Skip to content

Topic

Critical infrastructure security

Protecting power grids, water, transportation and industrial control/OT systems from cyberattacks and physical threats to essential services.

Current stories

security6 publishers

Warlock ransomware group narrows its targets to large Spanish- and Portuguese-speaking organizations

Warlock, the group Microsoft tracks as Storm-2603, hit four organizations in Spanish- or Portuguese-speaking countries in two months, Symantec says. It works like the Chinese state groups it first appeared beside and extorts like a ransomware crew.

Perspective Coverage

6 publishers
Builder
Builder 32%
Operator
Operator 59%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+15
Incentives30
Confidence68
leadership1 publisher

Triage and tuning decided which SOC caught CISA's red team

CISA's red team breached two critical-sector organisations, and only the water-sector one contained it, isolating machines in up to 20 minutes. The gap traces to alert tuning and triage, so the first fix most SOCs need is analyst time.

Publishers:itpro.com

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives55
Confidence45
build1 publisher

Keio's trains kept running through a ransomware attack on its group servers

Keio Corporation shut its network after ransomware hit its group servers on September 26, disrupting payments and the business behind its 25 hotels. Its trains appear unaffected. Investigators have not yet traced the attack path, so it is still unknown whether a designed boundary kept rail out of reach.

Publishers:dev.to

Reality

Evidence40
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence35
security6 publishers

Five new Iran determinations widen the sanctions perimeter to eight lines of business

Operation Economic Outcast names nearly 60 targets, but the durable change is the standing authority to designate foreign firms in crypto, technology, gold, aviation and shipping.

Perspective Coverage

6 publishers
Builder
Builder 15%
Operator
Operator 52%
Investor
Investor 33%

Reality

Evidence70
Adoption
Insufficient
Hype gap+40
Incentives60
Confidence65
security5 publishers

CISA ran the same tradecraft at two organisations; only the water utility caught it

Detection at the first hop forced CISA's red team onto donated access at Organization B. It did not stop the team reaching the same sensitive systems it reached at Organization A.

Perspective Coverage

5 publishers
Builder
Builder 39%
Operator
Operator 53%
Investor
Investor 8%

Reality

Evidence76
Adoption
Insufficient
Hype gap+12
Incentives35
Confidence72
product5 publishers

CrowdStrike and Fortinet co-sign a letter that dates the security tooling they sell

More than 100 companies signed a call for collective action on cyber defence whose first principle is that status quo security will not be enough, a sentence co-signed by five of the vendors who supply that status quo.

Perspective Coverage

5 publishers
Builder
Builder 33%
Operator
Operator 42%
Investor
Investor 25%

Reality

Evidence70
Adoption20
Hype gap+35
Incentives80
Confidence65
leadership4 publishers

The 100-firm cyber defense letter sets metrics for everyone but its own signatories

OpenAI, Anthropic, Google, Microsoft, Visa and Mastercard want defenders equipped before AI attacks scale. The document behind that call skips the money, the dates and the owner, leaving the 48-hour exploit window on the buyer's books.

Publishers:aiscoop.combusinessinsider.comcbsnews.comimplicator.ai

Perspective Coverage

4 publishers
Builder
Builder 30%
Operator
Operator 46%
Investor
Investor 24%

Reality

Evidence55
Adoption
Insufficient
Hype gap+35
Incentives65
Confidence60
security5 publishers

Check Point co-signs a cyber defense letter whose only named product belongs to OpenAI

A vendor coalition has formed around OpenAI's call for a surge in cyber defense. What an underfunded defender can actually requisition from it today is one subsidized model tier, on terms the letter does not state.

Perspective Coverage

5 publishers
Builder
Builder 25%
Operator
Operator 48%
Investor
Investor 27%

Reality

Evidence55
Adoption15
Hype gap+40
Incentives72
Confidence62
security5 publishers

CISA now tells critical infrastructure to plant fake credentials for attackers to trip over

The federal cyber agency now recommends planting fake records, credentials and files across critical infrastructure networks, and its pitch to understaffed teams is that an alert on a decoy needs no analyst to interpret it.

Perspective Coverage

5 publishers
Builder
Builder 46%
Operator
Operator 47%
Investor
Investor 7%

Reality

Evidence70
Adoption
Insufficient
Hype gap+15
Incentives30
Confidence75

Earlier coverage

  1. Coast Guard cyber teams found malicious activity aboard Texas-bound tanker and second vessel in Gulf of Mexico

    Security · September 17, 2026 · 3 publishers

  2. Coast Guard and FBI cyber teams boarded a tanker in the Gulf of Mexico on August 21

    Security · September 16, 2026 · 1 publisher

  3. Benioff says the war destroyed both of Salesforce's UAE backup data centres

    Product · September 16, 2026 · 1 publisher

  4. Brussels' draft Cybersecurity Act revision would start a 36-month Huawei removal clock at adoption

    Build · September 15, 2026 · 1 publisher

  5. OpenAI, Anthropic and 100+ others urge governments to fund defenses against AI-enabled cyberattacks

    Invest · August 30, 2026 · 8 publishers

  6. OpenAI measures its $1 billion cyber-defender commitment in access it prices itself

    Invest · September 4, 2026 · 3 publishers

  7. CISA marks which KEV vulnerabilities ransomware crews are known to use

    Security · September 12, 2026 · 1 publisher

  8. Stadtwerke Landsberg names eight service lines that stayed up while its office IT was encrypted

    Security · September 10, 2026 · 2 publishers

  9. CISA adds AI deception and adverse separations to the insider threat guide it wrote in 2020

    Security · September 10, 2026 · 1 publisher

  10. One critical-infrastructure incident still triggers reporting duties at several federal agencies

    Security · September 9, 2026 · 1 publisher

  11. Saudi Arabia's HUMAIN attaches a tenancy covenant to every check its $2.5bn fund writes

    Invest · September 3, 2026 · 1 publisher

  12. OpenAI enlists 120 companies behind AI cyber defense for the thinnest security budgets

    Product · August 28, 2026 · 1 publisher

  13. DOJ names China's proxy quartermaster; the seizure took domains, not devices

    Product · August 26, 2026 · 1 publisher

  14. CISA and the FBI put "exceptionally risky" software practices in writing, and buyers get the list

    Security · August 22, 2026 · 1 publisher

  15. FBI counts 30-plus ransomware disruptions this year, and the target is the plumbing

    Security · August 19, 2026 · 1 publisher

  16. Akira advisory update: $244m taken, one SonicWall CVE, three controls to audit now

    Security · August 18, 2026 · 1 publisher

  17. The Air Force Is Buying The Drones It Bans, Because DJI Cannot Be Faked

    Product · August 18, 2026 · 1 publisher

  18. Terra keeps its factories in Ghana and Nigeria, moves its sales desk to London

    Product · August 17, 2026 · 3 publishers