✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Energy
Breach intelligence, attack campaigns, and threat reports targeting the Energy sector.
Explore Other Sectors
Energy Threat Reports
Critical Unauthenticated Access Vulnerability in Synectix LAN 232 TRIO
In February 2026, a critical vulnerability (CVE-2026-1633) was identified in the Synectix LAN 232 TRIO 3-Port serial to Ethernet adapter. This flaw allows unauthenticated users to access the device's web management interface, enabling them to modify critical settings or perform a factory reset. The vulnerability has a CVSS score of 10.0, indicating maximum severity. Synectix is no longer in business, leaving the affected devices without official support or patches. ([securityonline.info](https://securityonline.info/unpatchable-critical-cisa-issues-cvss-10-0-alert-for-synectix-adapters/?utm_source=openai)) This incident underscores the risks associated with using unsupported legacy devices in critical infrastructure. Organizations must proactively identify and replace such equipment to mitigate potential security threats. ([securityonline.info](https://securityonline.info/unpatchable-critical-cisa-issues-cvss-10-0-alert-for-synectix-adapters/?utm_source=openai))
4 months ago
Kill Chain
Critical Vulnerabilities in Johnson Controls iSTAR Devices Expose Critical Infrastructure—What You Need to Know
In December 2025, Johnson Controls disclosed two critical vulnerabilities (CVE-2025-43875, CVE-2025-43876) affecting its iSTAR Ultra and Edge G2 access control devices worldwide. These vulnerabilities—improper neutralization of special elements used in OS commands (CWE-78)—can be exploited remotely with low complexity and limited privileges, potentially granting attackers unauthorized access to devices deployed across critical sectors, including commercial facilities, manufacturing, energy, transportation, and government. There are currently no reports of active exploitation, but if leveraged, these flaws could compromise physical security and facility operations. This incident underscores the persistent cybersecurity challenges in operational technology and building automation environments. The disclosure highlights an urgent need for regular patching, segregation of critical controls, and adoption of defensive measures, especially as threat actors increasingly target industrial and physical security systems with potentially far-reaching consequences.
5 months ago
Kill Chain
Johnson Controls iSTAR Ultra Vulnerabilities: 2025 Exposure of OT Systems
In December 2025, Johnson Controls publicly disclosed critical vulnerabilities (CVE-2025-43873 and CVE-2025-43874) affecting several versions of its iSTAR Ultra and Edge G2 door controllers used in building automation across critical infrastructure sectors worldwide. These OS Command Injection flaws, exploitable remotely with low attack complexity and minimal user interaction, could allow attackers to gain full control of vulnerable devices, modify firmware, and potentially disrupt or compromise secure building environments. The vulnerabilities were responsibly reported by Reid Wightman of Dragos, and patches have been made available for affected products. This incident highlights increasing threats targeting operational technology (OT) in critical sectors, as cybercriminals and nation-state actors leverage software supply chain and device-level weaknesses for initial access. The prevalence of command injection vulnerabilities, coupled with rising demands for segmentation and zero trust architectures, elevates the urgency for organizations to update OT and IoT assets and enforce proactive defense strategies.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports