The Containment Era is here. →Explore

Industry Category

Oil/Energy/Solar/Greentech

Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.

378 threat reports
Page 8 of 32

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Oil/Energy/Solar/Greentech Threat Reports

Showing 8596 / 378 reports
CISA Issues Warning on Cyberattacks Targeting Fuel Tank Monitoring Systems
Impact· CRITICAL

CISA Issues Warning on Cyberattacks Targeting Fuel Tank Monitoring Systems

In June 2026, the Cybersecurity and Infrastructure Security Agency (CISA), along with the FBI, NSA, and Department of Energy, issued a warning about cyberattacks targeting internet-exposed automatic tank gauge (ATG) systems used to monitor fuel and liquid storage tanks across critical infrastructure sectors. Attackers exploited vulnerabilities such as authentication bypasses, hardcoded credentials, and command-execution flaws to gain unauthorized access, allowing them to alter network settings, tank volumes, and pump controls. This manipulation could disable alerts and hinder operators from accurately monitoring tank levels, increasing the risk of leaks or equipment failures. This incident underscores the growing threat to operational technology (OT) systems within critical infrastructure. The exploitation of ATG systems highlights the need for enhanced cybersecurity measures, including restricting internet exposure, implementing strong authentication protocols, and applying timely security updates to prevent unauthorized access and potential operational disruptions.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Urgent Advisory: Securing Automatic Tank Gauge Systems Against Cyber Threats
Impact· CRITICAL

Urgent Advisory: Securing Automatic Tank Gauge Systems Against Cyber Threats

In April 2026, the Cybersecurity and Infrastructure Security Agency (CISA), along with multiple federal partners, issued an urgent advisory regarding active cyberattacks targeting Automatic Tank Gauge (ATG) systems across the United States. These systems, integral to monitoring fuel storage tanks in sectors such as Energy, Chemical, Food and Agriculture, and Transportation, were found to be vulnerable due to internet exposure and weak authentication mechanisms. Threat actors exploited these weaknesses to gain unauthorized access, potentially allowing them to manipulate tank levels, disable alarms, and disrupt operations. While no physical damage was reported, the incidents underscored significant cybersecurity gaps in critical infrastructure. ([infoodandfuel.org](https://www.infoodandfuel.org/news/cybersecurity-alert-automatic-tank-gauge-systems-targeted?utm_source=openai)) This advisory highlights the escalating threat landscape for operational technology (OT) systems, emphasizing the need for immediate action to secure ATG systems. The incidents serve as a stark reminder of the vulnerabilities present in internet-exposed OT devices and the potential for malicious actors to exploit these weaknesses to disrupt essential services.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Iran's MOIS Expands Handala Brand to Physical Threats in 2026
Impact· HIGH

Iran's MOIS Expands Handala Brand to Physical Threats in 2026

In early 2026, Iran's Ministry of Intelligence (MOIS) expanded its 'Handala' brand to include physical threat operations targeting U.S. and Israeli interests. This expansion introduced the Handala Popular Resistance Front (HPRF), a persona soliciting individuals to conduct physical attacks and espionage for financial rewards. Concurrently, three influence operations networks—'VIPEmployment,' 'MOISIRAN,' and 'Brave Israel'—were identified as MOIS personas, amplifying the reach of these operations. ([recordedfuture.com](https://www.recordedfuture.com/research/iran-handala-physical-threats?utm_source=openai)) This development signifies a strategic shift in MOIS's external operations, integrating cyber, physical, and influence tactics under the Handala brand. The coordinated use of these personas likely enhances the effectiveness of MOIS's campaigns, posing increased risks to U.S. and Israeli law enforcement, military, intelligence agencies, and critical infrastructure sectors. ([recordedfuture.com](https://www.recordedfuture.com/research/iran-handala-physical-threats?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Polish Water Treatment Plant Breach: A Wake-Up Call for Critical Infrastructure Security
Impact· HIGH

Polish Water Treatment Plant Breach: A Wake-Up Call for Critical Infrastructure Security

Between 2024 and 2025, Poland's Internal Security Agency (ABW) reported that state-sponsored threat actors, including APT28 and APT29, infiltrated industrial control systems (ICS) at five municipal water treatment facilities. The attackers exploited weak passwords and internet-exposed systems, gaining the capability to manipulate operational parameters, potentially compromising water quality and public safety. This breach underscores the critical vulnerabilities in essential infrastructure and the pressing need for robust cybersecurity measures. The incident highlights a growing trend of cyberattacks targeting operational technology (OT) systems within critical infrastructure sectors. As adversaries increasingly focus on these sectors, organizations must prioritize securing OT environments to prevent potential disruptions and safeguard public health.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
MacGregor VDR G4e Vulnerabilities Highlight Maritime Cybersecurity Challenges
Impact· MEDIUM

MacGregor VDR G4e Vulnerabilities Highlight Maritime Cybersecurity Challenges

In May 2026, multiple critical vulnerabilities were identified in the MacGregor Voyage Data Recorder (VDR) G4e, a maritime device essential for recording navigational and operational data. These vulnerabilities, including the use of default and hard-coded credentials, insufficiently protected passwords, and improper access controls, could allow unauthorized attackers to gain administrator access to the device. Such exploitation poses significant risks, including unauthorized data access, manipulation, or deletion, potentially compromising maritime safety and incident investigations. This incident underscores the pressing need for enhanced cybersecurity measures in maritime systems. As vessels increasingly integrate networked technologies, the attack surface expands, making it imperative to address security flaws promptly. The vulnerabilities in the VDR G4e highlight the broader challenge of securing critical infrastructure against evolving cyber threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Security Flaw in Jinan USR IOT's USR-W610 Converter Exposes Networks to Attack
Impact· HIGH

Critical Security Flaw in Jinan USR IOT's USR-W610 Converter Exposes Networks to Attack

In May 2026, a critical vulnerability (CVE-2026-7786) was identified in Jinan USR IOT Technology Limited's USR-W610 RS232/485 to Wi-Fi/Ethernet Converter, firmware version 7.03T.07. The device contains hard-coded plaintext administrative credentials embedded within the firmware, which can be extracted and used by attackers to gain full administrator access. This flaw poses significant risks, including unauthorized control over the device and potential network intrusion. The vendor has not responded to coordination attempts, leaving users without an official patch or remediation guidance. This incident underscores the persistent issue of hard-coded credentials in IoT devices, a vulnerability that has been exploited in various sectors, leading to unauthorized access and control. The lack of vendor response highlights the challenges in securing IoT devices, emphasizing the need for proactive security measures and regular vulnerability assessments to mitigate such risks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Schneider Electric's EcoStruxure Machine Expert HVAC Vulnerability: CVE-2026-6332
Impact· HIGH

Schneider Electric's EcoStruxure Machine Expert HVAC Vulnerability: CVE-2026-6332

In May 2026, Schneider Electric disclosed a vulnerability (CVE-2026-6332) in its EcoStruxure Machine Expert HVAC software versions prior to 1.10.0. This flaw involves the cleartext storage of sensitive information, potentially exposing protected source code when accessed by authorized users for editing or compiling. Such exposure could lead to a loss of confidentiality and unauthorized disclosure of proprietary logic and operational details. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-6332?utm_source=openai)) This incident underscores the critical importance of securing engineering workstations and programming environments in industrial settings. As industrial control systems become increasingly interconnected, ensuring the confidentiality and integrity of source code is paramount to prevent potential reconnaissance and exploitation by malicious actors.

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ESET APT Activity Report Q4 2025–Q1 2026: Key Cyber Threats Unveiled
Impact· HIGH

ESET APT Activity Report Q4 2025–Q1 2026: Key Cyber Threats Unveiled

Between October 2025 and March 2026, ESET researchers observed significant activities from various Advanced Persistent Threat (APT) groups. China-aligned actors conducted espionage campaigns targeting maritime, energy, and political sectors, notably in Venezuela and Syria. Iran-aligned groups experienced a decline in activity due to domestic internet restrictions, while proxy and hacktivist actors increased attacks on Israel and the United States. North Korea-aligned groups focused on developers and the cryptocurrency ecosystem, employing social engineering tactics for financial gain and potential supply-chain compromises. Russia-aligned actors intensified operations against Ukraine, deploying new wipers and targeting critical infrastructure, with notable incidents extending to NATO member states like Poland. Lesser-known clusters also emerged, including browser-in-the-browser phishing attacks and Android spyware targeting Arabic-speaking users. This period underscores the evolving tactics of APT groups and the necessity for robust cybersecurity measures to counteract these sophisticated threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
GreyVibe Hackers Leverage AI in 2025 Cyberattacks
Impact· HIGH

GreyVibe Hackers Leverage AI in 2025 Cyberattacks

In August 2025, the Russian-linked threat group GreyVibe initiated a cyberespionage campaign targeting Ukrainian military, government, civilian, and business sectors. Utilizing AI tools like ChatGPT and Google Gemini, they crafted sophisticated lures and developed custom malware, including LegionRelay and PhantomRelay, to infiltrate systems and exfiltrate sensitive data. Their tactics encompassed spear-phishing emails, fake CAPTCHA pages, and counterfeit websites, leading to significant data breaches and operational disruptions. This incident underscores the escalating use of AI in cyberattacks, enabling threat actors to enhance the scale and sophistication of their operations. Organizations must adapt by implementing advanced security measures and continuous monitoring to counteract these evolving threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Enhancing Industrial Security: AI-Assisted Sparkplug B Protocol Fuzzer Released
Impact· HIGH

Enhancing Industrial Security: AI-Assisted Sparkplug B Protocol Fuzzer Released

In May 2026, Bishop Fox released a security fuzzer for the Sparkplug B protocol, a dominant MQTT-based protocol in industrial control and SCADA environments. This tool systematically tests all nine message types, 19 data types, and over 87 unique field paths defined by the Eclipse Sparkplug specification. The fuzzer was developed with AI assistance, specifically utilizing Claude Code to identify coverage gaps and Python defects, resulting in a hardened, self-contained tool with CLI, logging, and passive network discovery capabilities. This development is crucial for ICS and SCADA operators, device vendors, and defenders, as it enables the identification of crashes, protocol violations, and state-handling bugs in Sparkplug B endpoints before attackers can exploit them. The tool is available on GitHub for immediate use.

2 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical DoS Vulnerability in ABB B&R Automation Runtime (CVE-2025-3450)
Impact· CRITICAL

Critical DoS Vulnerability in ABB B&R Automation Runtime (CVE-2025-3450)

In October 2025, ABB identified a critical vulnerability (CVE-2025-3450) in the System Diagnostics Manager (SDM) component of B&R Automation Runtime versions prior to 6.3 and Q4.93. This flaw allows unauthenticated, network-based attackers to delete data, leading to denial-of-service conditions. The vulnerability stems from improper resource locking within the SDM, potentially causing affected systems to cease operation upon exploitation. ABB has released updates to address this issue and recommends users upgrade to Automation Runtime versions 6.3 or Q4.93 to mitigate the risk. This incident underscores the importance of timely patch management and robust network security practices, especially in critical infrastructure sectors where such vulnerabilities can have significant operational impacts.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability in ABB Ability™ zenon: CVE-2025-8754
Impact· HIGH

Critical Vulnerability in ABB Ability™ zenon: CVE-2025-8754

In August 2025, a critical vulnerability (CVE-2025-8754) was identified in ABB's Ability™ zenon software, versions 7.50 through 14. This flaw allows unauthenticated remote attackers to access critical functions, potentially leading to denial-of-service conditions in industrial control environments. The vulnerability arises from missing authentication mechanisms in the Remote Transport Service, enabling unauthorized system reboots. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2025-8754&utm_source=openai)) The incident underscores the importance of robust authentication protocols in industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, organizations must prioritize timely vulnerability assessments and implement comprehensive security measures to mitigate potential risks.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports