The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Oil/Energy/Solar/Greentech
Breach intelligence, attack campaigns, and threat reports targeting the Oil/Energy/Solar/Greentech sector.
Explore Other Sectors
Oil/Energy/Solar/Greentech Threat Reports
Critical Vulnerability in Siemens SIMATIC S7-PLCSIM Advanced: CVE-2026-54429
In July 2026, Siemens disclosed a vulnerability (CVE-2026-54429) in its SIMATIC S7-PLCSIM Advanced software, affecting all versions. The flaw arises from improper handling of high-volume multicast network traffic, leading to memory exhaustion and a denial-of-service condition. An unauthenticated attacker on the local network can exploit this by sending excessive multicast traffic, rendering the application inaccessible until manually restarted. Notably, no project data is lost during this process. Exploitation requires a specific project configuration to be active on the targeted instance. This incident underscores the critical importance of securing industrial control systems against network-based attacks. As industrial environments become increasingly interconnected, vulnerabilities like this highlight the need for robust network segmentation, traffic monitoring, and timely application of security patches to prevent potential disruptions.
1 month ago
Kill Chain
Enhancing Critical Infrastructure Resilience: CISA's 'CI Fortify' Guidance
On July 28, 2026, the Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with international partners, released the 'CI Fortify – Advice for Isolating Vital Systems' guidance. This document provides critical infrastructure organizations with practical steps to isolate essential operational technology (OT) and supporting systems from other networks during cyber incidents or periods of heightened threat. The guidance emphasizes identifying critical systems, mapping their connections, and implementing effective separation points to ensure continuity of essential services during disruptions. The release of this guidance underscores the increasing cyber threats targeting critical infrastructure sectors. State-sponsored actors and cybercriminals are increasingly focusing on these sectors to conduct espionage or prepare for disruptive cyber activities. Implementing the recommended isolation strategies is vital for organizations to enhance their resilience and maintain operational continuity in the face of evolving cyber threats.
1 month ago
Kill Chain
Origin Energy Data Breach 2026: A Wake-Up Call for Critical Infrastructure Security
In July 2026, Origin Energy, Australia's largest energy retailer, confirmed unauthorized access to and disclosure of customer data. The compromised information includes names, addresses, dates of birth, contact numbers, account details, and partial financial data such as the last four digits of credit cards and the last three digits of bank accounts. The exact number of affected customers remains under investigation. Origin Energy has engaged with the Australian Cyber Security Centre and the Australian Federal Police to address the breach and is working to secure its systems to prevent further unauthorized access. This incident underscores the escalating threat of cyberattacks targeting critical infrastructure sectors. The exposure of personal and partial financial data heightens the risk of identity theft and sophisticated phishing scams, especially with the increasing use of AI by cybercriminals to craft convincing fraudulent communications.
2 months ago
Kill Chain
Critical Vulnerabilities in Panduit IntraVUE Threaten Industrial Control Systems
In July 2026, multiple critical vulnerabilities were identified in Panduit IntraVUE versions up to 3.2.1a14. These vulnerabilities include plaintext storage of passwords, unintended proxy usage, exposure of sensitive system information, and inadequate encryption strength. Exploitation could allow attackers to manipulate industrial control devices remotely without physical access or specialized knowledge, posing significant risks to critical infrastructure sectors such as manufacturing, energy, and water systems. The discovery of these vulnerabilities underscores the ongoing challenges in securing industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, organizations must prioritize timely vulnerability management and adopt robust security measures to mitigate potential risks.
2 months ago
Kill Chain
Critical Vulnerability in MZ Automation's lib60870: CVE-2026-16002
In July 2026, a critical out-of-bounds read vulnerability, identified as CVE-2026-16002, was discovered in MZ Automation's lib60870 versions up to and including 2.4.0. This flaw allows attackers to send specially crafted IEC 60870-5 messages, causing the parsing process to crash and resulting in a denial of service. The vulnerability is particularly concerning for industrial control systems in sectors like energy and water, where such disruptions can have significant operational impacts. ([vuldb.com](https://vuldb.com/cve/CVE-2026-16002?utm_source=openai)) The release of lib60870 version 2.4.1 addresses this vulnerability, emphasizing the importance of timely software updates in critical infrastructure. This incident underscores the ongoing need for robust security measures in industrial environments to prevent potential exploitation and service disruptions. ([lib60870.com](https://www.lib60870.com/?utm_source=openai))
2 months ago
Kill Chain
Critical Vulnerabilities Discovered in MZ Automation's libIEC61850 Library
In July 2026, multiple critical vulnerabilities were identified in MZ Automation's libIEC61850 library, widely used in industrial control systems. These vulnerabilities include stack-based and heap-based buffer overflows, as well as NULL pointer dereferences, which could allow unauthenticated attackers to execute arbitrary code or cause denial-of-service conditions. Affected versions range from v1.0.0 to v1.6.1. ([vuldb.com](https://vuldb.com/cve/CVE-2026-49035?utm_source=openai)) The discovery of these vulnerabilities underscores the ongoing risks in industrial control systems, emphasizing the need for regular security assessments and prompt patching to mitigate potential exploitation.
2 months ago
Kill Chain
Critical Vulnerabilities in Weintek cMT3092X HMIs Threaten Industrial Security
In July 2026, multiple critical vulnerabilities were identified in Weintek's cMT3092X Human-Machine Interface (HMI) devices, including CVE-2026-60134, CVE-2026-61892, CVE-2026-61886, and CVE-2026-60135. These flaws allowed non-privileged users to escalate privileges, modify cookies and tokens, and access or alter sensitive data stored in plaintext. Exploitation of these vulnerabilities could lead to unauthorized control over industrial processes and potential data breaches. ([crebral.ai](https://www.crebral.ai/work/SECURITY?utm_source=openai)) The discovery of these vulnerabilities underscores the ongoing security challenges in industrial control systems, emphasizing the need for robust security measures and timely patch management to protect critical infrastructure from emerging threats.
2 months ago
Kill Chain
Critical Vulnerability in Rockwell Automation ThinManager: CVE-2026-11917
In July 2026, a critical path traversal vulnerability (CVE-2026-11917) was identified in Rockwell Automation's ThinManager software, affecting versions 13.0.0 through 14.0.2. This flaw allows authenticated attackers to write arbitrary files to restricted system directories outside the application's intended directory, potentially leading to unauthorized access, data breaches, or manipulation of critical system files. Rockwell Automation has released patches to address this issue, and users are strongly advised to upgrade to the corrected versions immediately. ([rockwellautomation.com](https://www.rockwellautomation.com/es-es/trust-center/security-advisories/advisory.SD1782.html?utm_source=openai)) This incident underscores the importance of robust access controls and input validation in industrial control systems. The vulnerability's exploitation could lead to complete system compromise, data exfiltration, or disruption of industrial control processes that ThinManager typically supports in manufacturing and automation environments. ([vuldb.com](https://vuldb.com/cve/CVE-2026-11917?utm_source=openai))
2 months ago
Kill Chain
Russian Espionage Group Exploits Zimbra Vulnerability in 2025
In July 2025, the Russian state-sponsored threat group known as Laundry Bear initiated a cyber espionage campaign targeting government and commercial organizations by exploiting a zero-day vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite (ZCS). This vulnerability allowed attackers to execute malicious JavaScript via CSS @import directives in HTML emails, enabling unauthorized access to sensitive data such as emails, passwords, and two-factor authentication tokens. The exploit required no user interaction beyond viewing a malicious email, leading to significant data breaches across multiple sectors. ([cyberscoop.com](https://cyberscoop.com/russian-laundry-bear-zimbra-exploit/?utm_source=openai)) The continued exploitation of unpatched ZCS instances underscores the critical need for organizations to promptly apply security updates. This incident highlights the evolving tactics of state-sponsored actors and the importance of proactive cybersecurity measures to protect sensitive information. ([nsa.gov](https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4553352/nsa-and-partners-alert-zimbra-collaboration-suite-users-of-a-russian-state-supp/?utm_source=openai))
2 months ago
Kill Chain
Russian Hackers Exploit Zimbra Zero-Click Vulnerability (CVE-2025-66376) for Email Theft
In July 2026, the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, exploited a zero-click vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite's Classic UI to target organizations across various sectors, including defense, government, education, and technology. By embedding malicious JavaScript in specially crafted HTML emails, the attackers executed scripts automatically upon email viewing, enabling the theft of account data without user interaction. This campaign led to unauthorized access to sensitive information, including emails, credentials, and two-factor authentication tokens, significantly compromising organizational security. The incident underscores the critical importance of timely software updates and robust email security measures. Despite the vulnerability being patched in November 2025, many organizations remained unpatched, highlighting a persistent challenge in cybersecurity hygiene. The exploitation of this flaw by a sophisticated threat actor emphasizes the need for continuous vigilance and proactive defense strategies to mitigate emerging cyber threats.
2 months ago
Kill Chain
Origin Energy Data Breach: A Wake-Up Call for Critical Infrastructure Security
In July 2026, Origin Energy, Australia's largest energy retailer, confirmed a data breach involving unauthorized access to customer information. The compromised data includes names, addresses, dates of birth, contact numbers, account details, and partial financial information (last four digits of credit cards or last three digits of bank accounts). The company is working to determine the total number of affected customers and has engaged with the Australian Cyber Security Centre, the Australian Federal Police, and the Office of the Australian Information Commissioner to investigate the incident. ([originenergy.com.au](https://www.originenergy.com.au/about/investors-media/update-on-data-security-incident/?utm_source=openai)) This breach underscores the escalating threat of cyberattacks targeting critical infrastructure sectors. The exposure of personal information increases the risk of identity theft and sophisticated phishing scams, particularly with the rise of AI-driven cybercrime. Organizations must enhance their cybersecurity measures to protect sensitive customer data and maintain public trust. ([abc.net.au](https://www.abc.net.au/news/2026-07-24/origin-breach-could-fuel-wave-of-ai-powered-scams/106951588?utm_source=openai))
2 months ago
Kill Chain
Critical Vulnerability in Rockwell Automation's FactoryTalk Services Platform (CVE-2026-10714)
In July 2026, a critical vulnerability (CVE-2026-10714) was identified in Rockwell Automation's FactoryTalk Services Platform (FTSP) version 6.60. The flaw allows attackers to bypass JSON Web Token (JWT) signature validation during Okta Web Authentication by setting the algorithm to "none," enabling low-privilege users to impersonate authorized users. This could lead to unauthorized access to system configurations and the ability to grant permissions to other systems protected by FTSP. ([rockwellautomation.com](https://www.rockwellautomation.com/es-es/trust-center/security-advisories/advisory.SD1786.html?utm_source=openai)) This incident underscores the importance of robust authentication mechanisms in industrial control systems. As cyber threats targeting critical infrastructure become more sophisticated, organizations must prioritize timely patching and adherence to security best practices to mitigate potential risks.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports