The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Oil/Energy/Solar/Greentech
Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.
Explore Other Sectors
Oil/Energy/Solar/Greentech Threat Reports
Philips and GE Breached by Clop Ransomware Exploiting CVE-2026-12569
In August 2026, the Clop ransomware gang exploited a critical vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM platforms to breach systems at Philips and General Electric (GE). This vulnerability allowed remote code execution through the deserialization of untrusted data. The attackers infiltrated these systems, exfiltrating sensitive data such as backups, project plans, facility photos, drawings, diagrams, and blueprints. Philips confirmed the breach, stating it was contained and did not impact customer environments, while GE acknowledged awareness and is assessing the potential issue. This incident underscores the persistent threat posed by ransomware groups targeting critical vulnerabilities in widely used enterprise software. Organizations must remain vigilant, ensuring timely application of security patches and continuous monitoring to detect and mitigate such exploits promptly.
1 month ago
Kill Chain
Cavern C2 Framework's Evolution: Leveraging DNS and Google Apps Script for Stealth
In August 2026, cybersecurity researchers identified advancements in the Cavern (aka Cav3rn) command-and-control (C2) framework, utilized by Iranian nation-state hackers targeting Israeli entities. The updated framework incorporates a complex C2 module that leverages DNS A-record responses to dynamically select between direct HTTPS communication and a Google Apps Script relay for each transaction. This evolution enhances the framework's ability to blend malicious traffic with legitimate network activity, complicating detection efforts. The Cavern framework, first documented in July 2026, is associated with the Cavern Manticore group, linked to Iran's Ministry of Intelligence and Security (MOIS), and shares overlaps with other Iranian threat actors such as MuddyWater and Lyceum. The modular architecture of Cavern facilitates various post-exploitation activities, including file operations, database enumeration, Active Directory reconnaissance, and network tunneling. The integration of legitimate services like Google Apps Script and Microsoft 365 calendars into its C2 channels underscores a strategic shift towards more covert and resilient communication methods. This development highlights the increasing sophistication of nation-state cyber operations and the challenges in detecting and mitigating such threats.
1 month ago
Kill Chain
APT36's PATCHCORD Backdoor: A New Threat to South Asian Critical Infrastructure
In August 2026, a cyber espionage campaign attributed to the Pakistan-aligned threat actor APT36 (Transparent Tribe) targeted Afghan telecom providers and South Asian critical infrastructure. The attackers deployed a previously undocumented backdoor named PATCHCORD, delivered through sector-specific lures such as fake VPN installers impersonating Afghan Telecom. PATCHCORD establishes persistence by hijacking browser shortcuts and communicates with a command-and-control server to execute arbitrary commands, enumerate processes, and deploy additional payloads. The campaign also introduced SHEETCORD, a Go-based backdoor utilizing Google Sheets for command-and-control, delivered via domains impersonating India's National Informatics Center. This incident underscores the evolving tactics of APT36, highlighting their focus on critical infrastructure and the use of sophisticated malware to maintain long-term access and exfiltrate sensitive information. Organizations in the region should enhance their cybersecurity measures to detect and mitigate such threats.
1 month ago
Kill Chain
GeoServer Zero-Day SQL Injection Vulnerability Leads to RCE
In August 2026, a critical zero-day SQL injection vulnerability was discovered in GeoServer's 'jsonArrayContains' function, potentially leading to remote code execution (RCE). The flaw was publicly disclosed on August 12, 2026, by researcher @q1uf3ng, and active exploitation attempts were observed within hours. Attackers probed vulnerable systems, triggering errors without further action, but the risk of full exploitation remained high. GeoServer released patches on August 14, 2026, addressing the issue in versions 3.0.1, 2.28.5, and 2.27.6. Organizations were advised to update immediately to mitigate the risk. This incident underscores the persistent threat posed by SQL injection vulnerabilities in widely used open-source platforms. The rapid exploitation attempts highlight the need for prompt patching and vigilant monitoring of geospatial data servers to prevent potential RCE attacks.
1 month ago
Kill Chain
Critical Vulnerabilities in Siemens RUGGEDCOM APE1808 Devices with Fortinet FortiOS
In August 2026, Siemens disclosed multiple vulnerabilities in its RUGGEDCOM APE1808 devices, specifically those integrated with Fortinet's FortiOS. The identified vulnerabilities include CVE-2026-23573, an improper neutralization of input during web page generation (cross-site scripting), and CVE-2026-59839, an improper limitation of a pathname to a restricted directory (path traversal). These flaws could allow authenticated remote users to execute arbitrary code or commands and enable privileged authenticated attackers with physical access to delete the file system via crafted CLI commands. Siemens has released updates to address these issues and recommends users update to the latest versions to mitigate potential risks. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-975644.html?utm_source=openai)) This incident underscores the critical importance of timely software updates and vigilant monitoring of industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, organizations must prioritize the implementation of robust security measures and maintain awareness of emerging vulnerabilities to safeguard operational integrity.
1 month ago
Kill Chain
Critical Vulnerabilities in Hitachi Energy APM Edge: CVE-2026-43284 and CVE-2026-43500
In July 2026, Hitachi Energy disclosed two critical vulnerabilities in its APM Edge product, identified as CVE-2026-43284 and CVE-2026-43500. These flaws, present in versions up to and including 6.10, could allow local unprivileged users to escalate privileges to root by exploiting weaknesses in the Linux kernel's IPsec ESP subsystem and RxRPC protocol implementation. Successful exploitation could compromise the confidentiality, integrity, and availability of the affected systems. The disclosure underscores the persistent risks associated with kernel-level vulnerabilities in critical infrastructure components. Organizations relying on Hitachi Energy's APM Edge should prioritize applying the recommended mitigations, such as disabling the esp4, esp6, and rxrpc modules, to safeguard their systems against potential exploitation.
1 month ago
Kill Chain
Critical Vulnerability in AVEVA Enterprise SCADA: CVE-2025-7639
In August 2026, AVEVA disclosed a critical vulnerability (CVE-2025-7639) in its Enterprise SCADA software, affecting versions up to 2025. This flaw allows authenticated users with 'DNA Authority - Operator' privileges to tamper with serialized data, potentially leading to code execution during deserialization under the 'DNA Apps' security group. Exploitation could result in unauthorized control over SCADA systems, posing significant risks to industrial operations. The vulnerability underscores the persistent threat of deserialization flaws in industrial control systems. Organizations are urged to assess their SCADA deployments, apply the recommended patches, and implement robust access controls to mitigate potential exploitation.
1 month ago
Kill Chain
Critical Vulnerability in Haiwell IoT Cloud HMI Gateway: CVE-2026-19188
In August 2026, a critical OS command injection vulnerability (CVE-2026-19188) was identified in Haiwell's IoT Cloud HMI Gateway version 3.40.1.12. This flaw resides in the Net Check feature accessible via the /setting endpoint, where the cmdPing Socket.io event fails to properly sanitize user input, allowing attackers to execute arbitrary OS commands with root privileges. Exploitation of this vulnerability could lead to full system compromise, data exfiltration, and disruption of industrial operations. ([secportal.io](https://secportal.io/vulnerabilities/command-injection?utm_source=openai)) This incident underscores the persistent threat of command injection vulnerabilities in industrial control systems (ICS). As ICS devices become increasingly interconnected, the attack surface expands, necessitating rigorous input validation and secure coding practices to prevent such critical flaws. ([immuniweb.com](https://www.immuniweb.com/vulnerability/os-command-injection.html?utm_source=openai))
1 month ago
Kill Chain
Critical Vulnerabilities in ANDRITZ HIPASE-250 Devices: Immediate Action Required
In August 2026, multiple vulnerabilities were identified in ANDRITZ HIPASE-250 and 250 SCALA devices, including storing passwords in a recoverable format, missing authentication for critical functions, and the use of hard-coded credentials. These flaws could allow attackers to read sensitive data or gain unauthorized access to affected workstations. ANDRITZ has released updates to address these issues and recommends users upgrade to version V8.15.00. The discovery of these vulnerabilities underscores the critical importance of securing industrial control systems, especially in the energy sector. Organizations must prioritize timely updates and robust security measures to protect against potential exploits targeting such weaknesses.
1 month ago
Kill Chain
Critical Vulnerabilities in Siemens LOGO! Soft Comfort Software
In August 2026, Siemens disclosed multiple vulnerabilities in its LOGO! Soft Comfort software, specifically CVE-2026-57262 and CVE-2026-57263. These flaws involve the use of a hard-coded cryptographic key and unsalted password hashes, respectively. Exploitation could allow local attackers to decrypt project files or perform efficient offline attacks against password hashes, leading to unauthorized access or modification of sensitive project configurations. Siemens has released version 9 to address these issues and recommends users update promptly. This incident underscores the critical importance of robust cryptographic practices in industrial control systems. The vulnerabilities highlight the need for organizations to regularly review and update their security measures to protect against evolving threats, especially in software managing sensitive operational data.
1 month ago
Kill Chain
Near-Autonomous AI Cyberattack on Taiwanese Government in 2026
In August 2026, a sophisticated cyberattack targeted the Taiwanese government, marking the first publicly known instance of a near-autonomous AI-driven breach against a state entity. Suspected Chinese hackers employed open-source AI frameworks, Hermes and OpenClaw, to orchestrate the attack, which led to the exfiltration of over 2,500 personnel records. The AI system autonomously adapted during the operation, conducting 'Learning Cycles' to identify vulnerabilities and expanding its reach to government IT supply chain vendors, a nuclear safety agency, and multiple energy sector companies. This incident underscores the escalating use of AI in cyber warfare, highlighting the need for enhanced defensive measures against autonomous threats. The attack's ability to self-correct and adapt without human intervention signifies a paradigm shift in cyberattack methodologies, necessitating a reevaluation of current cybersecurity strategies to address AI-driven threats.
1 month ago
Kill Chain
Ransomware Attack Disrupts Colombian Justice Ministry Amid Political Transition
In early August 2026, Colombia's Ministry of Justice experienced a ransomware attack that disrupted several public-facing services, including those related to illicit-drug monitoring and legal processes. The incident occurred just days before the nation's presidential transition, highlighting the vulnerability of critical government infrastructure during periods of political change. While some files were encrypted, acting Minister of Justice Cielo Rusinque confirmed that no data was exfiltrated. This attack is part of a broader trend of increasing cyber threats targeting Colombian government agencies and critical infrastructure. In the past year, exploit attempts in the country have more than tripled, with attackers focusing on exposed and potentially vulnerable systems. The incident underscores the urgent need for enhanced cybersecurity measures to protect national assets, especially during times of political transition.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports