Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

28 / 28 results
Active filter:tag: #critical-infrastructure✕ clear
NCSC warns of increased targeting of internet-exposed OT systems globallyhighbug_reportVulnerability
bug_reportVulnerability

NCSC warns of increased targeting of internet-exposed OT systems globally

Organizations with operational technology (OT) systems exposed to the internet across multiple sectors globally, including UK critical national infrastructure and non-CNI sectors.

NCSC UK27 Aug · 10:00 UTC
DoJ Disrupts QTFY Chinese State-Sponsored Infrastructure Targeting U.S.highperson_alertThreat Actor
person_alertThreat Actor

DoJ Disrupts QTFY Chinese State-Sponsored Infrastructure Targeting U.S.

QTFY is a Chinese state-sponsored threat actor employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司), active since May 2018. The group functions as a digital quartermaster serving China's Ministry of State Security (MSS) and People…

U.S. critical infrastructure operators26 Aug · 14:42 UTC
U.S. Sanctions Iran-Linked MOIS Cyber Actors for Infrastructure Attackshighperson_alertThreat Actor
person_alertThreat Actor

U.S. Sanctions Iran-Linked MOIS Cyber Actors for Infrastructure Attacks

Iran-linked cyber actors affiliated with Iran's Ministry of Intelligence and Security (MOIS), specifically members of the Tehran-based Mabna Institute. The group conducts cyber espionage operations in support of Iran's political objectives, including…

The Hacker News25 Aug · 16:17 UTC
AI-Generated Exploits Target Siemens S7 PLCs in U.S. Critical Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

AI-Generated Exploits Target Siemens S7 PLCs in U.S. Critical Infrastructure

This campaign involves unattributed threat actors leveraging artificial intelligence to generate exploitation scripts targeting industrial control systems.

Siemens20 Aug · 14:59 UTC
AI-Generated Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

AI-Generated Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

No specific threat actor or group has been attributed to this campaign. The advisory describes ongoing activity by unidentified threat actors targeting Siemens S7 Series programmable logic controllers in U.S. critical infrastructure.

Siemens19 Aug · 15:50 UTC
Windows IKE Extension RCE (CVE-2026-33824) actively exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

Windows IKE Extension RCE (CVE-2026-33824) actively exploited

All supported Windows 10, Windows 11, and Windows Server versions. The vulnerability affects the Windows Internet Key Exchange (IKE) Service Extensions (MS-IKEE) component accessible via UDP ports 500 and 4500.

Microsoft19 Aug · 08:12 UTC
Medusa Ransomware Gang Breaches 500+ US Critical Infrastructure Orgscriticalperson_alertThreat Actor
person_alertThreat Actor

Medusa Ransomware Gang Breaches 500+ US Critical Infrastructure Orgs

Medusa is a ransomware operation active since January 2021 that evolved from a closed ransomware variant into a Ransomware-as-a-Service (RaaS) model with an affiliate program.

BleepingComputer19 Aug · 06:00 UTC
Iranian Cavern C2 Framework Evolves with DNS and Google Apps Script Relayhighperson_alertThreat Actor
person_alertThreat Actor

Iranian Cavern C2 Framework Evolves with DNS and Google Apps Script Relay

Cavern (aka Cav3rn) is a command-and-control framework attributed to Iranian nation-state threat actors, specifically linked to Cavern Manticore, a hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS).

The Hacker News17 Aug · 15:41 UTC
Cisco Secure Firewall DoS flaw under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Firewall DoS flaw under active exploitation

Cisco Secure Firewall products (specific versions not disclosed in available data). Organizations using Cisco ASA, FTD, or Firepower appliances should assume exposure until vendor advisory is reviewed.

Cisco13 Aug · 06:31 UTC
Cyberattack disrupts North Carolina port operations, critical infrastructurehighpublicGeopolitical
publicGeopolitical

Cyberattack disrupts North Carolina port operations, critical infrastructure

The incident at North Carolina Ports Authority facilities represents a significant disruption to U.S. critical maritime infrastructure. Port of Wilmington and Port of Morehead City together constitute key logistics nodes on the U.S.

BleepingComputer7 Aug · 11:34 UTC
4,407 Rockwell PLCs exposed online; 22 in cities hit by water attackshighbug_reportVulnerability
bug_reportVulnerability

4,407 Rockwell PLCs exposed online; 22 in cities hit by water attacks

Rockwell Automation programmable logic controllers (PLCs) globally: 4,407 exposed devices (2,844 in US). Primary models: MicroLogix 1400 (50%) and MicroLogix 1100 (8%).

Rockwell Automation6 Aug · 10:16 UTC
CISA warns of rising attacks on internet-exposed PLCs in water systemshighbug_reportVulnerability
bug_reportVulnerability

CISA warns of rising attacks on internet-exposed PLCs in water systems

Internet-exposed programmable logic controllers (PLCs) in U.S. water and wastewater systems. Specific vendors and models not disclosed in available information.

BleepingComputer31 Jul · 14:49 UTC
Cisco Secure Firewall Management Center under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Firewall Management Center under active exploitation

Cisco Secure Firewall Management Center (formerly Firepower Management Center). Specific affected versions not disclosed in available data. Vulnerability details including CVE identifier not yet published.

Cisco31 Jul · 06:58 UTC
Coordinated OT attack disrupts 30+ Minnesota water systemshighbug_reportVulnerability
bug_reportVulnerability

Coordinated OT attack disrupts 30+ Minnesota water systems

Over 30 community water systems in Minnesota. Operational technology (OT) systems at local water utilities targeted, including programmable logic controllers and computerized operating systems. Attacks occurred July 26-27, 2026. Threat actor unknown.

BleepingComputer29 Jul · 12:55 UTC
Coordinated attack hits 30+ Minnesota water systems, causes plant outageshighbug_reportVulnerability
bug_reportVulnerability

Coordinated attack hits 30+ Minnesota water systems, causes plant outages

Over 30 Minnesota community water systems targeted July 26-27, 2026. Operational technology (OT) infrastructure affected, including programmable logic controllers (PLCs) and human-machine interfaces (HMIs) at water treatment and wastewater facilities…

The Hacker News29 Jul · 11:48 UTC
JackSkid Adopts Blockchain C2 and Relay Mesh After March Takedownhighperson_alertThreat Actor
person_alertThreat Actor

JackSkid Adopts Blockchain C2 and Relay Mesh After March Takedown

JackSkid is an IoT botnet operator linked to the Dysphoria botnet family, targeted in coordinated U.S., German, and Canadian law enforcement actions on March 19, 2026.

The Hacker News27 Jul · 15:16 UTC
Russian Intelligence Services Exploit Security Cameras for Military Surveillancehighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Services Exploit Security Cameras for Military Surveillance

Russian intelligence services are conducting a systematic cyber-espionage campaign targeting internet-connected security cameras across Europe and Ukraine.

The Hacker News20 Jul · 10:13 UTC
CISA adds CVE-2023-4346 KNX Protocol flaw to KEV catalogcriticalbug_reportVulnerability
bug_reportVulnerability

CISA adds CVE-2023-4346 KNX Protocol flaw to KEV catalog

KNX Protocol implementations used in building automation and smart home systems. Specific affected products and versions not disclosed in available information.

CVE-2023-434616 Jul · 13:26 UTC
DHS Confirms Breach of Homeland Security Information NetworkhighpublicGeopolitical
publicGeopolitical

DHS Confirms Breach of Homeland Security Information Network

The compromise of the Homeland Security Information Network (HSIN) represents a significant breach of a critical federal information-sharing infrastructure.

Department of Homeland Security1 Jul · 15:32 UTC
CL-STA-1062 deploys TinyRCT backdoor against Southeast Asian governmenthighperson_alertThreat Actor
person_alertThreat Actor

CL-STA-1062 deploys TinyRCT backdoor against Southeast Asian government

CL-STA-1062 is a Chinese-speaking APT actor conducting targeted cyber espionage operations against government entities and critical infrastructure in Southeast Asia.

Palo Alto Networks26 Jun · 14:21 UTC
CL-STA-1062 targets Southeast Asian government with TinyRCT backdoorhighperson_alertThreat Actor
person_alertThreat Actor

CL-STA-1062 targets Southeast Asian government with TinyRCT backdoor

CL-STA-1062 is a threat actor conducting cyber espionage operations against government entities and critical infrastructure in Southeast Asia. The actor employs a hybrid toolkit centered around a custom backdoor known as TinyRCT.

Unit 42 (Palo Alto)25 Jun · 20:00 UTC
Scattered Spider Members Plead Guilty to Transport for London Breachhighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Members Plead Guilty to Transport for London Breach

Scattered Spider (G1015), also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944, is a financially motivated cybercrime group known for sophisticated social engineering and identity-based attacks.

Transport for London23 Jun · 13:31 UTC
CISA warns of 74,000 Fortinet credentials exposed in FortiBleed leakhighpublicGeopolitical
publicGeopolitical

CISA warns of 74,000 Fortinet credentials exposed in FortiBleed leak

The exposure of approximately 74,000 Fortinet firewall and VPN credentials represents a significant supply-side vulnerability affecting critical infrastructure globally.

Fortinet19 Jun · 04:47 UTC
900+ US fuel tank monitoring systems exposed online, vulnerable to attackhighbug_reportVulnerability
bug_reportVulnerability

900+ US fuel tank monitoring systems exposed online, vulnerable to attack

Over 900 automatic tank gauge (ATG) systems in the United States used to monitor fuel and chemical storage tanks in critical infrastructure. Specific vendors and product versions not disclosed.

BleepingComputer5 Jun · 12:50 UTC
GREYVIBE: Russian-linked APT targeting Ukraine since August 2025highperson_alertThreat Actor
person_alertThreat Actor

GREYVIBE: Russian-linked APT targeting Ukraine since August 2025

GREYVIBE is a previously undocumented threat actor attributed by WithSecure as Russian-linked, assessed to operate in support of Kremlin state interests. The group is characterized as Russian-speaking and operates within Russian time zones.

The Hacker News29 May · 09:31 UTC
Anthropic Glasswing project finds 10,000+ critical flaws in key softwarehighbug_reportVulnerability
bug_reportVulnerability

Anthropic Glasswing project finds 10,000+ critical flaws in key software

Widely used, systemically important software (specific products not disclosed). Over 10,000 high- or critical-severity vulnerabilities identified since project launch last month.

<UNKNOWN>23 May · 09:55 UTC
SonicWall Gen6 SSL-VPN exploited for credential brute-force and MFA bypasscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall Gen6 SSL-VPN exploited for credential brute-force and MFA bypass

SonicWall Gen6 SSL-VPN appliances with incomplete patching. Specific firmware versions not disclosed. Affects organizations using SonicWall SSL-VPN for remote access.

SonicWall20 May · 19:19 UTC
3onedata GW1101 Modbus gateway vulnerable to OS command injectionhighbug_reportVulnerability
bug_reportVulnerability

3onedata GW1101 Modbus gateway vulnerable to OS command injection

3onedata GW1101-1D(RS-485)-TB-P Modbus gateways. Specific affected firmware versions not disclosed. These are industrial IoT devices used for Modbus protocol conversion in OT/ICS environments.

CVE-2025-136054 May · 12:55 UTC