The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Oil/Energy/Solar/Greentech
Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.
Explore Other Sectors
Oil/Energy/Solar/Greentech Threat Reports
Critical VPN Vulnerability CVE-2026-75925 Exposes Infrastructure to Remote Code Execution
In August 2026, CISA disclosed CVE-2026-75925, a critical CRLF injection vulnerability in IXON VPN Client versions prior to 1.4.7 with a CVSS score of 9.6. The vulnerability allows remote attackers to execute commands with root or SYSTEM privileges by injecting malicious configuration directives through unvalidated line-ending sequences. The flaw stems from improper neutralization of CRLF sequences in configuration values written to files consumed by privileged subprocesses, combined with lack of authentication for configuration changes. IXON responded by automatically rejecting connections from vulnerable client versions and releasing patches, preventing exploitation on unpatched systems that cannot establish VPN connections. This incident highlights the growing sophistication of infrastructure-targeted attacks and the critical importance of secure coding practices in VPN solutions that organizations rely on for remote access security.
2 weeks ago
Kill Chain
Critical Vulnerabilities Expose Rockwell Automation Industrial Control Systems to Remote Attacks
CISA disclosed two critical vulnerabilities (CVE-2026-19471, CVE-2026-19472) affecting Rockwell Automation's ArmorStart LT motor protection devices version 2.001 and earlier. CVE-2026-19471 involves stored cross-site scripting (XSS) vulnerabilities that allow attackers to inject malicious scripts executed when users access affected web pages. CVE-2026-19472 is a denial-of-service vulnerability triggered by crafted HTTP PUT requests that can disable the embedded web server. Both vulnerabilities require no authentication and can be exploited remotely, potentially compromising industrial control systems used in critical manufacturing worldwide. These vulnerabilities highlight the growing attack surface of industrial IoT devices and the critical need for secure-by-design principles in operational technology environments, especially as industrial systems become increasingly connected to enterprise networks.
2 weeks ago
Kill Chain
Critical OT Vulnerability Exposes Industrial Control Systems to Code Execution Attacks
Rockwell Automation's ControlFLASH software versions 15.07 and earlier contain a critical vulnerability (CVE-2026-12663) that grants write permissions to the 'Everyone' group on installation directories. This security flaw allows attackers to execute arbitrary code at the logged-in user's permission level, potentially compromising industrial control systems across critical infrastructure sectors including manufacturing, energy, and water systems. The vulnerability stems from missing authentication for critical functions and affects installations worldwide. Rockwell has released version 15.08 to address this issue and provided manual mitigation steps for systems that cannot immediately upgrade. This incident highlights the growing cybersecurity risks facing operational technology (OT) environments as industrial systems become increasingly connected and targeted by threat actors seeking to disrupt critical infrastructure operations.
2 weeks ago
Kill Chain
Critical Vulnerabilities in Tycon Systems Industrial Monitoring Devices Threaten Infrastructure Security
In September 2026, CISA disclosed three critical vulnerabilities (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684) affecting Tycon Systems TPDIN-Monitor-WEB3 industrial control system devices version 2.2.9 and prior. These vulnerabilities include hard-coded credentials, cross-site request forgery, and missing authorization controls that could enable attackers to perform man-in-the-middle attacks, extract system credentials, cause factory resets, or retrieve sensitive operational data from critical infrastructure systems deployed worldwide in energy and manufacturing sectors. These vulnerabilities highlight the ongoing security challenges in operational technology environments where legacy authentication models and insufficient access controls create attack vectors that could disrupt critical infrastructure operations and expose sensitive industrial data.
2 weeks ago
Kill Chain
Critical Configuration Flaw Exposed in Inductive Automation Ignition SCADA Platform
In September 2026, CISA disclosed CVE-2026-77393 affecting Inductive Automation's Ignition SCADA platform versions 8.1.53 and earlier. The vulnerability stems from incorrect default permissions where the Gateway's 'Create Project Role(s)' setting shipped blank, allowing any authenticated user to create projects if they could execute gateway scripts. This configuration flaw exposed industrial control systems to potential unauthorized project creation and manipulation. Inductive Automation addressed the issue in version 8.1.54 by restricting project creation to Designer sessions and eliminating reliance on the problematic setting. This incident highlights the growing security challenges facing industrial control systems as they become increasingly connected and targeted by threat actors. With critical infrastructure under constant threat and new regulations emphasizing OT security, even seemingly minor configuration vulnerabilities can create significant exposure points for manufacturing and energy sector organizations.
2 weeks ago
Kill Chain
CVE-2026-77477 Exposes Critical Privilege Escalation Risk in OPC UA Infrastructure
CVE-2026-77477 affects OPCFoundation OPC UA LocalDiscoveryServer (LDS) installations prior to version 1.04.420, allowing attackers to intercept high-privilege console windows during installation. The vulnerability enables execution of arbitrary commands with elevated privileges when an attacker has physical or remote desktop access during the installation process. This impacts critical infrastructure sectors including chemical, energy, food and agriculture, and manufacturing worldwide, with a CVSS score of 4.6 (Medium severity). This vulnerability highlights the growing security challenges in industrial control systems and OT environments, where installation-time privilege escalation can provide attackers with persistent access to critical infrastructure components.
2 weeks ago
Kill Chain
CVE-2025-10478: Rockwell Automation ICS Module Vulnerability Threatens Critical Infrastructure
A critical denial-of-service vulnerability (CVE-2025-10478) has been discovered in Rockwell Automation's 1756-ENBT ControlLogix EtherNet/IP bridge modules, affecting all versions deployed across critical infrastructure sectors worldwide. Attackers can exploit this flaw by sending crafted CIP packets to crash the module, requiring a manual restart to restore operations. The vulnerability impacts manufacturing, food and agriculture, transportation, and water treatment facilities that rely on these industrial control systems for operational continuity. This incident highlights the growing threat landscape targeting industrial control systems as critical infrastructure becomes increasingly digitized and interconnected. The vulnerability demonstrates how network-accessible ICS components remain vulnerable to simple but effective attacks that can disrupt essential services.
2 weeks ago
Kill Chain
How Unpatched ownCloud Flaws Led to Philippines Nuclear Agency Espionage
In September 2026, threat actors exploited unpatched vulnerabilities in ownCloud (CVE-2023-49105) and LiteSpeed Cache WordPress plugin (CVE-2024-2800) to breach a Philippine nuclear agency and naval contractor. The attackers, likely Chinese-speaking based on code comments, exfiltrated 9GB of sensitive data including reactor databases, fuel inventories, radiation safety documents, personnel records, and credential stores. Hunt.io researchers discovered the stolen data on an Amsterdam-based server serving as an operational hub for the attackers. This incident reflects escalating cyber threats in the Philippines amid South China Sea tensions, with breach incidents nearly tripling in the first half of 2026. The successful exploitation of vulnerabilities patched over two years ago highlights critical gaps in patch management and security fundamentals at sensitive government facilities.
3 weeks ago
Kill Chain
Inside the Sality Botnet Takedown: How Authorities Turned P2P Architecture Against Itself
In August 2026, the U.S. Department of Justice led a coordinated international operation to disrupt the Sality botnet, a peer-to-peer malware network operating since 2003. Law enforcement from the U.S., Bulgaria, Hungary, and Romania, working with CrowdStrike and Shadowserver Foundation, executed a sophisticated sinkhole operation that turned Sality's decentralized architecture against itself. The botnet, operated by the Russian threat group Salty Spider from Bashkortostan, had infected over 15,000 machines worldwide and generated at least $150,000 through cryptocurrency theft via clipboard hijacking malware. The operation demonstrates evolving law enforcement capabilities against resilient P2P botnets that traditionally evade conventional takedown methods. This disruption highlights the increasing sophistication of international cybercrime enforcement and the vulnerability of even decentralized criminal infrastructure to coordinated technical and legal action, particularly relevant as threat actors increasingly adopt P2P architectures to avoid single points of failure.
3 weeks ago
Kill Chain
AI Weaponizes PLC Exploits: How Claude Ported Critical Infrastructure Attacks
In September 2026, Forescout's Vedere Labs demonstrated how Anthropic's Claude AI successfully ported a pre-authentication remote code execution exploit targeting CVE-2021-31886 from one WAGO programmable logic controller model to another. The research consumed $535.74 in API costs over 8.5 hours to adapt an existing 750-852 exploit for the 750-831 controller, exploiting a stack-based buffer overflow in the Nucleus FTP server with a CVSS score of 9.8. The AI-assisted exploit development achieved code execution by sending network packets, though a subsequent attempt to create a command-and-control implant permanently bricked the target PLC by writing to flash memory. This research highlights the evolving threat landscape where AI tools are lowering the technical barriers for developing industrial control system exploits, coinciding with recent warnings from NSA, CISA, and FBI about AI-generated scripts targeting Siemens PLCs and ongoing attacks against water utility infrastructure.
3 weeks ago
Kill Chain
Russian APT UAC-0099 Exploits AI Security Tools with GuardBreaker Prompt Injection
In September 2026, ESET researchers disclosed a new technique called GuardBreaker employed by Russia-aligned threat actor UAC-0099 against Ukrainian targets. The attack involved embedding provocative text about nuclear weapons creation into malicious VBS scripts to deliberately trigger AI safety mechanisms and prevent automated analysis. The technique aims to force large language models into refusal states, allowing malware like the MATCHBOIL loader to evade AI-assisted security workflows. This represents a sophisticated evolution in adversarial prompt injection, specifically designed to exploit the safety guardrails of modern AI security tools. This incident highlights the growing threat of AI-targeted evasion techniques as organizations increasingly rely on automated security analysis. With AI copilots and LLM-based scanners becoming standard in security operations, attackers are developing specific countermeasures to blind these systems, creating new vulnerabilities in modern defense strategies.
3 weeks ago
Kill Chain
Critical Privilege Escalation Flaw Exposes Industrial Control Systems to Complete Compromise
A critical privilege escalation vulnerability (CVE-2026-16675) was discovered in Rockwell Automation's FactoryTalk Activation Manager V5.02 and below, affecting industrial control systems worldwide. The vulnerability allows authenticated attackers to hijack console windows during installation or repair operations, escalating from standard user privileges to SYSTEM-level access with complete control over affected systems. This poses significant risks to critical manufacturing infrastructure, as attackers can access all files, processes, and system resources once exploited. This vulnerability highlights the ongoing security challenges facing industrial control systems as manufacturing environments become increasingly digitized and interconnected, making them attractive targets for cybercriminals and nation-state actors seeking to disrupt critical infrastructure operations.
3 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports