The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Oil/Energy/Solar/Greentech
Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.
Explore Other Sectors
Oil/Energy/Solar/Greentech Threat Reports
Critical Privilege Escalation Vulnerabilities Discovered in Rockwell Automation Industrial Systems
In September 2026, CISA disclosed two critical privilege escalation vulnerabilities (CVE-2026-9633 and CVE-2026-9634) in Rockwell Automation's Redundancy Module Configuration Tool affecting versions 9.00.00 through 10.00.00. The vulnerabilities stem from incorrect default permissions that allow the tool's executables to search for required DLLs in directories writable by standard users. If exploited, local attackers can place malicious DLLs in these directories, which are then loaded with Administrator/SYSTEM privileges when the tool is run by an administrator. Rockwell Automation has released version 10.01.00 to address these issues, affecting critical manufacturing infrastructure worldwide. This incident highlights the persistent threat of DLL hijacking attacks in industrial control systems, particularly as organizations modernize their operational technology environments. With increasing convergence of IT and OT networks, such privilege escalation vulnerabilities pose significant risks to critical infrastructure security and operational continuity.
3 weeks ago
Kill Chain
Critical DoS Vulnerability Exposes Rockwell Automation Industrial Controllers to Remote Attack
A critical denial-of-service vulnerability (CVE-2026-9637) affects multiple Rockwell Automation Logix Platform controllers including ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380 systems. The vulnerability stems from improper validation of input length during Common Industrial Protocol (CIP) message processing, allowing remote attackers to trigger a major nonrecoverable fault (MNRF) that requires a complete power cycle to restore operations. Affected versions span firmware releases up to V33 and specific ranges in V34-V36 branches, impacting critical manufacturing infrastructure worldwide. This vulnerability highlights the ongoing targeting of industrial control systems and the critical need for robust OT security measures. As industrial networks become increasingly connected and Nation-state actors continue to probe critical infrastructure, vulnerabilities in widely-deployed platforms like Rockwell's Logix controllers represent significant national security and operational continuity risks that require immediate attention.
3 weeks ago
Kill Chain
Critical Denial of Service Vulnerability Exposes Rockwell Automation Industrial Controllers
Rockwell Automation disclosed CVE-2021-42260, a high-severity denial of service vulnerability affecting ControlLogix, CompactLogix, GuardLogix, and Compact GuardLogix controllers. The vulnerability, with a CVSS score of 7.5, allows attackers to trigger an infinite loop condition through corrupt crafted data, causing major nonrecoverable faults (MNRF) in safety controllers and requiring program downloads for recovery. The flaw impacts multiple firmware versions across the 34.x, 35.x, 36.x, and 37.x series, affecting critical manufacturing infrastructure deployed worldwide. This vulnerability highlights the ongoing risks to operational technology environments where denial of service attacks can cause significant operational disruption. As industrial control systems become increasingly connected and targeted by threat actors, vulnerabilities like CVE-2021-42260 demonstrate the critical need for robust OT security measures and timely patch management in manufacturing environments.
3 weeks ago
Kill Chain
Critical DOS Vulnerabilities Threaten Rockwell Automation RSLinx Classic Industrial Systems
Four critical denial-of-service vulnerabilities (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) were discovered in Rockwell Automation's RSLinx Classic versions 4.50 and earlier. These vulnerabilities allow attackers to crash the RSLinx Classic service by sending specially crafted CIP packets, exploiting integer overflow, integer underflow, and buffer overflow conditions. The vulnerabilities affect critical manufacturing infrastructure worldwide and require service restarts to recover, potentially disrupting industrial operations and production systems. These vulnerabilities highlight the growing threat landscape facing industrial control systems as cybercriminals increasingly target critical infrastructure. With the rise of nation-state actors and ransomware groups focusing on OT environments, securing industrial communication protocols like CIP has become paramount for operational resilience.
3 weeks ago
Kill Chain
ownCloud Vulnerability CVE-2023-49105 Exploited in Philippine Nuclear Espionage Campaign
In August 2026, a Chinese-speaking threat actor exploited CVE-2023-49105, a critical ownCloud WebDAV authentication bypass vulnerability, to steal sensitive nuclear research data from a Philippine research body. The attacker used custom Python scripts to exploit the flaw's pre-signed URL mechanism, downloading 176 files totaling 372 MB including nuclear material records, strategic plans, reactor components, and employee data. The incident also involved a parallel attack on a Philippine marine engineering company serving the Navy, exploiting CVE-2024-28000 in WordPress LiteSpeed Cache plugin, highlighting coordinated cyber espionage targeting Philippine defense and nuclear sectors. This incident underscores the escalating cyber threats targeting critical infrastructure in the Asia-Pacific region amid South China Sea tensions, with state-affiliated actors increasingly focusing on nuclear and defense-related intelligence gathering through unpatched cloud collaboration platforms.
3 weeks ago
Kill Chain
ZBT Router Backdoors: How Chinese Manufacturer Compromised Global Networks
In August 2026, security researchers discovered that Shenzhen Zhibotong Electronics Co. Ltd. (ZBT), a major Chinese router manufacturer, had embedded multiple backdoors in firmware across millions of white-label routers sold globally. The backdoors, dubbed 'EndlessDoors,' 'SpeakingStone,' and 'DarkLantern,' provided root-level access and command-and-control capabilities to attackers. With ZBT producing 3.57 million units annually and exporting to over 50 countries including the US, Canada, Germany, and Australia, the supply chain compromise potentially affected hundreds of thousands of edge devices in critical infrastructure, corporate networks, and remote installations like oil pipelines. This incident exemplifies the growing threat of nation-state supply chain attacks targeting network infrastructure, particularly as organizations increasingly deploy edge devices with cellular connectivity in remote locations that are difficult to monitor and update.
3 weeks ago
Kill Chain
Critical Vulnerabilities Expose All-Line Equipment Fuel-Boss Industrial Control Systems to Remote Attacks
All-Line Equipment Company's Fuel-Boss industrial control systems across multiple variants (Standard, Portal, Master/Slave, and Backflush Systems) contain critical vulnerabilities CVE-2018-19518 and CVE-2019-11043 affecting PHP 7.1.5 implementations. These vulnerabilities enable remote code execution through argument injection and buffer overflow attacks, with CVSS scores reaching 8.7-9.4. The systems are deployed worldwide across critical infrastructure sectors including manufacturing, defense, emergency services, and transportation. While fixes are available for Standard and Portal variants, Master/Slave systems remain unpatched and Backflush Systems will not receive updates, leaving significant exposure in operational technology environments. This incident highlights the growing convergence of IT and OT security risks as legacy industrial systems with outdated software components become increasingly connected to enterprise networks and the internet, creating new attack vectors for threat actors targeting critical infrastructure.
3 weeks ago
Kill Chain
Critical ASE2000 Vulnerabilities Expose Industrial Control Systems to XXE and TLS Bypass Attacks
Applied Systems Engineering's ASE2000 V2 Communications Test Set, used in critical infrastructure sectors including energy and manufacturing, contains two critical vulnerabilities affecting versions 2.25 through 2.37. CVE-2018-1285 involves XML External Entity (XXE) attacks through vulnerable Apache log4net configurations, while CVE-2026-18717 enables TLS certificate validation bypass. These vulnerabilities could allow attackers to read or write arbitrary files, intercept encrypted communications, and potentially compromise industrial control systems used worldwide. These vulnerabilities highlight the persistent challenge of securing industrial control systems, particularly as critical infrastructure faces increasing cyber threats and nation-state targeting, making immediate patching and network segmentation essential for operational security.
3 weeks ago
Kill Chain
Critical Flaws in Ebyte Industrial Gateways Expose Global Infrastructure to Remote Attacks
In August 2026, CISA disclosed thirteen critical vulnerabilities in the Ebyte NA111-M industrial control system device, a Chinese-manufactured gateway used worldwide in critical infrastructure. The vulnerabilities include missing authentication, cleartext transmission of sensitive data, client-side authentication bypass, and weak cryptographic implementations. With CVSS scores up to 9.8, these flaws allow complete device compromise through remote exploitation, enabling attackers to access sensitive configurations, modify device settings, intercept MQTT credentials, and disrupt industrial operations. This disclosure highlights the persistent challenge of securing legacy industrial control systems that lack fundamental security controls, as nation-state actors and cybercriminals increasingly target critical infrastructure through vulnerable ICS devices for espionage and operational disruption.
3 weeks ago
Kill Chain
Industrial Automation Under Siege: Q2 2026 Threat Landscape Analysis
In Q2 2026, Kaspersky's industrial threat landscape report revealed a significant shift in cybersecurity threats targeting industrial control systems (ICS), with malicious objects blocked on 19.15% of ICS computers—the lowest level since 2022. The report identified 10,904 different malware families affecting industrial automation systems, with malicious scripts and phishing pages leading threat categories at 5.42% globally. Notable regional variations emerged, with Africa showing the highest attack rates at 27.9% while Northern Europe recorded the lowest at 8.1%. The biometrics sector faced the most severe threats at 26.44%, experiencing increases across multiple threat vectors including ransomware, spyware, and malicious documents. This trend reflects the evolving sophistication of threat actors targeting critical infrastructure, coinciding with increased adoption of cloud-native industrial systems and the expansion of attack surfaces through IoT integration. The data highlights growing concerns around industrial cybersecurity as nation-state actors and cybercriminal groups increasingly focus on operational technology environments.
4 weeks ago
Kill Chain
CVE-2025-3511 Exposes Critical Flaws in Industrial Network Security
In May 2025, CISA disclosed CVE-2025-3511, a critical denial-of-service vulnerability affecting over 45 Mitsubishi Electric factory automation (FA) products including CC-Link IE TSN modules, MELSEC iQ-R/iQ-F series controllers, and Ethernet interface modules. The vulnerability stems from improper validation of UDP packet quantities, allowing remote attackers to send specially crafted UDP packets that cause system crashes, communication delays, or timeout errors requiring manual system resets for recovery. This vulnerability highlights the growing threat surface in industrial control systems as manufacturers increasingly adopt networked automation technologies. With a CVSS score of 7.5, the flaw demonstrates how input validation failures in industrial protocols can create significant operational disruptions in critical manufacturing environments.
4 weeks ago
Kill Chain
Critical Vulnerabilities in Ebyte Industrial IoT Gateways Expose Manufacturing and Energy Infrastructure
The Ebyte NE2-D11 industrial IoT gateway contains 12 critical and high-severity vulnerabilities (ICSA-26-237-06) that enable complete device compromise through multiple attack vectors. These flaws include missing authentication for critical functions, cleartext transmission of sensitive data, client-side authentication bypass, CSRF attacks, and insufficient credential protection. The vulnerabilities affect firmware version FW-9167-0-11 deployed worldwide in critical manufacturing and energy sectors, allowing remote attackers to gain administrative access, intercept communications, modify configurations, and disrupt operations without authentication. This advisory highlights the persistent security challenges in industrial IoT devices as critical infrastructure increasingly relies on connected systems. With Ebyte's limited response to coordination efforts and no confirmed patch timeline, organizations face immediate risks from devices that lack basic security controls essential for industrial environments.
4 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports