The Containment Era is here. →Explore

Industry Category

Electrical/Electronic Manufacturing

Breach intelligence, attack campaigns, and threat reports targeting the Electrical/Electronic Manufacturing sector.

52 threat reports
Page 3 of 5

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Electrical/Electronic Manufacturing Threat Reports

Showing 2536 / 52 reports
Vect 2.0 Ransomware: A Flawed Threat Acting as a Data Wiper
Impact· CRITICAL

Vect 2.0 Ransomware: A Flawed Threat Acting as a Data Wiper

In April 2026, the Vect 2.0 ransomware variant was discovered to contain a critical design flaw that causes it to function as a data wiper rather than traditional ransomware. This flaw affects versions targeting Windows, Linux, and VMware ESXi systems. Specifically, for files larger than 128KB, the malware generates four encryption nonces but only retains the final one, rendering the first three-quarters of each large file permanently unrecoverable. Consequently, victims who pay the ransom cannot retrieve their critical data, as the necessary decryption information is irreversibly lost. ([darkreading.com](https://www.darkreading.com/threat-intelligence/vect-ransomware-wiper-design-error?utm_source=openai)) This incident underscores the evolving nature of cyber threats, where even ransomware can inadvertently become more destructive due to coding errors. Organizations must prioritize robust backup strategies and comprehensive security measures to mitigate such risks. The Vect 2.0 case also highlights the importance of thorough threat analysis and the potential unintended consequences of malware development flaws.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Authentication Bypass Vulnerability in Siemens SINEC NMS (CVE-2026-24032)
Impact· HIGH

Critical Authentication Bypass Vulnerability in Siemens SINEC NMS (CVE-2026-24032)

In April 2026, Siemens disclosed a critical authentication bypass vulnerability (CVE-2026-24032) in its SINEC NMS software, specifically within the User Management Component (UMC). This flaw allows unauthenticated remote attackers to bypass authentication mechanisms, potentially granting unauthorized access to network management functionalities. The vulnerability affects all versions of SINEC NMS prior to V4.0 SP3. Siemens has released an updated version to address this issue and strongly recommends users to upgrade promptly. This incident underscores the persistent risks associated with authentication weaknesses in critical infrastructure management systems. Organizations are urged to assess their network management tools for similar vulnerabilities and to implement robust access controls to mitigate potential exploitation.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in Delta Electronics COMMGR2: CVE-2026-3630
Impact· CRITICAL

Critical Vulnerability in Delta Electronics COMMGR2: CVE-2026-3630

In March 2026, Delta Electronics disclosed a critical stack-based buffer overflow vulnerability (CVE-2026-3630) in their COMMGR2 software, widely used in industrial automation. This flaw allows unauthenticated remote attackers to execute arbitrary code, potentially leading to full system compromise. The vulnerability affects COMMGR2 versions up to and including 2.11.0. Delta Electronics has released a security advisory (Delta-PCSA-2026-00005) detailing the issue and providing mitigation steps. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-3630?utm_source=openai)) The disclosure underscores the persistent risks in industrial control systems and the importance of timely patching. Organizations in manufacturing, energy, and logistics sectors should prioritize updating affected systems to prevent potential exploitation. ([praetorian.com](https://www.praetorian.com/blog/cve-2026-3630/?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities in Schneider Electric's Plant iT/Brewmaxx Systems: Immediate Action Required
Impact· CRITICAL

Critical Vulnerabilities in Schneider Electric's Plant iT/Brewmaxx Systems: Immediate Action Required

In March 2026, Schneider Electric disclosed multiple critical vulnerabilities in its Plant iT/Brewmaxx systems, stemming from the integration of Redis, an open-source in-memory database. These vulnerabilities, identified as CVE-2025-49844, CVE-2025-46817, CVE-2025-46818, and CVE-2025-46819, involve issues such as use-after-free errors and integer overflows within Redis's Lua scripting engine. Exploitation of these flaws could allow authenticated users to execute arbitrary code, leading to potential remote code execution and privilege escalation. The affected versions include Plant iT/Brewmaxx 9.60 and above. Schneider Electric has released patches and provided mitigation steps to address these vulnerabilities. ([se.com](https://www.se.com/in/en/download/document/SEVD-2026-013-01/?utm_source=openai)) The disclosure underscores the critical importance of securing third-party components within industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, organizations must remain vigilant, ensuring timely updates and adherence to cybersecurity best practices to mitigate potential risks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Warlock Ransomware Group's 2025 Exploitation of SharePoint Vulnerabilities
Impact· CRITICAL

