π Energy Security theater
Defends energy security: cyber-physical threats to electric grids, pipelines, refineries, and generation, spanning OT/ICS intrusions, wiper attacks, and physical sabotage. It matters because energy is the keystone critical infrastructure whose disruption cascades into every other sector and is a prime nation-state coercion target.
Live indicators
3.7K
in this theater
High severity
0
score β₯ 0.75 (top 60)
Actors tracked
7
documented
Mapped sources
2
in catalog
🦠 Malware & Tools
🛡 Exploited Vulnerabilities
| CVE | Vendor / Product | Ransomware | Malware |
|---|---|---|---|
| CVE-2026-1731 | BeyondTrust Remote Support (RS) and Pr | KNOWN | ransomware (KEV-flagged) |
| CVE-2025-55182 | Meta React Server Components | KNOWN | ransomware (KEV-flagged) |
| CVE-2023-36884 | Microsoft Windows | KNOWN | ransomware (KEV-flagged) |
| CVE-2017-7494 | Samba Samba | KNOWN | ransomware (KEV-flagged) |
| CVE-2015-2291 | Intel Ethernet Diagnostics Drive | KNOWN | ransomware (KEV-flagged) |
| CVE-2023-0669 | Fortra GoAnywhere MFT | KNOWN | Clop (GoAnywhere MFT) |
| CVE-2022-24990 | TerraMaster TerraMaster OS | KNOWN | ransomware (KEV-flagged) |
| CVE-2022-47966 | Zoho ManageEngine | KNOWN | ransomware (KEV-flagged) |
| CVE-2022-26500 | Veeam Backup & Replication | KNOWN | ransomware (KEV-flagged) |
| CVE-2022-26501 | Veeam Backup & Replication | KNOWN | ransomware (KEV-flagged) |
| CVE-2022-41091 | Microsoft Windows | KNOWN | ransomware (KEV-flagged) |
| CVE-2022-41040 | Microsoft Exchange Server | KNOWN | ProxyNotShell β Play, ransomware |
📚 Priority sources & datasets
📜 Energy Security Playbook
- Collect ICS/OT telemetry, exposed-device scans, and threat-actor infrastructure indicators for grid, pipeline, and generation assets
- Enrich indicators against ICS malware signatures and map affected protocols (IEC-104, Modbus, OPC) and PLC/RTU vendor exposure
- Analyze intrusion tradecraft against the ICS Cyber Kill Chain to gauge whether access enables disruption or destruction
- Attribute activity to state-linked groups via toolmarks, C2 clustering, and CVE-exploitation patterns targeting energy operators
- Alert utility operators and sector ISACs with detections, patch priorities, and OT segmentation guidance
- Drive coordinated remediation, threat hunting, and, where warranted, sanctions or diplomatic escalation against the operator
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🎯 Add to case
🧩 Advanced Capabilities
🔗 Cross-domain pivots
Workstation Β· Copilot Β· AI Skills Β· Automation Β· Playbooks Β· Lookups Β· Docs Β· Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron