The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Oil/Energy/Solar/Greentech

Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.

464 threat reports
Page 2 of 39

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Oil/Energy/Solar/Greentech Threat Reports

Showing 13–24 / 464 reports
Critical Authentication Bypass in Mitsubishi Electric GX Works3 Exposes Industrial Control Systems
Impact· CRITICAL

Critical Authentication Bypass in Mitsubishi Electric GX Works3 Exposes Industrial Control Systems

In September 2026, CISA disclosed CVE-2026-15688, a critical authentication bypass vulnerability in Mitsubishi Electric's GX Works3 and Motion Control Settings software used in industrial control systems worldwide. The vulnerability, scored 8.8 (CVSS v3.1) and 9.2 (CVSS v4.0), allows local attackers to bypass block password authentication by modifying executable modules in memory, enabling unauthorized access to view, tamper with, destroy, or delete control programs in critical manufacturing environments. This incident highlights the growing threat landscape targeting industrial control systems as cyber adversaries increasingly focus on critical infrastructure. With ICS environments becoming more connected and the rise of sophisticated state-sponsored attacks on manufacturing facilities, authentication vulnerabilities in widely-deployed engineering software represent significant risks to operational technology security and industrial resilience.

6 days ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
NightEagle APT Deploys GhostContainer Backdoor in Russian Enterprise Attacks
Impact· CRITICAL

NightEagle APT Deploys GhostContainer Backdoor in Russian Enterprise Attacks

NightEagle (APT-Q-95), an advanced persistent threat group active since 2023, has expanded operations from Asia to target Russian enterprises in 2024. The group employs compromised VPN credentials for initial access, deploys the GhostContainer backdoor on Microsoft Exchange servers, and utilizes legitimate Microsoft dev tunnels combined with rdp2tcp for covert traffic redirection. Attackers leverage RDP lateral movement, exploit CVE-2019-0708 (BlueKeep), and conduct DCSync attacks to compromise Active Directory infrastructure. The sophisticated campaign demonstrates advanced evasion techniques including AMSI bypass and virtual channel manipulation. This incident highlights the growing trend of APT groups expanding geographic targets while incorporating legitimate cloud services for persistence and evasion. As threat actors increasingly abuse trusted platforms like Microsoft dev tunnels, organizations face heightened challenges in detecting malicious traffic among legitimate communications.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Multi-Vector Assault: How Three Threat Groups Coordinated Attacks on Russian Infrastructure
Impact· CRITICAL

Multi-Vector Assault: How Three Threat Groups Coordinated Attacks on Russian Infrastructure

Three distinct threat groups - NightEagle, Hacking Cat, and Toy Ghouls - launched coordinated attacks against Russian enterprises throughout 2026, deploying backdoors, ransomware, and wipers. NightEagle leveraged compromised VPN credentials and the GhostContainer backdoor to target Microsoft Exchange servers, while pro-Ukrainian group Hacking Cat deployed Gorilla RAT and multi-platform Monkey ransomware variants. Toy Ghouls evolved from using leaked ransomware builders to developing custom Bird Agent backdoors that communicate via unconventional channels like MQTT brokers and Matrix messaging. This campaign demonstrates the increasing sophistication of multi-vector attacks and the growing trend of hacktivist groups collaborating to share custom toolsets, representing a significant escalation in cyber warfare targeting critical infrastructure.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Coast Guard and FBI Investigate Maritime Cyberattacks on Foreign Tankers
Impact· MEDIUM

Coast Guard and FBI Investigate Maritime Cyberattacks on Foreign Tankers

In August 2024, the U.S. Coast Guard and FBI conducted joint offshore security boardings of two foreign commercial tankers in the Gulf of Mexico following cyberattacks that compromised their networks. The first vessel, carrying oil and natural gas, was hacked while transiting the Strait of Gibraltar and lost communications for over 30 hours. Authorities investigated potential Iranian involvement or threat actors exploiting U.S.-Iran tensions, as part of broader concerns about 'dark fleets' carrying sanctioned oil using digital masking techniques. This incident highlights the growing convergence of cybersecurity threats with critical infrastructure and supply chain security, particularly as nation-state actors increasingly target maritime operations to disrupt global commerce and energy transportation networks.

1 week ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
CenterPoint Energy Breach Exposes 7.49M Records Through Unsecured API
Impact· HIGH

CenterPoint Energy Breach Exposes 7.49M Records Through Unsecured API

CenterPoint Energy, a Houston-based utility serving 7 million customers across Texas, Indiana, Minnesota, and Ohio, confirmed a significant data breach in September 2026 after a threat actor using the alias '4d722e4d656f77' stole 7.49 million customer records. The attacker exploited an unsecured public API lacking rate limiting and web application firewall protection, iterating through millions of customer IDs to extract names, phone numbers, addresses, account numbers, billing amounts, and partial Social Security numbers. When the company failed to respond to the threat actor's initial contact, the stolen data was publicly leaked, prompting multiple class-action lawsuits and SEC disclosure. This incident highlights the critical vulnerability of inadequately secured public APIs in utility infrastructure, occurring amid increased scrutiny of energy sector cybersecurity following recent attacks on critical infrastructure. The breach demonstrates how basic API security misconfigurations can lead to massive data exposure, emphasizing the urgent need for proper rate limiting, authentication, and monitoring on all external-facing systems.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Siemens Reyrolle 7SR5 Vulnerabilities Threaten Power Grid Security
Impact· CRITICAL

Critical Siemens Reyrolle 7SR5 Vulnerabilities Threaten Power Grid Security

Siemens Reyrolle 7SR5 protection relay systems before version 2.70 are affected by 14 critical vulnerabilities, including authentication bypass, session hijacking, and buffer overflow conditions. These vulnerabilities in the Cesanta Mongoose Web Server component allow unauthenticated remote attackers to gain administrative access, execute arbitrary code, and cause denial-of-service conditions on critical power grid protection equipment deployed worldwide. The highest severity vulnerability (CVE-2026-62645) achieves a CVSS score of 9.8, enabling complete system compromise through predictable session identifiers and missing authentication controls. These vulnerabilities highlight the growing cybersecurity risks in operational technology (OT) environments, particularly as critical infrastructure becomes increasingly connected and exposed to network-based attacks targeting industrial control systems.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Hardcoded Key Vulnerabilities Expose Maritime Infrastructure in Wärtsilä FOS-Onboard Systems
Impact· HIGH

Critical Hardcoded Key Vulnerabilities Expose Maritime Infrastructure in Wärtsilä FOS-Onboard Systems

Critical vulnerabilities CVE-2026-78225 and CVE-2026-81855 were discovered in Wärtsilä FOS-Onboard version 5.07.0923.01, affecting maritime transportation systems worldwide. Both vulnerabilities involve hardcoded cryptographic keys - one in the deployer-ng Update Controller component and another in the robot testing framework component. With CVSS scores of 9.0 and 9.1 respectively, successful exploitation could allow attackers to deliver unauthorized updates, execute arbitrary code, or extract credentials to impersonate privileged clients. Wärtsilä has developed security patches and states the vulnerabilities are not exploitable when the product is installed according to recommendations. This incident highlights the growing threat to maritime critical infrastructure as operational technology systems become increasingly connected and targeted by sophisticated adversaries seeking to disrupt global supply chains.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical Vulnerability in Schneider Electric SCADAPack x70 Systems Exposes Industrial Infrastructure
Impact· MEDIUM

Critical Vulnerability in Schneider Electric SCADAPack x70 Systems Exposes Industrial Infrastructure

Schneider Electric disclosed a critical vulnerability (CVE-2026-81861) affecting all versions of its SCADAPack x70 Remote Terminal Units used in critical infrastructure worldwide. The insufficiently protected credentials vulnerability could allow unauthorized access to RTU configuration through the legacy Secure Lock functionality, potentially compromising confidentiality of industrial control systems. The vulnerability affects SCADAPack 47x, 47xi, 47xd, 470R, 57x, 3xx, and 32 products deployed globally in critical manufacturing and energy sectors. Industrial control system vulnerabilities continue to represent a significant threat vector as critical infrastructure increasingly becomes a target for nation-state actors and ransomware groups seeking to disrupt essential services and cause maximum societal impact.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical mySCADA Vulnerabilities Expose Global Industrial Control Systems to Attack
Impact· HIGH

Critical mySCADA Vulnerabilities Expose Global Industrial Control Systems to Attack

Critical vulnerabilities CVE-2026-73807 and CVE-2026-82567 were discovered in mySCADA myPRO Manager versions 2.1 and earlier, affecting industrial control systems worldwide. The first vulnerability (CVSS 9.8) allows unauthenticated attackers with network access to bypass authentication and access privileged management functions through the command API. The second vulnerability (CVSS 6.3) exposes an unauthenticated HTTP endpoint that enables attackers to send arbitrary SMS messages through connected GSM modems. These flaws impact critical infrastructure sectors including energy, manufacturing, transportation, and water systems globally. These vulnerabilities highlight the growing threat to industrial control systems as attackers increasingly target operational technology environments. With critical infrastructure under heightened scrutiny following recent nation-state campaigns, organizations must urgently address authentication gaps in SCADA systems that could enable devastating disruptions to essential services.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Red Heron's Rapid Gitea Exploitation Exposes Critical Zero Trust Gaps
Impact· CRITICAL

Red Heron's Rapid Gitea Exploitation Exposes Critical Zero Trust Gaps

In July 2026, the Chinese threat actor Red Heron rapidly weaponized CVE-2026-60004, a critical Gitea remote code execution vulnerability, to compromise 13 organizations across six countries including Canada, Taiwan, the U.S., Qatar, Argentina, and Sri Lanka. The campaign targeted defense, election, energy, aerospace, telecommunications, government, and research sectors, progressing from source code theft to persistent access through deployment of the JITTERLY backdoor and SIXZUT rootkit. Red Heron's automated exploitation framework enabled systematic credential collection, lateral movement, and root-level access to critical infrastructure including a three-node Proxmox cluster. This incident demonstrates the accelerating threat landscape where nation-state actors can transform public proof-of-concept exploits into sophisticated automated frameworks within days of vulnerability disclosure, highlighting the critical window between patch availability and mass exploitation.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical SAP Kernel Vulnerability Exposes Enterprise Systems to Complete Compromise
Impact· CRITICAL

Critical SAP Kernel Vulnerability Exposes Enterprise Systems to Complete Compromise

SAP released critical security updates in September 2026 addressing multiple vulnerabilities, including CVE-2026-44756, a maximum-severity CVSS 10.0 flaw in SAP Extended Passport Processing. Discovered by Onapsis and codenamed OVERPASS, this memory corruption vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands with SAP administrative privileges. The flaw affects SAP kernel code across multiple protocols including web, GUI, and RFC layers, making it reachable through internet-facing components without requiring credentials. Successful exploitation enables complete compromise of SAP business data, lateral movement to connected systems, and manipulation of critical application configurations. This incident highlights the growing threat landscape targeting enterprise resource planning systems as organizations increasingly digitize their core business processes. With SAP systems managing critical financial and operational data for thousands of enterprises globally, kernel-level vulnerabilities represent existential risks that bypass traditional authentication controls and demand immediate remediation efforts.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Buffer Overflow Vulnerability CVE-2026-78012 Threatens Industrial Control Systems
Impact· CRITICAL

Critical Buffer Overflow Vulnerability CVE-2026-78012 Threatens Industrial Control Systems

In September 2026, CISA disclosed CVE-2026-78012, a critical stack-based buffer overflow vulnerability in Pyramid Solutions NetStaX EtherNet/IP Stack affecting versions prior to 5.6.1. The vulnerability allows attackers to send large Class 3 explicit-message requests that exceed application-side receive buffers without generating error warnings, potentially leading to memory corruption, device crashes, or remote code execution. With a CVSS score of 9.8, this flaw impacts multiple industrial control systems across critical infrastructure sectors including manufacturing, energy, water treatment, and chemical facilities worldwide. The vulnerability represents a significant threat to operational technology environments where these industrial communication stacks are widely deployed. This incident highlights the growing cybersecurity risks facing industrial control systems as OT networks become increasingly connected and targeted by sophisticated threat actors, making secure industrial communication protocols and robust buffer management critical for protecting critical infrastructure.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports