The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Oil/Energy/Solar/Greentech

Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.

464 threat reports
Page 19 of 39

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Oil/Energy/Solar/Greentech Threat Reports

Showing 217–228 / 464 reports
Critical Vulnerability in Carlson VASCO-B GNSS Receiver (CVE-2026-3893)
Impact· HIGH

Critical Vulnerability in Carlson VASCO-B GNSS Receiver (CVE-2026-3893)

In April 2026, a critical vulnerability (CVE-2026-3893) was identified in Carlson Software's VASCO-B GNSS Receiver versions prior to 1.4.0. This flaw, due to missing authentication mechanisms, allows remote attackers to alter system configurations and disrupt device operations without requiring credentials. The vulnerability has a CVSS score of 9.4, indicating its severity, and primarily affects the Critical Manufacturing sector globally. ([socdefenders.ai](https://www.socdefenders.ai/item/3f9fa938-de90-494a-99b5-bc0ba05499a8?utm_source=openai)) The incident underscores the importance of securing GNSS receivers, which are integral to infrastructure operations. Organizations are advised to update to version 1.4.0 or later, minimize network exposure of control systems, implement firewalls, and use secure remote access methods like VPNs to mitigate potential risks. ([socdefenders.ai](https://www.socdefenders.ai/item/3f9fa938-de90-494a-99b5-bc0ba05499a8?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Unveiling 'fast16': The Pre-Stuxnet Malware Targeting Engineering Software
Impact· HIGH

Unveiling 'fast16': The Pre-Stuxnet Malware Targeting Engineering Software

In April 2026, SentinelOne researchers uncovered 'fast16,' a previously undocumented Lua-based malware framework dating back to 2005. This sophisticated tool targeted high-precision engineering and physics simulation software, subtly altering calculations to introduce systematic errors. Unlike typical malware of its era, fast16 was engineered for strategic sabotage, potentially undermining scientific research and engineering projects without immediate detection. The discovery of fast16 highlights the advanced capabilities of state-sponsored cyber operations predating known incidents like Stuxnet. It underscores the long-standing use of cyber tools for covert sabotage, emphasizing the need for vigilance in protecting critical infrastructure and sensitive research from such sophisticated threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Itron Reports Cybersecurity Breach in Internal Systems
Impact· LOW

Itron Reports Cybersecurity Breach in Internal Systems

In April 2026, Itron, Inc., a leading utility technology company, disclosed a cybersecurity incident where an unauthorized third party accessed certain internal systems. Upon detection on April 13, 2026, Itron activated its cybersecurity response plan, engaged external advisors, and notified law enforcement. The company successfully contained the unauthorized activity, with no observed follow-up incidents. Importantly, customer-hosted systems remained unaffected, and business operations continued without material disruption. Itron anticipates that a significant portion of the incident-related costs will be reimbursed by insurance. ([sec.gov](https://www.sec.gov/Archives/edgar/data/780571/000119312526175249/d125229d8k.htm?utm_source=openai)) This incident underscores the persistent threat of cyberattacks targeting critical infrastructure sectors. As utility companies increasingly digitize operations, they become more attractive targets for cyber adversaries. The swift response and containment by Itron highlight the importance of robust cybersecurity measures and incident response plans in mitigating potential impacts on essential services.

5 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Unveiling 'fast16': The Earliest Known Cyber Sabotage Tool
Impact· HIGH

Unveiling 'fast16': The Earliest Known Cyber Sabotage Tool

In April 2026, SentinelOne researchers uncovered 'fast16,' a previously undocumented malware framework dating back to 2005. This sophisticated tool was designed to subtly corrupt high-precision mathematical computations in engineering and scientific software by introducing near-imperceptible errors. The malware employed a 'cluster munition' delivery mechanism, deploying multiple 'wormlets' to propagate the main payload across target environments by exploiting vulnerabilities. This discovery predates the infamous Stuxnet by at least five years, marking 'fast16' as the earliest known cyber weapon aimed at sabotaging critical infrastructure through data integrity manipulation. The revelation of 'fast16' underscores the longstanding and evolving nature of state-sponsored cyber sabotage. It highlights the necessity for organizations, especially those handling sensitive and high-precision computations, to implement robust security measures and maintain vigilance against sophisticated threats that may have been active undetected for extended periods.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Northern Minerals Suffers Data Breach in 2024 BianLian Ransomware Attack
Impact· MEDIUM

Northern Minerals Suffers Data Breach in 2024 BianLian Ransomware Attack

In late March 2024, Australian rare earths mining company Northern Minerals experienced a cyberattack attributed to the BianLian ransomware group. The attackers exfiltrated corporate, operational, financial, and personal data, including information on current and former employees and shareholders. The stolen data was subsequently published on the dark web. Despite the breach, Northern Minerals reported no material impact on its operations or broader systems. The company promptly engaged legal, technical, and cybersecurity specialists, notified relevant authorities, and implemented measures to strengthen its systems. This incident underscores the evolving tactics of ransomware groups like BianLian, which have shifted from encrypting systems to focusing on data theft and extortion. Organizations, especially those in critical infrastructure sectors, must remain vigilant and enhance their cybersecurity defenses to mitigate such threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability in Siemens RUGGEDCOM CROSSBOW SAC: CVE-2025-6965
Impact· CRITICAL

Critical Vulnerability in Siemens RUGGEDCOM CROSSBOW SAC: CVE-2025-6965

In April 2026, Siemens disclosed a critical vulnerability (CVE-2025-6965) in its RUGGEDCOM CROSSBOW Station Access Controller (SAC) versions prior to V5.8. This flaw, stemming from a numeric truncation error in the integrated SQLite component, could allow remote attackers to execute arbitrary code or cause a denial-of-service condition. The vulnerability affects systems deployed worldwide in critical manufacturing sectors. Siemens has released version V5.8 to address this issue and strongly recommends users update to this latest version. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-994087.html?utm_source=openai)) This incident underscores the persistent risks associated with third-party software components in industrial control systems. As attackers increasingly target vulnerabilities in widely used libraries, organizations must prioritize timely updates and rigorous security assessments to safeguard critical infrastructure.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Authentication Bypass Vulnerability in Siemens SINEC NMS (CVE-2026-24032)
Impact· HIGH

Critical Authentication Bypass Vulnerability in Siemens SINEC NMS (CVE-2026-24032)

In April 2026, Siemens disclosed a critical authentication bypass vulnerability (CVE-2026-24032) in its SINEC NMS software, specifically within the User Management Component (UMC). This flaw allows unauthenticated remote attackers to bypass authentication mechanisms, potentially granting unauthorized access to network management functionalities. The vulnerability affects all versions of SINEC NMS prior to V4.0 SP3. Siemens has released an updated version to address this issue and strongly recommends users to upgrade promptly. This incident underscores the persistent risks associated with authentication weaknesses in critical infrastructure management systems. Organizations are urged to assess their network management tools for similar vulnerabilities and to implement robust access controls to mitigate potential exploitation.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities in Hardy Barth Salia EV Charge Controllers Expose Infrastructure Risks
Impact· HIGH

Critical Vulnerabilities in Hardy Barth Salia EV Charge Controllers Expose Infrastructure Risks

In April 2026, CISA disclosed two critical vulnerabilities in Hardy Barth's Salia EV Charge Controller firmware versions up to 2.3.81. Identified as CVE-2025-5873 and CVE-2025-10371, these flaws allow remote attackers to upload malicious files via the web interface, potentially leading to remote code execution. Despite public proof-of-concept exploits being available, Hardy Barth has not responded to coordination requests, leaving systems at risk. This incident underscores the growing cybersecurity challenges in the EV infrastructure sector. The lack of vendor response highlights the need for proactive security measures and vigilant monitoring to protect critical energy and transportation systems from emerging threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities Discovered in SenseLive X3050 Devices
Impact· HIGH

Critical Vulnerabilities Discovered in SenseLive X3050 Devices

In April 2026, multiple critical vulnerabilities were identified in the SenseLive X3050 device, version V1.523. These vulnerabilities include authentication bypass, insufficient session expiration, use of hard-coded credentials, and cleartext transmission of sensitive information. Exploitation of these flaws could allow attackers to gain complete control over the device, leading to unauthorized access and potential disruption of operations. The affected devices are widely deployed across critical infrastructure sectors such as manufacturing, water and wastewater, and energy. ([cyberpings.com](https://cyberpings.com/article/senselive-x3050-vulnerabilities-explained-mo8x?utm_source=openai)) The urgency of addressing these vulnerabilities is heightened by the lack of response from SenseLive to coordinate remediation efforts. Organizations utilizing the X3050 are advised to contact SenseLive directly for guidance and to implement immediate defensive measures to mitigate potential exploitation. ([cyberpings.com](https://cyberpings.com/article/senselive-x3050-vulnerabilities-explained-mo8x?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Lotus Wiper Malware Targets Venezuelan Energy Systems in Destructive Attack
Impact· HIGH

Lotus Wiper Malware Targets Venezuelan Energy Systems in Destructive Attack

In late 2025 and early 2026, a previously undocumented malware known as Lotus Wiper targeted Venezuela's energy and utilities sector. The attack began with batch scripts that disabled system defenses and disrupted operations, paving the way for the wiper to erase recovery mechanisms, overwrite physical drives, and systematically delete files, rendering systems inoperable. ([securelist.com](https://securelist.com/tr/lotus-wiper/119472/?utm_source=openai)) This incident underscores the escalating threat of destructive malware against critical infrastructure. The absence of ransom demands suggests a focus on disruption rather than financial gain, highlighting the need for robust cybersecurity measures in essential services. ([securityweek.com](https://www.securityweek.com/new-wiper-malware-targeted-venezuelan-energy-sector-prior-to-us-intervention/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Siemens TPM 2.0 Vulnerability (CVE-2025-2884) Disclosure
Impact· MEDIUM

Siemens TPM 2.0 Vulnerability (CVE-2025-2884) Disclosure

In April 2026, Siemens disclosed a vulnerability (CVE-2025-2884) in its TPM 2.0 implementation, affecting multiple products including SIMATIC and SIPLUS IPC series. The flaw, an out-of-bounds read in the CryptHmacSign function, could allow local attackers to access sensitive information or cause a denial of service. Siemens has released updates for several affected products and is preparing further fixes, recommending users to update to the latest versions. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-628843.html?utm_source=openai)) This incident underscores the critical importance of timely firmware updates and robust access controls, especially as TPM vulnerabilities can compromise foundational security features like encryption and secure boot processes.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in Siemens RUGGEDCOM SAM-P: Immediate Action Required
Impact· HIGH

Critical Vulnerability in Siemens RUGGEDCOM SAM-P: Immediate Action Required

In April 2026, a critical privilege escalation vulnerability (CVE-2026-27668) was identified in Siemens RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) versions prior to V5.8. This flaw allows authenticated User Administrators to modify their own group memberships, potentially granting themselves elevated access across device groups. Siemens has addressed this issue by releasing version V5.8 and recommends immediate updates to mitigate the risk. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-741509.html?utm_source=openai)) This incident underscores the importance of stringent access controls and regular software updates in industrial control systems. Organizations should review their administrative privileges and ensure that all systems are updated to prevent unauthorized access and maintain operational integrity.

5 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports