The Containment Era is here. →Explore

Industry Category

Oil/Energy/Solar/Greentech

Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.

378 threat reports
Page 5 of 32

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Oil/Energy/Solar/Greentech Threat Reports

Showing 4960 / 378 reports
Critical Vulnerabilities in Delta Electronics DVP12SE PLCs: CVE-2026-12819 and CVE-2026-12818
Impact· CRITICAL

Critical Vulnerabilities in Delta Electronics DVP12SE PLCs: CVE-2026-12819 and CVE-2026-12818

In June 2026, critical vulnerabilities were identified in Delta Electronics DVP12SE Programmable Logic Controllers (PLCs), specifically CVE-2026-12819 and CVE-2026-12818. These flaws allow remote attackers to issue commands, modify operational values, and interfere with control logic without authentication. The vulnerabilities affect all versions of the DVP12SE PLC, potentially enabling unauthorized access to sensitive control functions and causing resource exhaustion through flooding attacks. The discovery of these vulnerabilities underscores the increasing risks associated with industrial control systems (ICS) and the necessity for robust security measures. Organizations utilizing Delta Electronics DVP12SE PLCs should implement recommended mitigations, such as enabling IP filtering, setting up password protection, and ensuring network isolation, to safeguard against potential exploitation.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical XZ Utils Vulnerability Affects B&R Products (CVE-2025-31115)
Impact· HIGH

Critical XZ Utils Vulnerability Affects B&R Products (CVE-2025-31115)

In June 2026, B&R Industrial Automation GmbH disclosed a critical vulnerability (CVE-2025-31115) in their products due to a flaw in XZ Utils versions 5.3.3alpha to 5.8.0. This race condition within the multithreaded .xz decoder in liblzma could allow attackers to crash the system or corrupt memory data. Affected products include PPC3100, C50, C80, FT50, MT50, T30, T80, and T50, with specific versions listed in the advisory. The vulnerability has a CVSS v3 base score of 7.5, indicating high severity. ([cisa.gov](https://www.cisa.gov/sites/default/files/publications/web-metrics/CISA.gov-Apr-2024-Web-Metrics-508.pdf?utm_source=openai)) This incident underscores the importance of promptly addressing vulnerabilities in widely used open-source libraries. Organizations are advised to update to XZ Utils version 5.8.1 or apply the provided patches to mitigate potential risks. ([cisa.gov](https://www.cisa.gov/sites/default/files/publications/web-metrics/CISA.gov-Apr-2024-Web-Metrics-508.pdf?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Authentication Bypass in Frangoteam FUXA SCADA/HMI Software (CVE-2026-13207)
Impact· HIGH

Critical Authentication Bypass in Frangoteam FUXA SCADA/HMI Software (CVE-2026-13207)

In June 2026, a critical authentication bypass vulnerability (CVE-2026-13207) was identified in Frangoteam's FUXA SCADA/HMI software versions 1.3.1 and earlier. This flaw allows unauthenticated remote attackers to access sensitive user and role data by exploiting improper path normalization in the REST API. By manipulating URL paths with dot-segment sequences, attackers can bypass authentication checks and retrieve confidential information without credentials. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-13207?utm_source=openai)) This incident underscores the persistent risks associated with authentication bypass vulnerabilities in industrial control systems. As SCADA environments increasingly integrate web-based interfaces, ensuring robust authentication mechanisms becomes paramount to prevent unauthorized access and potential operational disruptions.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities Discovered in Mitsubishi Electric's MELSOFT Update Manager
Impact· HIGH

Critical Vulnerabilities Discovered in Mitsubishi Electric's MELSOFT Update Manager

In June 2026, Mitsubishi Electric disclosed multiple vulnerabilities in its MELSOFT Update Manager SW1DND-UDM-M software, specifically versions 1.000A through 1.014Q. These vulnerabilities, identified as CVE-2025-53816, CVE-2025-53817, CVE-2025-55188, and CVE-2025-11001, stem from issues within the bundled 7-Zip component. Exploitation could allow local attackers to execute arbitrary code, cause denial-of-service conditions, or tamper with information by convincing users to decompress specially crafted archive files. The affected software is widely used in critical manufacturing sectors globally. ([knutmichael.com](https://knutmichael.com/radar/2026-06-30-mitsubishi-electric-melsoft-update-manager-sw1dnd-udm-m?utm_source=openai)) The disclosure underscores the persistent risks associated with third-party components in industrial control systems. Organizations are urged to promptly update to version 1.015R or later and implement recommended security measures to mitigate potential threats. ([knutmichael.com](https://knutmichael.com/radar/2026-06-30-mitsubishi-electric-melsoft-update-manager-sw1dnd-udm-m?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities in Schneider Electric's EasyLogic T150 and Saitel DP RTUs
Impact· HIGH

Critical Vulnerabilities in Schneider Electric's EasyLogic T150 and Saitel DP RTUs

In June 2026, Schneider Electric disclosed two critical vulnerabilities affecting their EasyLogic T150 and Saitel DP Remote Terminal Units (RTUs). The first, CVE-2026-9650, involves insufficiently protected credentials, allowing unauthenticated attackers to access sensitive information stored within firmware or system files. The second, CVE-2026-9651, pertains to incorrect permission assignments for critical resources, enabling attackers with privileged local access to read improperly protected system files, potentially leading to account compromise. These vulnerabilities pose significant risks to critical infrastructure sectors, including manufacturing and energy, as they could lead to unauthorized access and control over essential systems. The disclosure of these vulnerabilities underscores the ongoing challenges in securing industrial control systems (ICS). As cyber threats targeting ICS continue to evolve, organizations must remain vigilant, regularly updating and patching their systems to mitigate potential risks. This incident highlights the importance of proactive cybersecurity measures and the need for continuous monitoring to protect critical infrastructure from emerging threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in Yokogawa FAST/TOOLS and CI Server Exposes Sensitive Information
Impact· HIGH

Critical Vulnerability in Yokogawa FAST/TOOLS and CI Server Exposes Sensitive Information

In June 2026, a critical vulnerability (CVE-2026-11833) was identified in Yokogawa's FAST/TOOLS and Collaborative Information Server (CI Server). The web server component of these systems could return HTTP responses containing sensitive configuration information without requiring authentication. This flaw, present in FAST/TOOLS versions R9.01 through R10.04 and CI Server versions R1.01 through R1.04, exposes system settings that attackers could exploit for further attacks. The vulnerability has been assigned a CVSS 4.0 score of 8.2, indicating high severity. This incident underscores the ongoing risks associated with cleartext transmission of sensitive information in industrial control systems. Organizations utilizing these Yokogawa products should prioritize applying the recommended updates to mitigate potential exploitation and enhance their cybersecurity posture.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Security Flaws Discovered in EVoke Systems' Charging Station Management System
Impact· CRITICAL

Critical Security Flaws Discovered in EVoke Systems' Charging Station Management System

In June 2026, multiple critical vulnerabilities were identified in EVoke Systems' Charging Station Management System (CSMS), potentially allowing attackers to gain unauthorized administrative control over charging stations or disrupt services via denial-of-service attacks. The vulnerabilities include missing authentication for critical functions, improper restriction of excessive authentication attempts, insufficient session expiration, and insufficiently protected credentials. These flaws affect all versions of EVoke CSMS and pose significant risks to the energy and transportation sectors worldwide. The discovery of these vulnerabilities underscores the growing cybersecurity challenges in the electric vehicle infrastructure. As the adoption of EVs accelerates, ensuring the security of charging networks becomes paramount to prevent potential disruptions and safeguard user data.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Vulnerability in Horner Automation Cscape: CVE-2026-12897
Impact· HIGH

Critical Vulnerability in Horner Automation Cscape: CVE-2026-12897

In June 2026, a critical vulnerability (CVE-2026-12897) was identified in Horner Automation's Cscape software versions prior to 10.2 SP3. This out-of-bounds read flaw in the CSP file parser could allow local attackers to disclose sensitive information and execute arbitrary code. The vulnerability was reported by Michael Heinzl and has a CVSS v3 score of 7.8, indicating high severity. Horner Automation has released Cscape 10.2 SP3 to address this issue. This incident underscores the importance of timely software updates in industrial control systems. As cyber threats targeting critical manufacturing sectors increase, organizations must prioritize patch management and implement robust security measures to protect against potential exploits.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Schneider Electric PowerLogic P7 Vulnerabilities Disclosed in 2026
Impact· HIGH

Schneider Electric PowerLogic P7 Vulnerabilities Disclosed in 2026

In June 2026, Schneider Electric disclosed multiple vulnerabilities in its PowerLogic™ P7 product, including CVE-2026-9716 (NULL Pointer Dereference), CVE-2026-9717 (OS Command Injection), and CVE-2026-9718 (Reachable Assertion). These vulnerabilities could lead to denial-of-service conditions, unauthorized command execution, and system instability. Affected versions include PowerLogic™ P7 version 0.2.003.001.000 and prior. Schneider Electric has released firmware version V02.004.001 to address these issues. Organizations are advised to apply the update promptly to mitigate potential risks. ([radar.offseq.com](https://radar.offseq.com/threat/multiple-vulnerabilities-on-powerlogic-p7-e233bd41?utm_source=openai)) The disclosure underscores the critical importance of timely vulnerability management in industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, maintaining up-to-date systems and adhering to cybersecurity best practices are essential to safeguard operational integrity and prevent potential disruptions.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Chinese APT CL-STA-1062's Deployment of TinyRCT Backdoor in Southeast Asia
Impact· HIGH

Chinese APT CL-STA-1062's Deployment of TinyRCT Backdoor in Southeast Asia

In 2025, the Chinese-speaking advanced persistent threat (APT) group CL-STA-1062 targeted government entities and critical infrastructure in Southeast Asia, focusing on state-owned enterprises in the energy and government sectors. The attackers employed a hybrid toolkit, including common open-source tools like SoftEther VPN and Mimikatz, alongside a newly developed backdoor named TinyRCT. This backdoor facilitated arbitrary command execution, file exfiltration, screen capture, and included a self-destruct mechanism to erase forensic evidence. The campaign involved initial access through web application exploitation, deployment of ASPX web shells, and subsequent reconnaissance and lateral movement within the compromised networks. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/?utm_source=openai)) This incident underscores the evolving sophistication of APT groups in developing custom malware to infiltrate critical infrastructure. The use of TinyRCT highlights the need for organizations to enhance their detection capabilities and implement robust security measures to defend against such advanced threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Vulnerabilities in Siemens SINEC INS: Immediate Action Required
Impact· HIGH

Critical Vulnerabilities in Siemens SINEC INS: Immediate Action Required

In June 2026, Siemens disclosed multiple vulnerabilities in its SINEC INS software, versions prior to V1.0 SP2 Update 6. These vulnerabilities include improper input sanitization leading to OS command injection (CVE-2026-46746), path traversal (CVE-2026-46747), execution with unnecessary privileges (CVE-2026-46748), and the use of a one-way hash with a predictable salt (CVE-2026-46749). Exploitation of these flaws could allow attackers to execute arbitrary commands, access unintended file system locations, escalate privileges, and recover user passwords, potentially resulting in unauthorized access and control over affected systems. The disclosure underscores the critical importance of timely software updates and robust security practices in industrial control systems. Organizations utilizing SINEC INS are urged to upgrade to V1.0 SP2 Update 6 or later to mitigate these risks. This incident highlights the ongoing challenges in securing industrial networks against evolving cyber threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in Hubbell Aclara Metrum Cellular Web Interface (CVE-2026-1840)
Impact· HIGH

Critical Vulnerability in Hubbell Aclara Metrum Cellular Web Interface (CVE-2026-1840)

In June 2026, a critical vulnerability (CVE-2026-1840) was identified in the Hubbell Aclara Metrum Cellular Web Interface, affecting versions prior to v2.1.0.105. This flaw allows unauthorized access to critical system functions due to missing authentication controls, enabling attackers to alter device configurations and disrupt operations, potentially leading to loss of communications. The vulnerability poses significant risks to the energy sector, particularly in the United States, where these devices are widely deployed. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1740?utm_source=openai)) The incident underscores the importance of robust authentication mechanisms in industrial control systems. With increasing cyber threats targeting critical infrastructure, organizations must prioritize timely firmware updates and implement comprehensive security measures to mitigate such vulnerabilities.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports