Threat Theaters

πŸ”‹ Energy Security theater

Defends energy security: cyber-physical threats to electric grids, pipelines, refineries, and generation, spanning OT/ICS intrusions, wiper attacks, and physical sabotage. It matters because energy is the keystone critical infrastructure whose disruption cascades into every other sector and is a prime nation-state coercion target.

Live indicators

3.7K
in this theater

High severity

0
score β‰₯ 0.75 (top 60)

Actors tracked

7
documented

Mapped sources

2
in catalog

🛡 Exploited Vulnerabilities

CVEVendor / ProductRansomwareMalware
CVE-2026-1731BeyondTrust Remote Support (RS) and PrKNOWNransomware (KEV-flagged)
CVE-2025-55182Meta React Server ComponentsKNOWNransomware (KEV-flagged)
CVE-2023-36884Microsoft WindowsKNOWNransomware (KEV-flagged)
CVE-2017-7494Samba SambaKNOWNransomware (KEV-flagged)
CVE-2015-2291Intel Ethernet Diagnostics DriveKNOWNransomware (KEV-flagged)
CVE-2023-0669Fortra GoAnywhere MFTKNOWNClop (GoAnywhere MFT)
CVE-2022-24990TerraMaster TerraMaster OSKNOWNransomware (KEV-flagged)
CVE-2022-47966Zoho ManageEngineKNOWNransomware (KEV-flagged)
CVE-2022-26500Veeam Backup & ReplicationKNOWNransomware (KEV-flagged)
CVE-2022-26501Veeam Backup & ReplicationKNOWNransomware (KEV-flagged)
CVE-2022-41091Microsoft WindowsKNOWNransomware (KEV-flagged)
CVE-2022-41040Microsoft Exchange ServerKNOWNProxyNotShell β€” Play, ransomware

📜 Energy Security Playbook

  1. Collect ICS/OT telemetry, exposed-device scans, and threat-actor infrastructure indicators for grid, pipeline, and generation assets
  2. Enrich indicators against ICS malware signatures and map affected protocols (IEC-104, Modbus, OPC) and PLC/RTU vendor exposure
  3. Analyze intrusion tradecraft against the ICS Cyber Kill Chain to gauge whether access enables disruption or destruction
  4. Attribute activity to state-linked groups via toolmarks, C2 clustering, and CVE-exploitation patterns targeting energy operators
  5. Alert utility operators and sector ISACs with detections, patch priorities, and OT segmentation guidance
  6. Drive coordinated remediation, threat hunting, and, where warranted, sanctions or diplomatic escalation against the operator

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎯 Add to case

Attach Energy Security (Mission Domain) and pull all linked entities:
Workstation Β· Copilot Β· AI Skills Β· Automation Β· Playbooks Β· Lookups Β· Docs Β· Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php