The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Utilities

Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.

487 threat reports
Page 29 of 41

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Utilities Threat Reports

Showing 337–348 / 487 reports
Researchers Disclose Widespread Automotive and EV Vulnerabilities at Pwn2Own 2026
Impact· low

Researchers Disclose Widespread Automotive and EV Vulnerabilities at Pwn2Own 2026

In January 2026, security researchers at the Pwn2Own Automotive World competition uncovered and exploited dozens of critical vulnerabilities in modern vehicle infotainment systems and EV (electric vehicle) chargers from multiple manufacturers. By chaining flaws across network interfaces and poorly secured APIs, attackers demonstrated the ability to remotely compromise vehicle systems, extract sensitive data, and gain unauthorized control over critical vehicle functions. While these attacks were conducted in a controlled, ethical hacking contest, they highlighted the substantial risks posed by connected automotive platforms, which often lack robust segmentation and encryption for internal and external communications. This incident underscores the rapidly escalating threat landscape facing the automotive industry as vehicles integrate more digital and cloud-connected components. The research-driven breach foreshadows what real-world adversaries may attempt, making it urgent for OEMs and suppliers to adopt zero trust, comprehensive monitoring, and proactive vulnerability management.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Sandworm’s 2025 DynoWiper Attack on Poland’s Power Grid: Lessons in Critical Infrastructure Resilience
Impact· high

Sandworm’s 2025 DynoWiper Attack on Poland’s Power Grid: Lessons in Critical Infrastructure Resilience

In late 2025, a highly targeted cyberattack attributed to the Sandworm group struck Poland's national power grid. Using custom data-wiping malware identified as DynoWiper, the attackers infiltrated critical infrastructure networks, demonstrating sophisticated knowledge of operational technology environments. The initial compromise involved lateral movement through segmented OT/IT networks, facilitated by exploitation of unprotected east-west traffic and weak segmentation controls. The subsequent deployment of DynoWiper caused destructive impacts, including service outages and loss of operational data across several regional substations, with cascading effects on grid stability and dependent sectors. Immediate containment was complicated by attacker persistence and the rapid spread of the wiper. This incident underscores the rising trend of advanced, nation-state wiper malware targeting critical infrastructure, reflecting a shift from espionage to destructive tactics. Organizations face elevated urgency to harden network segmentation, implement robust egress security, and adopt zero trust operational models in light of these evolving threats.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Pwn2Own Automotive 2026: Hackers Expose Record 76 Zero-Days in Cars, Chargers & Tesla
Impact· high

Pwn2Own Automotive 2026: Hackers Expose Record 76 Zero-Days in Cars, Chargers & Tesla

Between January 21–23, 2026, the Pwn2Own Automotive competition in Tokyo saw security researchers demonstrate a record-breaking 76 zero-day vulnerabilities across in-vehicle infotainment systems (IVIs), electric vehicle chargers, and automotive operating systems, including high-profile exploits against Tesla, Alpitronic, Autel, Kenwood, and other leading manufacturers. Teams leveraged physical and remote attack vectors, with notable attacks including USB-based chaining to breach Tesla’s infotainment system. The event awarded $1,047,000 in prizes, underscoring significant risks within connected automotive infrastructure. Vendors now have 90 days to issue security patches before public disclosure. This incident highlights a concerning rise in exploitable vulnerabilities within rapidly digitalizing automotive ecosystems. As vehicles integrate more software-driven services and connected devices, adversaries and researchers alike are increasingly shifting focus toward automotive cyberattacks—driving new urgency for robust segmentation, secure update mechanisms, and continuous monitoring.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Microsoft Uncovers 2026 Multi-Stage BEC Attack Targeting Energy Sector
Impact· high

Microsoft Uncovers 2026 Multi-Stage BEC Attack Targeting Energy Sector

In January 2026, Microsoft identified a sophisticated multi-stage business email compromise (BEC) attack targeting several prominent energy sector organizations. The attackers leveraged adversary-in-the-middle (AitM) phishing tactics, abusing SharePoint file-sharing services to distribute malicious payloads and gaining user trust with legitimate-looking links. Once initial access was achieved, the threat actors established persistent access by creating malicious inbox rules, allowing them to hijack email conversations, evade user detection, and execute fraudulent transactions. The campaign underscores the evolving nature of BEC schemes and their business impact, with potential exposure of sensitive data and financial losses. This incident exemplifies a significant escalation in the complexity and persistence of phishing-driven BEC campaigns affecting critical infrastructure. As regulatory scrutiny increases and attackers continually evolve tactics, this case highlights the urgent need for modern defenses against advanced social engineering and privileged access abuse.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Pwn2Own Automotive 2026: 29 Zero-Days Unmasked in Next-Gen Vehicle Tech
Impact· medium

Pwn2Own Automotive 2026: 29 Zero-Days Unmasked in Next-Gen Vehicle Tech

At Pwn2Own Automotive 2026 in Tokyo, security researchers exploited 29 zero-day vulnerabilities on the second day alone, targeting fully patched electric vehicle (EV) chargers, in-vehicle infotainment systems (IVI), and automotive operating systems. Over $439,000 in prizes was awarded for these findings, impacting vendors like Phoenix Contact, ChargePoint, Grizzl-E, Kenwood, Alpine, and Alpitronic HYC50. Notably, researcher teams used advanced exploit chains to achieve root access, demonstrating how attackers could potentially compromise critical automotive technology with little or no prior warning. The event underscores the growing attack surface in connected vehicles and the persistent risk posed by unreported vulnerabilities. This incident highlights a significant surge in automotive cybersecurity threats, especially as EV and smart vehicle adoption accelerates. The frequency and sophistication of these exploits illustrate the urgency for automakers and suppliers to prioritize vulnerability management, rapid patch deployment, and layered defense strategies to protect both consumer safety and data integrity.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Tesla and Leading Automakers Hacked at Pwn2Own Automotive 2026: 37 Zero-Days Uncovered
Impact· medium

Tesla and Leading Automakers Hacked at Pwn2Own Automotive 2026: 37 Zero-Days Uncovered

In January 2026, security researchers at the Pwn2Own Automotive competition in Tokyo successfully exploited 37 zero-day vulnerabilities across flagship automotive technologies, including Tesla's infotainment system, multiple EV chargers, and in-vehicle digital receivers. The Synacktiv team achieved root access on the Tesla Infotainment System through chained vulnerabilities involving an information leak and out-of-bounds write flaw via USB. Other researchers compromised systems from Sony, Alpitronic, Autel, Kenwood, and Phoenix Contact. The event demonstrates the breadth of exploitable attack surfaces even in patched, production automotive hardware and highlights coordinated vulnerability disclosure processes wherein vendors have 90 days to issue fixes. This incident underscores how automotive technology—including electric vehicles and charging infrastructure—remains a top target for advanced security researchers, with new zero-day vulnerabilities continually emerging. As vehicle software stacks grow in complexity and interconnectivity, the imperative for proactive, industry-wide security controls and coordinated patch processes is increasingly urgent.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Schneider Electric Foxboro DCS: Intel Side-Channel Flaw Threatens Critical Infrastructure (2026)
Impact· medium

Schneider Electric Foxboro DCS: Intel Side-Channel Flaw Threatens Critical Infrastructure (2026)

In late 2025 and early 2026, Schneider Electric disclosed a side-channel vulnerability (CVE-2018-12130) impacting its EcoStruxure Foxboro DCS product line, widely used in critical infrastructure globally. The issue, originating from Intel processor flaws, could allow authenticated local attackers to extract sensitive data via side-channel methods, potentially leading to unauthorized disclosure or manipulation of system functions. The exploit primarily affects specific Foxboro DCS servers and workstations running on vulnerable Intel CPUs. Schneider Electric issued upgrades and remediation guidance while urging organizations to implement defense-in-depth strategies to mitigate risk. This incident highlights ongoing industry concerns over hardware-level vulnerabilities affecting operational technology in high-stakes sectors such as energy and manufacturing. As threat actors increasingly target supply chain and embedded flaws, organizations are under mounting pressure from regulators and customers to update aging infrastructure, strengthen segmentation, and accelerate threat detection capabilities.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Rockwell Automation Verve Asset Manager Vulnerabilities: 2026 Lessons for Critical Infrastructure
Impact· low

Rockwell Automation Verve Asset Manager Vulnerabilities: 2026 Lessons for Critical Infrastructure

In January 2026, Rockwell Automation disclosed two significant vulnerabilities (CVE-2025-14376, CVE-2025-14377) in its Verve Asset Manager product. These flaws were rooted in insecure and cleartext storage of sensitive data within the legacy ADI server and Ansible playbook components, impacting versions 1.33 through 1.41.3. Exploitation could have allowed attackers with system or network access to retrieve confidential data from environment variables and process files, potentially facilitating lateral movement or further compromises. The issues were addressed in version 1.42, and vulnerable components were made optional in newer releases. This incident is particularly relevant amid heightened attention to supply chain risk and critical infrastructure cybersecurity. As industrial control vendors face rising regulatory pressure and expansion of zero-trust mandates, unencrypted data storage flaws highlight the urgent need for comprehensive data-in-transit and at-rest protections.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
UK Under Siege: NoName057(16) DDoS Attacks Target Critical Infrastructure in 2026
Impact· high

UK Under Siege: NoName057(16) DDoS Attacks Target Critical Infrastructure in 2026

In January 2026, the UK's National Cyber Security Centre (NCSC) issued a warning about ongoing DDoS attacks targeting critical infrastructure and local government organizations across the United Kingdom. These attacks are attributed to the pro-Russian hacktivist group NoName057(16), known for leveraging their crowdsourced DDoSia platform to coordinate massive denial-of-service campaigns. Despite an international law enforcement operation in mid-2025 that resulted in arrests and the takedown of supporting servers, the core operators evaded capture and resumed disruptive activities. The attacks, while technically unsophisticated, resulted in interruptions of public-facing services, forced organizations to invest in defensive measures, and threatened operational resilience. This incident underscores a broader trend of ideologically motivated hacktivism targeting Western critical infrastructure, amplified by evolving techniques and persistent threat actors. As geopolitical tensions rise and hacktivists increasingly collaborate via decentralized platforms, DDoS threats have become a significant operational risk for organizations across the public and private sectors.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Sitecore 2025: China-Linked APT UAT-8837’s Zero-Day Attack Reveals Modern Espionage Tactics
Impact· medium

Sitecore 2025: China-Linked APT UAT-8837’s Zero-Day Attack Reveals Modern Espionage Tactics

In early September 2025, an advanced persistent threat group known as UAT-8837, believed to be linked to China, exploited a zero-day vulnerability (CVE-2025-53690) in Sitecore products to gain initial access to critical infrastructure targets in North America. The attackers obtained credentials and leveraged living-off-the-land tools, open-source utilities, and custom backdoors—including 'WeepSteel'—to conduct deep reconnaissance, move laterally, and collect sensitive data such as credentials and Active Directory configurations. Post-exploitation activity also included disabling security controls and exfiltrating internal DLLs, which could be leveraged for future supply chain attacks. This incident spotlights a surge in targeted espionage exploiting both zero-day and known software vulnerabilities, with an emphasis on credential compromise and lateral movement. Growing overlap in TTPs among China-nexus actors and continued attack innovation reinforce the importance of modernizing defenses against sophisticated identity- and supply-chain-driven attacks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
China-Linked APT Leverages Sitecore Zero-Day to Target Critical Infrastructure (2025)
Impact· medium

China-Linked APT Leverages Sitecore Zero-Day to Target Critical Infrastructure (2025)

In late 2025, a China-nexus advanced persistent threat group tracked as UAT-8837 exploited a critical Sitecore zero-day vulnerability (CVE-2025-53690, CVSS 9.0) to compromise multiple critical infrastructure organizations in North America. Following initial access through vulnerable servers or compromised credentials, the threat actor leveraged open-source post-exploitation tools to steal sensitive credentials, manipulate Active Directory, and establish multiple persistent access channels. Attackers disabled security features like RestrictedAdmin for RDP and exfiltrated confidential assets, including proprietary DLL libraries, potentially setting the stage for future supply chain attacks or further reverse engineering efforts. This incident reflects a broader trend of sophisticated, state-linked attackers increasingly targeting operational technology environments and critical infrastructure, exploiting unpatched vulnerabilities and adopting living-off-the-land techniques. The ongoing relevance is underscored by heightened governmental warnings and the urgent need for robust vulnerability management, segmentation, and monitoring in high-value environments.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Schneider Electric EcoStruxure Rapsody Software Vulnerabilities Threaten Critical Infrastructure in 2026
Impact· medium

Schneider Electric EcoStruxure Rapsody Software Vulnerabilities Threaten Critical Infrastructure in 2026

In January 2026, Schneider Electric disclosed multiple critical software vulnerabilities (CVE-2025-13844, CVE-2025-13845) in its EcoStruxure Power Build Rapsody platform, widely used in the energy, manufacturing, and commercial facilities sectors. The flaws—specifically double free and use after free issues—stem from improper memory management when importing malicious project files, enabling local attackers to potentially execute arbitrary code. Impacted product versions are deployed worldwide. Schneider Electric and independent security researchers reported these vulnerabilities, urging customers to upgrade immediately or apply mitigations to prevent unauthorized system access and memory corruption. This incident highlights the continued threat posed by software supply chain attacks and memory corruption vulnerabilities in critical infrastructure environments. As attackers shift towards exploiting insecure file imports and legacy software flaws, organizations must prioritize secure software lifecycle management and timely patching to counter emerging risks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports