⚡ Critical Infrastructure theater
Tracks nation-state and criminal threats to industrial control systems (ICS/SCADA/OT) across energy, water, pipeline, manufacturing and transport sectors. Compromise here risks physical destruction, loss of life and cascading service outages, making it the highest-consequence cyber domain.
Live indicators
3.8K
in this theater
High severity
0
score ≥ 0.75 (top 60)
Actors tracked
8
documented
Mapped sources
1
in catalog
🏹 Threat Actors
🦠 Malware & Tools
🛡 Exploited Vulnerabilities
| CVE | Vendor / Product | Ransomware | Malware |
|---|---|---|---|
| CVE-2026-1731 | BeyondTrust Remote Support (RS) and Pr | KNOWN | ransomware (KEV-flagged) |
| CVE-2025-55182 | Meta React Server Components | KNOWN | ransomware (KEV-flagged) |
| CVE-2024-21412 | Microsoft Windows | KNOWN | DarkGate, Water Hydra |
| CVE-2023-36884 | Microsoft Windows | KNOWN | ransomware (KEV-flagged) |
| CVE-2017-7494 | Samba Samba | KNOWN | ransomware (KEV-flagged) |
| CVE-2015-2291 | Intel Ethernet Diagnostics Drive | KNOWN | ransomware (KEV-flagged) |
| CVE-2023-0669 | Fortra GoAnywhere MFT | KNOWN | Clop (GoAnywhere MFT) |
| CVE-2022-24990 | TerraMaster TerraMaster OS | KNOWN | ransomware (KEV-flagged) |
| CVE-2022-47966 | Zoho ManageEngine | KNOWN | ransomware (KEV-flagged) |
| CVE-2022-26500 | Veeam Backup & Replication | KNOWN | ransomware (KEV-flagged) |
| CVE-2022-26501 | Veeam Backup & Replication | KNOWN | ransomware (KEV-flagged) |
| CVE-2022-41091 | Microsoft Windows | KNOWN | ransomware (KEV-flagged) |
📚 Priority sources & datasets
📜 Critical Infrastructure Playbook
- Collect exposed OT assets by fingerprinting Modbus/DNP3/S7 and HMI banners on Shodan/Censys and internet-facing VPN edges.
- Normalize and enrich ICS-specific IOCs against CISA ICS advisories and MITRE ATT&CK for ICS technique mappings.
- Analyze anomalous engineering-workstation-to-PLC traffic and firmware/logic changes for pre-positioning consistent with living-off-the-land tradecraft.
- Attribute activity to ICS threat groups (Volt Typhoon, Sandworm, XENOTIME) via malware toolmarks, C2 infrastructure reuse and targeting patterns.
- Disseminate sector-specific warnings to affected utilities and ISACs (E-ISAC, WaterISAC) with prioritized CVE and IOC blocklists.
- Trigger OT network segmentation, credential rotation and safety-instrumented-system integrity checks, then hunt for persistence across the estate.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🎯 Add to case
🧩 Advanced Capabilities
🔗 Cross-domain pivots
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron