✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Utilities
Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.
Explore Other Sectors
Utilities Threat Reports
Operation Highland: Unveiling a Decade of Stealthy Cyber-Espionage
In 2026, cybersecurity researchers uncovered 'Operation Highland,' a decade-long cyber-espionage campaign by the Chinese state-sponsored group Velvet Ant. Beginning in 2016, the attackers initially compromised internet-facing servers, deploying modified GS-Netcat reverse shells for encrypted remote access. They then installed custom SOCKS5 proxies to tunnel traffic, enabling access to isolated networks. By backdooring Linux Pluggable Authentication Modules (PAM) and OpenSSH components, Velvet Ant harvested credentials and maintained persistent access, effectively embedding themselves within the authentication process. This allowed them to monitor administrative activities and exfiltrate sensitive data undetected for ten years. The discovery of this prolonged intrusion underscores the evolving sophistication of state-sponsored cyber threats. It highlights the critical need for organizations to implement robust monitoring of authentication systems, conduct regular integrity checks of security components, and adopt a zero-trust security model to mitigate the risk of such stealthy and persistent attacks.
1 month ago
Kill Chain
Russian National Charged in Connection with Void Blizzard Espionage Campaign
In June 2026, U.S. federal prosecutors charged Denis Nikolayevich Obrezko, a Russian national, with conspiracy to commit unauthorized computer access. Obrezko is accused of facilitating cyber-espionage operations for the Russia-aligned threat group Void Blizzard by procuring virtual private servers and domain names used in attacks targeting businesses, educational institutions, and other organizations. The FBI's investigation revealed that Void Blizzard primarily relied on stolen session tokens to authenticate to victim accounts without triggering re-authentication requirements, and used U.S.-based commercial proxy services to mask the connection's location. The group targeted at least 11 U.S. companies, with the actual number of victims likely being higher. ([cyberscoop.com](https://cyberscoop.com/russian-national-charged-void-blizzard-cyber-espionage/?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber-espionage groups like Void Blizzard, which have been active since at least April 2024, targeting critical sectors across NATO member states and Ukraine. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/?utm_source=openai)) The group's methods, while not technically advanced, have proven effective, highlighting the need for organizations to implement robust cybersecurity measures to protect against such threats.
1 month ago
Kill Chain
Kyushu Electric Power Data Breach: 10.9 Million Customer Records Exposed
In April 2026, Kyushu Electric Power Co., Inc., a major Japanese utility company, experienced a significant data breach involving the loss of an external storage device containing personal information of approximately 10.9 million customers. The device, used for routine data backups, was stored in a server room cabinet with multiple physical security layers. On May 26, IT staff discovered the cabinet unlocked and the device missing. The data included customer names, service addresses, electricity usage data, telephone numbers, and names of retail electricity providers. Notably, no bank account or credit card information was stored on the device. The company has notified affected customers and relevant authorities, including Japan’s Personal Information Protection Commission and the Ministry of Economy, Trade, and Industry. Investigations are ongoing, with no evidence of data leakage confirmed as of now. This incident underscores the critical importance of robust physical security measures and strict access controls for sensitive data storage. It highlights the need for organizations to regularly review and enhance their data protection protocols to prevent unauthorized access and potential data breaches.
1 month ago
Kill Chain
Critical Vulnerability in Schneider Electric Modicon Switches: CVE-2024-3596
In April 2026, Schneider Electric disclosed a critical vulnerability (CVE-2024-3596) affecting all versions of its Modicon and Connexium managed network switches. This flaw resides in the RADIUS authentication protocol, where an attacker with a man-in-the-middle position can exploit the MD5-based Response Authenticator to forge authentication responses. Such exploitation could grant unauthorized access to protected network segments, leading to potential denial of service and compromise of confidentiality and integrity of connected devices. This vulnerability underscores the persistent risks associated with legacy cryptographic protocols like MD5 in critical infrastructure. Organizations relying on RADIUS for network access control must reassess their configurations and consider transitioning to more secure authentication methods to mitigate such threats.
1 month ago
Kill Chain
Critical Vulnerability in Schneider Electric's EcoStruxure Panel Server Devices (CVE-2026-6866)
In May 2026, Schneider Electric disclosed a vulnerability (CVE-2026-6866) in its EcoStruxure Panel Server devices, including models PAS400, PAS600, PAS600V2, PAS800, and PAS800V2, running firmware versions 002.005.000 and prior. This flaw, identified as CWE-1188, allows device credentials to revert to factory defaults under rare conditions, potentially enabling unauthorized access to operational technology (OT) networks. The vulnerability poses a significant risk to critical infrastructure sectors such as energy, utilities, and manufacturing, as it could lead to unauthorized disclosure of sensitive information. Schneider Electric has released firmware version 002.006.000 to address this issue. Organizations are urged to apply this update promptly to mitigate potential security breaches. ([techjacksolutions.com](https://techjacksolutions.com/scc-intel/schneider-electric-ecostruxure-panel-server-credential-reset-flaw-exposes-ot-gateways-in-critical-infrastructure/?utm_source=openai)) The incident underscores the importance of maintaining up-to-date firmware and implementing robust access controls in OT environments. As cyber threats targeting industrial control systems continue to evolve, ensuring the security of gateway devices like the EcoStruxure Panel Server is crucial to prevent unauthorized access and protect critical infrastructure.
1 month ago
Kill Chain
VerdantBamboo's Prolonged Cyber Espionage via BRICKSTORM Backdoor
In September 2025, cybersecurity firm Volexity identified a prolonged cyber espionage campaign by the Chinese state-sponsored group VerdantBamboo, also known as UNC5221. The attackers exploited a local privilege escalation vulnerability in an Egnyte Storage Sync appliance to deploy a BSD variant of the BRICKSTORM backdoor, maintaining undetected access for at least 18 months. This access facilitated further infiltration into the victim's Microsoft 365 environment and the deployment of additional malware, including PLENET and AGENTPSD, on various network appliances. The campaign underscores the increasing targeting of network appliances and storage systems by sophisticated threat actors, exploiting their lack of endpoint detection capabilities to establish long-term persistence. Organizations are urged to enhance monitoring and security measures for such devices to mitigate similar threats.
1 month ago
Kill Chain
Cyberattacks on U.S. Fuel Tank Monitoring Systems: A 2026 Overview
In June 2026, U.S. critical infrastructure sectors, including energy and transportation, faced cyberattacks targeting internet-exposed Automatic Tank Gauge (ATG) systems. These systems, essential for monitoring fuel and liquid levels, were compromised by threat actors exploiting vulnerabilities such as default passwords and command execution flaws. The attackers manipulated system settings, altered tank readings, and disabled alerts, posing significant operational and safety risks. In response, agencies like CISA, NSA, and FBI issued joint advisories urging organizations to secure ATG systems by removing them from public internet access, enforcing strong credentials, and applying necessary patches. This incident underscores the escalating threat to industrial control systems and the urgent need for enhanced cybersecurity measures to protect critical infrastructure from sophisticated cyber threats.
1 month ago
Kill Chain
Over 900 US Gas Station Tank Gauge Systems Exposed to Cyberattacks
In June 2026, over 900 Automatic Tank Gauge (ATG) systems across the United States were found exposed online, making them vulnerable to cyberattacks. ATG systems are critical for monitoring fuel and chemical storage tanks in various sectors, including energy and transportation. Threat actors exploited security flaws such as hardcoded credentials and authentication bypasses to gain unauthorized access, potentially leading to operational disruptions and safety hazards. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/over-900-us-gas-station-tank-gauge-systems-exposed-to-attacks/amp/?utm_source=openai)) This incident underscores the growing threat to critical infrastructure from cyberattacks targeting industrial control systems. Organizations must prioritize securing internet-exposed devices to prevent similar vulnerabilities from being exploited in the future.
1 month ago
Kill Chain
Critical Vulnerability in ABB's PPT30 Operating System: CVE-2025-11482
On May 26, 2026, ABB disclosed a vulnerability (CVE-2025-11482) in its PPT30 Operating System versions prior to 1.8.0. This flaw resides in the OPC-UA Server component, where an unauthenticated attacker can exploit resource allocation issues to cause a denial-of-service condition, rendering the server unresponsive and disrupting industrial control processes. The vulnerability has a CVSS v3.1 base score of 7.5, indicating a high severity level. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-11482?utm_source=openai)) The disclosure underscores the critical need for timely patching in industrial control systems to prevent potential operational disruptions. Organizations are advised to upgrade to version 1.8.0 or later and implement network segmentation to mitigate risks associated with this vulnerability. ([feed.craftedsignal.io](https://feed.craftedsignal.io/briefs/2026-05-abb-ppt30-cve-2025-11482/?utm_source=openai))
1 month ago
Kill Chain
Critical Vulnerabilities in Hitachi Energy's ITT600 Explorer: CVE-2024-8176 and CVE-2025-59375
In May 2026, Hitachi Energy disclosed two critical vulnerabilities in its ITT600 Explorer product, identified as CVE-2024-8176 and CVE-2025-59375. These vulnerabilities stem from issues within the libexpat library used by the product's IEC61850 functionality. CVE-2024-8176 involves a stack overflow due to improper restriction of XML entity expansion depth, potentially leading to denial of service (DoS) or memory corruption. CVE-2025-59375 allows attackers to trigger large dynamic memory allocations via small, crafted XML documents, also resulting in DoS conditions. Both vulnerabilities affect ITT600 Explorer versions prior to 2.1 SP6. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/cve-2024-8176?utm_source=openai)) The disclosure underscores the critical importance of securing components within industrial control systems, especially those handling XML parsing. Given the widespread use of libexpat across various applications, these vulnerabilities highlight the necessity for organizations to promptly update affected systems to mitigate potential exploitation risks.
1 month ago
Kill Chain
Critical Vulnerability in Hitachi Energy's MACH HiDraw: CVE-2026-7310
In May 2026, a heap-based buffer overflow vulnerability (CVE-2026-7310) was identified in the XML parser functionality of Hitachi Energy's MACH HiDraw versions up to 9.22. An authenticated user with local access could exploit this flaw using a specially crafted XML file, leading to memory corruption and potential arbitrary code execution. Successful exploitation could result in application crashes (denial of service) and compromise the confidentiality and integrity of the affected system. This incident underscores the critical importance of securing industrial control systems against local threats. As cyberattacks targeting infrastructure components become more sophisticated, organizations must prioritize timely vulnerability management and implement robust security measures to protect against potential exploits.
1 month ago
Kill Chain
Anthropic's Project Glasswing Expands to Strengthen Global Cybersecurity
In April 2026, Anthropic launched Project Glasswing, granting approximately 50 organizations access to its advanced AI model, Claude Mythos Preview, to identify software vulnerabilities. By June 2026, the initiative expanded to include around 150 additional organizations across 15 countries, focusing on critical infrastructure sectors such as power, water, healthcare, communications, and hardware. The model has uncovered over 10,000 high- or critical-severity vulnerabilities, with partners like Cloudflare and Mozilla reporting significant increases in bug discovery rates. The rapid identification of vulnerabilities has shifted the cybersecurity landscape, highlighting challenges in verifying, disclosing, and patching flaws before exploitation. A joint report from the Cloud Security Alliance, the SANS Institute, and OWASP warns that organizations may be overwhelmed by threat actors using AI to exploit vulnerabilities faster than defenders can address them.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports