✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Utilities
Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.
Explore Other Sectors
Utilities Threat Reports
Critical Vulnerabilities Discovered in Jinan USR IOT's USR-W610 Device
In February 2026, multiple critical vulnerabilities were identified in Jinan USR IOT Technology Limited's USR-W610 serial device server, affecting firmware versions up to and including 3.1.1.0. These vulnerabilities include weak password requirements, cleartext transmission of sensitive information, insufficiently protected credentials, and missing authentication for critical functions. Exploitation could lead to authentication bypass, denial-of-service conditions, or unauthorized access to user credentials, including administrative accounts. ([windowsforum.com](https://windowsforum.com/threads/high-severity-ics-advisory-hits-usr-w610-serial-gateway-cve-2026-25715-to-cve-2026-26048.402628/post-959899?utm_source=openai)) The USR-W610 is widely deployed in industrial environments to bridge legacy serial devices with IP-based networks. Given the device's role in critical manufacturing sectors, these vulnerabilities pose significant risks, including potential unauthorized process changes, production downtime, and safety incidents. ([windowsforum.com](https://windowsforum.com/threads/high-severity-ics-advisory-hits-usr-w610-serial-gateway-cve-2026-25715-to-cve-2026-26048.402628/post-959899?utm_source=openai))
5 months ago
Kill Chain
Critical Vulnerability in Valmet DNA Engineering Web Tools: CVE-2025-15577
In February 2026, a critical vulnerability (CVE-2025-15577) was identified in Valmet DNA Engineering Web Tools versions C2022 and earlier. This flaw allows unauthenticated attackers to manipulate URLs, enabling arbitrary file read access on the affected systems. Exploiting this vulnerability could lead to unauthorized access to sensitive information, posing significant risks to industrial control systems. ([valmet.com](https://www.valmet.com/company/innovation/advisories/CVE-2025-15577/?utm_source=openai)) The discovery of this vulnerability underscores the ongoing challenges in securing industrial control systems against cyber threats. Organizations utilizing Valmet DNA Web Tools are urged to apply the vendor-provided patches promptly and implement recommended security measures to mitigate potential exploitation. ([valmet.com](https://www.valmet.com/company/innovation/advisories/CVE-2025-15577/?utm_source=openai))
5 months ago
Kill Chain
Critical Vulnerabilities in EnOcean SmartServer IoT: Immediate Action Required
In February 2026, critical vulnerabilities were identified in EnOcean's SmartServer IoT versions up to 4.60.009. These flaws, CVE-2026-20761 and CVE-2026-22885, allowed remote attackers to execute arbitrary OS commands and cause memory leaks via specially crafted LON IP-852 management messages. Exploitation could lead to unauthorized control over affected devices and potential data breaches. EnOcean promptly addressed these issues by releasing SmartServer 4.6 Update 2 (v4.60.023) and provided a hardening guide to enhance security measures. Organizations utilizing SmartServer IoT are urged to update to the latest version and implement recommended security practices to mitigate risks associated with these vulnerabilities.
5 months ago
Kill Chain
Critical Vulnerability in Welker OdorEyes EcoSystem Pulse Bypass System (CVE-2026-24790)
In February 2026, a critical vulnerability (CVE-2026-24790) was identified in Welker's OdorEyes EcoSystem Pulse Bypass System with XL4 Controller, widely used in gas odorization processes. This flaw allows remote attackers to manipulate the device's programmable logic controller (PLC) without authentication, potentially leading to over- or under-odorization events. Such incidents can compromise safety, regulatory compliance, and operational integrity. The vendor has not responded to coordinated disclosure attempts, leaving systems exposed to potential exploitation. ([windowsforum.com](https://windowsforum.com/threads/cve-2026-24790-unauthenticated-control-flaw-in-welker-odoreyes-xl4.402623/?utm_source=openai)) This vulnerability underscores the pressing need for robust security measures in industrial control systems, especially those integral to critical infrastructure sectors like energy and chemical processing. The lack of authentication safeguards in such devices highlights a broader issue of security gaps in industrial equipment, necessitating immediate attention and remediation efforts to prevent potential disruptions and safety hazards.
5 months ago
Kill Chain
Sandworm's DynoWiper Targets Poland's Energy Sector in 2025 Cyberattack
In late December 2025, Poland's energy infrastructure was targeted by a coordinated cyberattack deploying a novel data-wiping malware named DynoWiper. The attack aimed to disrupt operations across multiple renewable energy facilities, including wind and solar farms, as well as a major combined heat and power plant serving approximately 500,000 customers. ESET researchers attributed the attack to the Russian state-sponsored group Sandworm with medium confidence, noting similarities to previous incidents involving wiper malware. Fortunately, the attack was intercepted before causing significant operational disruptions. ([eset.com](https://www.eset.com/us/about/newsroom/research/eset-research-russian-sandwormapt-attacks-energy-company-poland-with-dynowiper/?utm_source=openai)) This incident underscores the evolving threat landscape where state-sponsored actors increasingly target critical infrastructure with destructive malware. The timing, coinciding with the 10th anniversary of Sandworm's 2015 attack on Ukraine's power grid, highlights the symbolic nature of such operations and the persistent risk to energy sectors globally. ([welivesecurity.com](https://www.welivesecurity.com/en/eset-research/eset-research-sandworm-cyberattack-poland-power-grid-late-2025/?utm_source=openai))
5 months ago
Kill Chain
Operation Absolute Resolve: Cyber-Physical Tactics in Modern Warfare
On January 3, 2026, during Operation Absolute Resolve, U.S. forces executed a mission to capture Venezuelan President Nicolás Maduro. The operation involved over 150 aircraft conducting airstrikes on key military installations in Caracas, including Fuerte Tiuna and La Carlota Air Base. Concurrently, cyber capabilities were deployed to disrupt Venezuela's power grid, resulting in widespread blackouts across the capital. This multi-domain approach combined kinetic strikes with cyber operations to disable critical infrastructure and facilitate the extraction of Maduro. The operation led to significant physical damage to military facilities and substations, causing prolonged power outages in several districts. The integration of cyber and kinetic tactics underscores the evolving nature of modern military engagements, highlighting the strategic use of cyber operations to achieve tactical objectives. This incident serves as a case study in the application of cyber-physical strategies in contemporary warfare, emphasizing the need for robust cybersecurity measures to protect national infrastructure.
5 months ago
Kill Chain
Critical Vulnerability in Honeywell CCTV Products Exposes Unauthorized Access Risks
In February 2026, a critical vulnerability (CVE-2026-1670) was discovered in multiple Honeywell CCTV products, allowing unauthenticated attackers to remotely change the 'forgot password' recovery email address. This flaw enables unauthorized access to camera feeds and potential account hijacking. The affected models include I-HIB2PI-UL 2MP IP (version 6.1.22.1216), SMB NDAA MVO-3, PTZ WDR 2MP 32M, and 25M IPC, all running firmware version WDR_2MP_32M_PTZ_v2.0. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/critical-infra-honeywell-cctvs-vulnerable-to-auth-bypass-flaw/?utm_source=openai)) The vulnerability underscores the importance of securing IoT devices, especially those deployed in critical infrastructure. Organizations are advised to minimize network exposure of such devices, isolate them behind firewalls, and use secure remote access methods like updated VPN solutions. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/critical-infra-honeywell-cctvs-vulnerable-to-auth-bypass-flaw/?utm_source=openai))
5 months ago
Kill Chain
Poland's Energy Sector Thwarts Major Cyberattack by Sandworm Group
In late December 2025, Poland's energy infrastructure was targeted by a coordinated cyberattack involving the deployment of a new data-wiping malware named DynoWiper. The attack focused on over 30 wind and solar farms, a combined heat and power plant serving nearly half a million customers, and a manufacturing company. The attackers exploited exposed FortiGate devices lacking multi-factor authentication to gain initial access, then moved laterally within networks to deploy the wiper malware. Despite the sophisticated nature of the attack, endpoint detection and response systems successfully blocked the malware's execution, preventing any disruption to energy production or distribution. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/06/poland-cyberattacks-energy-sector-industrial-organizations/?utm_source=openai)) This incident underscores the escalating threat posed by state-sponsored cyber actors targeting critical infrastructure. The use of destructive malware like DynoWiper highlights the need for robust cybersecurity measures, including the implementation of multi-factor authentication and regular security audits, to protect against such sophisticated attacks. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/06/poland-cyberattacks-energy-sector-industrial-organizations/?utm_source=openai))
5 months ago
Kill Chain
GE Vernova Enervista UR Setup Vulnerabilities Disclosed in 2026
In February 2026, GE Vernova disclosed two vulnerabilities in their Enervista UR Setup software versions prior to 8.70. CVE-2026-1762 involves a directory traversal flaw that allows unauthorized file manipulation, while CVE-2026-1763 pertains to a DLL hijacking issue enabling code execution with elevated privileges. Both vulnerabilities require local access for exploitation and have been addressed in version 8.70. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1762?utm_source=openai)) The disclosure underscores the importance of timely software updates and robust local security measures, especially in critical infrastructure sectors where such vulnerabilities can have significant operational impacts.
5 months ago
Kill Chain
Critical RADIUS Vulnerability in Hitachi Energy XMC20 Devices (CVE-2024-3596)
In July 2024, a critical vulnerability (CVE-2024-3596) was identified in the RADIUS protocol, affecting Hitachi Energy's XMC20 devices. This flaw allows an on-path attacker to forge RADIUS server responses by exploiting weaknesses in the MD5-based Response Authenticator, potentially granting unauthorized network access. The vulnerability impacts XMC20 versions R18, R17A, and earlier, particularly when configured for remote RADIUS authentication. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/222287-blast-radius-cve-2024-3596-protocol-sp.html?utm_source=openai)) The discovery underscores the risks associated with legacy cryptographic protocols like MD5. Organizations relying on RADIUS for authentication should promptly implement mitigations, such as enabling the Message-Authenticator attribute, to safeguard against potential exploits. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/222287-blast-radius-cve-2024-3596-protocol-sp.html?utm_source=openai))
5 months ago
Kill Chain
Critical Vulnerability in Open62541: Immediate Action Required
In February 2026, a medium-severity vulnerability (CVE-2026-1301) was identified in o6 Automation GmbH's Open62541, an open-source OPC UA stack widely used in industrial automation. The flaw, present in versions from 1.5-rc1 to before 1.5-rc2, allows unauthenticated attackers to send crafted JSON PubSub messages, leading to out-of-bounds writes, process crashes, and potential memory corruption. This vulnerability poses significant risks to industrial control systems, potentially causing operational disruptions and compromising system integrity. ([windowsforum.com](https://windowsforum.com/threads/cve-2026-1301-open62541-json-pubsub-memory-safety-bug-upgrade-to-v1-5-0.400263/?utm_source=openai)) The discovery of this vulnerability underscores the critical importance of rigorous security practices in industrial automation software. Organizations utilizing Open62541 should promptly upgrade to the stable release v1.5.0 to mitigate this risk. Additionally, implementing network segmentation and minimizing exposure of control systems to external networks are essential steps to enhance security posture. ([windowsforum.com](https://windowsforum.com/threads/cve-2026-1301-open62541-json-pubsub-memory-safety-bug-upgrade-to-v1-5-0.400263/?utm_source=openai))
5 months ago
Kill Chain
Critical Vulnerability in Hitachi Energy's FOX61x Products (CVE-2024-3596)
In January 2026, Hitachi Energy disclosed a critical vulnerability (CVE-2024-3596) in its FOX61x products, specifically affecting versions R18 and R17A and earlier. This flaw, inherent in the RADIUS protocol under RFC 2865, allows local attackers to modify valid responses through a chosen-prefix collision attack on the MD5 Response Authenticator signature. Exploitation could compromise the confidentiality, integrity, and availability of the affected systems. The vulnerability is particularly relevant when FOX61x devices are configured to use remote RADIUS authentication. ([it4automation.com](https://it4automation.com/security-alerts/hitachi-energy-fox61x-foxcst-and-foxman-un-products/?utm_source=openai)) This incident underscores the persistent risks associated with legacy authentication protocols and the importance of implementing robust security measures. Organizations utilizing FOX61x devices are urged to apply the recommended mitigations promptly to prevent potential exploitation.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports