NEW: Group Profiler — instant APT intel lookup. Try it →

Critical Infra — threat intelligence

Recent advisories whose title or summary heuristically matches the Critical Infra sector. Derived in-browser/at-edge from a keyword catalog — treat tags as a hint and open each source for ground truth. Counts and contents update hourly.

27 recent Critical Infra advisories

  1. INFO securityweek · 2d ago

    UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

    Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify. The post UK Moves to Block High-Risk Tech Suppliers From Critical Infrastruc…

    UK
  2. INFO cisa-alerts · 2d ago

    Communicating Under Pressure: Best Practices for Service Providers

    Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational te…

    US
  3. CRITICAL 9.8 PoC thehackernews · 2d ago

    Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

    Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcod…

  4. INFO welivesecurity · 4d ago

    This month in security with Tony Anscombe – August 2026 edition

    Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity news

  5. INFO securityweek · 8d ago

    Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear

    The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns. The post Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear appeared first on SecurityWeek.

    US
  6. INFO EXPLOITED securelist · 8d ago

    Threat landscape for industrial automation systems. Q2 2026

    The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control systems.

  7. INFO securityweek · 8d ago

    US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks

    The operation focused on a group named QTFY, which offers hacking services to the Chinese government and others. The post US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks appeared first on SecurityWe…

    US
  8. INFO thehackernews · 8d ago

    FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

    The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. Th…

    US
  9. INFO thehackernews · 9d ago

    CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecr…

    US
  10. INFO thehackernews · 9d ago

    U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

    The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economi…

    IR
  11. INFO securityweek · 10d ago

    Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference

    Hands-on Cyber Attack Methods course returns to SecurityWeek’s ICS Cybersecurity Conference, October 6–8 at the W Nashville. The post Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference appeared first on Securit…

  12. INFO the-record · 10d ago

    US sanctions Iranian cyber actors as UK discloses power plant attack

    The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.

    GB
  13. INFO EXPLOITED thehackernews · 14d ago

    AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

    The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammab…

    siemens US
  14. INFO EXPLOITED tenable-advisories · 15d ago

    Frequently asked questions about the active threat to Siemens S7 Series PLCs

    A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors.Key TakeawaysU…

    siemens
  15. INFO the-record · 15d ago

    NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology

    The National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of known vulnerabilities.

    siemens US
  16. INFO EXPLOITED cisa-alerts · 16d ago

    Defending Against an Active Threat to Siemens S7 Series PLCs

    Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply re…

    siemens
  17. INFO EXPLOITED the-record · 16d ago

    More than 200 victims of Medusa ransomware identified over the last year, CISA says

    The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 vi…

    US
  18. INFO thehackernews · 16d ago

    Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

    Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing ma…

  19. INFO thehackernews · 22d ago

    New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

    Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD. According to Acronis Threat Research Unit…

    acronis AFIN
  20. MEDIUM cisa-alerts · 22d ago

    AVEVA Enterprise SCADA

    View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization. The following versions of AVEVA Enterprise SCADA are aff…

    aveva
  21. HIGH cisa-alerts · 22d ago

    Haiwell IoT Cloud HMI Gateway

    View CSAF Summary Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges. The following versions of Haiwell IoT Cloud HMI Gateway are affected: Haiwell IoT Cloud …

    github
  22. INFO EXPLOITED darkreading · 23d ago

    Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition

    Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.

    CO
  23. INFO securityweek · 23d ago

    ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact

    CISA has also published several advisories describing vulnerabilities in ICS and other OT products. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact appeared first on SecurityWeek.

    siemensschneider-electricphoenix-contact US
  24. INFO EXPLOITED darkreading · 23d ago

    Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

    The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.

    fortinet
  25. INFO EXPLOITED thehackernews · 24d ago

    Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

    Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public he…

    fortinetschneider-electric KR
  26. INFO thehackernews · 24d ago

    Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

    Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies h…

    PL
  27. INFO EXPLOITED the-record · 24d ago

    FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure

    The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.

    KRUS

Other sectors: Government ·Healthcare ·Finance ·Energy ·Education ·Technology ·Telecom ·Defense ·Retail ·Transportation ·Legal Services

Also on ThreatFilter: cross-source corroborated CVEs · threat group directory · every source we track