The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Utilities

Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.

487 threat reports
Page 40 of 41

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Utilities Threat Reports

Showing 469–480 / 487 reports
Flax Typhoon Turns ArcGIS Geo-Mapping Server into APT Backdoor
Impact· medium

Flax Typhoon Turns ArcGIS Geo-Mapping Server into APT Backdoor

In early 2024, Chinese state-sponsored threat group Flax Typhoon compromised an organization’s ArcGIS geospatial mapping server, turning the platform into a covert backdoor for persistent access. The attackers exploited vulnerabilities and weak segmentation, modifying core ArcGIS components to avoid detection while establishing reliable remote control and lateral movement capabilities. This stealthy intrusion allowed for unauthorized data access without typical alert triggers, posing significant operational and reputational risks for the victim, and demonstrated advanced tactics utilized by APT groups targeting critical infrastructure software. This incident highlights a growing trend where APTs compromise auxiliary business applications—like geo-mapping and analytics platforms—to evade detection and spread across internal networks. Organizations must reassess east-west security, encrypted traffic visibility, and zero trust segmentation to keep pace with evolving attacker tradecraft.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Blue Angel Suite Faces 2024 Webctrl.cgi OS Command Injection Attempts
Impact· low

Blue Angel Suite Faces 2024 Webctrl.cgi OS Command Injection Attempts

In October 2024, threat actors attempted to exploit an OS command injection vulnerability targeting the Blue Angel Software Suite's web interface on embedded Linux devices. Attackers issued crafted POST requests to the '/cgi-bin/webctrl.cgi' endpoint, aiming to inject arbitrary shell commands via the 'ipaddress' parameter. These attacks, detected by honeypots, mirror previous vulnerabilities such as CVE-2025-34033, which allows authenticated attackers to execute code as root by manipulating input passed to system commands like 'ping'. The incidents highlight persistent risks across IoT and broadband equipment, potentially providing attackers with full system control. This incident underscores a growing trend in targeting network appliances and IoT infrastructure for initial access and lateral movement. As regulatory attention increases and attackers shift toward exploiting device misconfigurations and weak input validation, robust segmentation and up-to-date patch management are even more critical.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(low)
Read Report
How Flax Typhoon Used ArcGIS Server as a Backdoor: 2025 Breach Breakdown
Impact· low

How Flax Typhoon Used ArcGIS Server as a Backdoor: 2025 Breach Breakdown

In mid-2025, threat intelligence researchers uncovered a year-long, state-sponsored attack committed by Chinese APT group Flax Typhoon (also known as Ethereal Panda/RedJuliett). The group exploited unpatched ArcGIS servers to establish persistent unauthorized access and covertly operated a backdoor for over twelve months. Using sophisticated techniques to evade detection and maintain long-term access, the attackers leveraged lateral movement and encrypted communication within targeted networks. The breach compromised sensitive data and potentially exposed critical infrastructure, highlighting a significant risk to affected organizations. This incident exemplifies a growing threat from well-resourced nation-state actors targeting enterprise geospatial systems, exploiting overlooked or under-patched software for initial entry. Attacks on infrastructure platforms are increasingly sophisticated, raising urgency for IT and security leaders to enhance detection, zero trust segmentation, and patch management programs in response to evolving APT campaigns.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Two CVSS 10.0 Flaws in Red Lion RTUs Expose Industrial Control Environments
Impact· medium

Two CVSS 10.0 Flaws in Red Lion RTUs Expose Industrial Control Environments

In October 2025, two critical vulnerabilities (CVE-2023-40151 and CVE-2023-42770) were publicly disclosed in Red Lion Sixnet RTU devices, which are widely used for industrial automation and critical infrastructure. Both flaws received a CVSS 10.0 rating, underscoring their exploitability and impact. Attackers exploiting these vulnerabilities could achieve remote code execution with the highest privileges, granting them full control over affected devices. These RTUs are often deployed in energy, utilities, and manufacturing, raising concerns about the potential for business disruption, safety risks, and further attacks via compromised operational technology networks. This incident is particularly relevant as it highlights how legacy and specialized industrial control systems remain a prime target for threat actors leveraging zero-day vulnerabilities. The convergence of IT and OT, combined with growing regulatory scrutiny and an uptick in supply chain exposures, means that organizations must refocus on asset visibility and patch management for embedded and hard-to-update devices.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
NSA-Linked Cyberattack Highlights Risks to China’s National Time Service Center (2023–2024)
Impact· low

NSA-Linked Cyberattack Highlights Risks to China’s National Time Service Center (2023–2024)

Between March 2022 and June 2024, China’s National Time Service Center reportedly fell victim to a sophisticated cyber-espionage campaign allegedly orchestrated by the U.S. National Security Agency (NSA). Attackers initially compromised employee mobile devices via a text-messaging service vulnerability, leading to credential theft and enabling unauthorized access to the Center’s internal systems by April 2023. From August 2023 onward, the NSA purportedly leveraged a suite of 42 advanced cyber tools to target sensitive infrastructure, using VPNs and forged certificates to evade detection and bypass defenses. The attack put critical services at risk, with potential consequences including network disruption, financial system instability, and interruptions to vital communications and national defense functions. This incident underscores escalating nation-state cyber competition, especially over foundational infrastructure. The methods used—mobile device exploitation, lateral movement, and evasion through encrypted channels—reflect trending Tactics, Techniques, and Procedures (TTPs) in state-sponsored attacks, raising concerns for governments and critical sectors worldwide about supply chain and timing-related risks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Satellite Communications Exposed: 2025’s Unencrypted Data Crisis
Impact· high

Satellite Communications Exposed: 2025’s Unencrypted Data Crisis

In mid-2025, a landmark study revealed that a vast portion of global geostationary satellite communications—including critical infrastructure, government, corporate, and consumer data—are transmitted unencrypted. Security researchers, using inexpensive commercially available satellite equipment, intercepted highly sensitive transmissions such as internal communications, private calls and SMS, and in-flight internet traffic. Because thousands of geostationary transponders broadcast across enormous geographic areas, these unprotected signals can be passively accessed by unauthorized parties from virtually anywhere within satellite coverage zones, putting confidential data at significant risk of interception and exploitation. This incident underscores a persistent and growing concern regarding the lack of robust encryption in satellite communications, even as regulations and cyber threats evolve rapidly. Increasing satellite connectivity for aviation, maritime, and remote access drives urgency around encryption, as adversaries and data brokers exploit these vulnerabilities on a global scale.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Nation-State Breach of F5 Sparks CISA Emergency Directive for Federal Agencies
Impact· medium

Nation-State Breach of F5 Sparks CISA Emergency Directive for Federal Agencies

In mid-2024, F5 Networks disclosed that a sophisticated nation-state attacker gained prolonged, unauthorized access to its internal systems, compromising BIG-IP source code and undisclosed vulnerability details. The breach, detected in August, prompted the US Cybersecurity and Infrastructure Security Agency (CISA) to issue an emergency directive compelling federal agencies to immediately identify, patch, or disconnect thousands of F5 products in their environments. While no direct federal compromises have been reported yet, the theft of sensitive product and security information could facilitate widespread exploitation across both federal agencies and private organizations relying on F5 systems. This incident underscores heightened risks to supply chain integrity and critical infrastructure posed by persistent nation-state campaigns. With attackers targeting widely deployed technology vendors, government and industry face urgent pressure to enhance monitoring, rapid patching, and zero trust defenses to mitigate risks from downstream exploitation of software supply chains.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Chinese APT Exploits ArcGIS Tool for Stealthy Persistence and Credential Theft
Impact· medium

Chinese APT Exploits ArcGIS Tool for Stealthy Persistence and Credential Theft

In 2025, a Chinese state-sponsored Advanced Persistent Threat (APT) group, attributed to Flax Typhoon, maintained over a year of undetected access to an organization's network by exploiting a public-facing ArcGIS geo-mapping server. The attackers leveraged stolen administrator credentials to upload a malicious Java Server Object Extension (SOE) acting as a covert web shell, allowing them to execute commands via a REST API and escalate privileges internally. Persistence was further established by deploying SoftEther VPN Bridge, enabling encrypted outbound connectivity and facilitating lateral movement, data exfiltration, and credential harvesting within the victim's environment. This incident underscores the increasing sophistication of APTs exploiting legitimate third-party software and obscure admin features for stealthy, long-term persistence. The method's novelty, combined with highly targeted credential theft and the use of living-off-the-land techniques, highlights urgent gaps in detection, segmentation, and secure configuration, especially in public-facing or critical GIS applications.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
TwoNet Hacktivists Target Decoy Water Plant in Bold Critical Infrastructure Attack
Impact· high

TwoNet Hacktivists Target Decoy Water Plant in Bold Critical Infrastructure Attack

In September 2025, the pro-Russian hacktivist group TwoNet targeted what they believed to be a vulnerable water treatment plant, unaware it was a decoy system (honeypot) operated by cybersecurity researchers. The attackers gained access using default credentials, escalated attacks through SQL enumeration, and exploited a known XSS vulnerability (CVE-2021-26829). Within 26 hours, they created new user accounts, manipulated PLC setpoints, disabled real-time updates, and attempted to disrupt both logs and alarms via the Human Machine Interface (HMI). Their tactics included data exfiltration and process disruption, signaling a shift toward operational technology (OT) attacks targeting critical infrastructure. This incident highlights a growing trend of hacktivist groups evolving from DDoS and defacement attacks to more sophisticated operations against OT and ICS targets. The rapid escalation and attempted sabotage observed in this breach emphasize the urgent need for robust segmentation, authentication, and real-time anomaly detection within critical infrastructure environments.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Confirms Active Exploitation of Meteobridge CVE-2025-4008 Command Injection Flaw
Impact· low

CISA Confirms Active Exploitation of Meteobridge CVE-2025-4008 Command Injection Flaw

On October 24, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) flagged an actively exploited command injection vulnerability (CVE-2025-4008) within Smartbedded Meteobridge's web interface. This critical flaw, assigned a CVSS score of 8.7, permits remote attackers to execute arbitrary code by exploiting improper input handling. Threat actors are leveraging this vulnerability in the wild, potentially compromising sensitive data and gaining unauthorized access to affected networks. The exposure primarily impacts organizations deploying Meteobridge for environmental monitoring or network-connected IoT operations, raising significant concerns about operational integrity and data confidentiality. This incident highlights a persistent trend in adversaries targeting device management interfaces and exploiting command injection vulnerabilities for lateral movement or further compromise. With regulatory scrutiny increasing and attackers rapidly capitalizing on newly discovered flaws, swift patching and enhanced network segmentation are more crucial than ever.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Attackers Exploit Milesight Routers to Launch European SMS Phishing Wave
Impact· high

Attackers Exploit Milesight Routers to Launch European SMS Phishing Wave

In early 2025, unidentified threat actors exploited vulnerabilities in Milesight industrial cellular routers to launch a large-scale smishing campaign across Europe. By abusing the routers’ publicly exposed APIs, attackers sent malicious SMS messages containing phishing URLs directly to mobile users in countries including Sweden and Italy. This campaign has been ongoing since at least February 2022, with attackers leveraging compromised infrastructure to bypass traditional security filters, resulting in widespread delivery of credential-theft links and potential downstream attacks. This incident highlights the increasing trend of attackers targeting edge infrastructure and IoT devices to amplify their phishing and malware operations. As threat actors shift tactics toward abusing legitimate network equipment, organizations face new regulatory and operational risks, with urgent need to secure device APIs, implement segmentation, and strengthen monitoring to counter evolving smishing threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
ICS Malware Attacks Spike in Q2 2025: Key Lessons for Industrial Automation Security
Impact· medium

ICS Malware Attacks Spike in Q2 2025: Key Lessons for Industrial Automation Security

In Q2 2025, industrial automation systems worldwide experienced significant and persistent threats, with 20.5% of ICS (Industrial Control Systems) computers encountering malicious objects, despite a slight quarterly decrease. Attackers leveraged a multi-stage campaign, beginning with phishing emails and malicious documents to gain access, and subsequently deploying next-stage malware such as spyware, ransomware, and cryptominers. Regions like Africa and sectors such as biometrics were among the most targeted, while common initial infection sources included malicious internet resources, infected emails, and removable media devices. Multiple sophisticated malware families (over 10,000 variants) exploited ICS security gaps to enable lateral movement, persistent access, and data exfiltration, impacting operational resilience and increasing risk of service disruption for critical industries. This incident underscores the continued evolution of ICS-targeting malware and the increasing sophistication of attack vectors in the operational technology sector. The upward trend in email-based infiltration and malicious cloud links, coupled with persistent use of multi-stage payloads, highlights the urgent need for robust, layered security, Zero Trust policies, and compliance alignment to protect critical infrastructure environments against both commodity and targeted threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports