Critical Infra — threat intelligence
Recent advisories whose title or summary heuristically matches the Critical Infra sector. Derived in-browser/at-edge from a keyword catalog — treat tags as a hint and open each source for ground truth. Counts and contents update hourly.
27 recent Critical Infra advisories
-
UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure
Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify. The post UK Moves to Block High-Risk Tech Suppliers From Critical Infrastruc…
-
Communicating Under Pressure: Best Practices for Service Providers
Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational te…
-
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcod…
-
This month in security with Tony Anscombe – August 2026 edition
Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity news
-
Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear
The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns. The post Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear appeared first on SecurityWeek.
-
Threat landscape for industrial automation systems. Q2 2026
The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control systems.
-
US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks
The operation focused on a group named QTFY, which offers hacking services to the Chinese government and others. The post US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks appeared first on SecurityWe…
-
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. Th…
-
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecr…
-
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economi…
-
Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference
Hands-on Cyber Attack Methods course returns to SecurityWeek’s ICS Cybersecurity Conference, October 6–8 at the W Nashville. The post Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference appeared first on Securit…
-
US sanctions Iranian cyber actors as UK discloses power plant attack
The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.
-
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammab…
-
Frequently asked questions about the active threat to Siemens S7 Series PLCs
A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors.Key TakeawaysU…
-
NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology
The National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of known vulnerabilities.
-
Defending Against an Active Threat to Siemens S7 Series PLCs
Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply re…
-
More than 200 victims of Medusa ransomware identified over the last year, CISA says
The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 vi…
-
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing ma…
-
New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure
Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD. According to Acronis Threat Research Unit…
-
AVEVA Enterprise SCADA
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization. The following versions of AVEVA Enterprise SCADA are aff…
-
Haiwell IoT Cloud HMI Gateway
View CSAF Summary Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges. The following versions of Haiwell IoT Cloud HMI Gateway are affected: Haiwell IoT Cloud …
-
Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.
-
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
CISA has also published several advisories describing vulnerabilities in ICS and other OT products. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact appeared first on SecurityWeek.
-
Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.
-
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public he…
-
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies h…
-
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.
Other sectors: Government ·Healthcare ·Finance ·Energy ·Education ·Technology ·Telecom ·Defense ·Retail ·Transportation ·Legal Services
Also on ThreatFilter: cross-source corroborated CVEs · threat group directory · every source we track