The Containment Era is here. →Explore

Industry Category

Oil/Energy/Solar/Greentech

Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.

378 threat reports
Page 29 of 32

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Oil/Energy/Solar/Greentech Threat Reports

Showing 337348 / 378 reports
Siemens COMOS 2025: Critical Software Vulnerabilities in Industrial Control Systems
Impact· low

Siemens COMOS 2025: Critical Software Vulnerabilities in Industrial Control Systems

In November 2025, Siemens disclosed critical software vulnerabilities affecting its COMOS platform, widely used in the industrial and critical manufacturing sectors. The flaws—specifically, an incomplete list of disallowed inputs and cleartext transmission of sensitive information—enabled remote attackers with low attack complexity to execute arbitrary code or intercept data. The affected versions were COMOS releases prior to 10.4.5, with potential for unauthorized access, data infiltration, or broader operational disruptions across global deployments. Siemens ProductCERT identified and reported the vulnerabilities, issuing patches and urging immediate upgrades and network protections. This incident is highly relevant given the increasing threats to industrial control systems and the persistent exploitation of software supply chain vulnerabilities. The convergence of IT and OT environments means that unresolved vulnerabilities like these present heightened risks in critical infrastructure, drawing attention from regulators and advanced cyber attackers alike.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Critical ICS Vulnerabilities in Siemens SICAM P850/P855 Devices Impact Energy Sector
Impact· low

Critical ICS Vulnerabilities in Siemens SICAM P850/P855 Devices Impact Energy Sector

In November 2025, Siemens disclosed vulnerabilities affecting their SICAM P850 and P855 industrial control device families. Specifically, these products were susceptible to a Cross-Site Request Forgery (CSRF) flaw and incorrect permission assignment for critical resources, allowing attackers to execute unauthorized actions or impersonate users. The weaknesses impacted devices globally deployed in energy-critical infrastructure, with the main risk being attackers exploiting web sessions to modify device configuration or gain prolonged unauthorized access. Siemens ProductCERT identified the issues, which could be exploited remotely with low attack complexity, scoring up to 5.5 CVSS. This incident highlights growing concerns over ICS (Industrial Control Systems) vulnerabilities due to their essential role in critical infrastructure and the rising sophistication of exploitation tactics targeting web interfaces. The disclosure underscores the need for proactive patch management and access restrictions amid evolving regulatory and threat environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Rockwell Automation SIS Workstation Vulnerability Exposes Critical Manufacturing
Impact· low

Rockwell Automation SIS Workstation Vulnerability Exposes Critical Manufacturing

In November 2025, Rockwell Automation disclosed a critical path traversal vulnerability (CVE-2024-48510) in its AADvance-Trusted SIS Workstation software, impacting versions 2.00.00 to 2.00.04. The flaw stems from improper validation in the DotNetZip component, enabling remote attackers to execute arbitrary code if a victim opens a malicious file. This issue poses significant risks to critical manufacturing systems worldwide, potentially allowing adversaries to compromise safety instrumented system environments. Rockwell has released a patch in version 2.01.00 to address the flaw. This vulnerability is particularly noteworthy due to its low attack complexity, remote exploitability, and potential for widespread impact across global critical infrastructure. The incident underscores ongoing supply chain risks in industrial software and the urgent need for timely patching, robust endpoint security, and defense-in-depth strategies for operational technology (OT) environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Critical Siemens LOGO! 8 Vulnerabilities Put Global ICS at Risk
Impact· high

Critical Siemens LOGO! 8 Vulnerabilities Put Global ICS at Risk

In November 2025, Siemens disclosed multiple critical vulnerabilities affecting its LOGO! 8 BM Devices, widely deployed in global commercial facilities and transportation systems. Security researchers from Thales Cybersecurity Services Australia identified flaws enabling unauthenticated remote attackers to exploit classic buffer overflow and missing authentication vulnerabilities. These flaws could allow malicious actors to execute arbitrary code, disrupt device operations via denial-of-service, or modify critical device parameters such as IP address and time settings, potentially impacting industrial operations. The incident underscores growing concerns about the security posture of industrial control systems (ICS), as attackers increasingly target remote management features lacking modern authentication. With regulatory scrutiny intensifying and attackers exploiting similar flaws in operational technology, organizations must prioritize ICS security and proactive patch management to reduce exposure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Landfall Spyware Campaign Exposes Samsung Galaxy Devices in the Middle East
Impact· medium

Landfall Spyware Campaign Exposes Samsung Galaxy Devices in the Middle East

In mid-2024, security researchers from Palo Alto Networks' Unit 42 uncovered 'Landfall', a sophisticated commercial-grade spyware campaign targeting Samsung Galaxy S22, S23, S24, and Fold/Flip devices in the Middle East, specifically in Iran, Iraq, Morocco, and Turkey. Attackers exploited a Samsung-specific zero-day vulnerability using malicious DNG image files, often distributed via WhatsApp, enabling zero-click infection without user interaction. Once compromised, Landfall enables extensive surveillance capabilities, such as microphone activation and unauthorized data collection—including contacts and photos. While attribution remains inconclusive, similarities in infrastructure hint at possible links to the Stealth Falcon APT group. This incident highlights the rising use of zero-click exploits and highly-targeted mobile spyware attacks against consumer devices. The sophistication and persistence of such campaigns are forcing device vendors, regulators, and enterprises to invest in rapid patching, threat detection, and zero trust mobile security strategies to counter fast-evolving mobile threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Malicious NuGet Packages Drop Sabotage Time Bombs in 2024 Supply Chain Attack
Impact· high

Malicious NuGet Packages Drop Sabotage Time Bombs in 2024 Supply Chain Attack

In early June 2024, security researchers uncovered a targeted supply-chain attack involving several malicious NuGet packages. These packages, posing as legitimate software dependencies, contained 'time bomb' sabotage payloads programmed to activate years in the future—specifically in 2027 and 2028. The malicious code was designed to disrupt database operations and potentially target Siemens S7 industrial control systems, representing a novel form of delayed-detonation supply chain attack. The technique leverages trust in package ecosystems, making detection difficult and threatening both IT and operational technology environments with considerable disruption. This incident highlights an emerging trend where attackers plant long-term, stealthy threats within software supply chains to evade short-term detection and maximize impact. With the increasing adoption of open-source components and growing regulatory scrutiny, organizations must urgently reassess their software sourcing and supply-chain risk controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
ABB FLXeon 2025 ICS Vulnerabilities: Protecting Critical Infrastructure from Remote Threats
Impact· medium

ABB FLXeon 2025 ICS Vulnerabilities: Protecting Critical Infrastructure from Remote Threats

In November 2025, ABB disclosed critical vulnerabilities affecting their FLXeon industrial control system (ICS) controllers, including the FBXi, FBVi, FBTi, and CBXi product lines. Security researcher Gjoko Krstikj of Zero Science Lab identified flaws such as the use of hard-coded credentials (CVE-2024-48842), improper input validation (CVE-2024-48851, CVE-2025-10207), and weak password hashing practices (CVE-2025-10205) that could allow remote attackers to gain control, execute arbitrary code, or cause system crashes. While exploitation requires some privileges and network access, the flaws impact ICS deployments globally, exposing critical infrastructure sectors to risk until patches are applied. This incident highlights the continued trend of vulnerabilities in operational technology and industrial systems, reinforcing fears that ICS environments remain attractive targets for cyber threat actors. As regulatory and industry pressure mounts for robust ICS security and segmentation, organizations must accelerate adoption of defense-in-depth strategies to protect essential infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
CISA Issues 2025 Industrial Control Systems Vulnerability Alerts: What You Need to Know
Impact· medium

CISA Issues 2025 Industrial Control Systems Vulnerability Alerts: What You Need to Know

In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released four Industrial Control Systems (ICS) security advisories highlighting critical and high-severity vulnerabilities in products from Advantech (DeviceOn iEdge), Ubia (Ubox), ABB (FLXeon Controllers), and Hitachi Energy (Asset Suite). These advisories revealed weaknesses that allow threat actors to exploit unencrypted communications, weak authentication, and inadequate segmentation, which could enable remote attackers to gain unauthorized access, move laterally within ICS environments, or disrupt operations. The announcement underscores the ongoing risk posed to critical infrastructure from both targeted and opportunistic threats leveraging these flaws. This incident exemplifies a growing trend where attackers target ICS components and operational technology, exploiting security gaps often found in legacy or poorly maintained systems. As regulatory expectations rise and the threat landscape becomes more sophisticated, organizations must urgently prioritize ICS security, bolster monitoring, and implement zero trust architectures to defend critical infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Delta Electronics 2025 ICS Vulnerability: Buffer Overflow in CNCSoft-G2 Threatens Industrial Operations
Impact· medium

Delta Electronics 2025 ICS Vulnerability: Buffer Overflow in CNCSoft-G2 Threatens Industrial Operations

In November 2025, Delta Electronics publicly disclosed a critical vulnerability in its CNCSoft-G2 software (version 2.1.0.27 and prior), used widely across critical manufacturing and energy sectors. The stack-based buffer overflow vulnerability (CVE-2025-58317) could be exploited by attackers using a malicious file to achieve arbitrary code execution with the privileges of the target process. Although no public exploitation has been reported yet and remote exploitation is not possible, the flaw poses significant risks to organizations controlling industrial networks, potentially undermining operational continuity and safety systems. Mitigations and patches have been released, with recommendations for further defense-in-depth and updated secure remote access. This case highlights the ongoing challenges in securing industrial control software as threat actors frequently target poorly validated file handling and legacy code. The need for robust patch management and segmentation is paramount—especially as ransomware groups and nation-state actors increasingly pursue industrial targets for disruption or extortion.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Fuji Electric HMI 2025: Buffer Overflow Exposes Critical Manufacturing Risks
Impact· medium

Fuji Electric HMI 2025: Buffer Overflow Exposes Critical Manufacturing Risks

In November 2025, vulnerabilities were disclosed in the Fuji Electric Monitouch V-SFT-6 HMI software (version 6.2.7.0), exposing critical manufacturing environments worldwide to potential compromise. Security researchers discovered both heap-based and stack-based buffer overflow flaws, which could allow a malicious user, via specially crafted project files, to crash targeted devices or execute arbitrary code. While there has been no evidence of active exploitation or remote attacks reported, these vulnerabilities highlight the exposed attack surface for industrial control system (ICS) operators. Following responsible disclosure, Fuji Electric addressed the issues in the October update, urging all users to upgrade immediately. This incident underscores the growing risk posed by supply chain and software vulnerabilities in critical infrastructure. With attackers increasingly targeting ICS and operational technology (OT) environments, prompt patching and layered defense strategies are more important than ever.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
CISA Discloses 2025 ICS Vulnerabilities Affecting Critical Infrastructure
Impact· medium

CISA Discloses 2025 ICS Vulnerabilities Affecting Critical Infrastructure

In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released five Industrial Control Systems (ICS) Advisories highlighting significant vulnerabilities impacting multiple vendors: Fuji Electric, Survision, Delta Electronics, Radiometrics, and IDIS. These advisories detail newly identified security issues, including unencrypted communication, improper authentication, and exploitable flaws exposing critical industrial and manufacturing systems to potential attack vectors. While no active exploitation has been publicly reported yet, the disclosed vulnerabilities could allow remote attackers to gain unauthorized access, disrupt operations, or compromise sensitive operational technology environments if left unaddressed. This incident underscores the ongoing and urgent need for proactive vulnerability management and timely patching within ICS environments. With an uptick in vulnerability disclosures and the rising convergence of IT and operational technology, threat actors continue to target unpatched systems in critical infrastructure, amplifying regulatory and business risk for operators in energy, manufacturing, and transportation sectors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Claroty Authentication Bypass Threatens OT Security in 2025
Impact· medium

Claroty Authentication Bypass Threatens OT Security in 2025

In early 2025, a critical vulnerability tracked as CVE-2025-54603 was discovered in Claroty’s industrial cybersecurity products, exposing operational technology (OT) networks and critical infrastructure to potential attacks and data theft. The flaw allowed threat actors to bypass authentication mechanisms, granting unauthorized access to sensitive network segments. Attackers leveraging this security gap could disrupt essential services, compromise confidential process data, and pose significant operational and safety risks. Claroty responded by issuing urgent patches to contain the exposure and mitigate ongoing threats. This incident highlights the increasing risk of authentication bypass exploits in OT environments, as threat actors target weak points in security architectures to gain privileged access. The event underscores an urgent need for robust, zero trust security frameworks and rapid vulnerability management in critical infrastructure sectors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports