The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Utilities

Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.

487 threat reports
Page 2 of 41

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Utilities Threat Reports

Showing 13–24 / 487 reports
Critical Privilege Escalation Flaw Exposes ABB Industrial Edge Computing Platforms
Impact· HIGH

Critical Privilege Escalation Flaw Exposes ABB Industrial Edge Computing Platforms

ABB disclosed CVE-2026-31431 (Copy Fail), a critical Linux kernel vulnerability affecting ABB Ability Edgenius edge computing platforms versions 3.2.0.0 through 3.2.4.1. The vulnerability, with a CVSS score of 7.8, stems from incorrect resource transfer in the Linux kernel's cryptographic subsystem and allows locally authenticated users or compromised container workloads to escalate privileges to root access. Once exploited, attackers gain complete system control over industrial edge computing infrastructure deployed globally across critical manufacturing, energy, water, and chemical sectors. ABB has released version 3.2.4.1 to address the vulnerability and recommends immediate patching. This incident highlights the growing attack surface of edge computing in industrial environments, where kernel-level vulnerabilities can provide attackers with deep system access to compromise operational technology networks and critical infrastructure control systems.

6 days ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CVE-2025-6625: Critical FTP Vulnerability in Schneider Electric Industrial Controllers
Impact· HIGH

CVE-2025-6625: Critical FTP Vulnerability in Schneider Electric Industrial Controllers

Schneider Electric disclosed CVE-2025-6625, a high-severity improper input validation vulnerability affecting Modicon M340 controllers and communication modules used across critical infrastructure sectors including energy, chemical, and water systems. The vulnerability allows attackers to send crafted FTP commands to cause denial of service attacks, potentially disrupting industrial control systems. Multiple product versions are affected, with firmware updates available for some modules while others await remediation. The vulnerability carries a CVSS score of 7.5 and impacts globally deployed industrial automation systems. This incident highlights the ongoing security challenges facing industrial control systems as threat actors increasingly target operational technology environments. With critical infrastructure under heightened scrutiny following recent nation-state campaigns, vulnerabilities in widely-deployed industrial controllers represent significant risk amplification across interconnected systems.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical Vulnerabilities Expose Schneider Electric NetBotz Environmental Monitors to Attack
Impact· HIGH

Critical Vulnerabilities Expose Schneider Electric NetBotz Environmental Monitors to Attack

Schneider Electric disclosed multiple critical vulnerabilities in its NetBotz 5-750/755 environmental monitoring devices affecting versions 5.5.2 and prior. The vulnerabilities include CVE-2026-13336, an OS command injection flaw that could allow arbitrary Linux command execution through maliciously modified system backups, and CVE-2026-13337, a Hibernate SQL injection vulnerability enabling malicious HQL query injection via web interfaces. These devices monitor critical infrastructure environments including temperature, humidity, and security systems across commercial facilities and manufacturing sectors worldwide. The vulnerabilities pose significant risks of device manipulation, unauthorized data access, and potential compromise of critical infrastructure monitoring capabilities. Schneider Electric has released version 5.6.0 as a remediation, requiring system restart for proper installation. The company emphasizes the importance of network segmentation and access controls to mitigate exploitation risks in industrial control environments.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities Disclosed in Hitachi Energy Power Grid Control Systems
Impact· CRITICAL

Critical Vulnerabilities Disclosed in Hitachi Energy Power Grid Control Systems

CISA published advisory ICSA-26-260-03 disclosing critical vulnerabilities in Hitachi Energy's FACTS Control Platform (FCP) affecting multiple versions from 3.4.0 to 4.1.1 when deployed with the GWS component. The vulnerabilities include SQL injection (CVE-2024-4872), path traversal (CVE-2024-3980), session hijacking (CVE-2024-3982), missing authentication (CVE-2024-7940), and open redirect (CVE-2024-7941) with CVSS scores ranging from 4.3 to 9.9. These flaws could allow authenticated attackers to execute code injection, access critical system files, hijack sessions, and redirect users to malicious sites, potentially compromising the confidentiality, integrity, and availability of critical power grid infrastructure. This disclosure highlights the growing cybersecurity challenges facing operational technology in the energy sector, particularly as industrial control systems become increasingly connected and targeted by sophisticated threat actors seeking to disrupt critical infrastructure operations.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Authentication Bypass in Mitsubishi Electric GX Works3 Exposes Industrial Control Systems
Impact· CRITICAL

Critical Authentication Bypass in Mitsubishi Electric GX Works3 Exposes Industrial Control Systems

In September 2026, CISA disclosed CVE-2026-15688, a critical authentication bypass vulnerability in Mitsubishi Electric's GX Works3 and Motion Control Settings software used in industrial control systems worldwide. The vulnerability, scored 8.8 (CVSS v3.1) and 9.2 (CVSS v4.0), allows local attackers to bypass block password authentication by modifying executable modules in memory, enabling unauthorized access to view, tamper with, destroy, or delete control programs in critical manufacturing environments. This incident highlights the growing threat landscape targeting industrial control systems as cyber adversaries increasingly focus on critical infrastructure. With ICS environments becoming more connected and the rise of sophisticated state-sponsored attacks on manufacturing facilities, authentication vulnerabilities in widely-deployed engineering software represent significant risks to operational technology security and industrial resilience.

6 days ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Authentication Flaw Exposes Schneider Electric PowerChute Systems to Bypass Attacks
Impact· MEDIUM

Critical Authentication Flaw Exposes Schneider Electric PowerChute Systems to Bypass Attacks

Schneider Electric disclosed a critical vulnerability (CVE-2026-13348) in PowerChute Serial Shutdown versions 1.5 and earlier, affecting UPS management software used globally across critical infrastructure sectors including energy, manufacturing, and IT facilities. The vulnerability enables attackers to perform unlimited authentication attempts when redirect handling is disabled, potentially leading to unauthorized system access and operational disruption of power management systems. The flaw carries a CVSS score of 5.3 and has been addressed in version 1.6 with automatic service restart upon installation. This incident highlights the growing security risks in industrial control systems and power management infrastructure, particularly as organizations increasingly digitize their operational technology environments. With critical infrastructure under heightened scrutiny following recent nation-state campaigns targeting power grids and manufacturing facilities, vulnerabilities in widely-deployed UPS management systems represent significant attack surface expansion for threat actors seeking to disrupt industrial operations.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
How Iranian Cyber Operations Target the Hidden Infrastructure Behind U.S. Military Power
Impact· HIGH

How Iranian Cyber Operations Target the Hidden Infrastructure Behind U.S. Military Power

Iranian cyber operations are increasingly targeting the interconnected civilian infrastructure that supports U.S. military operations, including commercial railroads, ports, utilities, and defense contractors. Rather than pursuing catastrophic single attacks, Iranian threat groups are conducting persistent, volume-based campaigns across multiple smaller targets to strain response capabilities and disrupt military logistics chains. Recent attacks on water utilities across 12 states and a four-day power plant outage in the UK demonstrate this strategy of imposing cumulative operational strain rather than seeking headline-grabbing breaches. This threat model reflects Iran's adaptation to prolonged conflict scenarios, where creating sustained disruption across military-supporting infrastructure becomes more strategically valuable than traditional espionage or single-point failures.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
CenterPoint Energy Breach Exposes 7.49M Records Through Unsecured API
Impact· HIGH

CenterPoint Energy Breach Exposes 7.49M Records Through Unsecured API

CenterPoint Energy, a Houston-based utility serving 7 million customers across Texas, Indiana, Minnesota, and Ohio, confirmed a significant data breach in September 2026 after a threat actor using the alias '4d722e4d656f77' stole 7.49 million customer records. The attacker exploited an unsecured public API lacking rate limiting and web application firewall protection, iterating through millions of customer IDs to extract names, phone numbers, addresses, account numbers, billing amounts, and partial Social Security numbers. When the company failed to respond to the threat actor's initial contact, the stolen data was publicly leaked, prompting multiple class-action lawsuits and SEC disclosure. This incident highlights the critical vulnerability of inadequately secured public APIs in utility infrastructure, occurring amid increased scrutiny of energy sector cybersecurity following recent attacks on critical infrastructure. The breach demonstrates how basic API security misconfigurations can lead to massive data exposure, emphasizing the urgent need for proper rate limiting, authentication, and monitoring on all external-facing systems.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Sandworm's Cyclops Blink Evolution: How Russian APT Exploited Cisco Infrastructure
Impact· MEDIUM

Sandworm's Cyclops Blink Evolution: How Russian APT Exploited Cisco Infrastructure

In September 2026, the Russian state-sponsored threat group Sandworm exploited two critical vulnerabilities in Cisco's Firewall Management Center (FMC) software to deploy an upgraded version of the Cyclops Blink malware. The attackers chained CVE-2026-20079 (a maximum severity authentication bypass flaw) with CVE-2026-20316 (a privilege escalation vulnerability) to gain root access and deploy sophisticated backdoors capable of credential harvesting, network scanning, and traffic interception. This campaign represents a significant evolution of Cyclops Blink from its original 2022 variant, now targeting 64-bit Linux systems with enhanced reconnaissance capabilities across network infrastructure devices. This incident highlights the growing trend of state-sponsored actors targeting critical network infrastructure through vulnerability chaining, demonstrating how APT groups are rapidly adapting their malware arsenals to exploit modern enterprise environments and expanding their attack surface beyond traditional endpoints to network management platforms.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Siemens Reyrolle 7SR5 Vulnerabilities Threaten Power Grid Security
Impact· CRITICAL

Critical Siemens Reyrolle 7SR5 Vulnerabilities Threaten Power Grid Security

Siemens Reyrolle 7SR5 protection relay systems before version 2.70 are affected by 14 critical vulnerabilities, including authentication bypass, session hijacking, and buffer overflow conditions. These vulnerabilities in the Cesanta Mongoose Web Server component allow unauthenticated remote attackers to gain administrative access, execute arbitrary code, and cause denial-of-service conditions on critical power grid protection equipment deployed worldwide. The highest severity vulnerability (CVE-2026-62645) achieves a CVSS score of 9.8, enabling complete system compromise through predictable session identifiers and missing authentication controls. These vulnerabilities highlight the growing cybersecurity risks in operational technology (OT) environments, particularly as critical infrastructure becomes increasingly connected and exposed to network-based attacks targeting industrial control systems.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Hardcoded Key Vulnerabilities Expose Maritime Infrastructure in Wärtsilä FOS-Onboard Systems
Impact· HIGH

Critical Hardcoded Key Vulnerabilities Expose Maritime Infrastructure in Wärtsilä FOS-Onboard Systems

Critical vulnerabilities CVE-2026-78225 and CVE-2026-81855 were discovered in Wärtsilä FOS-Onboard version 5.07.0923.01, affecting maritime transportation systems worldwide. Both vulnerabilities involve hardcoded cryptographic keys - one in the deployer-ng Update Controller component and another in the robot testing framework component. With CVSS scores of 9.0 and 9.1 respectively, successful exploitation could allow attackers to deliver unauthorized updates, execute arbitrary code, or extract credentials to impersonate privileged clients. Wärtsilä has developed security patches and states the vulnerabilities are not exploitable when the product is installed according to recommendations. This incident highlights the growing threat to maritime critical infrastructure as operational technology systems become increasingly connected and targeted by sophisticated adversaries seeking to disrupt global supply chains.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical Vulnerability in Schneider Electric SCADAPack x70 Systems Exposes Industrial Infrastructure
Impact· MEDIUM

Critical Vulnerability in Schneider Electric SCADAPack x70 Systems Exposes Industrial Infrastructure

Schneider Electric disclosed a critical vulnerability (CVE-2026-81861) affecting all versions of its SCADAPack x70 Remote Terminal Units used in critical infrastructure worldwide. The insufficiently protected credentials vulnerability could allow unauthorized access to RTU configuration through the legacy Secure Lock functionality, potentially compromising confidentiality of industrial control systems. The vulnerability affects SCADAPack 47x, 47xi, 47xd, 470R, 57x, 3xx, and 32 products deployed globally in critical manufacturing and energy sectors. Industrial control system vulnerabilities continue to represent a significant threat vector as critical infrastructure increasingly becomes a target for nation-state actors and ransomware groups seeking to disrupt essential services and cause maximum societal impact.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports