✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Electrical/Electronic Manufacturing
Breach intelligence, attack campaigns, and threat reports targeting the Electrical/Electronic Manufacturing sector.
Explore Other Sectors
Electrical/Electronic Manufacturing Threat Reports
Vect 2.0 Ransomware: A Flawed Threat Acting as a Data Wiper
In April 2026, the Vect 2.0 ransomware variant was discovered to contain a critical design flaw that causes it to function as a data wiper rather than traditional ransomware. This flaw affects versions targeting Windows, Linux, and VMware ESXi systems. Specifically, for files larger than 128KB, the malware generates four encryption nonces but only retains the final one, rendering the first three-quarters of each large file permanently unrecoverable. Consequently, victims who pay the ransom cannot retrieve their critical data, as the necessary decryption information is irreversibly lost. ([darkreading.com](https://www.darkreading.com/threat-intelligence/vect-ransomware-wiper-design-error?utm_source=openai)) This incident underscores the evolving nature of cyber threats, where even ransomware can inadvertently become more destructive due to coding errors. Organizations must prioritize robust backup strategies and comprehensive security measures to mitigate such risks. The Vect 2.0 case also highlights the importance of thorough threat analysis and the potential unintended consequences of malware development flaws.
2 months ago
Kill Chain
Critical Authentication Bypass Vulnerability in Siemens SINEC NMS (CVE-2026-24032)
In April 2026, Siemens disclosed a critical authentication bypass vulnerability (CVE-2026-24032) in its SINEC NMS software, specifically within the User Management Component (UMC). This flaw allows unauthenticated remote attackers to bypass authentication mechanisms, potentially granting unauthorized access to network management functionalities. The vulnerability affects all versions of SINEC NMS prior to V4.0 SP3. Siemens has released an updated version to address this issue and strongly recommends users to upgrade promptly. This incident underscores the persistent risks associated with authentication weaknesses in critical infrastructure management systems. Organizations are urged to assess their network management tools for similar vulnerabilities and to implement robust access controls to mitigate potential exploitation.
3 months ago
Kill Chain
Critical Vulnerability in Delta Electronics COMMGR2: CVE-2026-3630
In March 2026, Delta Electronics disclosed a critical stack-based buffer overflow vulnerability (CVE-2026-3630) in their COMMGR2 software, widely used in industrial automation. This flaw allows unauthenticated remote attackers to execute arbitrary code, potentially leading to full system compromise. The vulnerability affects COMMGR2 versions up to and including 2.11.0. Delta Electronics has released a security advisory (Delta-PCSA-2026-00005) detailing the issue and providing mitigation steps. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-3630?utm_source=openai)) The disclosure underscores the persistent risks in industrial control systems and the importance of timely patching. Organizations in manufacturing, energy, and logistics sectors should prioritize updating affected systems to prevent potential exploitation. ([praetorian.com](https://www.praetorian.com/blog/cve-2026-3630/?utm_source=openai))
3 months ago
Kill Chain
Critical Vulnerabilities in Schneider Electric's Plant iT/Brewmaxx Systems: Immediate Action Required
In March 2026, Schneider Electric disclosed multiple critical vulnerabilities in its Plant iT/Brewmaxx systems, stemming from the integration of Redis, an open-source in-memory database. These vulnerabilities, identified as CVE-2025-49844, CVE-2025-46817, CVE-2025-46818, and CVE-2025-46819, involve issues such as use-after-free errors and integer overflows within Redis's Lua scripting engine. Exploitation of these flaws could allow authenticated users to execute arbitrary code, leading to potential remote code execution and privilege escalation. The affected versions include Plant iT/Brewmaxx 9.60 and above. Schneider Electric has released patches and provided mitigation steps to address these vulnerabilities. ([se.com](https://www.se.com/in/en/download/document/SEVD-2026-013-01/?utm_source=openai)) The disclosure underscores the critical importance of securing third-party components within industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, organizations must remain vigilant, ensuring timely updates and adherence to cybersecurity best practices to mitigate potential risks.
4 months ago
Kill Chain
Warlock Ransomware Group's 2025 Exploitation of SharePoint Vulnerabilities
In mid-2025, the Warlock ransomware group exploited unpatched Microsoft SharePoint servers to gain initial access to various organizations across North America, Europe, Asia, and Africa. Utilizing known vulnerabilities (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771), they deployed web shells via HTTP POST requests, enabling reconnaissance, credential theft, and lateral movement. The attack culminated in the deployment of ransomware, encrypting files with the .x2anylock extension and exfiltrating data using RClone. ([clearphish.ai](https://www.clearphish.ai/news/warlock-ransomware-sharepoint-attacks-2025?utm_source=openai)) This incident underscores the critical importance of timely patch management, especially for widely used enterprise applications like SharePoint. The Warlock group's rapid escalation from forum discussions to impactful campaigns highlights the evolving threat landscape and the need for organizations to bolster their cybersecurity defenses against sophisticated ransomware operations.
4 months ago
Kill Chain
Delta Electronics CNCSoft-G2 2026 Out-of-Bounds Write Vulnerability
In March 2026, Delta Electronics identified a critical vulnerability (CVE-2026-3094) in its CNCSoft-G2 software, specifically an out-of-bounds write issue in the DOPSoft component's DPAX file parsing. This flaw allows attackers to execute arbitrary code if a user opens a maliciously crafted file, potentially compromising system integrity. The vulnerability affects CNCSoft-G2 versions prior to V2.1.0.39. Delta Electronics has released version 2.1.0.39 to address this issue and recommends users update promptly. This incident underscores the persistent risks associated with file parsing vulnerabilities in industrial control systems, emphasizing the need for regular software updates and vigilant cybersecurity practices to protect critical infrastructure.
4 months ago
Kill Chain
Critical Vulnerabilities in Mitsubishi Electric's MELSEC iQ-F Series Expose Industrial Systems to Denial-of-Service Attacks
In March 2026, Mitsubishi Electric disclosed multiple vulnerabilities in their MELSEC iQ-F Series EtherNet/IP and Ethernet modules, specifically FX5-ENET/IP and FX5-EIP models. These flaws, identified as CVE-2026-1874, CVE-2026-1875, and CVE-2026-1876, allow remote attackers to induce denial-of-service conditions by continuously sending UDP packets, rendering the devices unresponsive until a system reset is performed. The vulnerabilities affect FX5-ENET/IP versions up to 1.106 and all versions of FX5-EIP. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1874?utm_source=openai)) This incident underscores the critical need for robust network security measures in industrial control systems, as such vulnerabilities can disrupt essential operations in critical manufacturing sectors worldwide. Organizations are advised to implement recommended mitigations, including updating firmware where available and employing network defenses to prevent unauthorized access. ([cyber.gc.ca](https://www.cyber.gc.ca/en/alerts-advisories/control-systems-mitsubishi-electric-security-advisory-av26-191?utm_source=openai))
4 months ago
Kill Chain
Advantest 2026 Ransomware Attack: A Wake-Up Call for Semiconductor Cybersecurity
In February 2026, Advantest Corporation, a leading Japanese semiconductor test equipment manufacturer, detected unauthorized access within its IT environment, indicating a ransomware attack. The company promptly activated incident response protocols, isolated affected systems, and engaged third-party cybersecurity experts to investigate and contain the incident. Preliminary findings suggest that an unauthorized third party may have gained access to portions of the company's network and deployed ransomware. The full extent of the impact, including potential compromise of customer or employee data, is under active investigation. ([advantest.com](https://www.advantest.com/en/news/2026/20260219.html?utm_source=openai)) This incident underscores the escalating threat of ransomware attacks targeting critical infrastructure within the semiconductor industry. As adversaries increasingly focus on high-value targets, organizations must enhance their cybersecurity measures to protect sensitive data and maintain operational continuity.
5 months ago
Kill Chain
ShinyHunters' 2026 Attack: Exploiting OAuth Device Code Flow in Microsoft Entra
In early 2026, the cybercriminal group ShinyHunters orchestrated a sophisticated attack targeting Microsoft Entra accounts. By combining device code phishing with voice phishing (vishing), they exploited the OAuth 2.0 Device Authorization flow. Attackers generated legitimate device codes and, through impersonation of IT staff, convinced employees to enter these codes on authentic Microsoft login pages. This manipulation granted the attackers valid authentication tokens, enabling unauthorized access to victims' accounts and associated Single Sign-On (SSO) applications, including Microsoft 365, Salesforce, and Google Workspace. The breach led to significant data exfiltration and subsequent extortion attempts. This incident underscores a concerning evolution in phishing tactics, moving beyond traditional credential theft to the exploitation of trusted authentication processes. The success of such attacks highlights the pressing need for organizations to adopt phishing-resistant multi-factor authentication (MFA) methods and to enhance employee awareness regarding emerging social engineering techniques.
5 months ago
Kill Chain
Delta Electronics ASDA-Soft Vulnerability Exposes Critical Systems to Risk
In January 2026, Delta Electronics disclosed a critical stack-based buffer overflow vulnerability (CVE-2026-1361) in their ASDA-Soft software, versions up to 7.2.0.0. This flaw allows attackers to write arbitrary data beyond the bounds of a stack-allocated buffer, potentially leading to the corruption of a structured exception handler (SEH). Exploitation requires local access and user interaction, but no prior authentication, posing significant risks to confidentiality, integrity, and availability. Delta Electronics has released version 7.2.2.0 to address this issue. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1361?utm_source=openai)) This incident underscores the persistent threat of buffer overflow vulnerabilities in industrial control systems, emphasizing the need for rigorous input validation and timely software updates to mitigate potential exploits.
5 months ago
Kill Chain
Pwn2Own Automotive 2026: Hackers Expose Record 76 Zero-Days in Cars, Chargers & Tesla
Between January 21–23, 2026, the Pwn2Own Automotive competition in Tokyo saw security researchers demonstrate a record-breaking 76 zero-day vulnerabilities across in-vehicle infotainment systems (IVIs), electric vehicle chargers, and automotive operating systems, including high-profile exploits against Tesla, Alpitronic, Autel, Kenwood, and other leading manufacturers. Teams leveraged physical and remote attack vectors, with notable attacks including USB-based chaining to breach Tesla’s infotainment system. The event awarded $1,047,000 in prizes, underscoring significant risks within connected automotive infrastructure. Vendors now have 90 days to issue security patches before public disclosure. This incident highlights a concerning rise in exploitable vulnerabilities within rapidly digitalizing automotive ecosystems. As vehicles integrate more software-driven services and connected devices, adversaries and researchers alike are increasingly shifting focus toward automotive cyberattacks—driving new urgency for robust segmentation, secure update mechanisms, and continuous monitoring.
6 months ago
Kill Chain
INC Ransomware OpSec Fail Uncovers Data from 12 U.S. Organizations
In January 2026, an operational security lapse in the INC ransomware group's infrastructure enabled Cyber Centaurs researchers to recover encrypted data exfiltrated from twelve U.S. organizations. The investigation began after a RainINC ransomware attack on a client’s production SQL Server. Forensic analysis traced renamed binaries, PowerShell scripts, and usage of the Restic backup tool, revealing attacker scripts with hardcoded credentials and references to persistent cloud storage. By enumerating the attacker-controlled repositories, researchers identified encrypted data from healthcare, manufacturing, technology, and services firms, then decrypted and preserved it in coordination with law enforcement. This case highlights a rare opportunity where attacker mistakes allowed post-breach data retrieval for unrelated victim organizations. The incident underscores a growing trend in ransomware operations leveraging legitimate backup and exfiltration tools, persistent attacker infrastructure, and the importance of thorough incident response for uncovering wider impacts.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports