The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Mining/Metals

Breach intelligence, attack campaigns, and threat reports targeting the Mining/Metals sector.

9 threat reports
Page 1 of 1

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Mining/Metals Threat Reports

Showing 1–9 / 9 reports
BlueMoon Exploit Kit Weaponizes Chrome and Windows Zero-Days in Multi-Group APT Campaign
Impact· CRITICAL

BlueMoon Exploit Kit Weaponizes Chrome and Windows Zero-Days in Multi-Group APT Campaign

Multiple Chinese cyber-espionage groups deployed the BlueMoon exploit kit in August-September 2026, chaining three zero-day vulnerabilities in Chrome and Windows to achieve remote code execution and privilege escalation. The kit exploited CVE-2026-85046 and CVE-2026-87491 in Chrome's V8 JavaScript engine for sandbox escape, combined with CVE-2026-85880 in Windows ALPC for local privilege escalation. Threat actors including JungleBamboo (APT31), UTA0560, UNK_LateNight, and UNK_DoubleCheck targeted NGOs, aerospace companies, and manufacturing firms through spearphishing campaigns that delivered various backdoors including ShadowPad and Grimwedge. This incident demonstrates the increasing sophistication of state-sponsored actors in rapidly weaponizing zero-day vulnerabilities and sharing exploit tools across multiple threat groups. The coordinated use of BlueMoon by different Chinese APT groups signals a concerning trend of exploit kit sharing and collaborative cyber operations targeting critical infrastructure and civil society organizations.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Chinese APT Groups Coordinate BlueMoon Zero-Day Campaign Against U.S. Organizations
Impact· CRITICAL

Chinese APT Groups Coordinate BlueMoon Zero-Day Campaign Against U.S. Organizations

In late August 2024, at least four Chinese state-sponsored espionage groups exploited a zero-day exploit chain dubbed BlueMoon to conduct surveillance operations against U.S. organizations. The campaign, initiated by APT31 (Violet Typhoon) on August 28, leveraged three zero-day vulnerabilities in Chrome browsers and Windows to achieve remote code execution, sandbox escape, and system privilege escalation. The attackers targeted NGOs, mining companies, aerospace firms, and government organizations through phishing emails that installed malicious browser extensions disguised as Google Gemini, enabling credential theft and system surveillance. This incident highlights the accelerating timeline of zero-day exploitation as threat actors increasingly reverse-engineer public patches to weaponize vulnerabilities before widespread deployment. The coordinated use of the same exploit chain by multiple Chinese APT groups demonstrates enhanced intelligence sharing and operational coordination within China's cyber espionage apparatus, signaling a more systematic approach to targeting critical infrastructure and strategic industries.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
BlueMoon Exploit Kit Signals New Era of Commoditized Zero-Day Attacks
Impact· HIGH

BlueMoon Exploit Kit Signals New Era of Commoditized Zero-Day Attacks

In August 2026, multiple China-aligned espionage groups rapidly adopted the BlueMoon exploit kit, which chains together three zero-day vulnerabilities in Google Chrome and Windows. The kit was first deployed by APT31 on August 28, 2026, targeting NGOs, mining companies, and commodity trading firms through spear-phishing campaigns. Within days, three additional threat clusters began using the same exploit chain, deploying various payloads including the GemStone browser backdoor, ShadowPad malware, and custom .NET assemblies for persistent access and credential theft. This incident highlights the emerging trend of AI-assisted exploit development and the rapid commoditization of previously high-value exploit chains. The simultaneous adoption by multiple threat actors suggests a new paradigm where sophisticated exploit capabilities are becoming more accessible, potentially lowering barriers to entry for state-sponsored cyber espionage operations.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Phantom Deal Campaign Exploits M&A Processes in Sophisticated Enterprise Fraud
Impact· MEDIUM

Phantom Deal Campaign Exploits M&A Processes in Sophisticated Enterprise Fraud

The 'Phantom Deal' campaign represents a sophisticated evolution of advance fee scams targeting large enterprises through fake merger and acquisition proposals. Threat actors conducted extensive reconnaissance on companies like Gen (Norton/Avast parent company), impersonating executives via WhatsApp and creating fraudulent documentation from legitimate firms like PwC. The attackers attempted to trick employees into authorizing substantial financial transfers, with one attempt involving €626,735.45, by leveraging detailed corporate intelligence and social engineering tactics that exploited M&A processes and confidentiality requirements. This campaign highlights the growing sophistication of business email compromise attacks as threat actors increasingly target high-value corporate transactions. With M&A activity remaining robust and remote work normalizing digital-only communications, similar social engineering campaigns pose escalating risks to enterprise financial controls and decision-making processes.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
State-Sponsored Cyber Attacks on AI Supply Chain in 2026
Impact· MEDIUM

State-Sponsored Cyber Attacks on AI Supply Chain in 2026

In 2026, the global race to dominate artificial intelligence (AI) has intensified, with nations vying for control over critical minerals, semiconductor production, and AI model development. This competition has led to increased state-sponsored cyber operations targeting every link in the AI supply chain, from mining companies to data centers and AI research institutions. Notably, Chinese state-sponsored hackers have been implicated in sophisticated cyber espionage campaigns aimed at extracting sensitive information and disrupting competitors' advancements in AI technologies. The urgency of securing the AI development chain has never been more critical. As AI becomes deeply integrated into various sectors, the potential for cyber threats to disrupt economies and national security has escalated. Organizations must adopt comprehensive cybersecurity strategies to protect against these evolving threats, ensuring the resilience of their AI infrastructures.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability in Carlson VASCO-B GNSS Receiver (CVE-2026-3893)
Impact· HIGH

Critical Vulnerability in Carlson VASCO-B GNSS Receiver (CVE-2026-3893)

In April 2026, a critical vulnerability (CVE-2026-3893) was identified in Carlson Software's VASCO-B GNSS Receiver versions prior to 1.4.0. This flaw, due to missing authentication mechanisms, allows remote attackers to alter system configurations and disrupt device operations without requiring credentials. The vulnerability has a CVSS score of 9.4, indicating its severity, and primarily affects the Critical Manufacturing sector globally. ([socdefenders.ai](https://www.socdefenders.ai/item/3f9fa938-de90-494a-99b5-bc0ba05499a8?utm_source=openai)) The incident underscores the importance of securing GNSS receivers, which are integral to infrastructure operations. Organizations are advised to update to version 1.4.0 or later, minimize network exposure of control systems, implement firewalls, and use secure remote access methods like VPNs to mitigate potential risks. ([socdefenders.ai](https://www.socdefenders.ai/item/3f9fa938-de90-494a-99b5-bc0ba05499a8?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Northern Minerals Suffers Data Breach in 2024 BianLian Ransomware Attack
Impact· MEDIUM

Northern Minerals Suffers Data Breach in 2024 BianLian Ransomware Attack

In late March 2024, Australian rare earths mining company Northern Minerals experienced a cyberattack attributed to the BianLian ransomware group. The attackers exfiltrated corporate, operational, financial, and personal data, including information on current and former employees and shareholders. The stolen data was subsequently published on the dark web. Despite the breach, Northern Minerals reported no material impact on its operations or broader systems. The company promptly engaged legal, technical, and cybersecurity specialists, notified relevant authorities, and implemented measures to strengthen its systems. This incident underscores the evolving tactics of ransomware groups like BianLian, which have shifted from encrypting systems to focusing on data theft and extortion. Organizations, especially those in critical infrastructure sectors, must remain vigilant and enhance their cybersecurity defenses to mitigate such threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability in RISS SRL MOMA Seismic Station Firmware (CVE-2026-1632)
Impact· CRITICAL

Critical Vulnerability in RISS SRL MOMA Seismic Station Firmware (CVE-2026-1632)

In February 2026, a critical vulnerability (CVE-2026-1632) was identified in RISS SRL's MOMA Seismic Station firmware versions up to and including v2.4.2520. The flaw exposes the device's web management interface without requiring authentication, allowing unauthenticated attackers to modify configuration settings, access sensitive data, or remotely reset the device. This vulnerability poses significant risks to seismic monitoring operations, potentially leading to data manipulation, unauthorized data access, and operational disruptions. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1632?utm_source=openai)) The absence of authentication mechanisms in critical infrastructure devices underscores the urgent need for robust security measures in industrial control systems. As cyber threats targeting operational technology (OT) environments increase, organizations must prioritize securing their OT assets to prevent potential exploitation and ensure the integrity of essential services.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Güralp Systems 2025: Unauthenticated DoS Threat Hits Critical OT Devices
Impact· high

Güralp Systems 2025: Unauthenticated DoS Threat Hits Critical OT Devices

In December 2025, Güralp Systems disclosed a vulnerability affecting its Fortimus, Minimus, and Certimus Series devices, widely deployed in critical manufacturing and infrastructure sectors globally. The flaw (CVE-2025-14466) in the devices' web interface allows unauthenticated attackers on the network to send specially crafted HTTP requests, forcing the web service to restart and causing a temporary denial-of-service (DoS) condition. While the process automatically recovers, repeated exploitation could severely impact system availability for organizations relying on these seismic monitoring instruments. This type of DoS vulnerability is increasingly significant as threat actors increasingly target industrial control devices and operational technology (OT) with low-complexity attacks from unauthenticated vectors. Regulatory scrutiny of ICS network hygiene and cross-industry best practices is intensifying, pushing organizations to proactively address resource allocation and network exposure.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports