Threat Theaters

⚡ Critical Infrastructure theater

Tracks nation-state and criminal threats to industrial control systems (ICS/SCADA/OT) across energy, water, pipeline, manufacturing and transport sectors. Compromise here risks physical destruction, loss of life and cascading service outages, making it the highest-consequence cyber domain.

Live indicators

3.8K
in this theater

High severity

0
score ≥ 0.75 (top 60)

Actors tracked

8
documented

Mapped sources

1
in catalog

🛡 Exploited Vulnerabilities

CVEVendor / ProductRansomwareMalware
CVE-2026-1731BeyondTrust Remote Support (RS) and PrKNOWNransomware (KEV-flagged)
CVE-2025-55182Meta React Server ComponentsKNOWNransomware (KEV-flagged)
CVE-2024-21412Microsoft WindowsKNOWNDarkGate, Water Hydra
CVE-2023-36884Microsoft WindowsKNOWNransomware (KEV-flagged)
CVE-2017-7494Samba SambaKNOWNransomware (KEV-flagged)
CVE-2015-2291Intel Ethernet Diagnostics DriveKNOWNransomware (KEV-flagged)
CVE-2023-0669Fortra GoAnywhere MFTKNOWNClop (GoAnywhere MFT)
CVE-2022-24990TerraMaster TerraMaster OSKNOWNransomware (KEV-flagged)
CVE-2022-47966Zoho ManageEngineKNOWNransomware (KEV-flagged)
CVE-2022-26500Veeam Backup & ReplicationKNOWNransomware (KEV-flagged)
CVE-2022-26501Veeam Backup & ReplicationKNOWNransomware (KEV-flagged)
CVE-2022-41091Microsoft WindowsKNOWNransomware (KEV-flagged)

📜 Critical Infrastructure Playbook

  1. Collect exposed OT assets by fingerprinting Modbus/DNP3/S7 and HMI banners on Shodan/Censys and internet-facing VPN edges.
  2. Normalize and enrich ICS-specific IOCs against CISA ICS advisories and MITRE ATT&CK for ICS technique mappings.
  3. Analyze anomalous engineering-workstation-to-PLC traffic and firmware/logic changes for pre-positioning consistent with living-off-the-land tradecraft.
  4. Attribute activity to ICS threat groups (Volt Typhoon, Sandworm, XENOTIME) via malware toolmarks, C2 infrastructure reuse and targeting patterns.
  5. Disseminate sector-specific warnings to affected utilities and ISACs (E-ISAC, WaterISAC) with prioritized CVE and IOC blocklists.
  6. Trigger OT network segmentation, credential rotation and safety-instrumented-system integrity checks, then hunt for persistence across the estate.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎯 Add to case

Attach Critical Infrastructure (Mission Domain) and pull all linked entities:
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php