<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Critical-Infrastructure on CuraSec</title><link>https://curasec.metacog.co.kr/tags/critical-infrastructure/</link><description>Recent content in Critical-Infrastructure on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 27 Aug 2026 21:01:55 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/critical-infrastructure/index.xml" rel="self" type="application/rss+xml"/><item><title>ThreatsDay Digest: IoT Botnet, Water Systems, SharePoint RCE</title><link>https://curasec.metacog.co.kr/insights/2026-08-27-threatsday-296k-iot-botnet-100-water-systems-targeted-sharep/</link><pubDate>Thu, 27 Aug 2026 21:01:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-27-threatsday-296k-iot-botnet-100-water-systems-targeted-sharep/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> SharePoint RCE chain and AI-assisted botnet techniques are worth tracking, but the summary provides no CVE, EPSS, KEV, or patch target — read the full digest to identify whether any specific component you run is affected.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> C2 traffic hiding in public infrastructure and delayed-payload malware are tactically interesting detection themes, but no IOCs or ATT&amp;amp;CK mappings are surfaced here — use this as a prompt to review whether relevant log sources (DNS, proxy) would catch these patterns.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The mention of over 100 water systems targeted is notable for critical-infrastructure sector awareness, but this is a vague digest with no specifics suitable for a leadership brief or risk-register update.&lt;/li>
&lt;/ul></description></item><item><title>U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches</title><link>https://curasec.metacog.co.kr/insights/2026-08-26-u-s-sanctions-iran-linked-hackers-behind-critical-infrastruc/</link><pubDate>Wed, 26 Aug 2026 11:42:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-26-u-s-sanctions-iran-linked-hackers-behind-critical-infrastruc/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Attribution of Iranian cyber actors to critical infrastructure breaches is useful for sector threat modeling, but the summary contains no IOCs, TTPs, or detection-ready material to act on.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Relevant geopolitical context for board-level risk briefings on nation-state threats to critical infrastructure, but no specific sectors or victims are named here, so no immediate exposure assessment is warranted.&lt;/li>
&lt;/ul></description></item><item><title>AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure</title><link>https://curasec.metacog.co.kr/insights/2026-08-21-ai-generated-exploit-scripts-target-siemens-s7-plcs-in-u-s-c/</link><pubDate>Fri, 21 Aug 2026 11:38:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-21-ai-generated-exploit-scripts-target-siemens-s7-plcs-in-u-s-c/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Siemens S7 PLCs are OT/ICS territory outside typical cloud/AppSec scope, but the technique of using AI-generated scripts disguised as legitimate monitoring tools is a design-relevant threat model for anyone operating industrial or hybrid environments.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No IOCs are published yet, but a U.S. government active-threat designation warrants developing detections for anomalous PLC communication and tools impersonating legitimate monitoring agents in OT network segments; queue a hunt playbook now.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A formal U.S. government active-threat warning against critical infrastructure is board-question territory — confirm this week whether your organization or OT vendors operate Siemens S7 equipment and brief leadership before they read it elsewhere.&lt;/li>
&lt;/ul></description></item><item><title>US warns of AI-powered attacks on Siemens S7 PLCs in critical infrastructure</title><link>https://curasec.metacog.co.kr/insights/2026-08-20-us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-i/</link><pubDate>Thu, 20 Aug 2026 11:39:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-20-us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-i/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> AI-generated exploit scripts targeting Siemens S7 PLCs represents a novel offensive technique for ICS environments, but the thin summary offers no CVE, version range, or patch to act on. Engineers supporting OT/ICS should monitor for follow-on advisories with technical specifics.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, TTPs, or detection surface are described in this advisory, leaving nothing actionable to hunt or tune. Analysts in critical infrastructure sectors should track follow-up CISA publications for actor behaviors and log sources to enable.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A formal US government warning about AI-assisted attacks on critical infrastructure PLCs warrants a check of whether the organization operates or depends on Siemens S7 equipment, and a brief to OT security owners and relevant leadership before this surfaces in board-level news cycles.&lt;/li>
&lt;/ul></description></item><item><title>CISA: Medusa ransomware breached 500+ critical infrastructure orgs</title><link>https://curasec.metacog.co.kr/insights/2026-08-19-cisa-medusa-ransomware-hit-over-500-critical-infrastructure/</link><pubDate>Wed, 19 Aug 2026 11:36:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-19-cisa-medusa-ransomware-hit-over-500-critical-infrastructure/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The CISA/FBI advisory likely details initial-access vectors (historically RDP abuse and phishing) worth reviewing to validate existing hardening; no specific exploited CVE is surfaced in this summary, so no emergency patch action required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Pull the full CISA advisory for Medusa IOCs and ATT&amp;amp;CK TTPs, then hunt for those indicators in endpoint and network telemetry dating back to mid-2021 if within retention; tune ransomware-staging detections against the published behaviors.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A named campaign with 500+ confirmed critical-infrastructure victims backed by a joint CISA/FBI advisory is likely to generate board and customer questions this week; brief leadership on your sector&amp;rsquo;s exposure and confirm your ransomware IR plan and backup posture are current.&lt;/li>
&lt;/ul></description></item><item><title>Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-gunra-ransomware-exploits-fortinet-and-schneider-electric-fl/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-gunra-ransomware-exploits-fortinet-and-schneider-electric-fl/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Fortinet and Schneider Electric products are named as actively exploited entry points in a joint US/South Korea advisory; audit Fortinet appliances and OT-facing Schneider devices for unpatched vulnerabilities and apply vendor patches immediately.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Joint government advisory signals published TTPs and IOCs are available; run a Gunra hunt across network and endpoint telemetry now, prioritizing environments in healthcare, financial services, or government sectors given the stated targeting pattern.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A US/South Korea joint advisory naming specific critical-infrastructure sectors—healthcare, financial, government—warrants same-week action: confirm whether Fortinet or Schneider Electric products are in your estate and brief leadership before this appears in industry news.&lt;/li>
&lt;/ul></description></item><item><title>Hackers Breach Polish CHP Plant via Private Cellular APN, Shut Turbine</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-hackers-breach-polish-power-plant-controls-via-private-cellu/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-hackers-breach-polish-power-plant-controls-via-private-cellu/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The attack entered through a private cellular APN used for remote OT equipment access — a network path often assumed to be isolated. Any org running OT/SCADA with cellular-based remote access should audit that network segment for authentication controls and lateral-movement barriers, but no patch or CVE applies here.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, no ATT&amp;amp;CK-mapped TTPs, and no detection signatures are available from this item. The incident pattern — cellular APN pivot to industrial control systems — is worth noting for OT-aware threat models, but there is no actionable hunt or detection to write from current reporting.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A confirmed OT attack that disrupted heat for 50,000 residents is a strong board-level illustration of critical-infrastructure risk via unconventional network paths. Leaders at energy or utilities firms should review whether similar remote-access architectures exist in their estate; for general enterprise CISOs, this is useful context for OT risk conversations.&lt;/li>
&lt;/ul></description></item><item><title>Polish energy plant breached via private APN into OT network</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-hackers-breached-a-small-polish-energy-plant-via-private-apn/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-hackers-breached-a-small-polish-energy-plant-via-private-apn/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Illustrates how cellular private APN links can serve as overlooked OT ingress points — engineers managing hybrid IT/OT environments should review whether any private APN or cellular uplink bypasses standard network segmentation controls.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No published IOCs, TTPs, or actor attribution are available from this incident, and it occurred over a year ago; useful context for understanding OT detection blind spots but yields no immediate hunt or detection work.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>US &amp; South Korea warn of Gunra ransomware targeting govt/critical infra</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-us-and-south-korea-warn-of-gunra-ransomware-targeting-govt-a/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-us-and-south-korea-warn-of-gunra-ransomware-targeting-govt-a/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> A joint government advisory signals active ransomware targeting critical infrastructure; review backup integrity, network segmentation, and endpoint hardening against ransomware TTPs this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Joint advisory from US agencies and South Korea&amp;rsquo;s NPA indicates active Gunra ransomware campaign — hunt for associated TTPs and IOCs once the full advisory is reviewed, and ensure ransomware-stage detections (lateral movement, mass encryption) are tuned.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A US government warning about ransomware targeting critical infrastructure warrants briefing leadership and confirming your sector&amp;rsquo;s exposure; add Gunra to the risk register and verify incident response plans cover ransomware scenarios.&lt;/li>
&lt;/ul></description></item><item><title>North Carolina Ports Authority confirms disruptive cyberattack</title><link>https://curasec.metacog.co.kr/insights/2026-08-09-north-carolina-ports-confirms-cyberattack-disrupting-operati/</link><pubDate>Sun, 09 Aug 2026 11:41:42 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-09-north-carolina-ports-confirms-cyberattack-disrupting-operati/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Active attack against maritime critical infrastructure with operational impact, but no IOCs, TTPs, or attribution have been published yet — monitor for follow-up reporting before initiating a hunt.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A confirmed attack disrupting multi-site port operations illustrates supply-chain and critical-infrastructure risk; useful context for board risk discussions but no vendor exposure to verify or immediate action required at this stage.&lt;/li>
&lt;/ul></description></item><item><title>4,400+ Rockwell PLCs Exposed Online; 22 Near Water Utility Attack Sites</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-over-4-400-rockwell-plcs-exposed-online-22-found-in-water-at/</link><pubDate>Fri, 07 Aug 2026 00:21:58 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-over-4-400-rockwell-plcs-exposed-online-22-found-in-water-at/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If your organization runs Rockwell Automation PLCs, verify none are internet-facing — Forescout&amp;rsquo;s scan found 2,844 exposed in the US alone. No exploitation confirmed, but the attack surface is substantial; audit firewall rules and mobile-carrier connections to any OT assets this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The correlation of 22 internet-exposed Rockwell PLCs in water utility attack cities is noteworthy context, but no IOCs, TTPs, or detection opportunities are surfaced — file as threat-landscape awareness for critical infrastructure hunting programs.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> The pattern of water utility cyberattacks combined with thousands of internet-exposed industrial controllers warrants adding OT/ICS internet exposure to your next risk review; if your organization operates critical infrastructure or uses Rockwell equipment, request an exposure audit before this becomes a board question.&lt;/li>
&lt;/ul></description></item><item><title>CISA/Australia guidance on isolating OT systems during cyberattacks</title><link>https://curasec.metacog.co.kr/insights/2026-07-29-cisa-shares-advice-on-isolating-vital-systems-during-cyberat/</link><pubDate>Wed, 29 Jul 2026 13:07:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-29-cisa-shares-advice-on-isolating-vital-systems-during-cyberat/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Review the guidance and map your OT/IT network segmentation against CISA&amp;rsquo;s isolation playbook; identify which systems have manual fallback modes and document runbooks for emergency isolation this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Use this guidance to pressure-test your IR playbooks for OT environments — specifically, ensure you have documented procedures for triggering OT isolation and know who owns that call.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Joint US/Australian guidance signals regulatory direction for critical infrastructure operators; useful context for board-level resilience discussions but no immediate action required absent a specific deadline or incident.&lt;/li>
&lt;/ul></description></item><item><title>US and allies warn of Russian state hackers targeting routers</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-us-and-allies-warn-of-russian-critical-infrastructure-attack/</link><pubDate>Mon, 13 Jul 2026 13:18:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-us-and-allies-warn-of-russian-critical-infrastructure-attack/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> The advisory targets vulnerable and misconfigured routers — audit your edge router configurations against the joint advisory&amp;rsquo;s hardening guidance and prioritize patching any unmanaged or end-of-life devices on the network perimeter this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> A nine-nation joint advisory signals a documented campaign with TTPs worth operationalizing; pull the full advisory for any ATT&amp;amp;CK mappings and IOCs and build or tune detections for lateral movement originating from router-adjacent network segments.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A coordinated advisory from nine countries on Russian state targeting of critical infrastructure raises the threat posture for the quarter — assess whether your sector is named in the advisory and prepare a brief for leadership on edge-device exposure and any vendor dependencies in that space.&lt;/li>
&lt;/ul></description></item></channel></rss>