✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Utilities
Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.
Explore Other Sectors
Utilities Threat Reports
Iranian Cyberattacks on U.S. Critical Infrastructure: A 2026 Analysis
In March 2026, Iranian-affiliated cyber actors initiated a series of attacks targeting U.S. critical infrastructure sectors, including energy, water, and government services. These attackers exploited vulnerabilities in internet-exposed Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), leading to operational disruptions and financial losses. The Cybersecurity and Infrastructure Security Agency (CISA), along with other federal agencies, issued a joint advisory warning of these ongoing threats and provided mitigation strategies to affected organizations. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/us-warns-of-iranian-hackers-targeting-critical-infrastructure/?utm_source=openai)) This incident underscores the escalating cyber threat landscape, particularly from nation-state actors targeting industrial control systems. Organizations must prioritize securing operational technology environments to prevent similar disruptions and safeguard critical services.
3 months ago
Kill Chain
Critical Vulnerability in GPL Odorizers GPL750 Devices (CVE-2026-4436)
In April 2026, a critical vulnerability (CVE-2026-4436) was identified in GPL Odorizers' GPL750 devices, which are used for odorant injection in natural gas pipelines. This flaw allows low-privileged remote attackers to manipulate register values via Modbus packets, potentially leading to incorrect odorant levels being injected into gas lines. Affected versions include GPL750 (XL4) >=v1.0, GPL750 (XL4 Prime) >=v4.0, GPL750 (XL7) >=v13.0, and GPL750 (XL7 Prime) >=v18.4. The vulnerability has a CVSS v3 base score of 8.6, indicating high severity. ([gasodorizer.com](https://www.gasodorizer.com/odorization/gpl-750-odorant-injection/?utm_source=openai)) The exploitation of this vulnerability could result in significant safety hazards due to improper odorization of natural gas, which is essential for leak detection. Organizations using these devices are urged to update to the latest software versions and implement recommended mitigations to prevent potential exploitation. ([gasodorizer.com](https://www.gasodorizer.com/odorization/gpl-750-odorant-injection/?utm_source=openai))
3 months ago
Kill Chain
Critical Vulnerability in Contemporary Controls BASC-20T Puts Industrial Systems at Risk
In April 2026, a critical vulnerability (CVE-2025-13926) was identified in Contemporary Controls' BASC-20T unitary controller, widely used in industrial control systems. This flaw allows attackers to intercept and manipulate network traffic, enabling unauthorized actions such as reconfiguring devices, renaming or deleting files, performing file transfers, and executing remote procedure calls. The vulnerability affects BASControl20 version 3.1 and poses significant risks to sectors like commercial facilities, critical manufacturing, and energy. ([building-controls.com](https://www.building-controls.com/products/ccs-basc20t?utm_source=openai)) This incident underscores the escalating threats to industrial control systems, with a notable increase in vulnerabilities and attacks targeting operational technology environments. Organizations must prioritize securing legacy systems, implementing robust network segmentation, and ensuring timely updates to mitigate such risks. ([infosecurity-magazine.com](https://www.infosecurity-magazine.com/news/industrial-control-system-vulns/?utm_source=openai))
3 months ago
Kill Chain
Iran-Linked Hackers Target U.S. Critical Infrastructure in 2026
In early April 2026, Iran-affiliated cyber actors targeted internet-facing operational technology (OT) devices across U.S. critical infrastructure sectors, including programmable logic controllers (PLCs) manufactured by Rockwell Automation. These attacks led to diminished PLC functionality, manipulation of display data, and, in some cases, operational disruption and financial loss. The Cybersecurity and Infrastructure Security Agency (CISA), along with the FBI and NSA, issued warnings about these threats, emphasizing the need for immediate action to secure vulnerable OT assets. ([nextgov.com](https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/?utm_source=openai)) This incident underscores the escalating cyber threats from nation-state actors targeting critical infrastructure. The exploitation of internet-exposed PLCs highlights the urgent need for organizations to implement robust cybersecurity measures, including network segmentation, regular software updates, and the use of strong, unique passwords to protect against such sophisticated attacks.
3 months ago
Kill Chain
Masjesu Botnet: A New Era of DDoS-for-Hire Targeting IoT Devices
In April 2026, cybersecurity researchers identified 'Masjesu,' a sophisticated botnet operating as a DDoS-for-hire service. Masjesu has been active since 2023, primarily targeting a wide array of IoT devices, including routers and gateways, across multiple architectures. The botnet employs advanced evasion techniques, such as randomizing packet headers and payloads, to mimic legitimate traffic and avoid detection. It propagates by exploiting known vulnerabilities in devices from manufacturers like D-Link, GPON, and Netgear, and by brute-forcing weak or default passwords. Masjesu's operators advertise their services via Telegram, offering clients the ability to launch large-scale DDoS attacks on demand. ([trellix.com](https://www.trellix.com/blogs/research/masjesu-rising-stealth-iot-botnet-ddos-evasion/?utm_source=openai)) The emergence of Masjesu underscores the escalating threat posed by IoT-based botnets. With the proliferation of unsecured IoT devices, attackers can easily amass vast networks capable of launching devastating DDoS attacks. This trend highlights the urgent need for enhanced security measures, including regular firmware updates, strong password policies, and network monitoring, to protect against such evolving threats.
3 months ago
Kill Chain
Iranian APT Exploits PLC Vulnerabilities in U.S. Critical Infrastructure
In April 2026, Iranian-affiliated advanced persistent threat (APT) actors targeted internet-facing operational technology (OT) devices, specifically programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley, across multiple U.S. critical infrastructure sectors. These attacks led to disruptions in energy, water, and government facilities by manipulating project files and tampering with human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruptions and financial losses. ([databreaches.net](https://databreaches.net/2026/04/07/iranian-affiliated-cyber-actors-exploit-programmable-logic-controllers-across-us-critical-infrastructure/?utm_source=openai)) This incident underscores the escalating cyber threats from nation-state actors targeting critical infrastructure, highlighting the urgent need for enhanced cybersecurity measures and vigilance in protecting OT environments.
3 months ago
Kill Chain
Mitsubishi Electric's 2025 Vulnerability: A Wake-Up Call for Industrial Security
In May 2025, Mitsubishi Electric disclosed a vulnerability (CVE-2025-0921) in their GENESIS64, MC Works64, and GENESIS products. This flaw allows local attackers to perform unauthorized writes to arbitrary files by exploiting symbolic links, potentially leading to denial-of-service conditions. The vulnerability affects all versions of GENESIS64 and MC Works64, as well as GENESIS version 11.00. Mitsubishi Electric has released patches and mitigation strategies to address this issue. ([mitsubishielectric.com](https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-002_en.pdf?utm_source=openai)) This incident underscores the critical importance of securing industrial control systems against local privilege escalation attacks, which can disrupt essential operations. Organizations are urged to apply the provided patches promptly and review their security protocols to prevent similar vulnerabilities.
3 months ago
Kill Chain
Iranian APT Exploits U.S. Critical Infrastructure PLCs in 2026
In April 2026, Iranian-affiliated advanced persistent threat (APT) actors exploited internet-facing operational technology (OT) devices, notably Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), across multiple U.S. critical infrastructure sectors. The attackers accessed these devices via default or weak credentials, leading to disruptions through malicious interactions with project files and manipulation of data on human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruptions and financial losses. ([publicpower.org](https://www.publicpower.org/periodical/article/iranian-affiliated-cyber-actors-exploit-programmable-logic-controllers-across-us-critical?utm_source=openai)) This incident underscores the escalating threat posed by nation-state actors targeting critical infrastructure. The exploitation of OT devices highlights the urgent need for organizations to secure internet-facing systems, implement strong authentication measures, and regularly update and patch their systems to mitigate such risks.
3 months ago
Kill Chain
Iranian Hackers Exploit PLC Vulnerabilities in U.S. Critical Infrastructure
In March 2026, Iranian-affiliated Advanced Persistent Threat (APT) actors initiated cyberattacks targeting internet-exposed Rockwell/Allen-Bradley programmable logic controllers (PLCs) within U.S. critical infrastructure sectors, including Government Services, Water and Wastewater Systems, and Energy. These attacks involved unauthorized access to PLCs, manipulation of project files, and alteration of data displayed on Human-Machine Interface (HMI) and Supervisory Control and Data Acquisition (SCADA) systems, leading to operational disruptions and financial losses. This incident underscores the escalating cyber threat landscape, particularly in the context of geopolitical tensions. Organizations must prioritize securing internet-facing operational technology assets to mitigate risks associated with state-sponsored cyber activities.
3 months ago
Kill Chain
Critical RCE Vulnerability in Hitachi Energy's Ellipse Platform
In early 2026, a critical vulnerability (CVE-2025-10492) was identified in Hitachi Energy's Ellipse enterprise asset management platform, specifically within the JasperReports component used for custom reporting. This Java deserialization flaw allows remote code execution without authentication or user interaction, affecting Ellipse versions 9.0.50 and earlier. The vulnerability poses significant risks to critical infrastructure sectors, including energy and manufacturing, by potentially enabling unauthorized access and control over essential systems. ([windowsforum.com](https://windowsforum.com/threads/hitachi-ellipse-jasperreports-flaw-cve-2025-10492-rce-risk-and-mitigation-steps.409447/?utm_source=openai)) The exploitation of this vulnerability underscores the persistent threat posed by deserialization flaws in widely used third-party libraries. Organizations are urged to assess their exposure, apply available patches, and implement recommended mitigations to safeguard against potential attacks targeting this and similar vulnerabilities.
3 months ago
Kill Chain
Siemens SICAM 8 Vulnerabilities: Protecting Critical Infrastructure
In March 2026, Siemens identified two critical vulnerabilities in its SICAM 8 industrial control products: CVE-2026-27663 and CVE-2026-27664. CVE-2026-27663 is a denial-of-service vulnerability in CPCI85 and RTUM85 devices, where high-volume requests can exhaust system resources, leading to operational disruptions. CVE-2026-27664 is an out-of-bounds write vulnerability in CPCI85 and SICORE systems, exploitable through specially crafted XML inputs, potentially causing service crashes. Siemens has released firmware updates (V26.10 and V26.10.0) to address these issues. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-27663/?utm_source=openai)) These vulnerabilities highlight the ongoing risks in industrial control systems, emphasizing the need for timely patch management and robust network security measures to protect critical infrastructure from potential cyber threats.
3 months ago
Kill Chain
Yokogawa CENTUM VP Hardcoded Password Vulnerability Exposes Industrial Systems
In March 2026, a hardcoded password vulnerability (CVE-2025-7741) was identified in Yokogawa's CENTUM VP distributed control system. This flaw allows attackers with access to the Human Interface Station (HIS) to log in using the 'PROG' user account, potentially modifying system permissions. Affected versions include CENTUM VP R5.01.00 to R5.04.20, R6.01.00 to R6.12.00, and R7.01.00. Exploitation requires prior access to the HIS screen controls, limiting the immediate risk but highlighting significant security concerns in industrial control systems. ([cvedetails.com](https://www.cvedetails.com/cve/CVE-2025-7741/?utm_source=openai)) This incident underscores the critical need for robust authentication mechanisms in industrial environments. The reliance on hardcoded credentials poses substantial risks, especially when combined with potential insider threats or physical access breaches. Organizations must prioritize updating authentication protocols and implementing comprehensive security measures to mitigate such vulnerabilities.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports