The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Utilities
Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.
Explore Other Sectors
Utilities Threat Reports
Navigating the 'Smash-and-Grab Era': Understanding Rapid AI-Driven Cyber Threats
In 2026, cybersecurity experts identified a significant shift in cyberattack methodologies, termed the 'Smash-and-Grab Era.' This new approach is characterized by rapid, parallel attacks facilitated by advanced technologies like Large Language Models (LLMs). Unlike previous 'low and slow' tactics, attackers now execute swift operations, exploiting vulnerabilities and exfiltrating data within hours. This evolution challenges traditional detection and response strategies, as defenders struggle to manage multiple simultaneous attack vectors effectively. The emergence of this era underscores the urgent need for organizations to adapt their cybersecurity frameworks. The integration of AI in cyberattacks has accelerated the speed and complexity of threats, rendering conventional defense mechanisms less effective. As attackers leverage AI to automate and scale their operations, it is imperative for defenders to enhance their capabilities to detect and respond to these rapid, multifaceted attacks.
3 months ago
Kill Chain
Critical Vulnerabilities in Rockwell Automation FLEX I/O EtherNet/IP Adapters: CVE-2026-0646 and CVE-2026-0647
In June 2026, Rockwell Automation disclosed two critical vulnerabilities affecting their FLEX I/O EtherNet/IP Adapters, specifically models 1794-AENTR and 1794-AENTRXT version 2.012. The first vulnerability (CVE-2026-0646) involves improper memory handling of CIP protocol requests, leading to a denial-of-service condition that requires a manual reset. The second vulnerability (CVE-2026-0647) allows unauthenticated attackers to change the device's web interface password via a crafted HTTP GET request, potentially resulting in unauthorized access and account takeover. ([netstorage.rockwellautomation.com](https://netstorage.rockwellautomation.com/WebFiles/Resources/RAFirmware/1794-Products/1794-RN076G-EN-E.pdf?rwtoken=1778347671_97396ee2108d37e1ebe005d3b4e136a3&utm_source=openai)) These vulnerabilities are particularly concerning for critical manufacturing sectors, as exploitation could disrupt industrial operations and compromise system integrity. The increasing connectivity of industrial control systems heightens the risk of such vulnerabilities being exploited, emphasizing the need for timely updates and robust security measures.
3 months ago
Kill Chain
Critical Vulnerability in Rockwell Automation's FactoryTalk Analytics PavilionX: CVE-2025-14272
In June 2026, Rockwell Automation disclosed a critical vulnerability (CVE-2025-14272) in its FactoryTalk Analytics PavilionX software, versions prior to 7.01. This flaw arises from improper authorization enforcement in API endpoints, potentially allowing unauthorized actors to execute privileged operations, including user and role management. The vulnerability affects critical manufacturing sectors worldwide, with Rockwell Automation headquartered in the United States. To mitigate this risk, users are advised to update to version 7.01 or later. This incident underscores the persistent challenges in securing industrial control systems (ICS) and the importance of timely software updates. As cyber threats targeting ICS environments continue to evolve, organizations must remain vigilant and proactive in addressing vulnerabilities to safeguard operational integrity.
3 months ago
Kill Chain
Critical DoS Vulnerability in Rockwell Automation RSLinx Classic: CVE-2020-13573
In November 2020, a denial-of-service (DoS) vulnerability, identified as CVE-2020-13573, was discovered in Rockwell Automation's RSLinx Classic software, version 2.57.00.14 CPR 9 SR 3. This vulnerability resides in the Ethernet/IP server functionality and can be exploited by remote attackers sending specially crafted network requests, leading to a DoS condition. The vulnerability was reported by Cisco Talos and has a CVSS v3.0 base score of 7.5, indicating high severity. ([talosintelligence.com](https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1184?utm_source=openai)) The relevance of this vulnerability persists due to the widespread deployment of RSLinx Classic in industrial control systems. Exploitation could disrupt critical manufacturing, energy, and water sectors, emphasizing the need for timely patching and adherence to cybersecurity best practices to mitigate potential threats.
3 months ago
Kill Chain
Operation Highland: Unveiling a Decade of Stealthy Cyber-Espionage
In 2026, cybersecurity researchers uncovered 'Operation Highland,' a decade-long cyber-espionage campaign by the Chinese state-sponsored group Velvet Ant. Beginning in 2016, the attackers initially compromised internet-facing servers, deploying modified GS-Netcat reverse shells for encrypted remote access. They then installed custom SOCKS5 proxies to tunnel traffic, enabling access to isolated networks. By backdooring Linux Pluggable Authentication Modules (PAM) and OpenSSH components, Velvet Ant harvested credentials and maintained persistent access, effectively embedding themselves within the authentication process. This allowed them to monitor administrative activities and exfiltrate sensitive data undetected for ten years. The discovery of this prolonged intrusion underscores the evolving sophistication of state-sponsored cyber threats. It highlights the critical need for organizations to implement robust monitoring of authentication systems, conduct regular integrity checks of security components, and adopt a zero-trust security model to mitigate the risk of such stealthy and persistent attacks.
3 months ago
Kill Chain
Russian National Charged in Connection with Void Blizzard Espionage Campaign
In June 2026, U.S. federal prosecutors charged Denis Nikolayevich Obrezko, a Russian national, with conspiracy to commit unauthorized computer access. Obrezko is accused of facilitating cyber-espionage operations for the Russia-aligned threat group Void Blizzard by procuring virtual private servers and domain names used in attacks targeting businesses, educational institutions, and other organizations. The FBI's investigation revealed that Void Blizzard primarily relied on stolen session tokens to authenticate to victim accounts without triggering re-authentication requirements, and used U.S.-based commercial proxy services to mask the connection's location. The group targeted at least 11 U.S. companies, with the actual number of victims likely being higher. ([cyberscoop.com](https://cyberscoop.com/russian-national-charged-void-blizzard-cyber-espionage/?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber-espionage groups like Void Blizzard, which have been active since at least April 2024, targeting critical sectors across NATO member states and Ukraine. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/?utm_source=openai)) The group's methods, while not technically advanced, have proven effective, highlighting the need for organizations to implement robust cybersecurity measures to protect against such threats.
3 months ago
Kill Chain
Kyushu Electric Power Data Breach: 10.9 Million Customer Records Exposed
In April 2026, Kyushu Electric Power Co., Inc., a major Japanese utility company, experienced a significant data breach involving the loss of an external storage device containing personal information of approximately 10.9 million customers. The device, used for routine data backups, was stored in a server room cabinet with multiple physical security layers. On May 26, IT staff discovered the cabinet unlocked and the device missing. The data included customer names, service addresses, electricity usage data, telephone numbers, and names of retail electricity providers. Notably, no bank account or credit card information was stored on the device. The company has notified affected customers and relevant authorities, including Japan’s Personal Information Protection Commission and the Ministry of Economy, Trade, and Industry. Investigations are ongoing, with no evidence of data leakage confirmed as of now. This incident underscores the critical importance of robust physical security measures and strict access controls for sensitive data storage. It highlights the need for organizations to regularly review and enhance their data protection protocols to prevent unauthorized access and potential data breaches.
3 months ago
Kill Chain
Critical Vulnerability in Schneider Electric Modicon Switches: CVE-2024-3596
In April 2026, Schneider Electric disclosed a critical vulnerability (CVE-2024-3596) affecting all versions of its Modicon and Connexium managed network switches. This flaw resides in the RADIUS authentication protocol, where an attacker with a man-in-the-middle position can exploit the MD5-based Response Authenticator to forge authentication responses. Such exploitation could grant unauthorized access to protected network segments, leading to potential denial of service and compromise of confidentiality and integrity of connected devices. This vulnerability underscores the persistent risks associated with legacy cryptographic protocols like MD5 in critical infrastructure. Organizations relying on RADIUS for network access control must reassess their configurations and consider transitioning to more secure authentication methods to mitigate such threats.
3 months ago
Kill Chain
Critical Vulnerability in Schneider Electric's EcoStruxure Panel Server Devices (CVE-2026-6866)
In May 2026, Schneider Electric disclosed a vulnerability (CVE-2026-6866) in its EcoStruxure Panel Server devices, including models PAS400, PAS600, PAS600V2, PAS800, and PAS800V2, running firmware versions 002.005.000 and prior. This flaw, identified as CWE-1188, allows device credentials to revert to factory defaults under rare conditions, potentially enabling unauthorized access to operational technology (OT) networks. The vulnerability poses a significant risk to critical infrastructure sectors such as energy, utilities, and manufacturing, as it could lead to unauthorized disclosure of sensitive information. Schneider Electric has released firmware version 002.006.000 to address this issue. Organizations are urged to apply this update promptly to mitigate potential security breaches. ([techjacksolutions.com](https://techjacksolutions.com/scc-intel/schneider-electric-ecostruxure-panel-server-credential-reset-flaw-exposes-ot-gateways-in-critical-infrastructure/?utm_source=openai)) The incident underscores the importance of maintaining up-to-date firmware and implementing robust access controls in OT environments. As cyber threats targeting industrial control systems continue to evolve, ensuring the security of gateway devices like the EcoStruxure Panel Server is crucial to prevent unauthorized access and protect critical infrastructure.
3 months ago
Kill Chain
VerdantBamboo's Prolonged Cyber Espionage via BRICKSTORM Backdoor
In September 2025, cybersecurity firm Volexity identified a prolonged cyber espionage campaign by the Chinese state-sponsored group VerdantBamboo, also known as UNC5221. The attackers exploited a local privilege escalation vulnerability in an Egnyte Storage Sync appliance to deploy a BSD variant of the BRICKSTORM backdoor, maintaining undetected access for at least 18 months. This access facilitated further infiltration into the victim's Microsoft 365 environment and the deployment of additional malware, including PLENET and AGENTPSD, on various network appliances. The campaign underscores the increasing targeting of network appliances and storage systems by sophisticated threat actors, exploiting their lack of endpoint detection capabilities to establish long-term persistence. Organizations are urged to enhance monitoring and security measures for such devices to mitigate similar threats.
3 months ago
Kill Chain
Cyberattacks on U.S. Fuel Tank Monitoring Systems: A 2026 Overview
In June 2026, U.S. critical infrastructure sectors, including energy and transportation, faced cyberattacks targeting internet-exposed Automatic Tank Gauge (ATG) systems. These systems, essential for monitoring fuel and liquid levels, were compromised by threat actors exploiting vulnerabilities such as default passwords and command execution flaws. The attackers manipulated system settings, altered tank readings, and disabled alerts, posing significant operational and safety risks. In response, agencies like CISA, NSA, and FBI issued joint advisories urging organizations to secure ATG systems by removing them from public internet access, enforcing strong credentials, and applying necessary patches. This incident underscores the escalating threat to industrial control systems and the urgent need for enhanced cybersecurity measures to protect critical infrastructure from sophisticated cyber threats.
3 months ago
Kill Chain
Over 900 US Gas Station Tank Gauge Systems Exposed to Cyberattacks
In June 2026, over 900 Automatic Tank Gauge (ATG) systems across the United States were found exposed online, making them vulnerable to cyberattacks. ATG systems are critical for monitoring fuel and chemical storage tanks in various sectors, including energy and transportation. Threat actors exploited security flaws such as hardcoded credentials and authentication bypasses to gain unauthorized access, potentially leading to operational disruptions and safety hazards. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/over-900-us-gas-station-tank-gauge-systems-exposed-to-attacks/amp/?utm_source=openai)) This incident underscores the growing threat to critical infrastructure from cyberattacks targeting industrial control systems. Organizations must prioritize securing internet-exposed devices to prevent similar vulnerabilities from being exploited in the future.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports