The Containment Era is here. →Explore

Industry Category

Oil/Energy/Solar/Greentech

Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.

378 threat reports
Page 15 of 32

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Oil/Energy/Solar/Greentech Threat Reports

Showing 169180 / 378 reports
Operation Winter SHIELD 2026: A Proactive Approach to Cybersecurity
Impact· CRITICAL

Operation Winter SHIELD 2026: A Proactive Approach to Cybersecurity

In February 2026, the FBI launched Operation Winter SHIELD, a nine-week cybersecurity initiative aimed at enhancing the nation's defenses against escalating cyber threats targeting critical infrastructure sectors. The campaign emphasized the implementation of ten key defensive measures, including adopting phish-resistant authentication, managing third-party risks, and maintaining offline, immutable backups. This proactive approach was designed to address the growing sophistication of cyber adversaries and the increasing frequency of attacks on essential services. The initiative underscored the urgent need for organizations to move beyond awareness and actively implement robust cybersecurity practices. With cyberattacks becoming more sophisticated and pervasive, Operation Winter SHIELD served as a call to action for both public and private sectors to fortify their defenses and ensure the resilience of critical infrastructure against potential disruptions.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Iranian State-Backed Pay2Key Ransomware Targets U.S. Healthcare in 2026
Impact· HIGH

Iranian State-Backed Pay2Key Ransomware Targets U.S. Healthcare in 2026

In late February 2026, the Iranian state-backed ransomware group Pay2Key targeted an unnamed U.S. healthcare organization. The attackers gained access through a compromised administrator account, maintained presence for several days, and then deployed ransomware that encrypted the organization's systems within approximately three hours. Notably, no data exfiltration was detected, and no ransom demand was made, suggesting a shift towards purely disruptive operations. ([halcyon.ai](https://www.halcyon.ai/ransomware-research-reports/pay2key-iranian-linked-ransomware-is-back-back-again?utm_source=openai)) This incident underscores the evolving tactics of state-sponsored cyber actors, particularly Iran's use of ransomware as a tool for geopolitical objectives. The healthcare sector remains a prime target due to its critical nature and potential for widespread disruption. Organizations must enhance their cybersecurity posture to defend against such sophisticated threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Bearlyfy's 2025 Ransomware Campaign Against Russian Companies
Impact· HIGH

Bearlyfy's 2025 Ransomware Campaign Against Russian Companies

In early 2025, the pro-Ukrainian cyber group Bearlyfy initiated a series of over 70 ransomware attacks targeting Russian companies. Employing custom strains like GenieLocker, Bearlyfy exploited vulnerabilities in public-facing applications to gain initial access, subsequently encrypting critical data and demanding ransoms. The group's operations have caused significant disruptions across various sectors in Russia. This incident underscores a growing trend of politically motivated cyberattacks, where hacktivist groups leverage ransomware to inflict economic damage. The Bearlyfy attacks highlight the evolving landscape of cyber threats, emphasizing the need for robust security measures to protect against both financially and ideologically driven adversaries.

4 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities in WAGO Industrial Managed Switches Expose Systems to Remote Attacks
Impact· CRITICAL

Critical Vulnerabilities in WAGO Industrial Managed Switches Expose Systems to Remote Attacks

In early 2026, multiple critical vulnerabilities were discovered in WAGO GmbH & Co. KG's Industrial Managed Switches, notably models 852-1322 and 852-1328. These flaws, including stack buffer overflows and authentication bypasses, allowed unauthenticated remote attackers to execute arbitrary code, potentially leading to full system compromise. The vulnerabilities stemmed from unsafe input handling in the devices' web-based management interfaces, which utilized modified lighttpd servers and custom CGI binaries. Exploitation could result in denial-of-service conditions and unauthorized access to sensitive configurations. ([certvde.com](https://certvde.com/en/advisories/VDE-2026-004/?utm_source=openai)) This incident underscores the persistent risks associated with industrial control systems (ICS) and the critical need for robust security measures. The vulnerabilities highlight the importance of regular firmware updates, secure coding practices, and comprehensive network segmentation to protect against unauthorized access and potential operational disruptions.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Schneider Electric's Foxboro DCS Vulnerability Exposes Critical Infrastructure to Cyber Threats
Impact· HIGH

Schneider Electric's Foxboro DCS Vulnerability Exposes Critical Infrastructure to Cyber Threats

In March 2026, Schneider Electric disclosed a deserialization vulnerability (CVE-2026-1286) in its EcoStruxure Foxboro DCS versions prior to CS8.1. This flaw allows an authenticated administrator to execute arbitrary code by opening a malicious project file, potentially compromising system confidentiality, integrity, and availability. The vulnerability affects critical infrastructure sectors globally, including energy and manufacturing. ([cvedetails.com](https://www.cvedetails.com/cve/CVE-2026-1286/?utm_source=openai)) This incident underscores the persistent risks associated with deserialization vulnerabilities in industrial control systems. Organizations must prioritize timely software updates and implement strict access controls to mitigate such threats effectively.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities in Schneider Electric's Plant iT/Brewmaxx Systems: Immediate Action Required
Impact· CRITICAL

Critical Vulnerabilities in Schneider Electric's Plant iT/Brewmaxx Systems: Immediate Action Required

In March 2026, Schneider Electric disclosed multiple critical vulnerabilities in its Plant iT/Brewmaxx systems, stemming from the integration of Redis, an open-source in-memory database. These vulnerabilities, identified as CVE-2025-49844, CVE-2025-46817, CVE-2025-46818, and CVE-2025-46819, involve issues such as use-after-free errors and integer overflows within Redis's Lua scripting engine. Exploitation of these flaws could allow authenticated users to execute arbitrary code, leading to potential remote code execution and privilege escalation. The affected versions include Plant iT/Brewmaxx 9.60 and above. Schneider Electric has released patches and provided mitigation steps to address these vulnerabilities. ([se.com](https://www.se.com/in/en/download/document/SEVD-2026-013-01/?utm_source=openai)) The disclosure underscores the critical importance of securing third-party components within industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, organizations must remain vigilant, ensuring timely updates and adherence to cybersecurity best practices to mitigate potential risks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Siemens SICAM SIAPP SDK Vulnerabilities: What You Need to Know
Impact· HIGH

Siemens SICAM SIAPP SDK Vulnerabilities: What You Need to Know

In March 2026, Siemens disclosed multiple vulnerabilities in its SICAM SIAPP SDK versions prior to 2.1.7. These vulnerabilities include out-of-bounds write, stack-based buffer overflow, improper handling of length parameter inconsistency, and external control of file name or path. Exploitation could lead to denial of service, data corruption, or arbitrary code execution. Siemens has released version 2.1.7 to address these issues and recommends users update promptly. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-903736.html?utm_source=openai)) This incident underscores the critical importance of timely software updates and robust input validation in industrial control systems to prevent potential exploitation and ensure operational integrity.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Iranian Cyber Threat Evolution: Exploiting MDM Platforms in 2026
Impact· HIGH

Iranian Cyber Threat Evolution: Exploiting MDM Platforms in 2026

In March 2026, Iranian state-sponsored cyber actors executed a large-scale attack by compromising privileged identities within cloud-based Mobile Device Management (MDM) platforms. This allowed them to issue legitimate remote-wipe commands, resulting in the simultaneous erasure of data from over 200,000 devices globally. The attack exploited administrative tools to bypass traditional endpoint detection systems, leading to significant operational disruptions across multiple organizations. This incident underscores a strategic shift in Iranian cyber operations from deploying custom malware to leveraging existing administrative infrastructures for destructive purposes. The use of legitimate management tools for widescale data destruction highlights the evolving threat landscape and the need for organizations to enhance identity and access management protocols to mitigate such risks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Aurora Generator Test 2007: A Cybersecurity Wake-Up Call for Critical Infrastructure
Impact· CRITICAL

Aurora Generator Test 2007: A Cybersecurity Wake-Up Call for Critical Infrastructure

In March 2007, the Aurora Generator Test conducted by the Idaho National Laboratory demonstrated the potential for cyberattacks to physically destroy critical infrastructure. By exploiting vulnerabilities in industrial control systems, researchers remotely manipulated a diesel generator's circuit breakers, causing it to operate out of phase and ultimately leading to its destruction. This experiment highlighted the susceptibility of power grids to cyber threats, especially due to the use of legacy communication protocols lacking security measures. The Aurora Generator Test remains relevant today as it underscores the ongoing risks associated with outdated industrial control systems. Despite advancements in cybersecurity, many critical infrastructures still rely on legacy systems, making them vulnerable to similar attacks. This incident serves as a cautionary tale, emphasizing the need for continuous assessment and upgrading of security protocols in industrial environments.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Poland's Nuclear Research Center Successfully Defends Against Cyberattack
Impact· NONE

Poland's Nuclear Research Center Successfully Defends Against Cyberattack

In March 2026, Poland's National Centre for Nuclear Research (NCBJ) successfully thwarted a cyberattack targeting its IT infrastructure. The institute's security systems and internal procedures detected the intrusion early, preventing any compromise to their systems. Notably, the MARIA reactor, Poland's sole nuclear reactor used for scientific research and medical isotope production, remained unaffected and continued to operate safely at full capacity. While the NCBJ did not attribute the attack to any specific entity, reports suggest potential involvement of Iranian actors, though investigators caution that these indicators may be deceptive. This incident underscores the escalating cyber threats faced by critical infrastructure globally, particularly in the nuclear sector. Organizations must remain vigilant, continuously enhancing their cybersecurity measures to detect and respond to such sophisticated attacks promptly.

4 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in Inductive Automation's Ignition Software: CVE-2025-13911
Impact· MEDIUM

Critical Vulnerability in Inductive Automation's Ignition Software: CVE-2025-13911

In December 2025, a vulnerability (CVE-2025-13911) was identified in Inductive Automation's Ignition SCADA software versions 8.1.x and 8.3.x. This flaw allows authenticated administrators to upload malicious project files containing Python scripts, which execute with SYSTEM-level privileges on Windows systems. The vulnerability arises from insufficient restrictions on Python library imports within the scripting environment, combined with the Ignition service account possessing excessive system permissions. Exploitation could lead to full system compromise, enabling attackers to manipulate automation processes, disrupt operations, exfiltrate sensitive data, or deploy ransomware. ([support.inductiveautomation.com](https://support.inductiveautomation.com/hc/en-us/articles/41992057776397-Script-Resource-Import-Vulnerability-for-Windows-CVE-2025-13911?utm_source=openai)) This incident underscores the critical importance of implementing the principle of least privilege and enforcing strict validation of imported project files in industrial control systems. Organizations must prioritize mitigating such vulnerabilities to safeguard against potential operational disruptions and security breaches.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities in Siemens RUGGEDCOM APE1808 Devices: What You Need to Know
Impact· CRITICAL

Critical Vulnerabilities in Siemens RUGGEDCOM APE1808 Devices: What You Need to Know

In March 2026, Siemens disclosed multiple vulnerabilities in its RUGGEDCOM APE1808 devices, which integrate Fortinet's FortiOS. These vulnerabilities include HTTP request smuggling (CVE-2025-55018), improper verification of communication channels (CVE-2025-62439), use of externally-controlled format strings (CVE-2025-64157), and authentication bypass via alternate paths (CVE-2026-24858). Exploitation could allow unauthenticated attackers to execute arbitrary code, bypass authentication mechanisms, or cause denial-of-service conditions. Siemens has released updates to address these issues and recommends users update to the latest firmware versions. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-698820.html?utm_source=openai)) The disclosure underscores the critical need for organizations to promptly apply security patches, especially in industrial control systems. The vulnerabilities highlight the importance of securing supply chain components and ensuring that third-party integrations do not introduce security risks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports