✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Oil/Energy/Solar/Greentech
Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.
Explore Other Sectors
Oil/Energy/Solar/Greentech Threat Reports
BRIDGE:BREAK Vulnerabilities Threaten Critical Infrastructure Security
In April 2026, Forescout Technologies identified 22 vulnerabilities in serial-to-IP converters from Lantronix and Silex, devices integral to connecting legacy industrial equipment to modern networks. These vulnerabilities, collectively named BRIDGE:BREAK, could allow attackers to disrupt operations, move laterally across networks, tamper with sensitive data, or take control of affected devices. The flaws include remote code execution, authentication bypass, firmware manipulation, denial of service, and exposure of confidential information. Notably, tens of thousands of these devices are accessible over the internet, significantly broadening the attack surface for potential cyberattacks. This discovery underscores the persistent security challenges in operational technology environments, especially concerning devices that bridge legacy systems with modern infrastructure. The prevalence of these vulnerabilities highlights the need for organizations to reassess their security postures, particularly in sectors like utilities, manufacturing, and healthcare, where such devices are commonly deployed.
3 months ago
Kill Chain
Gentlemen Ransomware's Strategic Use of SystemBC Botnet in April 2026
In April 2026, the Gentlemen ransomware-as-a-service (RaaS) operation was found to be utilizing the SystemBC proxy malware to enhance its attack capabilities. This collaboration led to the creation of a botnet comprising over 1,570 compromised hosts, primarily targeting corporate environments. The attackers gained initial access, escalated privileges to Domain Admin, and deployed Cobalt Strike payloads for lateral movement. They then used SystemBC to establish covert command-and-control channels, facilitating the deployment of ransomware payloads across the network. This sophisticated attack chain resulted in significant operational disruptions and data encryption for the affected organizations. The integration of SystemBC into ransomware operations signifies a concerning evolution in cybercriminal tactics, emphasizing the need for organizations to bolster their defenses against such multifaceted threats. The incident underscores the importance of comprehensive security measures, including network segmentation, regular patching, and advanced threat detection systems, to mitigate the risks posed by increasingly sophisticated ransomware campaigns.
3 months ago
Kill Chain
Critical Authorization Flaw in AVEVA Pipeline Simulation: CVE-2026-5387
In April 2026, a critical vulnerability (CVE-2026-5387) was identified in AVEVA Pipeline Simulation software, affecting versions up to 2025 SP1 build 7.1.9497.6351. This flaw allows unauthenticated attackers to perform operations reserved for high-privilege roles, such as modifying simulation parameters and training records, leading to potential privilege escalation. ([cvefeed.io](https://cvefeed.io/vuln/detail/CVE-2026-5387?utm_source=openai)) The incident underscores the importance of robust authorization mechanisms in industrial control systems. Organizations are urged to upgrade to AVEVA Pipeline Simulation 2025 SP1 P01 (build 7.1.9580.8513) or higher and implement network access restrictions to mitigate this risk. ([aveva.com](https://www.aveva.com/en/support-and-success/cyber-security-updates/?utm_source=openai))
3 months ago
Kill Chain
Backdoor.MSIL.XWorm Phishing Campaign Compromises ICS Globally in Q4 2025
In Q4 2025, a significant phishing campaign known as "Curriculum-vitae-catalina" targeted HR personnel globally. Attackers sent emails disguised as job applications, with subjects like "Resume" or "Attached Resume," containing malicious attachments named "Curriculum Vitae-Catalina.exe." When executed, these files installed the Backdoor.MSIL.XWorm malware, granting remote control over infected systems. The campaign unfolded in two waves: the first in October affecting regions including Russia, Western Europe, South America, and Canada; the second in November impacting other areas. The attack subsided by December. Regions with historically high email threat rates, such as Southern Europe, South America, and the Middle East, reported the highest infection rates. In Africa, the malware also spread via USB devices connected to ICS computers. ([securelist.com](https://securelist.com/industrial-threat-report-q4-2025/119392/?utm_source=openai)) This incident underscores the evolving sophistication of phishing attacks targeting industrial control systems (ICS). The widespread distribution and rapid propagation of Backdoor.MSIL.XWorm highlight the critical need for enhanced email security measures and user awareness training to mitigate such threats.
3 months ago
Kill Chain
Volt Typhoon 2023: Unveiling the Chinese Cyber Threat to U.S. Infrastructure
In May 2023, Microsoft and U.S. intelligence agencies identified a Chinese state-sponsored cyber group, Volt Typhoon, infiltrating critical infrastructure sectors in the United States, including communications, manufacturing, utilities, and transportation. Active since mid-2021, Volt Typhoon employed 'living-off-the-land' techniques, utilizing legitimate system tools to evade detection, and targeted systems in Guam, a strategic U.S. military hub. The group's activities aimed to gather intelligence and potentially disrupt critical communications between the U.S. and Asia during future crises. ([techspot.com](https://www.techspot.com/news/98826-microsoft-global-intelligence-agencies-warn-chinese-hackers-infecting.html?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors to national security. The use of stealthy techniques by Volt Typhoon highlights the need for enhanced detection and response capabilities within critical infrastructure sectors to mitigate potential disruptions and safeguard sensitive information.
3 months ago
Kill Chain
Adobe Acrobat Reader Zero-Day CVE-2026-34621: A Critical Security Alert
In April 2026, Adobe released an emergency security update to address a critical zero-day vulnerability (CVE-2026-34621) in Acrobat Reader, which had been actively exploited since at least December 2025. This flaw allowed attackers to craft malicious PDF files that, when opened, could bypass sandbox restrictions and invoke privileged JavaScript APIs, leading to arbitrary code execution. The exploit enabled reading and exfiltrating arbitrary files without additional user interaction beyond opening the PDF. The incident underscores the persistent threat posed by zero-day vulnerabilities and the importance of timely software updates. Organizations are reminded to maintain robust patch management practices and exercise caution when handling unsolicited documents to mitigate similar risks.
3 months ago
Kill Chain
Iranian Cyberattack on U.S. Industrial Devices in 2026
In March 2026, Iranian state-sponsored hackers targeted U.S. critical infrastructure by exploiting internet-exposed Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs). These attacks led to operational disruptions and financial losses across sectors including government services, water and wastewater systems, and energy. The attackers extracted device project files and manipulated human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, compromising industrial processes. ([techcrunch.com](https://techcrunch.com/2026/04/07/iranian-hackers-are-targeting-american-critical-infrastructure-u-s-agencies-warn/?utm_source=openai)) This incident underscores the escalating cyber threats from nation-state actors targeting critical infrastructure. The exploitation of industrial control systems highlights the urgent need for enhanced cybersecurity measures, including network segmentation, regular patching, and the implementation of multifactor authentication to protect against such sophisticated attacks.
3 months ago
Kill Chain
APT28's PRISMEX Malware Campaign: A Threat to Global Security
In early 2026, the Russian state-sponsored group APT28, also known as Fancy Bear, launched a sophisticated cyber-espionage campaign targeting Ukraine and its NATO allies. The operation, active since at least September 2025 and intensifying in January 2026, involved the deployment of a modular malware suite named PRISMEX. This suite utilized advanced steganography, Component Object Model (COM) hijacking, and exploited newly disclosed vulnerabilities, including CVE-2026-21509 and CVE-2026-21513, to infiltrate defense supply chains and critical infrastructure sectors. The campaign's strategic focus on supply chains and operational planning capabilities underscores a shift toward operational disruption, potentially paving the way for more destructive activities. ([thehackernews.com](https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html?utm_source=openai)) The PRISMEX campaign highlights the persistent and evolving threat posed by APT28, emphasizing the necessity for organizations to adopt proactive cybersecurity measures. The rapid weaponization of vulnerabilities and the use of sophisticated techniques like steganography and cloud service abuse demonstrate the group's advanced capabilities. This incident serves as a critical reminder for entities within targeted sectors to enhance their security postures and remain vigilant against such advanced persistent threats. ([thehackernews.com](https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html?utm_source=openai))
3 months ago
Kill Chain
Iranian Cyberattacks on U.S. Critical Infrastructure: A 2026 Analysis
In March 2026, Iranian-affiliated cyber actors initiated a series of attacks targeting U.S. critical infrastructure sectors, including energy, water, and government services. These attackers exploited vulnerabilities in internet-exposed Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), leading to operational disruptions and financial losses. The Cybersecurity and Infrastructure Security Agency (CISA), along with other federal agencies, issued a joint advisory warning of these ongoing threats and provided mitigation strategies to affected organizations. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/us-warns-of-iranian-hackers-targeting-critical-infrastructure/?utm_source=openai)) This incident underscores the escalating cyber threat landscape, particularly from nation-state actors targeting industrial control systems. Organizations must prioritize securing operational technology environments to prevent similar disruptions and safeguard critical services.
3 months ago
Kill Chain
Handala Hack Team's 2026 Cyberattack on Stryker: A Wake-Up Call for Healthcare Cybersecurity
In March 2026, the pro-Iranian hacktivist group Handala Hack Team executed a significant cyberattack against Stryker Corporation, a U.S.-based multinational medical technology firm. The attackers deployed wiper malware, resulting in the destruction of data on over 200,000 devices and servers, and exfiltrated approximately 50 terabytes of sensitive information. This attack led to substantial operational disruptions for Stryker, particularly affecting its global operations and innovation hubs. ([ndtv.com](https://www.ndtv.com/world-news/handala-hacktivist-stryker-iran-war-live-how-iran-group-hacked-2-00-000-devices-in-cyber-onslaught-on-us-medtech-11210681?utm_source=openai)) This incident underscores the escalating cyber threats posed by nation-state-affiliated actors targeting critical infrastructure sectors. The use of destructive malware and large-scale data exfiltration highlights the need for enhanced cybersecurity measures and vigilance within the healthcare industry and beyond.
3 months ago
Kill Chain
Critical Vulnerability in GPL Odorizers GPL750 Devices (CVE-2026-4436)
In April 2026, a critical vulnerability (CVE-2026-4436) was identified in GPL Odorizers' GPL750 devices, which are used for odorant injection in natural gas pipelines. This flaw allows low-privileged remote attackers to manipulate register values via Modbus packets, potentially leading to incorrect odorant levels being injected into gas lines. Affected versions include GPL750 (XL4) >=v1.0, GPL750 (XL4 Prime) >=v4.0, GPL750 (XL7) >=v13.0, and GPL750 (XL7 Prime) >=v18.4. The vulnerability has a CVSS v3 base score of 8.6, indicating high severity. ([gasodorizer.com](https://www.gasodorizer.com/odorization/gpl-750-odorant-injection/?utm_source=openai)) The exploitation of this vulnerability could result in significant safety hazards due to improper odorization of natural gas, which is essential for leak detection. Organizations using these devices are urged to update to the latest software versions and implement recommended mitigations to prevent potential exploitation. ([gasodorizer.com](https://www.gasodorizer.com/odorization/gpl-750-odorant-injection/?utm_source=openai))
3 months ago
Kill Chain
Critical Vulnerability in Contemporary Controls BASC-20T Puts Industrial Systems at Risk
In April 2026, a critical vulnerability (CVE-2025-13926) was identified in Contemporary Controls' BASC-20T unitary controller, widely used in industrial control systems. This flaw allows attackers to intercept and manipulate network traffic, enabling unauthorized actions such as reconfiguring devices, renaming or deleting files, performing file transfers, and executing remote procedure calls. The vulnerability affects BASControl20 version 3.1 and poses significant risks to sectors like commercial facilities, critical manufacturing, and energy. ([building-controls.com](https://www.building-controls.com/products/ccs-basc20t?utm_source=openai)) This incident underscores the escalating threats to industrial control systems, with a notable increase in vulnerabilities and attacks targeting operational technology environments. Organizations must prioritize securing legacy systems, implementing robust network segmentation, and ensuring timely updates to mitigate such risks. ([infosecurity-magazine.com](https://www.infosecurity-magazine.com/news/industrial-control-system-vulns/?utm_source=openai))
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports