The Containment Era is here. →Explore

Industry Category

Utilities

Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.

387 threat reports
Page 8 of 33

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Utilities Threat Reports

Showing 8596 / 387 reports
Polish Water Treatment Plant Breach: A Wake-Up Call for Critical Infrastructure Security
Impact· HIGH

Polish Water Treatment Plant Breach: A Wake-Up Call for Critical Infrastructure Security

Between 2024 and 2025, Poland's Internal Security Agency (ABW) reported that state-sponsored threat actors, including APT28 and APT29, infiltrated industrial control systems (ICS) at five municipal water treatment facilities. The attackers exploited weak passwords and internet-exposed systems, gaining the capability to manipulate operational parameters, potentially compromising water quality and public safety. This breach underscores the critical vulnerabilities in essential infrastructure and the pressing need for robust cybersecurity measures. The incident highlights a growing trend of cyberattacks targeting operational technology (OT) systems within critical infrastructure sectors. As adversaries increasingly focus on these sectors, organizations must prioritize securing OT environments to prevent potential disruptions and safeguard public health.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Dutch Authorities' Raid on Russian Bulletproof Host Fails to Disrupt Cyber Activities
Impact· MEDIUM

Dutch Authorities' Raid on Russian Bulletproof Host Fails to Disrupt Cyber Activities

In May 2026, Dutch authorities seized over 800 servers and arrested two individuals associated with THE.Hosting, a bulletproof hosting service linked to Russian cybercriminal activities. Despite these efforts, the network's malicious operations, including broad scanning and botnet-building, continued largely unaffected due to the resilience of its infrastructure and the retention of its core IP address space. ([darkreading.com](https://www.darkreading.com/cyber-risk/dutch-raid-russian-bulletproof-host?utm_source=openai)) This incident underscores the challenges law enforcement faces in disrupting sophisticated cybercriminal networks that can rapidly adapt and reconstitute their operations, highlighting the need for coordinated international efforts and more comprehensive strategies to effectively combat such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Security Flaws Discovered in XCharge C6 EV Chargers
Impact· CRITICAL

Critical Security Flaws Discovered in XCharge C6 EV Chargers

In May 2026, multiple critical vulnerabilities were identified in XCharge's C6 electric vehicle charging controllers, including CVE-2026-9037, CVE-2026-9038, and CVE-2026-9039. These flaws could allow attackers to gain administrative rights or execute unauthorized code on affected devices. The vulnerabilities encompass issues such as unverified firmware updates, stack-based buffer overflows, and insecure default configurations. Exploitation of these vulnerabilities could lead to significant control over critical infrastructure in transportation systems worldwide. ([windowsforum.com](https://windowsforum.com/threads/cisa-warns-xcharge-c6-ev-chargers-have-3-critical-flaws-cvss-9-8.420545/?utm_source=openai)) The increasing integration of IoT devices in critical infrastructure highlights the urgency of addressing such vulnerabilities. Ensuring robust security measures and timely updates is essential to prevent potential disruptions and maintain the integrity of essential services.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Security Flaw in Jinan USR IOT's USR-W610 Converter Exposes Networks to Attack
Impact· HIGH

Critical Security Flaw in Jinan USR IOT's USR-W610 Converter Exposes Networks to Attack

In May 2026, a critical vulnerability (CVE-2026-7786) was identified in Jinan USR IOT Technology Limited's USR-W610 RS232/485 to Wi-Fi/Ethernet Converter, firmware version 7.03T.07. The device contains hard-coded plaintext administrative credentials embedded within the firmware, which can be extracted and used by attackers to gain full administrator access. This flaw poses significant risks, including unauthorized control over the device and potential network intrusion. The vendor has not responded to coordination attempts, leaving users without an official patch or remediation guidance. This incident underscores the persistent issue of hard-coded credentials in IoT devices, a vulnerability that has been exploited in various sectors, leading to unauthorized access and control. The lack of vendor response highlights the challenges in securing IoT devices, emphasizing the need for proactive security measures and regular vulnerability assessments to mitigate such risks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Schneider Electric's EcoStruxure Machine Expert HVAC Vulnerability: CVE-2026-6332
Impact· HIGH

Schneider Electric's EcoStruxure Machine Expert HVAC Vulnerability: CVE-2026-6332

In May 2026, Schneider Electric disclosed a vulnerability (CVE-2026-6332) in its EcoStruxure Machine Expert HVAC software versions prior to 1.10.0. This flaw involves the cleartext storage of sensitive information, potentially exposing protected source code when accessed by authorized users for editing or compiling. Such exposure could lead to a loss of confidentiality and unauthorized disclosure of proprietary logic and operational details. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-6332?utm_source=openai)) This incident underscores the critical importance of securing engineering workstations and programming environments in industrial settings. As industrial control systems become increasingly interconnected, ensuring the confidentiality and integrity of source code is paramount to prevent potential reconnaissance and exploitation by malicious actors.

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in ABB EIBPORT Devices Disclosed
Impact· HIGH

Critical Vulnerability in ABB EIBPORT Devices Disclosed

In May 2026, ABB disclosed a critical vulnerability in its EIBPORT V3 KNX and KNX GSM devices, versions prior to 3.9.2. The flaw, identified as CVE-2021-22291, is a cross-site scripting (XSS) vulnerability that could allow attackers to access sensitive information and alter device configurations. ABB has released firmware updates to address this issue and recommends immediate application to mitigate potential risks. This incident underscores the persistent threat of web-based vulnerabilities in industrial control systems, emphasizing the need for continuous monitoring and timely patch management to protect critical infrastructure from evolving cyber threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Enhancing Industrial Security: AI-Assisted Sparkplug B Protocol Fuzzer Released
Impact· HIGH

Enhancing Industrial Security: AI-Assisted Sparkplug B Protocol Fuzzer Released

In May 2026, Bishop Fox released a security fuzzer for the Sparkplug B protocol, a dominant MQTT-based protocol in industrial control and SCADA environments. This tool systematically tests all nine message types, 19 data types, and over 87 unique field paths defined by the Eclipse Sparkplug specification. The fuzzer was developed with AI assistance, specifically utilizing Claude Code to identify coverage gaps and Python defects, resulting in a hardened, self-contained tool with CLI, logging, and passive network discovery capabilities. This development is crucial for ICS and SCADA operators, device vendors, and defenders, as it enables the identification of crashes, protocol violations, and state-handling bugs in Sparkplug B endpoints before attackers can exploit them. The tool is available on GitHub for immediate use.

2 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical DoS Vulnerability in ABB B&R Automation Runtime (CVE-2025-3450)
Impact· CRITICAL

Critical DoS Vulnerability in ABB B&R Automation Runtime (CVE-2025-3450)

In October 2025, ABB identified a critical vulnerability (CVE-2025-3450) in the System Diagnostics Manager (SDM) component of B&R Automation Runtime versions prior to 6.3 and Q4.93. This flaw allows unauthenticated, network-based attackers to delete data, leading to denial-of-service conditions. The vulnerability stems from improper resource locking within the SDM, potentially causing affected systems to cease operation upon exploitation. ABB has released updates to address this issue and recommends users upgrade to Automation Runtime versions 6.3 or Q4.93 to mitigate the risk. This incident underscores the importance of timely patch management and robust network security practices, especially in critical infrastructure sectors where such vulnerabilities can have significant operational impacts.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability in ABB Ability™ zenon: CVE-2025-8754
Impact· HIGH

Critical Vulnerability in ABB Ability™ zenon: CVE-2025-8754

In August 2025, a critical vulnerability (CVE-2025-8754) was identified in ABB's Ability™ zenon software, versions 7.50 through 14. This flaw allows unauthenticated remote attackers to access critical functions, potentially leading to denial-of-service conditions in industrial control environments. The vulnerability arises from missing authentication mechanisms in the Remote Transport Service, enabling unauthorized system reboots. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2025-8754&utm_source=openai)) The incident underscores the importance of robust authentication protocols in industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, organizations must prioritize timely vulnerability assessments and implement comprehensive security measures to mitigate potential risks.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical Vulnerability in ABB AC500 V2 PLCs: CVE-2025-7745
Impact· MEDIUM

Critical Vulnerability in ABB AC500 V2 PLCs: CVE-2025-7745

In July 2025, a buffer over-read vulnerability, identified as CVE-2025-7745, was discovered in ABB's AC500 V2 programmable logic controllers (PLCs), affecting versions up to and including 2.5.2. This flaw could allow unauthorized access to fragments of previously transmitted Modbus telegrams, potentially exposing sensitive information. The vulnerability was reported by Reid Wightman of Dragos, Inc., and ABB released firmware version 2.5.3 to address the issue. The incident underscores the critical importance of timely patch management in industrial control systems (ICS). As cyber threats targeting ICS environments continue to evolve, organizations must remain vigilant in updating and securing their operational technology to prevent potential exploitation of such vulnerabilities.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in ABB Terra AC Wallbox Chargers: CVE-2025-5517
Impact· MEDIUM

Critical Vulnerability in ABB Terra AC Wallbox Chargers: CVE-2025-5517

In October 2025, ABB disclosed a heap-based buffer overflow vulnerability (CVE-2025-5517) affecting multiple models of its Terra AC wallbox electric vehicle chargers. This flaw could allow attackers to execute arbitrary code, cause denial-of-service conditions, or gain unauthorized access. Exploitation requires either a man-in-the-middle position with unencrypted communication or a compromised Charging Station Management System (CSMS). ABB has released firmware updates to address this issue and recommends users update their devices promptly. This incident underscores the critical importance of securing industrial control systems, especially as electric vehicle infrastructure becomes more widespread. Organizations should ensure encrypted communications and regularly update firmware to mitigate such vulnerabilities.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ABB MConfig Vulnerability CVE-2025-9970: Cleartext Storage of Sensitive Information
Impact· HIGH

ABB MConfig Vulnerability CVE-2025-9970: Cleartext Storage of Sensitive Information

In October 2025, ABB disclosed a vulnerability (CVE-2025-9970) in its MConfig software versions up to 1.4.9.21, where sensitive information was stored in cleartext within memory. This flaw could allow attackers with local access to extract credentials, potentially compromising system integrity. ABB released version 1.4.9.22 to address this issue. This incident underscores the critical importance of secure memory handling practices in software development, especially for applications managing sensitive data. Organizations are reminded to promptly apply security patches and review software for similar vulnerabilities to prevent unauthorized access.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports