The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Oil/Energy/Solar/Greentech
Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.
Explore Other Sectors
Oil/Energy/Solar/Greentech Threat Reports
Critical Siemens SIMATIC IoT2050 Vulnerability Exposes Industrial Systems to Remote Takeover
In August 2026, CISA disclosed a critical vulnerability (CVE-2026-58115) in Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed. The vulnerability stems from missing authentication on the Node-RED HTTP interface, allowing unauthenticated remote attackers to create malicious flows and execute arbitrary code with maximum privileges. With a CVSS score of 10.0, this vulnerability affects industrial control systems deployed globally across chemical, manufacturing, energy, and transportation sectors. Siemens has released version 4.3.4.1 to address the issue and strongly recommends immediate updates. This disclosure highlights the growing security risks in Industrial IoT environments as operational technology increasingly integrates with network-accessible programming interfaces. The vulnerability represents a broader trend of critical authentication bypasses in industrial control systems that could enable devastating attacks on critical infrastructure.
4 weeks ago
Kill Chain
Iranian Mabna Institute Hackers Sanctioned for Critical Infrastructure Breaches
In August 2026, the U.S. Treasury sanctioned five Iranian cyber actors affiliated with the Tehran-based Mabna Institute and Iran's Ministry of Intelligence and Security (MOIS) for conducting extensive compromises of U.S. critical infrastructure entities since late 2023. The threat actors successfully breached and exfiltrated data from energy companies, defense contractors, healthcare institutions, IT companies, and financial institutions, while also targeting local, state, and federal government offices in summer 2024. The group demonstrated dual motivations of state espionage and personal financial gain, with blockchain analysis revealing $16.8 million in cryptocurrency transactions across 30 wallets. This incident highlights the escalating cyber warfare between Iran and the U.S. following military strikes in February 2026, with Iranian threat actors increasingly targeting critical infrastructure as a form of asymmetric warfare. The emergence of coordinated hacktivist ecosystems and the blending of state-sponsored espionage with financially motivated cybercrime represents a significant evolution in nation-state threat actor behavior.
1 month ago
Kill Chain
U.S. Treasury Launches 'Economic D-Day' Against Iranian Cyber Operations Targeting Critical Infrastructure
In January 2025, the U.S. Treasury Department sanctioned four Iranian hackers as part of an 'economic D-Day' campaign against Iran's cyber operations. The sanctioned individuals - Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda'i, and Mojtaba Ghal'eh-Kuhi - conducted sophisticated attacks against U.S. critical infrastructure since late 2023, successfully compromising and exfiltrating data from energy companies, defense contractors, healthcare institutions, IT companies, and financial institutions. These attacks were directed by Iran's Ministry of Intelligence and Security (MOIS), with hackers motivated by both state objectives and personal financial gain, leading some to also target Iranian domestic companies. This incident highlights the escalating cyber warfare between nation-states and the U.S. government's increasingly aggressive economic response to state-sponsored cyberthreats. The sanctions represent a significant shift toward treating cyber operations as acts of war requiring comprehensive economic retaliation rather than just cybersecurity countermeasures.
1 month ago
Kill Chain
AI-Powered Cyber Attacks Target Critical Infrastructure PLCs
In August 2026, U.S. government agencies warned of active threat actors using AI to generate exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) across critical infrastructure sectors including water, energy, and manufacturing. Attackers leverage legitimate scanning services like Censys and ZoomEye to identify vulnerable PLCs, then deploy AI-generated scripts masquerading as monitoring tools to find exploits. The threat actors are systematically testing exploitation techniques against specific PLC models and using read access to understand target environments in preparation for future write operations that could cause operational disruption, safety incidents, equipment damage, and compliance violations. This incident marks a significant escalation in AI-enabled cyber threats against operational technology, demonstrating how artificial intelligence is lowering the barrier for sophisticated industrial control system attacks and compressing the timeline from vulnerability discovery to weaponization.
1 month ago
Kill Chain
Critical TSN Protocol Flaws Expose Industrial Control Systems to Manipulation
In August 2026, cybersecurity researchers from Nozomi Networks disclosed critical vulnerabilities in Time-Sensitive Networking (TSN) protocols, specifically targeting Mitsubishi Electric's CC-Link IE TSN implementation. The research demonstrated how attackers could exploit Layer 2 security weaknesses and TSN switch management interface flaws to inject malicious traffic into industrial control systems. Successful exploitation allows complete manipulation of operational technology processes, including starting and stopping robotic arms, tampering with synchronization clocks, and disrupting safety-critical communications in manufacturing environments. This research highlights the growing security challenges as industrial automation increasingly adopts TSN protocols for deterministic communication. With nation-state actors targeting critical infrastructure and the convergence of IT and OT networks accelerating, these vulnerabilities expose fundamental weaknesses in emerging industrial protocols that prioritize availability over security.
1 month ago
Kill Chain
TrueConf Server Supply Chain Attack: How Head Mare Exploited Critical CVE-2026-72529 Vulnerability
In August 2026, CISA ordered federal agencies to patch two critical TrueConf Server vulnerabilities (CVE-2026-72529 and CVE-2026-72530) within two weeks after adding them to the Known Exploited Vulnerabilities catalog. The flaws allow unauthenticated remote code execution and sandbox escape attacks on the self-hosted communications platform. The Head Mare hacktivist group has been actively exploiting these vulnerabilities since July 2026 to replace legitimate client installers with backdoor-laden versions, targeting Russian organizations across transportation, energy, and IT sectors. This incident follows previous TrueConf compromises, including Operation True Chaos linked to Chinese threat actors in April 2026. This attack highlights the growing trend of supply chain compromises targeting enterprise communication platforms, particularly as organizations increasingly rely on self-hosted solutions for secure corporate messaging and video conferencing amid rising cybersecurity concerns about cloud-based alternatives.
1 month ago
Kill Chain
AI-Powered Cyber Attacks Target Critical Infrastructure: The New Age of Autonomous Threats
In August 2026, the U.S. government warned of an active threat targeting critical infrastructure organizations using AI-generated exploit scripts against Siemens S7 Series Programmable Logic Controllers (PLCs). The attackers leveraged internet scanning services like Censys and ZoomEye to identify exposed PLCs running outdated software, then deployed custom Python scripts incorporating open-source automation libraries to gain unauthorized access to industrial control systems across Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities sectors. Concurrently, a separate multi-agent autonomous AI attack framework targeted Taiwan government entities in July 2026, demonstrating the evolution of AI-powered cyber operations. The Taiwan incident involved eight parallel AI sub-agents that performed reconnaissance, credential cracking, and data exfiltration, successfully compromising over 2,564 personnel records and establishing persistent backdoors across government infrastructure. These incidents mark a significant evolution in offensive capabilities, with AI assistance lowering technical barriers for Industrial Control System attacks and dramatically reducing the cost and expertise required for sophisticated cyber operations.
1 month ago
Kill Chain
How Pakistan's Transparent Tribe Exploited Cybersecurity Gaps in Afghan Infrastructure
Pakistan's Transparent Tribe (APT36) conducted an active cyber espionage campaign against Afghan government and telecommunications organizations from December 2025 through August 2026, deploying new malware variants including Patchcord and Sheetcord backdoors. The threat actor successfully compromised an Afghan Telecom IT officer and an international company's Afghan subsidiary, stealing sensitive data and WhatsApp communications for further social engineering attacks. While attacks against Indian government agencies including the Ministries of Defense and Foreign Affairs were attempted, these were unsuccessful due to India's superior cybersecurity defenses and proactive blocking by CERT-In. This incident highlights the growing sophistication of regional APT groups targeting countries with immature cybersecurity infrastructures, particularly in the context of heightened geopolitical tensions in South Asia and the Taliban's governance challenges in Afghanistan.
1 month ago
Kill Chain
Critical Vulnerability in Siemens Simcenter Nastran: CVE-2026-59086
In August 2026, Siemens disclosed a critical stack overflow vulnerability (CVE-2026-59086) in Simcenter Nastran versions prior to V2606. This flaw allows attackers to execute arbitrary code by exploiting the application's argument parsing mechanism. If a user is tricked into running the affected application with a malicious string, the vulnerability can be leveraged to perform remote code execution within the current process context. Siemens has released updated versions to address this issue and recommends users upgrade to V2606 or later. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-965753.html?utm_source=openai)) This incident underscores the persistent risk of stack overflow vulnerabilities in critical engineering software, highlighting the importance of timely software updates and vigilant security practices to prevent potential exploitation.
1 month ago
Kill Chain
Critical Vulnerabilities in Siemens S7 PLCs Discovered in 2026
In 2026, Siemens SIMATIC S7 Series PLCs were found to have multiple critical vulnerabilities, including cross-site scripting (XSS) flaws in their web servers and denial-of-service (DoS) issues in the S7-PLCSIM Advanced software. These vulnerabilities could allow attackers to execute arbitrary code or disrupt industrial processes. Siemens has released updates and advisories to address these issues, urging users to apply patches and implement recommended mitigations promptly. The discovery of these vulnerabilities underscores the ongoing risks to industrial control systems, especially as threat actors increasingly target critical infrastructure. Organizations must remain vigilant, regularly update their systems, and adhere to cybersecurity best practices to protect against potential exploits.
1 month ago
Kill Chain
Clop's Exploitation of PTC Windchill and FlexPLM Zero-Day Vulnerability in 2026
In June 2026, the Clop ransomware group exploited a zero-day vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM software, leading to unauthorized access and data theft from numerous organizations. The vulnerability, stemming from improper input validation and insecure deserialization, allowed unauthenticated remote code execution. PTC released patches on June 17, 2026, but exploitation had already commenced earlier that month. The Cybersecurity and Infrastructure Security Agency (CISA) added this flaw to its Known Exploited Vulnerabilities catalog on June 25, 2026. This incident underscores the critical importance of timely patch management and the need for robust security measures to protect against sophisticated threat actors like Clop. Organizations are urged to apply patches promptly and enhance monitoring to detect and mitigate such exploits.
1 month ago
Kill Chain
Critical Exploits Target MLflow and FUXA Vulnerabilities in August 2026
In August 2026, two critical vulnerabilities were actively exploited: CVE-2026-64849 in MLflow and CVE-2026-25895 in FUXA. The MLflow vulnerability allowed unauthenticated attackers to perform Server-Side Request Forgery (SSRF) attacks, enabling access to internal cloud metadata endpoints and extraction of sensitive data. The FUXA vulnerability permitted unauthenticated remote attackers to write arbitrary files to the server filesystem, potentially leading to remote code execution. Both vulnerabilities were promptly patched in subsequent software releases. The exploitation of these vulnerabilities underscores the persistent targeting of open-source platforms by threat actors. Organizations are urged to prioritize timely patching, conduct thorough audits for signs of compromise, and implement robust security measures to protect against similar threats.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports