and Mitigation
In December 2025, Siemens disclosed a critical vulnerability in its Building X - Security Manager Edge Controller (ACC-AP), affecting all firmware versions. The flaw, tracked as CVE-2022-31807, is an improper verification of cryptographic signature that enables a local—or, in some cases, remote—attacker to upload maliciously altered firmware to the device. This could be exploited by an individual with physical access or by intercepting firmware updates, introducing risks to device integrity and broadening the attack surface in critical manufacturing environments. Siemens has issued operational mitigations but no permanent patch is planned. This incident highlights increasing attention on firmware supply chain vulnerabilities across operational technology (OT) in critical infrastructure. Insecure update mechanisms are a prime target for actors seeking persistent access or sabotage, echoing a trend that is prompting regulators and organizations to strengthen controls—especially amid rising regulatory scrutiny and high-profile supply chain breaches.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports