The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Utilities
Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.
Explore Other Sectors
Utilities Threat Reports
Critical DoS Vulnerability in Rockwell Automation's 1718-AENTR/1719-AENTR Adapters
In July 2026, Rockwell Automation disclosed a denial-of-service (DoS) vulnerability (CVE-2026-9140) affecting their 1718-AENTR and 1719-AENTR EtherNet/IP adapters. The flaw arises from improper handling of UDP unicast network storms, leading to device overload and loss of communication, necessitating a power cycle for recovery. The vulnerability has a CVSS v3.1 base score of 7.5, indicating a high severity level. ([rockwellautomation.com](https://www.rockwellautomation.com/es-es/trust-center/security-advisories/advisory.SD1778.html?utm_source=openai)) This incident underscores the critical importance of robust network traffic management in industrial control systems. As cyber threats targeting industrial environments become more sophisticated, organizations must proactively address such vulnerabilities to maintain operational resilience and safeguard critical infrastructure.
2 months ago
Kill Chain
Critical Vulnerability in Rockwell Automation's 1734 POINT I/O Module (CVE-2026-10573)
In July 2026, Rockwell Automation disclosed a denial-of-service vulnerability (CVE-2026-10573) in its 1734 POINT I/O™ module, version 3.023. The flaw arises from improper handling of crafted Common Industrial Protocol (CIP) messages, which can cause the module to enter a faulted state, necessitating a restart to restore functionality. This vulnerability poses a significant risk to industrial operations, potentially leading to unplanned downtime and operational disruptions. The increasing connectivity of industrial control systems (ICS) to external networks heightens their exposure to cyber threats. This incident underscores the critical need for robust security measures in ICS environments to prevent exploitation of such vulnerabilities, which can have cascading effects on critical manufacturing sectors worldwide.
2 months ago
Kill Chain
Critical Security Flaws Discovered in Tycon Systems TPDIN-Monitor-WEB2 Devices
In July 2026, critical vulnerabilities were identified in Tycon Systems' TPDIN-Monitor-WEB2 devices, specifically affecting firmware version 2.3.9. The vulnerabilities, CVE-2026-61884 and CVE-2026-55985, allow unauthenticated remote attackers to bypass authentication and access sensitive credentials stored in cleartext. Exploitation of these flaws could lead to unauthorized control over device functions, disruption of connected infrastructure, and potential physical safety risks. ([windowsforum.com](https://windowsforum.com/threads/tycon-tpdin-monitor-web2-2-3-9-fix-critical-9-8-flaws.439865/?utm_source=openai)) This incident underscores the pressing need for robust security measures in industrial control systems, especially those deployed in critical manufacturing sectors worldwide. Organizations must prioritize timely firmware updates, network segmentation, and secure remote access protocols to mitigate such vulnerabilities.
2 months ago
Kill Chain
Bit2Watt Attack: Unveiling a New Cyber-Physical Threat to Power Grids
In July 2026, researchers from Zhejiang University unveiled the 'Bit2Watt' attack, demonstrating how cloud tenants can manipulate GPU workloads to induce high-frequency power oscillations. These oscillations have the potential to destabilize local power grids, especially those heavily reliant on renewable energy sources. The attack operates without exploiting traditional vulnerabilities, instead leveraging legitimate computational processes to create power fluctuations that can lead to significant harmonic distortion and system instability. ([thehackernews.com](https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html?m=1&utm_source=openai)) This discovery underscores the evolving nature of cyber-physical threats, highlighting the need for integrated security measures that consider both computational workloads and their physical impact on infrastructure. As data centers increasingly adopt GPU clusters and renewable energy, understanding and mitigating such vulnerabilities becomes paramount to ensure grid stability and operational continuity.
2 months ago
Kill Chain
Indictment of Russian Nationals for Bulletproof Hosting Services Facilitating Cyberattacks
In July 2026, U.S. federal prosecutors unsealed an indictment against three Russian nationals—Alexander Alexandrovich Volosovik, Yulia Vladimirovna Pankova, and Kirill Andreevich Zatolokin—accusing them of operating bulletproof hosting services through their companies, Media Land and ML.Cloud. These services allegedly facilitated cyberattacks on critical infrastructure across 21 U.S. states and several countries, resulting in over $62 million in damages. The indictment details how the accused provided infrastructure and technical support to cybercriminals, enabling malware distribution, ransomware attacks, and other illicit activities. ([cyberscoop.com](https://cyberscoop.com/russian-nationals-medialand-mlcloud-indicted-bulletproof-hosting/?utm_source=openai)) This case underscores the persistent threat posed by bulletproof hosting providers, which offer cybercriminals resilient infrastructure to conduct attacks with impunity. The indictment highlights the necessity for international cooperation in dismantling such networks and protecting critical infrastructure from cyber threats. ([cyberscoop.com](https://cyberscoop.com/russian-nationals-medialand-mlcloud-indicted-bulletproof-hosting/?utm_source=openai))
2 months ago
Kill Chain
Iran's AI-Enhanced Asymmetric Warfare in 2026
Between January and June 2026, Iran leveraged artificial intelligence (AI) to enhance its longstanding hybrid warfare model, blending asymmetric military operations, cyber operations, information warfare, proxy attacks, and coercive state control. AI acted as a force multiplier, increasing the speed, scale, and effectiveness of Iranian operations. This strategic use of AI enabled Iran to compensate for conventional military and economic disadvantages, improving its cyber capabilities, accelerating propaganda production, and expanding the reach of information campaigns. ([intelligentciso.com](https://www.intelligentciso.com/2026/07/16/recorded-future-examines-irans-growing-use-of-ai-in-cyber-operations/?utm_source=openai)) The integration of AI into Iran's asymmetric tactics underscores the evolving nature of cyber threats, highlighting the need for organizations to bolster defenses against AI-enhanced operations. This development reflects a broader trend of state actors utilizing AI to amplify their cyber and information warfare capabilities, posing elevated risks to critical infrastructure and vital industries. ([intelligentciso.com](https://www.intelligentciso.com/2026/07/16/recorded-future-examines-irans-growing-use-of-ai-in-cyber-operations/?utm_source=openai))
2 months ago
Kill Chain
CISA Highlights Critical Vulnerabilities in Latest KEV Catalog Update
On July 15, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2023-4346 and CVE-2026-46817. CVE-2023-4346 pertains to the KNX Protocol's overly restrictive account lockout mechanism, potentially allowing attackers to purge devices and set unauthorized keys. CVE-2026-46817 affects Oracle E-Business Suite's Payments component, enabling unauthenticated attackers to compromise the system via HTTP, leading to potential full system takeover. Both vulnerabilities pose significant risks to federal enterprises and have been actively exploited. The inclusion of these vulnerabilities in the KEV Catalog underscores the persistent threat posed by unpatched systems. Organizations are urged to prioritize remediation efforts, especially for vulnerabilities known to be actively exploited, to mitigate potential breaches and maintain system integrity.
2 months ago
Kill Chain
Critical DoS Vulnerability in Rockwell Automation Modules: CVE-2026-9653
In July 2026, a denial-of-service (DoS) vulnerability, identified as CVE-2026-9653, was discovered in Rockwell Automation's 1756-EN2, 1756-EN3, and 1756-ENBT communication modules. This flaw arises from improper validation of CIP Implicit Connection packets, allowing network-based attackers to send crafted packets that can continuously disrupt device connections. Although the devices automatically recover after each disruption, repeated exploitation can lead to significant operational downtime. The affected firmware versions include 1756-EN2 and 1756-EN3 up to V12.001, and 1756-ENBT V6.006. ([rockwellautomation.com](https://www.rockwellautomation.com/de-ch/trust-center/security-advisories.htmlhttps%3A.html?utm_source=openai)) The emergence of CVE-2026-9653 underscores the critical need for robust validation mechanisms in industrial control systems. As cyber threats targeting operational technology (OT) environments become more sophisticated, organizations must prioritize timely firmware updates and implement comprehensive network security measures to mitigate potential disruptions.
2 months ago
Kill Chain
Critical Vulnerabilities in AutomationDirect Productivity Suite Threaten Industrial Control Systems
In July 2026, multiple vulnerabilities were identified in AutomationDirect's Productivity Suite software, affecting versions up to v4.6.2.2. These vulnerabilities include out-of-bounds write and read errors, as well as divide-by-zero flaws, which could allow attackers with local or physical access to cause memory corruption, unintended information disclosure, application instability, or denial-of-service conditions. The affected products are widely used in the critical manufacturing sector globally. The discovery of these vulnerabilities underscores the ongoing challenges in securing industrial control systems (ICS). As ICS environments become increasingly interconnected, the potential impact of such vulnerabilities grows, highlighting the need for continuous monitoring and timely patching to maintain operational integrity and security.
2 months ago
Kill Chain
Critical Vulnerabilities Discovered in Rockwell Automation's Arena® Simulation Software
In July 2026, Rockwell Automation disclosed multiple memory corruption vulnerabilities in its Arena® Simulation software, specifically affecting components such as model.exe, expmt.exe, linker.exe, and siman.exe. These vulnerabilities, identified as CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, and CVE-2026-8314, arise from improper validation of user-supplied data, leading to out-of-bounds write conditions. Exploitation could allow attackers to execute arbitrary code by convincing users to open malicious files. The affected versions include Arena V17.00.00 and prior, with fixes available in version V17.00.01. ([rockwellautomation.com](https://www.rockwellautomation.com/es-es/trust-center/security-advisories/advisory.SD1784.html?utm_source=openai)) This incident underscores the critical importance of timely software updates and user awareness in mitigating risks associated with memory corruption vulnerabilities. As attackers increasingly exploit such flaws to gain unauthorized access, organizations must prioritize patch management and educate users on the dangers of opening untrusted files to maintain robust cybersecurity defenses.
2 months ago
Kill Chain
Critical Vulnerabilities in Siemens SICAM 8 Products: Immediate Updates Recommended
In July 2026, Siemens disclosed multiple vulnerabilities in its SICAM 8 products, including CPCI85 Central Processing/Communication and SICORE Base system, affecting versions prior to V26.20 and V26.20.0 respectively. These vulnerabilities encompass issues such as accessible debugging interfaces leading to denial-of-service conditions (CVE-2026-54798), flaws in firmware signature validation allowing malicious firmware installation (CVE-2026-54799), default configurations disabling OPC UA security mechanisms (CVE-2026-54800), and insufficient validation of authentication credentials enabling privilege escalation (CVE-2026-54801). Siemens has released updates to address these vulnerabilities and recommends users upgrade to the latest versions. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-229470.html?utm_source=openai)) The disclosure of these vulnerabilities underscores the critical importance of securing industrial control systems, especially in sectors like energy and manufacturing. The potential for unauthorized access and system compromise highlights the need for organizations to promptly apply security updates and review their system configurations to mitigate risks associated with these vulnerabilities.
2 months ago
Kill Chain
Critical Vulnerabilities in Rockwell Automation's ICS Controllers: What You Need to Know
In 2025, Rockwell Automation identified multiple vulnerabilities in its CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers. These flaws, including CVE-2025-12011, CVE-2025-12012, and CVE-2025-11698, could allow remote attackers to cause major non-recoverable faults (MNRF) in affected devices, leading to denial-of-service conditions. The vulnerabilities were found in firmware versions up to V35.015 for certain models, with Rockwell Automation releasing patches in versions V35.016, V36.011, and later to address these issues. ([rockwellautomation.com](https://www.rockwellautomation.com/pt-pt/trust-center/security-advisories.html?utm_source=openai)) The discovery of these vulnerabilities underscores the critical importance of securing industrial control systems (ICS) against remote attacks. As ICS environments become increasingly interconnected, the potential impact of such vulnerabilities grows, highlighting the need for continuous monitoring, timely patching, and adherence to cybersecurity best practices to protect critical infrastructure.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports