The Containment Era is here. →Explore

Industry Category

Oil/Energy/Solar/Greentech

Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.

378 threat reports
Page 22 of 32

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Oil/Energy/Solar/Greentech Threat Reports

Showing 253264 / 378 reports
Siemens 2026: Denial-of-Service Flaw Impacts SIMATIC & SIPLUS ICS Devices
Impact· high

Siemens 2026: Denial-of-Service Flaw Impacts SIMATIC & SIPLUS ICS Devices

In January 2026, Siemens publicly disclosed a denial-of-service vulnerability (CVE-2025-40944) impacting multiple SIMATIC and SIPLUS products used widely in critical manufacturing environments. The flaw allows an attacker to send a specially crafted S7 protocol Disconnect Request (COTP DR TPDU) over TCP port 102, which causes affected devices to become unresponsive, requiring a physical power cycle to restore service. While some products have received security updates, many still await permanent fixes. Incident response measures include network segmentation and port filtering to mitigate risk, as exploitation could disrupt operational technology and industrial control systems worldwide. This incident is especially relevant amid the ongoing focus on industrial cyber defenses, as threat actors increasingly target operational technology. The vulnerability highlights persistent risks from protocol weaknesses and layered third-party supply chains, underscoring the importance of proactive risk management, segmentation, and maintaining up-to-date mitigations in ICS environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Siemens RUGGEDCOM ROS 2025: TLS Input Validation Vulnerability Disrupts Industrial Devices
Impact· high

Siemens RUGGEDCOM ROS 2025: TLS Input Validation Vulnerability Disrupts Industrial Devices

In December 2025, Siemens disclosed a vulnerability (CVE-2025-40935) affecting multiple RUGGEDCOM ROS devices widely used in industrial control environments. The flaw resides in improper input validation during the TLS certificate upload process, which could allow an authenticated remote attacker to crash and automatically reboot the affected device, causing a temporary denial of service. Siemens promptly released security updates (V5.10.1 or later), and CISA amplified the advisory to increase awareness across critical infrastructure sectors globally. The vulnerability mainly impacts operational continuity, as no data compromise or persistent system access was observed. This incident underscores growing concerns about device-level vulnerabilities in operational technology environments, particularly as attackers increasingly target the industrial sector. The urgency around patching and secure configuration reflects an industry-wide shift toward defense-in-depth strategies and proactive risk mitigation for critical infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Siemens 2026 TeleControl Server Basic Vulnerability: What Critical Sectors Must Know
Impact· medium

Siemens 2026 TeleControl Server Basic Vulnerability: What Critical Sectors Must Know

In January 2026, Siemens disclosed a critical local privilege escalation vulnerability (CVE-2025-40942) affecting versions of its TeleControl Server Basic deployed widely across sectors such as energy, water, and transportation. The bug, identified as CWE-250 (execution with unnecessary privileges), enables local attackers to escalate privileges and potentially execute arbitrary code with elevated permissions. Siemens attributed the discovery to its ProductCERT and an external researcher, and promptly issued a security update (v3.1.2.4) to remediate impacted installations globally. The vulnerability poses particular risk to critical infrastructure given the prevalence and deployment reach of the affected software. This incident underscores a broader industry concern about securing operational technology (OT) environments, especially as threat actors increasingly focus on exploiting privilege escalation flaws in industrial control systems. The swift vendor response, coupled with government advisories, reflects rising urgency and regulatory pressure to safeguard vital sectors from potentially disruptive attacks.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Delta PLC Vulnerabilities: How 2024’s Critical Flaws Put Industrial Operations at Risk
Impact· medium

Delta PLC Vulnerabilities: How 2024’s Critical Flaws Put Industrial Operations at Risk

In June 2024, security researchers publicly disclosed three critical vulnerabilities in Delta Electronics' industrial PLC (Programmable Logic Controller) products, which are widely used across global manufacturing, energy, and automation sectors. These flaws allow remote attackers to bypass authentication, execute arbitrary code, and disrupt operational processes if exploited. While no in-the-wild attacks have been reported to date, the vulnerabilities could grant adversaries broad control over industrial systems and potentially lead to industrial sabotage or production halts. Delta Electronics has released security patches and advisories to help customers mitigate risks. This disclosure is significant because ICS-targeted attacks have increased in sophistication and frequency, exposing the strategic risks of legacy and industrial devices. Critical infrastructure organizations face urgent pressure to update and segment exposed controllers, reinforcing the necessity for real-time threat detection and Zero Trust policies to thwart emerging OT threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Rockwell Automation ICS Devices Exposed by Critical DoS Vulnerability (CVE-2025-9368)
Impact· high

Rockwell Automation ICS Devices Exposed by Critical DoS Vulnerability (CVE-2025-9368)

In January 2026, Rockwell Automation disclosed a critical vulnerability (CVE-2025-9368) affecting its 432ES-IG3 Series A industrial Ethernet/IP interface. The flaw, classified as a resource allocation vulnerability (CWE-770), can be exploited remotely to cause a denial-of-service (DoS) condition, rendering the device unresponsive and requiring manual power cycling to restore operations. The vulnerability affects version V1.001 of the device, widely deployed in critical manufacturing environments worldwide. No evidence of active exploitation has been reported as of the initial CISA advisory, but the risk of service disruption in operational technology (OT) networks is significant. This incident underscores the persistent threat posed by resource exhaustion flaws in industrial control systems, as attackers continue to seek low-complexity, high-impact vulnerabilities to disrupt critical infrastructure. With global regulatory focus increasing and ICS-targeted attacks on the rise, addressing resource and availability issues has become a pressing operational and compliance priority for manufacturers and critical infrastructure operators.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Rockwell Automation DataMosaix SQL Injection Exposes Critical Manufacturing Systems
Impact· medium

Rockwell Automation DataMosaix SQL Injection Exposes Critical Manufacturing Systems

In January 2026, Rockwell Automation disclosed a critical vulnerability in its FactoryTalk DataMosaix Private Cloud platform affecting versions 7.11, 8.00, and 8.01. Identified as CVE-2025-12807, this SQL Injection flaw allows low-privilege users to execute unauthorized sensitive database operations through exposed API endpoints. While no public exploitation has been reported, successful attacks could significantly compromise critical manufacturing infrastructure worldwide by enabling attackers to access or manipulate sensitive industrial data. The incident highlights ongoing risks to industrial control environments from common vulnerabilities like SQL Injection, especially in products globally deployed across critical infrastructure sectors. With attackers increasingly targeting OT platforms, organizations face renewed urgency to review security controls and ensure compliance with updated defensive best practices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Endesa 2024 Data Breach: Key Lessons for Energy Sector Security
Impact· high

Endesa 2024 Data Breach: Key Lessons for Energy Sector Security

In May 2024, Spanish energy giant Endesa, alongside its subsidiary Energía XXI, disclosed a data breach following unauthorized access to its internal systems by unknown attackers. The incident exposed sensitive contract-related information and personal details belonging to Endesa customers, although the company stated that no financial data was compromised. Endesa responded by promptly notifying affected clients, securing compromised systems, and initiating an investigation with law enforcement and the Spanish data protection authority. The breach underscores the growing targeting of critical infrastructure providers, where even non-financial data leaks can erode customer trust and regulatory posture. This incident is particularly relevant as critical infrastructure companies face heightened risk from threat actors leveraging lateral movement and data exfiltration techniques. With the energy sector increasingly interconnected and digitalized, organizations must prioritize zero trust strategies and robust monitoring to meet evolving compliance and regulatory demands.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
US Gray Zone Cyber Operations Disrupt Venezuela’s Oil Sector in 2020
Impact· medium

US Gray Zone Cyber Operations Disrupt Venezuela’s Oil Sector in 2020

In early 2020, cyber-enabled disruptions targeted Venezuela’s state-owned oil sector amidst political upheaval and mounting international pressure. While formal attribution remains disputed, sources suggest that US-affiliated actors leveraged advanced cyber techniques—such as persistent access, supply chain vulnerabilities, and mapped system dependencies—to intermittently degrade operational capabilities and exports. The campaign unfolded as ongoing, reversible disruptions aimed at eroding economic resilience and regime stability without triggering overt conflict. These actions exemplified nation-state 'gray zone' operations, leveraging cyber tools for sustained coercion rather than momentary effect. This incident marked a shift in statecraft, signaling the integration of cyber-enabled economic interference with traditional levers like sanctions and diplomacy. It reflects a broader, rising trend of major powers using deniable, persistent cyber operations to exert pressure on adversarial infrastructure while remaining below the threshold of conventional military escalation.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
APT28 Targets Energy and Policy Sectors With Sophisticated Credential Phishing (2025)
Impact· medium

APT28 Targets Energy and Policy Sectors With Sophisticated Credential Phishing (2025)

Between February and September 2025, Russian state-sponsored APT28 (aka BlueDelta, linked to the GRU) launched highly targeted credential-harvesting attacks against individuals in Turkish energy and nuclear agencies, a European think tank, and organizations in North Macedonia and Uzbekistan. The campaign relied on phishing emails with region-specific lures and fake login pages imitating Microsoft OWA, Google, and Sophos VPN portals. Stolen credentials were exfiltrated via disposable internet services, and victims were seamlessly redirected to legitimate sites to avoid suspicion, evading typical detection methods. Notably, attackers leveraged legitimate PDF documents themed around high-profile geopolitical events as decoy content. These incidents underscore the increasing sophistication and operational focus of nation-state phishing campaigns, with attackers rapidly exploiting current geopolitical tensions to credibly target sensitive sectors. Repeated use of trusted public infrastructure for data exfiltration further complicates defense and detection efforts.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical RCE Flaw in Hitachi Energy Asset Suite: Jasper Report Vulnerability Exposes Critical Infrastructure (2025)
Impact· low

Critical RCE Flaw in Hitachi Energy Asset Suite: Jasper Report Vulnerability Exposes Critical Infrastructure (2025)

In December 2025, Hitachi Energy disclosed a critical remote code execution (RCE) vulnerability (CVE-2025-10492) affecting its Asset Suite product versions 9.7 and prior. The flaw, found in the Jasper Report third-party component, arises from improper deserialization of untrusted data, allowing attackers to remotely execute arbitrary code on affected systems. The vulnerability particularly impacts organizations using Asset Suite in critical infrastructure sectors, such as energy, potentially exposing operational networks to severe risks of compromise, data breach, or service disruption. This incident underscores the persistent threat posed by supply chain vulnerabilities in industrial control software. As threat actors increasingly target critical infrastructure through third-party and open-source components, organizations face heightened regulatory scrutiny and an urgent need for robust patch and mitigation strategies to close compliance and security gaps.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Chinese Cyber Army Hits Taiwan: 2025 Critical Infrastructure Breach Analysis
Impact· high

Chinese Cyber Army Hits Taiwan: 2025 Critical Infrastructure Breach Analysis

In 2025, Taiwan experienced a major surge in cyberattacks attributed to Chinese nation-state actors, with over 2.6 million daily intrusion attempts targeting government agencies and critical infrastructure, including the energy and healthcare sectors. Attackers leveraged software and hardware vulnerabilities to breach networks, exfiltrate sensitive data from hospitals, and gain lateral access to backup communications, telecom networks, and supply chain partners in semiconductors and defense. These operations, often coordinated with political and military activity, aimed to steal technology, disrupt vital services, and compromise strategic intelligence. This campaign highlights a broader escalation in state-linked cyber offensives exploiting critical infrastructure vulnerabilities worldwide, emphasizing emerging tactics like supply chain targeting and increased ransomware attacks on healthcare. The incident underscores the urgent need for resilient security architectures and international cooperation as threat actors grow more sophisticated and persistent.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
GRU’s BlueDelta Targets Energy and Research: Advanced Credential Phishing in 2025
Impact· medium

GRU’s BlueDelta Targets Energy and Research: Advanced Credential Phishing in 2025

Between February and September 2025, the Russian state-sponsored threat group BlueDelta (APT28/GRU) conducted a series of targeted credential-harvesting attacks, focusing on organizations in Türkiye, Europe, North Macedonia, and Uzbekistan. The attackers deployed sophisticated phishing lures themed as Microsoft Outlook Web Access, Google, and Sophos VPN portals, abusing free hosting and tunneling services such as Webhook.site and ngrok to capture credentials and exfiltrate data. Victims were redirected through multi-stage phishing chains, and legitimate PDF documents were used to enhance believability and evade detection, ultimately supporting Russian intelligence collection. This incident underlines the evolution of state-sponsored phishing techniques, including automation for credential exfiltration and the increasing abuse of legitimate internet infrastructure. The campaign’s focus on energy and defense sectors reflects heightened geopolitical interest and reinforces the urgent need for robust email and identity security practices across sensitive organizations.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports