The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Utilities
Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.
Explore Other Sectors
Utilities Threat Reports
GE Vernova Enervista UR Setup Vulnerabilities Disclosed in 2026
In February 2026, GE Vernova disclosed two vulnerabilities in their Enervista UR Setup software versions prior to 8.70. CVE-2026-1762 involves a directory traversal flaw that allows unauthorized file manipulation, while CVE-2026-1763 pertains to a DLL hijacking issue enabling code execution with elevated privileges. Both vulnerabilities require local access for exploitation and have been addressed in version 8.70. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1762?utm_source=openai)) The disclosure underscores the importance of timely software updates and robust local security measures, especially in critical infrastructure sectors where such vulnerabilities can have significant operational impacts.
7 months ago
Kill Chain
Critical RADIUS Vulnerability in Hitachi Energy XMC20 Devices (CVE-2024-3596)
In July 2024, a critical vulnerability (CVE-2024-3596) was identified in the RADIUS protocol, affecting Hitachi Energy's XMC20 devices. This flaw allows an on-path attacker to forge RADIUS server responses by exploiting weaknesses in the MD5-based Response Authenticator, potentially granting unauthorized network access. The vulnerability impacts XMC20 versions R18, R17A, and earlier, particularly when configured for remote RADIUS authentication. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/222287-blast-radius-cve-2024-3596-protocol-sp.html?utm_source=openai)) The discovery underscores the risks associated with legacy cryptographic protocols like MD5. Organizations relying on RADIUS for authentication should promptly implement mitigations, such as enabling the Message-Authenticator attribute, to safeguard against potential exploits. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/222287-blast-radius-cve-2024-3596-protocol-sp.html?utm_source=openai))
7 months ago
Kill Chain
Critical Vulnerability in Open62541: Immediate Action Required
In February 2026, a medium-severity vulnerability (CVE-2026-1301) was identified in o6 Automation GmbH's Open62541, an open-source OPC UA stack widely used in industrial automation. The flaw, present in versions from 1.5-rc1 to before 1.5-rc2, allows unauthenticated attackers to send crafted JSON PubSub messages, leading to out-of-bounds writes, process crashes, and potential memory corruption. This vulnerability poses significant risks to industrial control systems, potentially causing operational disruptions and compromising system integrity. ([windowsforum.com](https://windowsforum.com/threads/cve-2026-1301-open62541-json-pubsub-memory-safety-bug-upgrade-to-v1-5-0.400263/?utm_source=openai)) The discovery of this vulnerability underscores the critical importance of rigorous security practices in industrial automation software. Organizations utilizing Open62541 should promptly upgrade to the stable release v1.5.0 to mitigate this risk. Additionally, implementing network segmentation and minimizing exposure of control systems to external networks are essential steps to enhance security posture. ([windowsforum.com](https://windowsforum.com/threads/cve-2026-1301-open62541-json-pubsub-memory-safety-bug-upgrade-to-v1-5-0.400263/?utm_source=openai))
7 months ago
Kill Chain
Critical Vulnerability in Hitachi Energy's FOX61x Products (CVE-2024-3596)
In January 2026, Hitachi Energy disclosed a critical vulnerability (CVE-2024-3596) in its FOX61x products, specifically affecting versions R18 and R17A and earlier. This flaw, inherent in the RADIUS protocol under RFC 2865, allows local attackers to modify valid responses through a chosen-prefix collision attack on the MD5 Response Authenticator signature. Exploitation could compromise the confidentiality, integrity, and availability of the affected systems. The vulnerability is particularly relevant when FOX61x devices are configured to use remote RADIUS authentication. ([it4automation.com](https://it4automation.com/security-alerts/hitachi-energy-fox61x-foxcst-and-foxman-un-products/?utm_source=openai)) This incident underscores the persistent risks associated with legacy authentication protocols and the importance of implementing robust security measures. Organizations utilizing FOX61x devices are urged to apply the recommended mitigations promptly to prevent potential exploitation.
7 months ago
Kill Chain
Mitsubishi Electric's 2026 PLC Vulnerability: A Wake-Up Call for Industrial Network Security
In February 2026, Mitsubishi Electric disclosed a critical vulnerability (CVE-2025-15080) in its MELSEC iQ-R Series programmable logic controllers (PLCs). This flaw allows unauthenticated attackers to read or modify device data and control programs, or to cause a denial-of-service condition by sending specially crafted packets. The affected models include R08PCPU, R16PCPU, R32PCPU, and R120PCPU with firmware versions up to 48. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-15080?utm_source=openai)) This incident underscores the persistent risks in industrial control systems, particularly those exposed to untrusted networks. Organizations must prioritize securing network access to critical infrastructure to prevent unauthorized exploitation of such vulnerabilities.
7 months ago
Kill Chain
Conpet's 2026 Cyberattack: A Wake-Up Call for Critical Infrastructure Security
In early February 2026, Conpet, Romania's national oil pipeline operator, experienced a cyberattack that disrupted its corporate IT infrastructure and rendered its website inaccessible. The Qilin ransomware group claimed responsibility, alleging the theft of nearly 1TB of sensitive documents, including financial records and personal identification data. Despite these disruptions, Conpet's operational technologies, such as the SCADA and telecommunications systems, remained unaffected, ensuring uninterrupted crude oil and gasoline transportation services. This incident underscores the escalating threat posed by ransomware groups like Qilin, which have increasingly targeted critical infrastructure sectors worldwide. Organizations must bolster their cybersecurity defenses to mitigate the risks associated with such sophisticated attacks.
7 months ago
Kill Chain
Salt Typhoon 2025: Unveiling the Global Espionage Campaign
In 2025, the Chinese state-sponsored cyber group known as Salt Typhoon orchestrated a sophisticated global espionage campaign, compromising government and critical infrastructure across 37 countries and conducting reconnaissance in 155 nations. The attackers exploited unpatched vulnerabilities in networking equipment, including those from Ivanti, Palo Alto, and Cisco, to gain initial access. Once inside, they established persistent access by modifying access control lists, creating privileged accounts, and enabling remote management on unusual high ports. This allowed them to monitor communications, harvest administrator credentials, and exfiltrate sensitive data through covert tunnels, all while remaining undetected for extended periods. The campaign's targets included telecommunications networks, government systems, transportation hubs, lodging networks, and military infrastructure, enabling continuous surveillance of individuals, communications, and movements globally. ([forbes.com](https://www.forbes.com/sites/emilsayegh/2025/08/30/us-and-allies-declare-salt-typhoon-hack-a-national-defense-crisis/?utm_source=openai)) The Salt Typhoon campaign underscores the escalating threat posed by state-sponsored cyber actors and the vulnerabilities within critical infrastructure. The attackers' ability to exploit known vulnerabilities and maintain long-term access highlights the urgent need for organizations to prioritize timely patching, robust access controls, and comprehensive monitoring to detect and mitigate such sophisticated threats.
7 months ago
Kill Chain
Critical Vulnerability in RISS SRL MOMA Seismic Station Firmware (CVE-2026-1632)
In February 2026, a critical vulnerability (CVE-2026-1632) was identified in RISS SRL's MOMA Seismic Station firmware versions up to and including v2.4.2520. The flaw exposes the device's web management interface without requiring authentication, allowing unauthenticated attackers to modify configuration settings, access sensitive data, or remotely reset the device. This vulnerability poses significant risks to seismic monitoring operations, potentially leading to data manipulation, unauthorized data access, and operational disruptions. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1632?utm_source=openai)) The absence of authentication mechanisms in critical infrastructure devices underscores the urgent need for robust security measures in industrial control systems. As cyber threats targeting operational technology (OT) environments increase, organizations must prioritize securing their OT assets to prevent potential exploitation and ensure the integrity of essential services.
7 months ago
Kill Chain
Critical Vulnerability in Avation Light Engine Pro Exposes Systems to Unauthorized Access
In February 2026, a critical vulnerability (CVE-2026-1341) was identified in Avation's Light Engine Pro devices, which are widely deployed in commercial facilities worldwide. The flaw involves the exposure of the device's configuration and control interface without any authentication or access control, potentially allowing unauthorized users to gain full control over the device. This vulnerability poses significant risks, including unauthorized access, data manipulation, and potential disruption of operations. ([itsecuritynews.info](https://www.itsecuritynews.info/avation-light-engine-pro/?utm_source=openai)) The absence of authentication mechanisms in critical infrastructure devices underscores the urgent need for robust security measures. Organizations must prioritize the implementation of authentication protocols and access controls to safeguard against such vulnerabilities, especially in devices integral to operational technology environments.
7 months ago
Kill Chain
Critical Vulnerability in Mitsubishi Electric's FREQSHIP-mini: CVE-2025-10314
In February 2026, Mitsubishi Electric disclosed a critical vulnerability (CVE-2025-10314) in its FREQSHIP-mini for Windows software, versions 8.0.0 to 8.0.2. The flaw arises from incorrect default permissions during installation, allowing local attackers to replace service executables or DLLs with malicious files. Exploiting this vulnerability enables arbitrary code execution with SYSTEM privileges, potentially leading to unauthorized access, data manipulation, or denial-of-service conditions. This vulnerability is particularly concerning for critical infrastructure sectors, including manufacturing and energy, where FREQSHIP-mini is commonly deployed. Organizations are urged to update to version 8.1.0 or later and implement recommended mitigation measures to prevent exploitation. ([jvn.jp](https://jvn.jp/en/jp/JVN64883963/?utm_source=openai))
7 months ago
Kill Chain
Critical Unauthenticated Access Vulnerability in Synectix LAN 232 TRIO
In February 2026, a critical vulnerability (CVE-2026-1633) was identified in the Synectix LAN 232 TRIO 3-Port serial to Ethernet adapter. This flaw allows unauthenticated users to access the device's web management interface, enabling them to modify critical settings or perform a factory reset. The vulnerability has a CVSS score of 10.0, indicating maximum severity. Synectix is no longer in business, leaving the affected devices without official support or patches. ([securityonline.info](https://securityonline.info/unpatchable-critical-cisa-issues-cvss-10-0-alert-for-synectix-adapters/?utm_source=openai)) This incident underscores the risks associated with using unsupported legacy devices in critical infrastructure. Organizations must proactively identify and replace such equipment to mitigate potential security threats. ([securityonline.info](https://securityonline.info/unpatchable-critical-cisa-issues-cvss-10-0-alert-for-synectix-adapters/?utm_source=openai))
7 months ago
Kill Chain
Poland's Energy Sector Cyberattack: A Wake-Up Call for Critical Infrastructure Security
On December 29, 2025, coordinated cyberattacks targeted over 30 wind and photovoltaic farms, a manufacturing company, and a large combined heat and power plant in Poland. The attacks, attributed to the Russian state-sponsored group Static Tundra (also known as Berserk Bear or Dragonfly), aimed to disrupt energy infrastructure by deploying wiper malware designed to destroy data and disable systems. While the attacks caused communication disruptions, they did not interrupt energy production or heat supply to consumers. ([cert.pl](https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/?utm_source=openai)) This incident underscores the escalating threat of nation-state cyberattacks on critical infrastructure, highlighting the need for enhanced cybersecurity measures and international cooperation to protect essential services from sophisticated adversaries.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports