The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Oil/Energy/Solar/Greentech
Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.
Explore Other Sectors
Oil/Energy/Solar/Greentech Threat Reports
2025 Industrial Automation Breach Exposes Critical Infrastructure Through Supply Chain Attack
Between March and April 2025, foreign cyber actors infiltrated a U.S. industrial automation solutions company providing SCADA programming and system integration services to critical infrastructure entities including power utilities and transportation systems. The attackers conducted reconnaissance using search terms like 'customers' and 'SCADA,' subsequently creating nine ZIP files containing approximately 800 exfiltrated files including customer SCADA information, ICS device specifications, and operational schematics. This supply chain compromise exposed sensitive infrastructure data that could enable future disruptive attacks against operational technology environments. This incident highlights the growing threat to critical infrastructure through third-party integrator compromises, occurring amid increased focus on ICS security following recent nation-state campaigns targeting operational technology systems and growing regulatory emphasis on supply chain risk management in critical sectors.
7 hours ago
Kill Chain
Gulf Cyber Crisis: UAE and Saudi Arabia Under AI-Powered Attack Siege
The United Arab Emirates and Saudi Arabia absorbed 50% of all cyberattacks recorded across the Gulf region in the first half of 2026, with organizations experiencing nearly 2,700 attacks per week compared to the global average of 2,300. The attacks have shifted from highly visible DDoS and website defacements to sophisticated, targeted intrusions focusing on vulnerability exploitation (38% of initial access vectors), stealthy infiltration of critical infrastructure, and data gathering operations. These financially-motivated cybercriminals are leveraging AI tools to accelerate exploit development and target the expanded attack surfaces created by aggressive digital transformation initiatives in both nations. This incident reflects the broader evolution of cyber threats in 2026, where AI-assisted attackers are demonstrating near-autonomous capabilities that can progress faster than traditional defense mechanisms. The emergence of autonomous sandbox breakouts and AI-accelerated vulnerability discovery represents a fundamental shift in the threat landscape, forcing organizations to rethink their cybersecurity strategies beyond conventional perimeter defenses.
1 day ago
Kill Chain
Critical Path Traversal Flaw Exposes Siemens Industrial Systems to Remote File Access
Siemens SIMOVE Fleetmanager and SIPLANT industrial management systems contain a critical path traversal vulnerability (CVE-2026-67367) with a CVSS score of 8.6. The flaw allows unauthenticated remote attackers to read arbitrary files from the underlying operating system through improper validation of directory traversal sequences in the embedded HTTP server's file-serving endpoint. Affected systems span multiple product versions deployed worldwide in critical manufacturing sectors, potentially exposing sensitive data including credential stores, private keys, and configuration secrets. This vulnerability highlights the persistent security challenges in industrial control systems and operational technology environments. As organizations increasingly digitize their manufacturing operations and connect OT systems to corporate networks, path traversal vulnerabilities in critical infrastructure components represent a growing attack surface that demands immediate attention and systematic security controls.
2 days ago
Kill Chain
Critical lwIP MQTT Vulnerability Threatens Global Critical Infrastructure
A critical out-of-bounds write vulnerability (CVE-2026-87121) was discovered in the lwIP TCP/IP Stack MQTT Client Application versions 2.0.1 through 2.2.1, affecting industrial control systems across multiple critical infrastructure sectors worldwide. The vulnerability carries a CVSS score of 9.8 and enables remote attackers to achieve full code execution without authentication, potentially compromising devices in chemical, energy, healthcare, transportation, and water systems. The flaw was discovered by Shahriyar Jalayeri of ByteRay Ltd. and reported to CISA, with fixes available through the lwIP repository. This vulnerability highlights the growing threat landscape facing industrial IoT devices and embedded systems, as attackers increasingly target foundational networking components to gain persistent access to critical infrastructure networks.
2 days ago
Kill Chain
Critical Copy Fail Vulnerability Exposes Siemens Industrial Control Systems
In September 2026, CISA disclosed CVE-2026-31431, known as the "Copy Fail" vulnerability, affecting multiple Siemens SIPLUS and SIMATIC industrial control products. The vulnerability stems from incorrect resource transfer between spheres in the Linux kernel's crypto subsystem, specifically in the algif_aead component. With a CVSS score of 7.8, the flaw allows local attackers with low privileges to potentially achieve high confidentiality, integrity, and availability impacts on affected systems. Siemens has released patches for most affected products, updating them to version 21.2.1 or later, while recommending specific countermeasures for products where fixes are not yet available. This incident highlights the growing sophistication of attacks targeting industrial control systems and the critical importance of maintaining updated security patches in operational technology environments. As industrial networks become increasingly connected and digitized, vulnerabilities like Copy Fail demonstrate the urgent need for comprehensive security frameworks that can protect critical infrastructure from both known and emerging threats.
2 days ago
Kill Chain
Siemens Industrial Control Vulnerability Exposes Critical Infrastructure to Denial of Service Attacks
Siemens has disclosed a critical vulnerability (CVE-2026-89207) affecting WTV676 and WTV776 industrial control devices used in energy infrastructure worldwide. The vulnerability allows unauthenticated remote attackers to exploit improper input validation from backend services, forcing devices into protection mode and disabling remote connectivity functions. This denial of service attack vector poses significant operational risks to critical infrastructure, particularly in energy sectors where these devices are deployed globally. The CVSS 6.5 rated vulnerability affects WTV676-HB6035 Web Interface versions below 3.94 and WTV776-HB6035 Web Interface versions below 4.17. This incident highlights the ongoing challenge of securing industrial control systems as cyber threats increasingly target critical infrastructure. With growing concerns about nation-state actors and ransomware groups focusing on operational technology environments, vulnerabilities in widely-deployed industrial devices represent escalating risks to essential services and national security.
2 days ago
Kill Chain
Critical Authentication Bypass in Siemens Industrial Edge Management Exposes Global Manufacturing Infrastructure
In September 2026, CISA published an advisory regarding a critical authentication bypass vulnerability (CVE-2026-18963) affecting Siemens Industrial Edge Management systems worldwide. The vulnerability, with a CVSS score of 9.1, allows unauthenticated remote attackers to perform complete account takeovers by exploiting the password reset mechanism without requiring email verification. The flaw affects multiple versions of Industrial Edge Management Cloud, Pro V1, Pro V2, and Virtual editions used in critical manufacturing environments globally. Siemens has released patches and implemented firewall rules to mitigate the threat. This incident highlights the growing threat landscape targeting industrial control systems and critical infrastructure, particularly as organizations increasingly adopt cloud-connected industrial IoT platforms. The vulnerability's high severity and potential for complete account compromise underscores the urgent need for robust authentication mechanisms and zero-trust security models in operational technology environments.
2 days ago
Kill Chain
Critical XSS Vulnerability in OpenPLC Runtime v3 Threatens Industrial Control Systems
A critical cross-site scripting (XSS) vulnerability (CVE-2026-88020) was discovered in OpenPLC Runtime v3, an open-source programmable logic controller platform used across critical infrastructure sectors including manufacturing, energy, transportation, and water systems. The vulnerability allows attackers to hijack session cookies and issue state-changing requests as operators, potentially enabling unauthorized control of industrial processes and physical systems. With a CVSS score of 6.1, the flaw stems from improper input neutralization in the web interface's query string parameter handling, affecting the end-of-life OpenPLC v3 platform deployed worldwide. This vulnerability highlights the growing cybersecurity risks facing industrial control systems as they become increasingly connected to corporate networks and the internet. The convergence of IT and OT security challenges continues to expand the attack surface for critical infrastructure, making legacy industrial systems attractive targets for nation-state actors and cybercriminals seeking to disrupt essential services.
2 days ago
Kill Chain
FamousSparrow's Latin America Campaign: When Cyber Espionage Meets Geopolitical Competition
In July 2025, the Chinese APT group FamousSparrow pivoted to exclusively target Latin American government organizations using a new custom backdoor called SparroWocky. The campaign focuses on countries with significant Chinese Belt and Road Initiative investments including Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group deployed sophisticated evasion techniques including stack spoofing, in-memory execution, encrypted C2 communications, and Beacon Object File compatibility to maintain persistent access while monitoring government responses to US pressure on Chinese regional influence. This incident represents the new reality of cyber espionage in geopolitical competition, as nation-state actors increasingly use targeted surveillance to gain strategic intelligence about economic and political developments that affect their global investments and sphere of influence.
6 days ago
Kill Chain
Critical Privilege Escalation Flaw Exposes ABB Industrial Edge Computing Platforms
ABB disclosed CVE-2026-31431 (Copy Fail), a critical Linux kernel vulnerability affecting ABB Ability Edgenius edge computing platforms versions 3.2.0.0 through 3.2.4.1. The vulnerability, with a CVSS score of 7.8, stems from incorrect resource transfer in the Linux kernel's cryptographic subsystem and allows locally authenticated users or compromised container workloads to escalate privileges to root access. Once exploited, attackers gain complete system control over industrial edge computing infrastructure deployed globally across critical manufacturing, energy, water, and chemical sectors. ABB has released version 3.2.4.1 to address the vulnerability and recommends immediate patching. This incident highlights the growing attack surface of edge computing in industrial environments, where kernel-level vulnerabilities can provide attackers with deep system access to compromise operational technology networks and critical infrastructure control systems.
6 days ago
Kill Chain
CVE-2025-6625: Critical FTP Vulnerability in Schneider Electric Industrial Controllers
Schneider Electric disclosed CVE-2025-6625, a high-severity improper input validation vulnerability affecting Modicon M340 controllers and communication modules used across critical infrastructure sectors including energy, chemical, and water systems. The vulnerability allows attackers to send crafted FTP commands to cause denial of service attacks, potentially disrupting industrial control systems. Multiple product versions are affected, with firmware updates available for some modules while others await remediation. The vulnerability carries a CVSS score of 7.5 and impacts globally deployed industrial automation systems. This incident highlights the ongoing security challenges facing industrial control systems as threat actors increasingly target operational technology environments. With critical infrastructure under heightened scrutiny following recent nation-state campaigns, vulnerabilities in widely-deployed industrial controllers represent significant risk amplification across interconnected systems.
6 days ago
Kill Chain
Critical Vulnerabilities Disclosed in Hitachi Energy Power Grid Control Systems
CISA published advisory ICSA-26-260-03 disclosing critical vulnerabilities in Hitachi Energy's FACTS Control Platform (FCP) affecting multiple versions from 3.4.0 to 4.1.1 when deployed with the GWS component. The vulnerabilities include SQL injection (CVE-2024-4872), path traversal (CVE-2024-3980), session hijacking (CVE-2024-3982), missing authentication (CVE-2024-7940), and open redirect (CVE-2024-7941) with CVSS scores ranging from 4.3 to 9.9. These flaws could allow authenticated attackers to execute code injection, access critical system files, hijack sessions, and redirect users to malicious sites, potentially compromising the confidentiality, integrity, and availability of critical power grid infrastructure. This disclosure highlights the growing cybersecurity challenges facing operational technology in the energy sector, particularly as industrial control systems become increasingly connected and targeted by sophisticated threat actors seeking to disrupt critical infrastructure operations.
6 days ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports