The Containment Era is here. →Explore

Industry Category

Oil/Energy/Solar/Greentech

Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.

378 threat reports
Page 3 of 32

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Oil/Energy/Solar/Greentech Threat Reports

Showing 2536 / 378 reports
Critical Vulnerabilities in Siemens SICAM 8 Products: Immediate Updates Recommended
Impact· HIGH

Critical Vulnerabilities in Siemens SICAM 8 Products: Immediate Updates Recommended

In July 2026, Siemens disclosed multiple vulnerabilities in its SICAM 8 products, including CPCI85 Central Processing/Communication and SICORE Base system, affecting versions prior to V26.20 and V26.20.0 respectively. These vulnerabilities encompass issues such as accessible debugging interfaces leading to denial-of-service conditions (CVE-2026-54798), flaws in firmware signature validation allowing malicious firmware installation (CVE-2026-54799), default configurations disabling OPC UA security mechanisms (CVE-2026-54800), and insufficient validation of authentication credentials enabling privilege escalation (CVE-2026-54801). Siemens has released updates to address these vulnerabilities and recommends users upgrade to the latest versions. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-229470.html?utm_source=openai)) The disclosure of these vulnerabilities underscores the critical importance of securing industrial control systems, especially in sectors like energy and manufacturing. The potential for unauthorized access and system compromise highlights the need for organizations to promptly apply security updates and review their system configurations to mitigate risks associated with these vulnerabilities.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Vulnerabilities in Rockwell Automation's ICS Controllers: What You Need to Know
Impact· CRITICAL

Critical Vulnerabilities in Rockwell Automation's ICS Controllers: What You Need to Know

In 2025, Rockwell Automation identified multiple vulnerabilities in its CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers. These flaws, including CVE-2025-12011, CVE-2025-12012, and CVE-2025-11698, could allow remote attackers to cause major non-recoverable faults (MNRF) in affected devices, leading to denial-of-service conditions. The vulnerabilities were found in firmware versions up to V35.015 for certain models, with Rockwell Automation releasing patches in versions V35.016, V36.011, and later to address these issues. ([rockwellautomation.com](https://www.rockwellautomation.com/pt-pt/trust-center/security-advisories.html?utm_source=openai)) The discovery of these vulnerabilities underscores the critical importance of securing industrial control systems (ICS) against remote attacks. As ICS environments become increasingly interconnected, the potential impact of such vulnerabilities grows, highlighting the need for continuous monitoring, timely patching, and adherence to cybersecurity best practices to protect critical infrastructure.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical Denial-of-Service Vulnerability in Rockwell Automation FLEX 5000 Adapters (CVE-2026-12659)
Impact· HIGH

Critical Denial-of-Service Vulnerability in Rockwell Automation FLEX 5000 Adapters (CVE-2026-12659)

In July 2026, Rockwell Automation disclosed a denial-of-service vulnerability (CVE-2026-12659) in their FLEX 5000® EtherNet/IP Adapters, specifically affecting version 6.011. The vulnerability arises from improper handling of exceptional conditions when processing crafted CIP packets, leading to system instability. Exploitation of this flaw requires a power cycle to restore functionality to the affected module and connected I/O devices. ([rockwellautomation.com](https://www.rockwellautomation.com/en-be/trust-center/security-advisories.html?utm_source=openai)) This incident underscores the critical importance of robust exception handling in industrial control systems. As cyber threats targeting operational technology (OT) environments become more sophisticated, organizations must prioritize timely patch management and implement comprehensive security measures to safeguard critical infrastructure.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Russian Cyberattacks in 2026 Exploit Weak Router Security
Impact· CRITICAL

Russian Cyberattacks in 2026 Exploit Weak Router Security

In July 2026, state-sponsored threat actors affiliated with Russia's Federal Security Service (FSB) Center 16 exploited weakly protected routers and networking equipment to infiltrate critical infrastructure networks globally. Targeted sectors included defense, energy, financial services, government, and healthcare. The attackers utilized techniques such as scanning for exposed SNMP services with default or easily guessed passwords and exploiting known vulnerabilities in Cisco devices. This activity led to significant disruptions and data breaches across multiple countries. The incident underscores the persistent threat posed by nation-state actors exploiting basic security lapses. It highlights the urgent need for organizations to implement robust network security measures, including updating device firmware, enforcing strong authentication protocols, and disabling unnecessary services to mitigate such risks.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
ABB Advant Master Online Builder Vulnerability: CVE-2025-13162
Impact· MEDIUM

ABB Advant Master Online Builder Vulnerability: CVE-2025-13162

In June 2026, ABB identified a vulnerability (CVE-2025-13162) in its Advant Master Online Builder software, affecting Control Builder A versions up to 1.4/4 and 800xA for Advant Master versions up to 6.2.0-1. The flaw, an uncontrolled search path element, could allow unauthorized code execution if exploited by an attacker with local access. ABB promptly released updates to remediate the issue and advised customers to upgrade to the latest versions to maintain system integrity. This incident underscores the critical importance of timely software updates and vigilant access control in industrial control systems. As cyber threats targeting operational technology environments continue to evolve, organizations must prioritize proactive vulnerability management to safeguard critical infrastructure.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in ABB Ability Edgenius: Immediate Action Required
Impact· HIGH

Critical Vulnerability in ABB Ability Edgenius: Immediate Action Required

In June 2026, ABB disclosed a critical vulnerability (CVE-2026-31431) in its Ability Edgenius platform, stemming from a flaw in the Linux kernel's cryptographic subsystem. This vulnerability allows locally authenticated users or compromised container workloads to escalate privileges to root, granting full control over affected systems. The issue impacts Edgenius versions 3.2.0.0 to 3.2.4.0 across various deployments, including Edgenius Gateway and Server models. ABB has released version 3.2.4.1 to address this vulnerability and recommends immediate updates. ([library.e.abb.com](https://library.e.abb.com/public/7fecf60652de4f8389c65dd3892ad4f0/7PAA024620_A_en%20ABB%20Ability%20Edgenius.pdf?x-sign=CTBqG4CeWrSNfPCZ4%2Bpgxw0qQeqB4l5P1o8dYUUq%2BXJ5ZJyaTAO4yFUHSWMPvOXH&utm_source=openai)) The 'Copy Fail' vulnerability has been actively exploited in the wild, with reports of attackers leveraging it to gain unauthorized root access in cloud environments. Given its widespread impact across multiple Linux distributions and the availability of proof-of-concept exploits, organizations are urged to prioritize patching to mitigate potential security breaches. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/?utm_source=openai))

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities in ABB T-MAC Plus Threaten Industrial Control Systems
Impact· CRITICAL

Critical Vulnerabilities in ABB T-MAC Plus Threaten Industrial Control Systems

In June 2026, ABB disclosed multiple critical vulnerabilities in its T-MAC Plus system, versions 4.0-24, affecting industrial control systems worldwide. The identified vulnerabilities include CVE-2025-14771 (file disclosure), CVE-2025-14772 (authorization bypass), CVE-2025-14773 (stored cross-site scripting), and CVE-2025-14774 (denial-of-service via insecure network protocol). Exploitation of these flaws could lead to unauthorized access, data exfiltration, and disruption of critical manufacturing operations. ABB has released version 4.0-25 to address these issues and recommends immediate updates. ([library.e.abb.com](https://library.e.abb.com/public/fdc6cdcbc5a14784a640c5f346bb5d5d/9AKK108472A7840_en_A_Vulnerabilities%20in%20T-MAC%20Plus.pdf?x-sign=9BMyAW9U5kVKNEtaWjhiCwtjt5iWMxiwQl8QdxbPx1vwCqNhlozXxFzbtRzs7ZQN&utm_source=openai)) The disclosure underscores the persistent threat landscape targeting industrial control systems, emphasizing the need for robust cybersecurity measures. Organizations are urged to assess their systems for similar vulnerabilities and implement comprehensive security protocols to safeguard against potential exploits.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Security Alert: Unauthenticated Remote Access Vulnerability in Rockwell Automation 1715-AENTR EtherNet/IP Adapter
Impact· CRITICAL

Critical Security Alert: Unauthenticated Remote Access Vulnerability in Rockwell Automation 1715-AENTR EtherNet/IP Adapter

In July 2026, a critical vulnerability (CVE-2026-10577) was identified in Rockwell Automation's 1715-AENTR EtherNet/IP Adapter, exposing a network-accessible debug port lacking proper authentication controls. This flaw allows unauthenticated remote attackers to execute intrusive command-line interface commands, including reading or deleting files, stopping tasks, modifying memory, and altering I/O states, thereby compromising the device's confidentiality, integrity, and availability. The vulnerability affects versions up to and including 3.003. Rockwell Automation has released version 3.011 to address this issue. Organizations utilizing these adapters are urged to update promptly to mitigate potential risks. This incident underscores the critical importance of securing industrial control systems against unauthorized access, especially as such vulnerabilities can lead to significant operational disruptions. The exposure of critical functions without authentication highlights the need for stringent security measures in industrial environments to prevent potential exploitation by malicious actors.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Russian FSB Exploits Cisco Vulnerabilities in Critical Infrastructure Attacks
Impact· CRITICAL

Russian FSB Exploits Cisco Vulnerabilities in Critical Infrastructure Attacks

In July 2026, a joint cybersecurity advisory from the United States and 12 other nations highlighted ongoing cyber intrusions by Russian state-sponsored hackers, specifically the FSB's Center 16, also known as Berserk Bear and Static Tundra. These actors have been exploiting vulnerabilities in Cisco networking devices, notably CVE-2008-4128 and CVE-2018-0171, to infiltrate critical infrastructure sectors such as defense, communications, energy, finance, government, and healthcare. The attackers leverage default or weak passwords and unpatched systems to gain unauthorized access, conduct reconnaissance, and potentially disrupt operations. This incident underscores the persistent threat posed by nation-state actors targeting outdated and misconfigured network devices. Organizations are urged to implement robust security measures, including disabling vulnerable features like Cisco's Smart Install, enforcing strong authentication protocols, and regularly updating systems to mitigate such risks.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
EU and UK Sanction Russian Entities Over Cyberespionage Campaign
Impact· HIGH

EU and UK Sanction Russian Entities Over Cyberespionage Campaign

In July 2026, the European Union and the United Kingdom imposed coordinated sanctions on Russian military intelligence officers, hackers, and private companies in response to a prolonged cyberespionage campaign attributed to Russian actors. The EU targeted nine individuals and four entities, while the UK sanctioned 24 individuals and organizations. These sanctions, including asset freezes and travel bans, were directed at actors linked to Russia's FSB and GRU intelligence agencies, accused of conducting cyber operations targeting governments and critical infrastructure since 2010. Key affected countries include France, Germany, Poland, the Netherlands, and Finland, with specific incidents such as the sabotage of Polish railway infrastructure highlighted. ([apnews.com](https://apnews.com/article/1d3c542e1409b54a10856eacad18b7ca?utm_source=openai)) This incident underscores the escalating threat of state-sponsored cyberattacks on critical infrastructure and governmental networks. The coordinated response by the EU and UK reflects a growing recognition of the need for unified action against cyber threats, emphasizing the importance of robust cybersecurity measures and international cooperation to safeguard national security and public services.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
EU and UK Sanction Russian GRU Hackers Over Cyberattacks
Impact· CRITICAL

EU and UK Sanction Russian GRU Hackers Over Cyberattacks

In July 2026, the European Union and the United Kingdom jointly imposed sanctions on Russian military intelligence officers and associated entities for orchestrating extensive cyberattacks across Europe. These operations, attributed to the GRU and FSB's 16th Centre, targeted government networks and critical infrastructure in countries including France, Germany, Poland, and Finland. Notably, the Turla hacking group, linked to the FSB, attempted to disrupt Poland's energy grid, potentially affecting 500,000 residents during winter. The sanctions encompass asset freezes and travel bans on individuals and entities involved in these cyberespionage activities. This incident underscores the escalating threat of state-sponsored cyberattacks on critical infrastructure, highlighting the need for enhanced cybersecurity measures and international cooperation to deter such activities. The coordinated response by the EU and UK reflects a growing consensus on the importance of addressing cyber threats through unified diplomatic and legal actions.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
US and Allies Issue Joint Advisory on Russian Cyber Threats to Critical Infrastructure
Impact· CRITICAL

US and Allies Issue Joint Advisory on Russian Cyber Threats to Critical Infrastructure

In July 2026, cybersecurity agencies from the United States and eight allied nations issued a joint advisory warning that Russian state-sponsored hackers, specifically FSB Center 16 (also known as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra), are actively targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks. These actors exploit default or weak SNMP authentication strings and known vulnerabilities, such as CVE-2018-0171 in Cisco's Smart Install feature, to gain unauthorized access, exfiltrate configuration files, and conduct reconnaissance within victim networks. The sectors most at risk include energy, communications, defense industrial base, healthcare, financial services, and government services. This incident underscores the persistent threat posed by nation-state actors to critical infrastructure, highlighting the importance of proactive cybersecurity measures. Organizations are urged to upgrade to SNMPv3, disable unnecessary services like Cisco Smart Install, enforce strong unique passwords, block TFTP and SNMP traffic at edge firewalls, update software and firmware, and replace end-of-life devices to mitigate such risks.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports