The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Oil/Energy/Solar/Greentech
Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.
Explore Other Sectors
Oil/Energy/Solar/Greentech Threat Reports
Critical Vulnerability in Hitachi Energy PCM600: CVE-2018-1002208
In April 2026, Hitachi Energy disclosed a vulnerability in its PCM600 product, specifically affecting versions up to 3.1 SP3. The flaw, identified as CVE-2018-1002208, stems from the use of SharpZipLib versions prior to 1.0 RC1, which are susceptible to directory traversal attacks. Exploiting this 'Zip-Slip' vulnerability, attackers can write arbitrary files via crafted Zip archives, potentially compromising system integrity. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2018-1002208?utm_source=openai)) This incident underscores the critical importance of timely software updates and vigilant dependency management. Organizations must proactively address known vulnerabilities in third-party libraries to mitigate risks associated with supply chain attacks and ensure the security of their operational environments.
4 months ago
Kill Chain
Critical Vulnerability in ABB B&R Automation Studio: CVE-2025-11043
In January 2026, ABB disclosed a critical vulnerability (CVE-2025-11043) in its B&R Automation Studio software versions prior to 6.5. This flaw involves improper certificate validation in the OPC-UA and ANSL over TLS clients, potentially allowing unauthenticated attackers to intercept and manipulate data exchanges. Such exploitation could lead to unauthorized access and control over industrial automation systems, posing significant risks to operational integrity. The increasing reliance on secure communication protocols in industrial control systems underscores the importance of robust certificate validation mechanisms. This incident highlights the necessity for organizations to promptly update affected systems and implement comprehensive security measures to mitigate similar vulnerabilities.
4 months ago
Kill Chain
Unitree Go1 Robot Backdoor Vulnerability Exposes Critical Security Flaws
In March 2025, security researchers uncovered a critical backdoor vulnerability in Unitree Robotics' Go1 quadruped robot, designated as CVE-2025-2894. This flaw allowed unauthorized remote control of the robots via the CloudSail service, posing significant risks to operational integrity and safety. Exploiting this backdoor, attackers could access live camera feeds, manipulate robot movements, and potentially exfiltrate sensitive data without the operator's knowledge. The discovery highlighted the urgent need for robust security measures in the rapidly evolving field of embodied AI systems. The incident underscores the growing cybersecurity challenges associated with integrating autonomous robots into critical workflows. As these systems become more prevalent, ensuring their security against unauthorized access and control is paramount to prevent potential operational disruptions and data breaches.
4 months ago
Kill Chain
Critical Security Update for ABB PCM600: Addressing CVE-2018-1002208
In November 2025, ABB disclosed a critical vulnerability (CVE-2018-1002208) in its Protection and Control IED Manager PCM600 software, versions 1.5 through 2.13. This flaw, stemming from the SharpZipLib component, allows attackers to execute arbitrary code by sending specially crafted messages to the system node. The vulnerability, known as 'Zip-Slip,' involves improper limitation of a pathname to a restricted directory, leading to path traversal issues. ABB has addressed this issue in PCM600 version 2.14 and recommends users update promptly. ([cyber.gc.ca](https://www.cyber.gc.ca/en/alerts-advisories/control-systems-abb-security-advisory-av25-719?utm_source=openai)) The disclosure underscores the persistent risks associated with third-party libraries in industrial control systems. Organizations must remain vigilant, ensuring timely updates and implementing robust security measures to protect critical infrastructure from evolving cyber threats.
4 months ago
Kill Chain
Critical Authentication Bypass Vulnerability in ABB Ability OPTIMAX (CVE-2025-14510)
In January 2026, ABB disclosed a critical vulnerability (CVE-2025-14510) in its Ability OPTIMAX software, widely used in industrial optimization. The flaw, stemming from an incorrect implementation of the authentication algorithm, affects versions 6.1, 6.2, 6.3.0 before 6.3.1-251120, and 6.4.0 before 6.4.1-251120. Exploitation could allow remote attackers to bypass authentication, potentially compromising confidentiality, integrity, and availability of industrial control systems. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2025-14510/?utm_source=openai)) This incident underscores the escalating risks in industrial control systems due to authentication vulnerabilities. With increasing integration of such systems into broader networks, the potential for unauthorized access and operational disruption grows, highlighting the need for robust security measures and timely patch management.
4 months ago
Kill Chain
Critical Vulnerability in ABB's IEC 61850 Communication Stack (CVE-2025-3756)
In April 2026, ABB disclosed a vulnerability (CVE-2025-3756) in the IEC 61850 communication stack used in its System 800xA and Symphony Plus products. An attacker with access to the IEC 61850 network could exploit this flaw by sending specially crafted packets, causing the PM 877, CI850, and CI868 modules to enter a fault state, or rendering the S+ Operations 61850 connectivity unavailable, leading to a denial-of-service condition. The overall functionality of the S+ Operations node remains unaffected; only the IEC 61850 communication function is impacted. Affected versions include AC800M (System 800xA) from 6.0.0x through 6.2.0006.0, Symphony Plus SD Series versions A_0 through B_0.005, Symphony Plus MR versions 3.10 through 3.52, and S+ Operations versions 2.1 through 3.3. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-3756?utm_source=openai)) This vulnerability underscores the critical importance of securing industrial control systems, especially those utilizing the IEC 61850 protocol. As cyber threats targeting operational technology environments continue to evolve, organizations must prioritize timely patching, network segmentation, and robust access controls to mitigate potential risks.
4 months ago
Kill Chain
Critical Vulnerability in ABB Ability Edgenius: Immediate Action Required
In November 2025, a critical authentication bypass vulnerability (CVE-2025-10571) was identified in ABB Ability Edgenius versions 3.2.0.0 and 3.2.1.1. This flaw allows unauthenticated attackers on adjacent networks to send specially crafted messages to the system node, enabling them to install and run arbitrary code, uninstall applications, and modify configurations of installed applications. The vulnerability has a CVSS v3.1 base score of 9.6, indicating its critical severity. ABB has released version 3.2.2.0 to address this issue and recommends immediate upgrading. ([library.e.abb.com](https://library.e.abb.com/public/6fed91aad9034910b99298c58e407979/7PAA022088_B_en_Edgenius%20Management%20Portal%20Authentication%20Bypass.pdf?x-sign=4U%2FLxIrP3%2FTAiNhR45U6GCkLpQhWbUhpnelc58Oz1NsjOPYafSbXv48t5cNUuiBc&utm_source=openai)) The discovery of this vulnerability underscores the increasing risks associated with edge computing platforms in industrial environments. As these systems often bridge IT and operational technology (OT) networks, their compromise can lead to significant operational disruptions and safety hazards. Organizations must prioritize securing such platforms to prevent unauthorized access and potential exploitation.
4 months ago
Kill Chain
Critical Security Vulnerabilities Discovered in ABB AWIN Gateways
In March 2026, ABB disclosed multiple vulnerabilities in its AWIN Gateways, specifically affecting firmware versions 2.0-0 and 2.0-1 on the GW100 rev.2, and versions 1.2-0 and 1.2-1 on the GW120. These vulnerabilities include authentication bypass by capture-replay (CVE-2025-13777), missing authentication for critical functions leading to remote device reboot (CVE-2025-13778), and unauthorized access to system configurations revealing sensitive details (CVE-2025-13779). Exploitation of these flaws could allow attackers to gain unauthorized access, disrupt device operations, and expose confidential information. ([library.e.abb.com](https://library.e.abb.com/public/3df44661342a482f9b39595fb1457446/4JNO000329_A_en%20Vulnerabilities%20in%20Embedded%20Webserver.pdf?x-sign=hpo%2FlHiVW9S%2FJFfI7on%2BhNiDyo6eVzQkPp6%2BJB4nbIGqiVRH4VpRTPwCRDjUFbLP&utm_source=openai)) The disclosure underscores the critical need for robust security measures in industrial control systems, as such vulnerabilities can have significant operational and safety implications. Organizations utilizing ABB AWIN Gateways should promptly apply the recommended firmware updates and review their network security protocols to mitigate potential risks.
4 months ago
Kill Chain
Critical Vulnerabilities in ABB Ability Symphony Plus Engineering: Immediate Action Required
In April 2026, ABB disclosed multiple vulnerabilities in its Ability Symphony Plus Engineering software, primarily due to outdated PostgreSQL components. These vulnerabilities, including CVE-2023-5869, CVE-2023-39417, CVE-2024-7348, and CVE-2024-0985, could allow attackers with network access to execute arbitrary code, potentially compromising entire systems. Affected versions range from 2.2 to 2.4 SP2. ABB has released updates to address these issues and recommends immediate application to mitigate risks. This incident underscores the critical importance of timely software updates and robust network security practices in industrial control systems. Organizations must remain vigilant against emerging threats targeting outdated components to ensure operational integrity and security.
4 months ago
Kill Chain
Unveiling Fast16: The Pre-Stuxnet Cyber Sabotage Tool
In 2005, a sophisticated malware named Fast16 was deployed, targeting high-precision engineering and simulation software such as LS-DYNA 970, PKPM, and MOHID. This malware subtly altered computational processes, leading to inaccurate results that could compromise infrastructure integrity, potentially causing engineering degradation or catastrophic failures. Fast16 propagated through networks by exploiting weak credentials on Windows 2000 and XP systems, and it was designed to evade major antivirus tools. Evidence suggests that Fast16 was state-sponsored, likely originating from the United States, and was used against Iran's nuclear program years before the discovery of Stuxnet. ([tomshardware.com](https://www.tomshardware.com/software/security-software/decades-old-pre-stuxnet-cyber-sabotage-tool-breaks-cover-nsa-listed-it-as-nothing-to-see-here-fast16-targeted-nuclear-reactors-dam-design-and-other-high-precision-civil-engineering-software-years-before-stuxnet-broke-cover?utm_source=openai)) The discovery of Fast16 highlights the long-standing use of cyber sabotage tools in geopolitical conflicts. Its existence underscores the need for robust cybersecurity measures to protect critical infrastructure from sophisticated, state-sponsored threats that can remain undetected for years.
4 months ago
Kill Chain
Lotus Wiper Attack Disrupts Venezuelan Energy Sector in 2025
In December 2025, Venezuela's state-owned oil company, Petróleos de Venezuela S.A. (PDVSA), experienced a significant cyberattack that disrupted its core administrative and operational systems. The attack, attributed to a previously unknown malware dubbed 'Lotus Wiper,' employed sophisticated living-off-the-land techniques to disable system defenses and systematically delete critical data, rendering systems unrecoverable. This incident led to the temporary suspension of oil cargo deliveries and forced PDVSA to rely on manual processes, highlighting vulnerabilities in the company's technological infrastructure. ([darkreading.com](https://www.darkreading.com/cyber-risk/lotus-wiper-attack-targeted-venezuelan-energy-firms-utilities?utm_source=openai)) The Lotus Wiper attack underscores the escalating use of destructive malware targeting critical infrastructure, particularly in the energy sector. The incident serves as a stark reminder of the need for robust cybersecurity measures and incident response strategies to protect against sophisticated cyber threats that can have severe operational and economic consequences.
4 months ago
Kill Chain
TGR-STA-1030's 2026 Cyber Espionage Surge in Central and South America
In early 2026, the state-aligned cyber espionage group TGR-STA-1030 intensified its operations, targeting government and critical infrastructure entities across Central and South America. Utilizing tactics such as phishing emails and exploiting known software vulnerabilities, the group infiltrated networks to exfiltrate sensitive data, including financial negotiations, contracts, and military operational updates. This campaign underscores the group's persistent and evolving threat to national security and key services in the region. The recent focus on Central and South America highlights a strategic shift in TGR-STA-1030's operations, emphasizing the need for heightened vigilance and robust cybersecurity measures among governmental and critical infrastructure organizations in these regions.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports