The Containment Era is here. →Explore

Industry Category

Utilities

Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.

388 threat reports
Page 29 of 33

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Utilities Threat Reports

Showing 337348 / 388 reports
Critical Flaws in General Industrial Controls Lynx+ Gateway Threaten Manufacturing Security (2025)
Impact· high

Critical Flaws in General Industrial Controls Lynx+ Gateway Threaten Manufacturing Security (2025)

In November 2025, critical vulnerabilities were discovered in General Industrial Controls' Lynx+ Gateway devices deployed worldwide across the critical manufacturing sector. The exposed flaws—included weak password requirements, missing authentication for critical functions, and cleartext transmission of sensitive information—allowed attackers to remotely access devices, obtain sensitive information, and, in some cases, potentially cause denial-of-service conditions. Multiple CVEs (CVE-2025-55034, CVE-2025-58083, CVE-2025-59780, CVE-2025-62765) were assigned, with the highest CVSS v4 base score reaching 9.2. Despite coordinated disclosure efforts, the vendor did not respond, leaving organizations reliant on their own layered defense measures. This incident is highly relevant as it highlights persistent challenges in secure authentication and encrypted traffic within operational technology environments. The surge in attacks exploiting similar unauthenticated remote access and cleartext weaknesses continues to drive regulatory pressure for zero trust and encryption controls within industrial networks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Siemens Altair Grid Engine 2025: Local Privilege Escalation and OT Vulnerability Risks
Impact· medium

Siemens Altair Grid Engine 2025: Local Privilege Escalation and OT Vulnerability Risks

In November 2025, Siemens disclosed two local privilege escalation vulnerabilities affecting all versions of Altair Grid Engine prior to V2026.0.0. These flaws, identified as CVE-2025-40760 (Generation of Error Message Containing Sensitive Information) and CVE-2025-40763 (Uncontrolled Search Path Element), could allow attackers with local access to extract password hashes or execute arbitrary code with superuser permissions by manipulating environment variables or error handling processes. Although there has been no evidence of exploitation in the wild, the vulnerabilities required only low attack complexity and affected critical manufacturing environments globally. This incident highlights ongoing risks posed by improper input validation and error handling in operational technology (OT) environments, especially as attackers increasingly target privilege escalation vectors. Regulatory bodies emphasize swift detection, patching, and IT/OT segmentation to reduce attack surface, as local escalation flaws remain a persistent threat vector in critical infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Siemens COMOS 2025: Critical Software Vulnerabilities in Industrial Control Systems
Impact· low

Siemens COMOS 2025: Critical Software Vulnerabilities in Industrial Control Systems

In November 2025, Siemens disclosed critical software vulnerabilities affecting its COMOS platform, widely used in the industrial and critical manufacturing sectors. The flaws—specifically, an incomplete list of disallowed inputs and cleartext transmission of sensitive information—enabled remote attackers with low attack complexity to execute arbitrary code or intercept data. The affected versions were COMOS releases prior to 10.4.5, with potential for unauthorized access, data infiltration, or broader operational disruptions across global deployments. Siemens ProductCERT identified and reported the vulnerabilities, issuing patches and urging immediate upgrades and network protections. This incident is highly relevant given the increasing threats to industrial control systems and the persistent exploitation of software supply chain vulnerabilities. The convergence of IT and OT environments means that unresolved vulnerabilities like these present heightened risks in critical infrastructure, drawing attention from regulators and advanced cyber attackers alike.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Critical ICS Vulnerabilities in Siemens SICAM P850/P855 Devices Impact Energy Sector
Impact· low

Critical ICS Vulnerabilities in Siemens SICAM P850/P855 Devices Impact Energy Sector

In November 2025, Siemens disclosed vulnerabilities affecting their SICAM P850 and P855 industrial control device families. Specifically, these products were susceptible to a Cross-Site Request Forgery (CSRF) flaw and incorrect permission assignment for critical resources, allowing attackers to execute unauthorized actions or impersonate users. The weaknesses impacted devices globally deployed in energy-critical infrastructure, with the main risk being attackers exploiting web sessions to modify device configuration or gain prolonged unauthorized access. Siemens ProductCERT identified the issues, which could be exploited remotely with low attack complexity, scoring up to 5.5 CVSS. This incident highlights growing concerns over ICS (Industrial Control Systems) vulnerabilities due to their essential role in critical infrastructure and the rising sophistication of exploitation tactics targeting web interfaces. The disclosure underscores the need for proactive patch management and access restrictions amid evolving regulatory and threat environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Rockwell Automation SIS Workstation Vulnerability Exposes Critical Manufacturing
Impact· low

Rockwell Automation SIS Workstation Vulnerability Exposes Critical Manufacturing

In November 2025, Rockwell Automation disclosed a critical path traversal vulnerability (CVE-2024-48510) in its AADvance-Trusted SIS Workstation software, impacting versions 2.00.00 to 2.00.04. The flaw stems from improper validation in the DotNetZip component, enabling remote attackers to execute arbitrary code if a victim opens a malicious file. This issue poses significant risks to critical manufacturing systems worldwide, potentially allowing adversaries to compromise safety instrumented system environments. Rockwell has released a patch in version 2.01.00 to address the flaw. This vulnerability is particularly noteworthy due to its low attack complexity, remote exploitability, and potential for widespread impact across global critical infrastructure. The incident underscores ongoing supply chain risks in industrial software and the urgent need for timely patching, robust endpoint security, and defense-in-depth strategies for operational technology (OT) environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Critical Siemens LOGO! 8 Vulnerabilities Put Global ICS at Risk
Impact· high

Critical Siemens LOGO! 8 Vulnerabilities Put Global ICS at Risk

In November 2025, Siemens disclosed multiple critical vulnerabilities affecting its LOGO! 8 BM Devices, widely deployed in global commercial facilities and transportation systems. Security researchers from Thales Cybersecurity Services Australia identified flaws enabling unauthenticated remote attackers to exploit classic buffer overflow and missing authentication vulnerabilities. These flaws could allow malicious actors to execute arbitrary code, disrupt device operations via denial-of-service, or modify critical device parameters such as IP address and time settings, potentially impacting industrial operations. The incident underscores growing concerns about the security posture of industrial control systems (ICS), as attackers increasingly target remote management features lacking modern authentication. With regulatory scrutiny intensifying and attackers exploiting similar flaws in operational technology, organizations must prioritize ICS security and proactive patch management to reduce exposure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical Infrastructure Active Directory Breach Highlights the Need for Zero Trust Controls
Impact· medium

Critical Infrastructure Active Directory Breach Highlights the Need for Zero Trust Controls

In October 2025, a coordinated threat campaign targeted the Active Directory environment of a major North American critical infrastructure provider. Attackers exploited vulnerabilities in legacy on-premises and misconfigured cloud authentication bridges to gain initial access, leveraging unencrypted internal traffic and credential harvesting tools. By establishing persistence inside hybrid systems, they used lateral movement techniques to escalate privileges, eventually exfiltrating sensitive operational and personal data. The attack briefly disrupted authentication services, causing operational outages and impacting supply chain partners reliant on secure access. Regulators and cyber response teams were engaged, intensifying scrutiny of infrastructure identity security. This incident underscores how attackers increasingly target hybrid and cloud-integrated identity platforms like Active Directory, exploiting gaps in east-west traffic security and multifactor enforcement. As ransomware and nation-state campaigns leverage similar methods, the urgency for zero trust segmentation, encrypted traffic, and strong policy enforcement within hybrid infrastructure has never been greater.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Advantech DeviceOn/iEdge 2025: Multiple Path Traversal and XSS Vulnerabilities Threaten IoT Security
Impact· medium

Advantech DeviceOn/iEdge 2025: Multiple Path Traversal and XSS Vulnerabilities Threaten IoT Security

In November 2025, security researchers disclosed multiple critical vulnerabilities in Advantech’s DeviceOn/iEdge IoT management platform, affecting version 2.0.2 and earlier. Among the vulnerabilities were improper input handling flaws including cross-site scripting (CVE-2025-64302) and several variants of path traversal (CVE-2025-62630, CVE-2025-59171, CVE-2025-58423), which could allow remote attackers to gain unauthorized access, execute arbitrary code, trigger denial-of-service conditions, or read sensitive files. No public exploitation has been reported, but the potential risks span information leakage and remote code execution, with system-level impact possible from authenticated and unauthenticated attackers. This incident is particularly relevant as IoT management and industrial control environments remain popular targets for exploitation of legacy systems, which often lack timely security updates. With operational continuity and data integrity at risk, organizations face mounting regulatory and business pressure to retire end-of-life products and implement robust remediation strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
ABB FLXeon 2025 ICS Vulnerabilities: Protecting Critical Infrastructure from Remote Threats
Impact· medium

ABB FLXeon 2025 ICS Vulnerabilities: Protecting Critical Infrastructure from Remote Threats

In November 2025, ABB disclosed critical vulnerabilities affecting their FLXeon industrial control system (ICS) controllers, including the FBXi, FBVi, FBTi, and CBXi product lines. Security researcher Gjoko Krstikj of Zero Science Lab identified flaws such as the use of hard-coded credentials (CVE-2024-48842), improper input validation (CVE-2024-48851, CVE-2025-10207), and weak password hashing practices (CVE-2025-10205) that could allow remote attackers to gain control, execute arbitrary code, or cause system crashes. While exploitation requires some privileges and network access, the flaws impact ICS deployments globally, exposing critical infrastructure sectors to risk until patches are applied. This incident highlights the continued trend of vulnerabilities in operational technology and industrial systems, reinforcing fears that ICS environments remain attractive targets for cyber threat actors. As regulatory and industry pressure mounts for robust ICS security and segmentation, organizations must accelerate adoption of defense-in-depth strategies to protect essential infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
CISA Issues 2025 Industrial Control Systems Vulnerability Alerts: What You Need to Know
Impact· medium

CISA Issues 2025 Industrial Control Systems Vulnerability Alerts: What You Need to Know

In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released four Industrial Control Systems (ICS) security advisories highlighting critical and high-severity vulnerabilities in products from Advantech (DeviceOn iEdge), Ubia (Ubox), ABB (FLXeon Controllers), and Hitachi Energy (Asset Suite). These advisories revealed weaknesses that allow threat actors to exploit unencrypted communications, weak authentication, and inadequate segmentation, which could enable remote attackers to gain unauthorized access, move laterally within ICS environments, or disrupt operations. The announcement underscores the ongoing risk posed to critical infrastructure from both targeted and opportunistic threats leveraging these flaws. This incident exemplifies a growing trend where attackers target ICS components and operational technology, exploiting security gaps often found in legacy or poorly maintained systems. As regulatory expectations rise and the threat landscape becomes more sophisticated, organizations must urgently prioritize ICS security, bolster monitoring, and implement zero trust architectures to defend critical infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
F5’s 2023 Supply Chain Breach: When Nation-State Attacks Undermine U.S. Cyber Readiness
Impact· medium

F5’s 2023 Supply Chain Breach: When Nation-State Attacks Undermine U.S. Cyber Readiness

In October 2023, a significant nation-state supply chain attack targeted F5, a leading provider of network and application security solutions. Threat actors believed to be linked to China successfully gained unauthorized access to F5's source code and undisclosed vulnerabilities, providing them with intimate knowledge required to craft advanced exploits capable of bypassing traditional security defenses. BIG-IP, F5's flagship product, is widely deployed by major enterprises, federal agencies, healthcare institutions, and utilities, making the impact of this breach exceptionally far-reaching. In response, CISA issued an emergency directive urging federal agencies to promptly patch vulnerable systems, citing the potential for cascading impacts across critical infrastructure. This incident is particularly relevant as it underscores the growing sophistication of supply chain attacks, where adversaries target foundational software providers instead of individual end-users. The breach comes amidst rising threats from nation-state actors and highlights the urgent need for proactive security controls, rapid patching, and improved cross-sector collaboration to strengthen cyber resilience.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Delta Electronics 2025 ICS Vulnerability: Buffer Overflow in CNCSoft-G2 Threatens Industrial Operations
Impact· medium

Delta Electronics 2025 ICS Vulnerability: Buffer Overflow in CNCSoft-G2 Threatens Industrial Operations

In November 2025, Delta Electronics publicly disclosed a critical vulnerability in its CNCSoft-G2 software (version 2.1.0.27 and prior), used widely across critical manufacturing and energy sectors. The stack-based buffer overflow vulnerability (CVE-2025-58317) could be exploited by attackers using a malicious file to achieve arbitrary code execution with the privileges of the target process. Although no public exploitation has been reported yet and remote exploitation is not possible, the flaw poses significant risks to organizations controlling industrial networks, potentially undermining operational continuity and safety systems. Mitigations and patches have been released, with recommendations for further defense-in-depth and updated secure remote access. This case highlights the ongoing challenges in securing industrial control software as threat actors frequently target poorly validated file handling and legacy code. The need for robust patch management and segmentation is paramount—especially as ransomware groups and nation-state actors increasingly pursue industrial targets for disruption or extortion.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports