✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Utilities
Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.
Explore Other Sectors
Utilities Threat Reports
Dutch Authorities Dismantle Hosting Firm Enabling Cyberattacks
In May 2026, the Dutch Fiscal Information and Investigation Service (FIOD) arrested two individuals and seized 800 servers associated with Stark Industries, a web hosting company implicated in facilitating cyberattacks, interference operations, and disinformation campaigns. The suspects, aged 57 and 39, were linked to providing infrastructure that supported actions undermining democracy and security, including information manipulation and disruption of public and economic systems. Stark Industries, founded in February 2022, was added to the European Union's list of sanctioned entities in May 2025. Following the sanctions, the company's infrastructure was transferred to a newly established Dutch entity, WorkTitans B.V., operating under the brand THE.Hosting, which investigators believe acted as a front for the sanctioned organization. The FIOD's coordinated raids in Dronten, Schiphol-Rijk, Enschede, and Almere resulted in the confiscation of servers, laptops, phones, and administrative records. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/netherlands-seizes-800-servers-of-hosting-firm-enabling-cyberattacks/amp/?utm_source=openai)) This incident underscores the persistent threat posed by cybercriminals leveraging hosting services to conduct malicious activities. The involvement of entities like WorkTitans B.V. highlights the challenges in enforcing sanctions and the need for continuous vigilance against infrastructure providers that may serve as conduits for cyberattacks. Organizations must remain proactive in monitoring and securing their networks against such threats.
2 months ago
Kill Chain
Critical Vulnerabilities in ABB B&R Automation Runtime Threaten Industrial Systems
In October 2025, ABB B&R Automation Runtime versions prior to 6.4 were found to have multiple vulnerabilities, including CVE-2025-3449, CVE-2025-3448, and CVE-2025-11498. These flaws could allow unauthenticated attackers to hijack sessions, execute arbitrary JavaScript in users' browsers, and inject malicious formulas into CSV files. Exploitation required network access and user interaction, posing significant risks to industrial control systems. The discovery of these vulnerabilities underscores the critical need for robust security measures in industrial automation environments. As cyber threats targeting operational technology increase, organizations must prioritize timely updates and comprehensive security practices to safeguard against potential exploits.
2 months ago
Kill Chain
Critical Vulnerabilities Discovered in ABB Terra AC Wallbox EV Chargers
In September 2025, ABB identified multiple buffer overflow vulnerabilities in its Terra AC Wallbox electric vehicle chargers, specifically affecting firmware versions up to 1.8.33. These vulnerabilities, cataloged as CVE-2025-10504, CVE-2025-12142, and CVE-2025-12143, could allow attackers with adjacent network access and high privileges to execute arbitrary code, potentially leading to unauthorized control over the device. ABB promptly released firmware version 1.8.36 to address these issues and recommended immediate updates to mitigate potential risks. The discovery of these vulnerabilities underscores the critical importance of securing IoT devices, especially those connected to critical infrastructure like energy distribution. As the adoption of electric vehicle chargers grows, ensuring robust cybersecurity measures is essential to prevent potential exploitation that could disrupt services and compromise user safety.
2 months ago
Kill Chain
Critical OpenSSL Vulnerability in Hitachi Energy's GMS600: CVE-2022-4304
In 2023, Hitachi Energy identified a vulnerability (CVE-2022-4304) in its GMS600 versions 1.3.0 and 1.3.1, stemming from a timing-based side channel in the OpenSSL RSA decryption implementation. This flaw could potentially allow attackers to recover plaintext across a network through a Bleichenbacher-style attack, necessitating the transmission of a large number of trial messages. Successful exploitation could lead to the decryption of sensitive application data transmitted over TLS connections. ([cve.mitre.org](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4304&utm_source=openai)) This incident underscores the critical importance of promptly addressing vulnerabilities in widely used cryptographic libraries like OpenSSL. Organizations must remain vigilant, as similar flaws can have far-reaching implications across various products and industries, emphasizing the need for continuous monitoring and timely patching to maintain robust cybersecurity defenses.
2 months ago
Kill Chain
ScadaBR 1.2.0 Vulnerabilities: A Wake-Up Call for SCADA Security
In May 2026, multiple critical vulnerabilities were identified in ScadaBR version 1.2.0, an open-source SCADA platform widely used in critical infrastructure sectors. These vulnerabilities include missing authentication for critical functions (CVE-2026-8602), OS command injection (CVE-2026-8603), cross-site request forgery (CVE-2026-8604), and the use of hard-coded credentials (CVE-2026-8605). Exploitation of these flaws could allow unauthenticated attackers to execute arbitrary code, manipulate sensor readings, and gain administrative access to the system, posing significant risks to operational technology environments. ([windowsforum.com](https://windowsforum.com/threads/cisa-warns-scadabr-1-2-0-flaws-enable-unauthenticated-rce-protect-ot-exposure.418951/post-978793?utm_source=openai)) The discovery of these vulnerabilities underscores the ongoing challenges in securing SCADA systems, especially those exposed to the internet or integrated with IT networks. Organizations must reassess their security postures, implement robust access controls, and ensure timely updates to mitigate such risks.
2 months ago
Kill Chain
Critical Vulnerability in ABB CoreSense Products: CVE-2025-3465
In October 2025, ABB disclosed a path traversal vulnerability (CVE-2025-3465) in its CoreSense™ HM and CoreSense™ M10 products, affecting versions up to 2.3.1 and 1.4.1.12, respectively. This flaw allows unauthenticated users to access restricted directories, potentially leading to complete system compromise and exposure of sensitive information. ABB has released updates to address this issue and recommends that customers apply them promptly. This incident underscores the critical importance of timely vulnerability management in industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, organizations must remain vigilant and proactive in applying security patches to mitigate potential risks.
2 months ago
Kill Chain
Critical Vulnerability in Palo Alto Networks PAN-OS: CVE-2026-0300
In May 2026, a critical buffer overflow vulnerability (CVE-2026-0300) was identified in the User-ID™ Authentication Portal service of Palo Alto Networks PAN-OS software. This flaw allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. The vulnerability affects PAN-OS versions prior to 12.1.4-h5, 11.2.4-h17, 11.1.4-h33, and 10.2.7-h34. Exploitation has been observed in the wild, primarily targeting systems with the Authentication Portal exposed to untrusted networks. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0300?utm_source=openai)) The incident underscores the importance of securing network access to critical services and adhering to best practice guidelines. Organizations are advised to restrict access to the User-ID™ Authentication Portal to trusted internal IP addresses and apply the necessary software updates promptly to mitigate potential risks. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0300?utm_source=openai))
2 months ago
Kill Chain
Iranian Hackers Compromise U.S. Fuel Monitoring Systems in 2026
In May 2026, Iranian hackers reportedly breached automatic tank gauge (ATG) systems monitoring fuel levels at gas stations across multiple U.S. states. These systems, exposed online without password protection, allowed attackers to alter display readings without affecting actual fuel levels. While no physical damage occurred, the incident underscores vulnerabilities in critical infrastructure. ([abc17news.com](https://abc17news.com/politics/national-politics/cnn-us-politics/2026/05/15/exclusive-hackers-have-breached-tank-readers-at-us-gas-stations-officials-suspect-iran-is-responsible/?utm_source=openai)) This breach highlights the evolving nature of cyber warfare, where nation-state actors target essential services. The incident serves as a stark reminder for organizations to secure internet-facing operational technology systems to prevent potential disruptions and safety hazards.
2 months ago
Kill Chain
Taiwan High Speed Rail Radio Hack: A Wake-Up Call for Critical Infrastructure Security
In April 2026, a 23-year-old university student in Taiwan exploited vulnerabilities in the Taiwan High Speed Rail's (THSR) radio communication system, using software-defined radio equipment to transmit a false 'General Alarm' signal. This unauthorized transmission caused four high-speed trains to halt for 48 minutes, disrupting operations and highlighting significant security flaws in critical infrastructure. The student was arrested and released on bail, facing charges related to endangering public transportation safety. ([taipeitimes.com](https://www.taipeitimes.com/News/taiwan/archives/2026/05/05/2003856781?utm_source=openai)) This incident underscores the pressing need for robust cybersecurity measures in transportation systems, especially as similar vulnerabilities have been exploited in other countries. It serves as a wake-up call for infrastructure operators worldwide to reassess and fortify their communication protocols against potential cyber threats.
2 months ago
Kill Chain
FamousSparrow APT's Persistent Attacks on Azerbaijani Energy Sector in 2026
In late December 2025 through February 2026, the China-linked Advanced Persistent Threat (APT) group known as FamousSparrow targeted an Azerbaijani oil and gas company. The attackers exploited a vulnerable Microsoft Exchange server to gain initial access, deploying sophisticated techniques such as a two-stage DLL sideloading mechanism to evade detection and install remote access tools like Deed RAT and Terndoor. Despite remediation efforts, the group conducted multiple attack waves, indicating a persistent and strategic cyber espionage campaign. ([bitdefender.com](https://www.bitdefender.com/en-us/blog/businessinsights/famoussparrow-apt-targets-azerbaijani-oil-gas-industry?utm_source=openai)) This incident underscores a significant shift in cyber threat landscapes, with Chinese APTs expanding their focus to regions traditionally influenced by other state actors. The use of advanced evasion techniques highlights the evolving sophistication of cyber adversaries, emphasizing the need for robust and proactive cybersecurity measures in critical infrastructure sectors. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/china-famoussparrow-apt-south-caucasus-energy-firm?utm_source=openai))
2 months ago
Kill Chain
FamousSparrow APT's Persistent Attacks on Azerbaijani Energy Infrastructure
Between late December 2025 and late February 2026, a Chinese-affiliated threat actor known as FamousSparrow conducted a multi-wave intrusion targeting an Azerbaijani oil and gas company. The attackers exploited vulnerabilities in Microsoft Exchange servers to gain initial access, deploying sophisticated backdoors such as Deed RAT and Terndoor. Despite multiple remediation efforts, the adversaries persistently re-exploited the same entry points, indicating a high level of determination and technical capability. This campaign underscores the evolving threat landscape where state-sponsored actors are increasingly targeting critical energy infrastructure in geopolitically sensitive regions. The incident highlights the necessity for organizations to implement comprehensive patch management, continuous monitoring, and robust incident response strategies to mitigate such persistent and sophisticated cyber threats.
2 months ago
Kill Chain
UK Water Supplier Fined $1.3M for Massive Data Breach
In May 2026, the UK's Information Commissioner's Office (ICO) fined South Staffordshire Water Plc and its parent company £963,900 ($1.3 million) following a cyberattack that exposed the personal data of 663,887 customers and employees. The breach originated in September 2020 through a phishing email, allowing attackers to install malware that remained undetected for 20 months. Between May and July 2022, the attackers escalated privileges, gaining domain administrator access. The breach was discovered in July 2022 after IT performance issues prompted an investigation. The compromised data included full names, addresses, email addresses, phone numbers, dates of birth, customer account credentials, bank account details, and employee HR data such as National Insurance numbers. This incident underscores the critical importance of robust cybersecurity measures, especially in essential service sectors. The prolonged undetected presence of malware highlights the need for continuous monitoring and rapid response capabilities to mitigate potential threats effectively.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports