✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Oil/Energy/Solar/Greentech
Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.
Explore Other Sectors
Oil/Energy/Solar/Greentech Threat Reports
Critical Vulnerabilities Uncovered in ePower's Charging Platform
In March 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory highlighting multiple critical vulnerabilities in ePower's charging platform, epower.ie. These vulnerabilities include missing authentication for critical functions, improper restriction of excessive authentication attempts, insufficient session expiration, and insufficiently protected credentials. Exploitation of these flaws could allow attackers to gain unauthorized administrative control over charging stations or disrupt services through denial-of-service attacks. ([windowsforum.com](https://windowsforum.com/threads/cisa-warns-of-epower-charging-platform-vulnerabilities-and-mitigations.403849/?utm_source=openai)) The disclosure underscores the growing cybersecurity risks in the energy and transportation sectors, particularly concerning electric vehicle (EV) infrastructure. As EV adoption accelerates, ensuring the security of charging networks becomes paramount to prevent potential disruptions and maintain public trust in these emerging technologies.
4 months ago
Kill Chain
Critical Vulnerability in Labkotec LID-3300IP Threatens Industrial Control Systems
In March 2026, a critical vulnerability (CVE-2026-1775) was identified in Labkotec's LID-3300IP ice detector software, allowing unauthenticated attackers to alter device parameters and execute operational commands via specially crafted packets. This flaw, stemming from missing authentication for critical functions, poses significant risks to industrial control systems, particularly in sectors like energy and communications. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1775?utm_source=openai)) The vulnerability underscores the growing threat landscape for industrial control systems, emphasizing the need for robust authentication mechanisms and network security practices to prevent unauthorized access and potential operational disruptions.
4 months ago
Kill Chain
Mobiliti e-mobi.hu 2026 Authentication Vulnerabilities Expose Critical Infrastructure Risks
In March 2026, multiple critical vulnerabilities were identified in Mobiliti's e-mobi.hu platform, a key player in Hungary's electric vehicle charging infrastructure. These flaws, including missing authentication for critical functions and insufficient session expiration, could allow attackers to gain unauthorized administrative control over charging stations or disrupt services through denial-of-service attacks. The vulnerabilities affect all versions of the e-mobi.hu platform, posing significant risks to the energy and transportation sectors. ([windowsforum.com](https://windowsforum.com/threads/cisa-advisories-warn-of-critical-authentication-and-session-flaws-in-mobiliti-e-mobi-platform.403855/?utm_source=openai)) This incident underscores the growing cybersecurity challenges in critical infrastructure, particularly within the rapidly expanding electric vehicle sector. As the adoption of EVs increases, ensuring the security of associated charging networks becomes paramount to prevent potential disruptions and maintain public trust.
4 months ago
Kill Chain
Critical Vulnerabilities in Hitachi Energy RTU500 Series Require Immediate Attention
In February 2026, Hitachi Energy disclosed multiple vulnerabilities affecting its RTU500 series products, including CVE-2026-1772, CVE-2026-1773, CVE-2024-8176, and CVE-2025-59375. These vulnerabilities, if exploited, could lead to unauthorized access to user management information and potential device outages. The affected firmware versions range from 12.7.1 to 13.8.1. Hitachi Energy has released firmware updates to address these issues and recommends users implement the provided mitigations to secure their systems. This incident underscores the critical importance of timely vulnerability management in industrial control systems, especially within the energy sector. Organizations are urged to stay vigilant and apply security patches promptly to mitigate potential risks associated with such vulnerabilities.
4 months ago
Kill Chain
SloppyLemming's Dual Malware Assault on South Asian Governments
Between January 2025 and January 2026, the threat actor known as SloppyLemming executed a series of cyber-espionage attacks targeting government entities and critical infrastructure in Pakistan and Bangladesh. Utilizing spear-phishing emails with malicious PDF and Excel attachments, the group deployed two distinct malware strains: BurrowShell, a backdoor facilitating file manipulation and network tunneling, and a Rust-based keylogger designed for information theft and network reconnaissance. These sophisticated attacks underscore the evolving tactics of nation-state actors in the region. The campaign's reliance on advanced techniques, such as disguising command-and-control traffic as legitimate Windows Update communications and exploiting Cloudflare Workers infrastructure, highlights the increasing complexity of cyber threats facing South Asian nations. This incident serves as a critical reminder for organizations to bolster their cybersecurity defenses against state-sponsored attacks.
4 months ago
Kill Chain
Pro-Iranian Cyberattacks 2026: Unveiling the Threat to Critical Infrastructure
In early 2026, amid escalating geopolitical tensions, pro-Iranian cyber actors launched a series of coordinated cyberattacks targeting critical infrastructure in the United States and allied nations. These attacks aimed to disrupt essential services, including utilities and transportation systems, and were characterized by sophisticated techniques such as ransomware deployment and data exfiltration. The cyber offensive resulted in significant operational disruptions and financial losses, highlighting the evolving threat landscape posed by nation-state-sponsored cyber activities. This incident underscores the persistent and adaptive nature of cyber threats from nation-state actors, particularly in the context of geopolitical conflicts. Organizations are urged to enhance their cybersecurity posture by implementing robust defense mechanisms, conducting regular threat assessments, and fostering information-sharing partnerships to mitigate the risks associated with such sophisticated cyberattacks.
4 months ago
Kill Chain
March 2026 Iranian Cyberattacks: A Wake-Up Call for Critical Infrastructure Security
In early March 2026, Iranian state-sponsored cyber actors launched a series of coordinated cyberattacks targeting critical infrastructure and government entities across the United States and its allies. These attacks included sophisticated phishing campaigns, deployment of data-exfiltrating malware, and disruptive operations attributed to Iranian-aligned hacktivist groups. The cyber offensive coincided with heightened geopolitical tensions following military strikes in the region, leading to significant disruptions in services and raising concerns over national security vulnerabilities. The escalation underscores the persistent threat posed by nation-state actors leveraging cyber capabilities to achieve strategic objectives. Organizations are urged to enhance their cybersecurity posture, as the current geopolitical climate suggests a continued risk of similar cyber operations targeting critical infrastructure and sensitive data.
4 months ago
Kill Chain
Escalation of Iranian Cyber Attacks Post-2026 Military Strikes
In response to the joint U.S.-Israeli military strikes on February 28, 2026, Iranian-affiliated cyber actors have intensified their operations targeting U.S. critical infrastructure. Utilizing tactics such as brute force attacks, password spraying, and exploitation of unpatched vulnerabilities, these actors aim to disrupt services and exfiltrate sensitive data. Notably, sectors including energy, defense, and public health have reported increased intrusion attempts, with some incidents leading to operational disruptions and data breaches. This escalation underscores the persistent cyber threat posed by Iranian state-sponsored and aligned groups, even amidst kinetic military engagements. Organizations are urged to bolster their cybersecurity postures, as the likelihood of retaliatory cyber operations remains high, potentially leading to significant operational and reputational impacts.
4 months ago
Kill Chain
AI-Assisted Cyberattack Compromises 600+ FortiGate Firewalls Globally
Between January 11 and February 18, 2026, a Russian-speaking threat actor utilized commercial generative AI tools to compromise over 600 Fortinet FortiGate firewalls across 55 countries. The attacker exploited exposed management interfaces and weak credentials lacking two-factor authentication, without leveraging any specific software vulnerabilities. Once access was gained, AI-generated scripts were employed to extract and decrypt sensitive data, including SSL-VPN credentials, administrative passwords, and network configurations. This information facilitated further network infiltration and reconnaissance activities. ([cybernews.com](https://cybernews.com/security/threat-actor-ai-tools-claude-fortinet-fortigate/?utm_source=openai)) This incident underscores the evolving threat landscape where AI tools enable even low-skilled attackers to execute large-scale, sophisticated cyberattacks. Organizations must reassess their security postures, emphasizing the importance of robust authentication mechanisms and the need to secure management interfaces against unauthorized access.
4 months ago
Kill Chain
APT37's Ruby Jumper Campaign: A New Threat to Air-Gapped Networks
In December 2025, the North Korean state-sponsored group APT37, also known as ScarCruft, launched the 'Ruby Jumper' campaign targeting air-gapped networks. The attack began with victims opening malicious Windows shortcut (LNK) files, which executed PowerShell scripts to deploy a series of malware tools: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, and FOOTWINE. These tools facilitated initial infection, established command-and-control via Zoho WorkDrive, and enabled lateral movement through removable media, ultimately compromising isolated systems. The campaign underscores the evolving tactics of APT37 in breaching highly secure environments. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/apt37-hackers-use-new-malware-to-breach-air-gapped-networks/?utm_source=openai)) This incident highlights a significant advancement in cyber-espionage techniques, demonstrating the capability to infiltrate air-gapped systems. Organizations with critical infrastructure should reassess their security protocols to mitigate such sophisticated threats.
4 months ago
Kill Chain
Critical WebSocket Vulnerabilities in SWITCH EV's Platform Threaten EV Infrastructure Security
In February 2026, multiple critical vulnerabilities were identified in SWITCH EV's swtchenergy.com platform, affecting all versions. These vulnerabilities include missing authentication for critical functions (CVE-2026-27767), improper restriction of excessive authentication attempts (CVE-2026-25113), insufficient session expiration (CVE-2026-25778), and insufficiently protected credentials (CVE-2026-27773). Exploitation of these flaws could allow attackers to impersonate charging stations, hijack sessions, suppress or misroute legitimate traffic, and manipulate data sent to the backend, potentially leading to large-scale denial of service and unauthorized control over charging infrastructure. ([cvedetails.com](https://www.cvedetails.com/cve/CVE-2026-27767/?utm_source=openai)) The increasing reliance on electric vehicle (EV) infrastructure underscores the critical need for robust cybersecurity measures. These vulnerabilities highlight the potential risks associated with inadequate authentication and session management in critical infrastructure systems, emphasizing the importance of implementing comprehensive security protocols to safeguard against such threats.
5 months ago
Kill Chain
EV2GO 2026 Authentication Vulnerabilities: A Wake-Up Call for Critical Infrastructure Security
In February 2026, multiple critical vulnerabilities were identified in EV2GO's ev2go.io charging management platform, affecting all versions. These flaws include missing authentication for critical functions (CVE-2026-24731), improper restriction of excessive authentication attempts (CVE-2026-25945), insufficient session expiration (CVE-2026-20895), and insufficiently protected credentials (CVE-2026-22890). Exploitation could allow attackers to impersonate charging stations, hijack sessions, misroute traffic causing large-scale denial of service, and manipulate backend data. ([therealistjuggernaut.com](https://therealistjuggernaut.com/2026/02/26/trj-cybersecurity-ev2go-charging-platform-exposed-authentication-failures-create-high-risk-entry-points-across-global-ev-infrastructure/?utm_source=openai)) The absence of vendor response and lack of available patches heighten the urgency for organizations to implement immediate defensive measures. This incident underscores the critical need for robust authentication mechanisms and proactive vulnerability management in infrastructure systems to prevent potential exploitation and operational disruptions.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports