The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Manufacturing

Breach intelligence, attack campaigns, and threat reports targeting the Manufacturing sector.

55 threat reports
Page 1 of 5

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Manufacturing Threat Reports

Showing 1–12 / 55 reports
Critical Configuration Flaw Exposed in Inductive Automation Ignition SCADA Platform
Impact· MEDIUM

Critical Configuration Flaw Exposed in Inductive Automation Ignition SCADA Platform

In September 2026, CISA disclosed CVE-2026-77393 affecting Inductive Automation's Ignition SCADA platform versions 8.1.53 and earlier. The vulnerability stems from incorrect default permissions where the Gateway's 'Create Project Role(s)' setting shipped blank, allowing any authenticated user to create projects if they could execute gateway scripts. This configuration flaw exposed industrial control systems to potential unauthorized project creation and manipulation. Inductive Automation addressed the issue in version 8.1.54 by restricting project creation to Designer sessions and eliminating reliance on the problematic setting. This incident highlights the growing security challenges facing industrial control systems as they become increasingly connected and targeted by threat actors. With critical infrastructure under constant threat and new regulations emphasizing OT security, even seemingly minor configuration vulnerabilities can create significant exposure points for manufacturing and energy sector organizations.

2 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Aurora Ransomware Weaponizes AI: The Future of Cybercrime is Here
Impact· HIGH

Aurora Ransomware Weaponizes AI: The Future of Cybercrime is Here

Between April and July 2026, Aurora ransomware operators conducted sophisticated attacks against over 20 organizations across nine countries, leveraging SpaceX's Cursor AI coding assistant to plan and execute their campaigns. The Russian-speaking cybercrime group used the AI tool to develop Active Directory Certificate Services exploitation plans in Russian, while systematically excluding CIS countries from their targeting scope. Initial access was achieved through aggressive email bombing combined with social engineering phone calls posing as IT help desk personnel, followed by lateral movement via SMB, LDAP, WinRM, and RDP protocols before deploying encryptors written in Zig programming language. This incident represents a critical evolution in ransomware operations, demonstrating how threat actors are weaponizing commercial AI tools to enhance attack planning and execution capabilities. The integration of AI assistants into cybercriminal workflows signals a new era where automated intelligence can accelerate threat development cycles and lower technical barriers for sophisticated attacks.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Hasbro Employee Data Breach Exposes Corporate Cybersecurity Vulnerabilities
Impact· MEDIUM

Hasbro Employee Data Breach Exposes Corporate Cybersecurity Vulnerabilities

In December 2024, toy manufacturing giant Hasbro disclosed a significant data breach affecting employee information after discovering unauthorized access to their systems. The company detected the security incident through their monitoring systems and immediately launched an investigation with external cybersecurity experts. The breach potentially exposed sensitive employee data including personal identification information, employment records, and other confidential details. Hasbro has notified affected employees and is working with law enforcement and regulatory authorities while implementing additional security measures to prevent future incidents. This incident highlights the ongoing vulnerability of large corporations to sophisticated cyber attacks targeting employee databases and internal systems, potentially affecting thousands of workers across the company's global operations. This breach reflects the accelerating trend of attackers targeting employee data as a pathway to broader organizational compromise, particularly as companies expand remote work capabilities and digital HR systems.

3 weeks ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Flaws in Ebyte Industrial Gateways Expose Global Infrastructure to Remote Attacks
Impact· CRITICAL

Critical Flaws in Ebyte Industrial Gateways Expose Global Infrastructure to Remote Attacks

In August 2026, CISA disclosed thirteen critical vulnerabilities in the Ebyte NA111-M industrial control system device, a Chinese-manufactured gateway used worldwide in critical infrastructure. The vulnerabilities include missing authentication, cleartext transmission of sensitive data, client-side authentication bypass, and weak cryptographic implementations. With CVSS scores up to 9.8, these flaws allow complete device compromise through remote exploitation, enabling attackers to access sensitive configurations, modify device settings, intercept MQTT credentials, and disrupt industrial operations. This disclosure highlights the persistent challenge of securing legacy industrial control systems that lack fundamental security controls, as nation-state actors and cybercriminals increasingly target critical infrastructure through vulnerable ICS devices for espionage and operational disruption.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Vulnerabilities in Ebyte Industrial IoT Gateways Expose Manufacturing and Energy Infrastructure
Impact· HIGH

Critical Vulnerabilities in Ebyte Industrial IoT Gateways Expose Manufacturing and Energy Infrastructure

The Ebyte NE2-D11 industrial IoT gateway contains 12 critical and high-severity vulnerabilities (ICSA-26-237-06) that enable complete device compromise through multiple attack vectors. These flaws include missing authentication for critical functions, cleartext transmission of sensitive data, client-side authentication bypass, CSRF attacks, and insufficient credential protection. The vulnerabilities affect firmware version FW-9167-0-11 deployed worldwide in critical manufacturing and energy sectors, allowing remote attackers to gain administrative access, intercept communications, modify configurations, and disrupt operations without authentication. This advisory highlights the persistent security challenges in industrial IoT devices as critical infrastructure increasingly relies on connected systems. With Ebyte's limited response to coordination efforts and no confirmed patch timeline, organizations face immediate risks from devices that lack basic security controls essential for industrial environments.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Mirage2FA Campaign Exposes Critical Gaps in Traditional MFA Security
Impact· HIGH

Mirage2FA Campaign Exposes Critical Gaps in Traditional MFA Security

The Mirage2FA phishing-as-a-service campaign targeted over 4,500 organizations across the US and EU from 2024 to 2026, exploiting Microsoft 365 login flows to bypass two-factor authentication. Using adversary-in-the-middle (AiTM) techniques, attackers stole passwords and session cookies, achieving a 48% compromise rate among targeted email addresses. The campaign primarily affected US-based companies in technology, manufacturing, and education sectors, with attackers gaining authenticated access to Microsoft 365 sessions and SSO-connected services, enabling account impersonation and data theft. This incident highlights the evolving threat landscape where traditional MFA is insufficient against sophisticated phishing operations that steal active sessions rather than just credentials, demonstrating the urgent need for phishing-resistant authentication methods and enhanced session management controls.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Clop Ransomware's Targeted Attack on PTC Windchill: A Wake-Up Call for PLM Security
Impact· CRITICAL

Clop Ransomware's Targeted Attack on PTC Windchill: A Wake-Up Call for PLM Security

In July 2026, the Clop ransomware gang exploited a critical vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM platforms, enabling unauthenticated remote code execution. This allowed attackers to deploy custom JavaServer Pages (JSP) web shells, granting them access to sensitive product lifecycle data. The breach led to significant data exfiltration, impacting numerous organizations reliant on these platforms for product design and management. This incident underscores the evolving tactics of ransomware groups, shifting from traditional encryption-based attacks to data theft and extortion. Organizations must prioritize timely patching of known vulnerabilities and enhance monitoring of enterprise applications to mitigate such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerabilities in ANDRITZ HIPASE-250 Devices: Immediate Action Required
Impact· HIGH

Critical Vulnerabilities in ANDRITZ HIPASE-250 Devices: Immediate Action Required

In August 2026, multiple vulnerabilities were identified in ANDRITZ HIPASE-250 and 250 SCALA devices, including storing passwords in a recoverable format, missing authentication for critical functions, and the use of hard-coded credentials. These flaws could allow attackers to read sensitive data or gain unauthorized access to affected workstations. ANDRITZ has released updates to address these issues and recommends users upgrade to version V8.15.00. The discovery of these vulnerabilities underscores the critical importance of securing industrial control systems, especially in the energy sector. Organizations must prioritize timely updates and robust security measures to protect against potential exploits targeting such weaknesses.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Microsoft Teams Vishing Attacks Facilitate Chaos Ransomware Deployment in 2026
Impact· HIGH

Microsoft Teams Vishing Attacks Facilitate Chaos Ransomware Deployment in 2026

Between February and June 2026, threat actors conducted a campaign targeting North American organizations by impersonating IT support staff via Microsoft Teams. They initiated chats and voice calls to deceive employees into granting remote access through tools like Microsoft Quick Assist and RemSupp. Once access was obtained, attackers deployed backdoors, established persistence, and in at least three instances, executed Chaos ransomware, encrypting files across compromised devices. One attack progressed from initial access to full encryption in under 17 hours. This incident underscores the evolving sophistication of social engineering tactics, particularly the exploitation of trusted communication platforms like Microsoft Teams. The rapid progression from initial access to ransomware deployment highlights the critical need for organizations to enhance their security awareness training and implement robust access controls to mitigate such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Bearlyfy's Custom GenieLocker Ransomware: A New Threat to Russian Enterprises
Impact· HIGH

Bearlyfy's Custom GenieLocker Ransomware: A New Threat to Russian Enterprises

In March 2026, the pro-Ukrainian hacking group Bearlyfy, also known as Labubu, launched over 70 cyberattacks against Russian companies, primarily targeting the manufacturing sector. The group deployed a custom-built Windows ransomware strain named GenieLocker, marking a significant evolution from their previous use of third-party encryptors like LockBit 3 and Babuk. These attacks involved exploiting external services and vulnerable applications to gain access, followed by the deployment of tools such as MeshAgent for remote access and encryption. Ransom demands escalated to hundreds of thousands of dollars, with approximately 20% of victims reportedly paying. ([thehackernews.com](https://thehackernews.com/2026/03/bearlyfy-hits-70-russian-firms-with.html?utm_source=openai)) This incident underscores the increasing sophistication and boldness of hacktivist groups in leveraging custom malware to achieve both financial gain and strategic sabotage. The development and deployment of proprietary ransomware like GenieLocker highlight a trend where threat actors are investing in bespoke tools to enhance their operational effectiveness and evade detection. ([thehackernews.com](https://thehackernews.com/2026/03/bearlyfy-hits-70-russian-firms-with.html?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Dysphoria IoT Botnet: A New Era of Resilient Cyber Threats
Impact· CRITICAL

Dysphoria IoT Botnet: A New Era of Resilient Cyber Threats

In July 2026, cybersecurity researchers identified a new IoT botnet named Dysphoria, which has infected approximately 200,000 devices globally. Following the March 2026 law enforcement takedown of the JackSkid botnet, Dysphoria emerged with enhanced resilience by integrating blockchain-based command-and-control (C2) mechanisms and utilizing infected devices as relays to obscure its infrastructure. This evolution complicates traditional disruption methods and poses significant challenges to cybersecurity defenses. The adoption of blockchain name services for C2 resolution and the use of victim devices as relays represent a concerning trend in botnet development. These tactics not only enhance the botnet's resilience against takedown efforts but also indicate a shift towards more sophisticated and decentralized control structures in cyber threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Clop Ransomware Exploits Critical Vulnerability in PTC Windchill and FlexPLM
Impact· CRITICAL

Clop Ransomware Exploits Critical Vulnerability in PTC Windchill and FlexPLM

In July 2026, the Clop ransomware group exploited a critical vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM systems, leading to unauthorized remote code execution. This flaw allowed attackers to deploy JSP webshells, facilitating the exfiltration of sensitive product data from compromised organizations. The exploitation of this vulnerability underscores the persistent threat posed by ransomware groups targeting critical infrastructure and intellectual property. Organizations utilizing PTC's Windchill and FlexPLM platforms are urged to apply the latest security patches and implement robust monitoring to detect and prevent such intrusions.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports