The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Utilities
Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.
Explore Other Sectors
Utilities Threat Reports
CyberAv3ngers' 2026 Attacks on U.S. Critical Infrastructure: A Wake-Up Call for OT Security
In early 2026, the Iranian-affiliated cyber group CyberAv3ngers, linked to the Islamic Revolutionary Guard Corps (IRGC), launched a series of cyberattacks targeting U.S. critical infrastructure sectors, including water, energy, and local government facilities. The attackers exploited internet-exposed Rockwell Automation and Allen-Bradley programmable logic controllers (PLCs), such as CompactLogix and Micro850 models, to gain unauthorized access, manipulate data displayed on human-machine interfaces (HMIs), and disrupt operations. These incidents resulted in operational disruptions and financial losses for the affected organizations. ([risidata.com](https://www.risidata.com/Database/Detail/iran-cyberav3ngers-plc-us-infrastructure-2026?utm_source=openai)) This campaign underscores the escalating cyber threat posed by state-sponsored actors targeting industrial control systems (ICS) and operational technology (OT) environments. Organizations must prioritize securing internet-facing OT devices, implement robust access controls, and maintain up-to-date patch management to mitigate such risks.
2 months ago
Kill Chain
Critical Vulnerability in Schneider Electric Easergy MiCOM Px40 Series: CVE-2026-4832
In April 2026, Schneider Electric disclosed a vulnerability (CVE-2026-4832) in its Easergy MiCOM Px40 Series protection relays. The flaw involves hard-coded credentials within the SNMP interface, allowing unauthenticated attackers to access sensitive device information. Affected models include Easergy MiCOM P14x, P24x, P341, and others, with versions prior to specific firmware updates being vulnerable. The vulnerability has a CVSS v4.0 score of 6.9, indicating a medium severity level. This incident underscores the critical importance of securing industrial control systems against unauthorized access. The use of hard-coded credentials is a known security risk, and organizations must prioritize updating firmware and implementing network protections to mitigate such vulnerabilities.
2 months ago
Kill Chain
OpenPLC v3 Vulnerability CVE-2026-14480: A Critical Threat to Industrial Control Systems
In July 2026, a critical vulnerability (CVE-2026-14480) was identified in OpenPLC v3, an open-source programmable logic controller widely used in industrial control systems. This flaw allows authenticated attackers to write arbitrary files to the filesystem, potentially leading to remote code execution with the privileges of the OpenPLC runtime user. Exploitation could result in unauthorized control over industrial processes, posing significant risks to critical infrastructure sectors such as manufacturing, energy, transportation, and water systems. The discovery of this vulnerability underscores the ongoing challenges in securing industrial control systems, especially those relying on open-source solutions. As cyber threats targeting critical infrastructure continue to evolve, it is imperative for organizations to proactively assess and mitigate vulnerabilities to prevent potential disruptions and ensure operational resilience.
2 months ago
Kill Chain
Hydro-Québec Charging Station Vulnerabilities Highlight Critical Infrastructure Risks
In July 2026, Hydro-Québec's Le Circuit Electrique charging station backend was found to have multiple critical vulnerabilities, including improper access control, insufficient session expiration, and lack of throttling on authentication attempts. These flaws could allow attackers to escalate privileges or execute denial-of-service attacks, potentially disrupting electric vehicle charging services across Canada. Hydro-Québec has since updated the majority of charging stations to disable the Open Charge Point Protocol (OCPP) and implemented authentication systems to mitigate these risks. This incident underscores the growing cybersecurity challenges in the electric vehicle infrastructure sector. As the adoption of EVs accelerates, ensuring the security of charging networks becomes paramount to prevent potential disruptions and maintain public trust in sustainable transportation solutions.
2 months ago
Kill Chain
Critical Vulnerability in Hitachi Energy's PROMOD V: CVE-2026-10763
In June 2026, Hitachi Energy disclosed a vulnerability (CVE-2026-10763) in its PROMOD V software, which utilized unencrypted HTTP communication due to the lack of HTTPS support from a third-party Digipede server. This flaw exposed sensitive data to potential interception and manipulation, posing risks such as credential theft and unauthorized access. The affected versions include PROMOD V up to 1.0.10. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-10763?utm_source=openai)) This incident underscores the critical importance of secure communication protocols in industrial control systems. Organizations are urged to review their software dependencies and ensure that all components support encrypted communications to mitigate similar vulnerabilities.
2 months ago
Kill Chain
Critical Vulnerability in Hitachi Energy e-mesh EMS: CVE-2026-42945
In July 2026, Hitachi Energy disclosed a critical vulnerability (CVE-2026-42945) in its e-mesh EMS versions 4.1.6, 4.4.2, and 4.7.0. This heap-based buffer overflow in the NGINX component's ngx_http_rewrite_module allows unauthenticated attackers to send crafted HTTP requests, potentially leading to application crashes and arbitrary code execution. The vulnerability arises when specific rewrite directives are used with unnamed PCRE captures and replacement strings containing a question mark. ([windowsforum.com](https://windowsforum.com/threads/cve-2026-42945-nginx-heap-overflow-hits-hitachi-energy-e-mesh-ems.435597/?utm_source=openai)) This incident underscores the risks of integrating widely-used web components like NGINX into critical infrastructure systems. Organizations must prioritize patching affected systems and reviewing configurations to mitigate potential exploitation, especially in environments where operational technology intersects with standard web technologies.
2 months ago
Kill Chain
Spain Arrests Alleged Member of Pro-Russian Hacktivist Group in 2026
In March 2026, Spanish authorities arrested an alleged member of the pro-Russian hacktivist group Cyber Army of Russia Reborn (CARR) in Palencia, Spain. The arrest followed an investigation initiated by an FBI tip in August 2025. The individual is accused of providing logistical support to a Ukrainian hacker associated with CARR, facilitating their escape to Russia, and participating in cyber activities attributed to the pro-Russian hacktivist group NoName057(16). Authorities seized computers and cryptocurrency storage devices from the suspect's residence and froze a cryptocurrency wallet allegedly used for illicit payments. The suspect faces accusations of collaborating with a terrorist organization, glorifying terrorism, and damaging computers. ([cyberscoop.com](https://cyberscoop.com/spain-arrests-alleged-cyber-army-of-russia-reborn-member/?utm_source=openai)) This arrest underscores the ongoing international efforts to combat cyber threats posed by state-sponsored hacktivist groups targeting critical infrastructure. The collaboration between Spanish authorities and the FBI highlights the importance of cross-border cooperation in addressing cybercrime. Organizations are advised to remain vigilant against such threats and implement robust cybersecurity measures to protect their systems.
2 months ago
Kill Chain
Spain Arrests Suspected Member of Pro-Russian Hacktivist Groups
In March 2026, Spain's National Police, in collaboration with the FBI, arrested a 34-year-old Italian man in Palencia for his alleged involvement with pro-Russian hacktivist groups, including CyberArmy of Russia Reborn (CARR) and Z-Pentest. The suspect is accused of providing logistical support to a Ukrainian hacker affiliated with CARR, facilitating their escape to Russia via Poland and Belarus. Authorities seized computers and cryptocurrency storage devices during the operation. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/spain-arrests-suspected-member-of-pro-russian-hacktivist-groups/?utm_source=openai)) This arrest underscores the ongoing threat posed by pro-Russian hacktivist groups targeting critical infrastructure in the U.S. and Europe. The collaboration between international law enforcement agencies highlights the importance of coordinated efforts to combat cyber threats that exploit geopolitical tensions. ([nsa.gov](https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4355881/nsa-fbi-and-others-call-out-pro-russia-hacktivist-groups-targeting-critical-inf/?utm_source=openai))
2 months ago
Kill Chain
Armored Likho's 2026 Cyber-Espionage Campaign: BusySnake Infostealer Targets Critical Infrastructure
In July 2026, the previously unknown APT group 'Armored Likho' launched sophisticated cyber-espionage campaigns targeting government agencies and electric power entities in Russia, Brazil, and Kazakhstan. Utilizing spear-phishing emails disguised as official communications, they deployed the Python-based 'BusySnake' infostealer to exfiltrate sensitive data, including credentials and cryptographic keys. The malware's advanced obfuscation techniques and modular architecture enabled persistent access and evasion of detection mechanisms. This incident underscores the escalating threat posed by APT groups leveraging AI-generated malware to target critical infrastructure. Organizations must enhance their cybersecurity posture to defend against such evolving tactics.
2 months ago
Kill Chain
Armored Likho's BusySnake Stealer Targets Government and Energy Sectors
In July 2026, a previously undocumented threat actor known as Armored Likho launched cyber attacks targeting government agencies and the electric power sector in Russia, Brazil, and Kazakhstan. The group employed spear-phishing emails with lures related to official government notices or social programs, distributing RAR archives containing EXE binaries that served as droppers for additional payloads retrieved from a GitHub repository. These payloads included a newly identified Python-based information stealer named BusySnake Stealer, which is capable of stealing browser passwords, cookies, clipboard contents, screenshots, documents, Telegram session data, OTP secrets, and cryptocurrency wallet files. The malware establishes persistence through a combination of VBScript files and scheduled tasks, allowing the attackers to maintain prolonged access to compromised systems. This incident underscores the evolving tactics of cyber espionage groups, highlighting their ability to blend financially motivated campaigns with targeted attacks on critical infrastructure. The use of AI-generated first-stage loaders and obfuscated, modular remote access trojans (RATs) and infostealers specifically engineered to bypass dynamic analysis demonstrates a significant advancement in their capabilities. Organizations must remain vigilant and adapt their cybersecurity measures to counter these sophisticated threats.
2 months ago
Kill Chain
Critical Vulnerability in Schneider Electric's License Manager Poses Risks to Industrial Systems
In 2024, a critical vulnerability identified as CVE-2024-2658 was discovered in Schneider Electric's Floating License Manager, specifically within the FlexNet Publisher component. This flaw, classified under CWE-427: Uncontrolled Search Path Element, allows local non-administrative users to manipulate the OpenSSL configuration file, leading to the execution of arbitrary code with elevated privileges. Exploitation of this vulnerability can result in full control over the affected system, including access to sensitive data and potential lateral movement within industrial networks. The urgency to address this vulnerability is heightened by the increasing targeting of industrial control systems by cyber adversaries. Organizations utilizing Schneider Electric's software are advised to implement the recommended mitigations promptly to prevent potential exploitation and safeguard critical infrastructure.
2 months ago
Kill Chain
China-Linked Group Targets Southeast Asia Critical Systems
In mid-2025, the Chinese-speaking advanced persistent threat (APT) group CL-STA-1062 initiated a cyber espionage campaign targeting government entities and critical infrastructure in Southeast Asia. The group compromised at least 10 organizations, including state-owned enterprises in the energy and government sectors, deploying a custom backdoor named TinyRCT. This backdoor facilitated unauthorized access, data exfiltration, and system control, posing significant risks to national security and operational stability. ([thehackernews.com](https://thehackernews.com/2026/06/chinese-speaking-apt-deploys-new.html?utm_source=openai)) The emergence of TinyRCT underscores the evolving sophistication of state-sponsored cyber threats in the region. Organizations must enhance their cybersecurity measures to detect and mitigate such advanced persistent threats, ensuring the resilience of critical infrastructure against future attacks. ([thehackernews.com](https://thehackernews.com/2026/06/chinese-speaking-apt-deploys-new.html?utm_source=openai))
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports