The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Utilities
Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.
Explore Other Sectors
Utilities Threat Reports
Mitsubishi Electric 2025: Denial-of-Service Vulnerability Impacts Industrial Control Systems
In November 2025, a denial-of-service (DoS) vulnerability (CVE-2025-10259) impacting Mitsubishi Electric MELSEC iQ-F Series programmable logic controllers was publicly disclosed. Researchers from Zhongguancun Laboratory and Tsinghua University identified that improper validation in the TCP communication module allowed remote attackers to send specially crafted TCP packets, causing affected devices to disconnect and become temporarily unresponsive. The vulnerability (CVSS 5.3) requires no authentication and can be exploited remotely, posing a notable risk to industrial control systems in the critical manufacturing sector worldwide. This incident highlights persistent cybersecurity weaknesses in industrial IoT and critical infrastructure devices, which attackers increasingly target to disrupt operations. As regulatory expectations and threat actor sophistication rise, even moderate-severity flaws in ICS environments must be prioritized and mitigated decisively.
8 months ago
Kill Chain
Rockwell Automation FactoryTalk DataMosaix: 2025 ICS Cloud Vulnerabilities Expose Industrial Risk
In November 2025, Rockwell Automation disclosed two critical vulnerabilities in its FactoryTalk DataMosaix Private Cloud platform, widely used across critical manufacturing sectors. The flaws include a weak authentication mechanism (CVE-2025-11084) that enables attackers to bypass MFA and gain unauthorized access, and a persistent cross-site scripting bug (CVE-2025-11085) that could facilitate account takeover, credential theft, or redirecting users to malicious sites. Rockwell and CISA jointly warned that attackers could exploit these remotely and potentially take control of sensitive ICS data or operations globally, demanding urgent updates. These vulnerabilities underscore rising risks tied to identity-driven attacks and web-based threats targeting industrial control environments. With Ransomware-as-a-Service and supply chain attacks escalating, organizations in critical sectors face mounting pressure to implement multi-layered controls and update legacy authentication practices.
8 months ago
Kill Chain
AVEVA Edge 2025: Cryptographic Weakness Leaves Critical Manufacturing at Risk
In November 2025, AVEVA disclosed a critical vulnerability (CVE-2025-9317) in its Edge HMI/SCADA software (versions 2023 R2 and prior), stemming from the use of a broken or risky cryptographic algorithm. The flaw allows local attackers with read access to Edge project or cache files to reverse engineer both application-native and Active Directory passwords via brute-force techniques. This security gap exposes organizations using AVEVA Edge in the critical manufacturing sector to unauthorized credential recovery, potentially impacting operational technology environments on a global scale. The incident highlights increased scrutiny of industrial control software security, especially against a backdrop of escalating supply chain and OT attacks. Regulatory and compliance pressures are intensifying, and organizations are urged to prioritize cryptographic hygiene, proactive patching, and strict access controls to mitigate insider and lateral threat risks.
8 months ago
Kill Chain
Critical Flaws in General Industrial Controls Lynx+ Gateway Threaten Manufacturing Security (2025)
In November 2025, critical vulnerabilities were discovered in General Industrial Controls' Lynx+ Gateway devices deployed worldwide across the critical manufacturing sector. The exposed flaws—included weak password requirements, missing authentication for critical functions, and cleartext transmission of sensitive information—allowed attackers to remotely access devices, obtain sensitive information, and, in some cases, potentially cause denial-of-service conditions. Multiple CVEs (CVE-2025-55034, CVE-2025-58083, CVE-2025-59780, CVE-2025-62765) were assigned, with the highest CVSS v4 base score reaching 9.2. Despite coordinated disclosure efforts, the vendor did not respond, leaving organizations reliant on their own layered defense measures. This incident is highly relevant as it highlights persistent challenges in secure authentication and encrypted traffic within operational technology environments. The surge in attacks exploiting similar unauthenticated remote access and cleartext weaknesses continues to drive regulatory pressure for zero trust and encryption controls within industrial networks.
8 months ago
Kill Chain
Siemens Altair Grid Engine 2025: Local Privilege Escalation and OT Vulnerability Risks
In November 2025, Siemens disclosed two local privilege escalation vulnerabilities affecting all versions of Altair Grid Engine prior to V2026.0.0. These flaws, identified as CVE-2025-40760 (Generation of Error Message Containing Sensitive Information) and CVE-2025-40763 (Uncontrolled Search Path Element), could allow attackers with local access to extract password hashes or execute arbitrary code with superuser permissions by manipulating environment variables or error handling processes. Although there has been no evidence of exploitation in the wild, the vulnerabilities required only low attack complexity and affected critical manufacturing environments globally. This incident highlights ongoing risks posed by improper input validation and error handling in operational technology (OT) environments, especially as attackers increasingly target privilege escalation vectors. Regulatory bodies emphasize swift detection, patching, and IT/OT segmentation to reduce attack surface, as local escalation flaws remain a persistent threat vector in critical infrastructure.
8 months ago
Kill Chain
Siemens COMOS 2025: Critical Software Vulnerabilities in Industrial Control Systems
In November 2025, Siemens disclosed critical software vulnerabilities affecting its COMOS platform, widely used in the industrial and critical manufacturing sectors. The flaws—specifically, an incomplete list of disallowed inputs and cleartext transmission of sensitive information—enabled remote attackers with low attack complexity to execute arbitrary code or intercept data. The affected versions were COMOS releases prior to 10.4.5, with potential for unauthorized access, data infiltration, or broader operational disruptions across global deployments. Siemens ProductCERT identified and reported the vulnerabilities, issuing patches and urging immediate upgrades and network protections. This incident is highly relevant given the increasing threats to industrial control systems and the persistent exploitation of software supply chain vulnerabilities. The convergence of IT and OT environments means that unresolved vulnerabilities like these present heightened risks in critical infrastructure, drawing attention from regulators and advanced cyber attackers alike.
8 months ago
Kill Chain
Critical ICS Vulnerabilities in Siemens SICAM P850/P855 Devices Impact Energy Sector
In November 2025, Siemens disclosed vulnerabilities affecting their SICAM P850 and P855 industrial control device families. Specifically, these products were susceptible to a Cross-Site Request Forgery (CSRF) flaw and incorrect permission assignment for critical resources, allowing attackers to execute unauthorized actions or impersonate users. The weaknesses impacted devices globally deployed in energy-critical infrastructure, with the main risk being attackers exploiting web sessions to modify device configuration or gain prolonged unauthorized access. Siemens ProductCERT identified the issues, which could be exploited remotely with low attack complexity, scoring up to 5.5 CVSS. This incident highlights growing concerns over ICS (Industrial Control Systems) vulnerabilities due to their essential role in critical infrastructure and the rising sophistication of exploitation tactics targeting web interfaces. The disclosure underscores the need for proactive patch management and access restrictions amid evolving regulatory and threat environments.
8 months ago
Kill Chain
Rockwell Automation SIS Workstation Vulnerability Exposes Critical Manufacturing
In November 2025, Rockwell Automation disclosed a critical path traversal vulnerability (CVE-2024-48510) in its AADvance-Trusted SIS Workstation software, impacting versions 2.00.00 to 2.00.04. The flaw stems from improper validation in the DotNetZip component, enabling remote attackers to execute arbitrary code if a victim opens a malicious file. This issue poses significant risks to critical manufacturing systems worldwide, potentially allowing adversaries to compromise safety instrumented system environments. Rockwell has released a patch in version 2.01.00 to address the flaw. This vulnerability is particularly noteworthy due to its low attack complexity, remote exploitability, and potential for widespread impact across global critical infrastructure. The incident underscores ongoing supply chain risks in industrial software and the urgent need for timely patching, robust endpoint security, and defense-in-depth strategies for operational technology (OT) environments.
8 months ago
Kill Chain
Critical Siemens LOGO! 8 Vulnerabilities Put Global ICS at Risk
In November 2025, Siemens disclosed multiple critical vulnerabilities affecting its LOGO! 8 BM Devices, widely deployed in global commercial facilities and transportation systems. Security researchers from Thales Cybersecurity Services Australia identified flaws enabling unauthenticated remote attackers to exploit classic buffer overflow and missing authentication vulnerabilities. These flaws could allow malicious actors to execute arbitrary code, disrupt device operations via denial-of-service, or modify critical device parameters such as IP address and time settings, potentially impacting industrial operations. The incident underscores growing concerns about the security posture of industrial control systems (ICS), as attackers increasingly target remote management features lacking modern authentication. With regulatory scrutiny intensifying and attackers exploiting similar flaws in operational technology, organizations must prioritize ICS security and proactive patch management to reduce exposure.
8 months ago
Kill Chain
Critical Infrastructure Active Directory Breach Highlights the Need for Zero Trust Controls
In October 2025, a coordinated threat campaign targeted the Active Directory environment of a major North American critical infrastructure provider. Attackers exploited vulnerabilities in legacy on-premises and misconfigured cloud authentication bridges to gain initial access, leveraging unencrypted internal traffic and credential harvesting tools. By establishing persistence inside hybrid systems, they used lateral movement techniques to escalate privileges, eventually exfiltrating sensitive operational and personal data. The attack briefly disrupted authentication services, causing operational outages and impacting supply chain partners reliant on secure access. Regulators and cyber response teams were engaged, intensifying scrutiny of infrastructure identity security. This incident underscores how attackers increasingly target hybrid and cloud-integrated identity platforms like Active Directory, exploiting gaps in east-west traffic security and multifactor enforcement. As ransomware and nation-state campaigns leverage similar methods, the urgency for zero trust segmentation, encrypted traffic, and strong policy enforcement within hybrid infrastructure has never been greater.
8 months ago
Kill Chain
Advantech DeviceOn/iEdge 2025: Multiple Path Traversal and XSS Vulnerabilities Threaten IoT Security
In November 2025, security researchers disclosed multiple critical vulnerabilities in Advantech’s DeviceOn/iEdge IoT management platform, affecting version 2.0.2 and earlier. Among the vulnerabilities were improper input handling flaws including cross-site scripting (CVE-2025-64302) and several variants of path traversal (CVE-2025-62630, CVE-2025-59171, CVE-2025-58423), which could allow remote attackers to gain unauthorized access, execute arbitrary code, trigger denial-of-service conditions, or read sensitive files. No public exploitation has been reported, but the potential risks span information leakage and remote code execution, with system-level impact possible from authenticated and unauthenticated attackers. This incident is particularly relevant as IoT management and industrial control environments remain popular targets for exploitation of legacy systems, which often lack timely security updates. With operational continuity and data integrity at risk, organizations face mounting regulatory and business pressure to retire end-of-life products and implement robust remediation strategies.
8 months ago
Kill Chain
ABB FLXeon 2025 ICS Vulnerabilities: Protecting Critical Infrastructure from Remote Threats
In November 2025, ABB disclosed critical vulnerabilities affecting their FLXeon industrial control system (ICS) controllers, including the FBXi, FBVi, FBTi, and CBXi product lines. Security researcher Gjoko Krstikj of Zero Science Lab identified flaws such as the use of hard-coded credentials (CVE-2024-48842), improper input validation (CVE-2024-48851, CVE-2025-10207), and weak password hashing practices (CVE-2025-10205) that could allow remote attackers to gain control, execute arbitrary code, or cause system crashes. While exploitation requires some privileges and network access, the flaws impact ICS deployments globally, exposing critical infrastructure sectors to risk until patches are applied. This incident highlights the continued trend of vulnerabilities in operational technology and industrial systems, reinforcing fears that ICS environments remain attractive targets for cyber threat actors. As regulatory and industry pressure mounts for robust ICS security and segmentation, organizations must accelerate adoption of defense-in-depth strategies to protect essential infrastructure.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports