Critical Infra — threat intelligence
Recent advisories whose title or summary heuristically matches the Critical Infra sector. Derived in-browser/at-edge from a keyword catalog — treat tags as a hint and open each source for ground truth. The underlying feed updates hourly; this page is a snapshot from its last build (timestamped below).
10 recent Critical Infra advisories
Snapshot built . The live filter and the RSS feed reflect new items as they arrive.
-
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The a…
-
'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries
The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team.
-
Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025. The post Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks appeared first on SecurityWeek.
-
OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators
Revision 4 of NIST’s operational technology security guide is open for public comments until November 30. The post OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators appeared first on SecurityWeek.
-
Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators
Introduction The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)—hereafter referred to as the “authoring agencies”—have published this fact sheet to highlight considerations for critical inf…
-
Only 13% of OT Network Segments Are Fully Isolated: Analysis
Forescout’s new network segmentation research shows that OT and medical devices often share network segments with other enterprise assets. The post Only 13% of OT Network Segments Are Fully Isolated: Analysis appeared first on SecurityWeek.
-
OpenPLC Runtime v3
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller a…
-
New CISA Guidance Helps Critical Infrastructure Detect, Observe and Impede Malicious Cyber Activity
-
Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.
Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture.Ke…
-
ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products. The post ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws appeared first on SecurityWeek.
Other sectors: Government ·Healthcare ·Finance ·Energy ·Education ·Technology ·Telecom ·Defense ·Retail ·Transportation ·Legal Services
Threat groups reported to target Critical Infra
MITRE ATT&CK records 3 tracked groups with reported targeting of this sector. Each links to its ATT&CK profile: techniques by tactic, aliases, tooling and the groups closest to it by technique overlap. Reported targeting is not attribution of any specific advisory above.
Also on ThreatFilter: cross-source corroborated CVEs · threat group directory · every source we track