The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Utilities

Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.

487 threat reports
Page 13 of 41

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Utilities Threat Reports

Showing 145–156 / 487 reports
Critical Vulnerabilities in Delta Electronics DVP12SE PLCs: CVE-2026-12819 and CVE-2026-12818
Impact· CRITICAL

Critical Vulnerabilities in Delta Electronics DVP12SE PLCs: CVE-2026-12819 and CVE-2026-12818

In June 2026, critical vulnerabilities were identified in Delta Electronics DVP12SE Programmable Logic Controllers (PLCs), specifically CVE-2026-12819 and CVE-2026-12818. These flaws allow remote attackers to issue commands, modify operational values, and interfere with control logic without authentication. The vulnerabilities affect all versions of the DVP12SE PLC, potentially enabling unauthorized access to sensitive control functions and causing resource exhaustion through flooding attacks. The discovery of these vulnerabilities underscores the increasing risks associated with industrial control systems (ICS) and the necessity for robust security measures. Organizations utilizing Delta Electronics DVP12SE PLCs should implement recommended mitigations, such as enabling IP filtering, setting up password protection, and ensuring network isolation, to safeguard against potential exploitation.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical XZ Utils Vulnerability Affects B&R Products (CVE-2025-31115)
Impact· HIGH

Critical XZ Utils Vulnerability Affects B&R Products (CVE-2025-31115)

In June 2026, B&R Industrial Automation GmbH disclosed a critical vulnerability (CVE-2025-31115) in their products due to a flaw in XZ Utils versions 5.3.3alpha to 5.8.0. This race condition within the multithreaded .xz decoder in liblzma could allow attackers to crash the system or corrupt memory data. Affected products include PPC3100, C50, C80, FT50, MT50, T30, T80, and T50, with specific versions listed in the advisory. The vulnerability has a CVSS v3 base score of 7.5, indicating high severity. ([cisa.gov](https://www.cisa.gov/sites/default/files/publications/web-metrics/CISA.gov-Apr-2024-Web-Metrics-508.pdf?utm_source=openai)) This incident underscores the importance of promptly addressing vulnerabilities in widely used open-source libraries. Organizations are advised to update to XZ Utils version 5.8.1 or apply the provided patches to mitigate potential risks. ([cisa.gov](https://www.cisa.gov/sites/default/files/publications/web-metrics/CISA.gov-Apr-2024-Web-Metrics-508.pdf?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Authentication Bypass in Frangoteam FUXA SCADA/HMI Software (CVE-2026-13207)
Impact· HIGH

Critical Authentication Bypass in Frangoteam FUXA SCADA/HMI Software (CVE-2026-13207)

In June 2026, a critical authentication bypass vulnerability (CVE-2026-13207) was identified in Frangoteam's FUXA SCADA/HMI software versions 1.3.1 and earlier. This flaw allows unauthenticated remote attackers to access sensitive user and role data by exploiting improper path normalization in the REST API. By manipulating URL paths with dot-segment sequences, attackers can bypass authentication checks and retrieve confidential information without credentials. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-13207?utm_source=openai)) This incident underscores the persistent risks associated with authentication bypass vulnerabilities in industrial control systems. As SCADA environments increasingly integrate web-based interfaces, ensuring robust authentication mechanisms becomes paramount to prevent unauthorized access and potential operational disruptions.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in Schneider Electric's EcoStruxure IT Data Center Expert: CVE-2026-8045
Impact· MEDIUM

Critical Vulnerability in Schneider Electric's EcoStruxure IT Data Center Expert: CVE-2026-8045

In June 2026, Schneider Electric disclosed a vulnerability (CVE-2026-8045) in its EcoStruxure IT Data Center Expert software, versions 9.1.1 and prior. This flaw, identified as an Improper Restriction of XML External Entity Reference (CWE-611), allows authenticated users to submit crafted XML payloads to SOAP service endpoints, potentially leading to unauthorized access and disclosure of sensitive server-side files. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-8045?utm_source=openai)) The vulnerability underscores the critical need for robust input validation and secure XML processing in software applications. Organizations utilizing affected versions should promptly apply the vendor-provided patch to mitigate potential risks associated with this security flaw.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities in Schneider Electric's EasyLogic T150 and Saitel DP RTUs
Impact· HIGH

Critical Vulnerabilities in Schneider Electric's EasyLogic T150 and Saitel DP RTUs

In June 2026, Schneider Electric disclosed two critical vulnerabilities affecting their EasyLogic T150 and Saitel DP Remote Terminal Units (RTUs). The first, CVE-2026-9650, involves insufficiently protected credentials, allowing unauthenticated attackers to access sensitive information stored within firmware or system files. The second, CVE-2026-9651, pertains to incorrect permission assignments for critical resources, enabling attackers with privileged local access to read improperly protected system files, potentially leading to account compromise. These vulnerabilities pose significant risks to critical infrastructure sectors, including manufacturing and energy, as they could lead to unauthorized access and control over essential systems. The disclosure of these vulnerabilities underscores the ongoing challenges in securing industrial control systems (ICS). As cyber threats targeting ICS continue to evolve, organizations must remain vigilant, regularly updating and patching their systems to mitigate potential risks. This incident highlights the importance of proactive cybersecurity measures and the need for continuous monitoring to protect critical infrastructure from emerging threats.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Nation-State Cyberattacks on Water Systems: A Growing Threat
Impact· CRITICAL

Nation-State Cyberattacks on Water Systems: A Growing Threat

Between 2024 and 2026, nation-state actors from Iran, Russia, and China have increasingly targeted water and wastewater systems worldwide. These cyberattacks exploit vulnerabilities such as weak passwords, exposed programmable logic controllers (PLCs), and inadequate network segmentation, leading to unauthorized access and potential operational disruptions. Notably, in 2025, Russian-linked actors caused a municipal water tank overflow in Muleshoe, Texas, by accessing a remote industrial interface. Similarly, Iranian groups have been observed exploiting exposed PLCs in the U.S. and Israel, while China's Volt Typhoon group has compromised critical infrastructure, including water systems, aiming for strategic pre-positioning. ([darkreading.com](https://www.darkreading.com/ics-ot-security/iran-russia-china-target-water-systems-sabotage?utm_source=openai)) The current relevance of these incidents is underscored by the persistent and evolving nature of cyber threats to critical infrastructure. The exploitation of basic security oversights by sophisticated threat actors highlights the urgent need for enhanced cybersecurity measures in the water sector to prevent potential disruptions and safeguard public health and safety.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Mustang Panda's Exploitation of Zoho WorkDrive in Indian Government Cyberattacks
Impact· HIGH

Mustang Panda's Exploitation of Zoho WorkDrive in Indian Government Cyberattacks

In June 2026, the China-aligned cyber espionage group Mustang Panda launched two concurrent campaigns targeting Indian government entities and the hydropower sector. Utilizing spear-phishing emails with thematic lures, the attackers delivered ZIP archives containing SHARDLOADER, a malicious loader that deployed two new implants: MINIRECON and ZOHOMURK. Notably, ZOHOMURK exploited Zoho WorkDrive, a legitimate cloud storage service, for command-and-control operations, enabling data exfiltration and remote task execution while evading detection by blending with normal network traffic. This incident underscores the evolving tactics of state-sponsored threat actors who increasingly abuse trusted cloud services to conceal malicious activities. Organizations, especially those in critical infrastructure sectors, must enhance their security measures to detect and mitigate such sophisticated threats.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Vulnerability in Yokogawa FAST/TOOLS and CI Server Exposes Sensitive Information
Impact· HIGH

Critical Vulnerability in Yokogawa FAST/TOOLS and CI Server Exposes Sensitive Information

In June 2026, a critical vulnerability (CVE-2026-11833) was identified in Yokogawa's FAST/TOOLS and Collaborative Information Server (CI Server). The web server component of these systems could return HTTP responses containing sensitive configuration information without requiring authentication. This flaw, present in FAST/TOOLS versions R9.01 through R10.04 and CI Server versions R1.01 through R1.04, exposes system settings that attackers could exploit for further attacks. The vulnerability has been assigned a CVSS 4.0 score of 8.2, indicating high severity. This incident underscores the ongoing risks associated with cleartext transmission of sensitive information in industrial control systems. Organizations utilizing these Yokogawa products should prioritize applying the recommended updates to mitigate potential exploitation and enhance their cybersecurity posture.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Security Flaws Discovered in EVoke Systems' Charging Station Management System
Impact· CRITICAL

Critical Security Flaws Discovered in EVoke Systems' Charging Station Management System

In June 2026, multiple critical vulnerabilities were identified in EVoke Systems' Charging Station Management System (CSMS), potentially allowing attackers to gain unauthorized administrative control over charging stations or disrupt services via denial-of-service attacks. The vulnerabilities include missing authentication for critical functions, improper restriction of excessive authentication attempts, insufficient session expiration, and insufficiently protected credentials. These flaws affect all versions of EVoke CSMS and pose significant risks to the energy and transportation sectors worldwide. The discovery of these vulnerabilities underscores the growing cybersecurity challenges in the electric vehicle infrastructure. As the adoption of EVs accelerates, ensuring the security of charging networks becomes paramount to prevent potential disruptions and safeguard user data.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Vulnerability in Horner Automation Cscape: CVE-2026-12897
Impact· HIGH

Critical Vulnerability in Horner Automation Cscape: CVE-2026-12897

In June 2026, a critical vulnerability (CVE-2026-12897) was identified in Horner Automation's Cscape software versions prior to 10.2 SP3. This out-of-bounds read flaw in the CSP file parser could allow local attackers to disclose sensitive information and execute arbitrary code. The vulnerability was reported by Michael Heinzl and has a CVSS v3 score of 7.8, indicating high severity. Horner Automation has released Cscape 10.2 SP3 to address this issue. This incident underscores the importance of timely software updates in industrial control systems. As cyber threats targeting critical manufacturing sectors increase, organizations must prioritize patch management and implement robust security measures to protect against potential exploits.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Schneider Electric PowerLogic P7 Vulnerabilities Disclosed in 2026
Impact· HIGH

Schneider Electric PowerLogic P7 Vulnerabilities Disclosed in 2026

In June 2026, Schneider Electric disclosed multiple vulnerabilities in its PowerLogic™ P7 product, including CVE-2026-9716 (NULL Pointer Dereference), CVE-2026-9717 (OS Command Injection), and CVE-2026-9718 (Reachable Assertion). These vulnerabilities could lead to denial-of-service conditions, unauthorized command execution, and system instability. Affected versions include PowerLogic™ P7 version 0.2.003.001.000 and prior. Schneider Electric has released firmware version V02.004.001 to address these issues. Organizations are advised to apply the update promptly to mitigate potential risks. ([radar.offseq.com](https://radar.offseq.com/threat/multiple-vulnerabilities-on-powerlogic-p7-e233bd41?utm_source=openai)) The disclosure underscores the critical importance of timely vulnerability management in industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, maintaining up-to-date systems and adhering to cybersecurity best practices are essential to safeguard operational integrity and prevent potential disruptions.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Vulnerability in Delta Electronics DTM Soft: CVE-2026-12578
Impact· HIGH

Critical Vulnerability in Delta Electronics DTM Soft: CVE-2026-12578

In June 2026, Delta Electronics' DTM Soft was found to have a critical vulnerability (CVE-2026-12578) involving the deserialization of untrusted data. This flaw allows attackers to execute arbitrary code by exploiting the software's handling of project files. The vulnerability affects all versions of DTM Soft, posing significant risks to systems utilizing this software. The discovery of this vulnerability underscores the ongoing challenges in securing industrial control systems, especially those integral to critical manufacturing sectors. Organizations are urged to apply the recommended mitigations promptly to prevent potential exploitation.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports