NEW: Group Profiler — instant APT intel lookup. Try it →

Critical Infra — threat intelligence

Recent advisories whose title or summary heuristically matches the Critical Infra sector. Derived in-browser/at-edge from a keyword catalog — treat tags as a hint and open each source for ground truth. The underlying feed updates hourly; this page is a snapshot from its last build (timestamped below).

10 recent Critical Infra advisories

Snapshot built . The live filter and the RSS feed reflect new items as they arrive.

  1. INFO EXPLOITED thehackernews ·

    Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

    The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The a…

    microsoft
  2. INFO EXPLOITED the-record ·

    'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries

    The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team.

    microsoft PTES
  3. INFO securityweek ·

    Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

    The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025. The post Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks appeared first on SecurityWeek.

    microsoft
  4. INFO securityweek ·

    OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators

    Revision 4 of NIST’s operational technology security guide is open for public comments until November 30. The post OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators appeared first on SecurityWeek.

    US
  5. INFO cisa-alerts ·

    Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators

    Introduction The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)—hereafter referred to as the “authoring agencies”—have published this fact sheet to highlight considerations for critical inf…

    cisco-umbrella US
  6. INFO securityweek ·

    Only 13% of OT Network Segments Are Fully Isolated: Analysis

    Forescout’s new network segmentation research shows that OT and medical devices often share network segments with other enterprise assets. The post Only 13% of OT Network Segments Are Fully Isolated: Analysis appeared first on SecurityWeek.

  7. INFO cisa-alerts ·

    OpenPLC Runtime v3

    View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller a…

    github
  8. INFO cisa-news ·

    New CISA Guidance Helps Critical Infrastructure Detect, Observe and Impede Malicious Cyber Activity

    US
  9. INFO tenable-advisories ·

    Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.

    Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture.Ke…

    AU
  10. INFO securityweek ·

    ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

    AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products. The post ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws appeared first on SecurityWeek.

    siemensschneider-electricrockwell-automation

Other sectors: Government ·Healthcare ·Finance ·Energy ·Education ·Technology ·Telecom ·Defense ·Retail ·Transportation ·Legal Services

Threat groups reported to target Critical Infra

MITRE ATT&CK records 3 tracked groups with reported targeting of this sector. Each links to its ATT&CK profile: techniques by tactic, aliases, tooling and the groups closest to it by technique overlap. Reported targeting is not attribution of any specific advisory above.

BRONZE BUTLER ·POLONIUM ·Sandworm Team

Also on ThreatFilter: cross-source corroborated CVEs · threat group directory · every source we track