NEW: Group Profiler — instant APT intel lookup. Try it →

Critical Infra — threat intelligence

Recent advisories whose title or summary heuristically matches the Critical Infra sector. Derived in-browser/at-edge from a keyword catalog — treat tags as a hint and open each source for ground truth. Counts and contents update hourly.

34 recent Critical Infra advisories

  1. INFO EXPLOITED cisa-alerts · 4h ago

    Defending Against an Active Threat to Siemens S7 Series PLCs

    Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply re…

    siemens
  2. INFO EXPLOITED the-record · 22h ago

    More than 200 victims of Medusa ransomware identified over the last year, CISA says

    The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 vi…

    US
  3. INFO thehackernews · 22h ago

    Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

    Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing ma…

  4. INFO thehackernews · 6d ago

    New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

    Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD. According to Acronis Threat Research Unit…

    acronis AFIN
  5. MEDIUM cisa-alerts · 6d ago

    AVEVA Enterprise SCADA

    View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization. The following versions of AVEVA Enterprise SCADA are aff…

    aveva
  6. HIGH cisa-alerts · 6d ago

    Haiwell IoT Cloud HMI Gateway

    View CSAF Summary Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges. The following versions of Haiwell IoT Cloud HMI Gateway are affected: Haiwell IoT Cloud …

    github
  7. INFO EXPLOITED darkreading · 7d ago

    Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition

    Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.

    CO
  8. INFO securityweek · 7d ago

    ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact

    CISA has also published several advisories describing vulnerabilities in ICS and other OT products. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact appeared first on SecurityWeek.

    siemensschneider-electricphoenix-contact US
  9. INFO EXPLOITED darkreading · 7d ago

    Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

    The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.

    fortinet
  10. INFO EXPLOITED thehackernews · 8d ago

    Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

    Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public he…

    fortinetschneider-electric KR
  11. INFO thehackernews · 8d ago

    Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

    Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies h…

    PL
  12. INFO EXPLOITED the-record · 8d ago

    FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure

    The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.

    KRUS
  13. INFO the-record · 9d ago

    Senate Democrats introduce bill to distribute $300 million annually to shore up water system cybersecurity

    Two Democratic senators introduced legislation that would allocate $300 million each year to fund cybersecurity improvements for the water and wastewater sector.

  14. INFO EXPLOITED cisa-news · 9d ago

    CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors

    US
  15. INFO EXPLOITED cisa-alerts · 9d ago

    #StopRansomware: Gunra Ransomware

    Advisory at a Glance Title #StopRansomware: Gunra Ransomware Original Publication August 10, 2026 Executive Summary Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organi…

  16. INFO securityweek · 9d ago

    New Jersey, Alabama Join States Targeted in Water Cyberattacks

    Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states. The post New Jersey, Alabama Join States Targeted in Water Cyberattacks appeared first on SecurityWeek.

    US
  17. INFO thehackernews · 13d ago

    Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

    Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed …

    rockwell US
  18. INFO the-record · 14d ago

    Cyberattacks targeting water systems expand to 12 states as South Dakota, Georgia announce incidents

    Water utilities in at least 12 states have reported cyberattacks on their operational technology, as the scope of a campaign allegedly linked to Iranian hackers continues to grow.

  19. INFO securityweek · 15d ago

    New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems

    The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure. The post New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems appeared…

    US
  20. INFO checkpoint · 16d ago

    3rd August – Threat Intelligence Report

    For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community…

    check-point US
  21. INFO the-record · 18d ago

    CISA warns of spike in attacks on water systems as Minnesota incidents probed

    The Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible."

    US
  22. INFO securityweek · 19d ago

    CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs

    CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems. The post CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs appeared first …

    US
  23. INFO darkreading · 19d ago

    Minnesota Water Utility Attacks Expose Sector's Cyber-Risks

    A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure.

    US
  24. INFO tenable-advisories · 19d ago

    What water utilities need to know about cybersecurity compliance

    As federal enforcement tightens and states begin stepping in with their own cybersecurity mandates, water and wastewater utilities face a looming wave of hard compliance deadlines, compounded by recent cyber attacks on state water utilities…

    US
  25. INFO tenable-advisories · 20d ago

    Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security

    Canada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full co…

    tenable CA
  26. INFO us-cert-ces · 20d ago

    CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs

    CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrator…

    US
  27. INFO cisa-alerts · 20d ago

    Schneider Electric IGSS

    View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA s…

    schneider-electric
  28. INFO cisa-alerts · 20d ago

    Open Source Software: Security Principles and Practices

    Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and…

    US
  29. INFO thehackernews · 21d ago

    Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline

    A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly des…

    US
  30. INFO securityweek · 21d ago

    US, Australia Release OT Isolation Guidance for Critical Infrastructure

    The guidance details steps organizations can take to isolate vital OT and supporting systems, and operate in isolation for an extended period. The post US, Australia Release OT Isolation Guidance for Critical Infrastructure appeared first o…

    USAU
  31. INFO securityweek · 21d ago

    Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks

    State and federal agencies respond after intrusions disrupt automated controls at municipal water and wastewater utilities. The post Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks appeared first on SecurityWeek.

    US
  32. INFO tenable-advisories · 21d ago

    Coordinated "cyberattack" on U.S. water utilities: What you need to know

    A coordinated cyber attack disrupted water and wastewater systems in at least 12 U.S. states, including more than 30 Minnesota communities. Here is what defenders need to know about the attack so far. This FAQ also details recent cyberactiv…

    US
  33. INFO tenable-advisories · 21d ago

    Coordinated “cyberattack” on Minnesota water utilities: What you need to know

    A coordinated cyber attack disrupted water systems across more than 30 Minnesota communities. Here is what defenders need to know about the attack so far. This FAQ also details recent cyberactivity targeting internet-exposed PLCs, and how t…

    US
  34. INFO cisa-news · 22d ago

    CISA Joins Australia and Others to Publish Guidance to Isolate Operational Technology and Enabling Systems in Critical Infrastructure

    USAU

Other sectors: Government ·Healthcare ·Finance ·Energy ·Education ·Technology ·Telecom ·Defense ·Retail ·Transportation ·Legal Services

Also on ThreatFilter: cross-source corroborated CVEs · threat group directory · every source we track