Tag
Multiple Critical Vulnerabilities in Hitachi Energy FACTS Control Platform
2 TTPs 5 CVEsHitachi Energy FACTS Control Platform (FCP) units equipped with the GWS component are affected by multiple critical vulnerabilities, including path traversal and authentication bypass, potentially leading to unauthorized system access or modification.
Multiple Vulnerabilities in Siemens Reyrolle 7SR5 Firmware
1 CVESiemens Reyrolle 7SR5 devices running firmware versions earlier than V2.70 are impacted by multiple vulnerabilities within the embedded Mongoose Web Server, potentially leading to denial of service, information disclosure, or authentication bypass.
Multiple Vulnerabilities in ANDRITZ HIPASE-250 and 250 SCALA
4 TTPs 3 CVEsANDRITZ HIPASE-250 and 250 SCALA devices (versions <=7.20) contain multiple high-severity vulnerabilities, including hard-coded credentials, missing authentication on critical functions, and insecure password storage, enabling potential remote exploitation.
Armored Likho APT Leverages BusySnake Stealer with AI-Generated Loaders and Phishing
2 rules 10 TTPsThe Armored Likho APT group is conducting a spear-phishing campaign against government and energy sectors in Russia, Kazakhstan, and Brazil, using AI-generated loaders and the Python-based BusySnake Stealer to exfiltrate credentials and sensitive data.
Lotus Data Wiper Targeting Venezuelan Energy and Utility Firms
3 rules 1 TTPThe Lotus wiper, a previously undocumented data-wiping malware, was deployed against Venezuelan energy and utilities organizations in 2025, overwriting physical drives, deleting files, and rendering systems unrecoverable.