✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Utilities
Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.
Explore Other Sectors
Utilities Threat Reports
Critical Vulnerability in Hitachi Energy's FOX61x Products (CVE-2024-3596)
In January 2026, Hitachi Energy disclosed a critical vulnerability (CVE-2024-3596) in its FOX61x products, specifically affecting versions R18 and R17A and earlier. This flaw, inherent in the RADIUS protocol under RFC 2865, allows local attackers to modify valid responses through a chosen-prefix collision attack on the MD5 Response Authenticator signature. Exploitation could compromise the confidentiality, integrity, and availability of the affected systems. The vulnerability is particularly relevant when FOX61x devices are configured to use remote RADIUS authentication. ([it4automation.com](https://it4automation.com/security-alerts/hitachi-energy-fox61x-foxcst-and-foxman-un-products/?utm_source=openai)) This incident underscores the persistent risks associated with legacy authentication protocols and the importance of implementing robust security measures. Organizations utilizing FOX61x devices are urged to apply the recommended mitigations promptly to prevent potential exploitation.
5 months ago
Kill Chain
Mitsubishi Electric's 2026 PLC Vulnerability: A Wake-Up Call for Industrial Network Security
In February 2026, Mitsubishi Electric disclosed a critical vulnerability (CVE-2025-15080) in its MELSEC iQ-R Series programmable logic controllers (PLCs). This flaw allows unauthenticated attackers to read or modify device data and control programs, or to cause a denial-of-service condition by sending specially crafted packets. The affected models include R08PCPU, R16PCPU, R32PCPU, and R120PCPU with firmware versions up to 48. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-15080?utm_source=openai)) This incident underscores the persistent risks in industrial control systems, particularly those exposed to untrusted networks. Organizations must prioritize securing network access to critical infrastructure to prevent unauthorized exploitation of such vulnerabilities.
5 months ago
Kill Chain
Conpet's 2026 Cyberattack: A Wake-Up Call for Critical Infrastructure Security
In early February 2026, Conpet, Romania's national oil pipeline operator, experienced a cyberattack that disrupted its corporate IT infrastructure and rendered its website inaccessible. The Qilin ransomware group claimed responsibility, alleging the theft of nearly 1TB of sensitive documents, including financial records and personal identification data. Despite these disruptions, Conpet's operational technologies, such as the SCADA and telecommunications systems, remained unaffected, ensuring uninterrupted crude oil and gasoline transportation services. This incident underscores the escalating threat posed by ransomware groups like Qilin, which have increasingly targeted critical infrastructure sectors worldwide. Organizations must bolster their cybersecurity defenses to mitigate the risks associated with such sophisticated attacks.
5 months ago
Kill Chain
Salt Typhoon 2025: Unveiling the Global Espionage Campaign
In 2025, the Chinese state-sponsored cyber group known as Salt Typhoon orchestrated a sophisticated global espionage campaign, compromising government and critical infrastructure across 37 countries and conducting reconnaissance in 155 nations. The attackers exploited unpatched vulnerabilities in networking equipment, including those from Ivanti, Palo Alto, and Cisco, to gain initial access. Once inside, they established persistent access by modifying access control lists, creating privileged accounts, and enabling remote management on unusual high ports. This allowed them to monitor communications, harvest administrator credentials, and exfiltrate sensitive data through covert tunnels, all while remaining undetected for extended periods. The campaign's targets included telecommunications networks, government systems, transportation hubs, lodging networks, and military infrastructure, enabling continuous surveillance of individuals, communications, and movements globally. ([forbes.com](https://www.forbes.com/sites/emilsayegh/2025/08/30/us-and-allies-declare-salt-typhoon-hack-a-national-defense-crisis/?utm_source=openai)) The Salt Typhoon campaign underscores the escalating threat posed by state-sponsored cyber actors and the vulnerabilities within critical infrastructure. The attackers' ability to exploit known vulnerabilities and maintain long-term access highlights the urgent need for organizations to prioritize timely patching, robust access controls, and comprehensive monitoring to detect and mitigate such sophisticated threats.
5 months ago
Kill Chain
Critical Vulnerability in RISS SRL MOMA Seismic Station Firmware (CVE-2026-1632)
In February 2026, a critical vulnerability (CVE-2026-1632) was identified in RISS SRL's MOMA Seismic Station firmware versions up to and including v2.4.2520. The flaw exposes the device's web management interface without requiring authentication, allowing unauthenticated attackers to modify configuration settings, access sensitive data, or remotely reset the device. This vulnerability poses significant risks to seismic monitoring operations, potentially leading to data manipulation, unauthorized data access, and operational disruptions. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1632?utm_source=openai)) The absence of authentication mechanisms in critical infrastructure devices underscores the urgent need for robust security measures in industrial control systems. As cyber threats targeting operational technology (OT) environments increase, organizations must prioritize securing their OT assets to prevent potential exploitation and ensure the integrity of essential services.
5 months ago
Kill Chain
Critical Vulnerability in Avation Light Engine Pro Exposes Systems to Unauthorized Access
In February 2026, a critical vulnerability (CVE-2026-1341) was identified in Avation's Light Engine Pro devices, which are widely deployed in commercial facilities worldwide. The flaw involves the exposure of the device's configuration and control interface without any authentication or access control, potentially allowing unauthorized users to gain full control over the device. This vulnerability poses significant risks, including unauthorized access, data manipulation, and potential disruption of operations. ([itsecuritynews.info](https://www.itsecuritynews.info/avation-light-engine-pro/?utm_source=openai)) The absence of authentication mechanisms in critical infrastructure devices underscores the urgent need for robust security measures. Organizations must prioritize the implementation of authentication protocols and access controls to safeguard against such vulnerabilities, especially in devices integral to operational technology environments.
5 months ago
Kill Chain
Critical Vulnerability in Mitsubishi Electric's FREQSHIP-mini: CVE-2025-10314
In February 2026, Mitsubishi Electric disclosed a critical vulnerability (CVE-2025-10314) in its FREQSHIP-mini for Windows software, versions 8.0.0 to 8.0.2. The flaw arises from incorrect default permissions during installation, allowing local attackers to replace service executables or DLLs with malicious files. Exploiting this vulnerability enables arbitrary code execution with SYSTEM privileges, potentially leading to unauthorized access, data manipulation, or denial-of-service conditions. This vulnerability is particularly concerning for critical infrastructure sectors, including manufacturing and energy, where FREQSHIP-mini is commonly deployed. Organizations are urged to update to version 8.1.0 or later and implement recommended mitigation measures to prevent exploitation. ([jvn.jp](https://jvn.jp/en/jp/JVN64883963/?utm_source=openai))
5 months ago
Kill Chain
Critical Unauthenticated Access Vulnerability in Synectix LAN 232 TRIO
In February 2026, a critical vulnerability (CVE-2026-1633) was identified in the Synectix LAN 232 TRIO 3-Port serial to Ethernet adapter. This flaw allows unauthenticated users to access the device's web management interface, enabling them to modify critical settings or perform a factory reset. The vulnerability has a CVSS score of 10.0, indicating maximum severity. Synectix is no longer in business, leaving the affected devices without official support or patches. ([securityonline.info](https://securityonline.info/unpatchable-critical-cisa-issues-cvss-10-0-alert-for-synectix-adapters/?utm_source=openai)) This incident underscores the risks associated with using unsupported legacy devices in critical infrastructure. Organizations must proactively identify and replace such equipment to mitigate potential security threats. ([securityonline.info](https://securityonline.info/unpatchable-critical-cisa-issues-cvss-10-0-alert-for-synectix-adapters/?utm_source=openai))
5 months ago
Kill Chain
Poland's Energy Sector Cyberattack: A Wake-Up Call for Critical Infrastructure Security
On December 29, 2025, coordinated cyberattacks targeted over 30 wind and photovoltaic farms, a manufacturing company, and a large combined heat and power plant in Poland. The attacks, attributed to the Russian state-sponsored group Static Tundra (also known as Berserk Bear or Dragonfly), aimed to disrupt energy infrastructure by deploying wiper malware designed to destroy data and disable systems. While the attacks caused communication disruptions, they did not interrupt energy production or heat supply to consumers. ([cert.pl](https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/?utm_source=openai)) This incident underscores the escalating threat of nation-state cyberattacks on critical infrastructure, highlighting the need for enhanced cybersecurity measures and international cooperation to protect essential services from sophisticated adversaries.
5 months ago
Kill Chain
Critical Vulnerability in iba Systems ibaPDA Exposes Industrial Systems to Unauthorized Access
In January 2026, a critical vulnerability (CVE-2025-14988) was identified in iba Systems' ibaPDA software, version 8.12.0. This flaw allowed unauthorized actions on the file system, potentially compromising the confidentiality, integrity, and availability of affected systems. The vulnerability was reported by Siemens and disclosed by CISA on January 27, 2026. ([iba-ag.com](https://www.iba-ag.com/en/security/iba-2025-04?utm_source=openai)) Given ibaPDA's widespread use in critical manufacturing sectors worldwide, this vulnerability posed significant risks to industrial operations. Organizations were urged to update to version 8.12.1 or later to mitigate potential exploitation. ([iba-ag.com](https://www.iba-ag.com/en/security/iba-2025-04?utm_source=openai))
5 months ago
Kill Chain
Rockwell Automation's ArmorStart LT Vulnerabilities: A Wake-Up Call for Industrial Security
In January 2026, Rockwell Automation disclosed multiple vulnerabilities in its ArmorStart® LT motor control devices, specifically models 290D, 291D, and 294D up to and including version V2.002. These vulnerabilities, identified as CVE-2025-9464 through CVE-2025-9283, can lead to denial-of-service conditions. Exploitation methods include fuzzing of CIP classes, execution of Achilles Comprehensive grammar tests, and active scanning with tools like Burp Suite, causing devices to become unresponsive or reboot unexpectedly. ([rockwellautomation.com](https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html?utm_source=openai)) The affected devices are widely used in the critical manufacturing sector globally. As of the disclosure, no patches or upgrades were available. Rockwell Automation recommends applying security best practices to mitigate risks, such as minimizing network exposure, placing devices behind firewalls, and using secure remote access methods like VPNs. ([rockwellautomation.com](https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html?utm_source=openai))
5 months ago
Kill Chain
Sandworm's DynoWiper Targets Poland's Energy Sector in 2025 Cyberattack
In late December 2025, Poland's energy infrastructure was targeted by a cyberattack involving a data-wiping malware named DynoWiper. The attack aimed to disrupt operations at two combined heat and power plants and several renewable energy facilities. ESET researchers attributed the attack to the Russian state-sponsored group Sandworm, noting similarities to previous incidents involving the group. Fortunately, the malware was intercepted before causing any substantial damage, and no operational disruptions were reported. ([welivesecurity.com](https://www.welivesecurity.com/en/eset-research/eset-research-sandworm-cyberattack-poland-power-grid-late-2025/?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors to critical infrastructure. The timing, coinciding with the tenth anniversary of Sandworm's first known assault on Ukraine’s power grid in 2015, highlights the group's continued focus on energy sector targets and disruptive operations. ([welivesecurity.com](https://www.welivesecurity.com/en/eset-research/eset-research-sandworm-cyberattack-poland-power-grid-late-2025/?utm_source=openai))
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports