✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Utilities
Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.
Explore Other Sectors
Utilities Threat Reports
ShadowV2 Botnet Turns AWS Outage into Opportunity: 2024 IoT and Hybrid Cloud Attacks Surge
In June 2024, a new botnet malware known as ShadowV2 emerged, leveraging Mirai source code to target IoT devices, particularly from D-Link and TP-Link, exploiting known vulnerabilities for large-scale infection. Security researchers observed the malware operators using the widespread AWS outage as an opportunity to test command and control resilience, evade detection, and enhance lateral spread across hybrid and cloud networks. Initial access occurred via unpatched vulnerabilities in internet-facing devices, leading to rapid compromise and recruitment of thousands of endpoints, posing heightened risks to corporate and critical infrastructure systems. Detection was challenged by the use of encrypted and east-west traffic, with attackers adapting quickly to shifting network topologies. This incident highlights the increasing sophistication of IoT-focused botnets and their opportunistic exploitation of cloud service disruptions. Organizations with hybrid or cloud-connected assets are strongly urged to reassess east-west traffic controls, segmentation, and anomaly detection, as automated threats now more readily exploit both vulnerable devices and network instability.
6 months ago
Kill Chain
Comcast Fined After 2024 Vendor Data Breach Hits 270,000 Customers
In February 2024, Comcast, one of the largest U.S. telecommunications providers, suffered a significant data breach due to a third-party vendor's security lapse. The incident resulted in unauthorized access to the personally identifiable information (PII) of nearly 275,000 Comcast customers. Exposed data included names, addresses, and partial account credentials. The breach was traced to vulnerabilities in the vendor's security infrastructure, highlighting risks posed by supply chain and vendor relationships. Following the breach, the Federal Communications Commission fined Comcast $1.5 million as part of its investigation into the company's responsibilities and controls over customer data. This case underscores the persistent and growing threat of supply chain breaches, which are increasingly targeted by cyber adversaries seeking to exploit trust relationships between organizations and their service providers. Regulatory bodies are intensifying scrutiny and penalties around third-party risk management following a pattern of similar high-impact incidents.
6 months ago
Kill Chain
How Online Formatting Tools Exposed Thousands of Credentials: The JSONFormatter & CodeBeautify Leak
In late 2025, researchers uncovered that thousands of sensitive credentials, including passwords and API keys from governments, telecoms, and critical infrastructure organizations, were exposed after being pasted into public web-based code formatting tools such as JSONFormatter and CodeBeautify. This inadvertent data exposure occurred over several years, as users leveraged these tools for convenience, unaware that information was being logged and stored without proper security. Security experts at watchTowr Labs discovered over 80,000 files containing this data, raising alarm over the significant risk posed to organizations relying on manual and unsecured workflows. This incident has highlighted the growing risks of shadow IT and insecure use of web utilities in enterprise environments. It mirrors a broader trend of misconfigured third-party tools creating substantial vulnerabilities, elevating concerns amid regulatory crackdowns and increased exploitation of exposed secrets by attackers.
6 months ago
Kill Chain
Zenitel TCIV-3+ 2025: Critical ICS Vulnerabilities Enable Remote Attacks
In November 2025, Zenitel disclosed multiple critical vulnerabilities affecting its TCIV-3+ intercom systems, widely deployed in communications-critical infrastructure worldwide. Security researchers from Claroty Team82 identified three separate OS command injection flaws (CVE-2025-64126, -64127, -64128), as well as a severe out-of-bounds write and a reflected cross-site scripting vulnerability. These issues allowed threat actors to remotely execute arbitrary code or cause denial-of-service conditions without authentication, putting operational technology environments at significant risk of disruption or compromise. The vulnerabilities require only low-complexity attacks and no user interaction, amplifying their business impact. This incident highlights the ongoing critical importance of securing industrial control system components exposed to remote exploitation. With threat actors increasingly targeting IoT and OT devices in critical communications infrastructure, these types of vulnerabilities are seeing a dramatic rise globally, and patching urgency is at an all-time high.
6 months ago
Kill Chain
SiRcom Vulnerability Exposes Critical Siren Systems to Hijack (2025)
In November 2025, a critical vulnerability (CVE-2025-13483) was disclosed in SiRcom SMART Alert (SiSA), a central emergency alert management system used globally in emergency services, government, and defense sectors. The flaw, due to missing authentication for critical API functions, enabled unauthenticated attackers to access restricted backend operations. Successful exploitation could allow remote manipulation and activation of emergency sirens, posing wide-reaching operational and safety risks to affected communities. The vulnerability, assigned a CVSS v4 score of 8.8, was initially reported by Microsec researcher Souvik Kandar. This incident highlights the persistent risks posed by missing authentication in critical infrastructure applications. With remote exploitation possible and attackers’ interest in manipulating physical environments on the rise, it underscores the urgent need for robust authentication, especially amid compliance and regulatory tightening in the critical infrastructure sector.
6 months ago
Kill Chain
Opto 22 groov View: 2025 ICS Vulnerability Exposes API Keys & Credentials
In November 2025, Opto 22 disclosed a critical vulnerability (CVE-2025-13084) affecting its groov View industrial control platform, impacting versions of groov View Server for Windows and GRV-EPIC firmware. Security researchers from Meta identified that the API's users endpoint could inadvertently expose all user metadata, including API keys and credentials—even those for administrator accounts—when accessed by users with Editor privileges. Although exploitation requires already having Editor-level access, a successful attack could result in full privilege escalation, credential compromise, and unauthorized access across critical manufacturing environments worldwide. This incident highlights ongoing risks in industrial control systems (ICS) where sensitive data is exposed through insufficient API controls. The breach underscores the rising importance of strict segmentation, encrypted traffic management, and proactive patch management in ICS environments, especially as remote exploitation and metadata exposure attacks become more common.
6 months ago
Kill Chain
CISA Exposes Multi-Vendor ICS Vulnerabilities: 2025 Critical Infrastructure Security Alert
In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA) issued six critical advisories revealing vulnerabilities across various Industrial Control Systems (ICS) devices, including those from Automated Logic, ICAM365, Opto 22, Festo, and Emerson. Attackers could exploit these flaws—ranging from weak authentication to remote code execution—potentially enabling unauthorized access, data exfiltration, or disruption of operational technology environments. ICS operators were urged to review technical details and partner with vendors for rapid mitigation to prevent lateral movement or credential compromise impacting essential infrastructure. This incident highlights the growing convergence of operational technology and IT risk, with threat actors increasingly targeting ICS environments. The regulatory and threat landscape is evolving, compelling organizations to strengthen segmentation, network monitoring, and zero trust security controls in light of rising attacks on critical infrastructure.
6 months ago
Kill Chain
Critical UPS Vulnerability: Emerson Appleton UPSMON-PRO Flaw Exposes ICS to Remote Attacks
In November 2025, a critical vulnerability (CVE-2024-3871) was disclosed affecting Emerson's Appleton UPSMON-PRO, a monitoring solution widely deployed in critical infrastructure sectors including manufacturing and healthcare. Security researchers found that remotely sent, specially crafted UDP packets could trigger a stack-based buffer overflow, granting attackers SYSTEM-level privileges and permitting remote code execution on unpatched systems. The product, which reached End of Life status prior to disclosure, is still in use across several organizations, amplifying the impact of the vulnerability on global operational technology environments. This incident underscores a growing pattern of legacy ICS software vulnerabilities being targeted via low-complexity, remote attacks. Increased regulatory scrutiny and the advancing sophistication of attackers elevate the importance of updating unsupported systems and implementing defense-in-depth strategies.
6 months ago
Kill Chain
Critical OS Command Injection Vulnerability Hits Opto 22 ICS Devices in 2025
In November 2025, Opto 22 announced a critical vulnerability (CVE-2025-13087) affecting its GRV-EPIC and groov RIO programmable logic controllers. Discovered by security researchers from Meta, the flaw resides in the Groov Manage REST API, allowing attackers with administrative access to exploit improper neutralization of special elements and execute arbitrary shell commands as root on affected devices. This vulnerability places manufacturing environments deploying these controllers at risk of remote code execution and potential full device compromise, particularly in critical infrastructure operations worldwide. The incident highlights the continued targeting of industrial control systems by security researchers and underscores the urgency for timely patching in operational technology (OT) environments. With attackers increasingly seeking entry via API abuse and elevated privileges, organizations must remain vigilant against growing threats to cloud-connected OT and IIoT assets.
6 months ago
Kill Chain
Cloud Firewall Flaws Lead to Widespread IoT Takeovers in 2024
In early 2024, security researchers uncovered a critical cloud misconfiguration enabling silent takeover of internet-connected IoT devices by exploiting gaps in firewall and router management interfaces. Attackers, leveraging lax default policies and insufficient segmentation in multi-cloud environments, gained unauthorized access to endpoints despite security software being in place. The exploit did not require the devices to be directly connected to the public internet—instead, it relied on weaknesses within cloud firewall interfaces and poor east-west traffic controls, allowing attackers to pivot laterally and compromise large numbers of devices with little to no detection. The resulting impact includes device disruption, risk of data exfiltration, and potential staging for larger attacks. This incident comes amid a surge in attacks against IoT and operational technology, with adversaries increasingly targeting missteps in cloud security architectures rather than application-level flaws. The trend underscores the urgency for organizations to implement multi-layered segmentation, robust policy enforcement, and continuous cloud configuration monitoring to defend against rapidly-evolving lateral movement tactics.
6 months ago
Kill Chain
PowerChute ICS Flaws: Schneider Electric 2025 Vulnerabilities Expose Critical Manufacturing
In November 2025, Schneider Electric disclosed multiple vulnerabilities affecting PowerChute Serial Shutdown version 1.3 and earlier, widely deployed in critical manufacturing. The flaws, reported by security researcher Aleksandar Djurdjevic, include a path traversal (CVE-2025-11565), improper authentication attempt controls (CVE-2025-11566), and insecure default permissions (CVE-2025-11567). Successful exploitation could allow attackers on the local network to gain user or system access, potentially compromising operational technology environments. Immediate mitigation involved updating to version 1.4, securing folder permissions, and implementing network isolation practices to reduce exposure. This incident highlights growing risks to industrial control systems amid increasing convergence of IT/OT and heightened attacker focus on supply chain and infrastructure software weaknesses. Regulatory and business pressures mount as organizations strive to bolster segmentation, logging, and zero trust practices to avoid costly operational disruptions and compliance failures.
6 months ago
Kill Chain
Critical 2025 METZ CONNECT EWIO2 Vulnerabilities: Auth Bypass and RCE Expose Industrial Control Risks
In November 2025, multiple critical vulnerabilities were disclosed in METZ CONNECT EWIO2 industrial control devices, enabling remote attackers to bypass authentication and gain full control, execute arbitrary code, and read sensitive device information. The flaws include authentication bypass (CVE-2025-41733), PHP remote file inclusion (CVE-2025-41734), unrestricted file upload (CVE-2025-41735), path traversal (CVE-2025-41736), and improper access control (CVE-2025-41737), with CVSS v4 scores ranging from 8.7 to 9.3. Affected devices are used globally in critical manufacturing environments, and exploitation could trigger operational disruption or unauthorized control. This incident is highly relevant as it targets the operational technology (OT) sector—a high-value, often less-protected attack surface increasingly sought after by threat actors. As convergence between IT and OT grows, unpatched, internet-exposed devices in critical infrastructure remain susceptible to devastating attacks, underscoring urgent need for robust patching, segmentation, and proactive defense.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports