<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Energy Sector</title><description>Cybersecurity articles tagged #Energy Sector on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Origin Energy Data Breach: 2 Million Customers&apos; Data Compromised</title><link>https://runtimerebel.com/blog/origin-energy-data-breach-2-million-customers-data-compromised</link><guid isPermaLink="true">https://runtimerebel.com/blog/origin-energy-data-breach-2-million-customers-data-compromised</guid><description>Australian energy giant Origin Energy confirms a data breach impacting 2 million customers. A hacker claims to have stolen information and threatens public disclosure.</description><pubDate>Fri, 24 Jul 2026 06:26:59 GMT</pubDate><category>Origin Energy</category><category>Data Breach</category><category>Australia</category><category>Customer Data</category><category>Energy Sector</category><category>Threat Disclosure</category></item><item><title>Origin Energy Data Breach Exposes Client PII</title><link>https://runtimerebel.com/blog/origin-energy-data-breach-exposes-client-pii</link><guid isPermaLink="true">https://runtimerebel.com/blog/origin-energy-data-breach-exposes-client-pii</guid><description>Australian energy provider Origin Energy confirms a data breach exposed sensitive Personally Identifiable Information of its clients, heightening fraud risks.</description><pubDate>Thu, 23 Jul 2026 21:06:35 GMT</pubDate><category>Origin Energy</category><category>Data Breach</category><category>PII Exposure</category><category>Australia</category><category>Energy Sector</category></item><item><title>Siemens KACO Blueplanet Inverter Vulnerabilities: CVE-2025-40946 &amp; CVE-2026-41125</title><link>https://runtimerebel.com/blog/siemens-kaco-blueplanet-inverter-vulnerabilities-cve-2025-40946-cve-2026-41125</link><guid isPermaLink="true">https://runtimerebel.com/blog/siemens-kaco-blueplanet-inverter-vulnerabilities-cve-2025-40946-cve-2026-41125</guid><description>Critical Siemens KACO Blueplanet Inverters are vulnerable to credential derivation (CVE-2025-40946) and SQL injection (CVE-2026-41125).</description><pubDate>Tue, 09 Jun 2026 17:02:56 GMT</pubDate><category>Siemens</category><category>KACO Blueplanet Inverters</category><category>ICS</category><category>Energy Sector</category><category>CVE-2025-40946</category><category>CVE-2026-41125</category><category>Hard Coded Key</category><category>SQL Injection</category><category>Operational Technology</category></item><item><title>ABB Terra AC Wallbox &lt;=1.8.33 Buffer Overflows: Patch Now</title><link>https://runtimerebel.com/blog/abb-terra-ac-wallbox-1-8-33-buffer-overflows-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/abb-terra-ac-wallbox-1-8-33-buffer-overflows-patch-now</guid><description>CISA warns of three buffer overflow vulnerabilities (CVE-2025-10504, CVE-2025-12142, CVE-2025-12143) in ABB Terra AC Wallbox EV chargers, leading to potential remote…</description><pubDate>Thu, 21 May 2026 20:43:05 GMT</pubDate><category>ABB</category><category>Terra AC Wallbox</category><category>EV Charger</category><category>CVE-2025-10504</category><category>CVE-2025-12142</category><category>CVE-2025-12143</category><category>Buffer Overflow</category><category>Heap Based Buffer Overflow</category><category>Stack Based Buffer Overflow</category><category>Energy Sector</category></item><item><title>FamousSparrow APT: China-Linked Group Targets Caucasus Energy Sector</title><link>https://runtimerebel.com/blog/famoussparrow-apt-china-linked-group-targets-caucasus-energy-sector</link><guid isPermaLink="true">https://runtimerebel.com/blog/famoussparrow-apt-china-linked-group-targets-caucasus-energy-sector</guid><description>China-linked FamousSparrow APT expands targeting to include Azerbaijani energy infrastructure, signaling a shift in strategic objectives for the threat group.</description><pubDate>Wed, 13 May 2026 16:54:43 GMT</pubDate><category>FamousSparrow</category><category>Energy Sector</category><category>CVE-2021-26855</category><category>South Caucasus</category><category>SparrowDoor</category></item><item><title>FamousSparrow Exploits Microsoft Exchange in Azerbaijani Energy Campaign</title><link>https://runtimerebel.com/blog/famoussparrow-exploits-microsoft-exchange-in-azerbaijani-energy-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/famoussparrow-exploits-microsoft-exchange-in-azerbaijani-energy-campaign</guid><description>Bitdefender reveals a multi-wave intrusion by FamousSparrow targeting an Azerbaijani oil and gas firm via repeated Microsoft Exchange exploitation.</description><pubDate>Wed, 13 May 2026 16:52:22 GMT</pubDate><category>FamousSparrow</category><category>UAT 9244</category><category>Azerbaijan</category><category>Microsoft Exchange</category><category>Energy Sector</category></item><item><title>Subnet Solutions PowerSYSTEM Center Vulnerabilities - Patch Now</title><link>https://runtimerebel.com/blog/subnet-solutions-powersystem-center-vulnerabilities-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/subnet-solutions-powersystem-center-vulnerabilities-patch-now</guid><description>CISA warns of high-severity vulnerabilities in Subnet Solutions PowerSYSTEM Center that allow sensitive data exposure and CRLF injection. Patch immediately.</description><pubDate>Tue, 12 May 2026 20:41:06 GMT</pubDate><category>CVE-2026-26289</category><category>CVE-2026-35504</category><category>Industrial Control Systems</category><category>Subnet Solutions</category><category>Energy Sector</category></item><item><title>CVE-2025-14510: ABB Ability OPTIMAX Azure AD SSO Auth Bypass</title><link>https://runtimerebel.com/blog/cve-2025-14510-abb-ability-optimax-azure-ad-sso-auth-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-14510-abb-ability-optimax-azure-ad-sso-auth-bypass</guid><description>CISA warns of CVE-2025-14510 impacting ABB Ability OPTIMAX, allowing authentication bypass on Azure AD SSO integrations. Patch immediately.</description><pubDate>Fri, 01 May 2026 00:56:01 GMT</pubDate><category>CVE-2025-14510</category><category>ABB Ability OPTIMAX</category><category>Authentication Bypass</category><category>Azure Active Directory SSO</category><category>ICS</category><category>SCADA</category><category>Energy Sector</category><category>Water and Wastewater</category></item><item><title>Lotus Wiper Analysis: Destructive Malware Targets Venezuelan Energy</title><link>https://runtimerebel.com/blog/lotus-wiper-analysis-destructive-malware-targets-venezuelan-energy</link><guid isPermaLink="true">https://runtimerebel.com/blog/lotus-wiper-analysis-destructive-malware-targets-venezuelan-energy</guid><description>Analysis of Lotus Wiper malware shows how it targets Venezuelan energy infrastructure by overwriting disks and disabling critical system recovery mechanisms.</description><pubDate>Wed, 22 Apr 2026 12:33:39 GMT</pubDate><category>Lotus Wiper</category><category>Venezuela</category><category>Energy Sector</category><category>Wiper Malware</category><category>Critical Infrastructure</category></item><item><title>Lotus Wiper Malware Targets Venezuelan Energy Sector</title><link>https://runtimerebel.com/blog/lotus-wiper-malware-targets-venezuelan-energy-sector</link><guid isPermaLink="true">https://runtimerebel.com/blog/lotus-wiper-malware-targets-venezuelan-energy-sector</guid><description>Kaspersky researchers uncover Lotus Wiper, a destructive malware targeting Venezuelan energy and utility systems via malicious batch scripts.</description><pubDate>Wed, 22 Apr 2026 12:29:41 GMT</pubDate><category>Lotus Wiper</category><category>Venezuela</category><category>Energy Sector</category><category>Data Wiper</category><category>Kaspersky</category></item><item><title>Lotus Data Wiper Targets Venezuelan Energy Utilities</title><link>https://runtimerebel.com/blog/lotus-data-wiper-targets-venezuelan-energy-utilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/lotus-data-wiper-targets-venezuelan-energy-utilities</guid><description>Analysis of the Lotus data wiper targeting Venezuelan energy and utility firms in 2023. Understand its destructive capabilities and TTPs for defense.</description><pubDate>Tue, 21 Apr 2026 20:23:47 GMT</pubDate><category>Lotus</category><category>Data Wiper</category><category>Venezuela</category><category>Energy Sector</category><category>Utilities</category><category>Critical Infrastructure</category><category>Industrial Control Systems</category><category>Cybereason</category></item><item><title>Venezuela Geopolitical Risk: Navigating Post-Maduro Transition</title><link>https://runtimerebel.com/blog/venezuela-geopolitical-risk-navigating-post-maduro-transition</link><guid isPermaLink="true">https://runtimerebel.com/blog/venezuela-geopolitical-risk-navigating-post-maduro-transition</guid><description>Analysis of the Venezuelan political landscape following the 2026 US operation, focusing on Delcy Rodríguez’s strategy and PSUV internal rivalries.</description><pubDate>Thu, 09 Apr 2026 08:44:29 GMT</pubDate><category>Venezuela</category><category>Geopolitical Risk</category><category>Delcy Rodriguez</category><category>Energy Sector</category><category>Psuv</category></item><item><title>Mobiliti e-mobi.hu EV Chargers: Critical Auth Bypass &amp; DoS Vulnerabilities</title><link>https://runtimerebel.com/blog/mobiliti-e-mobi-hu-ev-chargers-critical-auth-bypass-dos-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/mobiliti-e-mobi-hu-ev-chargers-critical-auth-bypass-dos-vulnerabilities</guid><description>Critical vulnerabilities in Mobiliti e-mobi.hu EV charging stations (all versions) allow unauthenticated attackers to gain administrative control or disrupt services.</description><pubDate>Tue, 03 Mar 2026 20:14:21 GMT</pubDate><category>CVE-2026-26051</category><category>CVE-2026-20882</category><category>CVE-2026-27764</category><category>CVE-2026-27777</category><category>Mobiliti E Mobi Hu</category><category>EV Charging</category><category>ICS Security</category><category>OT Security</category><category>Energy Sector</category><category>Transportation Systems</category><category>Missing Authentication</category><category>Denial of Service</category></item><item><title>Critical Authentication Flaws in Chargemap EV Infrastructure</title><link>https://runtimerebel.com/blog/critical-authentication-flaws-in-chargemap-ev-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-authentication-flaws-in-chargemap-ev-infrastructure</guid><description>CISA warns of critical vulnerabilities in Chargemap EV charging stations, including unauthenticated WebSocket access and session hijacking (CVE-2026-25851).</description><pubDate>Thu, 26 Feb 2026 20:16:22 GMT</pubDate><category>CVE-2026-25851</category><category>Chargemap</category><category>EV Charging</category><category>ICS</category><category>Energy Sector</category><category>OCPP</category><category>WebSocket</category></item></channel></rss>