✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Utilities
Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.
Explore Other Sectors
Utilities Threat Reports
Russian Nation-State Hackers Breach Critical Infrastructure via Edge Device Flaws
In early 2024, Russian-linked APT actors launched a prolonged cyberattack campaign targeting critical infrastructure organizations globally, with a particular focus on the energy sector. Leveraging misconfigured edge networking devices, attackers gained initial access to internal networks, allowing them to perform lateral movement and conduct espionage on sensitive operational systems. The campaign, detailed by Amazon's security division, utilized unencrypted management traffic, enabling threat actors to intercept data-in-transit and issue command-and-control instructions undetected. Widespread exploitation resulted in data exfiltration, system compromise, and operational disruptions for affected organizations. This incident highlights a surge in advanced persistent threats exploiting basic configuration weaknesses in edge devices. The continued targeting of critical sectors by nation-state actors underscores the urgent need for stronger segmentation, encrypted network traffic, and improved detection capabilities, as attackers are increasingly adept at bypassing conventional perimeter defenses.
6 months ago
Kill Chain
2025 Ransomware Attack Disrupts Venezuela’s State Oil Giant PDVSA
In December 2025, Petróleos de Venezuela (PDVSA), Venezuela’s national oil and gas company, experienced a significant ransomware attack that targeted its administrative systems. While official company communications downplayed the incident and attributed blame to international adversaries, media reports indicated substantial disruption: the attack resulted in major outages, took down vital IT systems, impacted cargo deliveries, and forced network disconnections. Efforts to remediate using antivirus software exacerbated downtime, and export activities, including loading instructions, were suspended. The incident highlighted operational fragility due to reliance on legacy infrastructure and a lack of segmentation between administrative and critical operational technologies. This breach spotlights the ongoing wave of ransomware attacks targeting energy and critical infrastructure sectors worldwide. It underscores how geopolitically charged environments, and legacy technologies without zero trust segmentation, remain especially vulnerable. The incident serves as a stark warning for the urgent adoption of robust east-west traffic controls and resilient response playbooks to mitigate emerging ransomware TTPs.
6 months ago
Kill Chain
Sandworm Shifts Tactics: How Misconfigured AWS Edge Devices Enabled State Espionage in 2025
In early 2025, Amazon Threat Intelligence disclosed a sustained campaign by Russia's GRU-linked Sandworm (APT44) targeting Western critical infrastructure, with a focus on the energy sector. The threat actors shifted tactics from exploiting software vulnerabilities to exploiting misconfigured network edge devices hosted on AWS as their primary entry vector. Once inside, attackers intercepted sensitive network traffic to steal credentials and leveraged these to expand and maintain access across enterprise and critical infrastructure environments, including electric utilities, energy providers, and managed security providers. Remediation included notification of affected customers, removal of compromised AWS EC2 instances, and intelligence sharing with partners. This incident marks a concerning evolution in nation-state attack tradecraft: adversaries are prioritizing misconfigurations over traditional exploits, highlighting the need for organizations to reassess cloud and hybrid network security. The prevalence of cloud-hosted infrastructure increases urgency around identity and segmentation defenses.
6 months ago
Kill Chain
Venezuelan Oil Giant PDVSA Hit by Cyberattack—Exports Disrupted in 2024 Incident
In June 2024, Petróleos de Venezuela S.A. (PDVSA), Venezuela’s state-owned oil giant, suffered a major cyberattack that disrupted its oil export operations. Attackers reportedly targeted IT infrastructure critical to the export scheduling and operational logistics of PDVSA, forcing the company to revert to manual processes while systems were restored. Although the precise entry vector and threat actor remain unconfirmed, preliminary indications suggest ransomware or disruptive malware may have played a role, leading to significant business interruption and delayed global shipments. This incident underscores the persistent risks facing critical infrastructure sectors worldwide, with cyberattacks increasingly targeting essential energy supply chains. With ransomware and nation-state threats evolving in sophistication, organizations must urgently prioritize segmentation, threat detection, and resilient network architectures.
6 months ago
Kill Chain
Amazon Stops Russian GRU Hackers Targeting Cloud Edge Devices in 2025
In December 2025, Amazon's Threat Intelligence team thwarted a sophisticated cyber-espionage campaign attributed to the Russian GRU, which actively targeted Western critical infrastructure via AWS cloud environments. Beginning in 2021 and intensifying through 2025, the threat actors transitioned from exploiting known and zero-day vulnerabilities to targeting misconfigured customer-managed edge devices such as VPN gateways and network appliances hosted on EC2. This allowed them to gain persistent access, harvest credentials, and move laterally within networks, yet there was no compromise of AWS's own infrastructure. Amazon responded rapidly by securing affected instances, notifying customers, and sharing threat intelligence with partners. This incident highlights the growing trend of state-sponsored groups shifting from vulnerability exploitation to leveraging customer misconfigurations. The persistent focus on edge devices underscores the importance of robust configuration and monitoring practices, especially as critical infrastructure organizations move sensitive operations into the cloud.
6 months ago
Kill Chain
Amazon Reveals Years-Long GRU Cyber Espionage on Critical Cloud & Energy Infrastructure
Between 2021 and 2025, Amazon's threat intelligence team uncovered a multi-year cyber campaign attributed to Russia's Main Intelligence Directorate (GRU), specifically associated with APT44/Sandworm. The attackers targeted Western energy sector organizations, critical infrastructure providers, and cloud-hosted network environments by exploiting vulnerabilities and, increasingly, leveraging misconfigured network edge devices. This facilitated credential interception and lateral movement through persistent network access, with efforts focused on credential harvesting and replay against victim organizations. Amazon responded by notifying affected customers and disrupting active operations, limiting further impact. This incident underscores the sophistication and persistence of nation-state actors in targeting vital infrastructure by adapting TTPs to minimize exposure. The campaign signals an urgent shift towards exploiting cloud and network misconfigurations rather than relying solely on zero-day vulnerabilities—a trend that broadens risk for organizations across sectors.
6 months ago
Kill Chain
Critical RADIUS MD5 Vulnerability Exposes Hitachi Energy Infrastructure — 2025 Analysis
In December 2025, Hitachi Energy disclosed a critical vulnerability (CVE-2024-3596) impacting their AFS, AFR, and AFF series infrastructure hardware, widely deployed in the global energy sector. The issue centers on improper enforcement of message integrity in RADIUS communications, allowing attackers in a local network to exploit a chosen-prefix collision attack against the MD5 response authenticator. This could let a malicious actor forge RADIUS authentication responses — potentially leading to unauthorized network access, disruption of critical systems, or exfiltration of sensitive data. The flaw carries a CVSS score of 9.0 (critical), but exploitation requires high attack complexity. This case highlights the continued risks posed by legacy authentication protocols and cryptographic weaknesses within operational technology environments. As adversaries increasingly target energy and critical infrastructure supply chains, prioritizing secure authentication and traffic integrity mechanisms is vital to maintaining resilience and regulatory compliance.
6 months ago
Kill Chain
Mitsubishi Electric's GT Designer3 Vulnerability (2025): Cleartext Credentials Endanger Industrial Systems
In December 2025, Mitsubishi Electric disclosed a vulnerability (CVE-2025-11009) impacting their GT Designer3 software, widely used in industrial control panel applications. Security researchers at Red Alert Lab discovered that plaintext credentials were being stored in project files, exposing critical manufacturing assets worldwide to potential unauthorized access. Although successful exploitation requires local access and has a high attack complexity, an attacker could obtain plaintext credentials to operate GOT2000 or GOT1000 series devices maliciously, raising risks for organizations with misconfigured networks or insufficient access controls. This incident highlights the persistent risk of cleartext credential exposures in operational technology, an issue often underestimated in critical infrastructure. With incidents involving credential theft and unauthorized device control on the rise, compliance frameworks and supply chain partners are placing increased urgency on eliminating weak storage practices in industrial environments.
6 months ago
Kill Chain
CISA Issues 2025 Industrial Control System Vulnerability Advisories
In December 2025, CISA disclosed six critical advisories highlighting a series of vulnerabilities across multiple industrial control system (ICS) products, including those from Güralp Systems, Johnson Controls, Hitachi Energy, Mitsubishi Electric, and Fuji Electric. The advisories detail software and firmware flaws that could allow unauthorized access, remote code execution, or complete system compromise in essential ICS devices. Exploitation could give attackers the means to disrupt critical infrastructure operations. Security teams are urged to apply mitigations, restrict network exposure, and follow vendor instructions to reduce risk. This incident underscores the growing frequency and severity of cybersecurity threats targeting ICS environments. With the expanding attack surface in operational technology (OT) networks, attackers increasingly focus on exploiting ICS vulnerabilities to disrupt important sectors. Regulators and asset owners are under pressure to implement robust, up-to-date defenses.
6 months ago
Kill Chain
CISA Orders Feds to Patch Active GeoServer XXE Vulnerability Exploitation
In June 2024, U.S. federal agencies were ordered by CISA to immediately patch a critical vulnerability in GeoServer, an open-source geospatial server widely deployed across government networks. Threat actors were observed actively exploiting an XML External Entity (XXE) injection flaw that allows attackers to access sensitive files, exfiltrate data, and potentially pivot within federal environments. The exploitation, which was discovered in the wild, underscores how quickly attackers can weaponize unpatched vulnerabilities to compromise mission-critical public sector infrastructure, putting sensitive government information at risk. This incident highlights a recent spike in the exploitation of internet-facing open-source software by both cybercriminal and nation-state groups. With regulatory pressure mounting around software supply chain risks and zero-day response times, such vulnerabilities remain a primary vehicle for initial access in sophisticated cyberattacks.
6 months ago
Kill Chain
CISA Flags Critical GeoServer XXE Vulnerability Exploited in the Wild
In December 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical XML External Entity (XXE) vulnerability, CVE-2025-58360, affecting OSGeo GeoServer to its Known Exploited Vulnerabilities catalog. This flaw impacts versions up to 2.25.5 and select subsequent releases, enabling unauthenticated attackers to exploit the /geoserver/wms GetMap endpoint. Successful exploitation may lead to unauthorized file access, Server-Side Request Forgery (SSRF), or denial-of-service attacks. The discovery, reported by vulnerability platform XBOW, has prompted warnings from both CISA and the Canadian Centre for Cyber Security, emphasizing risks to organizations using GeoServer in production environments. This incident underscores the persistent targeting of widely-used open-source tools by threat actors, particularly through unauthenticated exploit paths. Amid increased regulatory focus and real-world exploitation evidence, organizations face mounting pressure to patch vulnerable infrastructure and strengthen detective controls to mitigate post-exploitation impacts.
6 months ago
Kill Chain
How Zigbee Protocol Flaws Exposed Industrial IoT Networks in 2024
In early 2024, security researchers uncovered critical vulnerabilities affecting Zigbee-based industrial IoT and automation environments. By assessing real-world installations, attackers demonstrated how both spoofed packet injection and coordinator impersonation attacks could exploit application-layer protocol weaknesses and misconfigurations. Notably, exposed or hard-coded keys, absence of end-to-end encryption, and insecure default settings enabled adversaries to hijack communications, control relay devices, and ultimately compromise entire sensor networks. The attack techniques bypassed traditional network segmentation and leveraged custom wireless tools to overcome timing and profile mismatches. This incident highlights urgent gaps in IoT and industrial security — especially the risks posed by legacy or proprietary protocol deployments lagging on best-practice cryptographic implementation. With industrial sectors increasingly reliant on automated sensor networks, attackers are expanding TTPs to target low-power wireless protocols like Zigbee, making advanced monitoring and zero trust approaches more critical than ever.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports