✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Oil/Energy/Solar/Greentech
Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.
Explore Other Sectors
Oil/Energy/Solar/Greentech Threat Reports
HelloNet APT Exploits ViPNet Updates to Infiltrate Russian Organizations
In May 2026, a sophisticated Advanced Persistent Threat (APT) campaign, dubbed 'HelloNet,' was identified targeting large Russian organizations across sectors such as government, energy, transport, education, and logistics. The attackers exploited the update mechanism of ViPNet, a widely used secure networking product, by placing a malicious DLL ('wtsapi32.dll', known as 'HelloInjector') in the ViPNet Update System directory. This DLL was sideloaded by the legitimate 'itcsrvup64.exe' executable, leading to code injection into 'svchost.exe' and establishing persistence. The malware suite included components like 'HelloProxy' for traffic proxying, 'HelloExecutor' for command execution, 'HelloCleaner' for log file sanitization, and 'HelloBackdoor,' a Rust-based backdoor facilitating file manipulation and command execution. The campaign has been active since at least May 2026 and remains ongoing. ([mallory.ai](https://www.mallory.ai/stories/019f6a67-711c-7c67-8cd3-4c88705a116b?utm_source=openai)) This incident underscores the evolving tactics of APT groups in leveraging trusted software update mechanisms to infiltrate secure networks. The use of multiple sophisticated malware components highlights the need for organizations to implement robust monitoring and validation processes for software updates to prevent similar breaches.
6 hours ago
Kill Chain
Head Mare Group Exploits TrueConf Vulnerabilities to Deploy Backdoors
In August 2026, the Head Mare hacktivist group exploited vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions containing backdoors. By leveraging flaws identified as KLCERT-26-057 and KLCERT-26-058, attackers achieved remote code execution, escalated privileges to NT AUTHORITY\SYSTEM, and deployed web shells for persistent access. This allowed them to collect sensitive information, access databases, and distribute trojanized client installers embedded with the PhantomCore backdoor. Users downloading these installers inadvertently installed malware, granting attackers further access to organizational networks. This incident underscores the critical importance of timely patch management and the risks associated with supply chain attacks. Organizations must ensure that all software, especially communication tools like TrueConf, are regularly updated to mitigate vulnerabilities. The rise of such sophisticated attacks highlights the need for comprehensive security strategies that encompass both technical defenses and user awareness training.
1 day ago
Kill Chain
Surge in Device Code Phishing and Vishing Attacks in 2026
In the first half of 2026, CrowdStrike observed a 1,500% increase in device code phishing attacks and a doubling of voice phishing (vishing) incidents. Device code phishing, initially identified in 2020, gained traction among Russian state-sponsored actors by 2024 and has since been adopted by various cybercriminal groups. These attackers exploit device code authentication flows to compromise cloud identities, often bypassing traditional security measures. Concurrently, vishing campaigns have become more sophisticated, with threat actors like 'Cordial Spider' and 'Snarky Spider' targeting single sign-on (SSO) integrated SaaS applications. By directing victims to adversary-in-the-middle (AiTM) pages on mobile devices, these attackers circumvent conventional email security controls, facilitating unauthorized access to sensitive corporate data. The rapid adoption and evolution of these social engineering techniques underscore the need for organizations to enhance their security awareness training and implement robust multi-factor authentication mechanisms to mitigate the risks associated with these emerging threats.
6 days ago
Kill Chain
Minnesota Water Utility Cyberattack 2026: A Wake-Up Call for Critical Infrastructure Security
In late July 2026, over 30 community water systems in Minnesota experienced cyberattacks attributed to Iranian-affiliated actors. These attacks disrupted automated control systems, necessitating a temporary switch to manual operations. While water supply and quality remained largely unaffected, cities like Braham and Plymouth advised residents to limit water usage during the incidents. ([apnews.com](https://apnews.com/article/5bb1dcbaab8e3231889700c38a21e8ea?utm_source=openai)) This incident underscores the escalating cyber threats targeting U.S. critical infrastructure, particularly in the water sector. It highlights the vulnerabilities of operational technology systems and the pressing need for enhanced cybersecurity measures to protect essential services. ([csis.org](https://www.csis.org/analysis/iranian-cyber-threat-us-critical-infrastructure?utm_source=openai))
1 week ago
Kill Chain
Critical Vulnerabilities Discovered in Open62541
In July 2026, multiple vulnerabilities were identified in o6 Automation GmbH's Open62541, an open-source OPC UA stack widely used in industrial automation. These vulnerabilities, including CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, and CVE-2026-63559, affect versions from 1.3.0 to 1.5.4 and the master branch. Exploitation could allow attackers to disclose sensitive information, cause denial-of-service conditions, or execute arbitrary code. ([aviatrix.ai](https://aviatrix.ai/threat-research-center/o6-automation-gmbh-open62541-vulnerability-2026/?utm_source=openai)) The discovery of these vulnerabilities underscores the critical importance of rigorous security practices in industrial automation software. Organizations utilizing Open62541 should promptly upgrade to the latest version to mitigate these risks. Additionally, implementing network segmentation and minimizing exposure of control systems to external networks are essential steps to enhance security posture.
1 week ago
Kill Chain
Critical Vulnerability in Rockwell Automation's ControlLogix and CompactLogix Controllers
In July 2026, Rockwell Automation disclosed a security vulnerability (CVE-2026-9636) affecting its CompactLogix 5380, ControlLogix 5580, and 1756-EN4TR communication modules. The flaw involves improper handling of Certificate Revocation Lists (CRLs), allowing attackers to use revoked certificates to establish unauthorized connections, potentially bypassing CIP Security protections. This vulnerability impacts firmware versions V36 to V37 for the affected products. ([rockwellautomation.com](https://www.rockwellautomation.com/es-es/trust-center/security-advisories/advisory.SD1788.html?utm_source=openai)) The incident underscores the critical importance of robust certificate validation processes in industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, organizations must prioritize timely firmware updates and adhere to security best practices to mitigate potential risks.
1 week ago
Kill Chain
Critical Vulnerabilities in MZ Automation's lib60870: CVE-2026-61893 and CVE-2026-63033
In July 2026, MZ Automation's lib60870 library, widely used in industrial control systems, was found to have critical vulnerabilities identified as CVE-2026-61893 and CVE-2026-63033. These flaws, present in version 2.4.0, could be exploited by attackers to crash the parsing process, leading to a denial of service. The vulnerabilities stem from out-of-bounds read errors triggered by specially crafted IEC 60870-5-104 I-frames, allowing unauthorized access to memory beyond allocated buffers. ([windowsforum.com](https://windowsforum.com/security-alerts.84/cve-2026-16002-lib60870-2-4-1-fixes-scada-denial-of-service-risk.440185/?utm_source=openai)) Given the widespread deployment of lib60870 in critical infrastructure sectors such as energy, water, and manufacturing, these vulnerabilities pose significant operational risks. Organizations are urged to update to version 2.4.1 or later to mitigate potential threats. ([windowsforum.com](https://windowsforum.com/security-alerts.84/cve-2026-16002-lib60870-2-4-1-fixes-scada-denial-of-service-risk.440185/?utm_source=openai))
1 week ago
Kill Chain
Schneider Electric IGSS Vulnerability CVE-2026-12927: Critical Update Required
In July 2026, Schneider Electric disclosed a high-severity out-of-bounds write vulnerability (CVE-2026-12927) in its IGSS Definition module, versions 18.0.0.26124 and prior. Exploitation of this flaw could allow attackers to execute arbitrary code by importing a malicious CGF file, potentially leading to data loss and loss of control over the SCADA system. The vulnerability was reported by Michael Heinzl and has been addressed in version 18.0.0.26125 of the IGSS Definition module. ([se.com](https://www.se.com/ww/en/work/support/cybersecurity/security-notifications/?utm_source=openai)) This incident underscores the critical importance of timely software updates in industrial control systems. As cyber threats targeting SCADA systems become more sophisticated, organizations must prioritize patch management and adhere to cybersecurity best practices to safeguard operational technology environments.
1 week ago
Kill Chain
Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
Since 2017, a sophisticated fraud campaign has been targeting international firms by creating counterfeit websites that closely mimic those of major Russian companies in sectors such as fertilizer manufacturing, petrochemicals, metallurgy, logistics, and banking. These fraudulent sites, available in multiple languages including English, French, Arabic, and Russian, are designed to deceive businesses into making advance payments for non-existent goods. The attackers employ tactics like cold calls, phishing emails, and fake corporate websites to initiate contact, eventually providing falsified business documents with fraudulent banking details. One notable incident in April 2025 involved an Azerbaijani company losing $150,000 through such a scheme. This prolonged campaign underscores the evolving nature of cyber fraud, highlighting the need for businesses to remain vigilant against increasingly sophisticated social engineering tactics. The use of multilingual fake websites and the recruitment of unwitting sales representatives indicate a high level of organization and adaptability among cybercriminals, posing significant risks to international trade and business operations.
1 week ago
Kill Chain
Nimbus Manticore's 2026 Cyber Campaign: Unveiling NightLedger and Covert Tunneling Techniques
In July 2026, the Iranian state-sponsored hacking group known as Nimbus Manticore (also referred to as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) launched a series of cyber attacks targeting entities across the Middle East, Africa, and South Asia. The group employed a previously undocumented Windows backdoor named NightLedger, along with two custom WebSocket-based tunnelers, BridgeHead and ArcBridge, to maintain covert access to compromised systems. These tools enabled the attackers to perform reconnaissance, execute commands, and establish covert network access, effectively turning victim systems into relay nodes for further malicious activities. This incident underscores the evolving tactics of state-sponsored threat actors, who are increasingly developing and deploying sophisticated malware to achieve persistent access and control over targeted networks. The use of custom tunneling tools and backdoors highlights the need for organizations to enhance their detection and response capabilities to counter such advanced threats.
1 week ago
Kill Chain
Critical Vulnerability in Siemens SIMATIC S7-PLCSIM Advanced: CVE-2026-54429
In July 2026, Siemens disclosed a vulnerability (CVE-2026-54429) in its SIMATIC S7-PLCSIM Advanced software, affecting all versions. The flaw arises from improper handling of high-volume multicast network traffic, leading to memory exhaustion and a denial-of-service condition. An unauthenticated attacker on the local network can exploit this by sending excessive multicast traffic, rendering the application inaccessible until manually restarted. Notably, no project data is lost during this process. Exploitation requires a specific project configuration to be active on the targeted instance. This incident underscores the critical importance of securing industrial control systems against network-based attacks. As industrial environments become increasingly interconnected, vulnerabilities like this highlight the need for robust network segmentation, traffic monitoring, and timely application of security patches to prevent potential disruptions.
1 week ago
Kill Chain
Enhancing Critical Infrastructure Resilience: CISA's 'CI Fortify' Guidance
On July 28, 2026, the Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with international partners, released the 'CI Fortify – Advice for Isolating Vital Systems' guidance. This document provides critical infrastructure organizations with practical steps to isolate essential operational technology (OT) and supporting systems from other networks during cyber incidents or periods of heightened threat. The guidance emphasizes identifying critical systems, mapping their connections, and implementing effective separation points to ensure continuity of essential services during disruptions. The release of this guidance underscores the increasing cyber threats targeting critical infrastructure sectors. State-sponsored actors and cybercriminals are increasingly focusing on these sectors to conduct espionage or prepare for disruptive cyber activities. Implementing the recommended isolation strategies is vital for organizations to enhance their resilience and maintain operational continuity in the face of evolving cyber threats.
1 week ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports