✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Oil/Energy/Solar/Greentech
Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.
Explore Other Sectors
Oil/Energy/Solar/Greentech Threat Reports
Iran-Linked Hackers Target U.S. Critical Infrastructure in 2026
In early April 2026, Iran-affiliated cyber actors targeted internet-facing operational technology (OT) devices across U.S. critical infrastructure sectors, including programmable logic controllers (PLCs) manufactured by Rockwell Automation. These attacks led to diminished PLC functionality, manipulation of display data, and, in some cases, operational disruption and financial loss. The Cybersecurity and Infrastructure Security Agency (CISA), along with the FBI and NSA, issued warnings about these threats, emphasizing the need for immediate action to secure vulnerable OT assets. ([nextgov.com](https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/?utm_source=openai)) This incident underscores the escalating cyber threats from nation-state actors targeting critical infrastructure. The exploitation of internet-exposed PLCs highlights the urgent need for organizations to implement robust cybersecurity measures, including network segmentation, regular software updates, and the use of strong, unique passwords to protect against such sophisticated attacks.
3 months ago
Kill Chain
Iranian APT Exploits PLC Vulnerabilities in U.S. Critical Infrastructure
In April 2026, Iranian-affiliated advanced persistent threat (APT) actors targeted internet-facing operational technology (OT) devices, specifically programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley, across multiple U.S. critical infrastructure sectors. These attacks led to disruptions in energy, water, and government facilities by manipulating project files and tampering with human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruptions and financial losses. ([databreaches.net](https://databreaches.net/2026/04/07/iranian-affiliated-cyber-actors-exploit-programmable-logic-controllers-across-us-critical-infrastructure/?utm_source=openai)) This incident underscores the escalating cyber threats from nation-state actors targeting critical infrastructure, highlighting the urgent need for enhanced cybersecurity measures and vigilance in protecting OT environments.
3 months ago
Kill Chain
Mitsubishi Electric's 2025 Vulnerability: A Wake-Up Call for Industrial Security
In May 2025, Mitsubishi Electric disclosed a vulnerability (CVE-2025-0921) in their GENESIS64, MC Works64, and GENESIS products. This flaw allows local attackers to perform unauthorized writes to arbitrary files by exploiting symbolic links, potentially leading to denial-of-service conditions. The vulnerability affects all versions of GENESIS64 and MC Works64, as well as GENESIS version 11.00. Mitsubishi Electric has released patches and mitigation strategies to address this issue. ([mitsubishielectric.com](https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-002_en.pdf?utm_source=openai)) This incident underscores the critical importance of securing industrial control systems against local privilege escalation attacks, which can disrupt essential operations. Organizations are urged to apply the provided patches promptly and review their security protocols to prevent similar vulnerabilities.
3 months ago
Kill Chain
Iranian APT Exploits U.S. Critical Infrastructure PLCs in 2026
In April 2026, Iranian-affiliated advanced persistent threat (APT) actors exploited internet-facing operational technology (OT) devices, notably Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), across multiple U.S. critical infrastructure sectors. The attackers accessed these devices via default or weak credentials, leading to disruptions through malicious interactions with project files and manipulation of data on human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruptions and financial losses. ([publicpower.org](https://www.publicpower.org/periodical/article/iranian-affiliated-cyber-actors-exploit-programmable-logic-controllers-across-us-critical?utm_source=openai)) This incident underscores the escalating threat posed by nation-state actors targeting critical infrastructure. The exploitation of OT devices highlights the urgent need for organizations to secure internet-facing systems, implement strong authentication measures, and regularly update and patch their systems to mitigate such risks.
3 months ago
Kill Chain
Forest Blizzard 2026: Unveiling and Neutralizing a Global Espionage Threat
In early 2026, the Russian state-sponsored group Forest Blizzard (APT28) compromised over 18,000 routers across 120 countries, exploiting known vulnerabilities in TP-Link and MikroTik devices. By hijacking DNS settings, they conducted adversary-in-the-middle attacks, intercepting credentials and tokens for services like Microsoft Outlook Web Access. This extensive espionage campaign targeted more than 200 organizations, including government agencies and critical infrastructure sectors. A collaborative effort led by the FBI, known as Operation Masquerade, successfully neutralized the threat by resetting DNS settings and preventing further exploitation. This incident underscores the persistent threat posed by state-sponsored cyber actors and highlights the critical need for robust network security measures. Organizations must remain vigilant, regularly update and patch network devices, and implement comprehensive monitoring to detect and mitigate such sophisticated attacks.
3 months ago
Kill Chain
Iranian Hackers Exploit PLC Vulnerabilities in U.S. Critical Infrastructure
In March 2026, Iranian-affiliated Advanced Persistent Threat (APT) actors initiated cyberattacks targeting internet-exposed Rockwell/Allen-Bradley programmable logic controllers (PLCs) within U.S. critical infrastructure sectors, including Government Services, Water and Wastewater Systems, and Energy. These attacks involved unauthorized access to PLCs, manipulation of project files, and alteration of data displayed on Human-Machine Interface (HMI) and Supervisory Control and Data Acquisition (SCADA) systems, leading to operational disruptions and financial losses. This incident underscores the escalating cyber threat landscape, particularly in the context of geopolitical tensions. Organizations must prioritize securing internet-facing operational technology assets to mitigate risks associated with state-sponsored cyber activities.
3 months ago
Kill Chain
Forest Blizzard's 2026 SOHO Router DNS Hijacking: A Wake-Up Call for Network Security
In April 2026, the Russian state-sponsored group Forest Blizzard exploited vulnerabilities in small office/home office (SOHO) routers to perform DNS hijacking and adversary-in-the-middle (AiTM) attacks. By compromising these routers, they redirected DNS requests through attacker-controlled servers, enabling interception of sensitive communications. This campaign affected over 200 organizations and 5,000 consumer devices, primarily targeting sectors such as government, IT, telecommunications, and energy. The attackers leveraged the compromised infrastructure to collect intelligence and potentially facilitate further malicious activities. This incident underscores the critical need for securing SOHO devices, as they can serve as entry points for sophisticated cyberattacks. Organizations must prioritize regular firmware updates, enforce strong authentication measures, and monitor network traffic for anomalies to mitigate such threats.
3 months ago
Kill Chain
Critical RCE Vulnerability in Hitachi Energy's Ellipse Platform
In early 2026, a critical vulnerability (CVE-2025-10492) was identified in Hitachi Energy's Ellipse enterprise asset management platform, specifically within the JasperReports component used for custom reporting. This Java deserialization flaw allows remote code execution without authentication or user interaction, affecting Ellipse versions 9.0.50 and earlier. The vulnerability poses significant risks to critical infrastructure sectors, including energy and manufacturing, by potentially enabling unauthorized access and control over essential systems. ([windowsforum.com](https://windowsforum.com/threads/hitachi-ellipse-jasperreports-flaw-cve-2025-10492-rce-risk-and-mitigation-steps.409447/?utm_source=openai)) The exploitation of this vulnerability underscores the persistent threat posed by deserialization flaws in widely used third-party libraries. Organizations are urged to assess their exposure, apply available patches, and implement recommended mitigations to safeguard against potential attacks targeting this and similar vulnerabilities.
3 months ago
Kill Chain
Siemens SICAM 8 Vulnerabilities: Protecting Critical Infrastructure
In March 2026, Siemens identified two critical vulnerabilities in its SICAM 8 industrial control products: CVE-2026-27663 and CVE-2026-27664. CVE-2026-27663 is a denial-of-service vulnerability in CPCI85 and RTUM85 devices, where high-volume requests can exhaust system resources, leading to operational disruptions. CVE-2026-27664 is an out-of-bounds write vulnerability in CPCI85 and SICORE systems, exploitable through specially crafted XML inputs, potentially causing service crashes. Siemens has released firmware updates (V26.10 and V26.10.0) to address these issues. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-27663/?utm_source=openai)) These vulnerabilities highlight the ongoing risks in industrial control systems, emphasizing the need for timely patch management and robust network security measures to protect critical infrastructure from potential cyber threats.
3 months ago
Kill Chain
Yokogawa CENTUM VP Hardcoded Password Vulnerability Exposes Industrial Systems
In March 2026, a hardcoded password vulnerability (CVE-2025-7741) was identified in Yokogawa's CENTUM VP distributed control system. This flaw allows attackers with access to the Human Interface Station (HIS) to log in using the 'PROG' user account, potentially modifying system permissions. Affected versions include CENTUM VP R5.01.00 to R5.04.20, R6.01.00 to R6.12.00, and R7.01.00. Exploitation requires prior access to the HIS screen controls, limiting the immediate risk but highlighting significant security concerns in industrial control systems. ([cvedetails.com](https://www.cvedetails.com/cve/CVE-2025-7741/?utm_source=openai)) This incident underscores the critical need for robust authentication mechanisms in industrial environments. The reliance on hardcoded credentials poses substantial risks, especially when combined with potential insider threats or physical access breaches. Organizations must prioritize updating authentication protocols and implementing comprehensive security measures to mitigate such vulnerabilities.
3 months ago
Kill Chain
Operation TrueChaos: Exploiting Trust in Software Updates
In early 2026, a sophisticated cyber espionage campaign, dubbed 'Operation TrueChaos,' exploited a zero-day vulnerability (CVE-2026-3502) in the TrueConf video conferencing software. This flaw allowed attackers to manipulate the software's update mechanism, distributing malicious updates to all connected clients without proper integrity checks. The campaign primarily targeted government entities in Southeast Asia, enabling the execution of arbitrary code across multiple agencies simultaneously. The attackers leveraged this vulnerability to deploy the Havoc command-and-control framework, facilitating reconnaissance, privilege escalation, and persistent access within the compromised networks. The operation is attributed with moderate confidence to a Chinese-nexus threat actor, based on observed tactics, techniques, and infrastructure choices. This incident underscores the critical need for organizations to implement robust validation mechanisms for software updates and to monitor internal systems for signs of compromise, even within trusted environments. The exploitation of trusted update mechanisms highlights a growing trend where attackers target internal trust relationships to achieve widespread access and control.
3 months ago
Kill Chain
Critical Vulnerability in Delta Electronics COMMGR2: CVE-2026-3630
In March 2026, Delta Electronics disclosed a critical stack-based buffer overflow vulnerability (CVE-2026-3630) in their COMMGR2 software, widely used in industrial automation. This flaw allows unauthenticated remote attackers to execute arbitrary code, potentially leading to full system compromise. The vulnerability affects COMMGR2 versions up to and including 2.11.0. Delta Electronics has released a security advisory (Delta-PCSA-2026-00005) detailing the issue and providing mitigation steps. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-3630?utm_source=openai)) The disclosure underscores the persistent risks in industrial control systems and the importance of timely patching. Organizations in manufacturing, energy, and logistics sectors should prioritize updating affected systems to prevent potential exploitation. ([praetorian.com](https://www.praetorian.com/blog/cve-2026-3630/?utm_source=openai))
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports