✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Oil/Energy/Solar/Greentech
Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.
Explore Other Sectors
Oil/Energy/Solar/Greentech Threat Reports
Johnson Controls iSTAR ICU Tool Faces Critical Stack Buffer Overflow Vulnerability
In January 2026, Johnson Controls Inc. disclosed a significant vulnerability (CVE-2025-26386) affecting its iSTAR Configuration Utility (ICU) tool, versions up to 6.9.7. The issue, a stack-based buffer overflow, could be exploited by a remote attacker, potentially causing a failure in the operating system hosting the ICU tool. Although there have been no reported cases of active exploitation as of the disclosure, the vulnerability poses a risk to critical infrastructure sectors—including commercial facilities, energy, and government services—where the affected product is widely deployed. Security researchers at Tenable responsibly reported the flaw to CISA, who published the advisory. This incident rolls out against the backdrop of increasing attention to the cybersecurity of operational technology (OT) in industrial and critical infrastructure, with regulators and operators emphasizing timely patching and network segmentation practices to prevent lateral movement and operational disruption.
6 months ago
Kill Chain
Tesla and Leading Automakers Hacked at Pwn2Own Automotive 2026: 37 Zero-Days Uncovered
In January 2026, security researchers at the Pwn2Own Automotive competition in Tokyo successfully exploited 37 zero-day vulnerabilities across flagship automotive technologies, including Tesla's infotainment system, multiple EV chargers, and in-vehicle digital receivers. The Synacktiv team achieved root access on the Tesla Infotainment System through chained vulnerabilities involving an information leak and out-of-bounds write flaw via USB. Other researchers compromised systems from Sony, Alpitronic, Autel, Kenwood, and Phoenix Contact. The event demonstrates the breadth of exploitable attack surfaces even in patched, production automotive hardware and highlights coordinated vulnerability disclosure processes wherein vendors have 90 days to issue fixes. This incident underscores how automotive technology—including electric vehicles and charging infrastructure—remains a top target for advanced security researchers, with new zero-day vulnerabilities continually emerging. As vehicle software stacks grow in complexity and interconnectivity, the imperative for proactive, industry-wide security controls and coordinated patch processes is increasingly urgent.
6 months ago
Kill Chain
Exposing the Hidden Threat: Orphan Accounts and the Identity Dark Matter (2026)
In January 2026, the cybersecurity community highlighted mounting risks associated with orphaned accounts—dormant but still-active identities left behind after employee turnover, organizational change, or fragmented onboarding processes. Attackers have repeatedly leveraged these unattended, often highly privileged accounts as entry points, as seen in notable breaches such as Colonial Pipeline (2021) and a 2025 ransomware attack on a manufacturing firm. These accounts evade detection and deprovisioning, undermining traditional Identity and Access Management (IAM) controls and enabling credential-based attacks that can lead to regulatory violations, operational inefficiencies, and delayed incident response. Such orphaned identities are a growing concern amid expanding use of non-human and AI-driven service accounts, especially following M&A activity. Their proliferation reflects a macro trend in attacker tactics: exploiting visibility and lifecycle gaps in identity governance—putting critical compliance frameworks and business continuity at risk.
6 months ago
Kill Chain
Schneider Electric Foxboro DCS: Intel Side-Channel Flaw Threatens Critical Infrastructure (2026)
In late 2025 and early 2026, Schneider Electric disclosed a side-channel vulnerability (CVE-2018-12130) impacting its EcoStruxure Foxboro DCS product line, widely used in critical infrastructure globally. The issue, originating from Intel processor flaws, could allow authenticated local attackers to extract sensitive data via side-channel methods, potentially leading to unauthorized disclosure or manipulation of system functions. The exploit primarily affects specific Foxboro DCS servers and workstations running on vulnerable Intel CPUs. Schneider Electric issued upgrades and remediation guidance while urging organizations to implement defense-in-depth strategies to mitigate risk. This incident highlights ongoing industry concerns over hardware-level vulnerabilities affecting operational technology in high-stakes sectors such as energy and manufacturing. As threat actors increasingly target supply chain and embedded flaws, organizations are under mounting pressure from regulators and customers to update aging infrastructure, strengthen segmentation, and accelerate threat detection capabilities.
6 months ago
Kill Chain
Rockwell Automation Verve Asset Manager Vulnerabilities: 2026 Lessons for Critical Infrastructure
In January 2026, Rockwell Automation disclosed two significant vulnerabilities (CVE-2025-14376, CVE-2025-14377) in its Verve Asset Manager product. These flaws were rooted in insecure and cleartext storage of sensitive data within the legacy ADI server and Ansible playbook components, impacting versions 1.33 through 1.41.3. Exploitation could have allowed attackers with system or network access to retrieve confidential data from environment variables and process files, potentially facilitating lateral movement or further compromises. The issues were addressed in version 1.42, and vulnerable components were made optional in newer releases. This incident is particularly relevant amid heightened attention to supply chain risk and critical infrastructure cybersecurity. As industrial control vendors face rising regulatory pressure and expansion of zero-trust mandates, unencrypted data storage flaws highlight the urgent need for comprehensive data-in-transit and at-rest protections.
6 months ago
Kill Chain
China-Linked APT Leverages Sitecore Zero-Day to Target Critical Infrastructure (2025)
In late 2025, a China-nexus advanced persistent threat group tracked as UAT-8837 exploited a critical Sitecore zero-day vulnerability (CVE-2025-53690, CVSS 9.0) to compromise multiple critical infrastructure organizations in North America. Following initial access through vulnerable servers or compromised credentials, the threat actor leveraged open-source post-exploitation tools to steal sensitive credentials, manipulate Active Directory, and establish multiple persistent access channels. Attackers disabled security features like RestrictedAdmin for RDP and exfiltrated confidential assets, including proprietary DLL libraries, potentially setting the stage for future supply chain attacks or further reverse engineering efforts. This incident reflects a broader trend of sophisticated, state-linked attackers increasingly targeting operational technology environments and critical infrastructure, exploiting unpatched vulnerabilities and adopting living-off-the-land techniques. The ongoing relevance is underscored by heightened governmental warnings and the urgent need for robust vulnerability management, segmentation, and monitoring in high-value environments.
6 months ago
Kill Chain
Schneider Electric EcoStruxure Rapsody Software Vulnerabilities Threaten Critical Infrastructure in 2026
In January 2026, Schneider Electric disclosed multiple critical software vulnerabilities (CVE-2025-13844, CVE-2025-13845) in its EcoStruxure Power Build Rapsody platform, widely used in the energy, manufacturing, and commercial facilities sectors. The flaws—specifically double free and use after free issues—stem from improper memory management when importing malicious project files, enabling local attackers to potentially execute arbitrary code. Impacted product versions are deployed worldwide. Schneider Electric and independent security researchers reported these vulnerabilities, urging customers to upgrade immediately or apply mitigations to prevent unauthorized system access and memory corruption. This incident highlights the continued threat posed by software supply chain attacks and memory corruption vulnerabilities in critical infrastructure environments. As attackers shift towards exploiting insecure file imports and legacy software flaws, organizations must prioritize secure software lifecycle management and timely patching to counter emerging risks.
6 months ago
Kill Chain
Siemens Edge Device Vulnerability Exposes Critical Manufacturing Operations in 2026
In January 2026, Siemens disclosed a critical authorization bypass vulnerability (CVE-2025-40805) affecting a broad range of its Industrial Edge Devices and operator panels. The flaw allows an unauthenticated remote attacker to circumvent user authentication by exploiting weaknesses in certain API endpoints, enabling impersonation of legitimate users. Exploitation requires knowledge of a valid user identity. Siemens promptly released patches and mitigation recommendations for impacted devices, but multiple models remain without fixes as of the initial disclosure, heightening operational risk in environments relying on these devices. This incident underscores the ongoing threat posed by API weaknesses and identity-driven attacks in critical manufacturing and operational technology sectors. As API-driven automation proliferates in industry, organizations must rapidly address such vulnerabilities in devices that underpin essential infrastructure.
6 months ago
Kill Chain
Siemens SINEC Security Monitor: 2025 Vulnerabilities Expose Industrial OT Risks
In December 2025, Siemens disclosed two medium-severity vulnerabilities (CVE-2025-40830 and CVE-2025-40831) affecting SINEC Security Monitor software prior to version 4.10.0. The first vulnerability allows authenticated, low-privileged local users to bypass authorization controls and read or write arbitrary files on the server or sensor, potentially resulting in data tampering or unauthorized access. The second flaw enables an authenticated low-privileged attacker to cause a denial of service in the reporting module through improper input validation. Siemens and CISA recommend upgrading to version 4.10.0 and strongly advise hardening network access to affected devices. This incident highlights the ongoing risks posed by privilege escalation and input validation flaws, especially in critical infrastructure management software. As regulatory scrutiny over operational technology intensifies and attackers increasingly exploit supply chain and lateral movement techniques, maintaining timely patching and rigorous security baselines is essential to minimize the risk of compromise.
6 months ago
Kill Chain
Siemens 2026 Vulnerability Disclosure: New Multi-CVE Risks in RUGGEDCOM APE1808 Devices
In January 2026, Siemens disclosed multiple security vulnerabilities (including four CVEs: CVE-2025-40891, CVE-2025-40892, CVE-2025-40893, and CVE-2025-40898) affecting its RUGGEDCOM APE1808 devices used in critical manufacturing environments globally. The vulnerabilities include two types of stored cross-site scripting (XSS) and a path traversal flaw, exposing risks such as client-side code execution, privilege escalation, and manipulation of sensitive device configuration. Successful exploitation could enable unauthenticated or authenticated attackers to inject malicious code, alter reports, or compromise system availability, although Siemens’ additional input validation and content security policies restrict some impact scope. The company is working on fix versions and urges customers to apply recommended mitigations and patches promptly. The exposure of critical infrastructure devices to these vulnerabilities highlights the urgent need for robust patch management and network segmentation, especially given the industrial sector’s growing attractiveness to cyberattackers. The incident underscores the rising prevalence of complex, multi-vector attacks targeting operational technology (OT) environments and the increased regulatory pressures demanding enhanced security vigilance and rapid incident reporting.
6 months ago
Kill Chain
Critical Authorization Bypass Hits Siemens Industrial Edge in 2026
In January 2026, Siemens disclosed a critical vulnerability (CVE-2025-40805) affecting the Industrial Edge Device Kit line for both arm64 and x86-64 architectures. The flaw, present in numerous firmware versions, allows unauthenticated remote attackers to bypass user authentication on specific API endpoints by exploiting an authorization weakness. An attacker who learns a legitimate user’s identity could leverage this to impersonate that user and gain illicit control or visibility within industrial environments. Siemens promptly released security updates and mitigation guidance for impacted devices, urging organizations to update or restrict network access as a preventive measure. This incident highlights increasing risks to operational technology (OT) and critical infrastructure, as authentication flaws in widely deployed industrial solutions can expose factories and utilities globally. The CVE underscores growing threats facing manufacturing, regulatory pressure for timely patching, and ongoing urgency for zero trust controls in industrial systems.
6 months ago
Kill Chain
AVEVA 2026: Critical ICS Vulnerabilities Put Manufacturing at Risk
In January 2026, AVEVA disclosed seven critical vulnerabilities in its Process Optimization suite, widely used by critical manufacturing and infrastructure sectors worldwide. The flaws, reported by Veracode’s Christopher Wu, include unauthenticated remote code execution, SQL injection, privilege escalation, code injection, and cleartext transmission of sensitive data. Attackers exploiting these vulnerabilities could fully compromise servers, escalate user privileges, access sensitive process data, and potentially undermine operational continuity or safety. Affected versions include all AVEVA Process Optimization releases up to and including 2024.1. These vulnerabilities highlight increasing targeting of industrial control and process optimization platforms, exposing gaps in legacy ICS security. With global critical infrastructure at risk and exploitation methods aligned with broader trends in supply chain and lateral movement attacks, this incident underscores urgent needs for robust security controls, ongoing software updates, and regulatory compliance in the ICS/OT domain.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports