✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Oil/Energy/Solar/Greentech
Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.
Explore Other Sectors
Oil/Energy/Solar/Greentech Threat Reports
Chinese APT Group Exploits Middle East Tensions to Target Qatar with PlugX Malware
In early March 2026, the Chinese-linked Advanced Persistent Threat (APT) group known as Camaro Dragon launched a cyber-espionage campaign targeting entities in Qatar. Within 24 hours of the escalation of Middle East tensions, the group deployed PlugX malware using war-themed lure documents that mimicked legitimate communications related to the regional conflict. The infection chain involved malicious LNK files leading to DLL hijacking of a legitimate Baidu NetDisk binary, ultimately installing the PlugX backdoor. This malware enables remote command execution, keystroke logging, screen capture, and data exfiltration. The rapid deployment and contextually relevant lures highlight the group's ability to swiftly adapt to geopolitical events for intelligence gathering purposes. This incident underscores the increasing trend of state-sponsored cyber actors exploiting current geopolitical crises to enhance the effectiveness of their campaigns. Organizations, especially those in geopolitically sensitive regions, must remain vigilant against such rapidly evolving threats and ensure robust cybersecurity measures are in place to detect and mitigate sophisticated intrusion attempts.
4 months ago
Kill Chain
Critical Vulnerability in Ceragon and Siklu's EtherHaul and MultiHaul Devices (CVE-2025-57176)
In September 2025, a critical vulnerability (CVE-2025-57176) was identified in Ceragon Networks and Siklu Communication's EtherHaul and MultiHaul series devices. The 'rfpiped' service on TCP port 555 allowed unauthenticated file uploads to any writable location on the device. This flaw, present in firmware versions 7.4.0 through 10.7.3, utilized weak encryption for metadata and transmitted file contents in cleartext, lacking authentication and path validation. Exploitation could lead to unauthorized access and control over affected devices. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-57176?utm_source=openai)) This incident underscores the persistent risks associated with inadequate authentication mechanisms in network devices. Organizations must prioritize regular firmware updates and implement robust access controls to mitigate such vulnerabilities.
4 months ago
Kill Chain
Chinese Cyber Threat Targets Asian Critical Infrastructure
Since at least 2020, a Chinese-speaking threat actor identified as CL-UNK-1068 has been conducting cyber-espionage campaigns targeting critical infrastructure sectors across South, Southeast, and East Asia. The sectors affected include aviation, energy, government, law enforcement, pharmaceuticals, technology, and telecommunications. The attackers exploit vulnerabilities in public-facing web servers to gain initial access, deploying web shells like GodZilla and AntSword to maintain control. They employ tools such as Mimikatz and LsaRecorder for credential theft, and utilize custom malware alongside open-source utilities to facilitate lateral movement and data exfiltration. ([darkreading.com](https://www.darkreading.com/threat-intelligence/chinese-cyber-threat-critical-asian-sectors?utm_source=openai))This incident underscores the persistent and evolving nature of cyber threats from state-sponsored actors, particularly those linked to China. The use of sophisticated tools and techniques highlights the need for organizations to enhance their cybersecurity measures to detect and mitigate such threats effectively. ([darkreading.com](https://www.darkreading.com/threat-intelligence/chinese-cyber-threat-critical-asian-sectors?utm_source=openai))
4 months ago
Kill Chain
Critical Vulnerabilities in Hikvision and Rockwell Automation Devices Added to CISA KEV Catalog
In March 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2017-7921 affecting Hikvision products and CVE-2021-22681 impacting Rockwell Automation devices. CVE-2017-7921 is an improper authentication flaw that allows attackers to escalate privileges and access sensitive information in Hikvision cameras. CVE-2021-22681 involves insufficiently protected credentials in Rockwell Automation's Studio 5000 Logix Designer and related controllers, enabling unauthorized users to bypass verification mechanisms and alter device configurations. Both vulnerabilities have a CVSS score of 9.8, indicating their severity and the potential risk to critical infrastructure. The inclusion of these vulnerabilities in the KEV catalog underscores the ongoing threat posed by unpatched security flaws in widely used industrial and surveillance equipment. Organizations are urged to prioritize remediation efforts to mitigate the risk of exploitation, especially given the active targeting of such vulnerabilities by malicious actors.
4 months ago
Kill Chain
Iran's Integration of Cyber and Kinetic Warfare in 2026
In early 2026, Iranian threat actors intensified cyber operations targeting internet-connected surveillance cameras across the Middle East, including Israel, Qatar, Bahrain, Kuwait, the UAE, and Cyprus. These attacks, which began on February 28, coincided with missile strikes in the region, suggesting a coordinated effort to use compromised cameras for operational planning and battle damage assessment. The targeted devices, primarily from manufacturers Hikvision and Dahua, were exploited using known vulnerabilities, aligning with Iran's established military doctrine of integrating cyber and kinetic warfare. This incident underscores the evolving nature of cyber threats, where digital intrusions are increasingly used to support and enhance physical military operations. Organizations must recognize the strategic use of cyber capabilities in modern conflicts and bolster their defenses accordingly.
4 months ago
Kill Chain
Iranian Cyber Actors Escalate Attacks on Global Infrastructure in 2026
In early March 2026, Iranian state-affiliated cyber actors launched a coordinated campaign targeting critical infrastructure across Israel, Gulf Cooperation Council countries, Europe, and North America. The attacks, coinciding with joint U.S.-Israeli military operations, included over 150 incidents such as DDoS attacks, website defacements, and data exfiltration operations against sectors like government, finance, aviation, telecommunications, and energy. ([objectwire.org](https://www.objectwire.org/google/news/iran-cyber-attacks-google-threat-intelligence-march-2026?utm_source=openai)) This escalation underscores the persistent and evolving cyber threat posed by Iranian actors, highlighting the need for heightened vigilance and robust cybersecurity measures to protect critical infrastructure globally.
4 months ago
Kill Chain
Surge in Hacktivist DDoS Attacks Amid Middle East Tensions
Between February 28 and March 2, 2026, a surge of 149 hacktivist-driven distributed denial-of-service (DDoS) attacks targeted 110 organizations across 16 countries. This wave of cyber assaults was primarily in response to the U.S.-Israel coordinated military campaign against Iran, codenamed Epic Fury and Roaring Lion. The attacks predominantly focused on government entities, financial institutions, and telecommunications sectors, with the majority occurring in the Middle East, particularly in Kuwait, Israel, and Jordan. Notably, two hacktivist groups, Keymous+ and DieNet, were responsible for nearly 70% of the attack activity during this period. ([thehackernews.com](https://thehackernews.com/2026/03/149-hacktivist-ddos-attacks-hit-110.html?utm_source=openai)) This incident underscores the escalating trend of cyber retaliation in geopolitical conflicts, highlighting the need for organizations to bolster their cybersecurity defenses against ideologically motivated threat actors. The concentrated nature of these attacks emphasizes the importance of proactive threat intelligence and robust incident response strategies to mitigate potential disruptions to critical infrastructure and services.
4 months ago
Kill Chain
Iranian Cyber Retaliation in March 2026: A Wake-Up Call for Critical Infrastructure Security
In March 2026, following coordinated US-Israeli military strikes on Iran, Iranian state-sponsored cyber actors launched retaliatory cyber operations targeting critical infrastructure across the Middle East and the United States. These operations included Distributed Denial-of-Service (DDoS) attacks, phishing campaigns, and attempts to compromise surveillance systems. Notably, a malicious replica of the Israeli Home Front Command's RedAlert application was distributed to deliver surveillance malware, and internet-connected surveillance cameras in multiple countries were targeted to support operational planning and battle damage assessment. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/?utm_source=openai)) The escalation underscores the persistent cyber threat posed by Iranian actors, who have demonstrated the capability to exploit geopolitical tensions to conduct disruptive cyber activities. Organizations, especially those in critical infrastructure sectors, should remain vigilant and enhance their cybersecurity measures to mitigate potential risks associated with such state-sponsored cyber operations.
4 months ago
Kill Chain
Critical Vulnerabilities in Everon's OCPP Backends Threaten EV Charging Security
In March 2026, multiple critical vulnerabilities were identified in Everon's OCPP Backends, affecting all versions of the platform. These vulnerabilities include missing authentication for critical functions, improper restriction of excessive authentication attempts, insufficient session expiration, and insufficiently protected credentials. Exploitation of these flaws could allow attackers to gain unauthorized administrative control over charging stations or disrupt services through denial-of-service attacks. ([incibe.es](https://www.incibe.es/incibe-cert/alerta-temprana/avisos-sci/multiples-vulnerabilidades-en-ocpp-backends-de-everon?utm_source=openai)) The discovery of these vulnerabilities underscores the growing cybersecurity risks within the electric vehicle (EV) charging infrastructure. As the adoption of EVs accelerates, ensuring the security of charging networks becomes paramount to prevent potential operational disruptions and safeguard user data.
4 months ago
Kill Chain
Critical Vulnerabilities in Hitachi Energy's Relion REB500: Immediate Action Required
In February 2026, Hitachi Energy disclosed two significant vulnerabilities in its Relion REB500 product, identified as CVE-2026-2459 and CVE-2026-2460. These flaws allow authenticated users with specific roles to access and modify unauthorized directories, potentially compromising system integrity. The vulnerabilities affect versions up to and including 8.3.3.0. Hitachi Energy has released version 8.3.3.1 to address these issues and recommends users update promptly. ([cve.qwiksec.com](https://cve.qwiksec.com/cve/CVE-2026-2460?utm_source=openai)) This incident underscores the critical importance of stringent access controls and timely software updates in industrial control systems, especially within the energy sector. Organizations must remain vigilant against privilege escalation vulnerabilities to safeguard operational technology environments.
4 months ago
Kill Chain
Critical Vulnerabilities in Mitsubishi Electric's MELSEC iQ-F Series Expose Industrial Systems to Denial-of-Service Attacks
In March 2026, Mitsubishi Electric disclosed multiple vulnerabilities in their MELSEC iQ-F Series EtherNet/IP and Ethernet modules, specifically FX5-ENET/IP and FX5-EIP models. These flaws, identified as CVE-2026-1874, CVE-2026-1875, and CVE-2026-1876, allow remote attackers to induce denial-of-service conditions by continuously sending UDP packets, rendering the devices unresponsive until a system reset is performed. The vulnerabilities affect FX5-ENET/IP versions up to 1.106 and all versions of FX5-EIP. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1874?utm_source=openai)) This incident underscores the critical need for robust network security measures in industrial control systems, as such vulnerabilities can disrupt essential operations in critical manufacturing sectors worldwide. Organizations are advised to implement recommended mitigations, including updating firmware where available and employing network defenses to prevent unauthorized access. ([cyber.gc.ca](https://www.cyber.gc.ca/en/alerts-advisories/control-systems-mitsubishi-electric-security-advisory-av26-191?utm_source=openai))
4 months ago
Kill Chain
Critical Vulnerability in Portwell Engineering Toolkits Poses Risks to Industrial Control Systems
In March 2026, a critical vulnerability (CVE-2026-3437) was identified in Portwell Engineering Toolkits version 4.8.2, widely used in industrial control systems. This flaw allows local authenticated attackers to read and write arbitrary kernel memory via the toolkit's driver, potentially leading to privilege escalation or denial-of-service conditions. The vulnerability has a CVSS v3.1 base score of 8.8, indicating high severity. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-3437?utm_source=openai)) The vulnerability underscores the importance of securing engineering workstations in industrial environments, as exploitation could compromise critical manufacturing and energy sectors. Organizations are advised to implement defense-in-depth strategies, restrict access to engineering systems, and monitor for unauthorized activities to mitigate potential risks. ([therealistjuggernaut.com](https://therealistjuggernaut.com/2026/03/03/portwell-engineering-toolkits-vulnerability-raises-privilege-escalation-risks-in-industrial-development-environments/?utm_source=openai))
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports