Skip to main content
All Sectors

Energy

eu

European energy sector - NIS2 essential entity

NIS2 Essential Entity

Compliance tags are AI-generated and should not be cited as regulatory evidence without independent review.

Total (30d)

16

Critical

2

High

3

Medium

11

16 threats in last 30 days( 23% vs prior period)
Top ATT&CK Techniques
T1190Exploit Public-Facing Application12x

Deploy WAF rules, patch public-facing apps within 48h of CVE disclosure, segment DMZ from internal networks, and run authenticated vulnerability scans weekly.

T1078Valid Accounts7x

Enforce MFA on all accounts, implement conditional access policies, audit privileged accounts quarterly, and monitor for impossible-travel logins.

T1486Data Encrypted for Impact6x

Maintain offline/immutable backups tested monthly, enable ASR rules against ransomware, and deploy behavioural detection for mass file encryption patterns.

T1110Brute Force1x

Enforce account lockout after 5 failed attempts, require MFA, adopt NIST 800-63B password guidelines (length over complexity), and block known-breached passwords.

T1490Inhibit System Recovery1x

Protect Volume Shadow Copies via ACLs, store backups in immutable/air-gapped storage, and alert on vssadmin/bcdedit/wbadmin deletion commands.

T1562Impair Defenses1x

Enable tamper protection on EDR/AV, monitor for security service stop/disable events, alert on firewall rule modifications, and enforce audit log forwarding to SIEM.

Compliance Exposure
NIS2-Art21-2e(18)NIS2-Art21-2b(15)NIS2-Art21-2c(2)NIS2-Art21-2a(1)DORA-Art17-23(1)NIS2-Art21-2d(1)DORA-Art5-16(1)
Technologies
SCADAICSOTDCSRTU

Recent Intelligence

Besen EV Charger Vulnerability

A security vulnerability has been discovered in the Besen BS20 EV Charging Station, allowing for authentication bypass via capture-replay attacks on the BLE/WiFi component. This issue affects users of the Besen BS20 EV Charging Station, particularly those with local network access. Users should monitor for updates from Besen and consider implementing additional security measures to mitigate potential attacks.

24/5/2026Medium

Besen EV Charging Station Vulnerability

A vulnerability has been identified in the Besen BS20 EV Charging Station, allowing for improper authorization due to a weakness in the OTA Update Installation Handler. The vulnerability can be exploited remotely, but requires a high degree of complexity. Users of the affected charging stations should monitor for updates and follow best practices for secure configuration.

24/5/2026Medium

Bes

A security flaw has been discovered in the Besen BS20 EV Charging Station, affecting an unknown functionality of the Firmware Version Check component. This vulnerability allows for improper restriction of rendered UI layers and can be executed remotely, although exploitation is considered difficult due to a high complexity level. Users are advised to monitor for updates from Besen, as the company has acknowledged the issue and is reviewing it.

24/5/2026Medium

Besen EV Charger Vulnerability

A vulnerability has been discovered in the Besen BS20 EV Charging Station, affecting its Bluetooth Low Energy handler, which can lead to weak password requirements. The attack requires local network access and has high complexity. Users should monitor for updates from Besen and consider implementing additional security measures.

24/5/2026Medium

Besen EV Charging Station Vulnerability

A vulnerability in the Besen BS20 EV Charging Station allows for authentication bypass via BLE/WiFi replay attacks, affecting users of the charging station. The attack must be carried out from within the local network. Users should ensure their charging station is updated and monitor for suspicious activity.

24/5/2026Medium

EV Charging Station Vulnerability

A critical vulnerability was discovered in the Besen BS20 EV Charging Station, affecting its OTA Update Installation Handler, which can be exploited remotely. Users of the Besen BS20 EV Charging Station are advised to be cautious and monitor for

24/5/2026Critical

Untitled Security Alert

A vulnerability has been discovered in the Besen BS20 EV Charging Station, affecting its BLE/UDP component and potentially exposing credentials. The vulnerability can be exploited within a local network, and an exploit is available. Users are advised to monitor their systems and await a patch from the vendor.

24/5/2026Medium

Besen EV Charger Vulnerability

A vulnerability in the Besen BS20 EV Charging Station's Bluetooth Low Energy handler allows for weak password requirements, potentially affecting users with these charging stations. The vulnerability

24/5/2026Medium

OT Security Gap

A significant security gap exists in operational technology (OT) systems, where legacy devices and lack of monitoring hinder AI-driven security strategies. This gap affects various industries, including energy, automotive, and pharmaceuticals. Organizations should prioritize passive network monitoring and address the visibility gap to ensure effective security.

22/5/2026Medium

Turkiye Electricity App Vulnerability

A vulnerability was discovered in the Turkiye Electricity Transmission Corporation Mobile Application, allowing excessive authentication attempts. Users of the application are affected, and upgrading to a patched version is recommended. The vulnerability can be exploited remotely.

21/5/2026Medium

AI-Powered App Attacks Rise

A recent report by Digital.ai warns that AI-powered attacks on mobile apps are becoming faster, more frequent, and harder to stop, affecting all industries. These attacks can occur within hours of an app's release, erasing the distinction between emerging and primary targets. Users and developers should be vigilant and take proactive measures to secure their apps.

20/5/2026High

Vulnerability Exploitation Tops DBIR

According to the 2026 Verizon Data Breach Investigations Report, vulnerability exploitation has become the most common initial access vector, surpassing stolen credentials. This shift affects organizations of all sizes and industries, emphasizing the need for robust vulnerability management. To mitigate this risk, prioritize vulnerability patching and implement a comprehensive security strategy.

20/5/2026High

Nordex Wind Turbine SQL Injection

A high-severity SQL injection vulnerability has been discovered in the Nordex N149/4.0-4.5 Wind Turbine Web Server, allowing unauthenticated attackers to execute arbitrary SQL queries and bypass authentication mechanisms. Users of the affected wind turbine web server are advised to take immediate action to mitigate the vulnerability. Aff

17/5/2026High

Azerbaijani Oil Firm Hit by Microsoft Exchange Exploit

An Azerbaijani oil and gas company was targeted by a Chinese-affiliated threat actor in a multi-wave intrusion between December 2025 and February 2026. The attack, attributed to the FamousSparrow hacking group, exploited Microsoft Exchange vulnerabilities. Affected organizations should review their Exchange server security and apply patches.

13/5/2026Medium

China-Linked APT Targets Energy Firm

A China-linked advanced persistent threat (APT) group, known as FamousSparrow, has launched repeated attacks on an Azerbaijani oil

13/5/2026Medium

Ingecon EMS Board Vulnerability

A critical vulnerability has been discovered in the Ingecon Sun EMS Board, affecting its local SAT access functionality. The vulnerability allows for insecure generation of access credentials, potentially enabling privilege escalation attacks. Users of the Ingecon Sun EMS Board should take immediate action to secure their systems.

12/5/2026Critical

Lotus Wiper Malware Targets Energy

A recent analysis of the Lotus Wiper malware has revealed its use of sophisticated living-off-the-land (LotL) techniques to target Venezuelan energy firms and utilities, resulting in widespread data deletion. The malware's tactics, techniques, and procedures (TTPs) indicate a high level of planning and execution. Organizations in the energy sector should be vigilant and take proactive measures to protect against similar attacks.

29/4/2026High

Itron Cybersecurity Incident

Itron, a leading provider of energy and water management solutions, has experienced a cybersecurity incident involving unauthorized access to its systems, which was detected on April 13. This incident may have implications for the utilities and cities that rely on Itron's services. Affected parties are advised to exercise caution and monitor their systems for potential

27/4/2026Medium

Malware Threats Emerge

Multiple malware threats have been discovered, including a new spyware linked to IPS Intelligence and a wiper targeting the energy sector. These threats affect various industries and individuals, particularly those using iPhones and energy-related systems. Users are advised to exercise caution and implement security updates to protect against these emerging threats.

26/4/2026High

Lotus Wiper Malware

A new wiper malware, dubbed Lotus Wiper, has been discovered targeting the Venezuelan energy sector. The

22/4/2026High