Warlock Ransomware Group's 2025 Exploitation of SharePoint Vulnerabilities

In mid-2025, the Warlock ransomware group exploited unpatched Microsoft SharePoint servers to gain initial access to various organizations across North America, Europe, Asia, and Africa. Utilizing known vulnerabilities (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771), they deployed web shells via HTTP POST requests, enabling reconnaissance, credential theft, and lateral movement. The attack culminated in the deployment of ransomware, encrypting files with the .x2anylock extension and exfiltrating data using RClone. ([clearphish.ai](https://www.clearphish.ai/news/warlock-ransomware-sharepoint-attacks-2025?utm_source=openai)) This incident underscores the critical importance of timely patch management, especially for widely used enterprise applications like SharePoint. The Warlock group's rapid escalation from forum discussions to impactful campaigns highlights the evolving threat landscape and the need for organizations to bolster their cybersecurity defenses against sophisticated ransomware operations.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Delta Electronics CNCSoft-G2 2026 Out-of-Bounds Write Vulnerability
Impact· HIGH

Delta Electronics CNCSoft-G2 2026 Out-of-Bounds Write Vulnerability

In March 2026, Delta Electronics identified a critical vulnerability (CVE-2026-3094) in its CNCSoft-G2 software, specifically an out-of-bounds write issue in the DOPSoft component's DPAX file parsing. This flaw allows attackers to execute arbitrary code if a user opens a maliciously crafted file, potentially compromising system integrity. The vulnerability affects CNCSoft-G2 versions prior to V2.1.0.39. Delta Electronics has released version 2.1.0.39 to address this issue and recommends users update promptly. This incident underscores the persistent risks associated with file parsing vulnerabilities in industrial control systems, emphasizing the need for regular software updates and vigilant cybersecurity practices to protect critical infrastructure.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities in Mitsubishi Electric's MELSEC iQ-F Series Expose Industrial Systems to Denial-of-Service Attacks
Impact· HIGH

Critical Vulnerabilities in Mitsubishi Electric's MELSEC iQ-F Series Expose Industrial Systems to Denial-of-Service Attacks

In March 2026, Mitsubishi Electric disclosed multiple vulnerabilities in their MELSEC iQ-F Series EtherNet/IP and Ethernet modules, specifically FX5-ENET/IP and FX5-EIP models. These flaws, identified as CVE-2026-1874, CVE-2026-1875, and CVE-2026-1876, allow remote attackers to induce denial-of-service conditions by continuously sending UDP packets, rendering the devices unresponsive until a system reset is performed. The vulnerabilities affect FX5-ENET/IP versions up to 1.106 and all versions of FX5-EIP. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1874?utm_source=openai)) This incident underscores the critical need for robust network security measures in industrial control systems, as such vulnerabilities can disrupt essential operations in critical manufacturing sectors worldwide. Organizations are advised to implement recommended mitigations, including updating firmware where available and employing network defenses to prevent unauthorized access. ([cyber.gc.ca](https://www.cyber.gc.ca/en/alerts-advisories/control-systems-mitsubishi-electric-security-advisory-av26-191?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Advantest 2026 Ransomware Attack: A Wake-Up Call for Semiconductor Cybersecurity
Impact· HIGH

Advantest 2026 Ransomware Attack: A Wake-Up Call for Semiconductor Cybersecurity

In February 2026, Advantest Corporation, a leading Japanese semiconductor test equipment manufacturer, detected unauthorized access within its IT environment, indicating a ransomware attack. The company promptly activated incident response protocols, isolated affected systems, and engaged third-party cybersecurity experts to investigate and contain the incident. Preliminary findings suggest that an unauthorized third party may have gained access to portions of the company's network and deployed ransomware. The full extent of the impact, including potential compromise of customer or employee data, is under active investigation. ([advantest.com](https://www.advantest.com/en/news/2026/20260219.html?utm_source=openai)) This incident underscores the escalating threat of ransomware attacks targeting critical infrastructure within the semiconductor industry. As adversaries increasingly focus on high-value targets, organizations must enhance their cybersecurity measures to protect sensitive data and maintain operational continuity.

5 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
ShinyHunters' 2026 Attack: Exploiting OAuth Device Code Flow in Microsoft Entra
Impact· HIGH

ShinyHunters' 2026 Attack: Exploiting OAuth Device Code Flow in Microsoft Entra

In early 2026, the cybercriminal group ShinyHunters orchestrated a sophisticated attack targeting Microsoft Entra accounts. By combining device code phishing with voice phishing (vishing), they exploited the OAuth 2.0 Device Authorization flow. Attackers generated legitimate device codes and, through impersonation of IT staff, convinced employees to enter these codes on authentic Microsoft login pages. This manipulation granted the attackers valid authentication tokens, enabling unauthorized access to victims' accounts and associated Single Sign-On (SSO) applications, including Microsoft 365, Salesforce, and Google Workspace. The breach led to significant data exfiltration and subsequent extortion attempts. This incident underscores a concerning evolution in phishing tactics, moving beyond traditional credential theft to the exploitation of trusted authentication processes. The success of such attacks highlights the pressing need for organizations to adopt phishing-resistant multi-factor authentication (MFA) methods and to enhance employee awareness regarding emerging social engineering techniques.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Delta Electronics ASDA-Soft Vulnerability Exposes Critical Systems to Risk
Impact· CRITICAL

Delta Electronics ASDA-Soft Vulnerability Exposes Critical Systems to Risk

In January 2026, Delta Electronics disclosed a critical stack-based buffer overflow vulnerability (CVE-2026-1361) in their ASDA-Soft software, versions up to 7.2.0.0. This flaw allows attackers to write arbitrary data beyond the bounds of a stack-allocated buffer, potentially leading to the corruption of a structured exception handler (SEH). Exploitation requires local access and user interaction, but no prior authentication, posing significant risks to confidentiality, integrity, and availability. Delta Electronics has released version 7.2.2.0 to address this issue. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1361?utm_source=openai)) This incident underscores the persistent threat of buffer overflow vulnerabilities in industrial control systems, emphasizing the need for rigorous input validation and timely software updates to mitigate potential exploits.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Pwn2Own Automotive 2026: Hackers Expose Record 76 Zero-Days in Cars, Chargers & Tesla
Impact· high

Pwn2Own Automotive 2026: Hackers Expose Record 76 Zero-Days in Cars, Chargers & Tesla

Between January 21–23, 2026, the Pwn2Own Automotive competition in Tokyo saw security researchers demonstrate a record-breaking 76 zero-day vulnerabilities across in-vehicle infotainment systems (IVIs), electric vehicle chargers, and automotive operating systems, including high-profile exploits against Tesla, Alpitronic, Autel, Kenwood, and other leading manufacturers. Teams leveraged physical and remote attack vectors, with notable attacks including USB-based chaining to breach Tesla’s infotainment system. The event awarded $1,047,000 in prizes, underscoring significant risks within connected automotive infrastructure. Vendors now have 90 days to issue security patches before public disclosure. This incident highlights a concerning rise in exploitable vulnerabilities within rapidly digitalizing automotive ecosystems. As vehicles integrate more software-driven services and connected devices, adversaries and researchers alike are increasingly shifting focus toward automotive cyberattacks—driving new urgency for robust segmentation, secure update mechanisms, and continuous monitoring.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
INC Ransomware OpSec Fail Uncovers Data from 12 U.S. Organizations
Impact· high

INC Ransomware OpSec Fail Uncovers Data from 12 U.S. Organizations

In January 2026, an operational security lapse in the INC ransomware group's infrastructure enabled Cyber Centaurs researchers to recover encrypted data exfiltrated from twelve U.S. organizations. The investigation began after a RainINC ransomware attack on a client’s production SQL Server. Forensic analysis traced renamed binaries, PowerShell scripts, and usage of the Restic backup tool, revealing attacker scripts with hardcoded credentials and references to persistent cloud storage. By enumerating the attacker-controlled repositories, researchers identified encrypted data from healthcare, manufacturing, technology, and services firms, then decrypted and preserved it in coordination with law enforcement. This case highlights a rare opportunity where attacker mistakes allowed post-breach data retrieval for unrelated victim organizations. The incident underscores a growing trend in ransomware operations leveraging legitimate backup and exfiltration tools, persistent attacker infrastructure, and the importance of thorough incident response for uncovering wider impacts.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports