The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Electrical/Electronic Manufacturing
Breach intelligence, attack campaigns, and threat reports targeting the Electrical/Electronic Manufacturing sector.
Explore Other Sectors
Electrical/Electronic Manufacturing Threat Reports
Critical Vulnerability in Delta Electronics COMMGR2: CVE-2026-3630
In March 2026, Delta Electronics disclosed a critical stack-based buffer overflow vulnerability (CVE-2026-3630) in their COMMGR2 software, widely used in industrial automation. This flaw allows unauthenticated remote attackers to execute arbitrary code, potentially leading to full system compromise. The vulnerability affects COMMGR2 versions up to and including 2.11.0. Delta Electronics has released a security advisory (Delta-PCSA-2026-00005) detailing the issue and providing mitigation steps. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-3630?utm_source=openai)) The disclosure underscores the persistent risks in industrial control systems and the importance of timely patching. Organizations in manufacturing, energy, and logistics sectors should prioritize updating affected systems to prevent potential exploitation. ([praetorian.com](https://www.praetorian.com/blog/cve-2026-3630/?utm_source=openai))
5 months ago
Kill Chain
Critical Vulnerabilities in Schneider Electric's Plant iT/Brewmaxx Systems: Immediate Action Required
In March 2026, Schneider Electric disclosed multiple critical vulnerabilities in its Plant iT/Brewmaxx systems, stemming from the integration of Redis, an open-source in-memory database. These vulnerabilities, identified as CVE-2025-49844, CVE-2025-46817, CVE-2025-46818, and CVE-2025-46819, involve issues such as use-after-free errors and integer overflows within Redis's Lua scripting engine. Exploitation of these flaws could allow authenticated users to execute arbitrary code, leading to potential remote code execution and privilege escalation. The affected versions include Plant iT/Brewmaxx 9.60 and above. Schneider Electric has released patches and provided mitigation steps to address these vulnerabilities. ([se.com](https://www.se.com/in/en/download/document/SEVD-2026-013-01/?utm_source=openai)) The disclosure underscores the critical importance of securing third-party components within industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, organizations must remain vigilant, ensuring timely updates and adherence to cybersecurity best practices to mitigate potential risks.
6 months ago
Kill Chain
Warlock Ransomware Group's 2025 Exploitation of SharePoint Vulnerabilities
In mid-2025, the Warlock ransomware group exploited unpatched Microsoft SharePoint servers to gain initial access to various organizations across North America, Europe, Asia, and Africa. Utilizing known vulnerabilities (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771), they deployed web shells via HTTP POST requests, enabling reconnaissance, credential theft, and lateral movement. The attack culminated in the deployment of ransomware, encrypting files with the .x2anylock extension and exfiltrating data using RClone. ([clearphish.ai](https://www.clearphish.ai/news/warlock-ransomware-sharepoint-attacks-2025?utm_source=openai)) This incident underscores the critical importance of timely patch management, especially for widely used enterprise applications like SharePoint. The Warlock group's rapid escalation from forum discussions to impactful campaigns highlights the evolving threat landscape and the need for organizations to bolster their cybersecurity defenses against sophisticated ransomware operations.
6 months ago
Kill Chain
Delta Electronics CNCSoft-G2 2026 Out-of-Bounds Write Vulnerability
In March 2026, Delta Electronics identified a critical vulnerability (CVE-2026-3094) in its CNCSoft-G2 software, specifically an out-of-bounds write issue in the DOPSoft component's DPAX file parsing. This flaw allows attackers to execute arbitrary code if a user opens a maliciously crafted file, potentially compromising system integrity. The vulnerability affects CNCSoft-G2 versions prior to V2.1.0.39. Delta Electronics has released version 2.1.0.39 to address this issue and recommends users update promptly. This incident underscores the persistent risks associated with file parsing vulnerabilities in industrial control systems, emphasizing the need for regular software updates and vigilant cybersecurity practices to protect critical infrastructure.
6 months ago
Kill Chain
Critical Vulnerabilities in Mitsubishi Electric's MELSEC iQ-F Series Expose Industrial Systems to Denial-of-Service Attacks
In March 2026, Mitsubishi Electric disclosed multiple vulnerabilities in their MELSEC iQ-F Series EtherNet/IP and Ethernet modules, specifically FX5-ENET/IP and FX5-EIP models. These flaws, identified as CVE-2026-1874, CVE-2026-1875, and CVE-2026-1876, allow remote attackers to induce denial-of-service conditions by continuously sending UDP packets, rendering the devices unresponsive until a system reset is performed. The vulnerabilities affect FX5-ENET/IP versions up to 1.106 and all versions of FX5-EIP. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1874?utm_source=openai)) This incident underscores the critical need for robust network security measures in industrial control systems, as such vulnerabilities can disrupt essential operations in critical manufacturing sectors worldwide. Organizations are advised to implement recommended mitigations, including updating firmware where available and employing network defenses to prevent unauthorized access. ([cyber.gc.ca](https://www.cyber.gc.ca/en/alerts-advisories/control-systems-mitsubishi-electric-security-advisory-av26-191?utm_source=openai))
6 months ago
Kill Chain
Advantest 2026 Ransomware Attack: A Wake-Up Call for Semiconductor Cybersecurity
In February 2026, Advantest Corporation, a leading Japanese semiconductor test equipment manufacturer, detected unauthorized access within its IT environment, indicating a ransomware attack. The company promptly activated incident response protocols, isolated affected systems, and engaged third-party cybersecurity experts to investigate and contain the incident. Preliminary findings suggest that an unauthorized third party may have gained access to portions of the company's network and deployed ransomware. The full extent of the impact, including potential compromise of customer or employee data, is under active investigation. ([advantest.com](https://www.advantest.com/en/news/2026/20260219.html?utm_source=openai)) This incident underscores the escalating threat of ransomware attacks targeting critical infrastructure within the semiconductor industry. As adversaries increasingly focus on high-value targets, organizations must enhance their cybersecurity measures to protect sensitive data and maintain operational continuity.
7 months ago
Kill Chain
ShinyHunters' 2026 Attack: Exploiting OAuth Device Code Flow in Microsoft Entra
In early 2026, the cybercriminal group ShinyHunters orchestrated a sophisticated attack targeting Microsoft Entra accounts. By combining device code phishing with voice phishing (vishing), they exploited the OAuth 2.0 Device Authorization flow. Attackers generated legitimate device codes and, through impersonation of IT staff, convinced employees to enter these codes on authentic Microsoft login pages. This manipulation granted the attackers valid authentication tokens, enabling unauthorized access to victims' accounts and associated Single Sign-On (SSO) applications, including Microsoft 365, Salesforce, and Google Workspace. The breach led to significant data exfiltration and subsequent extortion attempts. This incident underscores a concerning evolution in phishing tactics, moving beyond traditional credential theft to the exploitation of trusted authentication processes. The success of such attacks highlights the pressing need for organizations to adopt phishing-resistant multi-factor authentication (MFA) methods and to enhance employee awareness regarding emerging social engineering techniques.
7 months ago
Kill Chain
Delta Electronics ASDA-Soft Vulnerability Exposes Critical Systems to Risk
In January 2026, Delta Electronics disclosed a critical stack-based buffer overflow vulnerability (CVE-2026-1361) in their ASDA-Soft software, versions up to 7.2.0.0. This flaw allows attackers to write arbitrary data beyond the bounds of a stack-allocated buffer, potentially leading to the corruption of a structured exception handler (SEH). Exploitation requires local access and user interaction, but no prior authentication, posing significant risks to confidentiality, integrity, and availability. Delta Electronics has released version 7.2.2.0 to address this issue. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1361?utm_source=openai)) This incident underscores the persistent threat of buffer overflow vulnerabilities in industrial control systems, emphasizing the need for rigorous input validation and timely software updates to mitigate potential exploits.
7 months ago
Kill Chain
Pwn2Own Automotive 2026: Hackers Expose Record 76 Zero-Days in Cars, Chargers & Tesla
Between January 21–23, 2026, the Pwn2Own Automotive competition in Tokyo saw security researchers demonstrate a record-breaking 76 zero-day vulnerabilities across in-vehicle infotainment systems (IVIs), electric vehicle chargers, and automotive operating systems, including high-profile exploits against Tesla, Alpitronic, Autel, Kenwood, and other leading manufacturers. Teams leveraged physical and remote attack vectors, with notable attacks including USB-based chaining to breach Tesla’s infotainment system. The event awarded $1,047,000 in prizes, underscoring significant risks within connected automotive infrastructure. Vendors now have 90 days to issue security patches before public disclosure. This incident highlights a concerning rise in exploitable vulnerabilities within rapidly digitalizing automotive ecosystems. As vehicles integrate more software-driven services and connected devices, adversaries and researchers alike are increasingly shifting focus toward automotive cyberattacks—driving new urgency for robust segmentation, secure update mechanisms, and continuous monitoring.
8 months ago
Kill Chain
INC Ransomware OpSec Fail Uncovers Data from 12 U.S. Organizations
In January 2026, an operational security lapse in the INC ransomware group's infrastructure enabled Cyber Centaurs researchers to recover encrypted data exfiltrated from twelve U.S. organizations. The investigation began after a RainINC ransomware attack on a client’s production SQL Server. Forensic analysis traced renamed binaries, PowerShell scripts, and usage of the Restic backup tool, revealing attacker scripts with hardcoded credentials and references to persistent cloud storage. By enumerating the attacker-controlled repositories, researchers identified encrypted data from healthcare, manufacturing, technology, and services firms, then decrypted and preserved it in coordination with law enforcement. This case highlights a rare opportunity where attacker mistakes allowed post-breach data retrieval for unrelated victim organizations. The incident underscores a growing trend in ransomware operations leveraging legitimate backup and exfiltration tools, persistent attacker infrastructure, and the importance of thorough incident response for uncovering wider impacts.
8 months ago
Kill Chain
Schneider Electric EcoStruxure Rapsody Software Vulnerabilities Threaten Critical Infrastructure in 2026
In January 2026, Schneider Electric disclosed multiple critical software vulnerabilities (CVE-2025-13844, CVE-2025-13845) in its EcoStruxure Power Build Rapsody platform, widely used in the energy, manufacturing, and commercial facilities sectors. The flaws—specifically double free and use after free issues—stem from improper memory management when importing malicious project files, enabling local attackers to potentially execute arbitrary code. Impacted product versions are deployed worldwide. Schneider Electric and independent security researchers reported these vulnerabilities, urging customers to upgrade immediately or apply mitigations to prevent unauthorized system access and memory corruption. This incident highlights the continued threat posed by software supply chain attacks and memory corruption vulnerabilities in critical infrastructure environments. As attackers shift towards exploiting insecure file imports and legacy software flaws, organizations must prioritize secure software lifecycle management and timely patching to counter emerging risks.
8 months ago
Kill Chain
Siemens Edge Device Vulnerability Exposes Critical Manufacturing Operations in 2026
In January 2026, Siemens disclosed a critical authorization bypass vulnerability (CVE-2025-40805) affecting a broad range of its Industrial Edge Devices and operator panels. The flaw allows an unauthenticated remote attacker to circumvent user authentication by exploiting weaknesses in certain API endpoints, enabling impersonation of legitimate users. Exploitation requires knowledge of a valid user identity. Siemens promptly released patches and mitigation recommendations for impacted devices, but multiple models remain without fixes as of the initial disclosure, heightening operational risk in environments relying on these devices. This incident underscores the ongoing threat posed by API weaknesses and identity-driven attacks in critical manufacturing and operational technology sectors. As API-driven automation proliferates in industry, organizations must rapidly address such vulnerabilities in devices that underpin essential infrastructure.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports