[{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-ae48c73dff970e42","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/","published_at":"2026-09-17T07:20:54+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"BleepingComputer","summary":"Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]","title":"Cisco warns of max severity ISE zero-day exploited in attacks"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-3a9971392581fc1c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-wants-claude-to-analyze-your-bank-account-and-financial-data/","published_at":"2026-09-17T00:35:48+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Anthropic is testing a new personal finance feature called \"Claude Money\" that will allow you to connect your bank accounts directly to Claude and \"understand your money.\" [...]","title":"Anthropic wants Claude to analyze your bank account and financial data"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5023b04135d22d4e","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5124008-update-breaks-domain-trust-for-some-users/","published_at":"2026-09-16T20:39:29+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. [...]","title":"Windows 11 KB5124008 update breaks domain trust for some users"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-44a6aa01277434bc","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/","published_at":"2026-09-16T20:24:55+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...]","title":"Iranian hackers use CHOSEN BRICK Windows malware to spy on targets"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-cce1405bb03123ff","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMivwFBVV95cUxONHpIRFZYVy1YQ1piazJKd2E0MUEzdDI1WTNpeE5rbWpKRS1UWjJIRmhKVUZLdHJDWUR2X3ZNejhQeTJfQW9fN0RhQWwtUVBqQTBka3NVVVpuYndKS25ybmJHUE9pTE9lcDg1emdyZEZvTm1XNmNxTnRlbUlBbzU4bkhjWEs3WDQ1WElObW02bng0UVMtWGprcFRPUERLNUhDR29CZ2FYdWMyTXkwUk4yV005VTAtU3pONDBZUTA2SQ?oc=5","published_at":"2026-09-16T19:08:40+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Rockwell Automation Joins Anthropic\u2019s Project Glasswing to Advance AI Cyber Defense&nbsp;&nbsp;AIM Media House","title":"Rockwell Automation Joins Anthropic\u2019s Project Glasswing to Advance AI Cyber Defense - AIM Media House"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-e7f72db23e0e42e2","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMivwFBVV95cUxONHpIRFZYVy1YQ1piazJKd2E0MUEzdDI1WTNpeE5rbWpKRS1UWjJIRmhKVUZLdHJDWUR2X3ZNejhQeTJfQW9fN0RhQWwtUVBqQTBka3NVVVpuYndKS25ybmJHUE9pTE9lcDg1emdyZEZvTm1XNmNxTnRlbUlBbzU4bkhjWEs3WDQ1WElObW02bng0UVMtWGprcFRPUERLNUhDR29CZ2FYdWMyTXkwUk4yV005VTAtU3pONDBZUTA2SQ?oc=5","published_at":"2026-09-16T19:08:40+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Rockwell Automation Joins Anthropic\u2019s Project Glasswing to Advance AI Cyber Defense&nbsp;&nbsp;aimmediahouse.com","title":"Rockwell Automation Joins Anthropic\u2019s Project Glasswing to Advance AI Cyber Defense - aimmediahouse.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6aa43ef93b8d21cd","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/","published_at":"2026-09-16T18:50:53+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"BleepingComputer","summary":"A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. [...]","title":"Malware bypasses browser checks to force install Chrome, Edge extensions"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-46777957f0db1777","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/spains-data-agency-gets-first-report-of-ai-powered-data-breach/","published_at":"2026-09-16T17:26:41+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]","title":"Spain's data agency gets first report of AI-powered data breach"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-be21dfbf283acfe6","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxOTlBBbFI0WHRpZWNZYWdNT1Nhd0N1MzBURzhVcVJLblNaNHE5RVJfQmhmLXV0aFJtVHZhMDFGSUNoU2hvclBpQUNZSnZjNV8zTmFpQnV1aTVpX1MzTGh0VmIwTDI5MUs5eExLLVFDTXRaV2FMbGFHZGZ3d0x1RnNUMTBLTQ?oc=5","published_at":"2026-09-16T16:34:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"Nintendo Urges Switch Owners to Update Their Firmware After Security Exploit Discovered&nbsp;&nbsp;CNET","title":"Nintendo Urges Switch Owners to Update Their Firmware After Security Exploit Discovered - CNET"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7a1b0a7bd840075c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/the-true-cost-of-a-ransomware-attack-with-and-without-bcdr/","published_at":"2026-09-16T14:00:10+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. [...]","title":"The true cost of a ransomware attack, with and without BCDR"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c693ec1ce133766a","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-workaround-for-missing-outlook-copilot-buttons/","published_at":"2026-09-16T12:16:32+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Microsoft says it's still investigating a known issue that causes the Copilot and Copilot Chat buttons in Classic Outlook to disappear for some Windows users. [...]","title":"Microsoft says Copilot buttons still missing in classic Outlook"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-69a934cc775d40b3","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/webinar-what-happens-in-the-first-hours-of-a-google-workspace-breach/","published_at":"2026-09-16T12:11:19+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse. [...]","title":"Webinar: What happens in the first hours of a Google Workspace breach"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6b34b964203a97b7","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-58704"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-one-known-exploited-vulnerability-catalog","published_at":"2026-09-16T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"CISA Advisories","summary":"CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-58704 Google Pixel Improper Authorization Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Securi...","title":"CISA Adds One Known Exploited Vulnerability to Catalog"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-71fe4bc03f6a8785","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/resources-tools/resources/using-cyber-decoys-strengthen-detection-and-response","published_at":"2026-09-16T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"CISA Advisories","summary":"CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data. Cyber ...","title":"Using Cyber Decoys to Strengthen Detection and Response"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-8a131e6c528b4bb0","category":"Industrial Network & Switches","cve_ids":["CVE-2026-76460","CVE-2026-87886"],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-two-known-exploited-vulnerabilities-catalog","published_at":"2026-09-16T12:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"CISA Advisories","summary":"CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose...","title":"CISA Adds Two Known Exploited Vulnerabilities to Catalog"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6dd028c47e1da026","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-screenconnect-flaw/","published_at":"2026-09-16T11:14:28+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"BleepingComputer","summary":"Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]","title":"Critical ScreenConnect flaw now actively exploited in attacks"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ce590ae97c0763f7","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches-end-of-mainstream-support-next-month/","published_at":"2026-09-16T09:10:20+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Microsoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031. [...]","title":"Windows Server 2022 reaches end of mainstream support next month"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e0cd8acac45bd7fa","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-zero-day-on-pixel-devices/","published_at":"2026-09-16T07:00:19+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"BleepingComputer","summary":"Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. [...]","title":"Google fixes actively exploited Android zero-day on Pixel devices"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-082dcbdf6581bf3a","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMifkFVX3lxTE5TejB4TnFfTEJzcWhUZVBGaEYtNWVpbzNfVVpUbTBYTEsxYjd1V0ZuSXR5ODhZcEI3VUNabmxyVXlQM2QtUnZFVlBBY3hDWElyalVfbWdrd1Nrb08tT0w5ZHBmOFZlcmFLbXNsVkJseU5iSzV4UVplejNfRWIxQQ?oc=5","published_at":"2026-09-16T02:10:47+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Nintendo Switch Wireless Flaw Lets Nearby Attackers Run Code via Photo Sharing and Mario Kart Live Pairing&nbsp;&nbsp;xenospectrum.com","title":"Nintendo Switch Wireless Flaw Lets Nearby Attackers Run Code via Photo Sharing and Mario Kart Live Pairing - xenospectrum.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-7763950d5bcc1aec","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMifkFVX3lxTE5TejB4TnFfTEJzcWhUZVBGaEYtNWVpbzNfVVpUbTBYTEsxYjd1V0ZuSXR5ODhZcEI3VUNabmxyVXlQM2QtUnZFVlBBY3hDWElyalVfbWdrd1Nrb08tT0w5ZHBmOFZlcmFLbXNsVkJseU5iSzV4UVplejNfRWIxQQ?oc=5","published_at":"2026-09-16T02:10:47+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Nintendo Switch Wireless Flaw Lets Nearby Attackers Run Code via Photo Sharing and Mario Kart Live Pairing&nbsp;&nbsp;XenoSpectrum","title":"Nintendo Switch Wireless Flaw Lets Nearby Attackers Run Code via Photo Sharing and Mario Kart Live Pairing - XenoSpectrum"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-dfbcb34ef1dcd30b","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/","published_at":"2026-09-15T21:37:35+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"BleepingComputer","summary":"Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]","title":"Acronis warns of actively exploited flaw in its cPanel backup plugin"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-ecb00808e3781b22","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxOb29kRHZ0MVFRWnpEa0pzd1BpRGRJbURlUHN6RlhrTXVLQWNGdmVvNzZncy05QThzUTVmQ3duQWN2dVZVUE9lRHpxb0UtLWh3OHhxa3dBX005cDlTU3o1RG1GZmdFb0ZvLUJGWTJyTUpQdFRIQ205N0ZPZHRPVjFRbFZJWHZBaUhKQ0VSYVM4Z2t0aFBlV1pXNXNiRVNRZHBkYWR0ZDRkaHJuUQ?oc=5","published_at":"2026-09-15T21:02:41+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"HIGH","source":"Industrial Switch Security","summary":"Exaforce Extends Cybersecurity Reach to Create AI Agent Kill Switch&nbsp;&nbsp;securityboulevard.com","title":"Exaforce Extends Cybersecurity Reach to Create AI Agent Kill Switch - securityboulevard.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-0f2e77f85eb42648","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/","published_at":"2026-09-15T20:34:15+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"BleepingComputer","summary":"Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]","title":"Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-fca5a2a8439cfe08","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxOb29kRHZ0MVFRWnpEa0pzd1BpRGRJbURlUHN6RlhrTXVLQWNGdmVvNzZncy05QThzUTVmQ3duQWN2dVZVUE9lRHpxb0UtLWh3OHhxa3dBX005cDlTU3o1RG1GZmdFb0ZvLUJGWTJyTUpQdFRIQ205N0ZPZHRPVjFRbFZJWHZBaUhKQ0VSYVM4Z2t0aFBlV1pXNXNiRVNRZHBkYWR0ZDRkaHJuUQ?oc=5","published_at":"2026-09-15T20:27:28+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"HIGH","source":"Industrial Switch Security","summary":"Exaforce Extends Cybersecurity Reach to Create AI Agent Kill Switch&nbsp;&nbsp;Security Boulevard","title":"Exaforce Extends Cybersecurity Reach to Create AI Agent Kill Switch - Security Boulevard"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6dcc8809c86141f0","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/centerpoint-energy-confirms-customer-data-stolen-in-cyberattack/","published_at":"2026-09-15T16:40:14+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company. [...]","title":"CenterPoint Energy confirms customer data stolen in cyberattack"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-98f9f40d1c33b5b1","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMijgFBVV95cUxNNUdVWWdQRC1KelJLVnJqdzRBTXhfMEtwZ0ZIeW5IV3JhSnBUcFp1VzlNMmU1MlFtRzVBYlp0QndTQ2VwZVVkckRRYlVscG1ma2tUZUt0OEhuZHRkN3dBVFQyTUdCRVU1ZXhYY1ZaaXhDazlVeEtiSXFCRTVaVklYM1FNNTFQNUJydFZWZW5B?oc=5","published_at":"2026-09-15T15:23:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Industrial Switch Security","summary":"Nintendo patches critical Nintendo Switch vulnerability&nbsp;&nbsp;SC Media","title":"Nintendo patches critical Nintendo Switch vulnerability - SC Media"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-dea233eec3f42cf8","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt/","published_at":"2026-09-15T15:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. [...]","title":"BambooToken malware controls Windows and Linux systems via MQTT"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-4fb622542d877fe7","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/","published_at":"2026-09-15T14:45:10+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"BleepingComputer","summary":"Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]","title":"Hackers target WordPress sites via third-party WooCommerce plugin"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d57db5ef4cf8754f","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/what-zero-day-response-should-be-in-the-post-mythos-era/","published_at":"2026-09-15T13:45:54+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"BleepingComputer","summary":"AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive. [...]","title":"What Zero-Day Response Should Be in the Post-Mythos Era"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-5f038edd538e71a5","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMivgFBVV95cUxQTlcyYU43cmNScklnaGxTNUN1bkR0WWMtM2J0aU52NVY1Wnh6MWRlWVRsRFFEcS1aeF9JTzhDZm5aNlp1dmo5U2xCUGhld3BJajFzWE5YeWtERDBFS1paUnJZbzUyRXpzaDBXX1l1MWQwazUwc0l6UDBoZTAzZGZVRVZ6cmZ3bllUS25pSFZ0ZDVQR19SOTBPZnlfWGY4ZkVha1gxbnQtQVBGVjJfNXg3cjhFZWFCYmJmbmdKenFB?oc=5","published_at":"2026-09-15T13:25:07+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell Automation Joins Anthropic Project Glasswing for Industrial Cyber Defense&nbsp;&nbsp;citybiz","title":"Rockwell Automation Joins Anthropic Project Glasswing for Industrial Cyber Defense - citybiz"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-49b1de666e1da45e","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/","published_at":"2026-09-15T12:16:32+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"BleepingComputer","summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. [...]","title":"CISA: Critical VMware RCE flaw now exploited by ransomware gangs"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f5f0a3c35ff0e4d4","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-84398","CVE-2026-84400","CVE-2026-88259"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-08","published_at":"2026-09-15T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access live video and sensitive device information, enable unauthorized services, execute arbitrary code, modify device operation, and recover stored credentials. The following versions of CareCam CM2507 are affected: HMT.CM2507 Firmware v251211.1507 (CVE-2026-88259, CVE-2026-84398, CVE-2026-84400, CVE...","title":"CareCam CM2507"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1b5c16ea7b098609","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-78225","CVE-2026-81855"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-02","published_at":"2026-09-15T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client. The following versions of W\u00e4rtsil\u00e4 FOS-Onboard are affected: FOS-Onboard 5.07.0923.01 (CVE-2026-78225, CVE-2026-81855) CVSS Vendor Equipment Vulnerabilities v3 9.1 W\u00e4rtsil\u00e4 W\u00e4r...","title":"W\u00e4rtsil\u00e4 FOS-Onboard"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-756a2b0af9b06d0d","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-06","published_at":"2026-09-15T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"CISA Advisories","summary":"View CSAF Summary Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version. The following versions of Siemens Mendix SAML are affected: Mendix SAML (Mendix 10 compatible) vers:intdot/&lt;4.2.3 (CVE-20...","title":"Siemens Mendix SAML"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-fcad4eb8394c72a1","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-07","published_at":"2026-09-15T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"CISA Advisories","summary":"View CSAF Summary A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new...","title":"Siemens Teamcenter"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-8cc9b8b5137f16c7","category":"ICS / SCADA Controls","cve_ids":["CVE-2026-73807","CVE-2026-82567"],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-03","published_at":"2026-09-15T12:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem. The following versions of mySCADA myPRO Manager are affected: mySCADA myPRO Manager &lt;=2.1 (CVE-2026-73807, CVE-2026-82567) CVSS Vendor Equipment Vulnerabilities v3 9.8 mySCADA Technologies mySCADA ...","title":"mySCADA myPRO Manager"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ae0752b8a93e3845","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2024-42384","CVE-2024-42385","CVE-2024-42386","CVE-2024-42391","CVE-2024-42392","CVE-2026-62645"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-05","published_at":"2026-09-15T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"CISA Advisories","summary":"View CSAF Summary Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version. The following versions of Siemens Reyrolle 7SR5 are affected: Reyrolle 7SR5 vers:intdot/&lt;2.70 (CVE-2024-42384, CVE-2024-42385, CVE-2024-42386, CVE-2024-42391, CVE-2024-42392, CVE-2026-62645, CVE-2026...","title":"Siemens Reyrolle 7SR5"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-73f43295114811b3","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-04","published_at":"2026-09-15T12:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"MEDIUM","source":"CISA Advisories","summary":"View CSAF Summary Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below may increase the risk of unauthorized access to RTU configu...","title":"Schneider Electric SCADAPack x70 Products"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-673813485ee94c25","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-68953"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-01","published_at":"2026-09-15T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point. The following versions of Digital Watchdog VMAX DVR and NVR Product Lineups are affected: VMAX A1 G4 DVRs vers:all/* (CVE-2026-68953, CVE-20...","title":"Digital Watchdog VMAX DVR and NVR Product Lineups"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-67c13b3025cfd8be","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/resources-tools/resources/protecting-tokens-and-assertions-forgery-theft-and-misuse-implementation-recommendations-agencies","published_at":"2026-09-15T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"CISA Advisories","summary":"Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with guidelines to protect the identity assertions, access tokens, and cryptographic mechanisms that support modern authentication and authorization. As agencies adopt hybrid and multi-cloud environments, single sign-on, federation, and a...","title":"Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7d93f067f95b0a2f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/black-axe-gang-members-extradited-to-us-face-cybercrime-charges/","published_at":"2026-09-15T09:50:25+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges. [...]","title":"Suspected Black Axe gang leaders face cybercrime charges in the US"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-bb66905c3f772fe2","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-september-kb5002914-security-update-breaks-excel-copy-and-paste/","published_at":"2026-09-15T08:40:20+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Microsoft has confirmed that copy and paste may silently fail for some Excel users after installing the September 2026 KB5002914 security update. [...]","title":"Microsoft confirms KB5002914 Excel update breaks copy and paste"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-73f0fd2632d8db74","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMibEFVX3lxTE5STU5iOEkyWDVRWDJldnE1RFpHeDJtMTVRTXRPbllVNElxRXJ3RkVuVUJHNGZwbnFjUUFyZ3FJSHBKS2gxRmNVSmh6TjVma0xQOXRhZmloRkhpdWx0NUZERGZhNXlsOWozN2JxS9IBckFVX3lxTE5TYjB6Y0NOc2R3cU55NjRDQ0k0QjRJLXFxd0o1MmFBWV9aTDQtSk5mN2oweUs0YlV4SVAtTTZBSDlHck1QNTBVSlVuM0xfVzZXSXlyanEwN1RsX3hEQlVuY3BLRWxfbklvSEJKalpjUXVJQQ?oc=5","published_at":"2026-09-15T07:50:31+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Nintendo Switch QR Code Vulnerability Lets Nearby Attackers Execute Unauthorized Code&nbsp;&nbsp;gbhackers.com","title":"Nintendo Switch QR Code Vulnerability Lets Nearby Attackers Execute Unauthorized Code - gbhackers.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-9d14ab49ddbf4481","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://www.bleepingcomputer.com/news/security/new-cisco-secure-email-zero-day-exploited-to-execute-commands-as-root/","published_at":"2026-09-15T07:31:09+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"BleepingComputer","summary":"Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]","title":"Cisco patches Secure Email Gateway zero-day exploited in attacks"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-390f4b58d23229d4","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiakFVX3lxTE1EQ0FtOThjdWVGQWN3aS1pZnhzTld3bnVPN1RvSDV0NkRJNUQzUkFkQ2pEQ1FEUnpEQW1OQV9sYVBmbUFVenNRUVZuMjl0VE82RTF5QUtCTnY1N1dZa0dSeUVqZTgtSW9TdUHSAW9BVV95cUxQemVzdWpOQWk3QkVGWUR1bjFjTUo5S19nNHBSSGxuMFZ4OURxckpwRy1SQ0lWUGprbTlVRS0yX1Q2eHBlSTV2TXpmYTR1N2Q3ZTBtQVJsb1JjNlhtdkp6VlZvQnhUQTlFSkZ1QVItQ2s?oc=5","published_at":"2026-09-15T07:04:27+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Nintendo Switch Vulnerability: Update Firmware Now&nbsp;&nbsp;thecyberexpress.com","title":"Nintendo Switch Vulnerability: Update Firmware Now - thecyberexpress.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-cf87a0ce9d63873c","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiakFVX3lxTE1EQ0FtOThjdWVGQWN3aS1pZnhzTld3bnVPN1RvSDV0NkRJNUQzUkFkQ2pEQ1FEUnpEQW1OQV9sYVBmbUFVenNRUVZuMjl0VE82RTF5QUtCTnY1N1dZa0dSeUVqZTgtSW9TdUHSAW9BVV95cUxQemVzdWpOQWk3QkVGWUR1bjFjTUo5S19nNHBSSGxuMFZ4OURxckpwRy1SQ0lWUGprbTlVRS0yX1Q2eHBlSTV2TXpmYTR1N2Q3ZTBtQVJsb1JjNlhtdkp6VlZvQnhUQTlFSkZ1QVItQ2s?oc=5","published_at":"2026-09-15T07:04:27+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Nintendo Switch Vulnerability: Update Firmware Now&nbsp;&nbsp;The Cyber Express","title":"Nintendo Switch Vulnerability: Update Firmware Now - The Cyber Express"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-5b0620c45854fd31","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiY0FVX3lxTE1rUXk3NGZTU3dmaXBrMGsza0p4Ni1vQlowZHNiTkIyaEFLV1dyQ0VQUXVldldKY1RPZU5QTFI4dWcyMlItSHdta2loX0FZbnNVVVp0MklJNDJWbFFOVUxsQTdHTdIBY0FVX3lxTE1rUXk3NGZTU3dmaXBrMGsza0p4Ni1vQlowZHNiTkIyaEFLV1dyQ0VQUXVldldKY1RPZU5QTFI4dWcyMlItSHdta2loX0FZbnNVVVp0MklJNDJWbFFOVUxsQTdHTQ?oc=5","published_at":"2026-09-15T07:02:14+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Nintendo Switch Vulnerability Lets Nearby Attackers Run Unauthorized Code via QR Codes&nbsp;&nbsp;cyberpress.org","title":"Nintendo Switch Vulnerability Lets Nearby Attackers Run Unauthorized Code via QR Codes - cyberpress.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b5951014b4133db2","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-emergency-windows-updates-to-fix-rds-failures/","published_at":"2026-09-14T20:52:18+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with Hyper-V and USB audio problems on some Windows versions. [...]","title":"Microsoft releases emergency Windows updates to fix RDS failures"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-f72b778cc8d3f861","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://www.bleepingcomputer.com/news/security/japans-digital-agency-says-vpn-flaw-exposed-246-000-personnel-records/","published_at":"2026-09-14T20:36:02+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"BleepingComputer","summary":"Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. [...]","title":"Japan's Digital Agency says VPN flaw exposed 246,000 personnel records"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-c3afd65199c963f5","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMixAFBVV95cUxNUHNpblROWmxSWkFCWUZQQUVwd281WEtWNjlwTlcyRjlqVElKczFTR3lpVGV1ZFdNbTBFS2NRbGN4QTdQY3Jhdl90RUNtSWZBNl91WXN5YUtwcWstRHhMU1hUdUg4NzdaemQ0a2tMV3RjYnYyLUwxN29DOTdmVEtjZHBMd3pTYzNaNUhlcDZ0QV9ISDJGUWk3WHk2Y243bEpGMGhVX0ZGbU50cGdBdlhRWHVkQll1WnNONjQzYjFwNkdVWlA1?oc=5","published_at":"2026-09-14T20:35:24+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"The Nintendo Switch had a QR code vulnerability that put it at risk from hackers&nbsp;&nbsp;Android Headlines","title":"The Nintendo Switch had a QR code vulnerability that put it at risk from hackers - Android Headlines"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-224139e1cf9cbc1b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/homebrew-700-gets-built-in-gui-better-security-controls/","published_at":"2026-09-14T19:51:04+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"BleepingComputer","summary":"Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. [...]","title":"Homebrew 7.0.0 gets built-in GUI, better security controls"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-089712ca0f270a88","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxOTlBBbFI0WHRpZWNZYWdNT1Nhd0N1MzBURzhVcVJLblNaNHE5RVJfQmhmLXV0aFJtVHZhMDFGSUNoU2hvclBpQUNZSnZjNV8zTmFpQnV1aTVpX1MzTGh0VmIwTDI5MUs5eExLLVFDTXRaV2FMbGFHZGZ3d0x1RnNUMTBLTQ?oc=5","published_at":"2026-09-14T19:14:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"Nintendo Switch Owners Should Update Their Firmware After Security Exploit Discovered&nbsp;&nbsp;CNET","title":"Nintendo Switch Owners Should Update Their Firmware After Security Exploit Discovered - CNET"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6b11b47934fb69ad","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/twitch-extension-with-30k-installs-exposes-users-oauth-tokens/","published_at":"2026-09-14T19:03:51+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users' Twitch OAuth session tokens to a commercial bot service. [...]","title":"Twitch extension with 30K installs exposes users\u2019 OAuth tokens"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-15c5fae497387808","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/","published_at":"2026-09-14T18:34:16+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...]","title":"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-8c18e92c1ecbb0bf","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMidEFVX3lxTE9wUGUwS2FhLUdadUhHSEc1ZEMzTDQ5ZTJFYTAycU16NHQ4ZVhkbmJsMC1IaTItR1VwazhMOXJ5aXRLRW9iLXE3cExPUlMtZk05UkFVRDRGd0JUSk82MmNwbFJPS2FZNlBwcm02WmdqX2Nnb1BT0gF6QVVfeXFMTUFpTkNmdEozWUFLMUxOM0hlNU5sYU9ZLTl4aWhIMEJjLURBdWtCR1ZYR0V0VU1kSmtrNVFPWFVuajhZWlBZdWxOOWI1UTdkQ2VyRW16a2liYU9zR24teXZoZlhnSDgwcDBJS3dSMlk1MFFBZW9SR2ZOZGc?oc=5","published_at":"2026-09-14T17:57:49+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Nintendo Switch Vulnerability Allows Attackers to Run Unauthorized Code on Your Console&nbsp;&nbsp;CyberSecurityNews","title":"Nintendo Switch Vulnerability Allows Attackers to Run Unauthorized Code on Your Console - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-052bff11a36119e9","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-servers-to-steal-aws-azure-secrets/","published_at":"2026-09-14T16:15:58+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments. [...]","title":"Hackers target exposed Vite dev servers to steal AWS, Azure secrets"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4ad18fb0e7246272","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/why-patch-automation-needs-brakes-not-just-an-accelerator/","published_at":"2026-09-14T14:01:11+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"BleepingComputer","summary":"Patch automation can help IT teams keep pace with growing update volumes, but deploying faster also means bad updates can spread faster. Action1 explains how update rings, predefined success criteria, and human oversight can make automated patching faster without sacrificing control. [...]","title":"Why Patch Automation Needs Brakes, Not Just an Accelerator"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-00c9b10b1389b188","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMitgFBVV95cUxNSThnTE9Fckw2dEhpZEhzazE0VnRkNWpXUlRiZ29ma05qTmstZFpiMnVaQzljVFBIYktjTnVoLXRueXFvZ3hmUDZCZFFNYmFWenduZVJ2VXFTSEs3dHpRVWdFb0hlb3dHQkJraTUwMklrYUl3RTgzY3g0bVZhZU94eHlyWTI3bmtpbVZDR1NoQmNUb0FuRk1GNF93NXc0YkxiWnBGaEM4d3J1OURpcmxOd1kyTmJwUQ?oc=5","published_at":"2026-09-14T13:13:21+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"SCADA and Industrial Control Malware: Securing Electrical Substations Against Weaponized Firmware Exploits&nbsp;&nbsp;streamlinefeed.co.ke","title":"SCADA and Industrial Control Malware: Securing Electrical Substations Against Weaponized Firmware Exploits - streamlinefeed.co.ke"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b636a80c8b974a2c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/webinar-how-malicious-oauth-apps-can-lead-to-google-workspace-breaches/","published_at":"2026-09-14T12:15:23+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords. This webinar examines two attacks to show how these breaches unfold and which security controls can help stop them. [...]","title":"Webinar: How malicious OAuth apps can lead to Google Workspace breaches"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-3e56459dceb93d77","category":"Industrial Network & Switches","cve_ids":["CVE-2026-76461"],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://www.cisa.gov/news-events/alerts/2026/09/14/cisa-adds-one-known-exploited-vulnerability-catalog","published_at":"2026-09-14T12:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"CISA Advisories","summary":"CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing S...","title":"CISA Adds One Known Exploited Vulnerability to Catalog"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6bcfd9eb24d8e477","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-september-updates-cause-rds-failures-on-windows-server/","published_at":"2026-09-14T09:50:25+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems. [...]","title":"Microsoft: September updates cause RDS failures on Windows Server"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-e514d0dc1eb8dd16","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://www.bleepingcomputer.com/news/security/revolut-discloses-data-breach-exposing-financial-info-passports/","published_at":"2026-09-14T08:48:24+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"BleepingComputer","summary":"Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency. [...]","title":"Revolut discloses data breach exposing financial info, passports"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-20b2889f40333c0d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-september-updates-break-audio-on-some-windows-pcs/","published_at":"2026-09-14T08:08:16+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Microsoft has confirmed that USB audio devices may fail on some Windows systems after installing the KB5124008and KB5124012 September 2026 security updates. [...]","title":"Microsoft: September updates break audio on some Windows PCs"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-976d1807e38f4330","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-max-severity-gitlab-flaw-in-attacks/","published_at":"2026-09-14T07:06:27+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"BleepingComputer","summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks. [...]","title":"CISA: Hackers now exploit max severity GitLab flaw in attacks"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-6789bdbde9e17f0c","category":"Critical Infrastructure & APT","cve_ids":["CVE-2026-51990"],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://www.bleepingcomputer.com/news/security/hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware/","published_at":"2026-09-13T14:26:32+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"BleepingComputer","summary":"Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]","title":"Hackers exploit Tencent app flaw to deploy GrayRabbit malware"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-d83e833e993ae864","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-85102","CVE-2026-85103"],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent/","published_at":"2026-09-12T14:14:32+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"BleepingComputer","summary":"The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]","title":"Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-ff1063257014bf6b","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/","published_at":"2026-09-11T20:19:09+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"BleepingComputer","summary":"Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...]","title":"Hackers abused Claude to extract secrets from 1.8M Android apps"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-0741edf86b5fc35f","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/","published_at":"2026-09-11T19:00:29+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]","title":"Florida confirms DMV database breached via stolen police account"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-cf24eaec8273ca4c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/","published_at":"2026-09-11T17:26:50+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"BleepingComputer","summary":"Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...]","title":"Passkey-themed phishing attacks lead to Microsoft 365 data theft"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-53007debb751c7dd","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://www.bleepingcomputer.com/news/security/artifactory-flaws-chained-in-attacks-deploying-backdoor-malware/","published_at":"2026-09-11T16:29:44+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"BleepingComputer","summary":"Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]","title":"Artifactory flaws chained in attacks deploying backdoor malware"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-7a8dd47c883fea82","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/","published_at":"2026-09-11T14:01:11+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"BleepingComputer","summary":"Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures. [...]","title":"How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7d1c2e5e15cbe303","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-85706"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog","published_at":"2026-09-11T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"CISA Advisories","summary":"CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD)...","title":"CISA Adds One Known Exploited Vulnerability to Catalog"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c1096d3d36ea8ee9","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-42016","CVE-2026-42018","CVE-2026-84869"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog","published_at":"2026-09-11T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"CISA Advisories","summary":"CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability&nbsp; CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability&nbsp; CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerabi...","title":"CISA Adds Three Known Exploited Vulnerabilities to Catalog"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a1f74eb6baf9bdfe","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-85706"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/","published_at":"2026-09-11T11:15:22+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"BleepingComputer","summary":"GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2023-2825. [...]","title":"GitLab urges users to patch max severity path traversal flaw"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c7091c072834f914","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-teams-outlook-launch-failures-on-arm-windows-pcs/","published_at":"2026-09-11T09:39:37+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"BleepingComputer","summary":"Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. [...]","title":"Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-946a26ec53d41f0c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/","published_at":"2026-09-11T07:55:15+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. [...]","title":"Trezor: 347,000 users targeted in phishing attacks after Brevo breach"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-024c9c73bb544cd9","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/conti-ransomware-gang-member-sentenced-to-four-years-in-prison/","published_at":"2026-09-11T06:48:37+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]","title":"Conti ransomware gang member sentenced to 4 years in prison"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-9e6b809ae9ad2a1c","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxPUzNPc2g0SnJjSFNIVWFDZEZjUVl2SnI4Qzh3Tl8yVGVFSG5RNEpEeEJIZVNmaDRRVU4yMmwwaW1OM2N0UXlkb0JwVmExdDIwXzZhWXlvc0w5QXR6RkFwclYtNVVMTjg0czNRQ3dBR2xsazNicmRKS2VTY19xQy1pRnFGbWdVWFhtb2ROQ3luY2lQS1FzelVReHN1b1djMG40RGVDRnpLTWFpU2dIZ1V0MA?oc=5","published_at":"2026-09-11T01:45:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Nintendo's Latest System Firmware Update Resolves Switch Vulnerability&nbsp;&nbsp;nintendolife.com","title":"Nintendo's Latest System Firmware Update Resolves Switch Vulnerability - nintendolife.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-de31259ca9f86548","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxPUzNPc2g0SnJjSFNIVWFDZEZjUVl2SnI4Qzh3Tl8yVGVFSG5RNEpEeEJIZVNmaDRRVU4yMmwwaW1OM2N0UXlkb0JwVmExdDIwXzZhWXlvc0w5QXR6RkFwclYtNVVMTjg0czNRQ3dBR2xsazNicmRKS2VTY19xQy1pRnFGbWdVWFhtb2ROQ3luY2lQS1FzelVReHN1b1djMG40RGVDRnpLTWFpU2dIZ1V0MA?oc=5","published_at":"2026-09-11T01:45:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Nintendo's Latest System Firmware Update Resolves Switch Vulnerability&nbsp;&nbsp;Nintendo Life","title":"Nintendo's Latest System Firmware Update Resolves Switch Vulnerability - Nintendo Life"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-519313032e36fa80","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/","published_at":"2026-09-10T21:40:43+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. [...]","title":"New Android malware encrypts files, steals data, and harasses victims"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6ae5d660280818d3","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/microsoft/september-windows-server-updates-break-remote-desktop-services/","published_at":"2026-09-10T20:34:37+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality. [...]","title":"September Windows Server updates break Remote Desktop Services"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-42215c4f8902a027","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://www.bleepingcomputer.com/news/security/surfshark-vpn-says-hackers-breached-internal-testing-proxy-servers/","published_at":"2026-09-10T19:15:07+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"BleepingComputer","summary":"Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. [...]","title":"Surfshark VPN says hackers breached internal testing, proxy servers"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-bfb504d65cc26665","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-excel-kb5002914-update-breaks-copy-and-paste-for-some-users/","published_at":"2026-09-10T19:07:33+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Microsoft Excel users report that this week's KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality. [...]","title":"Microsoft Excel KB5002914 update breaks copy and paste for some users"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-e3ae3fa74da05b39","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxQYUVzV3Vic3I4TENXaGJjdVA3RTFoMXdhLWVMdG5oZ09fWXJUek9SVE1YM2FpTkRhbFVEbTNKRFlITHZvNDQ5cmZSbGZHWmFjbEZWaS11eFgwalZSTm9UQ3BCTl9sVUN6b2tmS1RLZW1RRjNjLWhzeVZaQ2txSW1kV2hiUFkyX3gtZ0dPX2toSGNiYnhmNGF5cnk0bXVQTXhKU2ZYbF9FaUZzVjRTa3c?oc=5","published_at":"2026-09-10T17:15:35+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"Moxa EDR-8010 secure router targets industrial network cybersecurity&nbsp;&nbsp;worldoil.com","title":"Moxa EDR-8010 secure router targets industrial network cybersecurity - worldoil.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-6cfc265ce69edcfe","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxQYUVzV3Vic3I4TENXaGJjdVA3RTFoMXdhLWVMdG5oZ09fWXJUek9SVE1YM2FpTkRhbFVEbTNKRFlITHZvNDQ5cmZSbGZHWmFjbEZWaS11eFgwalZSTm9UQ3BCTl9sVUN6b2tmS1RLZW1RRjNjLWhzeVZaQ2txSW1kV2hiUFkyX3gtZ0dPX2toSGNiYnhmNGF5cnk0bXVQTXhKU2ZYbF9FaUZzVjRTa3c?oc=5","published_at":"2026-09-10T17:15:35+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"Moxa EDR-8010 secure router targets industrial network cybersecurity&nbsp;&nbsp;World Oil","title":"Moxa EDR-8010 secure router targets industrial network cybersecurity - World Oil"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-2a12849aa2b5b118","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://www.bleepingcomputer.com/news/security/ai-powered-attack-exploited-papercut-flaws-to-hack-395-organizations/","published_at":"2026-09-10T15:55:56+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"MEDIUM","source":"BleepingComputer","summary":"A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. [...]","title":"AI-powered attack exploited PaperCut flaws to hack 395 organizations"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-705a15bb9516bdc8","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/","published_at":"2026-09-10T15:43:58+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"BleepingComputer","summary":"Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [...]","title":"Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8f69bbd31c40c80a","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/","published_at":"2026-09-10T14:55:33+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans. [...]","title":"IDScan confirms breach tied to 153 million stolen driver\u2019s licenses"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-d1da6f95874f8b0f","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/","published_at":"2026-09-10T14:11:34+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"BleepingComputer","summary":"Multiple cyber-espionage groups deployed an exploit kit dubbed \"BlueMoon\" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...]","title":"New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f5e6e9a246dc45db","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/the-top-4-threats-we-found-by-investigating-every-alert-for-a-quarter/","published_at":"2026-09-10T14:00:10+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked. [...]","title":"The Top 4 Threats We Found by Investigating Every Alert for a Quarter"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9b21ad0b39992b6e","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-78224","CVE-2026-82578","CVE-2026-82583"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01","published_at":"2026-09-10T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition. The following versions of NextGen Healthcare Mirth Connect are affected: Mirth Connect &lt;=v4.7.1 (CVE-2026-82583, CVE-2026-78224, CVE-2026-82578) CVSS Vendor Equipment Vulnerabilities v3 8.3 NextGen Healthcare NextGen Healthcare Mirth Connect Im...","title":"NextGen Healthcare Mirth Connect"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c31fba42ee38c6d9","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-81821","CVE-2026-81822","CVE-2026-81823","CVE-2026-81824"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-253-01","published_at":"2026-09-10T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session. The following versions of AVEVA Pipeline Integrity Monitor are affected: AVEVA Pipeline Integrity Monitor &lt;=2025_SP1_P1_build_7.1.9580.8513 (CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824) CVSS Vend...","title":"AVEVA Pipeline Integrity Monitor"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-00576b9cffe087cd","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-02","published_at":"2026-09-10T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition. The following versions of Orthanc DICOM Server are affected: Orthanc DICOM Server &lt;1.13.0. (CVE-2026-8...","title":"Orthanc DICOM Server"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-aba0811aacb25091","category":"Industrial Network & Switches","cve_ids":["CVE-2026-67277","CVE-2026-86060"],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog","published_at":"2026-09-10T12:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"CISA Advisories","summary":"CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability These types of vulnerabilities are a frequent attack vector for...","title":"CISA Adds Two Known Exploited Vulnerabilities to Catalog"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-bca62ec59f7f6b26","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-38056","CVE-2026-38057","CVE-2026-38058","CVE-2026-38059"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-01","published_at":"2026-09-10T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST Engineering iDirect iQ-Series Terminals (Update A) are affected: Evolution iQ\u2011Series terminals &lt;=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058) 3315\u2011Series te...","title":"ST Engineering iDirect iQ-Series Terminals (Update A)"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-da054c699458ee3f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-resolves-mouse-settings-reset-bug-windows-11-update/","published_at":"2026-09-10T11:14:28+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Microsoft has fixed a known issue that wiped mouse settings on some Windows 11 systems after installing the KB5120998 August 2026 preview update. [...]","title":"Microsoft says September updates fix mouse settings reset issues"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-2dd10eb3b65e0fa1","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/","published_at":"2026-09-10T09:10:20+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"BleepingComputer","summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. [...]","title":"CISA: WatchGuard RCE flaw now exploited in ransomware attacks"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5a6df133c499db2f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bug-that-wiped-windows-desktop-settings/","published_at":"2026-09-10T08:08:16+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"BleepingComputer","summary":"Microsoft says the September 2026 Patch Tuesday updates fix a known issue causing desktop settings to be lost or reset on some Windows devices. [...]","title":"Microsoft fixes bug that wiped Windows desktop settings"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-54ee63ea52f2db3d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/","published_at":"2026-09-10T06:56:33+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"BleepingComputer","summary":"Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. [...]","title":"Trezor warns users of email provider breach, phishing attacks"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-9b517b828f1db970","category":"Industrial Network & Switches","cve_ids":["CVE-2026-20079"],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/","published_at":"2026-09-09T21:40:44+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"BleepingComputer","summary":"Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]","title":"Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-e881d1a390969525","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://www.bleepingcomputer.com/news/security/adapthealth-confirms-41-million-people-exposed-in-july-cyberattack/","published_at":"2026-09-09T21:30:36+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"BleepingComputer","summary":"Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. [...]","title":"AdaptHealth confirms 4.1 million people exposed in July cyberattack"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-22b5bf271b9385df","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/skullcandy-dime-3-earbuds-expose-users-to-bluetooth-hijacking/","published_at":"2026-09-09T21:02:14+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. [...]","title":"Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b7799de8b9963630","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/us-says-chinese-firms-extracted-billions-of-tokens-from-frontier-ai-models/","published_at":"2026-09-09T16:48:33+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. [...]","title":"US says Chinese firms extracted billions of tokens from frontier AI models"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ae1c07b8d073850d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/veradigm-discloses-patient-data-breach-after-gentlemen-gang-claims-attack/","published_at":"2026-09-09T15:31:23+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. [...]","title":"Veradigm warns of patient data breach after ransomware gang claims attack"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ce67362ce109e237","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/mfas-weakest-link-account-recovery-is-the-new-attack-path/","published_at":"2026-09-09T14:01:11+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"BleepingComputer","summary":"MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover. [...]","title":"MFA's Weakest Link: Account Recovery Is the New Attack Path"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7b0d1cacadc22643","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2025-25249","CVE-2026-19490","CVE-2026-87491"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog","published_at":"2026-09-09T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"CISA Advisories","summary":"CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. &nbsp; CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability ...","title":"CISA Adds Four Known Exploited Vulnerabilities to Catalog"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4e050d5fc79605b3","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/over-36-000-plex-servers-unpatched-against-recently-disclosed-flaws/","published_at":"2026-09-09T10:11:29+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"BleepingComputer","summary":"Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. [...]","title":"Over 36,000 exposed Plex servers vulnerable to recent flaws"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-31d4cfbfe432ad9c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/man-gets-15-years-in-prison-for-cyberstalking-and-sextortion/","published_at":"2026-09-09T08:44:22+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content. [...]","title":"Man gets 15 years for extorting women with AI-generated porn videos"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a8fa82c4aafd9622","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldcrash-zero-day-grants-system-access/","published_at":"2026-09-09T07:30:15+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"BleepingComputer","summary":"An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named \"ShieldCrash\" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]","title":"New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e261d8504ae118bd","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/google-patches-seventh-chrome-zero-day-exploited-in-attacks-this-year/","published_at":"2026-09-09T06:25:48+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"BleepingComputer","summary":"Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]","title":"Google warns of new Chrome zero-day bug exploited in attacks"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-fd26c60670691f9b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-adds-age-awareness-apis-that-can-tell-if-users-are-children-teens-or-adults/","published_at":"2026-09-09T01:16:27+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. [...]","title":"Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7089d0ebe77c29e5","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/doppelcart-fraud-network-uses-119-000-fake-shops-to-steal-credit-cards/","published_at":"2026-09-08T20:35:14+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"A massive operation dubbed \"DoppelCart\" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. [...]","title":"DoppelCart fraud network uses 119,000 fake shops to steal credit cards"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d584f2973d13a64d","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/the-eu-cras-real-question-what-shipped-and-when-did-you-know/","published_at":"2026-09-08T20:24:16+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"BleepingComputer","summary":"The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements. [...]","title":"The EU CRA's Real Question: What Shipped, and When Did You Know?"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-cded29844342d933","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/hackers-breach-f5-big-ip-apm-devices-to-deploy-linux-rootkit/","published_at":"2026-09-08T20:08:55+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"BleepingComputer","summary":"A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...]","title":"Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8741b4286e46765b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5122878-extended-security-update/","published_at":"2026-09-08T18:49:19+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"BleepingComputer","summary":"Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes. [...]","title":"Microsoft releases Windows 10 KB5122878 extended security update"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-60f3102bbb6217ec","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-days/","published_at":"2026-09-08T18:18:05+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"BleepingComputer","summary":"Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. [...]","title":"Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b5751f5a2baf1d9a","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/microsoft/windows-11-cumulative-updates-kb5124008-and-kb5122880-released/","published_at":"2026-09-08T17:57:03+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]","title":"Windows 11 cumulative updates KB5124008 & KB5122880 released"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7bbf3a38d688a2d3","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/","published_at":"2026-09-08T16:35:47+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as \"DAVID\" and stole over 200,000 records about drivers in the state. [...]","title":"ShinyHunters hackers claim breach of Florida \"DAVID\" DMV database"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-cbf71429d5cc4b42","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/technology/openai-says-chatgpt-outage-causes-image-generation-errors/","published_at":"2026-09-08T16:28:42+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"OpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files. [...]","title":"OpenAI says ChatGPT outage causes image generation errors"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5bc2d4415146571c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/microsoft/august-updates-trigger-0xc0000409-errors-on-windows-server-2016/","published_at":"2026-09-08T15:22:33+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled. [...]","title":"August updates trigger 0xc0000409 errors on Windows Server 2016"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-3f4f445f882ef00c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/sap-warns-of-maximum-severity-overpass-kernel-vulnerability/","published_at":"2026-09-08T14:55:20+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"BleepingComputer","summary":"SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. [...]","title":"SAP warns of maximum severity 'OVERPASS' kernel vulnerability"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1d9eb016bb6b3352","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/artificial-intelligence/openai-says-gpt-6-astra-can-find-zero-days-but-is-also-harder-to-monitor/","published_at":"2026-09-08T14:40:32+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"BleepingComputer","summary":"OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the \"Critical level\" for cybersecurity capabilities. [...]","title":"OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d8ec13404391b855","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-75650"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-magento-zero-day-exploited-to-backdoor-servers/","published_at":"2026-09-08T13:34:47+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"BleepingComputer","summary":"Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]","title":"Adobe fixes critical Magento zero-day exploited to backdoor servers"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-322bb14bdd431c3f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/webinar-the-forgotten-google-workspace-access-that-can-lead-to-a-breach/","published_at":"2026-09-08T12:40:48+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Third-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposure. [...]","title":"Webinar: The forgotten Google Workspace access that can lead to a breach"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-0380aff400cd795e","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-for-widescale-credential-theft/","published_at":"2026-09-08T12:03:03+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"BleepingComputer","summary":"Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. [...]","title":"Hackers build AI frameworks for widescale credential theft"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-aa5049581572aedb","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-85083"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-251-01","published_at":"2026-09-08T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take full control of the device. The following versions of CareCam Pro IP Cameras are affected: ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 (CVE-2026-85083) CVSS Vendor Equipment Vulnerabilities v3 6.8 CareCam CareCam Pro IP Cameras Use of H...","title":"CareCam Pro IP Cameras"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-773b754f5aa5df7b","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-75650","CVE-2026-81963","CVE-2026-85880"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog","published_at":"2026-09-08T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"CISA Advisories","summary":"CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. &nbsp; CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability &nbsp; CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow...","title":"CISA Adds Four Known Exploited Vulnerabilities to Catalog"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-99145c2d7ce8bc08","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a","published_at":"2026-09-08T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"CISA Advisories","summary":"Executive summary China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies\u2019 models through industrial-scale knowledge distillation campaigns that form the core\u2014not merely a supplement\u2014of their AI development strategy. While \u201cdistillation\u201d is recognized as a legitimate and useful technique in AI r...","title":"China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2c75d5af66256825","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-server-2025-changes-may-cause-app-crashes/","published_at":"2026-09-08T11:57:51+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Microsoft warned customers last week that they may experience application crashes on some Windows Server 2025 due to recent memory management changes. [...]","title":"Microsoft: Windows Server 2025 changes causing app crashes"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6f7d94d64ab2ce28","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/","published_at":"2026-09-08T07:35:50+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Exclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026. Researchers accessed the Vietnam-linked system through a cloud-based path using default credentials. [...]","title":"220 million traveler records exposed in Vietnam-linked APIS leak"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5e1886cc2f63c4ea","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/magento-stylesmuggler-zero-day-exploited-to-deploy-linux-backdoor/","published_at":"2026-09-07T16:50:29+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"BleepingComputer","summary":"A zero-day vulnerability dubbed \"StyleSmuggler\" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. [...]","title":"Magento StyleSmuggler zero-day exploited to deploy Linux backdoor"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e9fd8e27f1aab104","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/","published_at":"2026-09-07T15:39:51+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]","title":"BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-62c12e63b436b327","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/","published_at":"2026-09-07T13:05:11+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. [...]","title":"Mathspace discloses data breach affecting over 1 million people"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1a65ee32103cdf6b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/","published_at":"2026-09-07T12:16:32+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. [...]","title":"Trezor data breach impact now reaches 81,000 customers"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-3958cb7869ff0f9c","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiSkFVX3lxTE91Y2tWUWRJV0U5aXl2SGZKNHhfMVlMdzZLQzJPeHozbl90NG5MVUhwOTFYSmZUVWRPVXBtaERLUUFHaTJRa2p3amFn?oc=5","published_at":"2026-09-07T11:31:04+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"PLC lab inaugurated, industrial automation training course launched at UIU&nbsp;&nbsp;observerbd.com","title":"PLC lab inaugurated, industrial automation training course launched at UIU - observerbd.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-1843dd8816b0f3a8","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiSkFVX3lxTE91Y2tWUWRJV0U5aXl2SGZKNHhfMVlMdzZLQzJPeHozbl90NG5MVUhwOTFYSmZUVWRPVXBtaERLUUFHaTJRa2p3amFn?oc=5","published_at":"2026-09-07T11:31:04+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"PLC lab inaugurated, industrial automation training course launched at UIU&nbsp;&nbsp;Daily Observer","title":"PLC lab inaugurated, industrial automation training course launched at UIU - Daily Observer"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ff11dbbda9efb93e","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/artificial-intelligence/chatgpt-can-now-connect-to-your-personal-apps-to-mimic-writing-style/","published_at":"2026-09-07T10:36:37+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"OpenAI appears to be testing a new \"Writing Style\" feature for ChatGPT that can learn how you write by looking at examples from your connected apps. [...]","title":"ChatGPT can now connect to your personal apps to mimic writing style"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-0172f697599d4204","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://www.bleepingcomputer.com/news/security/hackers-exploit-new-mikrotik-routeros-flaws-to-hijack-routers/","published_at":"2026-09-07T10:32:40+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"BleepingComputer","summary":"Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet. [...]","title":"Hackers exploit new MikroTik RouterOS flaws to hijack routers"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9e79edcaaeb39070","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/connectwise-warns-of-new-screenconnect-flaw-without-patch/","published_at":"2026-09-07T10:06:38+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"BleepingComputer","summary":"ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week. [...]","title":"ConnectWise warns of new ScreenConnect flaw without patch"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-451b961e97b0fd48","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxOTU9sVG80aHlnZWh0SnlRazFkRW1RLS03SzQybndnZEQ5WXVSYVlPR3Y5VDlBdXNUd2dtUmRpYlBIVVpKblF4NmJ5U05JUFp0ZFY0YVo1Q0tzU3hxNFpxVVF3b0NUUkJwNkYzdWxzejlFS2VPMHE2SzNHaWdqS3NGQ1ZXR3I?oc=5","published_at":"2026-09-07T07:15:16+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"OT Security, a Practical Guide to Protecting an Industrial Plant&nbsp;&nbsp;Pasquale Pillitteri","title":"OT Security, a Practical Guide to Protecting an Industrial Plant - Pasquale Pillitteri"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-94c1b1b47416c4c0","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/security/n-able-patches-max-severity-n-central-flaw-amid-ongoing-attacks/","published_at":"2026-09-07T06:17:41+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"BleepingComputer","summary":"N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. [...]","title":"N-able patches max severity N-central flaw amid ongoing attacks"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-de50e4484f4acadc","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.bleepingcomputer.com/news/artificial-intelligence/chatgpt-astra-is-now-rolling-out-to-20-plus-subscription/","published_at":"2026-09-07T01:15:43+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"BleepingComputer","summary":"OpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there's no word on when free users will get access.. [...]","title":"ChatGPT Astra is now rolling out to $20 Plus subscription"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-70b40a6abb4232aa","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikAFBVV95cUxNVTZqdWhzeWw4OEVWbkM1Y2pKN0JIbmtsYTVCUDAtSjZiSjlhLS0zM2tCajE1OFBPZG1fcjhqc1l3czdSQUVMMG83VDgyWXBiZElqSFA0aFlmNEVrU0F0RlBzZmRCX21IWjhjZTUyLTJLV3I2Z01DS05mR2RVb1VCT0Z3T2F5WUZhTWZDZTl0b0Y?oc=5","published_at":"2026-09-04T16:02:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Climate change vulnerability tackled at confab&nbsp;&nbsp;Newswav","title":"Climate change vulnerability tackled at confab - Newswav"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1a57e6beed328cd1","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMivgFBVV95cUxNLXRHVmdvQlhrdjB4MU90Y19VQW45ZGZNdG51bjhnRGxmN21Dc1p5MERnSEFqN01aX3VPMHB3Q3liejBZR0NsUkh0bGRzZDBlS19mU3ZOTDVDcEFUc0pxb3hCd1ViRENUb1NJSGp2RGFFdEIzMzZVUHlEcmxWalVQVTlsYU1uNHI1Y1M4RGdpZ2RCTWVKckZ1N2lTNU5qTDZndFRGVUZNNWZWTS1JWkkwRmYyR2NfdG92SnlVSEZ30gHDAUFVX3lxTE5zM3hCSTJQa1gwNVNmV1VhR1gzaW96SHMwQjZsbEd6TE9PbGQtUDlzaDhTNG95aVdBN2hMVWVZZlQ4N1MxRnZ3U1diekZqN1dUbktvR1V4aEN3QmRtaHdVZURMemoxMDFZYVhpSzU5WTl2R0VwTjI4UWoyN0l6ck5jZGZ4NmRNOGF0dms4OTBIZlhEZUNWWUQ0MXgySVkxUzRrdUdZdGdpZ1llSU5HUXBfckdCa3ZGWmxUUFhKQjZCSUxVbw?oc=5","published_at":"2026-09-04T16:02:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Climate change vulnerability tackled at confab&nbsp;&nbsp;manilatimes.net","title":"Climate change vulnerability tackled at confab - manilatimes.net"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2b58c2a7da93496f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMivgFBVV95cUxNLXRHVmdvQlhrdjB4MU90Y19VQW45ZGZNdG51bjhnRGxmN21Dc1p5MERnSEFqN01aX3VPMHB3Q3liejBZR0NsUkh0bGRzZDBlS19mU3ZOTDVDcEFUc0pxb3hCd1ViRENUb1NJSGp2RGFFdEIzMzZVUHlEcmxWalVQVTlsYU1uNHI1Y1M4RGdpZ2RCTWVKckZ1N2lTNU5qTDZndFRGVUZNNWZWTS1JWkkwRmYyR2NfdG92SnlVSEZ30gHDAUFVX3lxTE5zM3hCSTJQa1gwNVNmV1VhR1gzaW96SHMwQjZsbEd6TE9PbGQtUDlzaDhTNG95aVdBN2hMVWVZZlQ4N1MxRnZ3U1diekZqN1dUbktvR1V4aEN3QmRtaHdVZURMemoxMDFZYVhpSzU5WTl2R0VwTjI4UWoyN0l6ck5jZGZ4NmRNOGF0dms4OTBIZlhEZUNWWUQ0MXgySVkxUzRrdUdZdGdpZ1llSU5HUXBfckdCa3ZGWmxUUFhKQjZCSUxVbw?oc=5","published_at":"2026-09-04T16:02:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Climate change vulnerability tackled at confab&nbsp;&nbsp;The Manila Times","title":"Climate change vulnerability tackled at confab - The Manila Times"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4e7e5021f4e0c4be","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-85046"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/alerts/2026/09/04/cisa-adds-one-known-exploited-vulnerability-catalog","published_at":"2026-09-04T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"CISA Advisories","summary":"CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. &nbsp; CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing S...","title":"CISA Adds One Known Exploited Vulnerability to Catalog"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-e2e42a7cc3c4de56","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMizgFBVV95cUxQWng3RjhWLWI4dDBzal9hNzhzV1drVU5sSFZpdWU3QjdQeDl2cl9BazgxN3JNbGNYc3QzWENrOHVUbFVHQ2MyUldTeXNWSktBTGkxaFhaTmU0WnNDckdmc3BpTlNGOGFkb2NDdXcyM0JWNFg3cU5MaUNZNHplOGhDQlVISnNNWmRhRmpDUjRVSklIeE1IOVQ4MEVEVmI2RzRzRzEzSHotMEpkVnlLM1dKLURhNnVETnA5T3A2Q2htN0d5V19QZUVtOGNzcXdMUQ?oc=5","published_at":"2026-09-04T11:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"FBI and DOJ Seize PRC-Linked QTFY Hacking Platform Used to Target Critical Infrastructure&nbsp;&nbsp;CPO Magazine","title":"FBI and DOJ Seize PRC-Linked QTFY Hacking Platform Used to Target Critical Infrastructure - CPO Magazine"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-88a5ef2ef4ff2bec","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMizgFBVV95cUxQWng3RjhWLWI4dDBzal9hNzhzV1drVU5sSFZpdWU3QjdQeDl2cl9BazgxN3JNbGNYc3QzWENrOHVUbFVHQ2MyUldTeXNWSktBTGkxaFhaTmU0WnNDckdmc3BpTlNGOGFkb2NDdXcyM0JWNFg3cU5MaUNZNHplOGhDQlVISnNNWmRhRmpDUjRVSklIeE1IOVQ4MEVEVmI2RzRzRzEzSHotMEpkVnlLM1dKLURhNnVETnA5T3A2Q2htN0d5V19QZUVtOGNzcXdMUQ?oc=5","published_at":"2026-09-04T11:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"FBI and DOJ Seize PRC-Linked QTFY Hacking Platform Used to Target Critical Infrastructure&nbsp;&nbsp;cpomagazine.com","title":"FBI and DOJ Seize PRC-Linked QTFY Hacking Platform Used to Target Critical Infrastructure - cpomagazine.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f9fec17a1493c9f5","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi6gFBVV95cUxPdlZidUhhN3B6TFZObHg5ZmxCWFpHVHpQWFRDUnctTF9oeFVtT0dUYnpNNE0zLTMtMVRTOWdFRmM5cjNWUFQwTGZ4bVNHNFNicG5tbk9meUpVdjBYM29UUVduLUo5MmVNQnBfalpBbXpBTExqeHR0bDVqLThpNWlQaXQ5RjFVd2FSMGE5Wi1ucmpJaFBHSm5LQ2JFbkg0TkMzdW50ZEdncmg1Sl9SOXdBdGNqTHBVR2dra1A1Y0ZkTHlrYnZ4SWxHR3dibVBOTEJLWUpXYzhDNDkwZmEzQWM3VS1kX25LNlVLd3c?oc=5","published_at":"2026-09-03T20:42:43+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"The Smart City Security Imperative: Lessons from New York's IoT Cyber Defense Program&nbsp;&nbsp;securityinfowatch.com","title":"The Smart City Security Imperative: Lessons from New York's IoT Cyber Defense Program - securityinfowatch.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-15e057c98aa00a78","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi6gFBVV95cUxPdlZidUhhN3B6TFZObHg5ZmxCWFpHVHpQWFRDUnctTF9oeFVtT0dUYnpNNE0zLTMtMVRTOWdFRmM5cjNWUFQwTGZ4bVNHNFNicG5tbk9meUpVdjBYM29UUVduLUo5MmVNQnBfalpBbXpBTExqeHR0bDVqLThpNWlQaXQ5RjFVd2FSMGE5Wi1ucmpJaFBHSm5LQ2JFbkg0TkMzdW50ZEdncmg1Sl9SOXdBdGNqTHBVR2dra1A1Y0ZkTHlrYnZ4SWxHR3dibVBOTEJLWUpXYzhDNDkwZmEzQWM3VS1kX25LNlVLd3c?oc=5","published_at":"2026-09-03T20:42:43+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"The Smart City Security Imperative: Lessons from New York's IoT Cyber Defense Program&nbsp;&nbsp;Security Info Watch","title":"The Smart City Security Imperative: Lessons from New York's IoT Cyber Defense Program - Security Info Watch"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-384e5ee124315b77","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMif0FVX3lxTFBjampyc08ySm80c0JwZnJpdF85S2NkLTk2MkdER3RFRGZ5M2xGZjhwUW5ZX1FPcV9FWjRnenFCdFZWMmxQazJxRnBRMjVqempHaGR5VktCMzEydDJ5T3pxamk3dGVEQlRydjNwUE0zMWZTb1l3TnN6STV1LXZadWc?oc=5","published_at":"2026-09-03T15:52:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Industrial Switch Security","summary":"Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root&nbsp;&nbsp;The Hacker News","title":"Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-62ed7a867548b5b1","category":"ICS / SCADA Controls","cve_ids":["CVE-2026-77393"],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-06","published_at":"2026-09-03T12:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"CRITICAL","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following versions of Inductive Automation Ignition are affected: Ignition &lt;=8.1.53 (CVE-2026-77393) CVSS Vendor Equipment Vulnerabilities v3 8.8 Inductive Automation Inductive Automation Ignition Incorrect Default Permissions Background Critical Infrastructure Sectors: ...","title":"Inductive Automation Ignition"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-e2ac314600279666","category":"PLC & Controller Firmware","cve_ids":["CVE-2026-19471","CVE-2026-19472"],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-04","published_at":"2026-09-03T12:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page. The following versions of Rockwell Automation ArmorStart LT are affected: ArmorStart LT &lt;=v2.001 (CVE-2026-19471, CVE-2026-19472) CVSS Vendor Equipment Vulnerabilit...","title":"Rockwell Automation ArmorStart LT"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-817b7f63852f2070","category":"PLC & Controller Firmware","cve_ids":["CVE-2025-10478"],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-05","published_at":"2026-09-03T12:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-ENBT Module Improper Check for Unusual or Exceptional C...","title":"Rockwell Automation 1756-ENBT Module"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-8ea59622fe837cf5","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-07","published_at":"2026-09-03T12:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"CISA Advisories","summary":"View CSAF Summary Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunction protection and control relays designed for medium, high and extra high voltage electrical ne...","title":"Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-81e4b443cab6a023","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-55985","CVE-2026-61884"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01","published_at":"2026-09-03T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected: TPDIN-Monitor-WEB2 &lt;2.4.5 (CVE-2026-61884, CVE-2026-55985) CVSS V...","title":"Tycon Systems TPDIN-Monitor-WEB2 (Update A)"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-abf6597e63e03d4d","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action","published_at":"2026-09-03T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"CISA Advisories","summary":"CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and critical assets from emerging quantum computing threats. &nbsp; The G7 Cyber Security Working Gro...","title":"Preparing for the Post-Quantum Era: A Call to Action"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-53c5ebe863f8586e","category":"PLC & Controller Firmware","cve_ids":["CVE-2026-12663"],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-03","published_at":"2026-09-03T12:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. The following versions of Rockwell Automation ControlFLASH are affected: ControlFLASH &lt;=V15.07 (CVE-2026-12663) CVSS Vendor Equipment Vulnerabilities v3 7.3 Rockwell Automation Roc...","title":"Rockwell Automation ControlFLASH"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e117dc1ce702e04c","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-77847","CVE-2026-82684","CVE-2026-82712"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08","published_at":"2026-09-03T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected: TPDIN-Monitor-WEB3 &lt;=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684) CVSS Vendor Equipment Vulner...","title":"Tycon Systems TPDIN-Monitor-WEB3"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-d27fadfe39870352","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-75925"],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-02","published_at":"2026-09-03T12:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"HIGH","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges. The following versions of IXON VPN Client are affected: VPN Client &lt;1.4.7 (CVE-2026-75925) CVSS Vendor Equipment Vulnerabilities v3 9.6 IXON IXON VPN Client Improper Neutralization of CRLF Sequences ('CRLF Inject...","title":"IXON VPN Client"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-ab3ea90ff93beb1b","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-07","published_at":"2026-09-03T12:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected: EtherNet/IP Adapter DLL Kit (EIPA) EtherNet/IP Adapter DL...","title":"Pyramid Solutions NetStaX EtherNet/IP Stack"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-750034a3da50d475","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-77477"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-01","published_at":"2026-09-03T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected: UA-LDS-Installers &lt;1.04.420 (CVE-2026-77477) CVSS Vendor Equipment Vulnerabilities v3 4.6 OPCFoundation OPCFoundation OPC UA ...","title":"OPCFoundation OPC UA LocalDiscoveryServer (LDS)"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-8b5b0896a7494b60","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMivwFBVV95cUxNdkZuV3VtYmR5NDdMeTVnNnVJZU9Sc0w4aUxOaU5ZZXQ4UnVpYVFMSEstd2tLUlZUeFkzdGtfT2JLbmhSdFBwT2lLVldWOHFQUjFjb1BEN1VZekdkbEtuT1lqb3dlWEpsVVk5U09taWZ6VHRzb19qcFI5eWhPMXh3endmbEFXRFZqNk1XeTJMUVhCN1lzOGVsVkMwSDZVWWhBSlBQRXZ6WjVKU3BLbTRKWGFOUUstRy1FV3RyMk9WONIBxAFBVV95cUxOLVpyaGE3YzdBdC1vWGFHcm9sY0hEZzR4a2gza2QxMkluYTlfNm8xMk5reE52UHRzR1ZCQkV3OTFzdXdRZGkyQjUwSlQwejBzRllYelRYbW4zRjF0SGlLaXIzRHVOcEhUT1R6VHdPdEV3N2I0T2ZYSUE3R2wzb0hPdV9jaF8zX09aZ3JUMlFPQ3h6RW4xOV9jSXBvSk82aGdDSUZwWXlXSENrbFlxMWlxMWF3c1FtS21NbWdYT1NpWGhlckww?oc=5","published_at":"2026-09-03T07:33:24+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"VPN Is the Biggest Backdoor Into Your Plant \u2014 Here's What Should Replace It on Your OT Network&nbsp;&nbsp;cybersecuritynews.com","title":"VPN Is the Biggest Backdoor Into Your Plant \u2014 Here's What Should Replace It on Your OT Network - cybersecuritynews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-0b7923bffc864250","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMivwFBVV95cUxNdkZuV3VtYmR5NDdMeTVnNnVJZU9Sc0w4aUxOaU5ZZXQ4UnVpYVFMSEstd2tLUlZUeFkzdGtfT2JLbmhSdFBwT2lLVldWOHFQUjFjb1BEN1VZekdkbEtuT1lqb3dlWEpsVVk5U09taWZ6VHRzb19qcFI5eWhPMXh3endmbEFXRFZqNk1XeTJMUVhCN1lzOGVsVkMwSDZVWWhBSlBQRXZ6WjVKU3BLbTRKWGFOUUstRy1FV3RyMk9WONIBxAFBVV95cUxOLVpyaGE3YzdBdC1vWGFHcm9sY0hEZzR4a2gza2QxMkluYTlfNm8xMk5reE52UHRzR1ZCQkV3OTFzdXdRZGkyQjUwSlQwejBzRllYelRYbW4zRjF0SGlLaXIzRHVOcEhUT1R6VHdPdEV3N2I0T2ZYSUE3R2wzb0hPdV9jaF8zX09aZ3JUMlFPQ3h6RW4xOV9jSXBvSk82aGdDSUZwWXlXSENrbFlxMWlxMWF3c1FtS21NbWdYT1NpWGhlckww?oc=5","published_at":"2026-09-03T07:33:24+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"VPN Is the Biggest Backdoor Into Your Plant \u2014 Here's What Should Replace It on Your OT Network&nbsp;&nbsp;CyberSecurityNews","title":"VPN Is the Biggest Backdoor Into Your Plant \u2014 Here's What Should Replace It on Your OT Network - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-44f18b45ce4ad046","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxOdDJkeHljMzAySC1oOC1POU43Y0xxUFdWWmdoUWxUX21ZV2tZeGJLVmVnVkhvR09kbmtBWUdEUTRzM1NiRFJ1Q19CUUFqNDJYRWtUa3M5VjBZa0RDNXo1X3h4d2RnLUtheUkyb0VMTmxXdUZ5XzR3WmdxRmZtWDhQYl9WZDdjS3ZubG00b2FLdm5ybC1wX0RwREtwMlBpcEhyOWRvU9IBqgFBVV95cUxNN3hMTk94X19tZnoyNHQ3d1FqWEJRVVpubGlGa3l3bDZHVWRhaXlaZlZkbTNqS3QwZkNSTWNRaGZCelVlYkN0UzlIRzBRcFhBSmpuZDc5b1lrV2dRMWhrT0Q4amx5WUFSQ1BWX2xhdU0yNWVVZ3dMNk5BWE5kdTVkb25nZWYzRXYzRk5BSWhmNUNXVHNPSGsxaEp1dnJnazB6WkY0TXYxd2Nzdw?oc=5","published_at":"2026-09-02T12:39:07+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products&nbsp;&nbsp;securityweek.com","title":"Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-7061eb2da017ac58","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxOdDJkeHljMzAySC1oOC1POU43Y0xxUFdWWmdoUWxUX21ZV2tZeGJLVmVnVkhvR09kbmtBWUdEUTRzM1NiRFJ1Q19CUUFqNDJYRWtUa3M5VjBZa0RDNXo1X3h4d2RnLUtheUkyb0VMTmxXdUZ5XzR3WmdxRmZtWDhQYl9WZDdjS3ZubG00b2FLdm5ybC1wX0RwREtwMlBpcEhyOWRvU9IBqgFBVV95cUxNN3hMTk94X19tZnoyNHQ3d1FqWEJRVVpubGlGa3l3bDZHVWRhaXlaZlZkbTNqS3QwZkNSTWNRaGZCelVlYkN0UzlIRzBRcFhBSmpuZDc5b1lrV2dRMWhrT0Q4amx5WUFSQ1BWX2xhdU0yNWVVZ3dMNk5BWE5kdTVkb25nZWYzRXYzRk5BSWhmNUNXVHNPSGsxaEp1dnJnazB6WkY0TXYxd2Nzdw?oc=5","published_at":"2026-09-02T12:39:07+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products&nbsp;&nbsp;SecurityWeek","title":"Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-25bc8445935b61ba","category":"Industrial Network & Switches","cve_ids":["CVE-2026-48710","CVE-2026-49869","CVE-2026-59822","CVE-2026-9586"],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog","published_at":"2026-09-02T12:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"CISA Advisories","summary":"CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. &nbsp; CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability&nbsp; CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability&nbsp; CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability&nbsp; CVE-2026-59822 BerriAI LiteLLM Impro...","title":"CISA Adds Seven Known Exploited Vulnerabilities to Catalog"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-c717a2c774756fa9","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://www.cisa.gov/resources-tools/resources/communicating-under-pressure-best-practices-service-providers","published_at":"2026-09-02T12:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"CISA Advisories","summary":"Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and s...","title":"Communicating Under Pressure: Best Practices for Service Providers"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-0e4f7e7872aca0a7","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMizwFBVV95cUxPSllvT25DUHdTcjVfbF95ajl3dFJvdWVPNWw1UkhGVzBvbHZCOHhoaDRpeG1qa3VKdlJZUWpfV0xNc0ZjanlVaUxpS0gwUHhSRTY1VVIzb2NUZUFaWXZvcVIyRXlQOFdqZzZBSnBULS1SYVJVYVlESWNwWmVGZV8taEJJRi03YUJMVjJOUlRqTjdwbUVqMFk0N0pVTDBMMmQ3YlZmSzRQZFprZEZRbUlzbXVMNmVGamw1aXZKeWZoZWRIUDIzUlowOWk5TjBuWEE?oc=5","published_at":"2026-09-02T09:05:05+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"Switch Solutions champions cybersecurity, data protection at GITEX Nigeria 2026&nbsp;&nbsp;nigeriacommunicationsweek.com.ng","title":"Switch Solutions champions cybersecurity, data protection at GITEX Nigeria 2026 - nigeriacommunicationsweek.com.ng"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-49c86ed5cd08db9d","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMizwFBVV95cUxPSllvT25DUHdTcjVfbF95ajl3dFJvdWVPNWw1UkhGVzBvbHZCOHhoaDRpeG1qa3VKdlJZUWpfV0xNc0ZjanlVaUxpS0gwUHhSRTY1VVIzb2NUZUFaWXZvcVIyRXlQOFdqZzZBSnBULS1SYVJVYVlESWNwWmVGZV8taEJJRi03YUJMVjJOUlRqTjdwbUVqMFk0N0pVTDBMMmQ3YlZmSzRQZFprZEZRbUlzbXVMNmVGamw1aXZKeWZoZWRIUDIzUlowOWk5TjBuWEE?oc=5","published_at":"2026-09-02T09:05:05+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"Switch Solutions champions cybersecurity, data protection at GITEX Nigeria 2026&nbsp;&nbsp;Nigeria Communications Week","title":"Switch Solutions champions cybersecurity, data protection at GITEX Nigeria 2026 - Nigeria Communications Week"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-289430ec58f33996","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiowFBVV95cUxQY2JoZDFrT2JldTVrY1Z1b1pWRDZuTmg5eVg1R3dNY2lnSEVuVlphLXU3UlJDMHM2c1lsOFJWR2w0d3dwbEdGQ0Rhak9DLVR2SnpQbDJhekhJWU5LdmQtMW4zSXZuVVFTRk5DVWYwQkVlWGFNM1FuWUpqUUlNYWN4SjUzYUNaYmNsaGpSNUVPLXZFRVJ6TWNIdWZFSlpaZUVPdFVv?oc=5","published_at":"2026-09-02T09:00:15+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"Switch Solutions Takes Cybersecurity, Sovereign AI Agenda to GITEX NIGERIA 2026&nbsp;&nbsp;Techeconomy","title":"Switch Solutions Takes Cybersecurity, Sovereign AI Agenda to GITEX NIGERIA 2026 - Techeconomy"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-c3b5a6300856af93","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiogFBVV95cUxPOFFrSGpVX3VPdWZXbFJjSFRFckVwOXNnaUVYbTJKem9zQ0RRU1dqN1kxamlRLWs3LUFPY3ZjRFJwdzdJUXlSYjZ3NzJKbkFnSGxwNHhCc29ncTFsa3lTMVR2bmtxcklwTkFHN2ZDeHkzMWhnZU1VVl9maDdsa1I2UllTYWIzbllvUzFxUHRibXA4UHNOMU9KeE45czhBMUVfN1E?oc=5","published_at":"2026-09-02T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Industrial Switch Security","summary":"Cybersecurity critical to Nigeria\u2019s $1trn digital economy ambition \u2014 Switch Solutions&nbsp;&nbsp;thesun.ng","title":"Cybersecurity critical to Nigeria\u2019s $1trn digital economy ambition \u2014 Switch Solutions - thesun.ng"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-5168ba34fa078422","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiogFBVV95cUxPOFFrSGpVX3VPdWZXbFJjSFRFckVwOXNnaUVYbTJKem9zQ0RRU1dqN1kxamlRLWs3LUFPY3ZjRFJwdzdJUXlSYjZ3NzJKbkFnSGxwNHhCc29ncTFsa3lTMVR2bmtxcklwTkFHN2ZDeHkzMWhnZU1VVl9maDdsa1I2UllTYWIzbllvUzFxUHRibXA4UHNOMU9KeE45czhBMUVfN1E?oc=5","published_at":"2026-09-02T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Industrial Switch Security","summary":"Cybersecurity critical to Nigeria\u2019s $1trn digital economy ambition \u2014 Switch Solutions&nbsp;&nbsp;The Sun Nigeria","title":"Cybersecurity critical to Nigeria\u2019s $1trn digital economy ambition \u2014 Switch Solutions - The Sun Nigeria"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-c37a78aa906654f7","category":"PLC & Controller Firmware","cve_ids":["CVE-2026-9633","CVE-2026-9634"],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-02","published_at":"2026-09-01T12:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges. The following versions of Rockwell Automation Redundancy Module Configuration Tool are affected: Redundancy Module Configuration Tool 10.00.00 (CVE-2026-9633) Redundancy Module Configuration Tool &gt;=9.00.00|&lt;=10.00.00 (CVE-2026-9634...","title":"Rockwell Automation Redundancy Module Configuration Tool"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-d7ecfea916699051","category":"PLC & Controller Firmware","cve_ids":["CVE-2026-9621","CVE-2026-9622","CVE-2026-9624","CVE-2026-9625"],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-01","published_at":"2026-09-01T12:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation RSLinx Classic are affected: RSLinx Classic &lt;=4.50 (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) CVSS Vendor Equipment Vulnerabilities v3 8.6 Rockwell Automation Rockwell Automat...","title":"Rockwell Automation RSLinx Classic"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-764e49d3d29b7e13","category":"PLC & Controller Firmware","cve_ids":["CVE-2026-9637"],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-03","published_at":"2026-09-01T12:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"CISA Advisories","summary":"View CSAF Summary The following versions of Rockwell Automation Logix Platform are affected: ControlLogix 5580 &lt;=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) CompactLogix 5380 &lt;=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) GuardLogix 5580 &lt;=V33, ...","title":"Rockwell Automation Logix Platform"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-290de46af1b675fd","category":"PLC & Controller Firmware","cve_ids":["CVE-2021-42260"],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-05","published_at":"2026-09-01T12:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"CISA Advisories","summary":"View CSAF Summary The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected: ControlLogix 5580 &lt;34.015, &lt;35.014, &lt;36.013, &lt;37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) GuardLogix 5580 &lt;34.015, &lt;35.014, &lt;36.013, &lt;37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260,...","title":"Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-3a26a19eb19be0ad","category":"PLC & Controller Firmware","cve_ids":["CVE-2026-16675"],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-04","published_at":"2026-09-01T12:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"CISA Advisories","summary":"View CSAF Summary The following versions of Rockwell Automation FactoryTalk Activation Manager are affected: FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation FactoryTalk Activation Manager Improper Restriction of Excessive Authentication Attempts Background Critical Infrastructure Sectors: Critic...","title":"Rockwell Automation FactoryTalk Activation Manager"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-6dd7f41b28220873","category":"PLC & Controller Firmware","cve_ids":["CVE-2025-12768","CVE-2026-12661"],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-06","published_at":"2026-09-01T12:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"HIGH","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution. The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series C 7.101 (CVE-2025-12768, CVE-2026-12661) CVSS Vendor Equipment Vulnerabilities v3 8 Rockwell Auto...","title":"Rockwell Automation Historian ME"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b6552f708f9ab204","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-81578","CVE-2026-82078"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog","published_at":"2026-08-31T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"CISA Advisories","summary":"CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. &nbsp; CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability&nbsp; CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability&nbsp; These types of vulnerabilities are a frequent attack vector for malicious cyber actors and p...","title":"CISA Adds Two Known Exploited Vulnerabilities to Catalog"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a06ab42b7040a533","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMixAFBVV95cUxQNmQ0a1JBSlk3dnlYWDllX1hQTkwxQ2dMY2ZlVUcwQjMxZTNjaWk3b0FGNVVIcnZHUV9Ed2MxS201dEQzcnhCVU5BeFF3SG5jRFlyWEpfUHRySFZRSWdhOWV4MGZ1NG5YZTc0SGQzaW85TFBUM0x1UUZiVmdPTEZROVAtcW9aYzl5Z1I3RXRTQnMya0ZsZFE2RW1pSFJyVGlEeDM2eUh0YmNJZFgtbHBFQUZBTlJ2V1ZPUEJHeE9lV3Q2NWc0?oc=5","published_at":"2026-08-31T11:28:35+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"How Hotel IT Leaders Turn Cybersecurity and Emerging Tech into Competitive Advantages |&nbsp;&nbsp;hoteltechnologynews.com","title":"How Hotel IT Leaders Turn Cybersecurity and Emerging Tech into Competitive Advantages | - hoteltechnologynews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-518a7ee582410186","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMixAFBVV95cUxQNmQ0a1JBSlk3dnlYWDllX1hQTkwxQ2dMY2ZlVUcwQjMxZTNjaWk3b0FGNVVIcnZHUV9Ed2MxS201dEQzcnhCVU5BeFF3SG5jRFlyWEpfUHRySFZRSWdhOWV4MGZ1NG5YZTc0SGQzaW85TFBUM0x1UUZiVmdPTEZROVAtcW9aYzl5Z1I3RXRTQnMya0ZsZFE2RW1pSFJyVGlEeDM2eUh0YmNJZFgtbHBFQUZBTlJ2V1ZPUEJHeE9lV3Q2NWc0?oc=5","published_at":"2026-08-31T11:28:35+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"How Hotel IT Leaders Turn Cybersecurity and Emerging Tech into Competitive Advantages |&nbsp;&nbsp;Hotel Technology News","title":"How Hotel IT Leaders Turn Cybersecurity and Emerging Tech into Competitive Advantages | - Hotel Technology News"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-1724d54c2f6547eb","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMif0FVX3lxTE9vOWpoREpIZFJrc0FybU1FYUY2ajBYaGl0TC02Z2k4XzVkR0JnRWhmeExNb2xzanNaUncwRUNxbGJfWDM5ay1BNzRxWncyYVpYRXhicjgzSFZoVGM2amJtQXUyREZra0tGdmx4WFhJa3JNOUMtdURkZjI4STFaQTg?oc=5","published_at":"2026-08-31T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Critical Infra & APTs","summary":"China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs&nbsp;&nbsp;thehackernews.com","title":"China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-03871760f672d480","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMif0FVX3lxTE9vOWpoREpIZFJrc0FybU1FYUY2ajBYaGl0TC02Z2k4XzVkR0JnRWhmeExNb2xzanNaUncwRUNxbGJfWDM5ay1BNzRxWncyYVpYRXhicjgzSFZoVGM2amJtQXUyREZra0tGdmx4WFhJa3JNOUMtdURkZjI4STFaQTg?oc=5","published_at":"2026-08-31T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Critical Infra & APTs","summary":"China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs&nbsp;&nbsp;The Hacker News","title":"China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e3b2318c43eb6694","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisgFBVV95cUxPRjRLWWE3elZxYXBIS1FyUWNaVzBXcU55cFdiVzBfZDVyTGlPc0FUMEJuN3E4WHFPQzJsUUdKZUxUN0dvcVpQTVQtOENtYkl5V0Yydi00NmdfZmNXV2VsM2xwTkZyelhULUk3aDJIS1I5R1UxTFFUX3NQWDVRQkJ3Y2ZEMTF0Y09QdXVRSkZDMW9lWXpYYlN4b0NpT25Rck82VEpkZGlCOTNlYktsWk5qdXNB?oc=5","published_at":"2026-08-31T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"AI and Financial Cybersecurity: How RBI and SEBI Are Tightening Rules&nbsp;&nbsp;Vajiram & Ravi","title":"AI and Financial Cybersecurity: How RBI and SEBI Are Tightening Rules - Vajiram & Ravi"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-f07dcab3031eb47e","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxOelAxRFVjU2gwMDUzalp1UWJaN083ZGM5NGI3YmQyaTUzTjd0dUk2RFhheDNRMkFmR21ySVRuRUwtVFE3T1dETnVqZnVseW9MS0EycU55Y0RjVFMxa1hyQng3TUVIejVOU290X3VTb2NPal9MYjJPaGU4Mm0tOWF0U0c1WTRlbmpKcEtuSldNc09PUl9VdkF6eHlTOFdMTjNXQ1dMSkt3ZE8?oc=5","published_at":"2026-08-27T19:42:51+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Salt Typhoon Is Already Inside \u2013 Encryption Doesn\u2019t Solve the Problem&nbsp;&nbsp;Security Boulevard","title":"Salt Typhoon Is Already Inside \u2013 Encryption Doesn\u2019t Solve the Problem - Security Boulevard"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-a7f24dff9b7a40b9","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxOelAxRFVjU2gwMDUzalp1UWJaN083ZGM5NGI3YmQyaTUzTjd0dUk2RFhheDNRMkFmR21ySVRuRUwtVFE3T1dETnVqZnVseW9MS0EycU55Y0RjVFMxa1hyQng3TUVIejVOU290X3VTb2NPal9MYjJPaGU4Mm0tOWF0U0c1WTRlbmpKcEtuSldNc09PUl9VdkF6eHlTOFdMTjNXQ1dMSkt3ZE8?oc=5","published_at":"2026-08-27T19:42:51+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Salt Typhoon Is Already Inside \u2013 Encryption Doesn\u2019t Solve the Problem&nbsp;&nbsp;securityboulevard.com","title":"Salt Typhoon Is Already Inside \u2013 Encryption Doesn\u2019t Solve the Problem - securityboulevard.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f1396769b82dbfdb","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijgFBVV95cUxQYlM5RnFnb2Z3Y0RkbGJmQlJjX1JWWGd6eVpvYVBaNXhUekFtUTQ3NEZERTVkOFhaMlpMQmxiQURYMUtIZ25FYkRmbVhnQmQzSXJaY1p4Y1FMdmdMNjZRSTRNUWFMSXpqSm9nQ2F5MEoxSHk3RzlwVXc0S2gtcUFwV09Ea1Rfdkctb1oydHBR?oc=5","published_at":"2026-08-27T15:15:22+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"DOJ: Chinese Hackers Targeted U.S. Infrastructure&nbsp;&nbsp;firststateupdate.com","title":"DOJ: Chinese Hackers Targeted U.S. Infrastructure - firststateupdate.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-06c4bf06155cc80c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijgFBVV95cUxQYlM5RnFnb2Z3Y0RkbGJmQlJjX1JWWGd6eVpvYVBaNXhUekFtUTQ3NEZERTVkOFhaMlpMQmxiQURYMUtIZ25FYkRmbVhnQmQzSXJaY1p4Y1FMdmdMNjZRSTRNUWFMSXpqSm9nQ2F5MEoxSHk3RzlwVXc0S2gtcUFwV09Ea1Rfdkctb1oydHBR?oc=5","published_at":"2026-08-27T15:15:22+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"DOJ: Chinese Hackers Targeted U.S. Infrastructure&nbsp;&nbsp;First State Update","title":"DOJ: Chinese Hackers Targeted U.S. Infrastructure - First State Update"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-5af9c24c2afbd5d8","category":"PLC & Controller Firmware","cve_ids":["CVE-2026-75112"],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-03","published_at":"2026-08-27T12:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"HIGH","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. The following versions of Rockwell Automation OTTO Fleet Manager are affected: OTTO Fleet Manager &lt;=V2.36.2 (CVE-2026-75112) CVSS Vendor Equipment Vulnerabilities v3 6.8 Rockwell Automation Rockwell...","title":"Rockwell Automation OTTO Fleet Manager"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-181f206ad51c39dc","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2018-19518","CVE-2019-11043"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-02","published_at":"2026-08-27T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems. The following versions of All-Line Equipment Company Fuel-Boss are affected: Fuel-Boss V1 Standard &gt;=|&lt;=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043) Fuel-Boss V1 Portal &gt;=|&lt;=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043) F...","title":"All-Line Equipment Company Fuel-Boss"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5f0b94d0a6eb1040","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-69658","CVE-2026-71187","CVE-2026-73125","CVE-2026-73809","CVE-2026-73819","CVE-2026-75548","CVE-2026-75814","CVE-2026-76133","CVE-2026-76179","CVE-2026-76940","CVE-2026-77966","CVE-2026-77975"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-05","published_at":"2026-08-27T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the device. The following versions of Ebyte NA111-M are affected: NA111-M Firmware 9013-2-17 (CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, ...","title":"Ebyte NA111-M"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-bba9daa6febae405","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2026-76943","CVE-2026-78037","CVE-2026-78239"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-01","published_at":"2026-08-27T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to take control over the device. The following versions of Xiiaozet LK100W are affected: LK100W &lt;2.1.240 (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943) CVSS Vendor Equipment Vulnerabilities v3 9.8 Xiiaozet Xiiaozet LK100W Improper Neutralization of Special Elements used in an OS Command ('OS Command ...","title":"Xiiaozet LK100W"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-bd937f1f34586921","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-25-128-03","published_at":"2026-08-27T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition, a timeout error, or a communication delay by sending a specially crafted UDP packet to the product. The following versions of Mitsubishi Electric Multiple FA Products (Update D) are affected: Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32D...","title":"Mitsubishi Electric Multiple FA Products (Update D)"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a39f10cd28c23573","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2023-49105","CVE-2026-53362","CVE-2026-66384"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/alerts/2026/08/27/cisa-adds-three-known-exploited-vulnerabilities-catalog","published_at":"2026-08-27T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"CISA Advisories","summary":"CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-49105 ownCloud Improper Authentication Vulnerability CVE-2026-53362 Linux Kernel Unspecified Vulnerability CVE-2026-66384 JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability&nbsp; These types of vulnerabilities ...","title":"CISA Adds Three Known Exploited Vulnerabilities to Catalog"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-0ce77c2c4ecff17b","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-04","published_at":"2026-08-27T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications. The following versions of Applied Systems Engineering ASE2000 V2 Commu...","title":"Applied Systems Engineering ASE2000 V2 Communications Test Set"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-41f1a1e7f66c3a55","category":"Zero-Day & CISA KEV","cve_ids":["CVE-2025-2399"],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-078-05","published_at":"2026-08-27T12:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"CISA Advisories","summary":"View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products. The following versions of Mitsubishi Electric CNC Series (Update A) are affected: Mitsubishi Electric M800VW (BND-2051W000) &lt;=BB (CVE-2025-2399) Mitsubishi Electric M800VS (BND-2052W000) &lt;=BB (CVE...","title":"Mitsubishi Electric CNC Series (Update A)"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-0870702464a795d9","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMicEFVX3lxTE5iVFV1VEFzWmJYZTNWdFJDU2dhMFBlMjZCeE02a1h4RHdaeEdhNC1EYjFCeWVjY0FGU2FFek9RTFoyWGx5Y0xtbV8zVVRqdFNzVm5EVHI2czIyd2xieDI0bWN1QjBzVmlmbjJnRzA0Tlk?oc=5","published_at":"2026-08-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Threat landscape for industrial automation systems. Q2 2026&nbsp;&nbsp;securelist.com","title":"Threat landscape for industrial automation systems. Q2 2026 - securelist.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-28861a1872914aed","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMicEFVX3lxTE5iVFV1VEFzWmJYZTNWdFJDU2dhMFBlMjZCeE02a1h4RHdaeEdhNC1EYjFCeWVjY0FGU2FFek9RTFoyWGx5Y0xtbV8zVVRqdFNzVm5EVHI2czIyd2xieDI0bWN1QjBzVmlmbjJnRzA0Tlk?oc=5","published_at":"2026-08-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Threat landscape for industrial automation systems. Q2 2026&nbsp;&nbsp;Securelist","title":"Threat landscape for industrial automation systems. Q2 2026 - Securelist"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-7d390f5096990329","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://www.cisa.gov/resources-tools/resources/cisa-vulnerability-review","published_at":"2026-08-26T12:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"MEDIUM","source":"CISA Advisories","summary":"Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the risk they pose. The CISA Vul...","title":"CISA Vulnerability Review"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1088698bf8f84a8e","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilgFBVV95cUxQYVI0bFlaWWZBanh6RnlVbTgzbk1tVmYyQnJVUmE0T3lOSzVuMmpjSmFidjZTamxJU08yemNpcmxCTVJDSmxuck1jTFcwRGtpV05JbXFHdU14cENtTk9URl9yaW53WGNjUXY4eERpTl9kZW9YVHVRVVNMdURHYnZQTzFfMmFXd2o3UDN3VW1hZmJLWVlQQ2c?oc=5","published_at":"2026-08-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"FBI, Department of Justice Announce Disruption of Global Botnet | Federal Bureau of Investigation&nbsp;&nbsp;fbi.gov","title":"FBI, Department of Justice Announce Disruption of Global Botnet | Federal Bureau of Investigation - fbi.gov"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8b7adabc62805a5b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilgFBVV95cUxQYVI0bFlaWWZBanh6RnlVbTgzbk1tVmYyQnJVUmE0T3lOSzVuMmpjSmFidjZTamxJU08yemNpcmxCTVJDSmxuck1jTFcwRGtpV05JbXFHdU14cENtTk9URl9yaW53WGNjUXY4eERpTl9kZW9YVHVRVVNMdURHYnZQTzFfMmFXd2o3UDN3VW1hZmJLWVlQQ2c?oc=5","published_at":"2026-08-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"FBI, Department of Justice Announce Disruption of Global Botnet \u2014 FBI&nbsp;&nbsp;fbi.gov","title":"FBI, Department of Justice Announce Disruption of Global Botnet \u2014 FBI - fbi.gov"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-0f798bf602d04895","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxQbHd1RmNSSjBuNWhKTGJVZlJTMFlweUpmV3lreWxTX2NSUDhkVXMtMm5Ib3JJMnl0YnhGdTlKOFl3dTBFNHVRS0RsZ2o2ZkM0aHVrUW8yZUg0dDk2WERBX1JEell6dnlOUWh5eFlkUktQcExLN2k3MTNQQVpfdnA3RUV2Q1pwTlFBMmZSTUF0c3ZQM0RuaXFXc2Zrdk83NmpFWGZCUmRCYkcyQW_SAbABQVVfeXFMTzhLVG5NQWhKcDFFRlhoRTdibFhyT296Q1ZCVTFtN2lrREZwMWc0VXVoSk1xeVRweTlmc2dJN3pFMkNPZXJPSkFTSFUtTkoxTTBaYnRsVm9zZUtfUFVqUFRicVA5alNmdGQ5SV9kbEdtYURKQ2plcFFMOHdZYnJnbDd5YjlncHBNNUItdVlQb3h0UzNlY1pfdWNfMzdNTnhLS2hNdnQyQjA1YTFsZW94aHo?oc=5","published_at":"2026-08-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Blacklisted Chinese firm claims it has built \u2018cyber nuclear weapon\u2019&nbsp;&nbsp;nationalsecuritynews.com","title":"Blacklisted Chinese firm claims it has built \u2018cyber nuclear weapon\u2019 - nationalsecuritynews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6b53960a82bee347","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxQbHd1RmNSSjBuNWhKTGJVZlJTMFlweUpmV3lreWxTX2NSUDhkVXMtMm5Ib3JJMnl0YnhGdTlKOFl3dTBFNHVRS0RsZ2o2ZkM0aHVrUW8yZUg0dDk2WERBX1JEell6dnlOUWh5eFlkUktQcExLN2k3MTNQQVpfdnA3RUV2Q1pwTlFBMmZSTUF0c3ZQM0RuaXFXc2Zrdk83NmpFWGZCUmRCYkcyQW_SAbABQVVfeXFMTzhLVG5NQWhKcDFFRlhoRTdibFhyT296Q1ZCVTFtN2lrREZwMWc0VXVoSk1xeVRweTlmc2dJN3pFMkNPZXJPSkFTSFUtTkoxTTBaYnRsVm9zZUtfUFVqUFRicVA5alNmdGQ5SV9kbEdtYURKQ2plcFFMOHdZYnJnbDd5YjlncHBNNUItdVlQb3h0UzNlY1pfdWNfMzdNTnhLS2hNdnQyQjA1YTFsZW94aHo?oc=5","published_at":"2026-08-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Blacklisted Chinese firm claims it has built \u2018cyber nuclear weapon\u2019&nbsp;&nbsp;National Security News","title":"Blacklisted Chinese firm claims it has built \u2018cyber nuclear weapon\u2019 - National Security News"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-3e6056d77dfce8b1","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMi4wFBVV95cUxNREl1eGlrU3R4VGRCelB0VC1hQXp5dUJvWkl0VXA3bUZ5V1Z2RGJDSVdwbERubVVIZElZX01JQ2ZsMDVsT0RyQmJFXzZpOEw1YjJtc2VnN3dLY0ZEWTE5UXdNbjRQVElqUXM2YkJfRnMzU3VXdFJUVEdjZkZuTGxucEVIWEc5RzNsdU5fdHhWeW1vT2JPX0pVZi1LOFZfRjhIRXc0UlJOZ0lHaFg1cmVFXzhFcUdyWnp1eUl1NElqOHYwS0h4UWtqWHFOc1piRXlMQVRMT1BzZnlpd185WUdvWWV2RQ?oc=5","published_at":"2026-08-26T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"DOJ, FBI seize China-linked QScan and QTRouter platforms used to target US critical infrastructure&nbsp;&nbsp;industrialcyber.co","title":"DOJ, FBI seize China-linked QScan and QTRouter platforms used to target US critical infrastructure - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-692d823c0a77f66b","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMi4wFBVV95cUxNREl1eGlrU3R4VGRCelB0VC1hQXp5dUJvWkl0VXA3bUZ5V1Z2RGJDSVdwbERubVVIZElZX01JQ2ZsMDVsT0RyQmJFXzZpOEw1YjJtc2VnN3dLY0ZEWTE5UXdNbjRQVElqUXM2YkJfRnMzU3VXdFJUVEdjZkZuTGxucEVIWEc5RzNsdU5fdHhWeW1vT2JPX0pVZi1LOFZfRjhIRXc0UlJOZ0lHaFg1cmVFXzhFcUdyWnp1eUl1NElqOHYwS0h4UWtqWHFOc1piRXlMQVRMT1BzZnlpd185WUdvWWV2RQ?oc=5","published_at":"2026-08-26T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"DOJ, FBI seize China-linked QScan and QTRouter platforms used to target US critical infrastructure&nbsp;&nbsp;Industrial Cyber","title":"DOJ, FBI seize China-linked QScan and QTRouter platforms used to target US critical infrastructure - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d62d5245003a3e98","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi2gFBVV95cUxQUHNkVTc1cEhqbHYtbFpBYUVhaTR6RHN4VnVfaU5OV0puMEJoM2JBTDZEQ0RDLW9uZDJmSXY4TjF1Q0VYQk9UNmFISVVLWXN4US1ZN1J2TTJkbW1nZlJCUEFyT0l1N3E1SWZzTGFSZUowRjJWX0ZmSGtVczBWbEVMM2Q1TjlvaGpVb0N0ZmgyRUVXeGhORU9HQmFSbHBTWVBjVDNkMmg5ZXJoRnIzWF9iX2szSG93Q0c4TG0yNjNaRlAxeTNDV2FOVjFPcjYtdmNXUFFKM05BMkxFZw?oc=5","published_at":"2026-08-20T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Building Automation & LoRaWAN","summary":"NIST offers resource-constrained BACS operators practical steps to address OT cybersecurity threats and risks&nbsp;&nbsp;Industrial Cyber","title":"NIST offers resource-constrained BACS operators practical steps to address OT cybersecurity threats and risks - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-562d4584e80fd2c0","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxPaWRjZmRQc2NicF9GUGc5TXlNU0daelBRajUtUWtLVDZlOHVud0JKTkpEWDVtUnNLWmU2OUoxOGpPZDdtZnhWYl9MM2dMMm9EQ0hFc2piQkFBRWF6ZUhpY01STnBsNnBCV1ZackZZeE1aTGlPSzFoUUFpV1hCenJWR0p6ZDZoLWhaNE1uaW5aRERhUS01OUk3enFzM3VTZkhCb0FjazFBYVRmR21jWHhqUA?oc=5","published_at":"2026-08-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"NIST Releases Tips & Tactics for Building Automation & Control System Cybersecurity&nbsp;&nbsp;National Institute of Standards and Technology (.gov)","title":"NIST Releases Tips & Tactics for Building Automation & Control System Cybersecurity - National Institute of Standards and Technology (.gov)"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ef3924705b6ca0c8","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijAFBVV95cUxOZ2tWM1dkT2ZXVnF0enpoVGZkWmdTY3gxQVk1SDB4dmYtUjBZamNKQXhVa0R1Zk5sSGZ1TTdwaXlaLVlkNXMtcTlQNHlNeXBjSlNqem9mS2Z6cmMxWXVSeTZQYlRJTTNXZks2VFllYlFBX1U0N0JDbmNMR1NmSmNCM0tfTVRBRV9XT1p0cA?oc=5","published_at":"2026-08-17T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Industrial Automation Services Market Size, Share [2026-2034]&nbsp;&nbsp;Fortune Business Insights","title":"Industrial Automation Services Market Size, Share [2026-2034] - Fortune Business Insights"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-22d50bc5c6c06be9","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijAFBVV95cUxOZ2tWM1dkT2ZXVnF0enpoVGZkWmdTY3gxQVk1SDB4dmYtUjBZamNKQXhVa0R1Zk5sSGZ1TTdwaXlaLVlkNXMtcTlQNHlNeXBjSlNqem9mS2Z6cmMxWXVSeTZQYlRJTTNXZks2VFllYlFBX1U0N0JDbmNMR1NmSmNCM0tfTVRBRV9XT1p0cA?oc=5","published_at":"2026-08-17T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Industrial Automation Services Market Size, Share [2026-2034]&nbsp;&nbsp;fortunebusinessinsights.com","title":"Industrial Automation Services Market Size, Share [2026-2034] - fortunebusinessinsights.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d6c5e56505e5708c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirwFBVV95cUxQR01wbjhETEwwVDAwbGVkLUw5OTR2cjZTVkpibDEyUXY5MEotSHliRGQ2eTF1emhDTE12cnNpNzVnTGQ3ZHJuSjlOQm5sdDNqTlpUMDBXVGY3Nm9iUXI4T3kyNlAzMkwwa2c2bVQ5c1RrMlhMS3VmLVpZMC14ZVFxVllockxxdW9uajVOMkJTejJhd0xvYzZiVDdlNEpzLVlqNEQxNVplLVJZcHZqWlUw?oc=5","published_at":"2026-08-14T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"How CSOs can turn cybersecurity into a business growth strategy&nbsp;&nbsp;csoonline.com","title":"How CSOs can turn cybersecurity into a business growth strategy - csoonline.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-dd699ba1393d5c88","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiZ0FVX3lxTE1DX2l3N3U0aHNOUndyYjVtT3N0VnFRNmFxaWVBajIxaDJCbFZ1eG4zQTVFcGhHNmxhOTBYRmU0UENBVl9ZNkFWTVNJUmFPNzJTNGI1UWhkaksyRTlfVWdpRWFWWVUyRDA?oc=5","published_at":"2026-08-13T09:33:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"\u201cAI doesn\u2019t fundamentally change cybersecurity. It changes the speed and scale\u201d&nbsp;&nbsp;calcalistech.com","title":"\u201cAI doesn\u2019t fundamentally change cybersecurity. It changes the speed and scale\u201d - calcalistech.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-50a64ee2ee3d7128","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMieEFVX3lxTE42YVhOUXpnOEtLdW41SXZndUQ2OWd6cmstNHBhc2JqVGZZaE05Z3pIQk8tYUtVU2t1dGdpYWJvSzBWQWNFTDFLWXp0LWtJUGQ4TWNXVnZlWkFIa2Z2TkNPMGRQRWRsOXA3WjlMNDJDbm5Lc2V6SW9UR9IBfkFVX3lxTE00VHJaekgzSDJvajdabVhmN2JXSmVZeHkyS19xNHp6dkhnOHNKZ2tETHhtYlBTTHlILXNHQ3YxZW9vYTBhN0djbnhDLTJpM3NkZ1pDZ0cwZ05YeDhseVF6TWFXS0RvQUFmdXQtNVUyM0k0bTYyMGY5b0N3YmNjUQ?oc=5","published_at":"2026-08-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"OpenAI tightens controls on its new model over cybersecurity risks, as AI security debate intensifies&nbsp;&nbsp;cnbc.com","title":"OpenAI tightens controls on its new model over cybersecurity risks, as AI security debate intensifies - cnbc.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-575f33d0b1f21eb2","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiZEFVX3lxTE5QcENGZzBqb1JhU2hQRC0zZ2JBek5Bam1jQ0pLSXFZUUpKbHhkSUZzUm9heXVjR1JPOGlNeVNfaDNPdjJOeWpmXzVCV3hsVy12aFZNck5TeEdzODFVRVpwT3dVbDc?oc=5","published_at":"2026-08-10T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Inductive Automation Revenue 2025: $41M Est. ARR&nbsp;&nbsp;GetLatka","title":"Inductive Automation Revenue 2025: $41M Est. ARR - GetLatka"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4b149e6495460427","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiowFBVV95cUxNZDdXamZBVmZ6SWVpWlZBZFZBMFByNjhmN0lXeHF6SXlfNGRpeW0zcXhvUWhFeVRsTXhuMEQ1V09UYnN1MlozSVhhbVJZR0ZLbG9WVm85aEFYUzRWMERESFE3Y1VPQlA5UmVtbTJ1d2VzNnpLdzJfWi03UkwwTVlzZDR2V3B2aFRVYXJNdXltSlYtbUpXUzQwRXI3MmVkUnI5VjFV?oc=5","published_at":"2026-08-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Machine Automation Controller Market Size, Share, Trend [2034]&nbsp;&nbsp;Fortune Business Insights","title":"Machine Automation Controller Market Size, Share, Trend [2034] - Fortune Business Insights"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-089a4842dd22858d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMieEFVX3lxTE42YVhOUXpnOEtLdW41SXZndUQ2OWd6cmstNHBhc2JqVGZZaE05Z3pIQk8tYUtVU2t1dGdpYWJvSzBWQWNFTDFLWXp0LWtJUGQ4TWNXVnZlWkFIa2Z2TkNPMGRQRWRsOXA3WjlMNDJDbm5Lc2V6SW9UR9IBfkFVX3lxTE00VHJaekgzSDJvajdabVhmN2JXSmVZeHkyS19xNHp6dkhnOHNKZ2tETHhtYlBTTHlILXNHQ3YxZW9vYTBhN0djbnhDLTJpM3NkZ1pDZ0cwZ05YeDhseVF6TWFXS0RvQUFmdXQtNVUyM0k0bTYyMGY5b0N3YmNjUQ?oc=5","published_at":"2026-08-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"OpenAI tightens controls on its new model over cybersecurity risks, as AI security debate intensifies&nbsp;&nbsp;CNBC","title":"OpenAI tightens controls on its new model over cybersecurity risks, as AI security debate intensifies - CNBC"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-c78e04029f02ddfc","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiZEFVX3lxTE5QcENGZzBqb1JhU2hQRC0zZ2JBek5Bam1jQ0pLSXFZUUpKbHhkSUZzUm9heXVjR1JPOGlNeVNfaDNPdjJOeWpmXzVCV3hsVy12aFZNck5TeEdzODFVRVpwT3dVbDc?oc=5","published_at":"2026-08-10T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Inductive Automation Revenue 2025: $41M Est. ARR&nbsp;&nbsp;getlatka.com","title":"Inductive Automation Revenue 2025: $41M Est. ARR - getlatka.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-634192f9a3fc0efc","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiowFBVV95cUxNZDdXamZBVmZ6SWVpWlZBZFZBMFByNjhmN0lXeHF6SXlfNGRpeW0zcXhvUWhFeVRsTXhuMEQ1V09UYnN1MlozSVhhbVJZR0ZLbG9WVm85aEFYUzRWMERESFE3Y1VPQlA5UmVtbTJ1d2VzNnpLdzJfWi03UkwwTVlzZDR2V3B2aFRVYXJNdXltSlYtbUpXUzQwRXI3MmVkUnI5VjFV?oc=5","published_at":"2026-08-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Machine Automation Controller Market Size, Share, Trend [2034]&nbsp;&nbsp;fortunebusinessinsights.com","title":"Machine Automation Controller Market Size, Share, Trend [2034] - fortunebusinessinsights.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-b73cd4f648ca60cd","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMi3gFBVV95cUxQS1piS1pFU3NlRHFhZEdIOVRIRmNXbTFUbS1rX3NyVGJzWGMzNURwSkRWSlpsYjNEZnpTdnFBYkN4Y3c2anpfeGtya0FHVThTcWJhdTdxZkdPcTlXaXBhQjQ3Zjhqc1hJR0dzeFJRYjY3QW9RRVdYMEhaVmQ1NktCV1VXMDJ4UHpLek1keU5ESWF6Q09sRFFKSzZNSktWS3MxLThxR0taMU1UeXVHd1dwdVJGbm9GNjR6a3JKUS16UUV2NHRwbTFsZGpoOEg0UGZ3dkJzZXlXRUxPUDQ0ZHc?oc=5","published_at":"2026-08-06T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"Campus Switch Refresh Gets Boost from AI Cybersecurity Threats, According to Dell'Oro Group&nbsp;&nbsp;prnewswire.com","title":"Campus Switch Refresh Gets Boost from AI Cybersecurity Threats, According to Dell'Oro Group - prnewswire.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-cf0a0efb3e9d77df","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMi3gFBVV95cUxQS1piS1pFU3NlRHFhZEdIOVRIRmNXbTFUbS1rX3NyVGJzWGMzNURwSkRWSlpsYjNEZnpTdnFBYkN4Y3c2anpfeGtya0FHVThTcWJhdTdxZkdPcTlXaXBhQjQ3Zjhqc1hJR0dzeFJRYjY3QW9RRVdYMEhaVmQ1NktCV1VXMDJ4UHpLek1keU5ESWF6Q09sRFFKSzZNSktWS3MxLThxR0taMU1UeXVHd1dwdVJGbm9GNjR6a3JKUS16UUV2NHRwbTFsZGpoOEg0UGZ3dkJzZXlXRUxPUDQ0ZHc?oc=5","published_at":"2026-08-06T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"Campus Switch Refresh Gets Boost from AI Cybersecurity Threats, According to Dell'Oro Group&nbsp;&nbsp;PR Newswire","title":"Campus Switch Refresh Gets Boost from AI Cybersecurity Threats, According to Dell'Oro Group - PR Newswire"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-c9af8644819944a2","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxOR3Y2aEswdTctSkwzVjBva2hGSmVaY2VXbVY0QmhrTTFuTWc5Y2E2ZWlWM3dNSDN4RFRhUHpHQjNhaHhFZXVjQUlmZzlMc3QxdmNRTlJNN1BnY1J5Wk1PNWVUSjFMeUljM2QyX0NGTkYzdTJuaF9iaFgySG90WkRMVWxLTQ?oc=5","published_at":"2026-08-06T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities&nbsp;&nbsp;The Hacker News","title":"Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-82815eec05235800","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxOR3Y2aEswdTctSkwzVjBva2hGSmVaY2VXbVY0QmhrTTFuTWc5Y2E2ZWlWM3dNSDN4RFRhUHpHQjNhaHhFZXVjQUlmZzlMc3QxdmNRTlJNN1BnY1J5Wk1PNWVUSjFMeUljM2QyX0NGTkYzdTJuaF9iaFgySG90WkRMVWxLTQ?oc=5","published_at":"2026-08-06T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities&nbsp;&nbsp;thehackernews.com","title":"Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1333790668649fef","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikwFBVV95cUxOWVpRTGl5NU13Wkl2UWk5dW1XUTZoQ3JmRURISUVjbk1Ybm85QmtnT1VLUzBuemttTFVhMVFrTVVBTTRhUUxuZklvemZVcGxIV05SWkdmTkpUdjlvN3RTS2xPZjFVcGZ5TUs4cDB3YXpGWG80Mk1XMnFGVXhBeEZhbF93NEwtXzhlSk9seHZfTzUzUkHSAZgBQVVfeXFMTnhVVUZneXNSanozdExUSzI2UU4tc0pnTVIyUGg2ZFpfWEt4aHdhZDBuWnI1cHZyRUNaX3NMNW9zNWRLZVM3Zi1iLWZrX2xVLV84X1RWOVFKV1RqOEIyNGNQaGhOa0tTblhocUxIV3FpTW1ITjBrSHVZTmp0SE84RzNxV3lneXk3bnhmOHlzekgwRy1fbDhiczk?oc=5","published_at":"2026-08-05T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Water Sector Cyberattacks Reportedly Hit at Least 12 States&nbsp;&nbsp;SecurityWeek","title":"Water Sector Cyberattacks Reportedly Hit at Least 12 States - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-91efe88099543d02","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikwFBVV95cUxOWVpRTGl5NU13Wkl2UWk5dW1XUTZoQ3JmRURISUVjbk1Ybm85QmtnT1VLUzBuemttTFVhMVFrTVVBTTRhUUxuZklvemZVcGxIV05SWkdmTkpUdjlvN3RTS2xPZjFVcGZ5TUs4cDB3YXpGWG80Mk1XMnFGVXhBeEZhbF93NEwtXzhlSk9seHZfTzUzUkHSAZgBQVVfeXFMTnhVVUZneXNSanozdExUSzI2UU4tc0pnTVIyUGg2ZFpfWEt4aHdhZDBuWnI1cHZyRUNaX3NMNW9zNWRLZVM3Zi1iLWZrX2xVLV84X1RWOVFKV1RqOEIyNGNQaGhOa0tTblhocUxIV3FpTW1ITjBrSHVZTmp0SE84RzNxV3lneXk3bnhmOHlzekgwRy1fbDhiczk?oc=5","published_at":"2026-08-05T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Water Sector Cyberattacks Reportedly Hit at Least 12 States&nbsp;&nbsp;securityweek.com","title":"Water Sector Cyberattacks Reportedly Hit at Least 12 States - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5ec87bfd5cfc3902","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxNR0FCVXJZQVNfY0xIN2dkRGF2bDlod0V5c21NSVdrT1FfSmtYMF84QVFLdzdvUXVBdUFkN0pGczBrc2toQjFrTTNaYUcyc1BTLThoYnBKYlN2dnlWcHk1OGlSMXhwa3M2Nk40V191cHRaWTE2dWRoSVUtZmRKRUdFeHE0SU4wX2lzMXltZjF1RER0U3RjRlYzZkk5cW1LN2YyaHhtdVlaT3E1ZjVnZWc?oc=5","published_at":"2026-08-03T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"30+ water utility cyberattacks expose a vulnerability across US cities&nbsp;&nbsp;Smart Cities Dive","title":"30+ water utility cyberattacks expose a vulnerability across US cities - Smart Cities Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-65acf08792f9351a","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihwFBVV95cUxNUW44N2RRMW5TTFZYczlVWlRvQkJRdE9UVFA2S2t5c3l6ODRCX3ZTN2tYM0Zocjc0TFNRb21JTnNuQ3FnNktwdl91aHpNZUkxeTVpYnoyRzR4TzVEckJadzJPcVRPRnhfMVl5NkRmWllMTTE1SnNmeUNxVVNuX0dPUk5lNHIxSWc?oc=5","published_at":"2026-08-03T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Industrial Control Systems Market Size, Share [2026-2034]&nbsp;&nbsp;fortunebusinessinsights.com","title":"Industrial Control Systems Market Size, Share [2026-2034] - fortunebusinessinsights.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2229faebf2a616c6","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihwFBVV95cUxNUW44N2RRMW5TTFZYczlVWlRvQkJRdE9UVFA2S2t5c3l6ODRCX3ZTN2tYM0Zocjc0TFNRb21JTnNuQ3FnNktwdl91aHpNZUkxeTVpYnoyRzR4TzVEckJadzJPcVRPRnhfMVl5NkRmWllMTTE1SnNmeUNxVVNuX0dPUk5lNHIxSWc?oc=5","published_at":"2026-08-03T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Industrial Control Systems Market Size, Share [2026-2034]&nbsp;&nbsp;Fortune Business Insights","title":"Industrial Control Systems Market Size, Share [2026-2034] - Fortune Business Insights"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b976460b92655b9f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxNR0FCVXJZQVNfY0xIN2dkRGF2bDlod0V5c21NSVdrT1FfSmtYMF84QVFLdzdvUXVBdUFkN0pGczBrc2toQjFrTTNaYUcyc1BTLThoYnBKYlN2dnlWcHk1OGlSMXhwa3M2Nk40V191cHRaWTE2dWRoSVUtZmRKRUdFeHE0SU4wX2lzMXltZjF1RER0U3RjRlYzZkk5cW1LN2YyaHhtdVlaT3E1ZjVnZWc?oc=5","published_at":"2026-08-03T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"30+ water utility cyberattacks expose a vulnerability across US cities&nbsp;&nbsp;smartcitiesdive.com","title":"30+ water utility cyberattacks expose a vulnerability across US cities - smartcitiesdive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-3d3f94c067e82b17","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMibkFVX3lxTE9oay1mMGU0TXlSSFpsTU5HVHNUb2lqcUcxb1k5NlF6bHJxVmwxMG1Jc3F6WVVNYmZSbW90SWFRYV82SHlwNWhMc3NhVUwyVHZ6dUdmQzI0bjlHYW1lN3ZKM3VITkltVmNyQi03aVh3?oc=5","published_at":"2026-08-03T02:19:06+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Cybersecurity, Then & Now: A Visual Look at 20 Years of Change&nbsp;&nbsp;darkreading.com","title":"Cybersecurity, Then & Now: A Visual Look at 20 Years of Change - darkreading.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-793beb9c7c682285","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMibkFVX3lxTE9oay1mMGU0TXlSSFpsTU5HVHNUb2lqcUcxb1k5NlF6bHJxVmwxMG1Jc3F6WVVNYmZSbW90SWFRYV82SHlwNWhMc3NhVUwyVHZ6dUdmQzI0bjlHYW1lN3ZKM3VITkltVmNyQi03aVh3?oc=5","published_at":"2026-08-03T02:19:06+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Cybersecurity, Then & Now: A Visual Look at 20 Years of Change&nbsp;&nbsp;Dark Reading","title":"Cybersecurity, Then & Now: A Visual Look at 20 Years of Change - Dark Reading"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-0b67e5189b986b8f","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi-wFBVV95cUxQYUJfLXZfZmFnbmtVTmtmbjF0RmkxcExnRWpKeDR1Rk41NTNmMFc3bUtuSFIyeFBTMUlHN3ZGUjBBYUtzUnBkb20tLXBiYkN0aVVDWW1WRWlfdTc3bU96NFN2MHVMV0hsQ0l1V0JMZW11NkNXN2NQeWhVenRCQnJCbDM0dFlHSzAzVTNGR0dxaTRnNmg0NkJ2VVBDTlh3Q05lYVZKSzdSd24tMzNHMUZqYVE2Y00zRXA4Z2lLdk56WXc2RUhEVXpfZndMazk0R0ZOemxGREhPV2t2a0FLZzRBOWVZWDhOMmNRam9LVzNzcGg1R3VrdHVOemFhcw?oc=5","published_at":"2026-08-01T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Cranswick deploys Rockwell Automation pick-and-place robots to hit 240 cycles per minute in end-of-line packaging&nbsp;&nbsp;marketscale.com","title":"Cranswick deploys Rockwell Automation pick-and-place robots to hit 240 cycles per minute in end-of-line packaging - marketscale.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-2f8cfe9cea8f8a93","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi-wFBVV95cUxQYUJfLXZfZmFnbmtVTmtmbjF0RmkxcExnRWpKeDR1Rk41NTNmMFc3bUtuSFIyeFBTMUlHN3ZGUjBBYUtzUnBkb20tLXBiYkN0aVVDWW1WRWlfdTc3bU96NFN2MHVMV0hsQ0l1V0JMZW11NkNXN2NQeWhVenRCQnJCbDM0dFlHSzAzVTNGR0dxaTRnNmg0NkJ2VVBDTlh3Q05lYVZKSzdSd24tMzNHMUZqYVE2Y00zRXA4Z2lLdk56WXc2RUhEVXpfZndMazk0R0ZOemxGREhPV2t2a0FLZzRBOWVZWDhOMmNRam9LVzNzcGg1R3VrdHVOemFhcw?oc=5","published_at":"2026-08-01T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Cranswick deploys Rockwell Automation pick-and-place robots to hit 240 cycles per minute in end-of-line packaging&nbsp;&nbsp;MarketScale","title":"Cranswick deploys Rockwell Automation pick-and-place robots to hit 240 cycles per minute in end-of-line packaging - MarketScale"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d4c7d0ef926619c7","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimAFBVV95cUxQR2RqcHFFblFJX29PdktudklDUUVtXzFRNVBuM1hObTlpc2lGbC1NNWxGUmlHbWoxeWp2WG5DaXVzVWZSalJfc0Q0bXdROUd6ci02RW1FVFBZNE9GaUV5V1JHeHE3Z0pPSnc3QWgtYnlXajRUdnYtWUpVbVNVR29rM1cwMGFCY0ZvY2hxbUVxem40eFN3RENKMg?oc=5","published_at":"2026-07-31T20:23:50+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"U.S. Ports Need a Cyber Insurance Backstop | Proceedings - August 2026 Vol. 152/8/1,482&nbsp;&nbsp;U.S. Naval Institute","title":"U.S. Ports Need a Cyber Insurance Backstop | Proceedings - August 2026 Vol. 152/8/1,482 - U.S. Naval Institute"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-72bba1bc9a277413","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimAFBVV95cUxQR2RqcHFFblFJX29PdktudklDUUVtXzFRNVBuM1hObTlpc2lGbC1NNWxGUmlHbWoxeWp2WG5DaXVzVWZSalJfc0Q0bXdROUd6ci02RW1FVFBZNE9GaUV5V1JHeHE3Z0pPSnc3QWgtYnlXajRUdnYtWUpVbVNVR29rM1cwMGFCY0ZvY2hxbUVxem40eFN3RENKMg?oc=5","published_at":"2026-07-31T20:23:50+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"U.S. Ports Need a Cyber Insurance Backstop | Proceedings - August 2026 Vol. 152/8/1,482&nbsp;&nbsp;usni.org","title":"U.S. Ports Need a Cyber Insurance Backstop | Proceedings - August 2026 Vol. 152/8/1,482 - usni.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-d2206c5c00d53069","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi6AFBVV95cUxPTTJwN194a2U1QnBfOVl0NDlpUXh5VmNQdW1EeXBUSlk4cXVSNHd0WFRSNHZIS2NIUU9vUXhLZHdtX2oxQld1clhBY245eUFUem1PNEpOQnVJdFNrRDdOSzZjT2hSNHVkcXJXdFJWSV9saHRnTWUxVUNwRlpHOERJOU4yRHZHMGJtMlpVWXhoU1F0dmdyVl9OTUZsY05pQkh6SEZoellUckRXSkZWOHUtXzE0bi1pQl9zd21HbjRmN3ZKSG4zT3QzSURrb0JTQ2FoUGFkV1ptc2wzT1lTM3p6NDZ0Q1NPZWxM?oc=5","published_at":"2026-07-31T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Cranswick deploys Rockwell Automation robotics to hit 240 picks per minute on pigs-in-blankets line&nbsp;&nbsp;marketscale.com","title":"Cranswick deploys Rockwell Automation robotics to hit 240 picks per minute on pigs-in-blankets line - marketscale.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-47797ba90f8091e1","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi6AFBVV95cUxPTTJwN194a2U1QnBfOVl0NDlpUXh5VmNQdW1EeXBUSlk4cXVSNHd0WFRSNHZIS2NIUU9vUXhLZHdtX2oxQld1clhBY245eUFUem1PNEpOQnVJdFNrRDdOSzZjT2hSNHVkcXJXdFJWSV9saHRnTWUxVUNwRlpHOERJOU4yRHZHMGJtMlpVWXhoU1F0dmdyVl9OTUZsY05pQkh6SEZoellUckRXSkZWOHUtXzE0bi1pQl9zd21HbjRmN3ZKSG4zT3QzSURrb0JTQ2FoUGFkV1ptc2wzT1lTM3p6NDZ0Q1NPZWxM?oc=5","published_at":"2026-07-31T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Cranswick deploys Rockwell Automation robotics to hit 240 picks per minute on pigs-in-blankets line&nbsp;&nbsp;MarketScale","title":"Cranswick deploys Rockwell Automation robotics to hit 240 picks per minute on pigs-in-blankets line - MarketScale"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-04316d0fad82f503","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihwFBVV95cUxQckZVa2plclhoTDVJdHJGZkk2OGpXdVNYZVVXX21KUlRtNEE3ZkZtREFDVDcydUlLM1VCekVlbU1nZjVWWFFyWmVYX2QxNUZNLUFJY2dnZjEwWlEtWnRWLXJyZUNaUV80Zi1vUlIxTThVQ2pMYS1sUUMweElhRDVIRE54N2VCUzA?oc=5","published_at":"2026-07-30T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"CISA, Australia Unveil New Guidance on Isolating Systems Mid-Cyberattack&nbsp;&nbsp;The420.in","title":"CISA, Australia Unveil New Guidance on Isolating Systems Mid-Cyberattack - The420.in"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f2483f3782b7bae4","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi0wFBVV95cUxQZjM1ZXpTbEtIRWtxMlFNSmpab1psbmhmVjNZQ3JaQzVmWkYyM0s1Q1BaQ0FaejJ5eHQ0ZXNyemJITDBaWW1FaWZfeE5hWlJJanA3WmVoZUlVUWFWT3Y0MWNWQk45dnVxelhVMndoRkhGbG1oTTdaZnZOdXF0V3lmREdUOUk0azFjNy1MelFnYWxMNG9GOXhmVk5zaXZPSEt4RUt3Z0J0R1BwLUNoMFZjenpuVTRLemZsUzZ5OEFtWGdVUVpaeFBNbUlNclo4Skx1Y0Nj?oc=5","published_at":"2026-07-29T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"China and Iran Are Already Inside US Grids: CISA Demands Tested Isolation Plans&nbsp;&nbsp;techtimes.com","title":"China and Iran Are Already Inside US Grids: CISA Demands Tested Isolation Plans - techtimes.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-98544063513dccbe","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi0AFBVV95cUxQQTlITV9pWXVSdWF6WVdDSDA2ZmVUd0o5UnlQSUJ3cFZNREtJaU42RFR5dnIwZEJMcmg0THZ4bHV3UkVTUlhxajVaQ2tsVWFvbHFHeWFqSzF2Y01tMy13RTM3X1J5RkpEalB0aUN4eDJRcUhNaHRrQ1VtbDVDRXdHd0hSUUZyTlpBOHlSVFJJbXhGQlRhbWpHbnhPUnhfNmZzZmJsMHVWaDkwRWt2TkpkbVV4LVpMckZ2bGpuOXQ2bWJvQkNXQkZEYXhjZkx6R2Z6?oc=5","published_at":"2026-07-29T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Iranian Hackers Exploited Unpatchable PLC Flaw to Breach 30 Minnesota Water Systems&nbsp;&nbsp;techtimes.com","title":"Iranian Hackers Exploited Unpatchable PLC Flaw to Breach 30 Minnesota Water Systems - techtimes.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b3876da15fc1ae2c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi5AFBVV95cUxNQ3U0dFNZYVZ5T3F6TWdfeVVXVWQ5VlktcmtHSlRmOENWWVdRZjQ0SXZkX2NwSVVZQXhOT0RnSi1MZEZIQUVVSFNJcklhcEF6Mlh4RVNXU3BrZUhkZzNJSUJ0bjBSSVVQM18zdDVmNGNOQkN4UnNMWEJLQks4R1kzWWpsM3hHYjBMWDkwSWd6M25XRlNjMlBrMnhBb0JRZGQzTDdjR0k2dWxqZDlYMlB3Mi04WEgyUnBvRGpZakRKNEhhRWhsd2VrVHktSlVBUUszenJmQ2dPc1ZzcG1TUG1aak1BMDU?oc=5","published_at":"2026-07-29T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"SonicWall warns OT/IT convergence expanding manufacturing cybersecurity risks despite fewer detected attacks&nbsp;&nbsp;industrialcyber.co","title":"SonicWall warns OT/IT convergence expanding manufacturing cybersecurity risks despite fewer detected attacks - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5ecd8c2f6753885d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi5AFBVV95cUxNQ3U0dFNZYVZ5T3F6TWdfeVVXVWQ5VlktcmtHSlRmOENWWVdRZjQ0SXZkX2NwSVVZQXhOT0RnSi1MZEZIQUVVSFNJcklhcEF6Mlh4RVNXU3BrZUhkZzNJSUJ0bjBSSVVQM18zdDVmNGNOQkN4UnNMWEJLQks4R1kzWWpsM3hHYjBMWDkwSWd6M25XRlNjMlBrMnhBb0JRZGQzTDdjR0k2dWxqZDlYMlB3Mi04WEgyUnBvRGpZakRKNEhhRWhsd2VrVHktSlVBUUszenJmQ2dPc1ZzcG1TUG1aak1BMDU?oc=5","published_at":"2026-07-29T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"SonicWall warns OT/IT convergence expanding manufacturing cybersecurity risks despite fewer detected attacks&nbsp;&nbsp;Industrial Cyber","title":"SonicWall warns OT/IT convergence expanding manufacturing cybersecurity risks despite fewer detected attacks - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-11ab04766c0f7433","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi0AFBVV95cUxQQTlITV9pWXVSdWF6WVdDSDA2ZmVUd0o5UnlQSUJ3cFZNREtJaU42RFR5dnIwZEJMcmg0THZ4bHV3UkVTUlhxajVaQ2tsVWFvbHFHeWFqSzF2Y01tMy13RTM3X1J5RkpEalB0aUN4eDJRcUhNaHRrQ1VtbDVDRXdHd0hSUUZyTlpBOHlSVFJJbXhGQlRhbWpHbnhPUnhfNmZzZmJsMHVWaDkwRWt2TkpkbVV4LVpMckZ2bGpuOXQ2bWJvQkNXQkZEYXhjZkx6R2Z6?oc=5","published_at":"2026-07-29T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Iranian Hackers Exploited Unpatchable PLC Flaw to Breach 30 Minnesota Water Systems&nbsp;&nbsp;Tech Times","title":"Iranian Hackers Exploited Unpatchable PLC Flaw to Breach 30 Minnesota Water Systems - Tech Times"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4c915e24e4a62ba5","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi0wFBVV95cUxQZjM1ZXpTbEtIRWtxMlFNSmpab1psbmhmVjNZQ3JaQzVmWkYyM0s1Q1BaQ0FaejJ5eHQ0ZXNyemJITDBaWW1FaWZfeE5hWlJJanA3WmVoZUlVUWFWT3Y0MWNWQk45dnVxelhVMndoRkhGbG1oTTdaZnZOdXF0V3lmREdUOUk0azFjNy1MelFnYWxMNG9GOXhmVk5zaXZPSEt4RUt3Z0J0R1BwLUNoMFZjenpuVTRLemZsUzZ5OEFtWGdVUVpaeFBNbUlNclo4Skx1Y0Nj?oc=5","published_at":"2026-07-29T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"China and Iran Are Already Inside US Grids: CISA Demands Tested Isolation Plans&nbsp;&nbsp;Tech Times","title":"China and Iran Are Already Inside US Grids: CISA Demands Tested Isolation Plans - Tech Times"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5e9df40a9dbaeaac","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiswFBVV95cUxQVlE5dV95SEt4YmRxSTZPazZ1ODgzSU0wS25VbHFZZkhuOFNEV2ptNDU3bmQ4LXdsX2dfNjhVVlZ2eFRSWDY5TGw5bmhtb2tFNDIzbF9KQUZhVjRxRnpoVDIxaHpGNHJpaTRIc0RpZUpYek9nMTFqeU1yem44c29wczU4c1p0NkFfb1hqdUc1NlhjMWZBblNFaXRFU2R3RlVpeEF4aC1EZXFKTlZOTFdwSWtUQQ?oc=5","published_at":"2026-07-28T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Coordinated \u201ccyberattack\u201d on Minnesota water utilities: What you need to know&nbsp;&nbsp;Security Boulevard","title":"Coordinated \u201ccyberattack\u201d on Minnesota water utilities: What you need to know - Security Boulevard"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-95dd6e73561e0ee3","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiswFBVV95cUxQVlE5dV95SEt4YmRxSTZPazZ1ODgzSU0wS25VbHFZZkhuOFNEV2ptNDU3bmQ4LXdsX2dfNjhVVlZ2eFRSWDY5TGw5bmhtb2tFNDIzbF9KQUZhVjRxRnpoVDIxaHpGNHJpaTRIc0RpZUpYek9nMTFqeU1yem44c29wczU4c1p0NkFfb1hqdUc1NlhjMWZBblNFaXRFU2R3RlVpeEF4aC1EZXFKTlZOTFdwSWtUQQ?oc=5","published_at":"2026-07-28T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Coordinated \u201ccyberattack\u201d on Minnesota water utilities: What you need to know&nbsp;&nbsp;securityboulevard.com","title":"Coordinated \u201ccyberattack\u201d on Minnesota water utilities: What you need to know - securityboulevard.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-b67b8fdc07bcbc9a","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiuAFBVV95cUxOdHRXX3RXT1pIS2NxeVAwNVExY3NlUGI1MWNwS0cwTHA2QzFKcUNpeE9GcEdxRTkwZkZmSUpXb3VIclRCT3pTeHQwSXVzZlZVWTA4VnRQSE1ET0o3VExZbU9JSUN5bzlwR1kzTS02M0ZFTFBjWHlwWjhoSmFYVUpaLWREM1JwaE01T3NHZGxNc3hVVGdDNWpFTGhJWXh5VHZpZGpFanhpbXV2UnpjR3Z1bHVkMzZCQmRH?oc=5","published_at":"2026-07-28T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"ASD to critical infrastructure ops: be ready to isolate systems for three months&nbsp;&nbsp;iTnews","title":"ASD to critical infrastructure ops: be ready to isolate systems for three months - iTnews"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-071e4a8f976d6224","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiZkFVX3lxTE1UMjZYMzFnV1ppRG5VbXgtcjhNUWRmS0x6bzJuZ0s4ZUZac1Q2WWhDZ0Q0QVRYMzREekVEU3lDTjUwdkdITHNPdDliVWQ5VkhSWmNnVmEwNlVBYzVGRTVEQ0gxZGxrZw?oc=5","published_at":"2026-07-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Turn cybersecurity into a high-value business function with Sophos CISO Advantage&nbsp;&nbsp;Sophos","title":"Turn cybersecurity into a high-value business function with Sophos CISO Advantage - Sophos"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-a0a212ef4fe446a4","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiZkFVX3lxTE5pYW9qbUpEakFRcHcxODV0aHc3UXlxXzYtSEthSlljSS1EWURXMl9USFBXWGJMc25RUERoUElqOVlXeVZ1dDdZaGl0R1kxTjN5ay1qWHdTQWZPQW15dV94bWxUYWxrd9IBa0FVX3lxTE9PRmVDSTBUTHN3c3Q4b05SYzVoWUtrd2tkdzlqSWhxeWk3Y0htLU9hdm5FRHVNYmpOS3BuUjZVSTBiWDBDX0J0Zkp5WjJ6VDFoaVpwUFFpaEdacG9GSXprTXVKZXhOdE84cm9Z?oc=5","published_at":"2026-07-27T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure&nbsp;&nbsp;gbhackers.com","title":"Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure - gbhackers.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-60b791290f39ee73","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiZkFVX3lxTE1UMjZYMzFnV1ppRG5VbXgtcjhNUWRmS0x6bzJuZ0s4ZUZac1Q2WWhDZ0Q0QVRYMzREekVEU3lDTjUwdkdITHNPdDliVWQ5VkhSWmNnVmEwNlVBYzVGRTVEQ0gxZGxrZw?oc=5","published_at":"2026-07-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Turn cybersecurity into a high-value business function with Sophos CISO Advantage&nbsp;&nbsp;sophos.com","title":"Turn cybersecurity into a high-value business function with Sophos CISO Advantage - sophos.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-02c4ccce13e30e7f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitwFBVV95cUxQcGxsNGg1dFUyVnZmRjBwWnlsVEhaQklreWthMGpzUDBwUFVBUThCblJacEZxREp0VFFVY1F3WFY2bURjVHJtMF9JOTJnSWFReEt1RFFfZUhsaHQxak1DZk9kWjBobFJhSTVreHBEcnRpc21NZTVZQU1HaUF3YWl5ek9ua25GR1FhaDF0QWEyX3VMcnh1MUg2ZzZ5UFlfUUNxdVRvLWo2NzRFRjJqc2hJM19kaGdQY28?oc=5","published_at":"2026-07-24T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"The most vulnerable AI products are also some of the most commonly exposed online&nbsp;&nbsp;Cybersecurity Dive","title":"The most vulnerable AI products are also some of the most commonly exposed online - Cybersecurity Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2bd015fa3b9e4900","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitwFBVV95cUxQcGxsNGg1dFUyVnZmRjBwWnlsVEhaQklreWthMGpzUDBwUFVBUThCblJacEZxREp0VFFVY1F3WFY2bURjVHJtMF9JOTJnSWFReEt1RFFfZUhsaHQxak1DZk9kWjBobFJhSTVreHBEcnRpc21NZTVZQU1HaUF3YWl5ek9ua25GR1FhaDF0QWEyX3VMcnh1MUg2ZzZ5UFlfUUNxdVRvLWo2NzRFRjJqc2hJM19kaGdQY28?oc=5","published_at":"2026-07-24T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"The most vulnerable AI products are also some of the most commonly exposed online&nbsp;&nbsp;cybersecuritydive.com","title":"The most vulnerable AI products are also some of the most commonly exposed online - cybersecuritydive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-894760fe9f8347ae","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi-gFBVV95cUxNWGpjRG9XMll2eTMzdVByTTRXUTJHclBYMllXN1VkbjdLQ0RRSzhBbDB5WGpxQVJmOEFJRlFYdFF0Tk9qc0xGWmFWOFJkZDREdzBwTGpjMzNYOE13NWFwUTBwNHlIdmVNaERyVkk1SVBxVnV5X1YxdU9iUkNBRHFlZEh4UWY4UVpCeUVTT05xai1sTzZoWW5oYmh4SVRDVWdHVDIzdTY4MlVfQldxT1B6cTllRF9lQXdSeHg4S1Z5S0wyNnVWTkx0SWZuYkpfald3NzJsOWtkd3E2WWRMMDdwdlBfWVVwNU9mUHk2Yml6X0lrX0RfYU44M1FB?oc=5","published_at":"2026-07-24T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"US agencies update advisory on Iranian cyber campaign targeting internet-connected PLCs in critical infrastructure&nbsp;&nbsp;industrialcyber.co","title":"US agencies update advisory on Iranian cyber campaign targeting internet-connected PLCs in critical infrastructure - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-cfc473d638d342c8","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi-gFBVV95cUxNWGpjRG9XMll2eTMzdVByTTRXUTJHclBYMllXN1VkbjdLQ0RRSzhBbDB5WGpxQVJmOEFJRlFYdFF0Tk9qc0xGWmFWOFJkZDREdzBwTGpjMzNYOE13NWFwUTBwNHlIdmVNaERyVkk1SVBxVnV5X1YxdU9iUkNBRHFlZEh4UWY4UVpCeUVTT05xai1sTzZoWW5oYmh4SVRDVWdHVDIzdTY4MlVfQldxT1B6cTllRF9lQXdSeHg4S1Z5S0wyNnVWTkx0SWZuYkpfald3NzJsOWtkd3E2WWRMMDdwdlBfWVVwNU9mUHk2Yml6X0lrX0RfYU44M1FB?oc=5","published_at":"2026-07-24T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"US agencies update advisory on Iranian cyber campaign targeting internet-connected PLCs in critical infrastructure&nbsp;&nbsp;Industrial Cyber","title":"US agencies update advisory on Iranian cyber campaign targeting internet-connected PLCs in critical infrastructure - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b7c56d2d5739b0f3","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxNMkV4Z3p0LU9TbjRsWVg5alIxVUREaDQyYlQzR2NtelNEOTBkUzVjQzk3STZUYWZUOVpJcDNJVXhNLVh5d3NnVG9LVW5yYWtrOUsydkFvaGVMblRQWVdmc2VmT205VkQ5WGdJSmp6QnJYUU1fY3BoZWtpb3hicnNkQktudVQ?oc=5","published_at":"2026-07-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"ANCHOR-CI could fix 20 years of broken government-industry collaboration&nbsp;&nbsp;cyberscoop.com","title":"ANCHOR-CI could fix 20 years of broken government-industry collaboration - cyberscoop.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-454269b50c170c99","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMic0FVX3lxTFBWc2paTkU2RlhJNURaSW9VUUtIWkpEX09fT0lsS0o5Ym53Vno0bE1adkI0YWd6d0EyUEttbnA4eWlXWEt1Y0tuVG5JeGpSZmhGc3lrbEp5WmZOZXo1Slptc1NaQ3lZazRXR0N1S3J3Wk56VjjSAXhBVV95cUxNMFJuTkZCWkJ2VV94QmlGSXNqSEpNVmNwQ3Nua3NNTWNUSzBqU09KN1RoVUpSZk5nRTJpcDFVWDh5Z1dLQkhJWEZyUk56QXA3NjNBTk1rUEQ0UXBFam1HaWktN0U0MF8tbFh1UV9NSDJ0TWtoRGZDcEY?oc=5","published_at":"2026-07-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure&nbsp;&nbsp;CyberSecurityNews","title":"CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-a50f05ea711c6eca","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMic0FVX3lxTFBWc2paTkU2RlhJNURaSW9VUUtIWkpEX09fT0lsS0o5Ym53Vno0bE1adkI0YWd6d0EyUEttbnA4eWlXWEt1Y0tuVG5JeGpSZmhGc3lrbEp5WmZOZXo1Slptc1NaQ3lZazRXR0N1S3J3Wk56VjjSAXhBVV95cUxNMFJuTkZCWkJ2VV94QmlGSXNqSEpNVmNwQ3Nua3NNTWNUSzBqU09KN1RoVUpSZk5nRTJpcDFVWDh5Z1dLQkhJWEZyUk56QXA3NjNBTk1rUEQ0UXBFam1HaWktN0U0MF8tbFh1UV9NSDJ0TWtoRGZDcEY?oc=5","published_at":"2026-07-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure&nbsp;&nbsp;cybersecuritynews.com","title":"CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure - cybersecuritynews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-882c5b7ff0f70679","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikgFBVV95cUxNaEEwcVlEVFQ2dUF2T2RTQmdWTDFkcGNUR3ZHWkxTWkJtLUIzb3Z5TndiRFRNVnppNFpJVjF3aVdQcl9UNU5ZQjNvUUp5b1FxTmJOMDRvQmZGeVEzdVBqQ3hFWTk3Y1JxV1BTRzNfNjg2T0ZOd0hYaEVYMjJLWnNDRmtFRk1XMlhTS0pvczVqZ0t1dw?oc=5","published_at":"2026-07-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA, FBI warn that Iran-linked hackers are expanding target set for water, energy&nbsp;&nbsp;Cybersecurity Dive","title":"CISA, FBI warn that Iran-linked hackers are expanding target set for water, energy - Cybersecurity Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-8c9de5b4c4dbfd3f","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi0wFBVV95cUxPaUFYMFdGaGxtaHRWSFB1N1RmWHhTT1RBeDFXYkxpRkF3amJPTFNxM2RHRXAwOFdCZTA5ZW5UX0I1WEt5bllnTGNpTjJOcjVRLW9LUkRKMDVKRW9VWlVzVC1sOVFLZTEzaVcxZ1g4all3WEpVVGJ5bHNmcjlJQUhGaGY3V09sRVNjM1A0ZE5WMjdvT1AwaTdxQy1FblRIQURKTVlBRDhYT0JkRjNZamVORmVqd003bGlMQkJMeUc2ZEZ2NjNCc0stYk5JQjRFWGtsaWtJ?oc=5","published_at":"2026-07-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Iranian Hackers Infiltrate Siemens and Schneider PLCs, Blinding Operators With Fake Readings&nbsp;&nbsp;techtimes.com","title":"Iranian Hackers Infiltrate Siemens and Schneider PLCs, Blinding Operators With Fake Readings - techtimes.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f665d4e08f4adab3","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikgFBVV95cUxNaEEwcVlEVFQ2dUF2T2RTQmdWTDFkcGNUR3ZHWkxTWkJtLUIzb3Z5TndiRFRNVnppNFpJVjF3aVdQcl9UNU5ZQjNvUUp5b1FxTmJOMDRvQmZGeVEzdVBqQ3hFWTk3Y1JxV1BTRzNfNjg2T0ZOd0hYaEVYMjJLWnNDRmtFRk1XMlhTS0pvczVqZ0t1dw?oc=5","published_at":"2026-07-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA, FBI warn that Iran-linked hackers are expanding target set for water, energy&nbsp;&nbsp;cybersecuritydive.com","title":"CISA, FBI warn that Iran-linked hackers are expanding target set for water, energy - cybersecuritydive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-bea76b37288b1cb4","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuwFBVV95cUxPSGVnVi1JZmk4NFh3Ql93TVhTNFh0ZGs0ZE5QMFBEMlRDZFJnOG1rSTJPNzFBZkxCYVhfdGJCcUIzanpZRXFWUGxxOHMwaFNMczF0S2R1VkN4NTZmRWtzcUdTR3hEcVcxNUp6dnlCVDdxTUdmN3pzM3RkbHlwUVE5b1gtZVJGRVZMYngwUDYycUZQZVJadHg2YmdhNUkwR3hoVnM5WWdiSHNEQ0xZaGNZbWNRT3RGVVcwMndv?oc=5","published_at":"2026-07-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Iran-linked crews are probing more flavors of US industrial kit&nbsp;&nbsp;theregister.com","title":"Iran-linked crews are probing more flavors of US industrial kit - theregister.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2cceff3f9cb5b99c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuwFBVV95cUxPSGVnVi1JZmk4NFh3Ql93TVhTNFh0ZGs0ZE5QMFBEMlRDZFJnOG1rSTJPNzFBZkxCYVhfdGJCcUIzanpZRXFWUGxxOHMwaFNMczF0S2R1VkN4NTZmRWtzcUdTR3hEcVcxNUp6dnlCVDdxTUdmN3pzM3RkbHlwUVE5b1gtZVJGRVZMYngwUDYycUZQZVJadHg2YmdhNUkwR3hoVnM5WWdiSHNEQ0xZaGNZbWNRT3RGVVcwMndv?oc=5","published_at":"2026-07-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Iran-linked crews are probing more flavors of US industrial kit&nbsp;&nbsp;The Register","title":"Iran-linked crews are probing more flavors of US industrial kit - The Register"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-e21ff0a480c682fd","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi4wFBVV95cUxNUVFvWmZac1htVGRXNWRkNHF1UzZydzU0ZE1wdktLWnIxLVpIMGhqSnhRZzE2MmxGQ2hMSVJOUnpoSTdhM3lvazNQX2JlQjM5dzNPOEV3bTg2c252SXRwNjRnT1MxVnB0dFZoNlhfVTQ3cW1haHBrYTl4RUlNYk5pYldRTFhMQjJ0ZmpydzlxMGhmNnl6VUxDQ2djaDNGaGFBQ3NvQ3p0dmtBRGhzMWZPZmlsTE1TTXItVFRvaWJVRXN6LVllNWpjZ3hPNlNoTjRlRkd0aUlvZ2hVeE02NzZuUmxwTQ?oc=5","published_at":"2026-07-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Active Exploitation Alert: Iranian State-Sponsored Attacks Targeting Siemens, Schneider Electric, and Rockwell Automation ICS Devices in US Critical Infrastructure&nbsp;&nbsp;Rescana","title":"Active Exploitation Alert: Iranian State-Sponsored Attacks Targeting Siemens, Schneider Electric, and Rockwell Automation ICS Devices in US Critical Infrastructure - Rescana"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-aa7aadaff96c8a25","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMirwFBVV95cUxPTHRoWVNXcmJnaEdDRmJmbHRXdC1Lb3hJSXhpRDFsbGE4Z1hQa29pdk9Wa281Vnc0cUoxRkc1MktfMTBSZFlSTUtHVFE5Vkdwck5JNmFrSlR3UFB5cWxXWDg2b2YzR2V5SXJCeEdOX25BSXlIWnhrRnFoOFVFUFJrbVdWMXFUbnhCZnpXU3pYX2ZHSzg2ZkZjYUJ5UEpVcjNkWldQVXpqaEU0NGVXSGhJ0gG0AUFVX3lxTE9lcElPbEhzek9pXzJrYW5ZRlhjRkZFaXJXRjdJTjN0c1lndFp3R1RWbHI3QVlzVUh3Q0k2Vy1xdUxWZ1ppb29nUFZ1akpjVVRXMjZWSWRPNVpVUUZOcnliUDNBOGVUSFFieUxkaVN6WVZMcW1GOWZKS1gwM0Ywa0hJZ2U5R1FDOGhaQ3A4Z0pKTWw2ZTVnQlVzdU5CV3V5dXJndGRaNzU0R3F5YXc0M2tSRkNNNg?oc=5","published_at":"2026-07-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices&nbsp;&nbsp;securityweek.com","title":"US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-4db95b6eaef10746","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMirwFBVV95cUxPTHRoWVNXcmJnaEdDRmJmbHRXdC1Lb3hJSXhpRDFsbGE4Z1hQa29pdk9Wa281Vnc0cUoxRkc1MktfMTBSZFlSTUtHVFE5Vkdwck5JNmFrSlR3UFB5cWxXWDg2b2YzR2V5SXJCeEdOX25BSXlIWnhrRnFoOFVFUFJrbVdWMXFUbnhCZnpXU3pYX2ZHSzg2ZkZjYUJ5UEpVcjNkWldQVXpqaEU0NGVXSGhJ0gG0AUFVX3lxTE9lcElPbEhzek9pXzJrYW5ZRlhjRkZFaXJXRjdJTjN0c1lndFp3R1RWbHI3QVlzVUh3Q0k2Vy1xdUxWZ1ppb29nUFZ1akpjVVRXMjZWSWRPNVpVUUZOcnliUDNBOGVUSFFieUxkaVN6WVZMcW1GOWZKS1gwM0Ywa0hJZ2U5R1FDOGhaQ3A4Z0pKTWw2ZTVnQlVzdU5CV3V5dXJndGRaNzU0R3F5YXc0M2tSRkNNNg?oc=5","published_at":"2026-07-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices&nbsp;&nbsp;SecurityWeek","title":"US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-b8a2a3e7a9dbbacb","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi4wFBVV95cUxNUVFvWmZac1htVGRXNWRkNHF1UzZydzU0ZE1wdktLWnIxLVpIMGhqSnhRZzE2MmxGQ2hMSVJOUnpoSTdhM3lvazNQX2JlQjM5dzNPOEV3bTg2c252SXRwNjRnT1MxVnB0dFZoNlhfVTQ3cW1haHBrYTl4RUlNYk5pYldRTFhMQjJ0ZmpydzlxMGhmNnl6VUxDQ2djaDNGaGFBQ3NvQ3p0dmtBRGhzMWZPZmlsTE1TTXItVFRvaWJVRXN6LVllNWpjZ3hPNlNoTjRlRkd0aUlvZ2hVeE02NzZuUmxwTQ?oc=5","published_at":"2026-07-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Active Exploitation Alert: Iranian State-Sponsored Attacks Targeting Siemens, Schneider Electric, and Rockwell Automation ICS Devices in US Critical Infrastructure&nbsp;&nbsp;rescana.com","title":"Active Exploitation Alert: Iranian State-Sponsored Attacks Targeting Siemens, Schneider Electric, and Rockwell Automation ICS Devices in US Critical Infrastructure - rescana.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7d937513ca9c52ec","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxQbG81MVhON3ZSZE5TdHNlZk1NdktieWxITWVDNUFpM0Rxd1pIX2tkdk9kYXc2MU9RNjlLRUZRdGtSVG5WUjVFWGpCUXQ4bXlXQm9YWkdQeGZyWEJaempDdHROQXdHTmhSamtVZWtPRVR5T09pU3Zqd2ptVWtKODZ3NlVoRQ?oc=5","published_at":"2026-07-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Iranian Hackers Target Siemens and Schneider Industrial Systems, CISA Warns&nbsp;&nbsp;Infosecurity Magazine","title":"Iranian Hackers Target Siemens and Schneider Industrial Systems, CISA Warns - Infosecurity Magazine"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-661cbfede84d21a1","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxNMkV4Z3p0LU9TbjRsWVg5alIxVUREaDQyYlQzR2NtelNEOTBkUzVjQzk3STZUYWZUOVpJcDNJVXhNLVh5d3NnVG9LVW5yYWtrOUsydkFvaGVMblRQWVdmc2VmT205VkQ5WGdJSmp6QnJYUU1fY3BoZWtpb3hicnNkQktudVQ?oc=5","published_at":"2026-07-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"ANCHOR-CI could fix 20 years of broken government-industry collaboration&nbsp;&nbsp;CyberScoop","title":"ANCHOR-CI could fix 20 years of broken government-industry collaboration - CyberScoop"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9fe6f7cc6f6d17d1","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxQbG81MVhON3ZSZE5TdHNlZk1NdktieWxITWVDNUFpM0Rxd1pIX2tkdk9kYXc2MU9RNjlLRUZRdGtSVG5WUjVFWGpCUXQ4bXlXQm9YWkdQeGZyWEJaempDdHROQXdHTmhSamtVZWtPRVR5T09pU3Zqd2ptVWtKODZ3NlVoRQ?oc=5","published_at":"2026-07-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Iranian Hackers Target Siemens and Schneider Industrial Systems, CISA Warns&nbsp;&nbsp;infosecurity-magazine.com","title":"Iranian Hackers Target Siemens and Schneider Industrial Systems, CISA Warns - infosecurity-magazine.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-79e2d7a2bd153598","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimwFBVV95cUxPM1d5SF9DdUNmbEt2Q2cteHRtRjNvN2N2TzJPVXpSaEtJMXVkVExJbWpFZE5YUEtJVjBhWmppc1AxYzEzQkVKeGlsamJMS3JyWFlwRDZVMHhrTnhPMjQ2QkxqRXNVNHpBSXFDTE9uaExpeU5JNHJ6ODR2YWF2YkM4eFNrZFljY0hJV2dHSmpwNGtiVHNmVGQ0cjJhMA?oc=5","published_at":"2026-07-22T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"U.S. Issues Cybersecurity Warning for Building Automation Protocol&nbsp;&nbsp;inside.lighting","title":"U.S. Issues Cybersecurity Warning for Building Automation Protocol - inside.lighting"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-ffcbf6cccdef3a2f","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMifEFVX3lxTE5FWW9NakxkbEFtNVZiRVFoS21WS3c1cUx1emxucDhIdmgyc3FCUnpPdEk5dm5hSDVlVXJ3ZmZobTFHSGhSaVFKSzJEd2pQNHpCV1ZuV3VpZnhLMUdNUmp3QXlfMkJKSy03YjQycjJiWm5DbmJRc0cwMVdoQjHSAYIBQVVfeXFMTWFod2Z0VjJSd3pKeGFvdFFwbWVCaVNpUGNEaWlQYXFwRDk1Mkg4VFVFRTNnYmlmSldWQUs1c2h2Yldlak9ndDdIMnR3YkhkdDR2eXp1ejZGT3h6Z1RGWk1GdUI2bER6Uld3a2hOTTlkX2NRQ09ReE9sU1hlelpDN2xGQQ?oc=5","published_at":"2026-07-22T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"ServiceNow CEO defends the company's relevancy, touting a kill switch for rogue AI agents&nbsp;&nbsp;cnbc.com","title":"ServiceNow CEO defends the company's relevancy, touting a kill switch for rogue AI agents - cnbc.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-e7c4c8d7f26963ff","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMifEFVX3lxTE5FWW9NakxkbEFtNVZiRVFoS21WS3c1cUx1emxucDhIdmgyc3FCUnpPdEk5dm5hSDVlVXJ3ZmZobTFHSGhSaVFKSzJEd2pQNHpCV1ZuV3VpZnhLMUdNUmp3QXlfMkJKSy03YjQycjJiWm5DbmJRc0cwMVdoQjHSAYIBQVVfeXFMTWFod2Z0VjJSd3pKeGFvdFFwbWVCaVNpUGNEaWlQYXFwRDk1Mkg4VFVFRTNnYmlmSldWQUs1c2h2Yldlak9ndDdIMnR3YkhkdDR2eXp1ejZGT3h6Z1RGWk1GdUI2bER6Uld3a2hOTTlkX2NRQ09ReE9sU1hlelpDN2xGQQ?oc=5","published_at":"2026-07-22T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"ServiceNow CEO defends the company's relevancy, touting a kill switch for rogue AI agents&nbsp;&nbsp;CNBC","title":"ServiceNow CEO defends the company's relevancy, touting a kill switch for rogue AI agents - CNBC"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5f6c0224c7cfb7b3","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimwFBVV95cUxPM1d5SF9DdUNmbEt2Q2cteHRtRjNvN2N2TzJPVXpSaEtJMXVkVExJbWpFZE5YUEtJVjBhWmppc1AxYzEzQkVKeGlsamJMS3JyWFlwRDZVMHhrTnhPMjQ2QkxqRXNVNHpBSXFDTE9uaExpeU5JNHJ6ODR2YWF2YkM4eFNrZFljY0hJV2dHSmpwNGtiVHNmVGQ0cjJhMA?oc=5","published_at":"2026-07-22T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"U.S. Issues Cybersecurity Warning for Building Automation Protocol&nbsp;&nbsp;Inside Lighting","title":"U.S. Issues Cybersecurity Warning for Building Automation Protocol - Inside Lighting"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-49b17fb53546d851","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiY0FVX3lxTE5fYWU2VU0zY3BxdzBvQ3NtNVZRSmV1bFlUcGRBUTNjWEQwWVl4RVR4bkFJdGQ5SVh0NnRkcVpEdGx0SW5BenNRNURVZGllN2JSMHloLS1UOExsVlo0OGlicWZUd9IBaEFVX3lxTE9tcmgzbGNaOGJVUlFJTGhIN0xTZ09CMEo0MXA5ZTlOSXBYQWZreU0yWlFmSGdmaUdnd0xwVjNzdUlDd05fQlFrNnA3VnptVkhYeEM3S21wSDFGcTdhNVhyVTJKMFZTZDND?oc=5","published_at":"2026-07-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"Gemini 3.5 Flash Cyber With Automated Faster Vulnerability Detection and Patch Capabilities&nbsp;&nbsp;cybersecuritynews.com","title":"Gemini 3.5 Flash Cyber With Automated Faster Vulnerability Detection and Patch Capabilities - cybersecuritynews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-29e057095eef6a1e","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimgFBVV95cUxQVXJQY2NJRG0tY3pQU1pZQWtqS1NhSkpCQWs2eWFSc2t2ZHN3U2I1emVoVy1hVVY3aXNfOEI3eEZndnNCOU9fbXl2SGtZb2dWNEZBWnM1Nk5vemlxY1hIRDlFUzhCaEJqZ2ZKTU5RS19vaS1iS21xTDhrWTc4Y2NqZ0kzQkw1djNQM2tES1I0NjJOV3hnMFpXdVVn?oc=5","published_at":"2026-07-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Latest Guard-led Cyber Shield exercise is focused on protecting the power sector, including OT&nbsp;&nbsp;DefenseScoop","title":"Latest Guard-led Cyber Shield exercise is focused on protecting the power sector, including OT - DefenseScoop"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7cece3d274b18f05","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimgFBVV95cUxQVXJQY2NJRG0tY3pQU1pZQWtqS1NhSkpCQWs2eWFSc2t2ZHN3U2I1emVoVy1hVVY3aXNfOEI3eEZndnNCOU9fbXl2SGtZb2dWNEZBWnM1Nk5vemlxY1hIRDlFUzhCaEJqZ2ZKTU5RS19vaS1iS21xTDhrWTc4Y2NqZ0kzQkw1djNQM2tES1I0NjJOV3hnMFpXdVVn?oc=5","published_at":"2026-07-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Latest Guard-led Cyber Shield exercise is focused on protecting the power sector, including OT&nbsp;&nbsp;defensescoop.com","title":"Latest Guard-led Cyber Shield exercise is focused on protecting the power sector, including OT - defensescoop.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a5710e4a67e6c41f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiY0FVX3lxTE5fYWU2VU0zY3BxdzBvQ3NtNVZRSmV1bFlUcGRBUTNjWEQwWVl4RVR4bkFJdGQ5SVh0NnRkcVpEdGx0SW5BenNRNURVZGllN2JSMHloLS1UOExsVlo0OGlicWZUd9IBaEFVX3lxTE9tcmgzbGNaOGJVUlFJTGhIN0xTZ09CMEo0MXA5ZTlOSXBYQWZreU0yWlFmSGdmaUdnd0xwVjNzdUlDd05fQlFrNnA3VnptVkhYeEM3S21wSDFGcTdhNVhyVTJKMFZTZDND?oc=5","published_at":"2026-07-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"Gemini 3.5 Flash Cyber With Automated Faster Vulnerability Detection and Patch Capabilities&nbsp;&nbsp;CyberSecurityNews","title":"Gemini 3.5 Flash Cyber With Automated Faster Vulnerability Detection and Patch Capabilities - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d46dadca45435a90","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMizAFBVV95cUxOMUVIZ3c1TENWYnZaeDRWeGtlR1BQRjEzOWlwZHEtS0tuUm9QQlhCX2hlNEZNQ2pGOFAyYy1fWFltM0ZpUzgzaERLMllZZzNoQ2lPd0JLZGJDQjB3WWs0UVZnd2pnc2Z3X0x6Zm1IVWVLcGtFTHNHS1ViZmRGdU9xWDFaRnZ5ZDRmaVFJWEh4OEEydlIzN2JrcElpT3pLQjlMTm5KZE9RSGNPeko2bGlzaVl0UGJjanVwQkxNWGxmWGR5QmdjY2w2MVJqVU4?oc=5","published_at":"2026-07-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Active Attacks on KNX Smart Building Protocol Leave Hardware Permanently Bricked&nbsp;&nbsp;techtimes.com","title":"Active Attacks on KNX Smart Building Protocol Leave Hardware Permanently Bricked - techtimes.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-0c22d40413d08e51","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMizAFBVV95cUxOMUVIZ3c1TENWYnZaeDRWeGtlR1BQRjEzOWlwZHEtS0tuUm9QQlhCX2hlNEZNQ2pGOFAyYy1fWFltM0ZpUzgzaERLMllZZzNoQ2lPd0JLZGJDQjB3WWs0UVZnd2pnc2Z3X0x6Zm1IVWVLcGtFTHNHS1ViZmRGdU9xWDFaRnZ5ZDRmaVFJWEh4OEEydlIzN2JrcElpT3pLQjlMTm5KZE9RSGNPeko2bGlzaVl0UGJjanVwQkxNWGxmWGR5QmdjY2w2MVJqVU4?oc=5","published_at":"2026-07-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Active Attacks on KNX Smart Building Protocol Leave Hardware Permanently Bricked&nbsp;&nbsp;Tech Times","title":"Active Attacks on KNX Smart Building Protocol Leave Hardware Permanently Bricked - Tech Times"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-238908885947b305","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMizwFBVV95cUxNVzVfQ1FvNHZ4Vmh1V25aOWFuSFBqT2JSOWRoNEVUUmRNTmJlT0ViZmJnYmRaV19UeDFvVVpPVkcxY09ad01vS1dDdUJxUjVBWXZtRVdyMFBQVnE1U3lvWXpvUWloUW9rR3hyNTJuY1l1S2dnQ2kxV2hKQUx3eko2NWZ1Uk1uU3k0WjhxNTFRb3Jla0EtM2pIS1RxZEtHaWZlT1ZmazdVQlBFWkZGYmZNZ2hCcUhTX1lnNTluc1V5dEttTjBsN1RCSWxaRENmbFk?oc=5","published_at":"2026-07-17T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Unauthenticated Debug Port in Rockwell Adapter Gives Attackers Plant-Floor Control&nbsp;&nbsp;techtimes.com","title":"Unauthenticated Debug Port in Rockwell Adapter Gives Attackers Plant-Floor Control - techtimes.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-7ae7ef99a15504d7","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMizwFBVV95cUxNVzVfQ1FvNHZ4Vmh1V25aOWFuSFBqT2JSOWRoNEVUUmRNTmJlT0ViZmJnYmRaV19UeDFvVVpPVkcxY09ad01vS1dDdUJxUjVBWXZtRVdyMFBQVnE1U3lvWXpvUWloUW9rR3hyNTJuY1l1S2dnQ2kxV2hKQUx3eko2NWZ1Uk1uU3k0WjhxNTFRb3Jla0EtM2pIS1RxZEtHaWZlT1ZmazdVQlBFWkZGYmZNZ2hCcUhTX1lnNTluc1V5dEttTjBsN1RCSWxaRENmbFk?oc=5","published_at":"2026-07-17T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Unauthenticated Debug Port in Rockwell Adapter Gives Attackers Plant-Floor Control&nbsp;&nbsp;Tech Times","title":"Unauthenticated Debug Port in Rockwell Adapter Gives Attackers Plant-Floor Control - Tech Times"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-0b7725ab891cd8e3","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiZ0FVX3lxTE1tWFJjOU4zdENXd3c0bzByczNTUG9UZ3RCSnhwS01vWkowb3FHdlRYbWJ1VjdSemlRMXlvaW51SVE5My1Xam5lOExSMXlPUVZsU0MydnIwX3dOb1R6ajEzOUtXckhMbDg?oc=5","published_at":"2026-07-16T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"Moxa Achieves IEC 62443-4-1 Maturity Level 3 Industrial Cybersecurity Certification&nbsp;&nbsp;thelec.net","title":"Moxa Achieves IEC 62443-4-1 Maturity Level 3 Industrial Cybersecurity Certification - thelec.net"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a1517d5c8aa3ed31","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijwFBVV95cUxOWFdxOTgtaEh6aVotbTd0VEY4alYwNE9WaDZpeEJmYXB6NEtLOHBCYWFmVU9tTmpFemdlOWdtZ082aGN4SjVBRWNzVjE2c1F5Y3FTNTFxUGcxWUk5dnRJdFBETW5iUVVvWnlUbXFvRmVsVW1jbllES1JBVTNNTEstZlh2ZUQ2RnFxcFZGXzRzYw?oc=5","published_at":"2026-07-14T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Cybersecurity budget changes for companies worldwide in 2026&nbsp;&nbsp;Statista","title":"Cybersecurity budget changes for companies worldwide in 2026 - Statista"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ac467c71ce0f4f28","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijwFBVV95cUxOWFdxOTgtaEh6aVotbTd0VEY4alYwNE9WaDZpeEJmYXB6NEtLOHBCYWFmVU9tTmpFemdlOWdtZ082aGN4SjVBRWNzVjE2c1F5Y3FTNTFxUGcxWUk5dnRJdFBETW5iUVVvWnlUbXFvRmVsVW1jbllES1JBVTNNTEstZlh2ZUQ2RnFxcFZGXzRzYw?oc=5","published_at":"2026-07-14T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Cybersecurity budget changes for companies worldwide in 2026&nbsp;&nbsp;statista.com","title":"Cybersecurity budget changes for companies worldwide in 2026 - statista.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f4c29d7e3399ded5","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxNUTY3cXB6T25saHM4SVo4TmVXZE9NN1ZkdXNKcWxVNzJkNXJHR0MyR3NLbTE0dEY2X2FWLVBYeUNQcmRtdG1GMjQzUnNkWGg2eklJTERRdEVUeWVNcjdSdHdicFNZaEczUndfRThXYkJwV3hydlB6MFRlYW43QzdHbjBTVUVrd2paak1JemVPYnpzdzZJMWhqSURPNzAtYVk2TkJ2Zk56LWh5d0k?oc=5","published_at":"2026-07-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"What Happens if China Hacks the U.S. Water Supply?&nbsp;&nbsp;hstoday.us","title":"What Happens if China Hacks the U.S. Water Supply? - hstoday.us"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-28192ac995d05550","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxNUTY3cXB6T25saHM4SVo4TmVXZE9NN1ZkdXNKcWxVNzJkNXJHR0MyR3NLbTE0dEY2X2FWLVBYeUNQcmRtdG1GMjQzUnNkWGg2eklJTERRdEVUeWVNcjdSdHdicFNZaEczUndfRThXYkJwV3hydlB6MFRlYW43QzdHbjBTVUVrd2paak1JemVPYnpzdzZJMWhqSURPNzAtYVk2TkJ2Zk56LWh5d0k?oc=5","published_at":"2026-07-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"What Happens if China Hacks the U.S. Water Supply? - HSToday&nbsp;&nbsp;hstoday.us","title":"What Happens if China Hacks the U.S. Water Supply? - HSToday - hstoday.us"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-696dc057f9ae1d60","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxNUTY3cXB6T25saHM4SVo4TmVXZE9NN1ZkdXNKcWxVNzJkNXJHR0MyR3NLbTE0dEY2X2FWLVBYeUNQcmRtdG1GMjQzUnNkWGg2eklJTERRdEVUeWVNcjdSdHdicFNZaEczUndfRThXYkJwV3hydlB6MFRlYW43QzdHbjBTVUVrd2paak1JemVPYnpzdzZJMWhqSURPNzAtYVk2TkJ2Zk56LWh5d0k?oc=5","published_at":"2026-07-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"What Happens if China Hacks the U.S. Water Supply? - HSToday&nbsp;&nbsp;Homeland Security Today","title":"What Happens if China Hacks the U.S. Water Supply? - HSToday - Homeland Security Today"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-02024e2da6196e79","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxNUTY3cXB6T25saHM4SVo4TmVXZE9NN1ZkdXNKcWxVNzJkNXJHR0MyR3NLbTE0dEY2X2FWLVBYeUNQcmRtdG1GMjQzUnNkWGg2eklJTERRdEVUeWVNcjdSdHdicFNZaEczUndfRThXYkJwV3hydlB6MFRlYW43QzdHbjBTVUVrd2paak1JemVPYnpzdzZJMWhqSURPNzAtYVk2TkJ2Zk56LWh5d0k?oc=5","published_at":"2026-07-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"What Happens if China Hacks the U.S. Water Supply?&nbsp;&nbsp;Homeland Security Today","title":"What Happens if China Hacks the U.S. Water Supply? - Homeland Security Today"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-82044a3c050f79ec","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxQRktTMHZYNHVoVExaWnVOOGdqTFd5Mm9qaHRWU18yUmlkVGozX2FSaWNQdEU1RnBNVE9sX2lRWkg2RkpVdWRSX21qeURBdjBneHRJazM4WkN5Q2FQQWNYNDk4RlR4R1hrbjdGX1pMZk82QmY0QXlCTWVZOEQ5aXhMeHFwcURTTXRCN0pPY3YyTTdnR2QxSXdVNHZ1N3ZnXzQ?oc=5","published_at":"2026-07-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out&nbsp;&nbsp;wired.com","title":"What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out - wired.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ada74a47ee7be373","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxQRktTMHZYNHVoVExaWnVOOGdqTFd5Mm9qaHRWU18yUmlkVGozX2FSaWNQdEU1RnBNVE9sX2lRWkg2RkpVdWRSX21qeURBdjBneHRJazM4WkN5Q2FQQWNYNDk4RlR4R1hrbjdGX1pMZk82QmY0QXlCTWVZOEQ5aXhMeHFwcURTTXRCN0pPY3YyTTdnR2QxSXdVNHZ1N3ZnXzQ?oc=5","published_at":"2026-07-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out&nbsp;&nbsp;WIRED","title":"What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out - WIRED"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-770cf23c9c213646","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMicEFVX3lxTE82ZlVablRiLTVBYTUtRExCWXpQSnBtSjVyY0lmZ0Nwa2RLc3JqdHU1NUpKNG9MS2FVRmxOby1tT0EwNXBjLWNDQmF3UlRnaFphNDFSN2JsTXkwMk81WVdIcHFwNzRTdm1EN1JIdE5UZVo?oc=5","published_at":"2026-07-07T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Threat landscape for industrial automation systems. Q1 2026&nbsp;&nbsp;Securelist","title":"Threat landscape for industrial automation systems. Q1 2026 - Securelist"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-3636fd5b557db394","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMicEFVX3lxTE82ZlVablRiLTVBYTUtRExCWXpQSnBtSjVyY0lmZ0Nwa2RLc3JqdHU1NUpKNG9MS2FVRmxOby1tT0EwNXBjLWNDQmF3UlRnaFphNDFSN2JsTXkwMk81WVdIcHFwNzRTdm1EN1JIdE5UZVo?oc=5","published_at":"2026-07-07T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Threat landscape for industrial automation systems. Q1 2026&nbsp;&nbsp;securelist.com","title":"Threat landscape for industrial automation systems. Q1 2026 - securelist.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-602c275ecf4abdf1","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitAFBVV95cUxPWnlLdHFEN0ZIT0ZXb1hlYk5qRDQ1TEVzZWxTc1I4TXJlOFZDUjZVRTZXekFhakx5c1M0eGdpRlE4RkxydVM1U3QteE5LeTFpU0ZDWDdLVENGV1p5VF9HMGVNNVN6Z0pVNS1BMHlUSDN5T3Y5UWFGQmVuM1cxUTBpQ2NfcXd0YlptWGFObS16TzZOdkYwSm1GSl9MbXc5TUFGaHp6eG5RVXFtY0I5c1Zpd21rTkzSAbwBQVVfeXFMUHZsVzRoREF5SGxVRFg5UDRyZlZpRWl0U01SWkxOa1hJOU14eG4tS2g0dEYwVFE0a185eXpWdllVTzZIemZnS3R2QWZkSUdMa3dDbW14TWhaZkRYTDd0RDNYUDNEclRSbU5iUjRZRmNITmZxZkFyeHAyTG9wR2hxd3FVVEJnV20xVGVKQmY4OW9FRnZOa3lxelA1UVVja1lad0ZiRzdKMVE4QmJuRFBPeGZYcTA3WjlnYzAyMHk?oc=5","published_at":"2026-07-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"The AI vulnerability storm is here: Is your security program ready?&nbsp;&nbsp;TechTarget","title":"The AI vulnerability storm is here: Is your security program ready? - TechTarget"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-87e0c9e5e1fd38ab","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiowFBVV95cUxOY19Xd1NTMno5ZWFVNkRKVkZ0LVZJU2tHT3RlclB1NHZyS3BqMC1EQ1ZYYmNJZElINU5BaHJqaWZzeUxkVGI5eUY4THNWSjhNUTYyUHZWLV82LUZta3lsaVFMajd4ZVQyVEd0aWtMQk9xYU9BR3BDWjdVSjBfRTVqa3AyZUxTUlpTTUVfdGE2My1SNXYwSk9lSkJ6RGRPZDhGNkx3?oc=5","published_at":"2026-07-02T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"How does adding AI change cybersecurity risks for government agencies?&nbsp;&nbsp;KALW","title":"How does adding AI change cybersecurity risks for government agencies? - KALW"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-fbc37e0d3077e614","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiowFBVV95cUxOY19Xd1NTMno5ZWFVNkRKVkZ0LVZJU2tHT3RlclB1NHZyS3BqMC1EQ1ZYYmNJZElINU5BaHJqaWZzeUxkVGI5eUY4THNWSjhNUTYyUHZWLV82LUZta3lsaVFMajd4ZVQyVEd0aWtMQk9xYU9BR3BDWjdVSjBfRTVqa3AyZUxTUlpTTUVfdGE2My1SNXYwSk9lSkJ6RGRPZDhGNkx3?oc=5","published_at":"2026-07-02T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"How does adding AI change cybersecurity risks for government agencies?&nbsp;&nbsp;kalw.org","title":"How does adding AI change cybersecurity risks for government agencies? - kalw.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-fe45f240968a4018","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitwFBVV95cUxOajBQRnRYYVhFRUVOcmNSNHlhYVpBckFNSEM4REJzRTdMdzlBc0FHTFNjSmppck1aRGtLZXEtMWZGaEoyZWozMDBGN05fRlhjdWF5bGdDazh4OHFaSjVib29GSmZTcm1pVHpKMjMzVUZOVUdqTFVlcDk1eEFrQTBvN2VRdEkxWjJuMDlRemFkeFhOSE1XNFpkVU9CVVUyZ2ZLU1JGUmw3ck5NemVVYXlNbVNzQ2FmUGM?oc=5","published_at":"2026-06-30T15:26:47+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Stronger Cybersecurity for Today's Connected Automation Systems&nbsp;&nbsp;Automation World","title":"Stronger Cybersecurity for Today's Connected Automation Systems - Automation World"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d71e153001986916","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitwFBVV95cUxOajBQRnRYYVhFRUVOcmNSNHlhYVpBckFNSEM4REJzRTdMdzlBc0FHTFNjSmppck1aRGtLZXEtMWZGaEoyZWozMDBGN05fRlhjdWF5bGdDazh4OHFaSjVib29GSmZTcm1pVHpKMjMzVUZOVUdqTFVlcDk1eEFrQTBvN2VRdEkxWjJuMDlRemFkeFhOSE1XNFpkVU9CVVUyZ2ZLU1JGUmw3ck5NemVVYXlNbVNzQ2FmUGM?oc=5","published_at":"2026-06-30T15:26:47+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Stronger Cybersecurity for Today's Connected Automation Systems&nbsp;&nbsp;automationworld.com","title":"Stronger Cybersecurity for Today's Connected Automation Systems - automationworld.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ff6f64c971f5a5a7","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilgFBVV95cUxOajZRN18tSGFFWFAtM3Izc2RBRG5XbVFZZU1wTE9BQmlEVzAyLWJUUkRsdUU1dlB6b0RBTmROczloSFN2VkVXNGJLckRpRXdXLUFVaDRxZXE2bFVtTHJDRXB6SDFIRl9TNE1zSWpQTHYxOWZUbkhXTFpLU0ExT29kNlZBU3ZMUmFKRzU1X25ySnFWTHl0U0E?oc=5","published_at":"2026-06-29T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Iran, Russia, China Target Water Systems for Sabotage&nbsp;&nbsp;Dark Reading","title":"Iran, Russia, China Target Water Systems for Sabotage - Dark Reading"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-be71335ed43642d9","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi2gFBVV95cUxNR05JWUNGUzVaek0wcnBEWmNqb1poLUl1OFVMdGU3ZEhuV3AySjZQSEFuRmJINUlVaERVeElZVkJJY0JlOGxwZFY1R2FELTYxNDNpUEcwM1dMUE5vR0lPME9uUGp1YmM1Z3hyX1hDb2RFcjl5THpCQS1xWnZ4TGFVSnhSQldVSDdoOHlHdHVyZlRPZWpOVm93dmc0Y01SV1lSZnlDTzZ6MEx4QXFSejBjOUViN1RBOUFjTVF5UTJPOHlxZ2R1X3hBMXJmZUgtSDlacFI1WDdEbkRYZw?oc=5","published_at":"2026-06-29T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"FDD\u2019s Ma warns weakening CISA could undermine US cyber resilience amid rising critical infrastructure threats&nbsp;&nbsp;industrialcyber.co","title":"FDD\u2019s Ma warns weakening CISA could undermine US cyber resilience amid rising critical infrastructure threats - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-95000ea40363a846","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi2gFBVV95cUxNR05JWUNGUzVaek0wcnBEWmNqb1poLUl1OFVMdGU3ZEhuV3AySjZQSEFuRmJINUlVaERVeElZVkJJY0JlOGxwZFY1R2FELTYxNDNpUEcwM1dMUE5vR0lPME9uUGp1YmM1Z3hyX1hDb2RFcjl5THpCQS1xWnZ4TGFVSnhSQldVSDdoOHlHdHVyZlRPZWpOVm93dmc0Y01SV1lSZnlDTzZ6MEx4QXFSejBjOUViN1RBOUFjTVF5UTJPOHlxZ2R1X3hBMXJmZUgtSDlacFI1WDdEbkRYZw?oc=5","published_at":"2026-06-29T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"FDD\u2019s Ma warns weakening CISA could undermine US cyber resilience amid rising critical infrastructure threats&nbsp;&nbsp;Industrial Cyber","title":"FDD\u2019s Ma warns weakening CISA could undermine US cyber resilience amid rising critical infrastructure threats - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d2b706c91305ffcf","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxPQnNZN1lEQVJvQlhhLUFleF9mSEJDeWE2VVlxWlhrd3puei1TT2VEVkxZaVoxcGtqZVh1VllrbG1KeTh1RmphenRDYzFnUzNyQ1VLRXloNHRuUHJmczJwcy1EWWxNdjZxUDU3eUcxeTZHc0FEd0JvNExRTi1XMUNZWXlFZmVQV3FnV0lmNHBzd2UzbzFlZmhac3RlSWFpZFJBcFBoMg?oc=5","published_at":"2026-06-25T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"5 Reasons Why CISA Is Indispensable to America\u2019s Cyber Defense&nbsp;&nbsp;Foundation for Defense of Democracies","title":"5 Reasons Why CISA Is Indispensable to America\u2019s Cyber Defense - Foundation for Defense of Democracies"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ab3a03857c6a1371","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxPQnNZN1lEQVJvQlhhLUFleF9mSEJDeWE2VVlxWlhrd3puei1TT2VEVkxZaVoxcGtqZVh1VllrbG1KeTh1RmphenRDYzFnUzNyQ1VLRXloNHRuUHJmczJwcy1EWWxNdjZxUDU3eUcxeTZHc0FEd0JvNExRTi1XMUNZWXlFZmVQV3FnV0lmNHBzd2UzbzFlZmhac3RlSWFpZFJBcFBoMg?oc=5","published_at":"2026-06-25T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"5 Reasons Why CISA Is Indispensable to America\u2019s Cyber Defense&nbsp;&nbsp;fdd.org","title":"5 Reasons Why CISA Is Indispensable to America\u2019s Cyber Defense - fdd.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-f4df9a79c5de12af","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMimAFBVV95cUxPaC00RHVZbjI5aFFWdVZNV2RPRDFYMFVYMmpxanFBeGVIMlpOUTNDNnNTYTVUTHNqTG4yQ0tDbVZTY3dhN0toaGM3Ty16NTNKeHZJRTJvT1JQUWYtamU5UXVBTGF6eHUwMU15VzBpY01VM1NmYkZtb0NnZ2tULVVVYXNnT3FUbDBxNmtTT0FrdWVWZDNQWHo1NQ?oc=5","published_at":"2026-06-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell Automation Announces Cranswick to Improve Production-Line Efficiency with Precision Robotic Pick-and-Place Technology \u2013 Company Announcement&nbsp;&nbsp;Financial Times","title":"Rockwell Automation Announces Cranswick to Improve Production-Line Efficiency with Precision Robotic Pick-and-Place Technology \u2013 Company Announcement - Financial Times"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-d2fbe39f9494cfb0","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMikgJBVV95cUxQNU1xOGJ1cEFmSFIzY1I0VzlpQzljeWNISC1uR3dnZlBJY1J4TUszRVNyT2h0SVg3eTEwVVBwSmpLdVpTTmM5bnlGQ04xd1hwZVlKbXZ2ZmVVMzkzTEhWTkZlS0RRcHcwT1dNVjJXVVo1aGRaUWlxY1Y1azlCWmhuZlAxb3lBVDY2SlJMd1pLbnhvc1ZJVjZSTHBkTy1oWi0weUtHSEVnX2UtOWpmXzhtVkRCdGVRM0pqQkVTR0lGb1JwSmE0Z2lmTHVrRGJubDdxdklMazhGVnUwUTY5aTFyOTR6cEwycTZJSXR3d0Vsd05hTUpEMjc5bmN2a1FXcmxWMi1JVmxUZmVNTXZCU3R1elF3?oc=5","published_at":"2026-06-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell Automation Announces Cranswick to Improve Production-Line Efficiency with Precision Robotic Pick-and-Place Technology&nbsp;&nbsp;prnewswire.co.uk","title":"Rockwell Automation Announces Cranswick to Improve Production-Line Efficiency with Precision Robotic Pick-and-Place Technology - prnewswire.co.uk"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-0fb29b077659ddc6","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMirwJBVV95cUxQTjF0TG5SMEpKaG5UOG1NZzFxVXQ4N2xwdGNrbHVYUHlOS25SNXBFbFQzMnh6MURKZHJPaDBjczdwTGo0TXhncUhjQ01vdHpWSGEySFJHYkJMelFpQTBrTDZwc2JESDVPVVNrWVo4cFloUDlpNm9pT1dpQ2NKOEFmM1UyLU81T0pNNGx1Q3pmQWx3WGZ5aGM0dVhfclNocVpWcmZpSHBiampkN1J2VFlPaXBTTFNldzVSX2d3MC1UaFlXaWl4NG10dTd3UUVyZG5jSW5xVm5wWlJweVFrdXlpelk2aEIzWDV5SS1kUVRoZkJJR2JoVV9NckFRSkotLWttQTJDS2V4YTU2M2czSGZvS0NFakhOM0ViLTJIakp1ZlRjdGl0a1FRNl9MU3JXem8?oc=5","published_at":"2026-06-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell Automation Announces Cranswick to Improve Production-Line Efficiency with Precision Robotic Pick-and-Place Technology | Corporate&nbsp;&nbsp;eqs-news.com","title":"Rockwell Automation Announces Cranswick to Improve Production-Line Efficiency with Precision Robotic Pick-and-Place Technology | Corporate - eqs-news.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-3ec06c429ec71a22","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMikgJBVV95cUxQNU1xOGJ1cEFmSFIzY1I0VzlpQzljeWNISC1uR3dnZlBJY1J4TUszRVNyT2h0SVg3eTEwVVBwSmpLdVpTTmM5bnlGQ04xd1hwZVlKbXZ2ZmVVMzkzTEhWTkZlS0RRcHcwT1dNVjJXVVo1aGRaUWlxY1Y1azlCWmhuZlAxb3lBVDY2SlJMd1pLbnhvc1ZJVjZSTHBkTy1oWi0weUtHSEVnX2UtOWpmXzhtVkRCdGVRM0pqQkVTR0lGb1JwSmE0Z2lmTHVrRGJubDdxdklMazhGVnUwUTY5aTFyOTR6cEwycTZJSXR3d0Vsd05hTUpEMjc5bmN2a1FXcmxWMi1JVmxUZmVNTXZCU3R1elF3?oc=5","published_at":"2026-06-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell Automation Announces Cranswick to Improve Production-Line Efficiency with Precision Robotic Pick-and-Place Technology&nbsp;&nbsp;PR Newswire UK","title":"Rockwell Automation Announces Cranswick to Improve Production-Line Efficiency with Precision Robotic Pick-and-Place Technology - PR Newswire UK"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-17248bba9779ec8c","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMirwJBVV95cUxQTjF0TG5SMEpKaG5UOG1NZzFxVXQ4N2xwdGNrbHVYUHlOS25SNXBFbFQzMnh6MURKZHJPaDBjczdwTGo0TXhncUhjQ01vdHpWSGEySFJHYkJMelFpQTBrTDZwc2JESDVPVVNrWVo4cFloUDlpNm9pT1dpQ2NKOEFmM1UyLU81T0pNNGx1Q3pmQWx3WGZ5aGM0dVhfclNocVpWcmZpSHBiampkN1J2VFlPaXBTTFNldzVSX2d3MC1UaFlXaWl4NG10dTd3UUVyZG5jSW5xVm5wWlJweVFrdXlpelk2aEIzWDV5SS1kUVRoZkJJR2JoVV9NckFRSkotLWttQTJDS2V4YTU2M2czSGZvS0NFakhOM0ViLTJIakp1ZlRjdGl0a1FRNl9MU3JXem8?oc=5","published_at":"2026-06-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell Automation Announces Cranswick to Improve Production-Line Efficiency with Precision Robotic Pick-and-Place Technology | Corporate&nbsp;&nbsp;EQS News","title":"Rockwell Automation Announces Cranswick to Improve Production-Line Efficiency with Precision Robotic Pick-and-Place Technology | Corporate - EQS News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-330dbbe4235585e9","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiV0FVX3lxTE5Idnl4Si1Pb0xEYUVJZVQwV2NZNHVfckh6bGdYUXhKZHlQUkpXQzNuZ3BRZndDRmtINU96OU1CN202YTR3UEtIbWhKQWVBVWlmNjA2Z2pvbw?oc=5","published_at":"2026-06-23T03:21:30+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"OpenAI Releases GPT\u20115.5\u2011Cyber With Full Automation for Vulnerability Detection and Patching&nbsp;&nbsp;CyberSecurityNews","title":"OpenAI Releases GPT\u20115.5\u2011Cyber With Full Automation for Vulnerability Detection and Patching - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-8e4bc1eacd811e2d","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMirAFBVV95cUxOSnp6cy1lcUg0SDlxOWhrWW1qTGlVX2hHMTJ2c3hzUEVBVW4xQWVrQ3dmdHhzQTVsaXlkLVg2Y3FmRHBramQ3cXFHZkdaQk02OVhBN0hDQzZST2twRW9heWQ2S1Q3YXI3UUltYVlsTXNURWRPcFdHN1dZRlJkNFFYOUZuUnJ6ZXZNZlp1U0xDY2dndnNsbXNRREx3My1DQno1V0p2OE1RUmFzNkhW?oc=5","published_at":"2026-06-22T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Major critical infrastructure disruptions are inevitable, acting CISA chief says&nbsp;&nbsp;utilitydive.com","title":"Major critical infrastructure disruptions are inevitable, acting CISA chief says - utilitydive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-632c53304d57efe2","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiyAFBVV95cUxNNHBkT3hTWG0zbUo5MWE3bnVIb1BLR3J4TXRKRExTbGlURmY3Vm9FOW45bEdCS3g5NXM3eHdaV0JpNXFFRW85ckJ3blFYZkxDWl82UjNiY0pYbld0WHBUalJwRmJYNll0Z0lvbmJmRkpYNEhsT0JrUUltUHRyX3FmbklnWFVlaDRJb2c0YUF4eFpSejZMN0gzV01lNFVvZkttRnpmb2lvdkpKTUUtR0s4dVNQeFhMczVkUHk3RVZfZWozM2JIcUhPVA?oc=5","published_at":"2026-06-22T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Policymakers struggle to factor cybersecurity into federal funding programs&nbsp;&nbsp;Federal News Network","title":"Policymakers struggle to factor cybersecurity into federal funding programs - Federal News Network"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-2b890a513d67f994","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMirAFBVV95cUxOSnp6cy1lcUg0SDlxOWhrWW1qTGlVX2hHMTJ2c3hzUEVBVW4xQWVrQ3dmdHhzQTVsaXlkLVg2Y3FmRHBramQ3cXFHZkdaQk02OVhBN0hDQzZST2twRW9heWQ2S1Q3YXI3UUltYVlsTXNURWRPcFdHN1dZRlJkNFFYOUZuUnJ6ZXZNZlp1U0xDY2dndnNsbXNRREx3My1DQno1V0p2OE1RUmFzNkhW?oc=5","published_at":"2026-06-22T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Major critical infrastructure disruptions are inevitable, acting CISA chief says&nbsp;&nbsp;Utility Dive","title":"Major critical infrastructure disruptions are inevitable, acting CISA chief says - Utility Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b9cb6c5280ddd4fb","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi-AFBVV95cUxQWmR6Qm5Ma0RBWGpfQXkyNTJDRl9zd09JMEIyb21yMVJDUlJoZWhWeGgzRkpDV3EzMG1aRU9qSHhNUWRrYWdEOVp0bXd4VjNHRWNpaHBkNzFBSzhRZ2RKNzJoSG05UmQwemRaUWlMN0JRanpUemZlb1RHbmlWS3JDNXdpMkQ2YTh6TVZVZFFFRWRYMi1YbDh0bXdzcmlGNkNxdWRGcENkQlhtVmd3bDNkeDNwckJlWUs4d1ZTTFJ6czlEWHZBMEt1dUg1X3lBVVk5WWhzVEFZVzZ4U0szUmEzOXFUQzB3dWhCcERSNWVFcExFT2dxUkR1Mg?oc=5","published_at":"2026-06-22T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"\u201cToto, I\u2019ve a Feeling We\u2019re Not in Kansas Anymore\u201d: Cyber Resilience for Operational Technology in the Face of Mythos-Driven Attacks&nbsp;&nbsp;Security Boulevard","title":"\u201cToto, I\u2019ve a Feeling We\u2019re Not in Kansas Anymore\u201d: Cyber Resilience for Operational Technology in the Face of Mythos-Driven Attacks - Security Boulevard"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-cebad0ac900f2407","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiyAFBVV95cUxNNHBkT3hTWG0zbUo5MWE3bnVIb1BLR3J4TXRKRExTbGlURmY3Vm9FOW45bEdCS3g5NXM3eHdaV0JpNXFFRW85ckJ3blFYZkxDWl82UjNiY0pYbld0WHBUalJwRmJYNll0Z0lvbmJmRkpYNEhsT0JrUUltUHRyX3FmbklnWFVlaDRJb2c0YUF4eFpSejZMN0gzV01lNFVvZkttRnpmb2lvdkpKTUUtR0s4dVNQeFhMczVkUHk3RVZfZWozM2JIcUhPVA?oc=5","published_at":"2026-06-22T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Policymakers struggle to factor cybersecurity into federal funding programs&nbsp;&nbsp;federalnewsnetwork.com","title":"Policymakers struggle to factor cybersecurity into federal funding programs - federalnewsnetwork.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-9208402bfc78c61c","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxNYXc5MWEyejJzZTZYajlRdC1hM1Jnb2pyN1V5OGJPeDM2bWVCSkFFUXRBMV9YVmpHMl90OUNoWEM3SlhFUTBXVTZtUmM2UEhJODdQX1FvQVZja2lnQ2VFWW85NU5sYktkQ3dGcWVzUWl5Ym5Ja3JpRXU0a0F3S1JoM3FoR3paa1Fockx1QmozTUR4ZVZldVVxdVBPNkRHaWZMSHByeTBELTQ?oc=5","published_at":"2026-06-18T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Hostile states behind three-quarters of UK critical infrastructure attacks&nbsp;&nbsp;IT Pro","title":"Hostile states behind three-quarters of UK critical infrastructure attacks - IT Pro"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-5c6869fd563dc88c","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxNYXc5MWEyejJzZTZYajlRdC1hM1Jnb2pyN1V5OGJPeDM2bWVCSkFFUXRBMV9YVmpHMl90OUNoWEM3SlhFUTBXVTZtUmM2UEhJODdQX1FvQVZja2lnQ2VFWW85NU5sYktkQ3dGcWVzUWl5Ym5Ja3JpRXU0a0F3S1JoM3FoR3paa1Fockx1QmozTUR4ZVZldVVxdVBPNkRHaWZMSHByeTBELTQ?oc=5","published_at":"2026-06-18T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Hostile states behind three-quarters of UK critical infrastructure attacks&nbsp;&nbsp;itpro.com","title":"Hostile states behind three-quarters of UK critical infrastructure attacks - itpro.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-8557ae5488b1fb93","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMitgFBVV95cUxNSnpBejJJZmNCNGw1ZGU2ekRheWxDQ041Nkd2OFl2Q0U5cDhlYmU5X21Zb01PYWVUQmpMN29taDRfdWF0VVE2S09RZXpVWU45MTYzcXRzQmkxT3dpbzhkdmJXRUt0WlN6Z2EwXzhMOUxPeTRER1M4b2xDZG9FUjlaWWsxZ2h5RHI3Z01sb0Y3bzVqblh2ajQwaFFQYUZaU3ZxejdsN2VsVU8zRkJkakJUaklsYVR6QQ?oc=5","published_at":"2026-06-18T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"Digital Switch-Over: Reps is advancing stronger data, cybersecurity reforms \u2014 Kalu&nbsp;&nbsp;Nairametrics","title":"Digital Switch-Over: Reps is advancing stronger data, cybersecurity reforms \u2014 Kalu - Nairametrics"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-fb5561146565ad8b","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxNdjlCdnhKSXZid3V0TFNRU3otQUhza1E4dEJTYUtTZC1YbnZyX2lIYi0tYTJoZVNBVUwzTWpyUnRIVnpWVXg2c1FieTZueTZkQXVKSlZ6Y2F4RWlQNzJ0R29KTUswc2V1NTZ4ZnM1bkhQUFhBU1dhRHVhaWZHNkhxbWlvcW0?oc=5","published_at":"2026-06-18T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Hostile States Behind 75% of Cyber-Attacks on UK Critical Infrastructure, NCSC Warns&nbsp;&nbsp;Infosecurity Magazine","title":"Hostile States Behind 75% of Cyber-Attacks on UK Critical Infrastructure, NCSC Warns - Infosecurity Magazine"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-202cdae82c01c279","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxNdjlCdnhKSXZid3V0TFNRU3otQUhza1E4dEJTYUtTZC1YbnZyX2lIYi0tYTJoZVNBVUwzTWpyUnRIVnpWVXg2c1FieTZueTZkQXVKSlZ6Y2F4RWlQNzJ0R29KTUswc2V1NTZ4ZnM1bkhQUFhBU1dhRHVhaWZHNkhxbWlvcW0?oc=5","published_at":"2026-06-18T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Hostile States Behind 75% of Cyber-Attacks on UK Critical Infrastructure, NCSC Warns&nbsp;&nbsp;infosecurity-magazine.com","title":"Hostile States Behind 75% of Cyber-Attacks on UK Critical Infrastructure, NCSC Warns - infosecurity-magazine.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-c4f36dbcb082889b","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxPUWxwSVR3SW9oaWI0WTRmZFdpOXNLbTNTTnNsZ2RDV2wxTHNYQXJvUHFHQVROZl9oTWFHakhrUk1GclhKTTZfOUhZUHRZb0d5elMxRzNZVjd2ajVTUkVMSnVvSU1lc3BuQjRuQWhuOTVLNkJiZE5QRjVaZlNEbU1ucHVUSXNlWWJySlR4aHZWcW9KYUpNcXF4a29oaUE0WkRBYU1KZkVQNmbSAa4BQVVfeXFMT3c5TGhBeWpUMUFfMGNvX0lvLVJ1S0VRVE1DTnZXaWtiRGEtS3dXM0JXQjE4X2RTQXlFcVdkWVA1LTdrdlJnOFVSWlBQa0xMSFRaalJJSHY0Y1dQQ09jWks2SzNIa3hVakdrZ21INEY2ZngyZUJaOFVlSWVaLUEwdGF0MHhjSE8xWUZFOVdYMXJiV1ZSaWNrRG5iZ3pXUFhLc2RSV3dYX0tUVnIzZ3Zn?oc=5","published_at":"2026-06-17T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software&nbsp;&nbsp;SecurityWeek","title":"Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-89517fc8feb2d963","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMifkFVX3lxTE9UN1YtNzZZWVJGYU1EN3lKUTdCSS1Id0RWT285c1ZXcEc0NkdieU5COW9ocDhxVmxlbF92U2sxQmlLNU9LaWpIVUhQOTRLZjdoRU51TmFIS0NFY2VoOGRKZFkyN0tsR1F4YXBkbjI3NkxmMWZ3UFdrRGpXT1hjUQ?oc=5","published_at":"2026-06-17T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Exclusive: Cyber warfare startup Twenty is now worth $1 billion&nbsp;&nbsp;axios.com","title":"Exclusive: Cyber warfare startup Twenty is now worth $1 billion - axios.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-5f87da3e5d87ea71","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMitAFBVV95cUxNR1N2bG9WckZKc3R1YzJsZnoxYldxOHd3YlRlWThNY2RoWDJQb2dJa01Fd3FDNjhKZ044V3pqRVA5cE5WZlNGVl9sUTRiM3BqSXNMQ2dQZTNRR3BzTjYxNk93LWEwUXVZRjE3Y2hsSGJaV3M2Z1N1SW1WZXE1Rmd3bjk1OFNHVG5jU3N6eWRxSnkyMGxfYmV6S05tYTBpRjJqSXVtLXdhbXNxMkJSLUh1c0N0TS0?oc=5","published_at":"2026-06-17T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Major critical infrastructure disruptions are inevitable, acting CISA chief says&nbsp;&nbsp;cybersecuritydive.com","title":"Major critical infrastructure disruptions are inevitable, acting CISA chief says - cybersecuritydive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-77d69ea0e60659f8","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMitAFBVV95cUxNR1N2bG9WckZKc3R1YzJsZnoxYldxOHd3YlRlWThNY2RoWDJQb2dJa01Fd3FDNjhKZ044V3pqRVA5cE5WZlNGVl9sUTRiM3BqSXNMQ2dQZTNRR3BzTjYxNk93LWEwUXVZRjE3Y2hsSGJaV3M2Z1N1SW1WZXE1Rmd3bjk1OFNHVG5jU3N6eWRxSnkyMGxfYmV6S05tYTBpRjJqSXVtLXdhbXNxMkJSLUh1c0N0TS0?oc=5","published_at":"2026-06-17T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Major critical infrastructure disruptions are inevitable, acting CISA chief says&nbsp;&nbsp;Cybersecurity Dive","title":"Major critical infrastructure disruptions are inevitable, acting CISA chief says - Cybersecurity Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-38d95e29b7fe647c","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxPUWxwSVR3SW9oaWI0WTRmZFdpOXNLbTNTTnNsZ2RDV2wxTHNYQXJvUHFHQVROZl9oTWFHakhrUk1GclhKTTZfOUhZUHRZb0d5elMxRzNZVjd2ajVTUkVMSnVvSU1lc3BuQjRuQWhuOTVLNkJiZE5QRjVaZlNEbU1ucHVUSXNlWWJySlR4aHZWcW9KYUpNcXF4a29oaUE0WkRBYU1KZkVQNmbSAa4BQVVfeXFMT3c5TGhBeWpUMUFfMGNvX0lvLVJ1S0VRVE1DTnZXaWtiRGEtS3dXM0JXQjE4X2RTQXlFcVdkWVA1LTdrdlJnOFVSWlBQa0xMSFRaalJJSHY0Y1dQQ09jWks2SzNIa3hVakdrZ21INEY2ZngyZUJaOFVlSWVaLUEwdGF0MHhjSE8xWUZFOVdYMXJiV1ZSaWNrRG5iZ3pXUFhLc2RSV3dYX0tUVnIzZ3Zn?oc=5","published_at":"2026-06-17T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software&nbsp;&nbsp;securityweek.com","title":"Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ed4c381ff9f6064c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMifkFVX3lxTE9UN1YtNzZZWVJGYU1EN3lKUTdCSS1Id0RWT285c1ZXcEc0NkdieU5COW9ocDhxVmxlbF92U2sxQmlLNU9LaWpIVUhQOTRLZjdoRU51TmFIS0NFY2VoOGRKZFkyN0tsR1F4YXBkbjI3NkxmMWZ3UFdrRGpXT1hjUQ?oc=5","published_at":"2026-06-17T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Exclusive: Cyber warfare startup Twenty is now worth $1 billion&nbsp;&nbsp;Axios","title":"Exclusive: Cyber warfare startup Twenty is now worth $1 billion - Axios"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9e4ede5aca01635f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMicEFVX3lxTE5SYU95aTBsa3FNeV9EWDF2VEZZOHJfbGxNSnhvLUNNV1ctc084dmZTeUszek9VR2VQOGNMRzlwQnd0QjZScExHT1BsdlVIbmZEMmJmcGpCQmhhRHVmZ1VnaFBFNkFnbDFxZ2hiN3F1V0I?oc=5","published_at":"2026-06-16T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Canada's Spy Service Won Permission to Hack Two State-Linked Botnets \u2014 Assessed to Likely Include China \u2014 Hiding Inside Canadian Homes&nbsp;&nbsp;thebureau.news","title":"Canada's Spy Service Won Permission to Hack Two State-Linked Botnets \u2014 Assessed to Likely Include China \u2014 Hiding Inside Canadian Homes - thebureau.news"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8b1527c1991cdd22","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMicEFVX3lxTE5SYU95aTBsa3FNeV9EWDF2VEZZOHJfbGxNSnhvLUNNV1ctc084dmZTeUszek9VR2VQOGNMRzlwQnd0QjZScExHT1BsdlVIbmZEMmJmcGpCQmhhRHVmZ1VnaFBFNkFnbDFxZ2hiN3F1V0I?oc=5","published_at":"2026-06-16T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Canada's Spy Service Won Permission to Hack Two State-Linked Botnets \u2014 Assessed to Likely Include China \u2014 Hiding Inside Canadian Homes&nbsp;&nbsp;The Bureau | Sam Cooper","title":"Canada's Spy Service Won Permission to Hack Two State-Linked Botnets \u2014 Assessed to Likely Include China \u2014 Hiding Inside Canadian Homes - The Bureau | Sam Cooper"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-0dbf2e1ec55fd1ed","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMimAFBVV95cUxNbU9jd0E0T2loYjNXTkp1ZTFWNDcwanlCOTJGc2JoRzg5Q05sd2wwbW5FclFybnZTRV91bloyc1pKcUR6bEZNb21nUWhQRmJxaDA5eUg5QnNYc1RXLWRVd000Z0xlQWE4MHRXa1BqZUNlWHUwZ1BfU1NxSjRKRkxQcGplV2dlMzRRTU9CUlZCU05JcGJMa3lIMw?oc=5","published_at":"2026-06-15T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Pentagon builds cyberdefence for critical infrastructure&nbsp;&nbsp;Defence24.com","title":"Pentagon builds cyberdefence for critical infrastructure - Defence24.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-4a91389febc8d2a5","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMivgFBVV95cUxPUm5wSHpXLXotWEVKTWN4OXFVdjQ5YTdIdjkzazdYMEZSVzBHdnV3WGFqbmVPTThwRmxCMUxuN0VQZ0gyXzh2WWM0UDNaQ3Q5cDJjdVRKSVlrX2psX3FZT3hkNzRoSTE4OVZxcXlWc1VwYk9ESU5nbE44WWlXaEh5akNJRzh1LVlGZm9BTGNLUk5PMGxPVEpWUnFJSS1KTGFEdDVDSDRhdjBUb2w1NVNkNjJiT1EyOE9TUmNXandB?oc=5","published_at":"2026-06-12T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"South Africa\u2019s lights could be switched off from anywhere in the world \u2014 Cybersecurity company&nbsp;&nbsp;MyBroadband","title":"South Africa\u2019s lights could be switched off from anywhere in the world \u2014 Cybersecurity company - MyBroadband"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-93c08103faad63e4","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMivgFBVV95cUxPUm5wSHpXLXotWEVKTWN4OXFVdjQ5YTdIdjkzazdYMEZSVzBHdnV3WGFqbmVPTThwRmxCMUxuN0VQZ0gyXzh2WWM0UDNaQ3Q5cDJjdVRKSVlrX2psX3FZT3hkNzRoSTE4OVZxcXlWc1VwYk9ESU5nbE44WWlXaEh5akNJRzh1LVlGZm9BTGNLUk5PMGxPVEpWUnFJSS1KTGFEdDVDSDRhdjBUb2w1NVNkNjJiT1EyOE9TUmNXandB?oc=5","published_at":"2026-06-12T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"South Africa\u2019s lights could be switched off from anywhere in the world \u2014 Cybersecurity company&nbsp;&nbsp;mybroadband.co.za","title":"South Africa\u2019s lights could be switched off from anywhere in the world \u2014 Cybersecurity company - mybroadband.co.za"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9d78fd8b81805daa","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitAFBVV95cUxNQjNYQ3hKSHhWYkRCLUFEaFRid1FkRGZvYklRSUQtVklJeng1WjJ4a09YVnVYTUtkN3ZVMF9CQS0tNFVuLW83aEZRMXpRVzJjaVZRRkZadTB6TTQtYUJ0bHRHdGRIOE9mLWwxcVhGREV6SWQ3ejdxVTVra1MzXzJUUHplRmdXdHU1SUxRaGxHQWdCUmFmOWZWbWVnZ2NuQTJJeHZiaFRuUjlXdnctN2hFLUJrejM?oc=5","published_at":"2026-06-12T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Sweet Magnolias Season 5 Review: The Rabbit Hole of Change, Vulnerability, and Growth&nbsp;&nbsp;telltaletv.com","title":"Sweet Magnolias Season 5 Review: The Rabbit Hole of Change, Vulnerability, and Growth - telltaletv.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4adc0af5e2a92688","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitAFBVV95cUxNQjNYQ3hKSHhWYkRCLUFEaFRid1FkRGZvYklRSUQtVklJeng1WjJ4a09YVnVYTUtkN3ZVMF9CQS0tNFVuLW83aEZRMXpRVzJjaVZRRkZadTB6TTQtYUJ0bHRHdGRIOE9mLWwxcVhGREV6SWQ3ejdxVTVra1MzXzJUUHplRmdXdHU1SUxRaGxHQWdCUmFmOWZWbWVnZ2NuQTJJeHZiaFRuUjlXdnctN2hFLUJrejM?oc=5","published_at":"2026-06-12T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Sweet Magnolias Season 5 Review: The Rabbit Hole of Change, Vulnerability, and Growth&nbsp;&nbsp;Tell-Tale TV","title":"Sweet Magnolias Season 5 Review: The Rabbit Hole of Change, Vulnerability, and Growth - Tell-Tale TV"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4d441d941b9e71e0","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisgFBVV95cUxQMUZZWnhQZjV1UEFoYkVmc3plZkMwcHAtWmFmdnhZSnRZRTAxNEVBSzNmeGpfaTB1VDZ5ZjdEaHh6WXlRblE0Q3ZCenhhcHdMODd1UUtiNGJKeHFhNks3T0MtS0JIYzFyallkbUtiWUt5UlVRcmd6UXhWa0tKbVI3c21GRmt4Ty12MDRiVUhWdXdQVjRsNWVsUHVwc290bmFqbVRfUG1BR3AwNmtHUEhaREd3?oc=5","published_at":"2026-06-11T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"The Escalating Cyber Risk Landscape in Regional Conflicts & Strategic Actions for 2026&nbsp;&nbsp;EclecticIQ Blog","title":"The Escalating Cyber Risk Landscape in Regional Conflicts & Strategic Actions for 2026 - EclecticIQ Blog"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-9f79c2245177e7bf","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxNdDhqWTE5TFYzeHhZbFM2VDBsUVkwRnQyVXZqQ19QOGRMc1EyVDdCRjlCRXRPbkh0clhWb3JCU05LNGRXVGhkX0l5dk1la1dzS3ozNmtieGJYTlkwQk91MDlWVG1DQ3BQOGFKQ0pueW9LazVVZDBwVDBvX1FqNDFsMnZn?oc=5","published_at":"2026-06-11T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Critical Infra & APTs","summary":"China-linked JDY botnet targets routers, fueling new Volt Typhoon concerns&nbsp;&nbsp;Cybernews","title":"China-linked JDY botnet targets routers, fueling new Volt Typhoon concerns - Cybernews"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-82106c2454bc5083","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisgFBVV95cUxQMUZZWnhQZjV1UEFoYkVmc3plZkMwcHAtWmFmdnhZSnRZRTAxNEVBSzNmeGpfaTB1VDZ5ZjdEaHh6WXlRblE0Q3ZCenhhcHdMODd1UUtiNGJKeHFhNks3T0MtS0JIYzFyallkbUtiWUt5UlVRcmd6UXhWa0tKbVI3c21GRmt4Ty12MDRiVUhWdXdQVjRsNWVsUHVwc290bmFqbVRfUG1BR3AwNmtHUEhaREd3?oc=5","published_at":"2026-06-11T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"The Escalating Cyber Risk Landscape in Regional Conflicts & Strategic Actions for 2026&nbsp;&nbsp;blog.eclecticiq.com","title":"The Escalating Cyber Risk Landscape in Regional Conflicts & Strategic Actions for 2026 - blog.eclecticiq.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-03142b9988236bef","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxNdDhqWTE5TFYzeHhZbFM2VDBsUVkwRnQyVXZqQ19QOGRMc1EyVDdCRjlCRXRPbkh0clhWb3JCU05LNGRXVGhkX0l5dk1la1dzS3ozNmtieGJYTlkwQk91MDlWVG1DQ3BQOGFKQ0pueW9LazVVZDBwVDBvX1FqNDFsMnZn?oc=5","published_at":"2026-06-11T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Critical Infra & APTs","summary":"China-linked JDY botnet targets routers, fueling new Volt Typhoon concerns&nbsp;&nbsp;cybernews.com","title":"China-linked JDY botnet targets routers, fueling new Volt Typhoon concerns - cybernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-691af3297d019463","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi5wFBVV95cUxNdmxqOEtMSWFqam10YVJlcmNSaFZScl9uZHREVUVldm4yVFIwbTNQWTRvM01fcGF3M1NkQm9CYjNlUlJLalRLMU4wbkhxa1NmaGd6MEwzTUVZdjRPRWtiVzZveDVfY0RVSTRjV0ZHRlNxV3B2S2RJSE1hVmdvcHBTV1R1ZEh1Nlh4dkZpLU1wV0F0TnQ5TExIUUxpUmZ5cFFYTHFPcFN3YzluWGFSSkRqbWNUcHAyazJkSGFrTDBHR2JQa2pXWjJMYTVTTXlxRnVaTnI3d2U1WDJ4SE5xMW0zMF9RWFNIMnM?oc=5","published_at":"2026-06-10T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Energy and utilities sector targeted in 66% of observed APT campaigns, as Mustang Panda, Lazarus, Sandworm remain active&nbsp;&nbsp;Industrial Cyber","title":"Energy and utilities sector targeted in 66% of observed APT campaigns, as Mustang Panda, Lazarus, Sandworm remain active - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-52596a19ce17a4de","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxPMmtTZFJEZVlScVViSWJtaGNBUnZrNm82bGU2VGx0RHNMd1BRZlhYUVpoQzNEWWJTOTk4WkpBWGZGVU1QQ1o4WkZLSWpjLS04UDJlNzJvN3RYQU5MaURNM05BcHFfeVNMc0RXbFVYS0lHSk5pMFM1blhMNmpoYmRDUlNqdTQ?oc=5","published_at":"2026-06-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance&nbsp;&nbsp;The Hacker News","title":"China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-5ca4f520792ec994","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMi8gFBVV95cUxPSVZrekUwaDVsUUYxV1VCN0NITjVlRjliYzZDZ3BtMWdNSjFJNXg2LUhtX3hxajEzVXBlWkxhNEdfdlc2R1lzZ19EMk9XQmJ4SHhPMjI5MTJSV0h2Vnk4ektkeU5jaGd6c1RjSVNjN3NEZVNSWXBWVzVuN2pCakZxMmo1Unl1czFkeDFRQkotUlRkNEdxTVlsMG91Wm1ZQTZoQXkxS1V4c2FTbTVJbFB6SHkwWU91TDBrOGNyX2tDUHBKRVFOLTBKLVphV1BhRjdVWnlCcmVjeXc1c2RSNzg0SHBTTkIwX2I5MHJoR1BndlFKdw?oc=5","published_at":"2026-06-10T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"Mountain Rides switches web platforms after cybersecurity issues&nbsp;&nbsp;Idaho Mountain Express Newspaper","title":"Mountain Rides switches web platforms after cybersecurity issues - Idaho Mountain Express Newspaper"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-225de56588308014","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi5wFBVV95cUxNdmxqOEtMSWFqam10YVJlcmNSaFZScl9uZHREVUVldm4yVFIwbTNQWTRvM01fcGF3M1NkQm9CYjNlUlJLalRLMU4wbkhxa1NmaGd6MEwzTUVZdjRPRWtiVzZveDVfY0RVSTRjV0ZHRlNxV3B2S2RJSE1hVmdvcHBTV1R1ZEh1Nlh4dkZpLU1wV0F0TnQ5TExIUUxpUmZ5cFFYTHFPcFN3YzluWGFSSkRqbWNUcHAyazJkSGFrTDBHR2JQa2pXWjJMYTVTTXlxRnVaTnI3d2U1WDJ4SE5xMW0zMF9RWFNIMnM?oc=5","published_at":"2026-06-10T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Energy and utilities sector targeted in 66% of observed APT campaigns, as Mustang Panda, Lazarus, Sandworm remain active&nbsp;&nbsp;industrialcyber.co","title":"Energy and utilities sector targeted in 66% of observed APT campaigns, as Mustang Panda, Lazarus, Sandworm remain active - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-35a952353f3da4a0","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxPMmtTZFJEZVlScVViSWJtaGNBUnZrNm82bGU2VGx0RHNMd1BRZlhYUVpoQzNEWWJTOTk4WkpBWGZGVU1QQ1o4WkZLSWpjLS04UDJlNzJvN3RYQU5MaURNM05BcHFfeVNMc0RXbFVYS0lHSk5pMFM1blhMNmpoYmRDUlNqdTQ?oc=5","published_at":"2026-06-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance&nbsp;&nbsp;thehackernews.com","title":"China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-5dad8b8022c59147","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMi8gFBVV95cUxPSVZrekUwaDVsUUYxV1VCN0NITjVlRjliYzZDZ3BtMWdNSjFJNXg2LUhtX3hxajEzVXBlWkxhNEdfdlc2R1lzZ19EMk9XQmJ4SHhPMjI5MTJSV0h2Vnk4ektkeU5jaGd6c1RjSVNjN3NEZVNSWXBWVzVuN2pCakZxMmo1Unl1czFkeDFRQkotUlRkNEdxTVlsMG91Wm1ZQTZoQXkxS1V4c2FTbTVJbFB6SHkwWU91TDBrOGNyX2tDUHBKRVFOLTBKLVphV1BhRjdVWnlCcmVjeXc1c2RSNzg0SHBTTkIwX2I5MHJoR1BndlFKdw?oc=5","published_at":"2026-06-10T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"Mountain Rides switches web platforms after cybersecurity issues&nbsp;&nbsp;mtexpress.com","title":"Mountain Rides switches web platforms after cybersecurity issues - mtexpress.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-e8e0811162b6abed","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMi3wFBVV95cUxOQmM4cU5YdThmM2pCblhxNU94bXdhR2xUNHlPN0FVTjVqYkZYVjBPWjAwb2hPU0lfeXJwM093QlZSLTlQRTQwUDdlMnZDTm0xT19mUVZqblMza2dPSnBzYVpuOTJQRTZDWEdmejZPN28tM1RTSU1iN2hnWDZpSWd0WkV0QU95UEhhWE9PVGhwQVlQQTBfam1jTDI0bmpNZE1SSG0xTGxZaG9WdXpDa09NTkZjX0Vha2VzZTZVNlFZS2xWYWlsSXZxdEFja1NtRzVnNm1pejNhMm1xNm1jMy1R0gHkAUFVX3lxTFBVV3hJN0lNTF9IbTUzLThEU2w4aHVFT0JQSEFIakhURThYYVZReVhEWE9xUkRUem1YOFNrQ2lIQW50NThKVUFfTGh5aUJFeVItVEo5QmxERkVYSjN0ZUJSLUdnUDZENG1Iak1TLWN4UndISmJ4b3pPWGNneV9pdml4RkVlSFhDaVRnLUNvMnZtZlpMX05WaXkyYnBMY2Q2Vi0xWXRWalo3N3NlQ05UdE5iQm8xVWRPVExldlluOEtKTU5UR1RCMzlaY1NOY3Z3WnBHODdsV2M0Y25aQTBJY3FQN1pSRw?oc=5","published_at":"2026-06-08T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"57K cybersecurity pros switch jobs annually amid talent crunch : Report&nbsp;&nbsp;The Times of India","title":"57K cybersecurity pros switch jobs annually amid talent crunch : Report - The Times of India"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-ff51b525667be34d","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxPNXhsMjhxdVl1OWpkS2ZsMEFFYUp2RWcyYzZ4MTRoRjJqNXhpY0JwdUVjYTlSemFfcWlsdk0tUHNPYVV4dm1SVE5TTjhBamJ6SEJFN24xMUJmQklmTkp5Y0FsQ1ZBMzFFT2RxVkR5d2N2WWdfQnI3U2NITXNyNXVPd0F3MG8?oc=5","published_at":"2026-06-08T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"PLC, PAC, and Industrial PC Architectures for Automation&nbsp;&nbsp;eletimes.ai","title":"PLC, PAC, and Industrial PC Architectures for Automation - eletimes.ai"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-20cd21263b9fe6d9","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxPNXhsMjhxdVl1OWpkS2ZsMEFFYUp2RWcyYzZ4MTRoRjJqNXhpY0JwdUVjYTlSemFfcWlsdk0tUHNPYVV4dm1SVE5TTjhBamJ6SEJFN24xMUJmQklmTkp5Y0FsQ1ZBMzFFT2RxVkR5d2N2WWdfQnI3U2NITXNyNXVPd0F3MG8?oc=5","published_at":"2026-06-08T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"PLC, PAC, and Industrial PC Architectures for Automation&nbsp;&nbsp;ELE Times","title":"PLC, PAC, and Industrial PC Architectures for Automation - ELE Times"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-aa1597dcb17af11b","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMi3wFBVV95cUxOQmM4cU5YdThmM2pCblhxNU94bXdhR2xUNHlPN0FVTjVqYkZYVjBPWjAwb2hPU0lfeXJwM093QlZSLTlQRTQwUDdlMnZDTm0xT19mUVZqblMza2dPSnBzYVpuOTJQRTZDWEdmejZPN28tM1RTSU1iN2hnWDZpSWd0WkV0QU95UEhhWE9PVGhwQVlQQTBfam1jTDI0bmpNZE1SSG0xTGxZaG9WdXpDa09NTkZjX0Vha2VzZTZVNlFZS2xWYWlsSXZxdEFja1NtRzVnNm1pejNhMm1xNm1jMy1R0gHkAUFVX3lxTFBVV3hJN0lNTF9IbTUzLThEU2w4aHVFT0JQSEFIakhURThYYVZReVhEWE9xUkRUem1YOFNrQ2lIQW50NThKVUFfTGh5aUJFeVItVEo5QmxERkVYSjN0ZUJSLUdnUDZENG1Iak1TLWN4UndISmJ4b3pPWGNneV9pdml4RkVlSFhDaVRnLUNvMnZtZlpMX05WaXkyYnBMY2Q2Vi0xWXRWalo3N3NlQ05UdE5iQm8xVWRPVExldlluOEtKTU5UR1RCMzlaY1NOY3Z3WnBHODdsV2M0Y25aQTBJY3FQN1pSRw?oc=5","published_at":"2026-06-08T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"57K cybersecurity pros switch jobs annually amid talent crunch : Report&nbsp;&nbsp;timesofindia.indiatimes.com","title":"57K cybersecurity pros switch jobs annually amid talent crunch : Report - timesofindia.indiatimes.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-74494aba2dcfee6e","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi1gFBVV95cUxQQ3diWG5weXhHMUtIeFMyVEVuQzlWeUhoMVM4aERDdm5BVUtfS2RIMkNYOUh3ak5zbFRxanB3YUxmQnZfTjlnYzdJMm42SHBjTmI5TFl3aUJPOFdtTWZ6b3hXcGV1aGVzYWFRZzIxY2k3NktvZGFLSWFuZ3BkZEUwbXp1VlhOM3RmMUFfRFFzXy00UzIwMkVzcFFLVTd5VVdua1EtYnFFcF9lcGpKRUNVTjRnUHZjWTltbEd6WW5KMHJHeGlUUVVJME93NnFNcUpDWmtNckNR?oc=5","published_at":"2026-06-06T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"HIGH","source":"Critical Infra & APTs","summary":"FBI Surveillance Network Breached: Salt Typhoon's Quiet War on American Law Enforcement Infrastructure&nbsp;&nbsp;Security Boulevard","title":"FBI Surveillance Network Breached: Salt Typhoon's Quiet War on American Law Enforcement Infrastructure - Security Boulevard"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-a2594f823480f495","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi1gFBVV95cUxQQ3diWG5weXhHMUtIeFMyVEVuQzlWeUhoMVM4aERDdm5BVUtfS2RIMkNYOUh3ak5zbFRxanB3YUxmQnZfTjlnYzdJMm42SHBjTmI5TFl3aUJPOFdtTWZ6b3hXcGV1aGVzYWFRZzIxY2k3NktvZGFLSWFuZ3BkZEUwbXp1VlhOM3RmMUFfRFFzXy00UzIwMkVzcFFLVTd5VVdua1EtYnFFcF9lcGpKRUNVTjRnUHZjWTltbEd6WW5KMHJHeGlUUVVJME93NnFNcUpDWmtNckNR?oc=5","published_at":"2026-06-06T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"HIGH","source":"Critical Infra & APTs","summary":"FBI Surveillance Network Breached: Salt Typhoon's Quiet War on American Law Enforcement Infrastructure&nbsp;&nbsp;securityboulevard.com","title":"FBI Surveillance Network Breached: Salt Typhoon's Quiet War on American Law Enforcement Infrastructure - securityboulevard.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-01e760197354d4bb","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMitwFBVV95cUxQLVl3RWRlcWRtWGxtTE9NS1l1MjA2cHNkSkVYeTk2azh2ZE50aGRzbTdLNGZFTWV6UnhfN0lVMHF5MnQxMXdpa2l3YlZQb0l5UmRDc3pSNm9kQlpnMFpiMTVhNTZFVEVXQkkzdC1GRWEweW9MRTltUlFoaVgyYkFBTC10bmRtZ2lqVTI3UjI1S0RzWmdlbG5HSzJsaGltOEswTHdhQXVJX1A1ZkZZWnM2MzhsZF9zaW8?oc=5","published_at":"2026-06-04T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Pentagon\u2019s Cyber Defense Command drafting plan to defend critical infrastructure&nbsp;&nbsp;Breaking Defense","title":"Pentagon\u2019s Cyber Defense Command drafting plan to defend critical infrastructure - Breaking Defense"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-b817553bc766088d","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMitwFBVV95cUxQLVl3RWRlcWRtWGxtTE9NS1l1MjA2cHNkSkVYeTk2azh2ZE50aGRzbTdLNGZFTWV6UnhfN0lVMHF5MnQxMXdpa2l3YlZQb0l5UmRDc3pSNm9kQlpnMFpiMTVhNTZFVEVXQkkzdC1GRWEweW9MRTltUlFoaVgyYkFBTC10bmRtZ2lqVTI3UjI1S0RzWmdlbG5HSzJsaGltOEswTHdhQXVJX1A1ZkZZWnM2MzhsZF9zaW8?oc=5","published_at":"2026-06-04T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Pentagon\u2019s Cyber Defense Command drafting plan to defend critical infrastructure&nbsp;&nbsp;breakingdefense.com","title":"Pentagon\u2019s Cyber Defense Command drafting plan to defend critical infrastructure - breakingdefense.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-024bcec34edad3d9","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTFA3dDVlb3d0WGpCR1BlMEFNdlJ5MVIydHFZczQtVWxwYVE4T0JveU1LN2MzRGtUZjJwb0xxMXdUdGhEMklJN2xuRk1MUnBpSU9ZME9LMWo2b3VrcVIweW4w?oc=5","published_at":"2026-06-03T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Species-specific assessment of climate change vulnerability in Himalayan Pikas and identification of at-risk elevational and latitudinal zones&nbsp;&nbsp;Nature","title":"Species-specific assessment of climate change vulnerability in Himalayan Pikas and identification of at-risk elevational and latitudinal zones - Nature"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e533068ee04edb5a","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxOQ1VadEJqcGd0akFYMEp3UnFxOHdGdzlGNk9rd1ZWZ2RNZDdWeEhuVzBBNHhxYUJ6UldHU0pHaDdZcFBXWmx3TEhKQVFnU1lNa21hOEhSUE5lenV6dkl3djdXak1SNmFtZEFiTTZmYlBCUElDLWJrZ19DZkZJY014Y2lFQWRUQ0gtSTRyeVc5SnlBQjQzSERfVlhlOVNPYUpXQmswVGxJQXdxUQ?oc=5","published_at":"2026-06-03T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Adversaries Could Really Harm U.S. Infrastructure, Experts Warn&nbsp;&nbsp;AFCEA International","title":"Adversaries Could Really Harm U.S. Infrastructure, Experts Warn - AFCEA International"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-64da18ef3087699c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxQOGJKcEhRVDdhS0dWc3FvdldycXVaVUxmMnU4VlI1eXpzTmNjeE9sZWRxS0gzMjZ4YmJpVXRWcFVsYjVmVnFYbTFaVFRKYkd2WXJPejJQdTJhM0NlWmlmanJja1JvYkh3TU1DUVE4NzAwWE1EcVBmWW85SkFkUEtwdGNpcDh1ZTFzanZubFF5aGhUMDJfbGRvU3llOGdkTGh0VnpRNW9CZXJsOHfSAasBQVVfeXFMUDhiSnBIUVQ3YUtHVnNxb3ZXcnF1WlVMZjJ1OFZSNXl6c05jY3hPbGVkcUtIMzI2eGJiaVV0VnBVbGI1ZlZxWG0xWlRUSmJHdllyT3oyUHUyYTNDZVppZmpyY2tSb2JId01NQ1FRODcwMFhNRHFQZllvOUpBZFBLcHRjaXA4dWUxc2p2bmxReWhoVDAyX2xkb1N5ZThnZExodFZ6UTVvQmVybDh3?oc=5","published_at":"2026-06-03T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Nyagatare tops climate vulnerability rankings| The New Times&nbsp;&nbsp;The New Times","title":"Nyagatare tops climate vulnerability rankings| The New Times - The New Times"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-83d6ca588cbd84d9","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxOQ1VadEJqcGd0akFYMEp3UnFxOHdGdzlGNk9rd1ZWZ2RNZDdWeEhuVzBBNHhxYUJ6UldHU0pHaDdZcFBXWmx3TEhKQVFnU1lNa21hOEhSUE5lenV6dkl3djdXak1SNmFtZEFiTTZmYlBCUElDLWJrZ19DZkZJY014Y2lFQWRUQ0gtSTRyeVc5SnlBQjQzSERfVlhlOVNPYUpXQmswVGxJQXdxUQ?oc=5","published_at":"2026-06-03T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Adversaries Could Really Harm U.S. Infrastructure, Experts Warn&nbsp;&nbsp;afcea.org","title":"Adversaries Could Really Harm U.S. Infrastructure, Experts Warn - afcea.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-71139f44ec4dec0b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTFA3dDVlb3d0WGpCR1BlMEFNdlJ5MVIydHFZczQtVWxwYVE4T0JveU1LN2MzRGtUZjJwb0xxMXdUdGhEMklJN2xuRk1MUnBpSU9ZME9LMWo2b3VrcVIweW4w?oc=5","published_at":"2026-06-03T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Species-specific assessment of climate change vulnerability in Himalayan Pikas and identification of at-risk elevational and latitudinal zones&nbsp;&nbsp;nature.com","title":"Species-specific assessment of climate change vulnerability in Himalayan Pikas and identification of at-risk elevational and latitudinal zones - nature.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1413c8c09bb8f76b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE9hSU10NFF4dFlpcHZvMklTZ2xZR0NrR2lEX29ib2RVTEFLb0dIRHRVNUdlbjlZTXloUFJOajVab1ZWQk5OMUE1OS1VMTdjUnVtWmZlRFE3MV9udGlwT3Fz?oc=5","published_at":"2026-06-02T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Industrial Switch Security","summary":"Vulnerability of fishery resources to climate change in the Tropical Eastern Pacific Ecosystem off Peru&nbsp;&nbsp;Nature","title":"Vulnerability of fishery resources to climate change in the Tropical Eastern Pacific Ecosystem off Peru - Nature"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6f4b616af60708fe","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE9hSU10NFF4dFlpcHZvMklTZ2xZR0NrR2lEX29ib2RVTEFLb0dIRHRVNUdlbjlZTXloUFJOajVab1ZWQk5OMUE1OS1VMTdjUnVtWmZlRFE3MV9udGlwT3Fz?oc=5","published_at":"2026-06-02T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Industrial Switch Security","summary":"Vulnerability of fishery resources to climate change in the Tropical Eastern Pacific Ecosystem off Peru&nbsp;&nbsp;nature.com","title":"Vulnerability of fishery resources to climate change in the Tropical Eastern Pacific Ecosystem off Peru - nature.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9e30562ef08b8441","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiyAFBVV95cUxPOVlhaExxd1lmeHZvZDZUNktWdmxKNFZQOTctN1RTeWZCOV9HOEQ0aGhqdXpZQ2xwSEd0YkZENnlNT3pGWV9OcTNMdlJ3dExoNE8teFo1YUJIdnlsQjJCb1h6UXQzNmNERzhJUWowSG94cVFuNkV0YkZDXzNhWUl5a1A0YWpYazhKaUtPdk1oV3YwTzI4VVNMcWQtTDdacVk5V0ZpRUI3YUU1WFpYQ1oxWnBkeDlLbzBfT1hXSlA4R1Z2LWpYLS1ORw?oc=5","published_at":"2026-06-02T02:33:31+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Can Bangladesh defend itself in the great-power cyber war?&nbsp;&nbsp;The Daily Star","title":"Can Bangladesh defend itself in the great-power cyber war? - The Daily Star"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-65f304fcc39cb9d8","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxOSFIxR2U3WEN1TjBPRlg3VV96VnFWVVU3eThvSjJqY1pmY3ZCTC1KM3NZVTR0Qmx2Y1VOV205c2JsZzZhM0xta1VzWUtUSEZpUU9kVzlPN0FQc3JfdllmVm9fOVlkY3gtYlFlUFlRcUQxSkR4Y3BwV2tDd3JtUTZfSTl3?oc=5","published_at":"2026-06-01T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Turn Privacy Regulation into a Competitive Advantage&nbsp;&nbsp;Harvard Business Review","title":"Turn Privacy Regulation into a Competitive Advantage - Harvard Business Review"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ce41fad6ff0c7beb","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxOSFIxR2U3WEN1TjBPRlg3VV96VnFWVVU3eThvSjJqY1pmY3ZCTC1KM3NZVTR0Qmx2Y1VOV205c2JsZzZhM0xta1VzWUtUSEZpUU9kVzlPN0FQc3JfdllmVm9fOVlkY3gtYlFlUFlRcUQxSkR4Y3BwV2tDd3JtUTZfSTl3?oc=5","published_at":"2026-06-01T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Turn Privacy Regulation into a Competitive Advantage&nbsp;&nbsp;hbr.org","title":"Turn Privacy Regulation into a Competitive Advantage - hbr.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ca076f8f1bc78c04","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikAFBVV95cUxPR1pWVzNycU1xWmdWR21mV2t3bHJsNk5yRUhVVzJKR1RMX3NoOHhpSWZySEdJb1NhUjVlSUJYYWRhRkFOMGJPelBDNlk5eEdaT2R4bWpRbFlKNHdNbmNhTXhnWmhjQnRTOEFNVng2S0dzTW53RjJHZ3BhbTRkOWNLVVZPcHpaSTAtNDRkcmN3Yk4?oc=5","published_at":"2026-05-28T03:02:58+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Infrastructure Destruction Squad & BLACKNET-00: The Rise of a Hybrid Hacktivist-Ransomware Threat&nbsp;&nbsp;KELA Cyber Threat Intelligence","title":"Infrastructure Destruction Squad & BLACKNET-00: The Rise of a Hybrid Hacktivist-Ransomware Threat - KELA Cyber Threat Intelligence"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f2699af5d4ad7619","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiwAFBVV95cUxQUEMxNlFUQUphZk1MXzZfbldlRjNjelpXS2JNdGVaYXRDYXFPX2lLMlBXZW9WbjFvc2VxRjBfY2o2aWdINWZUVzA2V01DWVN2X2xHQ0IwV09sSDhpaUNacHk2UXplUWV1QWVZeHpROGNjYUd2UF85TEFva3NNOHBWaGhxY2JZOVZ2ZTNrLS1uQlFOQ1g1b0FnV3g2SFBlSmp0amtCeWczbGZhZ2s2YUI4QjFQWTQyeDA0SWJ0d2FDQ1A?oc=5","published_at":"2026-05-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Critical Infra & APTs","summary":"Senate Bill Aims for Cyber Task Force Focused on Chinese Threats&nbsp;&nbsp;hstoday.us","title":"Senate Bill Aims for Cyber Task Force Focused on Chinese Threats - hstoday.us"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2bbea2ffb2259a9d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiwAFBVV95cUxQUEMxNlFUQUphZk1MXzZfbldlRjNjelpXS2JNdGVaYXRDYXFPX2lLMlBXZW9WbjFvc2VxRjBfY2o2aWdINWZUVzA2V01DWVN2X2xHQ0IwV09sSDhpaUNacHk2UXplUWV1QWVZeHpROGNjYUd2UF85TEFva3NNOHBWaGhxY2JZOVZ2ZTNrLS1uQlFOQ1g1b0FnV3g2SFBlSmp0amtCeWczbGZhZ2s2YUI4QjFQWTQyeDA0SWJ0d2FDQ1A?oc=5","published_at":"2026-05-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Critical Infra & APTs","summary":"Senate Bill Aims for Cyber Task Force Focused on Chinese Threats&nbsp;&nbsp;Homeland Security Today","title":"Senate Bill Aims for Cyber Task Force Focused on Chinese Threats - Homeland Security Today"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-044d1b03570782b8","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiwwFBVV95cUxPVnJZY2hvcmdwQXgtS2tlcmNOR0RHUUlHNC1RQkNyeGNkeW4wZElMaW03SGJZeF81UVdqRGF0Sk5QbmRiQ3dwb3dHNU9KUmZwTGdzMFJ3aVZLaWZ2ZVk2Z2t6R2ZvYk1MTi0xTld1TXRKUThBSV9fcUI5eXIwLWVCbmNFYWRjaWpMRTVvVjNPaDRRTW5MOWI2dmFzRnBkSmlHWEx5bWdWU3RlamZnSVI5dmFMcTNOU3RYWWpkbS1PSzc0S0E?oc=5","published_at":"2026-05-26T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"OMB Switches to \u2018Risk-Based Approach\u2019 to Cybersecurity Incident Response&nbsp;&nbsp;fedweek.com","title":"OMB Switches to \u2018Risk-Based Approach\u2019 to Cybersecurity Incident Response - fedweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-1391d5bf21cd8d49","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiwwFBVV95cUxPVnJZY2hvcmdwQXgtS2tlcmNOR0RHUUlHNC1RQkNyeGNkeW4wZElMaW03SGJZeF81UVdqRGF0Sk5QbmRiQ3dwb3dHNU9KUmZwTGdzMFJ3aVZLaWZ2ZVk2Z2t6R2ZvYk1MTi0xTld1TXRKUThBSV9fcUI5eXIwLWVCbmNFYWRjaWpMRTVvVjNPaDRRTW5MOWI2dmFzRnBkSmlHWEx5bWdWU3RlamZnSVI5dmFMcTNOU3RYWWpkbS1PSzc0S0E?oc=5","published_at":"2026-05-26T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"OMB Switches to \u2018Risk-Based Approach\u2019 to Cybersecurity Incident Response&nbsp;&nbsp;FEDweek","title":"OMB Switches to \u2018Risk-Based Approach\u2019 to Cybersecurity Incident Response - FEDweek"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-aa603f025d3cdf99","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiywFBVV95cUxPZUdWUGx0NnduNHI2WU1ZbnhVUmpaWVhDLTUxbDhxcjVtWUVJQjNkSVFtVGhBbGVwLUpfNWRLdjFQT09jckZSSzc2anAxYjlWekFqdVNPdTMzWWxJdnY1T0RJRFBFYkdELXB0UmExeFdYaHlDM0wwSm9wd01tY0ZMR2QtMU9WTmMwZW12WWxzSVFKbktKU2tYRWE0VHZ1NjBiLXh2dDlXdmYwaE01aFVhZkZUX1pzeU5TRTU1V3QwR3pTS2p2YVF4OGZOYw?oc=5","published_at":"2026-05-25T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Mythos Exposes a Bigger Problem in Critical Infrastructure Cyber Defense&nbsp;&nbsp;Homeland Security Today","title":"Mythos Exposes a Bigger Problem in Critical Infrastructure Cyber Defense - Homeland Security Today"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-0fd4a53da0a81ae6","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiywFBVV95cUxPZUdWUGx0NnduNHI2WU1ZbnhVUmpaWVhDLTUxbDhxcjVtWUVJQjNkSVFtVGhBbGVwLUpfNWRLdjFQT09jckZSSzc2anAxYjlWekFqdVNPdTMzWWxJdnY1T0RJRFBFYkdELXB0UmExeFdYaHlDM0wwSm9wd01tY0ZMR2QtMU9WTmMwZW12WWxzSVFKbktKU2tYRWE0VHZ1NjBiLXh2dDlXdmYwaE01aFVhZkZUX1pzeU5TRTU1V3QwR3pTS2p2YVF4OGZOYw?oc=5","published_at":"2026-05-25T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Mythos Exposes a Bigger Problem in Critical Infrastructure Cyber Defense&nbsp;&nbsp;hstoday.us","title":"Mythos Exposes a Bigger Problem in Critical Infrastructure Cyber Defense - hstoday.us"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-db3452de2d69b91b","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi7AFBVV95cUxQQU1pZzlJQTBpT2plUnJMTTNwNVY1MXdVSkZlcF9aSzhZYjBmanJjRHBSUDJtLWxQVkpzYVJNXzd5cVhEc01pQy00YXhkZmdieU9GdXo5Z0pKUkFxXzRZd0xncENSV2diTWdBR1dHS3U1NXhIbjNQc3FJNXFvbXNpakhDSFo5ZXEwSEpCU2RZUUdqZkhUREZyZzRyU0hRZXJRUFNnSEdieldtdzBnRU5PUWJWOW81VmRkU21MLWtGREdIRFlXbnFtVkJaWmNwS21ZVF9tRzRjNzNPU3hxajViYXJGc2hhR29TeXNZZA?oc=5","published_at":"2026-05-22T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Critical Infra & APTs","summary":"Iranian state-sponsored hackers exploit Microsoft Exchange, Fortinet flaws to access US infrastructure networks, CRS finds&nbsp;&nbsp;industrialcyber.co","title":"Iranian state-sponsored hackers exploit Microsoft Exchange, Fortinet flaws to access US infrastructure networks, CRS finds - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-291ab5e43a74aef3","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi7AFBVV95cUxQQU1pZzlJQTBpT2plUnJMTTNwNVY1MXdVSkZlcF9aSzhZYjBmanJjRHBSUDJtLWxQVkpzYVJNXzd5cVhEc01pQy00YXhkZmdieU9GdXo5Z0pKUkFxXzRZd0xncENSV2diTWdBR1dHS3U1NXhIbjNQc3FJNXFvbXNpakhDSFo5ZXEwSEpCU2RZUUdqZkhUREZyZzRyU0hRZXJRUFNnSEdieldtdzBnRU5PUWJWOW81VmRkU21MLWtGREdIRFlXbnFtVkJaWmNwS21ZVF9tRzRjNzNPU3hxajViYXJGc2hhR29TeXNZZA?oc=5","published_at":"2026-05-22T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Critical Infra & APTs","summary":"Iranian state-sponsored hackers exploit Microsoft Exchange, Fortinet flaws to access US infrastructure networks, CRS finds&nbsp;&nbsp;Industrial Cyber","title":"Iranian state-sponsored hackers exploit Microsoft Exchange, Fortinet flaws to access US infrastructure networks, CRS finds - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-547c678131df6406","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxNNHpKTmRKN2RkNTBDbU00LVNmSENfSmN0TzNFM1dCR0kwOHpBZTNyMnNONmxCYmJ3SFl1QTZXYXBOZllwYTV5eE11ZHFKYm1NYTJMVXRxb2VlODN1bUVuU3R3dXdJNG11N3UzdDd0MGpkZ05mRnNHQVFNSEpZZkFScFRNTm9FR0dNckxUTEpIX1hyY2hvVjV4QmstbnlmaUM5ajl5Tm5qeUk1QQ?oc=5","published_at":"2026-05-16T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Apple @ Work: How AI is going to change cybersecurity training for Mac admins&nbsp;&nbsp;9to5mac.com","title":"Apple @ Work: How AI is going to change cybersecurity training for Mac admins - 9to5mac.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5b39ca75df48e4d5","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiakFVX3lxTE5tVTBuMmdDMG9LMDFhcUhFeF9ySUQzeFEwU0ttNTVhQlZQVEg1akJFbU5nVlBlTEtDYmJVVmJBM0pOM2JnRE04bmpBb1RJdGdfakNXRFIyakp2M2JoYnJrUHhKaVhSbXRRSGc?oc=5","published_at":"2026-05-16T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Top Cyber Security Companies in India (2026)&nbsp;&nbsp;Jaro Education","title":"Top Cyber Security Companies in India (2026) - Jaro Education"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1914ac656636ca0d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiakFVX3lxTE5tVTBuMmdDMG9LMDFhcUhFeF9ySUQzeFEwU0ttNTVhQlZQVEg1akJFbU5nVlBlTEtDYmJVVmJBM0pOM2JnRE04bmpBb1RJdGdfakNXRFIyakp2M2JoYnJrUHhKaVhSbXRRSGc?oc=5","published_at":"2026-05-16T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Top Cyber Security Companies in India (2026)&nbsp;&nbsp;jaroeducation.com","title":"Top Cyber Security Companies in India (2026) - jaroeducation.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b6abf1adf6832791","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxNNHpKTmRKN2RkNTBDbU00LVNmSENfSmN0TzNFM1dCR0kwOHpBZTNyMnNONmxCYmJ3SFl1QTZXYXBOZllwYTV5eE11ZHFKYm1NYTJMVXRxb2VlODN1bUVuU3R3dXdJNG11N3UzdDd0MGpkZ05mRnNHQVFNSEpZZkFScFRNTm9FR0dNckxUTEpIX1hyY2hvVjV4QmstbnlmaUM5ajl5Tm5qeUk1QQ?oc=5","published_at":"2026-05-16T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Apple @ Work: How AI is going to change cybersecurity training for Mac admins&nbsp;&nbsp;9to5Mac","title":"Apple @ Work: How AI is going to change cybersecurity training for Mac admins - 9to5Mac"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-041220b23a39c98e","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxQenV5UEFlT2QtZGxtYmpZNThrbmpxVGNSckpCRXhCLWVmc1RyMC1lR3M5MTV5YS0zMENualZ2RkdjV1hNV2g4ZzY5ZEFnV1RDamI3WHBvVFFaVVFqUHBuNjg5VjgwdmNYZzZ3UDhGU0p1SDcyV3hhVVpNakFDWU00VUNjSGlJcXVibzBLMFpQbTFHX1hnd1Vvd1ZDTDBhblU?oc=5","published_at":"2026-05-14T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Palestine\u2019s Climate Change Planning Faces Its Limits&nbsp;&nbsp;carnegieendowment.org","title":"Palestine\u2019s Climate Change Planning Faces Its Limits - carnegieendowment.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c2689d9b9be509be","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxQenV5UEFlT2QtZGxtYmpZNThrbmpxVGNSckpCRXhCLWVmc1RyMC1lR3M5MTV5YS0zMENualZ2RkdjV1hNV2g4ZzY5ZEFnV1RDamI3WHBvVFFaVVFqUHBuNjg5VjgwdmNYZzZ3UDhGU0p1SDcyV3hhVVpNakFDWU00VUNjSGlJcXVibzBLMFpQbTFHX1hnd1Vvd1ZDTDBhblU?oc=5","published_at":"2026-05-14T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Palestine\u2019s Climate Change Planning Faces Its Limits&nbsp;&nbsp;Carnegie Endowment for International Peace","title":"Palestine\u2019s Climate Change Planning Faces Its Limits - Carnegie Endowment for International Peace"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-63b07bee88b40e16","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikwFBVV95cUxNaTRSdE1pWk1BQ20tUkFudEtfSFQ2VUROczJtT2dzQW5TaWdURXhsUGlYZFI5d0UwR0d4d2dWakM4ZmZKRDd3ZVhKbEtlX2tva0ZkMEoyQlJjb3p5aWpvQ045ZUNBRTlEeElKWFVIV3JRNkx2Q25xZXpXQmx0MUJwLVI3d1dpeTBTU0pucGd6eFpOX0U?oc=5","published_at":"2026-05-12T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"20 Leaders Who Built the CISO Era: 2 Decades of Change&nbsp;&nbsp;Dark Reading","title":"20 Leaders Who Built the CISO Era: 2 Decades of Change - Dark Reading"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-187f78e3be56f0b9","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikwFBVV95cUxNaTRSdE1pWk1BQ20tUkFudEtfSFQ2VUROczJtT2dzQW5TaWdURXhsUGlYZFI5d0UwR0d4d2dWakM4ZmZKRDd3ZVhKbEtlX2tva0ZkMEoyQlJjb3p5aWpvQ045ZUNBRTlEeElKWFVIV3JRNkx2Q25xZXpXQmx0MUJwLVI3d1dpeTBTU0pucGd6eFpOX0U?oc=5","published_at":"2026-05-12T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"20 Leaders Who Built the CISO Era: 2 Decades of Change&nbsp;&nbsp;darkreading.com","title":"20 Leaders Who Built the CISO Era: 2 Decades of Change - darkreading.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8a0d4581cea612ae","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxPMjF6Nm9ZZVQxX0NsX2NUZzVXcWxiaTBiMmUwVVRfdG8wNm1iazNhbzIyOEdvT1hqNHVaR2o5QmkxM0w5a05Ib21fX0lwdFIxc3R4Vk4wcUZTLUpPVHJfV3ozeW4xX0VRMm00d2RiN2J5blhsN1l6eGlaaHVzNXJiM2E1dkdWUFpFUjBDR1U2ZTFCYmxHU0RnTkRVaFNfVndxTUVOZg?oc=5","published_at":"2026-05-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Universities Turn SOCs Into Cybersecurity Career Pipelines&nbsp;&nbsp;govtech.com","title":"Universities Turn SOCs Into Cybersecurity Career Pipelines - govtech.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d06be96c43b7a292","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxPMjF6Nm9ZZVQxX0NsX2NUZzVXcWxiaTBiMmUwVVRfdG8wNm1iazNhbzIyOEdvT1hqNHVaR2o5QmkxM0w5a05Ib21fX0lwdFIxc3R4Vk4wcUZTLUpPVHJfV3ozeW4xX0VRMm00d2RiN2J5blhsN1l6eGlaaHVzNXJiM2E1dkdWUFpFUjBDR1U2ZTFCYmxHU0RnTkRVaFNfVndxTUVOZg?oc=5","published_at":"2026-05-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Universities Turn SOCs Into Cybersecurity Career Pipelines&nbsp;&nbsp;GovTech","title":"Universities Turn SOCs Into Cybersecurity Career Pipelines - GovTech"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-d44fbf529ea361d6","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMimAFBVV95cUxNcXBnZlhReExGaWtieC1KTVRKMUtETnl4RnpEd2ZtREpXYmVYS2xmLUpTN2VOQ0cyUmRERjJMM3FXeDZhcEplQ0I4NW9JQ0FjZ21BLV8zbURldFUtWUx3Y0lUVTFWbklQYTJEanp4YkJROEFpVzg4MVBrTHB2Q3g4UGg0aHNfbmY2OFk1T0pjS01PdVF0bDUydg?oc=5","published_at":"2026-05-08T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Linux Kernel Killswitch Proposed After Recent Vulnerability Disclosures&nbsp;&nbsp;Linuxiac","title":"Linux Kernel Killswitch Proposed After Recent Vulnerability Disclosures - Linuxiac"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9ea3d7b076f6920f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi6AFBVV95cUxPeEVSdkxSaXRESzRkeFpJWXd4V2R3TW1DWmZITWRyMHV0eXA1YlFCSUU3bWZHSDJLRUZDUFNiMnVQalZjRl9JS1laeVlMWGpvNGRRWl9LZ0dmNWdKQlBuQ0tQdUpVMnVTSk9pQldOb25vZXkzc1g3ejdnUHAwVVRKZXplVEFyb1owcWthbW1jM1d4LWh3ZUx2OTRJMDRpMUZxT0NnZ1ZQZ3JEbEw1OFNWdVBPZkwyS3MtSS1BTUphVFlyWFFNM1Z4dV9zUEp4eFMwdlV5LTlnbjJ2VTNrdllMSHZuQ3N3U2I2?oc=5","published_at":"2026-05-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Dragos details AI-assisted intrusion targeting Mexican water utility as Claude, OpenAI models used to pursue OT access&nbsp;&nbsp;industrialcyber.co","title":"Dragos details AI-assisted intrusion targeting Mexican water utility as Claude, OpenAI models used to pursue OT access - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-85f36f2ea61668fe","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi6AFBVV95cUxPeEVSdkxSaXRESzRkeFpJWXd4V2R3TW1DWmZITWRyMHV0eXA1YlFCSUU3bWZHSDJLRUZDUFNiMnVQalZjRl9JS1laeVlMWGpvNGRRWl9LZ0dmNWdKQlBuQ0tQdUpVMnVTSk9pQldOb25vZXkzc1g3ejdnUHAwVVRKZXplVEFyb1owcWthbW1jM1d4LWh3ZUx2OTRJMDRpMUZxT0NnZ1ZQZ3JEbEw1OFNWdVBPZkwyS3MtSS1BTUphVFlyWFFNM1Z4dV9zUEp4eFMwdlV5LTlnbjJ2VTNrdllMSHZuQ3N3U2I2?oc=5","published_at":"2026-05-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Dragos details AI-assisted intrusion targeting Mexican water utility as Claude, OpenAI models used to pursue OT access&nbsp;&nbsp;Industrial Cyber","title":"Dragos details AI-assisted intrusion targeting Mexican water utility as Claude, OpenAI models used to pursue OT access - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-31a0e9dc31f213d1","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMimAFBVV95cUxNcXBnZlhReExGaWtieC1KTVRKMUtETnl4RnpEd2ZtREpXYmVYS2xmLUpTN2VOQ0cyUmRERjJMM3FXeDZhcEplQ0I4NW9JQ0FjZ21BLV8zbURldFUtWUx3Y0lUVTFWbklQYTJEanp4YkJROEFpVzg4MVBrTHB2Q3g4UGg0aHNfbmY2OFk1T0pjS01PdVF0bDUydg?oc=5","published_at":"2026-05-08T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Linux Kernel Killswitch Proposed After Recent Vulnerability Disclosures&nbsp;&nbsp;linuxiac.com","title":"Linux Kernel Killswitch Proposed After Recent Vulnerability Disclosures - linuxiac.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-255b120e43113dd3","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMie0FVX3lxTE1lU2RTOHJTNnhYOC0tQ0xoZjNZeEZYTndaZzZwQmZPdm1Dcl9Oa0UxcEZObmY5RkozejlLalRPZ0VvWWo4T0VoQU9VQ1ZxYzhHUld5NXFBTTR5NjlYbXRwYlVyeVlKM0t2LUNVd3VrNU1MM2Vxdm9HSGhRa9IBgAFBVV95cUxPeTduaUE4cEpCdVpiWHl5WGVERmJwTHdKZ3BZVnVjNk5zOWR1QTBDcjVBRy1fWXRwaHZMSXZWRGxnWTBCNklhX0FFdk1yXzFPRWswNU1JM0tmYzkteTYyVV9ZNENmQkdiTk9ndW9hQ2xIcDN0cUlyNllLQWRyc2toZg?oc=5","published_at":"2026-05-07T09:03:41+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"CI Fortify Targets Critical Infrastructure Threats&nbsp;&nbsp;The Cyber Express","title":"CI Fortify Targets Critical Infrastructure Threats - The Cyber Express"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-e7e55935def25b62","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMie0FVX3lxTE1lU2RTOHJTNnhYOC0tQ0xoZjNZeEZYTndaZzZwQmZPdm1Dcl9Oa0UxcEZObmY5RkozejlLalRPZ0VvWWo4T0VoQU9VQ1ZxYzhHUld5NXFBTTR5NjlYbXRwYlVyeVlKM0t2LUNVd3VrNU1MM2Vxdm9HSGhRa9IBgAFBVV95cUxPeTduaUE4cEpCdVpiWHl5WGVERmJwTHdKZ3BZVnVjNk5zOWR1QTBDcjVBRy1fWXRwaHZMSXZWRGxnWTBCNklhX0FFdk1yXzFPRWswNU1JM0tmYzkteTYyVV9ZNENmQkdiTk9ndW9hQ2xIcDN0cUlyNllLQWRyc2toZg?oc=5","published_at":"2026-05-07T09:03:41+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"CI Fortify Targets Critical Infrastructure Threats&nbsp;&nbsp;thecyberexpress.com","title":"CI Fortify Targets Critical Infrastructure Threats - thecyberexpress.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-140aa688c967f6df","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMipwFBVV95cUxPMzlSMXhMajg3dmhWT1pJS2lpZEc0M3d3MVN2UndGcEJRc0dwOFFJM2NEUmRndFVIWDNIQmY5UXJMcVhCcDFodUZ0Rlg4XzlDU0JkY1NQT0dHb2M3cTV0UUJpc1N3SktTTW1KZ1RMWmZWYkUzcGJpZ2puMjBTZC0zME40RjRLMmoxd0tqbEFkcXZqVzdzRG5mZVNzbFRyVXJsbkF6d2FVZw?oc=5","published_at":"2026-05-07T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"How Modern PLC Systems Improve Industrial Automation Efficiency and Reliability&nbsp;&nbsp;techbullion.com","title":"How Modern PLC Systems Improve Industrial Automation Efficiency and Reliability - techbullion.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-ab9002e35dbca354","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMitgFBVV95cUxPRVBzeG1pTUhCcmFRMjl3NlNMWlhNOHhwVjlKclFDWmt0ZUVIcUxZMGtha3VXU2tuRU55UVgzVVA3c3BtOWUzZC1URjBqYmVScnNOTnUyOG11cDljdFhvZ0hkLVBPNThoNUNQazNWN3g2QUZUZlNVTDNaNmZCSklIQmh6QnVLNEpjYjJjSGxUMURRb2oyTkdpYnp6Rm5tUm1obWpYQURBek1pT2x3SURXTXA3V2FMdw?oc=5","published_at":"2026-05-07T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Feds urge greater protection of critical infrastructure from Chinese hacks&nbsp;&nbsp;Washington Times","title":"Feds urge greater protection of critical infrastructure from Chinese hacks - Washington Times"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7cddc6a40410dfef","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiwAFBVV95cUxOUG9pQ3FTcWRSMW5rTUZBRG5acHBkNGJheEVhZFozVVd6RU44RENZcnVqRzZsanFKRDd3LTNDYnItb21qN2pLRDNSY0xLZU1VTHZ0Qy1la0R1YnhCSHRiWnZ5N3REcl9xR1hhTnJTOGlVeXQxVFM5amJuNDdsSFRVQXhEcGFDeEZwaGx4QnhHS1dIQU83RjVIRnc1TWhaQ01uNll1Y29tT05sNWNVX1Job2hWbG85dk9FRTdGYWRxUkU?oc=5","published_at":"2026-05-07T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Ex-Biden adviser urges Australia to ban Chinese EVs on spy fears&nbsp;&nbsp;afr.com","title":"Ex-Biden adviser urges Australia to ban Chinese EVs on spy fears - afr.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-53a753badedad4e6","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMipwFBVV95cUxPMzlSMXhMajg3dmhWT1pJS2lpZEc0M3d3MVN2UndGcEJRc0dwOFFJM2NEUmRndFVIWDNIQmY5UXJMcVhCcDFodUZ0Rlg4XzlDU0JkY1NQT0dHb2M3cTV0UUJpc1N3SktTTW1KZ1RMWmZWYkUzcGJpZ2puMjBTZC0zME40RjRLMmoxd0tqbEFkcXZqVzdzRG5mZVNzbFRyVXJsbkF6d2FVZw?oc=5","published_at":"2026-05-07T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"How Modern PLC Systems Improve Industrial Automation Efficiency and Reliability&nbsp;&nbsp;TechBullion","title":"How Modern PLC Systems Improve Industrial Automation Efficiency and Reliability - TechBullion"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-abf0dc51912fbfb3","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMitgFBVV95cUxPRVBzeG1pTUhCcmFRMjl3NlNMWlhNOHhwVjlKclFDWmt0ZUVIcUxZMGtha3VXU2tuRU55UVgzVVA3c3BtOWUzZC1URjBqYmVScnNOTnUyOG11cDljdFhvZ0hkLVBPNThoNUNQazNWN3g2QUZUZlNVTDNaNmZCSklIQmh6QnVLNEpjYjJjSGxUMURRb2oyTkdpYnp6Rm5tUm1obWpYQURBek1pT2x3SURXTXA3V2FMdw?oc=5","published_at":"2026-05-07T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Feds urge greater protection of critical infrastructure from Chinese hacks&nbsp;&nbsp;washingtontimes.com","title":"Feds urge greater protection of critical infrastructure from Chinese hacks - washingtontimes.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f7db3479db923713","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMie0FVX3lxTFAxeGRvZGFUZkR6NFB1Z1Y2WTE2XzkwOHhLSHlpemFXTkZ5VkloU1dzN2ZlQklFMzUtM1JPQUN6WkRvMDRsUVZDVTBEdks4cmd0bjVoVXJIMEpIc1lYUTNOWm55aWtVOVZKVlVySHlkODY5N25BeVI5cEE4MA?oc=5","published_at":"2026-05-07T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"The name is Spy, Corporate Spy&nbsp;&nbsp;Klement on Investing","title":"The name is Spy, Corporate Spy - Klement on Investing"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-3490c850884626d2","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiwAFBVV95cUxOUG9pQ3FTcWRSMW5rTUZBRG5acHBkNGJheEVhZFozVVd6RU44RENZcnVqRzZsanFKRDd3LTNDYnItb21qN2pLRDNSY0xLZU1VTHZ0Qy1la0R1YnhCSHRiWnZ5N3REcl9xR1hhTnJTOGlVeXQxVFM5amJuNDdsSFRVQXhEcGFDeEZwaGx4QnhHS1dIQU83RjVIRnc1TWhaQ01uNll1Y29tT05sNWNVX1Job2hWbG85dk9FRTdGYWRxUkU?oc=5","published_at":"2026-05-07T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Ex-Biden adviser urges Australia to ban Chinese EVs on spy fears&nbsp;&nbsp;AFR","title":"Ex-Biden adviser urges Australia to ban Chinese EVs on spy fears - AFR"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c8510201c8a6633d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijAFBVV95cUxNakZ2MGRscjlvMDd1R0F6RGpKcFBDTDdGUFFKbF9vbjJldGQxUmtNTlBDTF9lajduTTdWMnhPYXlFay1LWm01YjExZmJGS21OU2tCb01VN3hVUnpRcDVnN18zMHJzLTRyYkRBRDZDN0djY1B4V1dRQUNlNTVZOW01QzQ3a2c4aUdfSlpSaA?oc=5","published_at":"2026-05-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"From the desk of the CISO: How will Anthropic\u2019s Mythos change vulnerability discovery?&nbsp;&nbsp;Barracuda Networks Blog","title":"From the desk of the CISO: How will Anthropic\u2019s Mythos change vulnerability discovery? - Barracuda Networks Blog"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-0e051fc1faecd608","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxQYUZ2a1ZDQnZqZ2RLeDBRNXo0SEhtUmExcm5VOW9sMUpaN2MxU25FOU94YjdjOU95dHZ3R193NHBjSU1aVGItUFNwMUNmOTVPQjhEOVdmQzZBTWszWE0tLVdHQzNjczZkRktyajNnVkNZYU1sTzRMQkREUEV0RWhsa19B?oc=5","published_at":"2026-05-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"CISA Launches Cyber Resilience Initiative&nbsp;&nbsp;rtoinsider.com","title":"CISA Launches Cyber Resilience Initiative - rtoinsider.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-33956eb7693756ce","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxQcEFYRlJ4ZTNEODR1RWI4VFpWTlZtRWNPeFVFM1AyZkFGc1hhYmFXWEx4YlM5c0txQTB3STJsbGowWVFSWlBPdVlldTVfRldpa1dmeUNLWngtSnZnU19tRTBQY2pvdTFMQ000VWl5Z0tGS0w1bG5SWU5wb2FqQ3hTNHJrc1h5b1RKVDVoMlRrTVctdWxxbHNBUk1qS0Q3LU5EcDRfS3VTVTJURkkzLWRTOQ?oc=5","published_at":"2026-05-06T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"CISA\u2019s \u2018CI Fortify\u2019 Aims to Secure Critical Infrastructure During Conflicts&nbsp;&nbsp;securityboulevard.com","title":"CISA\u2019s \u2018CI Fortify\u2019 Aims to Secure Critical Infrastructure During Conflicts - securityboulevard.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ccd44b5c6e82bd7c","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxQYUZ2a1ZDQnZqZ2RLeDBRNXo0SEhtUmExcm5VOW9sMUpaN2MxU25FOU94YjdjOU95dHZ3R193NHBjSU1aVGItUFNwMUNmOTVPQjhEOVdmQzZBTWszWE0tLVdHQzNjczZkRktyajNnVkNZYU1sTzRMQkREUEV0RWhsa19B?oc=5","published_at":"2026-05-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"CISA Launches Cyber Resilience Initiative&nbsp;&nbsp;RTO Insider","title":"CISA Launches Cyber Resilience Initiative - RTO Insider"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-d291d01c26c9ac33","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxQcEFYRlJ4ZTNEODR1RWI4VFpWTlZtRWNPeFVFM1AyZkFGc1hhYmFXWEx4YlM5c0txQTB3STJsbGowWVFSWlBPdVlldTVfRldpa1dmeUNLWngtSnZnU19tRTBQY2pvdTFMQ000VWl5Z0tGS0w1bG5SWU5wb2FqQ3hTNHJrc1h5b1RKVDVoMlRrTVctdWxxbHNBUk1qS0Q3LU5EcDRfS3VTVTJURkkzLWRTOQ?oc=5","published_at":"2026-05-06T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"CISA\u2019s \u2018CI Fortify\u2019 Aims to Secure Critical Infrastructure During Conflicts&nbsp;&nbsp;Security Boulevard","title":"CISA\u2019s \u2018CI Fortify\u2019 Aims to Secure Critical Infrastructure During Conflicts - Security Boulevard"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7ff7229f2740232e","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiwAFBVV95cUxPSDQ2bjhmOVVaanMxb2hnV0p3d1U4UE1XUTJXazVRY3B2QWFNc3Qzdmc5OElJSDJueWFSMDlWMmRNZmNaOUo3cHJiVUpPSUdsaFc2QU5GLWNWT1N1MVhWVXdSNzAxXzhYaWtiSUFsdFF2TkVhTkt0bjBkZ0dJUUtLcWN2S01YbGJRLTZOSG1ia3RoekVpNi1nbk1DbkhOckJERG1WVTR0T0NpamRUOXMxLWgxdFNUd0E4WXdKRGxrazjSAcABQVVfeXFMT3JIMDZCVlBLa2kyMER0OW55bkNESTlzb3lOd19EcWYxZWdMODJwbjA1c3ZZcDBDUlZRUnVZcE1WVG1KNWdKdTZrM0FSNk9LejdCQUt5T09raTRkcldOcjFTMUluRHMzM29IMEVWRlktV1hHWFBvNkJaaFc0QUlEeGRJVGJrSlJYMnM0NnBoZ3kzQmYzdDd3ck9MbWRfM1drVHAzQTVseGc4LXIxcHRJTXl1dnpZQ1NMMVVSbnRaUDdi?oc=5","published_at":"2026-05-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Opinion | How China-Gulf ties can turn energy vulnerability into sustainability&nbsp;&nbsp;scmp.com","title":"Opinion | How China-Gulf ties can turn energy vulnerability into sustainability - scmp.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-3582c2a724a00217","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijAFBVV95cUxNakZ2MGRscjlvMDd1R0F6RGpKcFBDTDdGUFFKbF9vbjJldGQxUmtNTlBDTF9lajduTTdWMnhPYXlFay1LWm01YjExZmJGS21OU2tCb01VN3hVUnpRcDVnN18zMHJzLTRyYkRBRDZDN0djY1B4V1dRQUNlNTVZOW01QzQ3a2c4aUdfSlpSaA?oc=5","published_at":"2026-05-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"From the desk of the CISO: How will Anthropic\u2019s Mythos change vulnerability discovery?&nbsp;&nbsp;blog.barracuda.com","title":"From the desk of the CISO: How will Anthropic\u2019s Mythos change vulnerability discovery? - blog.barracuda.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-e5dbe5c9ecaf06d1","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMipgFBVV95cUxQNGlGM2NsazMxb2lPVWR2M3dIdzM3UmdHNExBTVd4NHc2ZHRmSVViZUNsRjFZdmZNbGxHazlsUFA5U3FOWDIyeWlTS1liaHBFbkNKYURDTVluZHlOY0VPU1gzbFg2U2txeE5zQm4zT3BiaEtJdTF0Y1hkWTFwRkkwM0MyVFVVSFd0OHppcWMtX0pOQV9vMWsta01Pd3phMFZtT2VBeU9B?oc=5","published_at":"2026-05-06T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"New CISA initiative aims for critical infrastructure to operate offline during cyberattacks&nbsp;&nbsp;The Record from Recorded Future News","title":"New CISA initiative aims for critical infrastructure to operate offline during cyberattacks - The Record from Recorded Future News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1babbe89e1313f06","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiwAFBVV95cUxPSDQ2bjhmOVVaanMxb2hnV0p3d1U4UE1XUTJXazVRY3B2QWFNc3Qzdmc5OElJSDJueWFSMDlWMmRNZmNaOUo3cHJiVUpPSUdsaFc2QU5GLWNWT1N1MVhWVXdSNzAxXzhYaWtiSUFsdFF2TkVhTkt0bjBkZ0dJUUtLcWN2S01YbGJRLTZOSG1ia3RoekVpNi1nbk1DbkhOckJERG1WVTR0T0NpamRUOXMxLWgxdFNUd0E4WXdKRGxrazjSAcABQVVfeXFMT3JIMDZCVlBLa2kyMER0OW55bkNESTlzb3lOd19EcWYxZWdMODJwbjA1c3ZZcDBDUlZRUnVZcE1WVG1KNWdKdTZrM0FSNk9LejdCQUt5T09raTRkcldOcjFTMUluRHMzM29IMEVWRlktV1hHWFBvNkJaaFc0QUlEeGRJVGJrSlJYMnM0NnBoZ3kzQmYzdDd3ck9MbWRfM1drVHAzQTVseGc4LXIxcHRJTXl1dnpZQ1NMMVVSbnRaUDdi?oc=5","published_at":"2026-05-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Opinion | How China-Gulf ties can turn energy vulnerability into sustainability&nbsp;&nbsp;South China Morning Post","title":"Opinion | How China-Gulf ties can turn energy vulnerability into sustainability - South China Morning Post"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-428c6a80cc2ca608","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMipgFBVV95cUxQNGlGM2NsazMxb2lPVWR2M3dIdzM3UmdHNExBTVd4NHc2ZHRmSVViZUNsRjFZdmZNbGxHazlsUFA5U3FOWDIyeWlTS1liaHBFbkNKYURDTVluZHlOY0VPU1gzbFg2U2txeE5zQm4zT3BiaEtJdTF0Y1hkWTFwRkkwM0MyVFVVSFd0OHppcWMtX0pOQV9vMWsta01Pd3phMFZtT2VBeU9B?oc=5","published_at":"2026-05-06T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"New CISA initiative aims for critical infrastructure to operate offline during cyberattacks&nbsp;&nbsp;therecord.media","title":"New CISA initiative aims for critical infrastructure to operate offline during cyberattacks - therecord.media"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-3f297e09c44a5c85","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxPMkhlOTRYanBCanpORWsyUGtrSWVhZVhKQ01TVkZoNGJaUVRDOFFEaG1GNF9sYVI0NTVJem9YdXBUYmUwQVZCNnlrMndXLXpnR05vZDY1bVZjYlpYT0I1MG8tY3JXa1J6MkJiOWp6bmpONU50TVg2UmIxdm11a25KcW9fWFk3YnozUE93QjlSYVRhb1B4OVlRMlhyMGxHeWdZNHI3eUE3TUJhTVU?oc=5","published_at":"2026-05-05T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"CISA wants critical infrastructure to operate \u2018weeks to months\u2019 in isolation during conflict&nbsp;&nbsp;CyberScoop","title":"CISA wants critical infrastructure to operate \u2018weeks to months\u2019 in isolation during conflict - CyberScoop"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-78cd5fa22ecf81b0","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMilAFBVV95cUxPNTFGM3VEUWhEbHY5WFFqcHY3aWlBTUJrc0JRNUJqN0NoZkYtQkVpVUVBRl9URjFpeUxRZm15M2tQTERyWTJjaHp6U3V4cGFYSy1EOEN3MThIRkEzQUJSclZ6OEhMM1B5SDFzaWJoOFpqWVFqMnE2QTVjN3pzdVZMMHNuV3NrSm9UMUFTd0NnbEFUbjFx?oc=5","published_at":"2026-05-05T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"CISA urges critical infrastructure firms to \u2018fortify\u2019 before it\u2019s too late&nbsp;&nbsp;cybersecuritydive.com","title":"CISA urges critical infrastructure firms to \u2018fortify\u2019 before it\u2019s too late - cybersecuritydive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-5da6e98915c41f46","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxPMkhlOTRYanBCanpORWsyUGtrSWVhZVhKQ01TVkZoNGJaUVRDOFFEaG1GNF9sYVI0NTVJem9YdXBUYmUwQVZCNnlrMndXLXpnR05vZDY1bVZjYlpYT0I1MG8tY3JXa1J6MkJiOWp6bmpONU50TVg2UmIxdm11a25KcW9fWFk3YnozUE93QjlSYVRhb1B4OVlRMlhyMGxHeWdZNHI3eUE3TUJhTVU?oc=5","published_at":"2026-05-05T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"CISA wants critical infrastructure to operate \u2018weeks to months\u2019 in isolation during conflict&nbsp;&nbsp;cyberscoop.com","title":"CISA wants critical infrastructure to operate \u2018weeks to months\u2019 in isolation during conflict - cyberscoop.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-8298905896589112","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMilAFBVV95cUxPNTFGM3VEUWhEbHY5WFFqcHY3aWlBTUJrc0JRNUJqN0NoZkYtQkVpVUVBRl9URjFpeUxRZm15M2tQTERyWTJjaHp6U3V4cGFYSy1EOEN3MThIRkEzQUJSclZ6OEhMM1B5SDFzaWJoOFpqWVFqMnE2QTVjN3pzdVZMMHNuV3NrSm9UMUFTd0NnbEFUbjFx?oc=5","published_at":"2026-05-05T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"CISA urges critical infrastructure firms to \u2018fortify\u2019 before it\u2019s too late&nbsp;&nbsp;Cybersecurity Dive","title":"CISA urges critical infrastructure firms to \u2018fortify\u2019 before it\u2019s too late - Cybersecurity Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ddac9820501e71dd","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi8wFBVV95cUxPM3ZPVVNRaHVYXzYxRWEwWVFUa0JVM0wyWFZsdkFTNTF2UHplTVBFMUpRRGNLc3dwV1ZVUWJFMk5oT1NKRWozYXRWYVJtR3RNa0pUV1Z4VGRRRDZTMERpUThvTkRDQVhLVGFpd3hJQU50YTJBZE94cUVLVXJvNmxSSi1EVUFyZWJLckE4eGFZZFloQXFoQ3FZV0RrQnpTTWUxMnFUVzVaUEk3X2o0d01FMV9hWmVqRVBWYTYyX19NZjNfMXN1ODZla0lxaktzbkVnT0NmWDc1NVpEZVctdUstWkluWEpaQ094Rm1jallvZG1vQWc?oc=5","published_at":"2026-05-01T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Chained vulnerabilities in CODESYS runtime could allow root-level control of industrial devices, Nozomi warns&nbsp;&nbsp;Industrial Cyber","title":"Chained vulnerabilities in CODESYS runtime could allow root-level control of industrial devices, Nozomi warns - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4868ab4efeecb9e0","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi8wFBVV95cUxPM3ZPVVNRaHVYXzYxRWEwWVFUa0JVM0wyWFZsdkFTNTF2UHplTVBFMUpRRGNLc3dwV1ZVUWJFMk5oT1NKRWozYXRWYVJtR3RNa0pUV1Z4VGRRRDZTMERpUThvTkRDQVhLVGFpd3hJQU50YTJBZE94cUVLVXJvNmxSSi1EVUFyZWJLckE4eGFZZFloQXFoQ3FZV0RrQnpTTWUxMnFUVzVaUEk3X2o0d01FMV9hWmVqRVBWYTYyX19NZjNfMXN1ODZla0lxaktzbkVnT0NmWDc1NVpEZVctdUstWkluWEpaQ094Rm1jallvZG1vQWc?oc=5","published_at":"2026-05-01T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Chained vulnerabilities in CODESYS runtime could allow root-level control of industrial devices, Nozomi warns&nbsp;&nbsp;industrialcyber.co","title":"Chained vulnerabilities in CODESYS runtime could allow root-level control of industrial devices, Nozomi warns - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-5f1bca6c31fd5259","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiywFBVV95cUxOM2FNV2JJUG9lMzNYRFZSdXoxbDR2YzlJcXpZTUhkQkw0Rm5KYWZMZzgybDNXY19aenRRX0FqamN0UUlib25EeVA1Y2QxdW5HVG15RUpGcF9GV3RNRTgzRlhwM2JFZ1lnN3Y4cndOMEpIVGVGbnVwMmN1ekhsYmJpRzJGMVFyMmVFY0xCMEpvdU1qTDV0eHlGZGZUVzdDTk4zY2VrMDY4bU1ERFhhLVpfcVJkUEhsSm9QNFlWQnNVZTVmRnNNRjNNTm84WQ?oc=5","published_at":"2026-04-30T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Dismantle implicit trust in OT networks, CISA tells critical infrastructure operators&nbsp;&nbsp;csoonline.com","title":"Dismantle implicit trust in OT networks, CISA tells critical infrastructure operators - csoonline.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-14fcbe6bbe976267","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxOdnhydHl0eXRWaU9FOEN4Zy1taHFpUnpFNEEwZzdXMDQ3ZF9qSWdWeWRubzc4UWJvMG82UVJTRnBrSkdwaWwxTE1ybzJXTDBnM0hVNXBGZXJ3WTFkVFBtNU1DWWtOM05TYWNGRmNKNExEZ29GUDBKMFBTUGRhS0FBUEdadnNwVUhwUzFCM1psdVJDOGo5NWVIeE5tZWpINDR6a3BvVFhOWGE?oc=5","published_at":"2026-04-29T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Data Centers, Telecommunications Networks, and Space-Based Systems&nbsp;&nbsp;fdd.org","title":"Data Centers, Telecommunications Networks, and Space-Based Systems - fdd.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-72d927f000827410","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxOdnhydHl0eXRWaU9FOEN4Zy1taHFpUnpFNEEwZzdXMDQ3ZF9qSWdWeWRubzc4UWJvMG82UVJTRnBrSkdwaWwxTE1ybzJXTDBnM0hVNXBGZXJ3WTFkVFBtNU1DWWtOM05TYWNGRmNKNExEZ29GUDBKMFBTUGRhS0FBUEdadnNwVUhwUzFCM1psdVJDOGo5NWVIeE5tZWpINDR6a3BvVFhOWGE?oc=5","published_at":"2026-04-29T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Data Centers, Telecommunications Networks, and Space-Based Systems&nbsp;&nbsp;Foundation for Defense of Democracies","title":"Data Centers, Telecommunications Networks, and Space-Based Systems - Foundation for Defense of Democracies"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-65b1d3bb9d4a93b4","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxOZmF0aUI1aHZtZEFMZnZXZ0dnVEN0aU5rb2VWRzYxYzU5V1RKeTdhRzhaZ1JDUFMtQVRydVlmVzNPMUdwUklKQ0NSUlo4SjQyWUdQVjlISlptakpHN0JHeE5qS3pWS0RweVE5eV9iVlZBNlprSjdGc2tBbzRfRDI3bWs3dWNtc0ZScTRZcU0yZTY0QUtWUl92dFhCQWNrcnFMNFM2ZA?oc=5","published_at":"2026-04-27T19:04:47+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Gendered livelihood vulnerability to climate change among small-scale fishing communities in Lake Victoria, Kenya&nbsp;&nbsp;frontiersin.org","title":"Gendered livelihood vulnerability to climate change among small-scale fishing communities in Lake Victoria, Kenya - frontiersin.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-bf1fba04d01f26a5","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxOZmF0aUI1aHZtZEFMZnZXZ0dnVEN0aU5rb2VWRzYxYzU5V1RKeTdhRzhaZ1JDUFMtQVRydVlmVzNPMUdwUklKQ0NSUlo4SjQyWUdQVjlISlptakpHN0JHeE5qS3pWS0RweVE5eV9iVlZBNlprSjdGc2tBbzRfRDI3bWs3dWNtc0ZScTRZcU0yZTY0QUtWUl92dFhCQWNrcnFMNFM2ZA?oc=5","published_at":"2026-04-27T19:04:47+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Gendered livelihood vulnerability to climate change among small-scale fishing communities in Lake Victoria, Kenya&nbsp;&nbsp;Frontiers","title":"Gendered livelihood vulnerability to climate change among small-scale fishing communities in Lake Victoria, Kenya - Frontiers"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-b2b5f29a0ac31c45","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxOUFI2bWo3T2w0b3VCMDJNOU4weUN3V1ZDbU9KeDdtdjBzaGxyNDBubFRJNVA4TGN1T2ROMm96dVhjVTZ3c296amRYZGNaX0VOeU9yZEFVUVRqNzhtcy1sMTBKbDFPUk4wMmladzR1VERxT0hITGppMkpSOUJPRkJlVHV3RkcydlF5emlNRFdGdTNxNkkyQ1NRUnA1Mzhpb3U2QmQ3eXhXVmJOQQ?oc=5","published_at":"2026-04-27T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"AI Kill Switch Isn\u2019t Enough: Why Real-Time AI Governance Matters&nbsp;&nbsp;Dark Reading","title":"AI Kill Switch Isn\u2019t Enough: Why Real-Time AI Governance Matters - Dark Reading"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ad64b95094492161","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikwFBVV95cUxOUEtONGJXbkE3bVF3TkR3b0I5X05DblI4WnB3Z1k2YUdKV0lENWhuOFRiaFlWMENLQ25fcTlMR3dtLXhBbGxZc0VTMnNDbjVzSmFNUXpqS2FtY2ZyWG5ZM0JPaVFHaFJ6UWdaRThWTGw0QnZHX05xRDI4VmdPSGNNc3JuQzdFb05FVFVLU3B3RU16dU0?oc=5","published_at":"2026-04-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"CISA, Peers Outline Risk from China-compromised Devices&nbsp;&nbsp;RTO Insider","title":"CISA, Peers Outline Risk from China-compromised Devices - RTO Insider"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-0703560dba8022d1","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxOUFI2bWo3T2w0b3VCMDJNOU4weUN3V1ZDbU9KeDdtdjBzaGxyNDBubFRJNVA4TGN1T2ROMm96dVhjVTZ3c296amRYZGNaX0VOeU9yZEFVUVRqNzhtcy1sMTBKbDFPUk4wMmladzR1VERxT0hITGppMkpSOUJPRkJlVHV3RkcydlF5emlNRFdGdTNxNkkyQ1NRUnA1Mzhpb3U2QmQ3eXhXVmJOQQ?oc=5","published_at":"2026-04-27T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"AI Kill Switch Isn\u2019t Enough: Why Real-Time AI Governance Matters&nbsp;&nbsp;darkreading.com","title":"AI Kill Switch Isn\u2019t Enough: Why Real-Time AI Governance Matters - darkreading.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-959044a07f73d515","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikwFBVV95cUxOUEtONGJXbkE3bVF3TkR3b0I5X05DblI4WnB3Z1k2YUdKV0lENWhuOFRiaFlWMENLQ25fcTlMR3dtLXhBbGxZc0VTMnNDbjVzSmFNUXpqS2FtY2ZyWG5ZM0JPaVFHaFJ6UWdaRThWTGw0QnZHX05xRDI4VmdPSGNNc3JuQzdFb05FVFVLU3B3RU16dU0?oc=5","published_at":"2026-04-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"CISA, Peers Outline Risk from China-compromised Devices&nbsp;&nbsp;rtoinsider.com","title":"CISA, Peers Outline Risk from China-compromised Devices - rtoinsider.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e75101e8160bc60b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi1wFBVV95cUxNWU5QVlo4QXkxWFYyZTlJUksxVnI3MTBUeGRBcENiRVlQSnY5Ni1RX2FmYnhJT0MwSVZaUi0tUVlQMU1xcE8zYWlxOVdTbGRrNXJtdkgtN2xHYklHalQ0SGRoSDlYTjhpSExXTzQ2MkhhLV8ydXlwdTFpTDhiS2JsSVluMHN4czVvNWZqMzQ4LVo1LTVuQ3VjZDgxbjN5YXkwcGVTTDNmdEZWYzgxeU5fV2psS3BfaVZSVnYzNEY5Q2N0NE9BOWJsT0dJMDJHclFZaU1mMk44Zw?oc=5","published_at":"2026-04-24T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Critical Infra & APTs","summary":"Advisory details shifting tactics of Chinese cyber actors using covert networks for malicious activity&nbsp;&nbsp;American Hospital Association","title":"Advisory details shifting tactics of Chinese cyber actors using covert networks for malicious activity - American Hospital Association"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-fb7f8abb01e67ba9","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi1wFBVV95cUxPSFRSRUdiNk15QVdYTkRDV3hEQ2ZFb0NWaW1vM1FBcGtoTV91YjBhY2w1d2ZoRTQyWEQzT28zaUo3a1hUTmNVU0dGWGRPNzlrRW9aS0dJenBoN1h0d2xYVnJKeWVNSGdUaDZYSHZUTzRhd3ZBdHRzcWdXaGpKSHZxT0VoU2ZhVmk4SmJUMEZRUHdIY0RZWDdzZFVGLWlSTDE4aWlFMUJ1RWg1blNPYVpmeGgzaFhlUl9yeDhXaDRfUVpsQ05pdmZjUlN4VFhCb0pYel9RYjJMSQ?oc=5","published_at":"2026-04-24T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Why Cyber Threats to Critical Infrastructure Demand a New Homeland Response Model&nbsp;&nbsp;Homeland Security Today","title":"Why Cyber Threats to Critical Infrastructure Demand a New Homeland Response Model - Homeland Security Today"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d21f6608e08215d7","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi1wFBVV95cUxNWU5QVlo4QXkxWFYyZTlJUksxVnI3MTBUeGRBcENiRVlQSnY5Ni1RX2FmYnhJT0MwSVZaUi0tUVlQMU1xcE8zYWlxOVdTbGRrNXJtdkgtN2xHYklHalQ0SGRoSDlYTjhpSExXTzQ2MkhhLV8ydXlwdTFpTDhiS2JsSVluMHN4czVvNWZqMzQ4LVo1LTVuQ3VjZDgxbjN5YXkwcGVTTDNmdEZWYzgxeU5fV2psS3BfaVZSVnYzNEY5Q2N0NE9BOWJsT0dJMDJHclFZaU1mMk44Zw?oc=5","published_at":"2026-04-24T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Critical Infra & APTs","summary":"Advisory details shifting tactics of Chinese cyber actors using covert networks for malicious activity&nbsp;&nbsp;aha.org","title":"Advisory details shifting tactics of Chinese cyber actors using covert networks for malicious activity - aha.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8e1ca1d25a5fca0a","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi7gFBVV95cUxNeWJ2dWhoV0l6Y1EySkhpNGprenBZX1h2aEFDZDVycGJzbmV4MjhTVkhNWjZidWcxR0ZPYTVKcmYwNDR0Y0pEa1EyeXpHbUNiSVFGWkUwZDRSVmg3WkdJTWc4SklhT2lkdnQzYnFkREhnQlpQbVFKMVM2cXRVV2E4N09YZDlXUmNwUnk4QUtILXBEMV9DV3BxYmhVUVhuY3dobF8xOUJTeU1makV5em1UXy1wSjY1Mm13RENJRUg5Sl9xOVhqZE9HQkFKZXF3YnF2b0V0bEF4eU9tTTZqVl9Ja1ZUbWQxckduWmt3ODNR?oc=5","published_at":"2026-04-24T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Critical Infra & APTs","summary":"CISA, NCSC UK, and Global Partners Issue Advisory on Chinese Government-Linked Covert Cyber Networks&nbsp;&nbsp;Homeland Security Today","title":"CISA, NCSC UK, and Global Partners Issue Advisory on Chinese Government-Linked Covert Cyber Networks - Homeland Security Today"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-3df37a6805fad2ec","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi7gFBVV95cUxNeWJ2dWhoV0l6Y1EySkhpNGprenBZX1h2aEFDZDVycGJzbmV4MjhTVkhNWjZidWcxR0ZPYTVKcmYwNDR0Y0pEa1EyeXpHbUNiSVFGWkUwZDRSVmg3WkdJTWc4SklhT2lkdnQzYnFkREhnQlpQbVFKMVM2cXRVV2E4N09YZDlXUmNwUnk4QUtILXBEMV9DV3BxYmhVUVhuY3dobF8xOUJTeU1makV5em1UXy1wSjY1Mm13RENJRUg5Sl9xOVhqZE9HQkFKZXF3YnF2b0V0bEF4eU9tTTZqVl9Ja1ZUbWQxckduWmt3ODNR?oc=5","published_at":"2026-04-24T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Critical Infra & APTs","summary":"CISA, NCSC UK, and Global Partners Issue Advisory on Chinese Government-Linked Covert Cyber Networks&nbsp;&nbsp;hstoday.us","title":"CISA, NCSC UK, and Global Partners Issue Advisory on Chinese Government-Linked Covert Cyber Networks - hstoday.us"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-22b068f18fd19b81","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiYEFVX3lxTE9fZjV2cmtPeUZqWVFDdjlFenZlUHJIZnl1RXFzSXh3U1ZJeFFXZGpNT0NGYkcwWEJISDhvc2czZUV2U21tRnJRNHVLWmFtc1hNSjJQVHJRYXJlM2hKanJpcA?oc=5","published_at":"2026-04-24T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Intelligence Agencies From 10 Countries Warn of Sophisticated Cyberattacks by Chinese Hackers Exploiting Home Appliances&nbsp;&nbsp;finance.biggo.com","title":"Intelligence Agencies From 10 Countries Warn of Sophisticated Cyberattacks by Chinese Hackers Exploiting Home Appliances - finance.biggo.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-2a2d758cf7b608b9","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi1wFBVV95cUxPSFRSRUdiNk15QVdYTkRDV3hEQ2ZFb0NWaW1vM1FBcGtoTV91YjBhY2w1d2ZoRTQyWEQzT28zaUo3a1hUTmNVU0dGWGRPNzlrRW9aS0dJenBoN1h0d2xYVnJKeWVNSGdUaDZYSHZUTzRhd3ZBdHRzcWdXaGpKSHZxT0VoU2ZhVmk4SmJUMEZRUHdIY0RZWDdzZFVGLWlSTDE4aWlFMUJ1RWg1blNPYVpmeGgzaFhlUl9yeDhXaDRfUVpsQ05pdmZjUlN4VFhCb0pYel9RYjJMSQ?oc=5","published_at":"2026-04-24T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Why Cyber Threats to Critical Infrastructure Demand a New Homeland Response Model&nbsp;&nbsp;hstoday.us","title":"Why Cyber Threats to Critical Infrastructure Demand a New Homeland Response Model - hstoday.us"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b8e8c901fabc21e9","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuAFBVV95cUxPMzNlWDhCSGJPZVI4VzQtMEZTelFqWUtrc3VaN1p3RHNiSkVlVWtMNFZVdWd2elNtdU9lbVRJclVhTWVJaVRCOWhFRk9RS2lLLWtjWFNRSDg1dHBqMVRnQlFxVnd1U0gyUURpUXg5WnAtVlViXzVxb1l2akprdGgzYUdxNVdYbEZyQmtoZW8zUTE3cnprc0cwMFhVeTdURzJkSUZHTjBRcHdlNUJUZEgzdEFNaDdycFJ6?oc=5","published_at":"2026-04-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Security agencies say Chinese hackers using hijacked networks for large-scale cyberattacks&nbsp;&nbsp;Washington Times","title":"Security agencies say Chinese hackers using hijacked networks for large-scale cyberattacks - Washington Times"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-44ebd4ad83517e74","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxOVmpsY1ZoYVB2WTlvWGNJRF9HcDdUQXRkWE0zbjBlckVURUFvZ19pNEVVY0tCT2lvaHp0SG5qX1Q1dmd6THdPaU95aERiNVU5REltRkdSdFF3NnFVWkczUFBZb25HU3BwTGZwMTJLcnJHcWxaWkJwbDZpb05vMDNqMlMxVkxwTzFDY2Z0VEZfbm45ZWtFV3Y5ei1NOVVmM0k?oc=5","published_at":"2026-04-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"China disguises cyberattacks with \u2018covert network\u2019 botnets, US and allies warn&nbsp;&nbsp;cybersecuritydive.com","title":"China disguises cyberattacks with \u2018covert network\u2019 botnets, US and allies warn - cybersecuritydive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-0e28feb97bba4eb3","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMingFBVV95cUxPbVh5cURWUnhkdWl3Wm54VnRjdl93Wnljc0h3ZEJ3SkFfTW9kamJPNUI5ZXhfQ19ickJCOWNsSWJfN3M1MkY5OGVZdUkyMXJpWXk4c1pTalBFeGpfM1lTZ0QtSUhqRUZjM0hBUGN0a3V5M1g3R21YOF9rZE5xVTRlQTJKSHRVczdzZElIU2lHeENUVDd5ZmR1Wng4VDlhZw?oc=5","published_at":"2026-04-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Defending against China-nexus covert networks of compromised devices&nbsp;&nbsp;National Cyber Security Centre","title":"Defending against China-nexus covert networks of compromised devices - National Cyber Security Centre"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2cca854d079dc9c7","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMigwJBVV95cUxQY3dfZDhoc196S08tUmFUYmFWVUdTQWlyUjE2a1pOZjJ0UV96YUhBcldtbnBEQlFhN0dFQzFtV3ZSQ3g0dE1FeWUyYzJNaVQ2cktSTVlvSG9PRlVwb3JJcEpQclhLRU5hOWZnSUtJS1NsMXJwZjF5eTY4UXRYSUU0RXJHcVdCMDM1NnduRHJxNTVvaUVMSDR3czZsajhMaC1RR2prWVppb0JCZ0RkWnpoUHRfeEJ1aXR2SHdQcnVYcDZhMHB2Z3VMRUI5dzVrNC1TQ0VKbm5EQnc4T24tOWYySEEwM2lOeFJ6dmpCZlJJYzhfX05mTWZTWUlsbHZvejR6VDBv?oc=5","published_at":"2026-04-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Panelists: Guam in the crosshairs for major cyber attacks; US adversaries prove they can disrupt services&nbsp;&nbsp;guampdn.com","title":"Panelists: Guam in the crosshairs for major cyber attacks; US adversaries prove they can disrupt services - guampdn.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-526a5d2c583fdef2","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipwFBVV95cUxPUkN3M0VoS0FiTllNSjNlSFJEM1JBSUpYc3ZTMGpGcU5NTXotOThHaHlBX0JQQ2VRbldGM2plSFpWRjREdWtWU0RDQVZTRm96czNtQ1RVMVp6V0UwY0piX2FHVkZram0yM2puTExrMmFmbHVaclZPWGhnV3lWTWwwWmh6d3E0ZDlXdjJPdXM1a0c5VkJlU1pMUnYwVnU0NWNzU2JnT1IzNA?oc=5","published_at":"2026-04-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"China-Linked Cyber Actors Shift Tactics, Use \u2018Covert Networks,\u2019 CISA Says&nbsp;&nbsp;meritalk.com","title":"China-Linked Cyber Actors Shift Tactics, Use \u2018Covert Networks,\u2019 CISA Says - meritalk.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b304a78ce2466052","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipwFBVV95cUxPUkN3M0VoS0FiTllNSjNlSFJEM1JBSUpYc3ZTMGpGcU5NTXotOThHaHlBX0JQQ2VRbldGM2plSFpWRjREdWtWU0RDQVZTRm96czNtQ1RVMVp6V0UwY0piX2FHVkZram0yM2puTExrMmFmbHVaclZPWGhnV3lWTWwwWmh6d3E0ZDlXdjJPdXM1a0c5VkJlU1pMUnYwVnU0NWNzU2JnT1IzNA?oc=5","published_at":"2026-04-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"China-Linked Cyber Actors Shift Tactics, Use \u2018Covert Networks,\u2019 CISA Says&nbsp;&nbsp;MeriTalk","title":"China-Linked Cyber Actors Shift Tactics, Use \u2018Covert Networks,\u2019 CISA Says - MeriTalk"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-409bdd76e0516f3f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxOVmpsY1ZoYVB2WTlvWGNJRF9HcDdUQXRkWE0zbjBlckVURUFvZ19pNEVVY0tCT2lvaHp0SG5qX1Q1dmd6THdPaU95aERiNVU5REltRkdSdFF3NnFVWkczUFBZb25HU3BwTGZwMTJLcnJHcWxaWkJwbDZpb05vMDNqMlMxVkxwTzFDY2Z0VEZfbm45ZWtFV3Y5ei1NOVVmM0k?oc=5","published_at":"2026-04-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"China disguises cyberattacks with \u2018covert network\u2019 botnets, US and allies warn&nbsp;&nbsp;Cybersecurity Dive","title":"China disguises cyberattacks with \u2018covert network\u2019 botnets, US and allies warn - Cybersecurity Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4bdff21292565ced","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuAFBVV95cUxPMzNlWDhCSGJPZVI4VzQtMEZTelFqWUtrc3VaN1p3RHNiSkVlVWtMNFZVdWd2elNtdU9lbVRJclVhTWVJaVRCOWhFRk9RS2lLLWtjWFNRSDg1dHBqMVRnQlFxVnd1U0gyUURpUXg5WnAtVlViXzVxb1l2akprdGgzYUdxNVdYbEZyQmtoZW8zUTE3cnprc0cwMFhVeTdURzJkSUZHTjBRcHdlNUJUZEgzdEFNaDdycFJ6?oc=5","published_at":"2026-04-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Security agencies say Chinese hackers using hijacked networks for large-scale cyberattacks&nbsp;&nbsp;washingtontimes.com","title":"Security agencies say Chinese hackers using hijacked networks for large-scale cyberattacks - washingtontimes.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-436b66b64699995b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMingFBVV95cUxPbVh5cURWUnhkdWl3Wm54VnRjdl93Wnljc0h3ZEJ3SkFfTW9kamJPNUI5ZXhfQ19ickJCOWNsSWJfN3M1MkY5OGVZdUkyMXJpWXk4c1pTalBFeGpfM1lTZ0QtSUhqRUZjM0hBUGN0a3V5M1g3R21YOF9rZE5xVTRlQTJKSHRVczdzZElIU2lHeENUVDd5ZmR1Wng4VDlhZw?oc=5","published_at":"2026-04-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Defending against China-nexus covert networks of compromised devices&nbsp;&nbsp;ncsc.gov.uk","title":"Defending against China-nexus covert networks of compromised devices - ncsc.gov.uk"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-addeec1012d54120","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi2gFBVV95cUxOeDB6M1k1ZWE2d2g3dG1MTjM3UnZ4Z293bGo2Yy1ESW1FMnAycTZucU1uRF9UcS1sV1d4cWFSdGhYM1hidzltSmNzRmRkdzZWdE5sNkRRRlctUkdza3pJSkU1aThZaFZUNlR1eG5pVEpzQndla2s3VEV0TGpPY3RrbkxvbzdZTUZrZ25FbXVNTW9FUnlaRk1nS19qWHd4Q0xZNTV5SzVORlR3bnBIczdubExacFk4RjdSY2VMR2xOYkZlNGFRakdyQjZJbmNndFVCWTB1UE1xWEQtdw?oc=5","published_at":"2026-04-20T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Siemens launches AI engineering agent to automate PLC coding and industrial workflows&nbsp;&nbsp;roboticsandautomationnews.com","title":"Siemens launches AI engineering agent to automate PLC coding and industrial workflows - roboticsandautomationnews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4b5ac422ace531e4","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi3gFBVV95cUxQR3ZFN3ZvU2pJUUNjdzA5UU9acFpURXNBd2JOR24wbDJpMFBKN2NXTkU2djNlV1lxb3plWXhwWUpzMktlc3FkcHJSQk1Rb1MycnlFZHdrWnNYWXhtVlpzbk1vdGlHUG1JNS1USXNTYl9lNHdReGlpeHFyZnA4eXBpMlFWR3pOSUlvX3ZhMnZYbFJrbExKdm1iYVRVTWRqYkZiaVpuNUZrQWZFbzljaWxudElmeDE0Yll5SUNoOHpDa21Ma2JleEZOVFVCejFQeDNxODhPRUNxenVENWdaNmc?oc=5","published_at":"2026-04-20T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"New OT-ISAC advisory exposes critical flaws across industrial control and management systems&nbsp;&nbsp;Industrial Cyber","title":"New OT-ISAC advisory exposes critical flaws across industrial control and management systems - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ddb58c17197a8a04","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi3gFBVV95cUxQR3ZFN3ZvU2pJUUNjdzA5UU9acFpURXNBd2JOR24wbDJpMFBKN2NXTkU2djNlV1lxb3plWXhwWUpzMktlc3FkcHJSQk1Rb1MycnlFZHdrWnNYWXhtVlpzbk1vdGlHUG1JNS1USXNTYl9lNHdReGlpeHFyZnA4eXBpMlFWR3pOSUlvX3ZhMnZYbFJrbExKdm1iYVRVTWRqYkZiaVpuNUZrQWZFbzljaWxudElmeDE0Yll5SUNoOHpDa21Ma2JleEZOVFVCejFQeDNxODhPRUNxenVENWdaNmc?oc=5","published_at":"2026-04-20T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"New OT-ISAC advisory exposes critical flaws across industrial control and management systems&nbsp;&nbsp;industrialcyber.co","title":"New OT-ISAC advisory exposes critical flaws across industrial control and management systems - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-5618c58b9226993b","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi2gFBVV95cUxOeDB6M1k1ZWE2d2g3dG1MTjM3UnZ4Z293bGo2Yy1ESW1FMnAycTZucU1uRF9UcS1sV1d4cWFSdGhYM1hidzltSmNzRmRkdzZWdE5sNkRRRlctUkdza3pJSkU1aThZaFZUNlR1eG5pVEpzQndla2s3VEV0TGpPY3RrbkxvbzdZTUZrZ25FbXVNTW9FUnlaRk1nS19qWHd4Q0xZNTV5SzVORlR3bnBIczdubExacFk4RjdSY2VMR2xOYkZlNGFRakdyQjZJbmNndFVCWTB1UE1xWEQtdw?oc=5","published_at":"2026-04-20T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Siemens launches AI engineering agent to automate PLC coding and industrial workflows&nbsp;&nbsp;Robotics & Automation News","title":"Siemens launches AI engineering agent to automate PLC coding and industrial workflows - Robotics & Automation News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-60948b5167938aed","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilgFBVV95cUxNbDlBdkJ6cWxxWFh1NjY4UmJIbDBON2N1QlF3R1BUSGktREZ6YjhIdnh6Q3oyaHl1TTQ1S0VNMzF5d2NiblRZQWlYNGktWjFMWXUxZ18tT3ZpSVhleTkxSGoyMERyZFdTNUdWTHFtaTR6NjR1ak5LNjVRM0NqVFNVbXQwSTBMbjg0WFQtMTlsR3BmOWZDRHc?oc=5","published_at":"2026-04-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"The Imperative for the Connected Built Environment&nbsp;&nbsp;Foundation for Defense of Democracies","title":"The Imperative for the Connected Built Environment - Foundation for Defense of Democracies"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c102390cd0dcd173","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuwFBVV95cUxNeE9VZVh0MjhGM3Ewdmp6UjVfWFRiRlQwa202ZDJTNE5CYV9vcm9KWDdfYVRIQ2NfVm1BaVowbnRKYXNWSFBpYkt5MzY2anc5Q2ZkaGpfeVQzbldtTDlTeEVhVnZwd3BUYW1VX1lzbkxkSzF2Zm14clZTdFQ3SG5YR3FObWhyWVZXbk8zanNMS0NSMFBBR09Oam5WUURRUnptU1RMOTgxVDdiZzUxd0hWYXowT3VSc3BFZThr?oc=5","published_at":"2026-04-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"\u2018Mythos\u2019 Could Change Cybersecurity For Credit Unions Faster Than Many Are Ready For&nbsp;&nbsp;CUToday","title":"\u2018Mythos\u2019 Could Change Cybersecurity For Credit Unions Faster Than Many Are Ready For - CUToday"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e1014d2d4a00f90b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuwFBVV95cUxNeE9VZVh0MjhGM3Ewdmp6UjVfWFRiRlQwa202ZDJTNE5CYV9vcm9KWDdfYVRIQ2NfVm1BaVowbnRKYXNWSFBpYkt5MzY2anc5Q2ZkaGpfeVQzbldtTDlTeEVhVnZwd3BUYW1VX1lzbkxkSzF2Zm14clZTdFQ3SG5YR3FObWhyWVZXbk8zanNMS0NSMFBBR09Oam5WUURRUnptU1RMOTgxVDdiZzUxd0hWYXowT3VSc3BFZThr?oc=5","published_at":"2026-04-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"\u2018Mythos\u2019 Could Change Cybersecurity For Credit Unions Faster Than Many Are Ready For&nbsp;&nbsp;CU Today","title":"\u2018Mythos\u2019 Could Change Cybersecurity For Credit Unions Faster Than Many Are Ready For - CU Today"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2b815e4abbb68fad","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuwFBVV95cUxNeE9VZVh0MjhGM3Ewdmp6UjVfWFRiRlQwa202ZDJTNE5CYV9vcm9KWDdfYVRIQ2NfVm1BaVowbnRKYXNWSFBpYkt5MzY2anc5Q2ZkaGpfeVQzbldtTDlTeEVhVnZwd3BUYW1VX1lzbkxkSzF2Zm14clZTdFQ3SG5YR3FObWhyWVZXbk8zanNMS0NSMFBBR09Oam5WUURRUnptU1RMOTgxVDdiZzUxd0hWYXowT3VSc3BFZThr?oc=5","published_at":"2026-04-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"\u2018Mythos\u2019 Could Change Cybersecurity For Credit Unions Faster Than Many Are Ready For&nbsp;&nbsp;cutoday.info","title":"\u2018Mythos\u2019 Could Change Cybersecurity For Credit Unions Faster Than Many Are Ready For - cutoday.info"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-010d40291677bdd7","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilgFBVV95cUxNbDlBdkJ6cWxxWFh1NjY4UmJIbDBON2N1QlF3R1BUSGktREZ6YjhIdnh6Q3oyaHl1TTQ1S0VNMzF5d2NiblRZQWlYNGktWjFMWXUxZ18tT3ZpSVhleTkxSGoyMERyZFdTNUdWTHFtaTR6NjR1ak5LNjVRM0NqVFNVbXQwSTBMbjg0WFQtMTlsR3BmOWZDRHc?oc=5","published_at":"2026-04-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"The Imperative for the Connected Built Environment&nbsp;&nbsp;fdd.org","title":"The Imperative for the Connected Built Environment - fdd.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-7af7e3d8318dd455","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMivgFBVV95cUxOTU42S2tiWnZSSGJ0UXVQQk9tcGh6bEo4ekNmWklQVDFSMWdpbk1oczJxLUJIcGs3a2drY2VKcUlSS21RaUdaNno1S2pBc090RG1SaHl0STcxd2kxb0tqSENrc1VnVk5fYWJVMVE5YmdYdW5TZnFzVnZtNEpoYk5aajQ5ZXhqOUl6eXRTUHNBSzRtbGFNUnpqb1M2UFdVNVJkWWxqUnU5a1BRa2FXTzZxbFY1T1dmdzlZMk4xd01n?oc=5","published_at":"2026-04-16T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Does Climate Change Vulnerability Matter for the Allocation of Adaptation Finance? An Empirical Analysis of Donors and Instruments over the Period 2019\u20132023&nbsp;&nbsp;AFD - Agence Fran\u00e7aise de D\u00e9veloppement","title":"Does Climate Change Vulnerability Matter for the Allocation of Adaptation Finance? An Empirical Analysis of Donors and Instruments over the Period 2019\u20132023 - AFD - Agence Fran\u00e7aise de D\u00e9veloppement"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-e02631e17c060acd","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMivgFBVV95cUxOTU42S2tiWnZSSGJ0UXVQQk9tcGh6bEo4ekNmWklQVDFSMWdpbk1oczJxLUJIcGs3a2drY2VKcUlSS21RaUdaNno1S2pBc090RG1SaHl0STcxd2kxb0tqSENrc1VnVk5fYWJVMVE5YmdYdW5TZnFzVnZtNEpoYk5aajQ5ZXhqOUl6eXRTUHNBSzRtbGFNUnpqb1M2UFdVNVJkWWxqUnU5a1BRa2FXTzZxbFY1T1dmdzlZMk4xd01n?oc=5","published_at":"2026-04-16T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Does Climate Change Vulnerability Matter for the Allocation of Adaptation Finance? An Empirical Analysis of Donors and Instruments over the Period 2019\u20132023&nbsp;&nbsp;afd.fr","title":"Does Climate Change Vulnerability Matter for the Allocation of Adaptation Finance? An Empirical Analysis of Donors and Instruments over the Period 2019\u20132023 - afd.fr"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-90a92d48ba89b433","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMicEFVX3lxTFBDUzk5VXBlMXVSQ1p5TGRJTG5EYnpGaUhITkdFWVBxT3hUSVpQRVo0RmsxZHR4aV9wenA3Y0YxRktPU1dVaXhwRWhhSmRkZ1hYdWZNdk5xS01XMUFEaUVfR1pyMVEwS1BDV1EtRHlpZGM?oc=5","published_at":"2026-04-15T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Threat landscape for industrial automation systems in Q4 2025&nbsp;&nbsp;Securelist","title":"Threat landscape for industrial automation systems in Q4 2025 - Securelist"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9b1fb5da5635d308","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMicEFVX3lxTFBDUzk5VXBlMXVSQ1p5TGRJTG5EYnpGaUhITkdFWVBxT3hUSVpQRVo0RmsxZHR4aV9wenA3Y0YxRktPU1dVaXhwRWhhSmRkZ1hYdWZNdk5xS01XMUFEaUVfR1pyMVEwS1BDV1EtRHlpZGM?oc=5","published_at":"2026-04-15T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Threat landscape for industrial automation systems in Q4 2025&nbsp;&nbsp;securelist.com","title":"Threat landscape for industrial automation systems in Q4 2025 - securelist.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-37c6f8dd52e97333","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMioAFBVV95cUxOcVExV0h5QnZPLVhnQmVuLUxtdDVSeldUZzRTZXNtbFhLSEN6SURHdkpFSFA5eE1DZERQY0sxakdIYUpsR2xMXy1nTEp6bFEwMHkyLWljSzhxRE1iTElBOS1ZWk1ZeVpRQzhFZUVNTFNyZGJxV0YtaFdVZU9kSXRVVV9TN1JaVUVnNzJRYmtsVS1nUXRkMG1RU2ZEYzBKekc30gGmAUFVX3lxTFBfMGpLVVNxRHVSSHZrUGc0VXhtYVZuNTRubTY1LV96VjZtTkl6ZHNvMkszMXltS3dLSjVIUWZzcXRxUTZxaUpzT0pwV3ZKc0JSN05EdUNkT2xULVhmX0JyM3RMRVM4OGxadDZoMGprUUpZTE5zTmRkZHZuazFHenhJdWk5T2Z3R3l4QUJHdVFIQ2gwNUNuN3VldGtHTWZHdFZsalhqVUE?oc=5","published_at":"2026-04-15T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"ICS Patch Tuesday: 8 Industrial Giants Publish New Security Advisories&nbsp;&nbsp;securityweek.com","title":"ICS Patch Tuesday: 8 Industrial Giants Publish New Security Advisories - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-7291fe9ce47fc99b","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTFBYUll3am9XTDA4V2kzUHpXclNodzJFUVYtQU5UXzJVdmJ4MEdlbXh4NjFPNXZRNnZTbVVGUDlBYzlka2pOMm1DQzVfVXBSNGRGYWVsbnEwQ25oaVo5aWsw?oc=5","published_at":"2026-04-15T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"An integrated assessment of climate change on landscape adaptive capacity, vulnerability, and divergence in Avicennia species&nbsp;&nbsp;Nature","title":"An integrated assessment of climate change on landscape adaptive capacity, vulnerability, and divergence in Avicennia species - Nature"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-4e7bb0248c22716a","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTFBYUll3am9XTDA4V2kzUHpXclNodzJFUVYtQU5UXzJVdmJ4MEdlbXh4NjFPNXZRNnZTbVVGUDlBYzlka2pOMm1DQzVfVXBSNGRGYWVsbnEwQ25oaVo5aWsw?oc=5","published_at":"2026-04-15T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"An integrated assessment of climate change on landscape adaptive capacity, vulnerability, and divergence in Avicennia species&nbsp;&nbsp;nature.com","title":"An integrated assessment of climate change on landscape adaptive capacity, vulnerability, and divergence in Avicennia species - nature.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-90a22574c65066cc","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMioAFBVV95cUxOcVExV0h5QnZPLVhnQmVuLUxtdDVSeldUZzRTZXNtbFhLSEN6SURHdkpFSFA5eE1DZERQY0sxakdIYUpsR2xMXy1nTEp6bFEwMHkyLWljSzhxRE1iTElBOS1ZWk1ZeVpRQzhFZUVNTFNyZGJxV0YtaFdVZU9kSXRVVV9TN1JaVUVnNzJRYmtsVS1nUXRkMG1RU2ZEYzBKekc30gGmAUFVX3lxTFBfMGpLVVNxRHVSSHZrUGc0VXhtYVZuNTRubTY1LV96VjZtTkl6ZHNvMkszMXltS3dLSjVIUWZzcXRxUTZxaUpzT0pwV3ZKc0JSN05EdUNkT2xULVhmX0JyM3RMRVM4OGxadDZoMGprUUpZTE5zTmRkZHZuazFHenhJdWk5T2Z3R3l4QUJHdVFIQ2gwNUNuN3VldGtHTWZHdFZsalhqVUE?oc=5","published_at":"2026-04-15T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"ICS Patch Tuesday: 8 Industrial Giants Publish New Security Advisories&nbsp;&nbsp;SecurityWeek","title":"ICS Patch Tuesday: 8 Industrial Giants Publish New Security Advisories - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f8322aa9ce64e2d6","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiekFVX3lxTE0tVV8xTWZTT2JiWjhWOEdpenBCb3hyZUc2aEI1QkFxOUFQdlluLVg4Yk5HdmtWMXRVbW1uekFFZ0tJMi10U3BDZ2hVYm5HdFpjeEJIbWJCRE9yWWpGZThxZmRrakZHamtJUUM4aC1UN0ZUZkx3Qk5McmV3?oc=5","published_at":"2026-04-13T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Industrial Switch Security","summary":"Love the Virus: Anthropic\u2019s Mythos Forces Cybersecurity\u2019s Biological Turn&nbsp;&nbsp;fintechnews.sg","title":"Love the Virus: Anthropic\u2019s Mythos Forces Cybersecurity\u2019s Biological Turn - fintechnews.sg"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-aa7d7fc526cffd57","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiekFVX3lxTE0tVV8xTWZTT2JiWjhWOEdpenBCb3hyZUc2aEI1QkFxOUFQdlluLVg4Yk5HdmtWMXRVbW1uekFFZ0tJMi10U3BDZ2hVYm5HdFpjeEJIbWJCRE9yWWpGZThxZmRrakZHamtJUUM4aC1UN0ZUZkx3Qk5McmV3?oc=5","published_at":"2026-04-13T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Industrial Switch Security","summary":"Love the Virus: Anthropic\u2019s Mythos Forces Cybersecurity\u2019s Biological Turn&nbsp;&nbsp;Fintech Singapore","title":"Love the Virus: Anthropic\u2019s Mythos Forces Cybersecurity\u2019s Biological Turn - Fintech Singapore"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-dc1e29e2dd552356","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMixAFBVV95cUxNa3lxdy1rUkYwWE5kNjNSeEhFVUZLY0hwYnZ6ZDJJbGdKYk91dlNMSGt2T1ZCQkFNVjg0RzAwajBlSFZxc1EzOHVrTHBwZ3JUaVFlZGU3ZzlTckFEUWlRckczUzliclpDN1FxdHItSDNOcTlKVWhodE1XVEl2RlJZY21JZldUUkNFXzVVeGZCRndJbjVEQW9zRUdXbHlCVy1MaTQxbElNb1VGVng3QUt5c1RQWlZGRU1aZ0R2LWNCOHRTZlVI0gHKAUFVX3lxTE9nVWM5NmtQNzl4Y2FacWVMZ0lPN1BzQ2p0eG42Z21IYnJ0Zks5LVNGdmE3NW5VV051b3FrMHkzZWN3RHRHZjJJSy0wOTZMYVlubXZ4cnNpM2xVdmY5c0ZybF8wdEZvNEt2MWVYOHNDRlZyUVl4Rm02RGpobVJhN21RM0N6azRkSV82M2dLQUtPX1hEU3VfUEgyM1kzVFJhOVdYby0zcjJYLVNvc0l5ZThjd19yTzJNV3Zra25MUlc0RWplaTd3VFRITEE?oc=5","published_at":"2026-04-11T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Censys finds 5,219 devices exposed to attacks by Iranian APTs, majority in U.S.&nbsp;&nbsp;securityaffairs.com","title":"Censys finds 5,219 devices exposed to attacks by Iranian APTs, majority in U.S. - securityaffairs.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-da2f238f4e67b65d","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMixAFBVV95cUxNa3lxdy1rUkYwWE5kNjNSeEhFVUZLY0hwYnZ6ZDJJbGdKYk91dlNMSGt2T1ZCQkFNVjg0RzAwajBlSFZxc1EzOHVrTHBwZ3JUaVFlZGU3ZzlTckFEUWlRckczUzliclpDN1FxdHItSDNOcTlKVWhodE1XVEl2RlJZY21JZldUUkNFXzVVeGZCRndJbjVEQW9zRUdXbHlCVy1MaTQxbElNb1VGVng3QUt5c1RQWlZGRU1aZ0R2LWNCOHRTZlVI0gHKAUFVX3lxTE9nVWM5NmtQNzl4Y2FacWVMZ0lPN1BzQ2p0eG42Z21IYnJ0Zks5LVNGdmE3NW5VV051b3FrMHkzZWN3RHRHZjJJSy0wOTZMYVlubXZ4cnNpM2xVdmY5c0ZybF8wdEZvNEt2MWVYOHNDRlZyUVl4Rm02RGpobVJhN21RM0N6azRkSV82M2dLQUtPX1hEU3VfUEgyM1kzVFJhOVdYby0zcjJYLVNvc0l5ZThjd19yTzJNV3Zra25MUlc0RWplaTd3VFRITEE?oc=5","published_at":"2026-04-11T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Censys finds 5,219 devices exposed to attacks by Iranian APTs, majority in U.S.&nbsp;&nbsp;Security Affairs","title":"Censys finds 5,219 devices exposed to attacks by Iranian APTs, majority in U.S. - Security Affairs"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b8d91e279c30f994","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitAFBVV95cUxNNkNLS1NoN3lTSnR2bHVqaS11QnFwXy1kRHRwQTJKX0NsMWRQMW4ydDdLRUh0U2pOc2xLZFI4akxpX2NkVklmd1BmeHlsaHBvX1ptbzJPTjFIWlJNaXFHaC1HNTNadld3dW5NSUdRQlpMNzVFT1d5UzZHd1BwQUd0TkdHWC1tVlMzc1dvZ0xKRnhwM2ZVbGNTTlJxS0dnYVJWblRUNDFRNzNTZDQtckhvTWVLYzjSAboBQVVfeXFMTy1FS1VKTXdHaE1aNG1ZcDBUNmM0dV9lVFM4ZzlyTzY1aURqRzNkQ1M5Z1UwMXZpSXVSS2lQZHNWTF8xYjRjbWRrOVdCOW1WNHhndGxXa0pFU09xcnhrb3NoWWlGOWtzRmVnekVEcE5IZzZpZjZma1d6RnVyeldKM3Bubm1xdFJ5NGQ4Y2RrbEFqSkJlYW94VjZaU1NrRUhQdHVNUGJfZDl4cEZiNG4yTVctTXFqZUhPY2tB?oc=5","published_at":"2026-04-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Nearly 4,000 US industrial devices exposed to Iranian cyberattacks&nbsp;&nbsp;BleepingComputer","title":"Nearly 4,000 US industrial devices exposed to Iranian cyberattacks - BleepingComputer"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-8b558a7c5d184e7b","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxQUG1oUmRMb2UtZWx3TEc1cldBQWJOclkzMk9JMzRlMHAycDFYdDNPbFpJYTlZbXVybDJrdkVCXzlaalBFLXhqb0JJY3pvd2JtS2gya0FrZXV0a2M1Z25HbWozTDFSME56SmhoR3hmQ0RFUDB4c0R4ekRHWHlQa0FoTDVVUTJkeTk3b2JkbHRRMjBvRWNzUmY1RTh6ODhnRjBlV0EwbU1EaDZ2c19BSFdUZNIBtgFBVV95cUxOUU9MeERuQlRNUmxzWXM5dWtlQkFmalNfcTZLdGFablJhYzh4eDFOSmk3a0hJUG9vVGVrTmM1bnpWeFF5RWlFUlNzcU9wZzBpT2dGU1dKZG9GRDVhYUNCbk43M1doLXBQSWFEYVRCb2d0RmI0NV9pZzJ1c2VBZmZXRkpnZ2VUWGRfQ3lGcmJBRFhtZ0ozdjNmc3h2a1lQWDktWnRHdHdiMm55UzFvcC1mM04yZ2w4dw?oc=5","published_at":"2026-04-10T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Industry Reactions to Iran Hacking ICS in Critical Infrastructure: Feedback Friday&nbsp;&nbsp;SecurityWeek","title":"Industry Reactions to Iran Hacking ICS in Critical Infrastructure: Feedback Friday - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f7d97b541577658b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimgFBVV95cUxOUWR2RGZyR29ieFFWN09OTHBhcVo5MnJ6TXdxX3JwTnU5Z0pTZVpwemM2Y0JES1FjYXByMWdlcVJyY1gwWm8yak9pZnpEUW1pSDlwMjc4ZzZBaHFuNGM4R1M0cTVTWHE2NFBMSG1KTEFvWFBaUmpqbWx4RmVBUWswaGhoQ3VkMEc0T0VscGVWZFVmYWgwNXc1b3Fn?oc=5","published_at":"2026-04-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Nearly 4K industrial control devices vulnerable to Iran-linked hacking campaign&nbsp;&nbsp;cybersecuritydive.com","title":"Nearly 4K industrial control devices vulnerable to Iran-linked hacking campaign - cybersecuritydive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-65f022ef29d16115","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxQUG1oUmRMb2UtZWx3TEc1cldBQWJOclkzMk9JMzRlMHAycDFYdDNPbFpJYTlZbXVybDJrdkVCXzlaalBFLXhqb0JJY3pvd2JtS2gya0FrZXV0a2M1Z25HbWozTDFSME56SmhoR3hmQ0RFUDB4c0R4ekRHWHlQa0FoTDVVUTJkeTk3b2JkbHRRMjBvRWNzUmY1RTh6ODhnRjBlV0EwbU1EaDZ2c19BSFdUZNIBtgFBVV95cUxOUU9MeERuQlRNUmxzWXM5dWtlQkFmalNfcTZLdGFablJhYzh4eDFOSmk3a0hJUG9vVGVrTmM1bnpWeFF5RWlFUlNzcU9wZzBpT2dGU1dKZG9GRDVhYUNCbk43M1doLXBQSWFEYVRCb2d0RmI0NV9pZzJ1c2VBZmZXRkpnZ2VUWGRfQ3lGcmJBRFhtZ0ozdjNmc3h2a1lQWDktWnRHdHdiMm55UzFvcC1mM04yZ2w4dw?oc=5","published_at":"2026-04-10T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Industry Reactions to Iran Hacking ICS in Critical Infrastructure: Feedback Friday&nbsp;&nbsp;securityweek.com","title":"Industry Reactions to Iran Hacking ICS in Critical Infrastructure: Feedback Friday - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d11c3ddfa39d6e69","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimgFBVV95cUxOUWR2RGZyR29ieFFWN09OTHBhcVo5MnJ6TXdxX3JwTnU5Z0pTZVpwemM2Y0JES1FjYXByMWdlcVJyY1gwWm8yak9pZnpEUW1pSDlwMjc4ZzZBaHFuNGM4R1M0cTVTWHE2NFBMSG1KTEFvWFBaUmpqbWx4RmVBUWswaGhoQ3VkMEc0T0VscGVWZFVmYWgwNXc1b3Fn?oc=5","published_at":"2026-04-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Nearly 4K industrial control devices vulnerable to Iran-linked hacking campaign&nbsp;&nbsp;Cybersecurity Dive","title":"Nearly 4K industrial control devices vulnerable to Iran-linked hacking campaign - Cybersecurity Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1e1208945350b615","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitAFBVV95cUxNNkNLS1NoN3lTSnR2bHVqaS11QnFwXy1kRHRwQTJKX0NsMWRQMW4ydDdLRUh0U2pOc2xLZFI4akxpX2NkVklmd1BmeHlsaHBvX1ptbzJPTjFIWlJNaXFHaC1HNTNadld3dW5NSUdRQlpMNzVFT1d5UzZHd1BwQUd0TkdHWC1tVlMzc1dvZ0xKRnhwM2ZVbGNTTlJxS0dnYVJWblRUNDFRNzNTZDQtckhvTWVLYzjSAboBQVVfeXFMTy1FS1VKTXdHaE1aNG1ZcDBUNmM0dV9lVFM4ZzlyTzY1aURqRzNkQ1M5Z1UwMXZpSXVSS2lQZHNWTF8xYjRjbWRrOVdCOW1WNHhndGxXa0pFU09xcnhrb3NoWWlGOWtzRmVnekVEcE5IZzZpZjZma1d6RnVyeldKM3Bubm1xdFJ5NGQ4Y2RrbEFqSkJlYW94VjZaU1NrRUhQdHVNUGJfZDl4cEZiNG4yTVctTXFqZUhPY2tB?oc=5","published_at":"2026-04-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Nearly 4,000 US industrial devices exposed to Iranian cyberattacks&nbsp;&nbsp;bleepingcomputer.com","title":"Nearly 4,000 US industrial devices exposed to Iranian cyberattacks - bleepingcomputer.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-b50b70d49346210d","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxQZEh0X19WRWo5dHJwRncwSXpKQUNucXhaOXNlZ1dsRDJOZ0pNeHI5YW1KaTVZN1hlcUtRMEtzalo1bl9NdmdjXzhhdnBJbkl4bUNCaGJPV2w4bDJFVHFGZTNZUC1Rb1RVX2VlcDY2TGU4NEZVdW1PTjZiNGpoMUI1M3hB0gGHAUFVX3lxTE16RlRVQVQwZEJnWXMybU1LeDdabUlLdnJmZUE4b0Z4UEtlOVBZVDQxaWYwTW10SE5LaWU2dUVMb3lMSDdXd1JwMmN0OGh5dThTMXh5S0hOT0hGdVM1Y09nek93SHBwTVFTUHRkdDRsNW5vUzFkUlY2Qkg0eXdqb0FjNm9KdUMxTQ?oc=5","published_at":"2026-04-10T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Censys Warns 5,219 Rockwell/Allen-Bradley PLCs Are Exposed Amid Iranian APT Activity&nbsp;&nbsp;CyberSecurityNews","title":"Censys Warns 5,219 Rockwell/Allen-Bradley PLCs Are Exposed Amid Iranian APT Activity - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-05e33e4f7a5c7aae","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxQZEh0X19WRWo5dHJwRncwSXpKQUNucXhaOXNlZ1dsRDJOZ0pNeHI5YW1KaTVZN1hlcUtRMEtzalo1bl9NdmdjXzhhdnBJbkl4bUNCaGJPV2w4bDJFVHFGZTNZUC1Rb1RVX2VlcDY2TGU4NEZVdW1PTjZiNGpoMUI1M3hB0gGHAUFVX3lxTE16RlRVQVQwZEJnWXMybU1LeDdabUlLdnJmZUE4b0Z4UEtlOVBZVDQxaWYwTW10SE5LaWU2dUVMb3lMSDdXd1JwMmN0OGh5dThTMXh5S0hOT0hGdVM1Y09nek93SHBwTVFTUHRkdDRsNW5vUzFkUlY2Qkg0eXdqb0FjNm9KdUMxTQ?oc=5","published_at":"2026-04-10T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Censys Warns 5,219 Rockwell/Allen-Bradley PLCs Are Exposed Amid Iranian APT Activity&nbsp;&nbsp;cybersecuritynews.com","title":"Censys Warns 5,219 Rockwell/Allen-Bradley PLCs Are Exposed Amid Iranian APT Activity - cybersecuritynews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8008ddab7b790de7","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiwwFBVV95cUxNVkU2TnFsUzZUWVdqc3VGOFlxNmh3dkZkWjQ1UEZxdXY3N0hDQ3pzU0VsQzV3bUJkcU5qUmxQd09JaTYtOTBkemdocDh0RTJiODcxQ2VoZU8yRzFBaWxBUGpmTXVhVk5zWktPUlRmNXp1TkMxUmM3Q0haNzAtNUJGVHBzb205OHVYb2RtRUt1cDhOeWoyNUFOb0NTWThMN3ZTbmxNbllSMlV0YW1PYVg2cE96aEpObVZtSE9tZHc3UzlOLXPSAcMBQVVfeXFMTVZFNk5xbFM2VFlXanN1RjhZcTZod3ZGZFo0NVBGcXV2NzdIQ0N6c1NFbEM1d21CZHFOalJsUHdPSWk2LTkwZHpnaHA4dEUyYjg3MUNlaGVPMkcxQWlsQVBqZk11YVZOc1pLT1JUZjV6dU5DMVJjN0NIWjcwLTVCRlRwc29tOTh1WG9kbUVLdXA4TnlqMjVBTm9DU1k4TDd2U25sTW5ZUjJVdGFtT2FYNnBPemhKTm1WbUhPbWR3N1M5Ti1z?oc=5","published_at":"2026-04-09T09:55:57+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"What Is Project Glasswing and How Will Anthropic\u2019s AI Change Cybersecurity?&nbsp;&nbsp;outlookbusiness.com","title":"What Is Project Glasswing and How Will Anthropic\u2019s AI Change Cybersecurity? - outlookbusiness.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-263c0a42fe93222b","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiiwFBVV95cUxNLVYwb01YWkFzMjdzNlNra1Nab01hMkJRQ3pFTEx1eEJzMG5nSE1PcW45dnlKNlFIRUhvTHd6QXRiQkJDckp2QkoyaTdpU1VJOVVDbldsUFBKZHNwSzNTcW9KaGZRQmZ1UjN2NjRFbXNUTW5IakhSalRCVUFiSGNRWWEtZXBKYXplRGxN?oc=5","published_at":"2026-04-09T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Iranian attacks on US critical infrastructure puts 3,900 devices in crosshairs&nbsp;&nbsp;CyberScoop","title":"Iranian attacks on US critical infrastructure puts 3,900 devices in crosshairs - CyberScoop"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-fc05f21e07e451e1","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuwFBVV95cUxNSlVscFRuVDZGN09WTVdTVHlFWGQ2ZlpLMDFmV1Bzc0Y0YWhkclpBMFlaWUpmNTBNZENVd255UUFYbW52Nm9TY1ZPRHo2ejNIbFFoamlzVWhtcHhRQTNMeWJCakRsSnFyS3V0d2gxdGNRcnJtdVZMbHNNNlRGMEJGa1dYMmsxUE9aTHRWMW1jZmlhOU9zX01vWnJOYVY5RmJra0NoSUdUM0R0S3VOYVpsNnNYd1dCa19zLW5V?oc=5","published_at":"2026-04-09T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"CISA issues advisory on Iran-affiliated cyber threat to U.S. infrastructure&nbsp;&nbsp;homelandprepnews.com","title":"CISA issues advisory on Iran-affiliated cyber threat to U.S. infrastructure - homelandprepnews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-07ad8f84bf2ee5db","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiiwFBVV95cUxQeUF5WTl4V19JZmVRazBmS3Nha3JtbjZJZmFnSE1Bc3lkeE5HdWhNY0x1SENiQVVpNXBKVFlVQlNuVWcyYXVTR0xiUnFLS0gwbi1HWEhqUnZwaXNGUzFMUUphQVJNVnoxNWo3VWhHYlhOdVl6QzdlMlVQQmlKeUFmbUg5bjVPYWpJTnVZ?oc=5","published_at":"2026-04-09T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Iran hackers hit US critical systems through exposed PLCs&nbsp;&nbsp;Cybernews","title":"Iran hackers hit US critical systems through exposed PLCs - Cybernews"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-affcfdb2d3f4be55","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiekFVX3lxTE1GTFFKanV4N1pIMFRmdkhCalZCSmxTRnZhXy1MeFNZRG1Denp3WUJjQTBOaTk2Y1hWZk9lT3NIMkxEUWpFOGpPSnIxVmxSYk1Sb0U3Zl9rbVgxbnpxSEtIcF94OXpCM3RNOF9CNFZ1WHhwb0xDRDNCV3NR?oc=5","published_at":"2026-04-09T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"The rise of autonomous AI in cybersecurity&nbsp;&nbsp;pwc.com","title":"The rise of autonomous AI in cybersecurity - pwc.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-03e0ee7a71eece27","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuwFBVV95cUxNSlVscFRuVDZGN09WTVdTVHlFWGQ2ZlpLMDFmV1Bzc0Y0YWhkclpBMFlaWUpmNTBNZENVd255UUFYbW52Nm9TY1ZPRHo2ejNIbFFoamlzVWhtcHhRQTNMeWJCakRsSnFyS3V0d2gxdGNRcnJtdVZMbHNNNlRGMEJGa1dYMmsxUE9aTHRWMW1jZmlhOU9zX01vWnJOYVY5RmJra0NoSUdUM0R0S3VOYVpsNnNYd1dCa19zLW5V?oc=5","published_at":"2026-04-09T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"CISA issues advisory on Iran-affiliated cyber threat to U.S. infrastructure&nbsp;&nbsp;Homeland Preparedness News","title":"CISA issues advisory on Iran-affiliated cyber threat to U.S. infrastructure - Homeland Preparedness News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7d426b6c2b0d9ad4","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxQWDV5OXYyclVmejdoMHhCRnp5YU5ybWhSQ1JaOHRodlMwY2U2UERYRFpkWElWQ3VTLXJWUGJGVkE3NTNjajlUMG8zek9LUGNRSGlyd3VWYVNKWnJ0SHE1cnNRU0p3TXZkUjd5OXVNYjl4S04wNmN6aGMwNTlnWHRpTXlrbGNuU3ZQY3dnYTQ5OUxXaWNiTFQ3Wm9Lc3lIcHZrdUtoanBfbDRDOTJFVjhvUg?oc=5","published_at":"2026-04-09T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"Internet-Exposed ICS Devices Raise Alarm for Critical Sectors&nbsp;&nbsp;securityaffairs.com","title":"Internet-Exposed ICS Devices Raise Alarm for Critical Sectors - securityaffairs.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-1a4ff8c961d09db8","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiiwFBVV95cUxQeUF5WTl4V19JZmVRazBmS3Nha3JtbjZJZmFnSE1Bc3lkeE5HdWhNY0x1SENiQVVpNXBKVFlVQlNuVWcyYXVTR0xiUnFLS0gwbi1HWEhqUnZwaXNGUzFMUUphQVJNVnoxNWo3VWhHYlhOdVl6QzdlMlVQQmlKeUFmbUg5bjVPYWpJTnVZ?oc=5","published_at":"2026-04-09T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Iran hackers hit US critical systems through exposed PLCs&nbsp;&nbsp;cybernews.com","title":"Iran hackers hit US critical systems through exposed PLCs - cybernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2bcc561265336397","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxQWDV5OXYyclVmejdoMHhCRnp5YU5ybWhSQ1JaOHRodlMwY2U2UERYRFpkWElWQ3VTLXJWUGJGVkE3NTNjajlUMG8zek9LUGNRSGlyd3VWYVNKWnJ0SHE1cnNRU0p3TXZkUjd5OXVNYjl4S04wNmN6aGMwNTlnWHRpTXlrbGNuU3ZQY3dnYTQ5OUxXaWNiTFQ3Wm9Lc3lIcHZrdUtoanBfbDRDOTJFVjhvUg?oc=5","published_at":"2026-04-09T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"Internet-Exposed ICS Devices Raise Alarm for Critical Sectors&nbsp;&nbsp;Security Affairs","title":"Internet-Exposed ICS Devices Raise Alarm for Critical Sectors - Security Affairs"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6834a86261a3aa2e","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiekFVX3lxTE1GTFFKanV4N1pIMFRmdkhCalZCSmxTRnZhXy1MeFNZRG1Denp3WUJjQTBOaTk2Y1hWZk9lT3NIMkxEUWpFOGpPSnIxVmxSYk1Sb0U3Zl9rbVgxbnpxSEtIcF94OXpCM3RNOF9CNFZ1WHhwb0xDRDNCV3NR?oc=5","published_at":"2026-04-09T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"The rise of autonomous AI in cybersecurity&nbsp;&nbsp;PwC","title":"The rise of autonomous AI in cybersecurity - PwC"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-5e55c3f3e0fa547e","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiiwFBVV95cUxNLVYwb01YWkFzMjdzNlNra1Nab01hMkJRQ3pFTEx1eEJzMG5nSE1PcW45dnlKNlFIRUhvTHd6QXRiQkJDckp2QkoyaTdpU1VJOVVDbldsUFBKZHNwSzNTcW9KaGZRQmZ1UjN2NjRFbXNUTW5IakhSalRCVUFiSGNRWWEtZXBKYXplRGxN?oc=5","published_at":"2026-04-09T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Iranian attacks on US critical infrastructure puts 3,900 devices in crosshairs&nbsp;&nbsp;cyberscoop.com","title":"Iranian attacks on US critical infrastructure puts 3,900 devices in crosshairs - cyberscoop.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-413d726b36a67ef5","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi_AFBVV95cUxPT0pOYjRIUzJ1UHl2SFVtaUhNUlh0QnY3R1UzdlRZVG9YQ2ptOE9wMTNKRHVsZi0zZUNRcjk2RTBLN1pUcThVUkljVUdYV01GTUFkdmd0MWIyejBKNmhmNHUycklDN09Mb1VoVkU3ZjRjbF9nQkdHVURkOEI1ZHJXZHdlcUFfZWZQTHk5WnF2emtxZ2JNWmpjbzdiS2thTHNrRmxvS0ZJWDlFbEx5WFFMU3RWWG1aRElJYXpFQkhzSkpKQUFHRzNZOTd3WlZNcUdKZlNQd21faUl1YzkzRkdVUGFGZnVaVUVuTWJCSUhsclFDcVZ0OGkzRjBQYjY?oc=5","published_at":"2026-04-09T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Censys warns systemic exposure of Rockwell PLCs enable Iran-linked targeting of critical infrastructure OT networks&nbsp;&nbsp;industrialcyber.co","title":"Censys warns systemic exposure of Rockwell PLCs enable Iran-linked targeting of critical infrastructure OT networks - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-d2c2acf567f44417","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi_AFBVV95cUxPT0pOYjRIUzJ1UHl2SFVtaUhNUlh0QnY3R1UzdlRZVG9YQ2ptOE9wMTNKRHVsZi0zZUNRcjk2RTBLN1pUcThVUkljVUdYV01GTUFkdmd0MWIyejBKNmhmNHUycklDN09Mb1VoVkU3ZjRjbF9nQkdHVURkOEI1ZHJXZHdlcUFfZWZQTHk5WnF2emtxZ2JNWmpjbzdiS2thTHNrRmxvS0ZJWDlFbEx5WFFMU3RWWG1aRElJYXpFQkhzSkpKQUFHRzNZOTd3WlZNcUdKZlNQd21faUl1YzkzRkdVUGFGZnVaVUVuTWJCSUhsclFDcVZ0OGkzRjBQYjY?oc=5","published_at":"2026-04-09T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Censys warns systemic exposure of Rockwell PLCs enable Iran-linked targeting of critical infrastructure OT networks&nbsp;&nbsp;Industrial Cyber","title":"Censys warns systemic exposure of Rockwell PLCs enable Iran-linked targeting of critical infrastructure OT networks - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8f22822dcb659efd","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiiwFBVV95cUxOT19nem1MMlhlNWkyemdTWDdKNXc1ZmI0OUQ0NFNVb2d3VXh1NUtTSUR4RldaeU9LNFNFdjh1S2FZRkQ5YXBocW0wam9mOXRXZW0xblN5bEdKRmdkeUhLQWZEOWI3X3BlMVY2QzNFa3pqSkNPbnFNclQyNXZqUmFjN191QllQTENVR1Y4?oc=5","published_at":"2026-04-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Iranian cyber activity hits US energy, water, and government networks&nbsp;&nbsp;helpnetsecurity.com","title":"Iranian cyber activity hits US energy, water, and government networks - helpnetsecurity.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-eec20f45487ae813","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiiwFBVV95cUxOT19nem1MMlhlNWkyemdTWDdKNXc1ZmI0OUQ0NFNVb2d3VXh1NUtTSUR4RldaeU9LNFNFdjh1S2FZRkQ5YXBocW0wam9mOXRXZW0xblN5bEdKRmdkeUhLQWZEOWI3X3BlMVY2QzNFa3pqSkNPbnFNclQyNXZqUmFjN191QllQTENVR1Y4?oc=5","published_at":"2026-04-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Iranian cyber activity hits US energy, water, and government networks&nbsp;&nbsp;Help Net Security","title":"Iranian cyber activity hits US energy, water, and government networks - Help Net Security"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-1a1a72736476f3cb","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMipwFBVV95cUxQSjJtcEtEdk1zaXBGUkxMNXB1WkZ4dWxQQkU2dk16SW9aLTNjRHV0WjFSM3pKbll5YzY3Mk9aZW5KOFloRkJGVEFPYlNFQktIa1I3Ul9iUEVnQ3lnTlAyQjI3LUlGdUlDcy1LR2d4N1htTEhOSUhJRlMycFJDelBILTdaYmFrQll6SmRrRmkzVFB1cUUwU0FOWG0tZGJnZEhoMGlZOHNkMA?oc=5","published_at":"2026-04-08T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Iran-Linked Hackers Target US Critical Infrastructure: FBI&nbsp;&nbsp;mexicobusiness.news","title":"Iran-Linked Hackers Target US Critical Infrastructure: FBI - mexicobusiness.news"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-2094398b4c7c515b","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi0gFBVV95cUxOVTVfeEtCZmgtS3dmSHd4bEUtR1hjSUtzdjNYSkR1c1dDbXVHR3lXaGVzSklZbEVDTTE2Zzk2Sjc5N0lvUmowNnZBNHRwTDR0RGE5bTFpaWtZZzlpVHotdEdSWnZBVXF5UHJPOEZWQU0yaFJXQWNoUlNVTGRRUDY4Q1JHeXc4VlhZRElHMmFubnoxdXFpQkpvRXIzenUyY19mWGdNM0UxalBKOExFTWRhck8wRVdzTWt6alpTTkpKTDZ6NlIzTmloekVudG9JV0RRS2c?oc=5","published_at":"2026-04-08T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Ongoing cyberattacks targeting internet-connected PLCs disrupt US critical infrastructure, agencies warn&nbsp;&nbsp;Industrial Cyber","title":"Ongoing cyberattacks targeting internet-connected PLCs disrupt US critical infrastructure, agencies warn - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-53cdf6bf12490c92","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiswFBVV95cUxNLS1TeDFDVHJfNlZkTlVFd2hmRHNVQWxTcUlUY0xsWmVSZDAtaWJ1NVNEcmpnSE83N3lXSkVidGhwRkRaTlJvbkNqN3EtaEhzbzd2UDRYdUV6LXdRaGFTc2tISE9zWEozRzg3N2FZeWdhOWpPdjRmNlM2UVpIZzFvYzNCRmstU0VoWmNXNjJESm4zam9LNUFtclgyQkdaQXhiYmczT1NlSHhOa3hqNHlpdnZpNA?oc=5","published_at":"2026-04-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Iran-linked hackers target water, energy in US, FBI and CISA warn&nbsp;&nbsp;cybersecuritydive.com","title":"Iran-linked hackers target water, energy in US, FBI and CISA warn - cybersecuritydive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-53d83995bca9aaf2","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilAFBVV95cUxOY3I5RWNobXVqdjlSZ2Z1aWNyT0wxOXZqM2tLMkQtMzFVX3c3LVc4T2JldjBXbG9FNWdyZGs3MWNQSXF1U0NtSHN4RUhqWlBZUFE5c1k4OEJuWHctUnhjdC1LekZ2ZEhWYnhrdTNkZ3VNY1FLN2JHeHRpMXdiME9nX25vd2hUek5qYXBLUUUwN2E4Qndm?oc=5","published_at":"2026-04-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Officials: Iran Cyber Attacks Targeting U.S. Infrastructure&nbsp;&nbsp;GovTech","title":"Officials: Iran Cyber Attacks Targeting U.S. Infrastructure - GovTech"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-fd24fce00ec3ec31","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMipwFBVV95cUxQSjJtcEtEdk1zaXBGUkxMNXB1WkZ4dWxQQkU2dk16SW9aLTNjRHV0WjFSM3pKbll5YzY3Mk9aZW5KOFloRkJGVEFPYlNFQktIa1I3Ul9iUEVnQ3lnTlAyQjI3LUlGdUlDcy1LR2d4N1htTEhOSUhJRlMycFJDelBILTdaYmFrQll6SmRrRmkzVFB1cUUwU0FOWG0tZGJnZEhoMGlZOHNkMA?oc=5","published_at":"2026-04-08T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Iran-Linked Hackers Target US Critical Infrastructure: FBI&nbsp;&nbsp;Mexico Business News","title":"Iran-Linked Hackers Target US Critical Infrastructure: FBI - Mexico Business News"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-3ac357d6413ce253","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxOS1lHNW94a3Ztak9yTWwxZnIyanNQRUJwSGxtb05VQXp4S2Z3ejdEa1loblo1Zjg3M0czQ1NNR1pmeTdZd2Ftczdpa21qSVd2Tm5qRjU2LWRjZG1aWHdQSUtJZW16eHItTUs1c1piOGtEejA0OWtDa05yVlhyU2d5b2U5QUxGWm11NDRaX21GT1haVWFBbDZHSm5nLTdISkx2eVZzY3FpTXA?oc=5","published_at":"2026-04-08T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Iranian Threat Actors Disrupt US Critical Infrastructure via Exposed PLCs&nbsp;&nbsp;darkreading.com","title":"Iranian Threat Actors Disrupt US Critical Infrastructure via Exposed PLCs - darkreading.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-1ab35b7b4c924254","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxNelNNU2owNHBrWEgwdERyUDFFZ0RJVm4yUGxNc0VzVEhNVk1mbXphNDlkbC1nTkJDd0dmLXlwLVZLbE5aejlVOVRyZVhWUGpIS2NYa3pzbEw5OElSUDdMem52OWlROUlZUWhLdWMzV1o1TlRwMDJSdGlDQkdyeENFd3lrM0I?oc=5","published_at":"2026-04-08T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs&nbsp;&nbsp;The Hacker News","title":"Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-82d04dc5da941868","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilAFBVV95cUxOY3I5RWNobXVqdjlSZ2Z1aWNyT0wxOXZqM2tLMkQtMzFVX3c3LVc4T2JldjBXbG9FNWdyZGs3MWNQSXF1U0NtSHN4RUhqWlBZUFE5c1k4OEJuWHctUnhjdC1LekZ2ZEhWYnhrdTNkZ3VNY1FLN2JHeHRpMXdiME9nX25vd2hUek5qYXBLUUUwN2E4Qndm?oc=5","published_at":"2026-04-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Officials: Iran Cyber Attacks Targeting U.S. Infrastructure&nbsp;&nbsp;govtech.com","title":"Officials: Iran Cyber Attacks Targeting U.S. Infrastructure - govtech.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-d6a45e08d0d6e113","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi0gFBVV95cUxOVTVfeEtCZmgtS3dmSHd4bEUtR1hjSUtzdjNYSkR1c1dDbXVHR3lXaGVzSklZbEVDTTE2Zzk2Sjc5N0lvUmowNnZBNHRwTDR0RGE5bTFpaWtZZzlpVHotdEdSWnZBVXF5UHJPOEZWQU0yaFJXQWNoUlNVTGRRUDY4Q1JHeXc4VlhZRElHMmFubnoxdXFpQkpvRXIzenUyY19mWGdNM0UxalBKOExFTWRhck8wRVdzTWt6alpTTkpKTDZ6NlIzTmloekVudG9JV0RRS2c?oc=5","published_at":"2026-04-08T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Ongoing cyberattacks targeting internet-connected PLCs disrupt US critical infrastructure, agencies warn&nbsp;&nbsp;industrialcyber.co","title":"Ongoing cyberattacks targeting internet-connected PLCs disrupt US critical infrastructure, agencies warn - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8aaf5f2c9190986a","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiswFBVV95cUxNLS1TeDFDVHJfNlZkTlVFd2hmRHNVQWxTcUlUY0xsWmVSZDAtaWJ1NVNEcmpnSE83N3lXSkVidGhwRkRaTlJvbkNqN3EtaEhzbzd2UDRYdUV6LXdRaGFTc2tISE9zWEozRzg3N2FZeWdhOWpPdjRmNlM2UVpIZzFvYzNCRmstU0VoWmNXNjJESm4zam9LNUFtclgyQkdaQXhiYmczT1NlSHhOa3hqNHlpdnZpNA?oc=5","published_at":"2026-04-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Iran-linked hackers target water, energy in US, FBI and CISA warn&nbsp;&nbsp;Cybersecurity Dive","title":"Iran-linked hackers target water, energy in US, FBI and CISA warn - Cybersecurity Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-237e7e6c5c660b5c","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxOS1lHNW94a3Ztak9yTWwxZnIyanNQRUJwSGxtb05VQXp4S2Z3ejdEa1loblo1Zjg3M0czQ1NNR1pmeTdZd2Ftczdpa21qSVd2Tm5qRjU2LWRjZG1aWHdQSUtJZW16eHItTUs1c1piOGtEejA0OWtDa05yVlhyU2d5b2U5QUxGWm11NDRaX21GT1haVWFBbDZHSm5nLTdISkx2eVZzY3FpTXA?oc=5","published_at":"2026-04-08T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Iranian Threat Actors Disrupt US Critical Infrastructure via Exposed PLCs&nbsp;&nbsp;Dark Reading","title":"Iranian Threat Actors Disrupt US Critical Infrastructure via Exposed PLCs - Dark Reading"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-686f752cac8ebde5","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxNelNNU2owNHBrWEgwdERyUDFFZ0RJVm4yUGxNc0VzVEhNVk1mbXphNDlkbC1nTkJDd0dmLXlwLVZLbE5aejlVOVRyZVhWUGpIS2NYa3pzbEw5OElSUDdMem52OWlROUlZUWhLdWMzV1o1TlRwMDJSdGlDQkdyeENFd3lrM0I?oc=5","published_at":"2026-04-08T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs&nbsp;&nbsp;thehackernews.com","title":"Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-49f278c3a44b45a5","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiowFBVV95cUxNS0VJUG9TbjhNWGN4SHNyMVcwM09oQnlId00ybDNvSGVMOHNnTHpPYUx4MG42YjUyNEVoOXhKRG9wVGR3RW1vXzRYNm5Pak5GNGpDOHUtNFdqRy1uQmJfamRHMU9wdTIyLTVhUlBHVUpBWGpWdVhpZnNEZnFyQTQ3MUhfVGRkYnhPU2Npb1c5OUlVdnF5ZFVMc3NxWHFPeU9HNTZZ?oc=5","published_at":"2026-04-07T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn&nbsp;&nbsp;CyberScoop","title":"Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn - CyberScoop"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-837194e02858fd57","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi7AFBVV95cUxQZmVZWGJ2QzV4WFBhOGFjV0pDSllOVVBnOHJnMzFJaHhIbmhoVjhXRVctSUxrSk1UcWd4OFpGTW15UURmZjc4QzNDWTFwVF8wQUU1ZVZ3UHRocHZtYmRieHBzVEdnbTdZVGZwQ244MVZqcEZ2MHVQLVYzcmZjcXRMbVlvalY0ZWdneW1nU2M4RTJBU0JhbElSc0Y1aG1qcU1pSnFOOFRxTVMtbzBhM3lEb0pLTWdEakRnSTN4S2RfRnU0MWVuMWFmV0pnMVlfRjNhRGRXajBWZVRnRjFhNUVpVkcyLXY0blhYcTBBUQ?oc=5","published_at":"2026-04-07T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"CSIS flags Iran's shift from episodic cyberattacks to sustained campaign against critical infrastructure&nbsp;&nbsp;industrialcyber.co","title":"CSIS flags Iran's shift from episodic cyberattacks to sustained campaign against critical infrastructure - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-a727282273113115","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiogFBVV95cUxPWWUzSWdkVDZ1anliZkEzQ2lURzJMRXFKVnhGbFFYS2gxbXlaZDhvdFJ3UlpnNkptSmtlOUNCamtBSjRmLXBFZ2NadktkWlU3eGZpWDItVVFrM1dET1J3TkY3UjBpSFV5bU03U1RBZFZ4R3F5N1JTb0pGZm5GVTRsMm5kXzlfbTY1c3lvN1lhRzJtUTRMUTBsdjdIUHhpWi1abWfSAacBQVVfeXFMUGpVLWJmNlhEVG9BSExLWkxidmJvVDJXSlZlckd0QmpKMTRlMHBNLWJ2NGNmWGJHeVBUSkFOVlNPb2hNMUJsVS1CMnM1R1hTWDJlazdWSGd6MjNMUUxjUUdoOVFuN3NrZkhQOUdOVlNrQ0ZrRnNxdlFTZ1RHZ0VfNldCRDhmWVdZbkRKY3lSQVFIZHRyaVBWc3U5M2JSWDZWRWM4NnJZVTQ?oc=5","published_at":"2026-04-07T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Iran-Linked Hackers Disrupt US Critical Infrastructure via PLC Attacks&nbsp;&nbsp;securityweek.com","title":"Iran-Linked Hackers Disrupt US Critical Infrastructure via PLC Attacks - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-d0cf075d7901f3ae","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi7AFBVV95cUxQZmVZWGJ2QzV4WFBhOGFjV0pDSllOVVBnOHJnMzFJaHhIbmhoVjhXRVctSUxrSk1UcWd4OFpGTW15UURmZjc4QzNDWTFwVF8wQUU1ZVZ3UHRocHZtYmRieHBzVEdnbTdZVGZwQ244MVZqcEZ2MHVQLVYzcmZjcXRMbVlvalY0ZWdneW1nU2M4RTJBU0JhbElSc0Y1aG1qcU1pSnFOOFRxTVMtbzBhM3lEb0pLTWdEakRnSTN4S2RfRnU0MWVuMWFmV0pnMVlfRjNhRGRXajBWZVRnRjFhNUVpVkcyLXY0blhYcTBBUQ?oc=5","published_at":"2026-04-07T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"CSIS flags Iran's shift from episodic cyberattacks to sustained campaign against critical infrastructure&nbsp;&nbsp;Industrial Cyber","title":"CSIS flags Iran's shift from episodic cyberattacks to sustained campaign against critical infrastructure - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-bcccc25ba926df71","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiogFBVV95cUxPWWUzSWdkVDZ1anliZkEzQ2lURzJMRXFKVnhGbFFYS2gxbXlaZDhvdFJ3UlpnNkptSmtlOUNCamtBSjRmLXBFZ2NadktkWlU3eGZpWDItVVFrM1dET1J3TkY3UjBpSFV5bU03U1RBZFZ4R3F5N1JTb0pGZm5GVTRsMm5kXzlfbTY1c3lvN1lhRzJtUTRMUTBsdjdIUHhpWi1abWfSAacBQVVfeXFMUGpVLWJmNlhEVG9BSExLWkxidmJvVDJXSlZlckd0QmpKMTRlMHBNLWJ2NGNmWGJHeVBUSkFOVlNPb2hNMUJsVS1CMnM1R1hTWDJlazdWSGd6MjNMUUxjUUdoOVFuN3NrZkhQOUdOVlNrQ0ZrRnNxdlFTZ1RHZ0VfNldCRDhmWVdZbkRKY3lSQVFIZHRyaVBWc3U5M2JSWDZWRWM4NnJZVTQ?oc=5","published_at":"2026-04-07T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Iran-Linked Hackers Disrupt US Critical Infrastructure via PLC Attacks&nbsp;&nbsp;SecurityWeek","title":"Iran-Linked Hackers Disrupt US Critical Infrastructure via PLC Attacks - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-3e35aa847dbedbaa","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiowFBVV95cUxNS0VJUG9TbjhNWGN4SHNyMVcwM09oQnlId00ybDNvSGVMOHNnTHpPYUx4MG42YjUyNEVoOXhKRG9wVGR3RW1vXzRYNm5Pak5GNGpDOHUtNFdqRy1uQmJfamRHMU9wdTIyLTVhUlBHVUpBWGpWdVhpZnNEZnFyQTQ3MUhfVGRkYnhPU2Npb1c5OUlVdnF5ZFVMc3NxWHFPeU9HNTZZ?oc=5","published_at":"2026-04-07T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn&nbsp;&nbsp;cyberscoop.com","title":"Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn - cyberscoop.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-643db49a7a2abb88","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilAFBVV95cUxQUDhjcXJLeFh6UVE1SFNCcUwtSlRPVk5PNHREZFdqS2ZFaTF0YkNtM3R5QllwOTE1RENQZVRqeVo0eWkxOUtzS0pUT0tXMGdHTnVscW5fZ3dsOTVmcnFfcTMxTy12My1QdEQ0Q0Nsb012Y2lfNzByUGJQbTZqQ0VJN2RxOFhDX0otN0ZkYzM4YnE5XzVu?oc=5","published_at":"2026-04-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"AI Will Change Cybersecurity. Humans Will Define Its Success. A Lesson No Algorithm Can Teach&nbsp;&nbsp;thehackernews.com","title":"AI Will Change Cybersecurity. Humans Will Define Its Success. A Lesson No Algorithm Can Teach - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6c639f51f23ef96b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilAFBVV95cUxQUDhjcXJLeFh6UVE1SFNCcUwtSlRPVk5PNHREZFdqS2ZFaTF0YkNtM3R5QllwOTE1RENQZVRqeVo0eWkxOUtzS0pUT0tXMGdHTnVscW5fZ3dsOTVmcnFfcTMxTy12My1QdEQ0Q0Nsb012Y2lfNzByUGJQbTZqQ0VJN2RxOFhDX0otN0ZkYzM4YnE5XzVu?oc=5","published_at":"2026-04-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"AI Will Change Cybersecurity. Humans Will Define Its Success. A Lesson No Algorithm Can Teach&nbsp;&nbsp;The Hacker News","title":"AI Will Change Cybersecurity. Humans Will Define Its Success. A Lesson No Algorithm Can Teach - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5a983bcfade61e23","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiZ0FVX3lxTE04NVlhOEp5LWNmSkctWmJIbF91M1hDUDEzSnMySk1UQm1xNEg3SVpFMmd4M3hIZDQ0YmpJanNVdF9ZeUd2M2xsUmJsdzBCM2Z0UTFiUDhvUFlhZVktazlJcU9qM2p5ZUE?oc=5","published_at":"2026-04-03T19:11:35+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"The (Non-Kinetic) War Has Already Started |&nbsp;&nbsp;U.S. Naval Institute","title":"The (Non-Kinetic) War Has Already Started | - U.S. Naval Institute"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-947d0944e46dabdd","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiZ0FVX3lxTE04NVlhOEp5LWNmSkctWmJIbF91M1hDUDEzSnMySk1UQm1xNEg3SVpFMmd4M3hIZDQ0YmpJanNVdF9ZeUd2M2xsUmJsdzBCM2Z0UTFiUDhvUFlhZVktazlJcU9qM2p5ZUE?oc=5","published_at":"2026-04-03T19:11:35+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"The (Non-Kinetic) War Has Already Started |&nbsp;&nbsp;usni.org","title":"The (Non-Kinetic) War Has Already Started | - usni.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-a2e179fc2a39c97f","category":"Industrial Network & Switches","cve_ids":["CVE-2026-4698"],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMi7gFBVV95cUxOOGhNbV9YM3lCblpPb1ZyM0JsT3dLc256RXhELW96Y2hVbmZqd0xCaFdQeWR2NmpIMVBIeC1GcXdBUndGUjZ4c29LNDZ5MDFYY3FUdDFfam1jTDZSYWRIblRqMDlTUk1aeFgzREtvLVZZbmVoYWZOQWpEWXFiNVJYQXg0MlpwQlFrZUZ5dEJFRWhVLXlEVmFCcFM0Q2hwSnkxUkgtWk0wX2xqMVdfZHRMOVpERlZfZFVXQ1VETWFvcE4zVWRsaTZDQVdvYVYzSWhtdEczU2ZDQTVNcWhUUmFwQVlfS1ljYmtkaDRaVjJR?oc=5","published_at":"2026-04-03T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"HIGH","source":"Industrial Switch Security","summary":"Mozilla Firefox IonMonkey Switch Statement Optimization Type Confusion Remote Code Execution Vulnerability (CVE-2026-4698)&nbsp;&nbsp;systemtek.co.uk","title":"Mozilla Firefox IonMonkey Switch Statement Optimization Type Confusion Remote Code Execution Vulnerability (CVE-2026-4698) - systemtek.co.uk"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5d8b88e58b673ae0","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxQX0FfcDAwYmc2ZnpsTTVqRU93WE9iZF91VG5teWhtLXY5N19lQTJlUkRnNXZNNGZJUDVKS0dmQ1VDR0J3Y3JodV9NcmlER3lwdWZXaF9nOHVUN2Y5OUF5N3JRQ2hmY2pnc2RSMGJIdXF2N0RnUVNvb1RmT216aDIxdFJtbGROWDJLMU95TjFJTktOaXhhekE2dVNUeEhkRWhBSVJCUw?oc=5","published_at":"2026-04-02T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"FBI Labels China-Linked Hack of Surveillance System a \"Major Cyber Incident\"&nbsp;&nbsp;Homeland Security Today","title":"FBI Labels China-Linked Hack of Surveillance System a \"Major Cyber Incident\" - Homeland Security Today"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-22a88ee67d7157ab","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuwFBVV95cUxQenM4cnZ3TVlDbDBvVlRWNGp4bGppcmhJNzZsd0w4X21TNUQ5TWtMVlJTMmgwWXd1dm4tSFZkajI4VVBUN2VheGRNWWVLVUs2R0VFQXpCSHVPazNlNjNaU0VwU2pUalhiQ2JVRFhhNHRJQ2x0N0dqUDQ5Y3VMM04wZnNfaTFEcm9YYnk1czE5dEMySkNJU3dIVFpTVW4tMDhyaGM3ZWlIRDVKRk9faE5HTWxmeTJaeXR6czVJ?oc=5","published_at":"2026-04-02T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"TAC InfoSec crosses 10,000 clients, enters global top 5 in vulnerability management&nbsp;&nbsp;ET Edge Insights","title":"TAC InfoSec crosses 10,000 clients, enters global top 5 in vulnerability management - ET Edge Insights"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-bb835f672636f13e","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxQdTdWM0c2YmY4VVVNallWalZYNG05Wnp1SVZ5akU4R0hoTFZ5OExkVEVXSVNySC1tdzBHV29JSm5QS0RvVFk5em40Z3lXdW83QjM2X2taQjI5QUozWC0wa2lEOUI0QmFvdTdiX1Z5TTd6UVdNbW5UeXFWaXYtMkxxQWU5dUZ2aGU5VFpMLWpxTG5tS0U4aHlwMlluVHhadHM?oc=5","published_at":"2026-04-02T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"How Iranian hackers pose a threat to US critical infrastructure&nbsp;&nbsp;theconversation.com","title":"How Iranian hackers pose a threat to US critical infrastructure - theconversation.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c9f37de9430101f6","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilwFBVV95cUxNYW1VRXBteVBkMV8wVmF0X3FQbEFHRkJoWU5McVcyd3ZCdnVJT2V5VHJVai1nVWp2NS1BQ3RxMnhPMUZzRjFMa1k5X0RGNTJ3TVp0NDJWeGZyM0dQeTBJQ2U1YUtDXzZXcnU3ZjJCVE9DVlBNaE84QlQ1dE5RZkdVM25TTEJadXlzU3Z3TG5XNE9NVFIxeXNn?oc=5","published_at":"2026-04-02T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Iran Conflict Heightens Cyber Threats to U.S. Energy Infrastructure&nbsp;&nbsp;CSIS | Center for Strategic and International Studies","title":"Iran Conflict Heightens Cyber Threats to U.S. Energy Infrastructure - CSIS | Center for Strategic and International Studies"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-e357a725813ff0ac","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxQdTdWM0c2YmY4VVVNallWalZYNG05Wnp1SVZ5akU4R0hoTFZ5OExkVEVXSVNySC1tdzBHV29JSm5QS0RvVFk5em40Z3lXdW83QjM2X2taQjI5QUozWC0wa2lEOUI0QmFvdTdiX1Z5TTd6UVdNbW5UeXFWaXYtMkxxQWU5dUZ2aGU5VFpMLWpxTG5tS0U4aHlwMlluVHhadHM?oc=5","published_at":"2026-04-02T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"How Iranian hackers pose a threat to US critical infrastructure&nbsp;&nbsp;The Conversation","title":"How Iranian hackers pose a threat to US critical infrastructure - The Conversation"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-12e4a88d17df5a1f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilwFBVV95cUxNYW1VRXBteVBkMV8wVmF0X3FQbEFHRkJoWU5McVcyd3ZCdnVJT2V5VHJVai1nVWp2NS1BQ3RxMnhPMUZzRjFMa1k5X0RGNTJ3TVp0NDJWeGZyM0dQeTBJQ2U1YUtDXzZXcnU3ZjJCVE9DVlBNaE84QlQ1dE5RZkdVM25TTEJadXlzU3Z3TG5XNE9NVFIxeXNn?oc=5","published_at":"2026-04-02T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Iran Conflict Heightens Cyber Threats to U.S. Energy Infrastructure&nbsp;&nbsp;csis.org","title":"Iran Conflict Heightens Cyber Threats to U.S. Energy Infrastructure - csis.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-95a2f23bfd1f4377","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxQX0FfcDAwYmc2ZnpsTTVqRU93WE9iZF91VG5teWhtLXY5N19lQTJlUkRnNXZNNGZJUDVKS0dmQ1VDR0J3Y3JodV9NcmlER3lwdWZXaF9nOHVUN2Y5OUF5N3JRQ2hmY2pnc2RSMGJIdXF2N0RnUVNvb1RmT216aDIxdFJtbGROWDJLMU95TjFJTktOaXhhekE2dVNUeEhkRWhBSVJCUw?oc=5","published_at":"2026-04-02T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"FBI Labels China-Linked Hack of Surveillance System a \"Major Cyber Incident\"&nbsp;&nbsp;hstoday.us","title":"FBI Labels China-Linked Hack of Surveillance System a \"Major Cyber Incident\" - hstoday.us"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-37c3c6f18166650a","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMipgFBVV95cUxNLVVvNHpJQU1aQ1A2cGJYUTdJWmhPa3lGMGJLZi1pUTZ1WjdHUVlzcnBiZU82Vk1vRVBESWNuMHBHVVRJeF9TMGs0bkRvZDdPWFJ5aWdlQXFrcHREdzNWREVyTDRRVnV3cFA4ZnZHZERXMnJvSGdfZkhRcU5MY3Y3NGZQcXkyeUZuYzVfbTRSbjFYN2ZiU2hWSVZvc2lPQmxueGhHbjhB?oc=5","published_at":"2026-04-01T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"President's Commentary: Strategically Securing Critical Infrastructure&nbsp;&nbsp;AFCEA International","title":"President's Commentary: Strategically Securing Critical Infrastructure - AFCEA International"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-845b80ffc44b6d1a","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMib0FVX3lxTFBLTzBZS1M3dUVEXzNNYVNHRWNVOU5uNVRQbkxSdE9xOGFBMEhkNFhwZEJvaDJ5d0F1cmlLalhQYTF5VUx3cC1laDN3MzJ4TFk4U1BhNnRwVmxkS3VPNERrTDJMRjFUa2NqcHY1WmlVNA?oc=5","published_at":"2026-04-01T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"How to Make a Career Change to Cybersecurity&nbsp;&nbsp;Coursera","title":"How to Make a Career Change to Cybersecurity - Coursera"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a7265821cabc7114","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMib0FVX3lxTFBLTzBZS1M3dUVEXzNNYVNHRWNVOU5uNVRQbkxSdE9xOGFBMEhkNFhwZEJvaDJ5d0F1cmlLalhQYTF5VUx3cC1laDN3MzJ4TFk4U1BhNnRwVmxkS3VPNERrTDJMRjFUa2NqcHY1WmlVNA?oc=5","published_at":"2026-04-01T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"How to Make a Career Change to Cybersecurity&nbsp;&nbsp;coursera.org","title":"How to Make a Career Change to Cybersecurity - coursera.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ce3f075800d5dcd9","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimAFBVV95cUxQU0xCMUplMENEZTNKU0txeU45M2tJN3Q3Vm96SWxmU3ZhZURKeVIzYlJJb1c5dEdvbWlWM3ROd1UyZUxRMi1Fd1puM003Uk5GTFBiUDRodVA2ZUxxc3dkeDF0YTNTdG9xc0o5ZklrQS1scFBPbHFndlZpMVQyRWdPaGxXYTFxWng1cXIzWmNiYjRNUjg4WXlWVg?oc=5","published_at":"2026-04-01T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"FBI declares suspected Chinese hack of US surveillance system a \u2018major cyber incident\u2019&nbsp;&nbsp;politico.com","title":"FBI declares suspected Chinese hack of US surveillance system a \u2018major cyber incident\u2019 - politico.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-e3db64d8893f2341","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMipgFBVV95cUxNLVVvNHpJQU1aQ1A2cGJYUTdJWmhPa3lGMGJLZi1pUTZ1WjdHUVlzcnBiZU82Vk1vRVBESWNuMHBHVVRJeF9TMGs0bkRvZDdPWFJ5aWdlQXFrcHREdzNWREVyTDRRVnV3cFA4ZnZHZERXMnJvSGdfZkhRcU5MY3Y3NGZQcXkyeUZuYzVfbTRSbjFYN2ZiU2hWSVZvc2lPQmxueGhHbjhB?oc=5","published_at":"2026-04-01T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"President's Commentary: Strategically Securing Critical Infrastructure&nbsp;&nbsp;afcea.org","title":"President's Commentary: Strategically Securing Critical Infrastructure - afcea.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-bda8fabc6d51bcfd","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimAFBVV95cUxQU0xCMUplMENEZTNKU0txeU45M2tJN3Q3Vm96SWxmU3ZhZURKeVIzYlJJb1c5dEdvbWlWM3ROd1UyZUxRMi1Fd1puM003Uk5GTFBiUDRodVA2ZUxxc3dkeDF0YTNTdG9xc0o5ZklrQS1scFBPbHFndlZpMVQyRWdPaGxXYTFxWng1cXIzWmNiYjRNUjg4WXlWVg?oc=5","published_at":"2026-04-01T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"FBI declares suspected Chinese hack of US surveillance system a \u2018major cyber incident\u2019&nbsp;&nbsp;Politico","title":"FBI declares suspected Chinese hack of US surveillance system a \u2018major cyber incident\u2019 - Politico"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-6c405d056c0dc586","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMivAFBVV95cUxPRUhqUFlZSWV0UlNmSlc4dlo0b1QtQlZYZHNaU0lUeENaTzJXNnl4VXB6b20xN2xLalVrMnVnTUZuWFRmRTZ6ZjJqaGZkektTT0RoOG1MZHFLRmZ1V2pCTGluUzJ2WGUxYVZwZTAyR3Z6VmJMcXpaLWJCeFd3d0R6czR2RGRRTUNoNm93LUxUVEdaOU01dmxKcV96RUlGQ3BXcjFLblJpcUc1aTVWVkZfcXIteDBEUjdab2o5Vw?oc=5","published_at":"2026-03-31T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Critical Infrastructure Cybersecurity Guide | Security Insider&nbsp;&nbsp;Microsoft","title":"Critical Infrastructure Cybersecurity Guide | Security Insider - Microsoft"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-cd8bbe914ab60878","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMivAFBVV95cUxPRUhqUFlZSWV0UlNmSlc4dlo0b1QtQlZYZHNaU0lUeENaTzJXNnl4VXB6b20xN2xLalVrMnVnTUZuWFRmRTZ6ZjJqaGZkektTT0RoOG1MZHFLRmZ1V2pCTGluUzJ2WGUxYVZwZTAyR3Z6VmJMcXpaLWJCeFd3d0R6czR2RGRRTUNoNm93LUxUVEdaOU01dmxKcV96RUlGQ3BXcjFLblJpcUc1aTVWVkZfcXIteDBEUjdab2o5Vw?oc=5","published_at":"2026-03-31T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Critical Infrastructure Cybersecurity Guide | Security Insider&nbsp;&nbsp;microsoft.com","title":"Critical Infrastructure Cybersecurity Guide | Security Insider - microsoft.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-86fd9a0fe96e03b7","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikgFBVV95cUxNaVNFVUpmN0pSU1p1QndNeDFoLVdRbWhCaXgzV3IyRHBtdC11VlhwR1RJZlhwaktaRURhdG5FM3pjcmdsUXZ6SlNJeDI3YVladVJaWGR1cWN1MWFPMS1NZk9SYWdWXy1ldUZUWGZvQXdJNkxqTkJHS1Z6NnRfbVMwLV9HTEdRRUdwSThBd3dXNV9GUQ?oc=5","published_at":"2026-03-30T19:29:16+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"Top 9 Claude Skills for Cybersecurity, Hacking, and Vulnerability Scanning&nbsp;&nbsp;snyk.io","title":"Top 9 Claude Skills for Cybersecurity, Hacking, and Vulnerability Scanning - snyk.io"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-00dc57e162174caf","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikgFBVV95cUxNaVNFVUpmN0pSU1p1QndNeDFoLVdRbWhCaXgzV3IyRHBtdC11VlhwR1RJZlhwaktaRURhdG5FM3pjcmdsUXZ6SlNJeDI3YVladVJaWGR1cWN1MWFPMS1NZk9SYWdWXy1ldUZUWGZvQXdJNkxqTkJHS1Z6NnRfbVMwLV9HTEdRRUdwSThBd3dXNV9GUQ?oc=5","published_at":"2026-03-30T19:29:16+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"Top 9 Claude Skills for Cybersecurity, Hacking, and Vulnerability Scanning&nbsp;&nbsp;Snyk","title":"Top 9 Claude Skills for Cybersecurity, Hacking, and Vulnerability Scanning - Snyk"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-34f42e3dbe1bda1d","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMihgJBVV95cUxPX196UlRCSERwX3RXbGtySDNRd1pKMkJTczgwaDl4TkpFUEdzNk1VeWNTWTJaWGdsNDhLM1ZYOWtRb0RCRWF3NDgzX0owajg5V1RtakVzUmlXbmdnUGhNTWJOY1dJbGV4c1VfWEtMRko1SzgtTXpnTUozYWtiWmQyOHluTjhab2J6Ukd0VkZldzdXUDFaSzB0cGdKb0FWcXZpNFp3Sld1SUE3cW5jTzRKTW5Eb09QMUdOTzdxVGwyY29RZ3dyaVdSekpjckdxaDdWMXg2SWwwZVRVQmlUYkZ2T0txQ1RSNVdRZXk4cjEwSmJjSm5ZbUx1Q0t4SlB0TV9YMXRrbVhR?oc=5","published_at":"2026-03-30T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Team Cymru warns exposed ICS and OT devices targeted by nation-state actors raise industrial, critical infrastructure risks&nbsp;&nbsp;industrialcyber.co","title":"Team Cymru warns exposed ICS and OT devices targeted by nation-state actors raise industrial, critical infrastructure risks - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-4461f705b29b577d","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMihgJBVV95cUxPX196UlRCSERwX3RXbGtySDNRd1pKMkJTczgwaDl4TkpFUEdzNk1VeWNTWTJaWGdsNDhLM1ZYOWtRb0RCRWF3NDgzX0owajg5V1RtakVzUmlXbmdnUGhNTWJOY1dJbGV4c1VfWEtMRko1SzgtTXpnTUozYWtiWmQyOHluTjhab2J6Ukd0VkZldzdXUDFaSzB0cGdKb0FWcXZpNFp3Sld1SUE3cW5jTzRKTW5Eb09QMUdOTzdxVGwyY29RZ3dyaVdSekpjckdxaDdWMXg2SWwwZVRVQmlUYkZ2T0txQ1RSNVdRZXk4cjEwSmJjSm5ZbUx1Q0t4SlB0TV9YMXRrbVhR?oc=5","published_at":"2026-03-30T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Team Cymru warns exposed ICS and OT devices targeted by nation-state actors raise industrial, critical infrastructure risks&nbsp;&nbsp;Industrial Cyber","title":"Team Cymru warns exposed ICS and OT devices targeted by nation-state actors raise industrial, critical infrastructure risks - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-63286aff6215aea3","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMimgFBVV95cUxPeU8wZDg0b2k0dWYzS0Q4SXNHV2FueF9lOTVUX0ExNklLQU5DNlA3U2M4ZWxrMnB6Y2w0eTZWWFdDdGV5Ui0zOHRGR1NSamdScHVYRGVDcDJYQ0ZESjVBUzdGSzNHMC10dGVrVWdXQTJwQkRjTzg4NFRlY2pBZDAxYVBVbkl6NWtPUXRiQjk1M0wyb3FCM284d3N3?oc=5","published_at":"2026-03-27T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Espionage campaign targets telecom with stealthy Linux-based backdoor&nbsp;&nbsp;cybersecuritydive.com","title":"Espionage campaign targets telecom with stealthy Linux-based backdoor - cybersecuritydive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5392cdb74c998cbf","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiYkFVX3lxTE5pRWE1bUl0WXhxR0pRdjVDTDl1Wnh6dlh5Z2NMeFpwRDl2bVp4TjY0NnNqMUxYVFFHTlI1SEdjWHo2RzVyNjZRZ1lyUkFXakppMUR5ZzUyTS1abVZtUzdkMGFR?oc=5","published_at":"2026-03-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"We Are At War&nbsp;&nbsp;The Hacker News","title":"We Are At War - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-bbd5a726480e2e99","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiYkFVX3lxTE5pRWE1bUl0WXhxR0pRdjVDTDl1Wnh6dlh5Z2NMeFpwRDl2bVp4TjY0NnNqMUxYVFFHTlI1SEdjWHo2RzVyNjZRZ1lyUkFXakppMUR5ZzUyTS1abVZtUzdkMGFR?oc=5","published_at":"2026-03-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"We Are At War&nbsp;&nbsp;thehackernews.com","title":"We Are At War - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-cfc41f946b329a2d","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMimgFBVV95cUxPeU8wZDg0b2k0dWYzS0Q4SXNHV2FueF9lOTVUX0ExNklLQU5DNlA3U2M4ZWxrMnB6Y2w0eTZWWFdDdGV5Ui0zOHRGR1NSamdScHVYRGVDcDJYQ0ZESjVBUzdGSzNHMC10dGVrVWdXQTJwQkRjTzg4NFRlY2pBZDAxYVBVbkl6NWtPUXRiQjk1M0wyb3FCM284d3N3?oc=5","published_at":"2026-03-27T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Espionage campaign targets telecom with stealthy Linux-based backdoor&nbsp;&nbsp;Cybersecurity Dive","title":"Espionage campaign targets telecom with stealthy Linux-based backdoor - Cybersecurity Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-abbc32acad7dd813","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisgFBVV95cUxPdWJXT0wzUGpQTW1QQldHZnZCeTY3OU04dUwxRlFOWHgyeWxPY3daakZHZkU0Nm1wLVZMNEhFd1NtemRjWGZBUEM2b0RCQzNsYzVpZ1dVbWxlTlhxWGtneDMwQlVsMzFCMjZuWHNaS2lxckdyV1UweUgxTlowQThPbFlYTkQyNGlXR1M4U011RDNJblMxd0tMOTZuWXBURl9KSVJxbjVWbEFSYVFaUC1GMEZn?oc=5","published_at":"2026-03-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Trump\u2019s Cyber Strategy Is a Strong Playbook, but It\u2019s All in the Execution&nbsp;&nbsp;fdd.org","title":"Trump\u2019s Cyber Strategy Is a Strong Playbook, but It\u2019s All in the Execution - fdd.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d469996075af838f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisgFBVV95cUxPdWJXT0wzUGpQTW1QQldHZnZCeTY3OU04dUwxRlFOWHgyeWxPY3daakZHZkU0Nm1wLVZMNEhFd1NtemRjWGZBUEM2b0RCQzNsYzVpZ1dVbWxlTlhxWGtneDMwQlVsMzFCMjZuWHNaS2lxckdyV1UweUgxTlowQThPbFlYTkQyNGlXR1M4U011RDNJblMxd0tMOTZuWXBURl9KSVJxbjVWbEFSYVFaUC1GMEZn?oc=5","published_at":"2026-03-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Trump\u2019s Cyber Strategy Is a Strong Playbook, but It\u2019s All in the Execution&nbsp;&nbsp;Foundation for Defense of Democracies","title":"Trump\u2019s Cyber Strategy Is a Strong Playbook, but It\u2019s All in the Execution - Foundation for Defense of Democracies"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4c51d4ca9d130c91","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi4wFBVV95cUxOaEVBdDhIajZlV21pdUwwaktqc0tnSWdqRUhzS3Q5RGktMEsxSndfazRFd29zZ3pZMjROa0ZfTGw1dnJyekswcFpxeTBaTmk2c21ZUFdBeGVmQjdtWXhVTFd3SGdrXzRsaEtmXzJFMnJmcGo5aklUbGJFNk94ZERMcGdWdndxVkxYX25zRVlDcDNLcksxSi1UaEMtTXd2REU0X1FEUnk5QlVvalB4Ymw4M0plR2pOZUhwcGluRjFLY0lYRnJEU1RNR0NZQ2VWSkNDSVBwb0tRWnExTDhpcjAybWNfOA?oc=5","published_at":"2026-03-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Exclusive: Anthropic is testing \u2018Mythos,\u2019 its \u2018most powerful AI model ever developed\u2019&nbsp;&nbsp;Fortune","title":"Exclusive: Anthropic is testing \u2018Mythos,\u2019 its \u2018most powerful AI model ever developed\u2019 - Fortune"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-596ed666edf849fa","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMi9gFBVV95cUxQQ2NCN3Nub3JZQjF4RXd3XzdxcWs4LVYxd2JfeDZ4Zkxqd3F3VFFxQ3hJQ1pqV2dxMmFaSE81dW14SlVWYnBYRDBRQXJMX1N1YnFMSUpQeFEtNERsbmxxdHdlcXlmV3FFMk5tSGFsTXp0NjRNTlZOX2hqQnhiZndDWnFvZy1xaGlSOFY0R0h1UjRKaU9NYkpCa29YRU5TRHo5aHdPWU9kd3FPY1ZDM3dIYVlYRHMycHpCZkpCR080YXFGQkZsZkpFdFJPTEUtRWdvQm5VNEJPX0ZKbTRPTy1ZenZxbGdjTWNJclNVdEdheWUzWlE1c2c?oc=5","published_at":"2026-03-26T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Critical Infra & APTs","summary":"FCC expands Covered List to block high-risk routers and drones, tighten ban on foreign-made connectivity devices&nbsp;&nbsp;Industrial Cyber","title":"FCC expands Covered List to block high-risk routers and drones, tighten ban on foreign-made connectivity devices - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9384ab7bbded185f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi4wFBVV95cUxOaEVBdDhIajZlV21pdUwwaktqc0tnSWdqRUhzS3Q5RGktMEsxSndfazRFd29zZ3pZMjROa0ZfTGw1dnJyekswcFpxeTBaTmk2c21ZUFdBeGVmQjdtWXhVTFd3SGdrXzRsaEtmXzJFMnJmcGo5aklUbGJFNk94ZERMcGdWdndxVkxYX25zRVlDcDNLcksxSi1UaEMtTXd2REU0X1FEUnk5QlVvalB4Ymw4M0plR2pOZUhwcGluRjFLY0lYRnJEU1RNR0NZQ2VWSkNDSVBwb0tRWnExTDhpcjAybWNfOA?oc=5","published_at":"2026-03-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Exclusive: Anthropic is testing \u2018Mythos,\u2019 its \u2018most powerful AI model ever developed\u2019&nbsp;&nbsp;fortune.com","title":"Exclusive: Anthropic is testing \u2018Mythos,\u2019 its \u2018most powerful AI model ever developed\u2019 - fortune.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-eb66a3db4d746a08","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMi9gFBVV95cUxQQ2NCN3Nub3JZQjF4RXd3XzdxcWs4LVYxd2JfeDZ4Zkxqd3F3VFFxQ3hJQ1pqV2dxMmFaSE81dW14SlVWYnBYRDBRQXJMX1N1YnFMSUpQeFEtNERsbmxxdHdlcXlmV3FFMk5tSGFsTXp0NjRNTlZOX2hqQnhiZndDWnFvZy1xaGlSOFY0R0h1UjRKaU9NYkpCa29YRU5TRHo5aHdPWU9kd3FPY1ZDM3dIYVlYRHMycHpCZkpCR080YXFGQkZsZkpFdFJPTEUtRWdvQm5VNEJPX0ZKbTRPTy1ZenZxbGdjTWNJclNVdEdheWUzWlE1c2c?oc=5","published_at":"2026-03-26T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Critical Infra & APTs","summary":"FCC expands Covered List to block high-risk routers and drones, tighten ban on foreign-made connectivity devices&nbsp;&nbsp;industrialcyber.co","title":"FCC expands Covered List to block high-risk routers and drones, tighten ban on foreign-made connectivity devices - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-35ac8aa8edd74f45","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMifEFVX3lxTE1lNkdVU2NTdE5kUHdKRlBLWjVRRkJLUzlLY19yeVVQZFNqNWMxblBnczZ0TnY2QldCcmFMZVduejdkdDlUY29mUTY2MlZ3N3lXbkJGM2tHWm1hU3ZNRWdfZVo5VDR3bUF2dkwyV0lrRHJoSnBPMDF6cmRlbVrSAYIBQVVfeXFMTW1yWWd1QTdKdTRPUU95UFBBRXBNZk5iTzZ1YUx3SURubWc4ak9HUU9pdi10TlFiS1hYdVBUVElIREZKUHhvcW8wdE1CS1ZoQVNIRWpNdzZPVmdpaFlXSUd6VlluUElRQUI4MUUtRzM4OTduZl9QWFU3RlBUTUZuZXlNdw?oc=5","published_at":"2026-03-25T11:18:18+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Critical Infra & APTs","summary":"FCC Just Blocked Every New Foreign-Made Router From the U.S.&nbsp;&nbsp;thecyberexpress.com","title":"FCC Just Blocked Every New Foreign-Made Router From the U.S. - thecyberexpress.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-7f15856a71e96789","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMifEFVX3lxTE1lNkdVU2NTdE5kUHdKRlBLWjVRRkJLUzlLY19yeVVQZFNqNWMxblBnczZ0TnY2QldCcmFMZVduejdkdDlUY29mUTY2MlZ3N3lXbkJGM2tHWm1hU3ZNRWdfZVo5VDR3bUF2dkwyV0lrRHJoSnBPMDF6cmRlbVrSAYIBQVVfeXFMTW1yWWd1QTdKdTRPUU95UFBBRXBNZk5iTzZ1YUx3SURubWc4ak9HUU9pdi10TlFiS1hYdVBUVElIREZKUHhvcW8wdE1CS1ZoQVNIRWpNdzZPVmdpaFlXSUd6VlluUElRQUI4MUUtRzM4OTduZl9QWFU3RlBUTUZuZXlNdw?oc=5","published_at":"2026-03-25T11:18:18+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Critical Infra & APTs","summary":"FCC Just Blocked Every New Foreign-Made Router From the U.S.&nbsp;&nbsp;The Cyber Express","title":"FCC Just Blocked Every New Foreign-Made Router From the U.S. - The Cyber Express"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-63b9aacca713e29d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxOdmRtUmlZYzBJRjFnb3dOaURHUTFVMEhkT2VTSmxvLWlYemNsQmIxYlNmeGVKRzNsN0w4VGdjSFd2UUZDT2tBYU1YMkpqXzYzUXJld2JWRWZFUFFnVTE5NmhqS3hHcXNJWFIxdWpDR0JlczF2TzBKbHQyZGt5RmhMdmc4MnRTek9BcXFDMjJkazZLaTZjc1lNSHo3a0ozeGxnMVRTR2s0V28?oc=5","published_at":"2026-03-25T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Federal Cyber Grants for States Are Authorized but Unfunded, Officials Say&nbsp;&nbsp;broadbandbreakfast.com","title":"Federal Cyber Grants for States Are Authorized but Unfunded, Officials Say - broadbandbreakfast.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-04e03b6636c07c00","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxNMjA1UjBDSkcxYzN5SnRsOGRPWEpGUWRFXzZLczZvaDVKdjEySHY5VkprOVc1V1V0Z2owNXVyTnVlYU13TGtCVjdybFU1QkstREl2TUU3QWNzLWFUUGdtS1I4NERRWHdjZFpOd3QzZ2VLdjdQM3I2N0VGQ0hfS0NXLTNfdw?oc=5","published_at":"2026-03-25T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Critical Infra & APTs","summary":"FCC Bans New Foreign-Made Routers Over Supply Chain and Cyber Risk Concerns&nbsp;&nbsp;thehackernews.com","title":"FCC Bans New Foreign-Made Routers Over Supply Chain and Cyber Risk Concerns - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f035a67e1aacab97","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxOdmRtUmlZYzBJRjFnb3dOaURHUTFVMEhkT2VTSmxvLWlYemNsQmIxYlNmeGVKRzNsN0w4VGdjSFd2UUZDT2tBYU1YMkpqXzYzUXJld2JWRWZFUFFnVTE5NmhqS3hHcXNJWFIxdWpDR0JlczF2TzBKbHQyZGt5RmhMdmc4MnRTek9BcXFDMjJkazZLaTZjc1lNSHo3a0ozeGxnMVRTR2s0V28?oc=5","published_at":"2026-03-25T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Federal Cyber Grants for States Are Authorized but Unfunded, Officials Say&nbsp;&nbsp;Broadband Breakfast","title":"Federal Cyber Grants for States Are Authorized but Unfunded, Officials Say - Broadband Breakfast"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-30d8e4528233db5e","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMijAFBVV95cUxQaXFoeURXQk1iOTRVNnpablNaODFaU3VJZjlPMmVFZmVyTDh4a0ZiRjdoMjRyUjYtZjBiTGNmMl9LVmE3NVlVNnBnUlVhT3RTaGtHcXprTjZBT0VDTWE0eEtIY2oyaWxBZGY0WDdfSW55T080OC1XbzE4SHVwdGdCc0tubFVDVGdLSEhnNQ?oc=5","published_at":"2026-03-25T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Critical Infra & APTs","summary":"US blocks new foreign-made routers after FCC cites China-linked cyber threats&nbsp;&nbsp;cybernews.com","title":"US blocks new foreign-made routers after FCC cites China-linked cyber threats - cybernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-203675f1b4524ccd","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxNMjA1UjBDSkcxYzN5SnRsOGRPWEpGUWRFXzZLczZvaDVKdjEySHY5VkprOVc1V1V0Z2owNXVyTnVlYU13TGtCVjdybFU1QkstREl2TUU3QWNzLWFUUGdtS1I4NERRWHdjZFpOd3QzZ2VLdjdQM3I2N0VGQ0hfS0NXLTNfdw?oc=5","published_at":"2026-03-25T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Critical Infra & APTs","summary":"FCC Bans New Foreign-Made Routers Over Supply Chain and Cyber Risk Concerns&nbsp;&nbsp;The Hacker News","title":"FCC Bans New Foreign-Made Routers Over Supply Chain and Cyber Risk Concerns - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-91367776a44459a3","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMijAFBVV95cUxQaXFoeURXQk1iOTRVNnpablNaODFaU3VJZjlPMmVFZmVyTDh4a0ZiRjdoMjRyUjYtZjBiTGNmMl9LVmE3NVlVNnBnUlVhT3RTaGtHcXprTjZBT0VDTWE0eEtIY2oyaWxBZGY0WDdfSW55T080OC1XbzE4SHVwdGdCc0tubFVDVGdLSEhnNQ?oc=5","published_at":"2026-03-25T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Critical Infra & APTs","summary":"US blocks new foreign-made routers after FCC cites China-linked cyber threats&nbsp;&nbsp;Cybernews","title":"US blocks new foreign-made routers after FCC cites China-linked cyber threats - Cybernews"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-d4ad82b33748141a","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxPbTRQT1JsT0p3STh0d0I5czJkMWZkYl9FeUxBU2F3SGUxMWVtRG9HZFZWZUhQTmY3alpnSTluYmFqRHBFS2xXY25ZU0RUanFCWUNiZEt0UkFBSDkyWmRzejJycGRjSzFqRDVUVjJIdEcwY2Ezd1pldXdtNEhBMzFGOS1nb3BCS0l0aEhJRS1IT09wRmNGSlJQQllKQTU0V3F2UDNLdkRjSjZwSm1VT2c?oc=5","published_at":"2026-03-24T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Critical Infra & APTs","summary":"US FCC bans wireless router imports, citing security concerns&nbsp;&nbsp;straitstimes.com","title":"US FCC bans wireless router imports, citing security concerns - straitstimes.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-011b861993fb84b1","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxPbTRQT1JsT0p3STh0d0I5czJkMWZkYl9FeUxBU2F3SGUxMWVtRG9HZFZWZUhQTmY3alpnSTluYmFqRHBFS2xXY25ZU0RUanFCWUNiZEt0UkFBSDkyWmRzejJycGRjSzFqRDVUVjJIdEcwY2Ezd1pldXdtNEhBMzFGOS1nb3BCS0l0aEhJRS1IT09wRmNGSlJQQllKQTU0V3F2UDNLdkRjSjZwSm1VT2c?oc=5","published_at":"2026-03-24T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Critical Infra & APTs","summary":"US FCC bans wireless router imports, citing security concerns&nbsp;&nbsp;The Straits Times","title":"US FCC bans wireless router imports, citing security concerns - The Straits Times"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-86f7c74e8bc7fe6b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMibEFVX3lxTE4tbmJLdE1yaG9sSER3ZEFYeGp1OHJOS2JnTjExWGxBTHJ5aXJBWWxNX0NPR2lpVEo2UV9oWXFhV3pxUE1TNHhOdHdIbjg3ME5PSTlXbjVTazRxYnNNZUpWT3FnQkhSVTlSd1Y3cQ?oc=5","published_at":"2026-03-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"SINGAPORE THREAT LANDSCAPE&nbsp;&nbsp;Cyfirma","title":"SINGAPORE THREAT LANDSCAPE - Cyfirma"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1b77ed13e3fee34c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMibEFVX3lxTE4tbmJLdE1yaG9sSER3ZEFYeGp1OHJOS2JnTjExWGxBTHJ5aXJBWWxNX0NPR2lpVEo2UV9oWXFhV3pxUE1TNHhOdHdIbjg3ME5PSTlXbjVTazRxYnNNZUpWT3FnQkhSVTlSd1Y3cQ?oc=5","published_at":"2026-03-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"SINGAPORE THREAT LANDSCAPE&nbsp;&nbsp;cyfirma","title":"SINGAPORE THREAT LANDSCAPE - cyfirma"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-b9f327c681c51fcd","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMilgFBVV95cUxPWXhFWUEwS2w0Q3FhZUE5RTBKVDhvRFlmVnJ5SnVqWXI1NzNvNWtOTW9YTEV2YWROblA3enpjY0RGdkcwcTZjMHNMdHNMSnFhRnJSQjhxbS1GS0Vha2RXdjExanZrelUtZmMxQXBnbWs5S1VBOUkyT3kzcjYxMjVRaWdTeXpyaE90QTJ3S1k0X0tFcGk4aXc?oc=5","published_at":"2026-03-20T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"ICS Security for Australian Critical Infrastructure&nbsp;&nbsp;trellix.com","title":"ICS Security for Australian Critical Infrastructure - trellix.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-02be1d2f42414343","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMilgFBVV95cUxPWXhFWUEwS2w0Q3FhZUE5RTBKVDhvRFlmVnJ5SnVqWXI1NzNvNWtOTW9YTEV2YWROblA3enpjY0RGdkcwcTZjMHNMdHNMSnFhRnJSQjhxbS1GS0Vha2RXdjExanZrelUtZmMxQXBnbWs5S1VBOUkyT3kzcjYxMjVRaWdTeXpyaE90QTJ3S1k0X0tFcGk4aXc?oc=5","published_at":"2026-03-20T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"ICS Security for Australian Critical Infrastructure&nbsp;&nbsp;Trellix","title":"ICS Security for Australian Critical Infrastructure - Trellix"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-440008778d2f7e71","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMimAFBVV95cUxOd3hOMjhFbUhfTnFYc2xGa1BRTVY2dWxhcXNkZHRjbXBiN2wyMVB5SmR6bUs4bkY3aUVmbXc4TGNvV1FQZVphRDdGNEhUUUl0QWNhbjY1VHR2cWZxLVJxTVUxcWRtempxeVA3UUxOOXQ0dklrVFlRWU9JMGZWWjRKSnRXekZBV3Z2NUVKRjFKcDdJenB3RTJGMg?oc=5","published_at":"2026-03-17T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"CISA official advises agencies not to get too hung up on who takes lead in critical infrastructure sectors&nbsp;&nbsp;CyberScoop","title":"CISA official advises agencies not to get too hung up on who takes lead in critical infrastructure sectors - CyberScoop"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-e45e84f2ec574f35","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMimAFBVV95cUxOd3hOMjhFbUhfTnFYc2xGa1BRTVY2dWxhcXNkZHRjbXBiN2wyMVB5SmR6bUs4bkY3aUVmbXc4TGNvV1FQZVphRDdGNEhUUUl0QWNhbjY1VHR2cWZxLVJxTVUxcWRtempxeVA3UUxOOXQ0dklrVFlRWU9JMGZWWjRKSnRXekZBV3Z2NUVKRjFKcDdJenB3RTJGMg?oc=5","published_at":"2026-03-17T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"CISA official advises agencies not to get too hung up on who takes lead in critical infrastructure sectors&nbsp;&nbsp;cyberscoop.com","title":"CISA official advises agencies not to get too hung up on who takes lead in critical infrastructure sectors - cyberscoop.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-19b918d434b5b4bc","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikAJBVV95cUxNVG9Za3czYlZnUmd6b01QeGZsblZBOUp5QkJ1Q3pWY204OE84c2Z2d2d4UTZzOUtucmJTZG14YmFtTERwbnpoQzVrNi1oVTVSa01zbTg1VG5yQzZjRWtvZGxxSktRZE5EeTlaamxfT0loOGg5aVhfdDFOOE5PQW5DdnZLdlBHckhJMGl3VFd6NHZYWmRya2ZPQzVTNmUwYmhndHhzVTBoWGppUnRaa3U1TGh5TFgyLXB1blplNHJyc2VuN2IyZUdLanZvVUJkRXVMYXctQVJlWFJ0Rm9URU11QUo0eU1ibnlRMTYwXzVoRDNXc19aM2VVVG04VnFyV0EwRHZoYV9lQ1YwSi0yTjZBdg?oc=5","published_at":"2026-03-16T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"How Billy Solano Aims to Turn Cybersecurity Into a Bridge to Better Clients, Bigger Markets, and Bolder Growth&nbsp;&nbsp;USA Today","title":"How Billy Solano Aims to Turn Cybersecurity Into a Bridge to Better Clients, Bigger Markets, and Bolder Growth - USA Today"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5e2b7d02ceac5bb2","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikAJBVV95cUxNVG9Za3czYlZnUmd6b01QeGZsblZBOUp5QkJ1Q3pWY204OE84c2Z2d2d4UTZzOUtucmJTZG14YmFtTERwbnpoQzVrNi1oVTVSa01zbTg1VG5yQzZjRWtvZGxxSktRZE5EeTlaamxfT0loOGg5aVhfdDFOOE5PQW5DdnZLdlBHckhJMGl3VFd6NHZYWmRya2ZPQzVTNmUwYmhndHhzVTBoWGppUnRaa3U1TGh5TFgyLXB1blplNHJyc2VuN2IyZUdLanZvVUJkRXVMYXctQVJlWFJ0Rm9URU11QUo0eU1ibnlRMTYwXzVoRDNXc19aM2VVVG04VnFyV0EwRHZoYV9lQ1YwSi0yTjZBdg?oc=5","published_at":"2026-03-16T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"How Billy Solano Aims to Turn Cybersecurity Into a Bridge to Better Clients, Bigger Markets, and Bolder Growth&nbsp;&nbsp;usatoday.com","title":"How Billy Solano Aims to Turn Cybersecurity Into a Bridge to Better Clients, Bigger Markets, and Bolder Growth - usatoday.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d6cb1df0bd08c6fb","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxPSnJWZExKOWtHVFhNVDN4UDNOUmhwX2ctdWZtRmFhdVJVWmE4VWltU1BWdHZWbWlYME11VXdzSEN4c3d4MnBjSVFKSUsyZEwzZHdMWkMyMVlPcklROEI0TUp3c0cyWndQZnZtYkpmbkZ0R3ZwRC1rZGhsX0JFNnVpMzhQY2R1TF83UGVWelNzYjdPV1l5U2RJbE5rZm1LMGNJTU5TLXI0UG1Yb25iaVE?oc=5","published_at":"2026-03-13T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Inadequate public pressure complicates push for stronger US telecom cyber rules&nbsp;&nbsp;SC Media","title":"Inadequate public pressure complicates push for stronger US telecom cyber rules - SC Media"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-bf699914c11c3a29","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiZ0FVX3lxTFByZGctZEhKNU9pNElic25FN2RoZU1RNDBSQmIwR2lRX3hxaXVlZzBvLS1NS19GdnJjcHl4V1ItU2xnbXpUYWFNOFpyQlNKaUhKNHFJS2NQM0FpajRMNnJ2WHFJQ2RNNWc?oc=5","published_at":"2026-03-13T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"New York cyber regulations for water organizations to take effect in 2027&nbsp;&nbsp;The Record from Recorded Future News","title":"New York cyber regulations for water organizations to take effect in 2027 - The Record from Recorded Future News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ec888815c25358ae","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxPSnJWZExKOWtHVFhNVDN4UDNOUmhwX2ctdWZtRmFhdVJVWmE4VWltU1BWdHZWbWlYME11VXdzSEN4c3d4MnBjSVFKSUsyZEwzZHdMWkMyMVlPcklROEI0TUp3c0cyWndQZnZtYkpmbkZ0R3ZwRC1rZGhsX0JFNnVpMzhQY2R1TF83UGVWelNzYjdPV1l5U2RJbE5rZm1LMGNJTU5TLXI0UG1Yb25iaVE?oc=5","published_at":"2026-03-13T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Inadequate public pressure complicates push for stronger US telecom cyber rules&nbsp;&nbsp;scworld.com","title":"Inadequate public pressure complicates push for stronger US telecom cyber rules - scworld.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ad898ff3c585a181","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiZ0FVX3lxTFByZGctZEhKNU9pNElic25FN2RoZU1RNDBSQmIwR2lRX3hxaXVlZzBvLS1NS19GdnJjcHl4V1ItU2xnbXpUYWFNOFpyQlNKaUhKNHFJS2NQM0FpajRMNnJ2WHFJQ2RNNWc?oc=5","published_at":"2026-03-13T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"New York cyber regulations for water organizations to take effect in 2027&nbsp;&nbsp;therecord.media","title":"New York cyber regulations for water organizations to take effect in 2027 - therecord.media"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-7edfdf1e13bf8010","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMitgFBVV95cUxQakJrY2dRWWpqRzRoY0VQX1JOTm10OHd1c0ZDbW1lSjcwMEc0bnZucWhCY1Z2VGstY20yOW5SMWVPbHV5SHBEcHl4a2VQT05USW1LdF9BcXAtNWE0RW84cGR3TjJKSDFHa21Jcm44a0RZMzVKNUZfQ0ozb0RQTFFsS3VCZ2wxaW9mNDBpSlRVNnZHZE95WWFSaG5yNk9icFIzakVHUkpsazJiZFJrQ2lfOXRZYTY0Z9IBuwFBVV95cUxPZWlMQjlXeWd5V1FMbXA4NlZTbktabWZlNFFNaGcwaTBKX3d5eXNjQm1TRmpnNjBKNG5wQ0duRjBpamFJbWZTbDlYU0hMUDNodjlpQUZoOVRPVVpVUmgtTGRNRmhBU3AwRjhDbzlILXBoODg0NmRJNWdxMW1mYzF4cHN4eldlUWF2SG5LQlk5UmdUdXh5NFA4WTNyTVZ5NHd6WHVMT3RUOUhXa01VdUFtRDJTelNmWmVUbDBJ?oc=5","published_at":"2026-03-11T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Moxa, Mitsubishi Electric&nbsp;&nbsp;SecurityWeek","title":"ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Moxa, Mitsubishi Electric - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-0a82a1042ec4cb90","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi-wFBVV95cUxPanJIU0xWMjh0MkEtNXVTMHg2RjR4NVFhS3JTU2M4WkhRYnA0S2dVWkN2YUpvTm1SSGh5R2lHdkNkbEZ2M1NrdEx5TjdFSGhpaXVDWXJJNWFRbERFX01ta1VHYllqWVFLOEVtd1N6NTBWWjROeHg3YXlKNzRHbXRCSW1KRGtqNjA1dzk0M3ZQOElRWFNuM01KNDJHbUFzWTVVNlZKSUw4ZllzRkFtR25TUnFVUmpFcndSaklpOVR5YTV3ekt5aXpra2RTbzJiMGNsUjVrU2NReTVXUUhrQVl2MUtYU2dhMGJ2Z0NfOTJOdUY2T3A4bkNHdHdoYw?oc=5","published_at":"2026-03-11T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Surging Wireless Vulnerabilities Put Corporate Trade Secrets, National Security at Risk, Bastille Report Finds&nbsp;&nbsp;Homeland Security Today","title":"Surging Wireless Vulnerabilities Put Corporate Trade Secrets, National Security at Risk, Bastille Report Finds - Homeland Security Today"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-9fd55834b1e23650","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMitgFBVV95cUxQakJrY2dRWWpqRzRoY0VQX1JOTm10OHd1c0ZDbW1lSjcwMEc0bnZucWhCY1Z2VGstY20yOW5SMWVPbHV5SHBEcHl4a2VQT05USW1LdF9BcXAtNWE0RW84cGR3TjJKSDFHa21Jcm44a0RZMzVKNUZfQ0ozb0RQTFFsS3VCZ2wxaW9mNDBpSlRVNnZHZE95WWFSaG5yNk9icFIzakVHUkpsazJiZFJrQ2lfOXRZYTY0Z9IBuwFBVV95cUxPZWlMQjlXeWd5V1FMbXA4NlZTbktabWZlNFFNaGcwaTBKX3d5eXNjQm1TRmpnNjBKNG5wQ0duRjBpamFJbWZTbDlYU0hMUDNodjlpQUZoOVRPVVpVUmgtTGRNRmhBU3AwRjhDbzlILXBoODg0NmRJNWdxMW1mYzF4cHN4eldlUWF2SG5LQlk5UmdUdXh5NFA4WTNyTVZ5NHd6WHVMT3RUOUhXa01VdUFtRDJTelNmWmVUbDBJ?oc=5","published_at":"2026-03-11T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Moxa, Mitsubishi Electric&nbsp;&nbsp;securityweek.com","title":"ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Moxa, Mitsubishi Electric - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-44bfb8642accec1b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxPalBUekFHMWd2N3JFMjZUQzdOLUVUenp1Umd6TUJRVTdMRTNsdUFEWTJqdG9VblA5Z2k2MnE3V3FESG5sTjVrakpfVjBEdVVLcVRZZklqdW81ZURzUjFYTkp5ZF9zWDJrQThBM3d1TE5JU2ZvaWpZcGk4VlF1UWdja2dXOUhmQWNpV1pnMjM1RE1VMWNXaWxWamZlS0FYRGt5c0NZUXgxTXpGWGVaQ1E?oc=5","published_at":"2026-03-10T03:53:20+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"How CCPA\u2019s cybersecurity audit rules change cyber governance&nbsp;&nbsp;EY","title":"How CCPA\u2019s cybersecurity audit rules change cyber governance - EY"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d520287bfd5b3521","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxPalBUekFHMWd2N3JFMjZUQzdOLUVUenp1Umd6TUJRVTdMRTNsdUFEWTJqdG9VblA5Z2k2MnE3V3FESG5sTjVrakpfVjBEdVVLcVRZZklqdW81ZURzUjFYTkp5ZF9zWDJrQThBM3d1TE5JU2ZvaWpZcGk4VlF1UWdja2dXOUhmQWNpV1pnMjM1RE1VMWNXaWxWamZlS0FYRGt5c0NZUXgxTXpGWGVaQ1E?oc=5","published_at":"2026-03-10T03:53:20+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"How CCPA\u2019s cybersecurity audit rules change cyber governance&nbsp;&nbsp;ey.com","title":"How CCPA\u2019s cybersecurity audit rules change cyber governance - ey.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-a5b0341e45f33f5b","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMimwFBVV95cUxOQkRuRXZMZ2VrR1FWcTZkalQzd2tobHlIdDJ2VTJTaUxsMWQtZFVGcEZpUGp6QllwME1nWmgzSmx2MXBfR3FLdXhrbk1ob2NzNzZ2WFpLQzJkQnF5YnNBWW9zd0lyUGM2TmJBVFNTSEtLUWtjcXYwV0Z0dUpYQzYwX283SlRfV3Y3Si03Z3FnOTZOeDN3QlVKb0FxQQ?oc=5","published_at":"2026-03-09T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Salt Typhoon is hacking the world's phone and internet giants \u2014 here's everywhere that's been hit&nbsp;&nbsp;TechCrunch","title":"Salt Typhoon is hacking the world's phone and internet giants \u2014 here's everywhere that's been hit - TechCrunch"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-864cabd3fdea9f59","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMimwFBVV95cUxOQkRuRXZMZ2VrR1FWcTZkalQzd2tobHlIdDJ2VTJTaUxsMWQtZFVGcEZpUGp6QllwME1nWmgzSmx2MXBfR3FLdXhrbk1ob2NzNzZ2WFpLQzJkQnF5YnNBWW9zd0lyUGM2TmJBVFNTSEtLUWtjcXYwV0Z0dUpYQzYwX283SlRfV3Y3Si03Z3FnOTZOeDN3QlVKb0FxQQ?oc=5","published_at":"2026-03-09T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Salt Typhoon is hacking the world's phone and internet giants \u2014 here's everywhere that's been hit&nbsp;&nbsp;techcrunch.com","title":"Salt Typhoon is hacking the world's phone and internet giants \u2014 here's everywhere that's been hit - techcrunch.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4942bafb48cdd04c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijAFBVV95cUxQdDM1ek4wVzJETkxnQmZWeEpiU1c0emh2ZWZzalR1bmNrNDhtZ1p4SWwySy1mWFFwdDkzY2dxX0QtWU9HT3ZLMzVpaGtIcVRlVm8xTzllZWJDOV9QMFFWa2ZuZ2VVdVdDQTFXajBLQVotamFjTDl5UlNzd1dGZUxMOGFIYlBTbGRfUm9WUg?oc=5","published_at":"2026-03-08T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Trump's Cyber Strategy: Offensive Ambitions, Defensive Gaps&nbsp;&nbsp;bisi.org.uk","title":"Trump's Cyber Strategy: Offensive Ambitions, Defensive Gaps - bisi.org.uk"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-02e576b4fee4f0f8","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijAFBVV95cUxQdDM1ek4wVzJETkxnQmZWeEpiU1c0emh2ZWZzalR1bmNrNDhtZ1p4SWwySy1mWFFwdDkzY2dxX0QtWU9HT3ZLMzVpaGtIcVRlVm8xTzllZWJDOV9QMFFWa2ZuZ2VVdVdDQTFXajBLQVotamFjTDl5UlNzd1dGZUxMOGFIYlBTbGRfUm9WUg?oc=5","published_at":"2026-03-08T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Trump's Cyber Strategy: Offensive Ambitions, Defensive Gaps&nbsp;&nbsp;Bloomsbury Intelligence and Security Institute (BISI)","title":"Trump's Cyber Strategy: Offensive Ambitions, Defensive Gaps - Bloomsbury Intelligence and Security Institute (BISI)"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-27b3ebdc15c8f018","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMib0FVX3lxTE5SMkE5ZE5FUlRIa1VwU0VsNDZJSmVhSkxZUTVLRERheHVybExtOTh0NVBMMEFCdzBsSWV0SlVjMkFSTW9XZThtRzZTWmlDWXJZLUdFQzM2cE1KcXNCNjVNT0ZjRzBJUHpBaUtCdTU1RQ?oc=5","published_at":"2026-03-06T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"CISA Flags Hikvision Camera & Rockwell Logix Flaws as&nbsp;&nbsp;socradar.io","title":"CISA Flags Hikvision Camera & Rockwell Logix Flaws as - socradar.io"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-2574bb0006296b70","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE9ka1Z4UGt4SGVPREpLOGZ4UnNHRHFwaXZIRE54Ukp6NnpHVG5WSE9yMXVjNTJwZDVRUl9RX3R2TVVlblo3ODJGRURQYkJpb08zOHRTSWVrZ29nbldxT0JR?oc=5","published_at":"2026-03-06T08:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Lactylation as a metabolic-epigenetic switch in cancer: dual roles in cell death resistance and therapeutic vulnerability&nbsp;&nbsp;nature.com","title":"Lactylation as a metabolic-epigenetic switch in cancer: dual roles in cell death resistance and therapeutic vulnerability - nature.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-fb40c94c2033e0ca","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxPdWY2dXQtRG1zZU9IZmo2TUtCNzVsRUNfR3ptb2NXLWxHNUk5LVdIVG52ajA2bFJaNXBPbWpTakNqTWl0cEZsaVBHSWJPUlJMcmNRV2tURDJGdEVnM2o0Mmk1NUdRT2t3Qjc2SkNSRWQtWlBtd1V0MXg2Z2xnUWc4M0FoVQ?oc=5","published_at":"2026-03-06T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog&nbsp;&nbsp;The Hacker News","title":"Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-c9ce672150404368","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMib0FVX3lxTE5SMkE5ZE5FUlRIa1VwU0VsNDZJSmVhSkxZUTVLRERheHVybExtOTh0NVBMMEFCdzBsSWV0SlVjMkFSTW9XZThtRzZTWmlDWXJZLUdFQzM2cE1KcXNCNjVNT0ZjRzBJUHpBaUtCdTU1RQ?oc=5","published_at":"2026-03-06T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"CISA Flags Hikvision Camera & Rockwell Logix Flaws as&nbsp;&nbsp;SOCRadar Extended Threat Intelligence Platform","title":"CISA Flags Hikvision Camera & Rockwell Logix Flaws as - SOCRadar Extended Threat Intelligence Platform"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-1494e75aa4ddb5e5","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxPdWY2dXQtRG1zZU9IZmo2TUtCNzVsRUNfR3ptb2NXLWxHNUk5LVdIVG52ajA2bFJaNXBPbWpTakNqTWl0cEZsaVBHSWJPUlJMcmNRV2tURDJGdEVnM2o0Mmk1NUdRT2t3Qjc2SkNSRWQtWlBtd1V0MXg2Z2xnUWc4M0FoVQ?oc=5","published_at":"2026-03-06T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog&nbsp;&nbsp;thehackernews.com","title":"Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-d1af8128e1d46a78","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE9ka1Z4UGt4SGVPREpLOGZ4UnNHRHFwaXZIRE54Ukp6NnpHVG5WSE9yMXVjNTJwZDVRUl9RX3R2TVVlblo3ODJGRURQYkJpb08zOHRTSWVrZ29nbldxT0JR?oc=5","published_at":"2026-03-06T08:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Lactylation as a metabolic-epigenetic switch in cancer: dual roles in cell death resistance and therapeutic vulnerability&nbsp;&nbsp;Nature","title":"Lactylation as a metabolic-epigenetic switch in cancer: dual roles in cell death resistance and therapeutic vulnerability - Nature"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-15d6d9aa37c34800","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMixwFBVV95cUxPY0ZxLWVrSjRUZ1ZfOFlmNEFGSldJWVFINk5PNGJJYlhjSUVKdExYNmtTdzlOQVFhMWRxN0Y5Qy1sa1JDa2c0V19tNl9CaDUwaUdFNkppZW1jQWJSajBUeGxDUmtyUVBNVFNOeVhDeEQ3TlZzbWtRSEU1TGI3SU43ZlI5T2dMMnlGcHJUb2M4VlpjalU5LU1xeThoN2RCWUpqTlJ1MUV3Z1J2QVpURXlFZTdscjZLWU9GUU5EdXZ6NjZELUxFekJr?oc=5","published_at":"2026-03-05T08:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"Global Surge: 149 Hacktivist DDoS Attacks Target SCADA and Critical Infrastructure Across 16 Countries After Middle East Conflict&nbsp;&nbsp;rescana.com","title":"Global Surge: 149 Hacktivist DDoS Attacks Target SCADA and Critical Infrastructure Across 16 Countries After Middle East Conflict - rescana.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d73741e4f195e3da","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMizAFBVV95cUxQTURMUjlybUVFZy1uLWtUS2tBa2VoTmV2TXRScGlJald2X3BoYlVkYkpSblR6dkhPdFhHdXNSalVIOGs0WjlaRm1kTlFrQVdJeUlzaHBOZF9XMFNhdVktbkdBcXZHYlhWa0hmSWlFUzBoNkdJSDdzaWdaLVNRZ3Ztc0VOdDZFeE5GcGdEUDBmMjEtQnBNYXlfUXN2UFZmUU8wRGFVVnBpRnY2S0RUcGNNNjFscWRkUXFDSWx4bG11VXlqdTZodUZXejlaLWw?oc=5","published_at":"2026-03-05T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"State-affiliated hackers set up for critical OT attacks that operators may not detect&nbsp;&nbsp;csoonline.com","title":"State-affiliated hackers set up for critical OT attacks that operators may not detect - csoonline.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-e776304c2a61df56","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMixwFBVV95cUxPY0ZxLWVrSjRUZ1ZfOFlmNEFGSldJWVFINk5PNGJJYlhjSUVKdExYNmtTdzlOQVFhMWRxN0Y5Qy1sa1JDa2c0V19tNl9CaDUwaUdFNkppZW1jQWJSajBUeGxDUmtyUVBNVFNOeVhDeEQ3TlZzbWtRSEU1TGI3SU43ZlI5T2dMMnlGcHJUb2M4VlpjalU5LU1xeThoN2RCWUpqTlJ1MUV3Z1J2QVpURXlFZTdscjZLWU9GUU5EdXZ6NjZELUxFekJr?oc=5","published_at":"2026-03-05T08:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"Global Surge: 149 Hacktivist DDoS Attacks Target SCADA and Critical Infrastructure Across 16 Countries After Middle East Conflict&nbsp;&nbsp;Rescana","title":"Global Surge: 149 Hacktivist DDoS Attacks Target SCADA and Critical Infrastructure Across 16 Countries After Middle East Conflict - Rescana"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-dde85d3c68e3926d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirAFBVV95cUxQV2YwTkp3bDJZd2kwd1B5M0loN1RoVkVaajFFbGtMcDI2MFgwYVdHX3ZlQVRRQ3lhbGhKUkFkcDdFb3hWcy1BZFJFTHNjUFVOMHM2ZmduSTlDdkJ4bm5jcGk3V3VERkxEZFlVNnBOeGZKUVV4a3ZHbGpNTlNIcEItbmc1a2s3OEl5QUpDU29GRVhhcVM1SmZWRVluRWdmM3pnWTRFYzFQbTlPazVV?oc=5","published_at":"2026-03-03T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"FBI reminds of potentially malicious activity by Iranian cyber actors&nbsp;&nbsp;American Hospital Association","title":"FBI reminds of potentially malicious activity by Iranian cyber actors - American Hospital Association"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-0dec5b7e7c1f5214","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxNbFFGSnNzN3RYWEp5N0RKeDM1VlViYTZwaWZsdmhzUE40M082S256WW5yXzdCVzB1OG5hY29JV2UtNG10R0VyN0lXV2taR1ZVTjk4T1B1c1hIeTNXQk1BUWtEZFFzTFJCWEx4dVVnTTdrb3VFNlc3UlpBdDFzMHdpRHo2SmFnZzFGLS1fb0NzR1labUNEUnVMT0lleDZrbmw2UTRWZ3c5ekjSAa4BQVVfeXFMTlB2NFV3dENxZlJEcG1xbW9PSjhTSFh3M1pkdU5RZUVVb3J3YWVVNUdmSjdqOGxzODlON19GVEx6LW9qRGhOOEY0N1F2VGZoNU5jT2xGMTFEMWRKWFZ2UXZlYTJxMXZaTU02MjFMOUY3Y01nejZSV2dUT1NQRU1LcFZ1YjhjU1RidVc3WEpuMDhUYmVkLXl0ODNldUZtdmV0OFA3a0JXM3YtcS1zT2VR?oc=5","published_at":"2026-03-03T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"Honeywell, Researcher Clash Over Impact of Building Controller Vulnerability&nbsp;&nbsp;securityweek.com","title":"Honeywell, Researcher Clash Over Impact of Building Controller Vulnerability - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-61d3608c830a72c4","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxNbFFGSnNzN3RYWEp5N0RKeDM1VlViYTZwaWZsdmhzUE40M082S256WW5yXzdCVzB1OG5hY29JV2UtNG10R0VyN0lXV2taR1ZVTjk4T1B1c1hIeTNXQk1BUWtEZFFzTFJCWEx4dVVnTTdrb3VFNlc3UlpBdDFzMHdpRHo2SmFnZzFGLS1fb0NzR1labUNEUnVMT0lleDZrbmw2UTRWZ3c5ekjSAa4BQVVfeXFMTlB2NFV3dENxZlJEcG1xbW9PSjhTSFh3M1pkdU5RZUVVb3J3YWVVNUdmSjdqOGxzODlON19GVEx6LW9qRGhOOEY0N1F2VGZoNU5jT2xGMTFEMWRKWFZ2UXZlYTJxMXZaTU02MjFMOUY3Y01nejZSV2dUT1NQRU1LcFZ1YjhjU1RidVc3WEpuMDhUYmVkLXl0ODNldUZtdmV0OFA3a0JXM3YtcS1zT2VR?oc=5","published_at":"2026-03-03T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"Honeywell, Researcher Clash Over Impact of Building Controller Vulnerability&nbsp;&nbsp;SecurityWeek","title":"Honeywell, Researcher Clash Over Impact of Building Controller Vulnerability - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-db3afc71abebf324","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirAFBVV95cUxQV2YwTkp3bDJZd2kwd1B5M0loN1RoVkVaajFFbGtMcDI2MFgwYVdHX3ZlQVRRQ3lhbGhKUkFkcDdFb3hWcy1BZFJFTHNjUFVOMHM2ZmduSTlDdkJ4bm5jcGk3V3VERkxEZFlVNnBOeGZKUVV4a3ZHbGpNTlNIcEItbmc1a2s3OEl5QUpDU29GRVhhcVM1SmZWRVluRWdmM3pnWTRFYzFQbTlPazVV?oc=5","published_at":"2026-03-03T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"FBI reminds of potentially malicious activity by Iranian cyber actors&nbsp;&nbsp;aha.org","title":"FBI reminds of potentially malicious activity by Iranian cyber actors - aha.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7ff778b59c8fe077","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijgFBVV95cUxOY0JQQ2pzYUZoQnVoNTQxMjhidGdPNWhDTi1NU0dWME5sSWhoVUpjU1JMLUhscVlNcW1hbmpTQWZ3WEg1a01TR1VndEJKSURvVl9rZExxcnkyTnpEdjQtRzl2OHR1Qm1GWUh5LVdVRHNYRmZMdFJHUGhyZU5aVUIxWUx5V2l6bC1CV04xMkZn?oc=5","published_at":"2026-03-03T03:02:12+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Building Automation & LoRaWAN","summary":"Manage Vulnerabilities in ICS Open Source Software&nbsp;&nbsp;automation.com","title":"Manage Vulnerabilities in ICS Open Source Software - automation.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2bb56048d81be5b1","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijgFBVV95cUxOY0JQQ2pzYUZoQnVoNTQxMjhidGdPNWhDTi1NU0dWME5sSWhoVUpjU1JMLUhscVlNcW1hbmpTQWZ3WEg1a01TR1VndEJKSURvVl9rZExxcnkyTnpEdjQtRzl2OHR1Qm1GWUh5LVdVRHNYRmZMdFJHUGhyZU5aVUIxWUx5V2l6bC1CV04xMkZn?oc=5","published_at":"2026-03-03T03:02:12+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Building Automation & LoRaWAN","summary":"Manage Vulnerabilities in ICS Open Source Software&nbsp;&nbsp;Automation.com","title":"Manage Vulnerabilities in ICS Open Source Software - Automation.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7b809a41cf1bad6d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMioAFBVV95cUxNXzR2bnB0VlRBWmd0bE9fajM0MnpxQ19HTXFsTVM5UmFRSnBkUUw2ZUlFU1J5WlR5clZUTWJmc1FrVzIyQjM1WG1OSjlmekJoUlozWC02N1NYZFUxWk9pVTI1QnFEbnJZN3haVk5rbFR0QmswVzNTaHRmcVI0U0lvTTkzNTN5YUc4Z2RpWnNpc1BaX3lkM0RQNkg3VWMtZ3VF?oc=5","published_at":"2026-02-24T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Cybersecurity jobs available right now: February 24, 2026&nbsp;&nbsp;Help Net Security","title":"Cybersecurity jobs available right now: February 24, 2026 - Help Net Security"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2a675f0cb8bdc0e0","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMioAFBVV95cUxNXzR2bnB0VlRBWmd0bE9fajM0MnpxQ19HTXFsTVM5UmFRSnBkUUw2ZUlFU1J5WlR5clZUTWJmc1FrVzIyQjM1WG1OSjlmekJoUlozWC02N1NYZFUxWk9pVTI1QnFEbnJZN3haVk5rbFR0QmswVzNTaHRmcVI0U0lvTTkzNTN5YUc4Z2RpWnNpc1BaX3lkM0RQNkg3VWMtZ3VF?oc=5","published_at":"2026-02-24T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Cybersecurity jobs available right now: February 24, 2026&nbsp;&nbsp;helpnetsecurity.com","title":"Cybersecurity jobs available right now: February 24, 2026 - helpnetsecurity.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8b28c09c71d2af31","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipwFBVV95cUxQdUxoeVVZRHpKUkxTVWNtd3F3d2xzc19PblNORjE2SG01RHJ3c2NGazM2Si14ZDAxVnd4ME5lcHNaWUhpaUkyUFUyMFJTMkw2WnJ0eDBFam1LWDlBTDRqRHpCUUloSmQwZ3hlZnJuSUNWSkR3bTBka2x6NmZTdkxRallQVlIzVlc5a1FGaXJOMl9MdEpTWGlhamNKXzlLRTd5dDZTelRVaw?oc=5","published_at":"2026-02-23T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Legacy BMS protocol poses threat to building systems: Claroty&nbsp;&nbsp;facilitiesdive.com","title":"Legacy BMS protocol poses threat to building systems: Claroty - facilitiesdive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6ff3014a9c97d88e","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipwFBVV95cUxQdUxoeVVZRHpKUkxTVWNtd3F3d2xzc19PblNORjE2SG01RHJ3c2NGazM2Si14ZDAxVnd4ME5lcHNaWUhpaUkyUFUyMFJTMkw2WnJ0eDBFam1LWDlBTDRqRHpCUUloSmQwZ3hlZnJuSUNWSkR3bTBka2x6NmZTdkxRallQVlIzVlc5a1FGaXJOMl9MdEpTWGlhamNKXzlLRTd5dDZTelRVaw?oc=5","published_at":"2026-02-23T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Legacy BMS protocol poses threat to building systems: Claroty&nbsp;&nbsp;Facilities Dive","title":"Legacy BMS protocol poses threat to building systems: Claroty - Facilities Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-703c5076f78d4fde","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxOVVdPemZtbVZWQ2kxcW1wSWx2bEt5MTBkanJiTmhsUDNLN2lLc3BHT2pNbjVOOVJTZklGc09PX0lFZmN5MUlHZXBHay04OVZELTJTVktDaEwwaWhRNlY3d0pfMktvVFlTUk1hZkZOZDFEZUZ1RnVDcWdBSTA5UTJPZjVZTXpKcU5wWWhSOVFYRVFQdDY0T1JVZlV4Q2NldXpXdzlYaTBYV2dSZw?oc=5","published_at":"2026-02-23T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"The looming cyber threats to US ports, and critical infrastructure by 'Volt Typhoon'&nbsp;&nbsp;The Loadstar","title":"The looming cyber threats to US ports, and critical infrastructure by 'Volt Typhoon' - The Loadstar"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-7183527805f6e797","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxOVVdPemZtbVZWQ2kxcW1wSWx2bEt5MTBkanJiTmhsUDNLN2lLc3BHT2pNbjVOOVJTZklGc09PX0lFZmN5MUlHZXBHay04OVZELTJTVktDaEwwaWhRNlY3d0pfMktvVFlTUk1hZkZOZDFEZUZ1RnVDcWdBSTA5UTJPZjVZTXpKcU5wWWhSOVFYRVFQdDY0T1JVZlV4Q2NldXpXdzlYaTBYV2dSZw?oc=5","published_at":"2026-02-23T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"The looming cyber threats to US ports, and critical infrastructure by 'Volt Typhoon'&nbsp;&nbsp;theloadstar.com","title":"The looming cyber threats to US ports, and critical infrastructure by 'Volt Typhoon' - theloadstar.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6607049f67572860","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi4AFBVV95cUxPdEhZRkp2ZU1WNTBYYmhiN3RkbWcwRWxXUl9tZzRDMFUxMHV1TEJ1aXN5SUEzTWZpc0VxcEwyZzNuZ0hZdDJta19DSk53RE1fVDdqbUcweVk1djl0VXBRNHdxQlpoUVVGTUdJRThnenZtTlVqaWR0MEl2TTBpZm9LZlp0ZUdTX0tNa3djU0NYc0ZKbXZ0Snl5QTl6Qnp2TzBuX0l5QUkwSmVyLVEtUFNXOE4xUlhqSmF0MWpfSW0zYl92RjZwZ0FQcVJNY0twN1I0SW1xa0lxY0xMMGZUTGh1Rg?oc=5","published_at":"2026-02-20T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Claroty Team82 warns of growing cybersecurity risks in legacy LonTalk protocols across BMS deployments&nbsp;&nbsp;industrialcyber.co","title":"Claroty Team82 warns of growing cybersecurity risks in legacy LonTalk protocols across BMS deployments - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-bf86ff9fa0e00ff4","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi4AFBVV95cUxPdEhZRkp2ZU1WNTBYYmhiN3RkbWcwRWxXUl9tZzRDMFUxMHV1TEJ1aXN5SUEzTWZpc0VxcEwyZzNuZ0hZdDJta19DSk53RE1fVDdqbUcweVk1djl0VXBRNHdxQlpoUVVGTUdJRThnenZtTlVqaWR0MEl2TTBpZm9LZlp0ZUdTX0tNa3djU0NYc0ZKbXZ0Snl5QTl6Qnp2TzBuX0l5QUkwSmVyLVEtUFNXOE4xUlhqSmF0MWpfSW0zYl92RjZwZ0FQcVJNY0twN1I0SW1xa0lxY0xMMGZUTGh1Rg?oc=5","published_at":"2026-02-20T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Claroty Team82 warns of growing cybersecurity risks in legacy LonTalk protocols across BMS deployments&nbsp;&nbsp;Industrial Cyber","title":"Claroty Team82 warns of growing cybersecurity risks in legacy LonTalk protocols across BMS deployments - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-0a0cdba07e0dc57c","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMilAFBVV95cUxQTThGcHFiM2hfX1JUQ18tUXZkcHJSdGFEa2RPZE9hUjIxZUFYaGg2ZURDWUZDaVdhTGtET0lXVk53clFjaEpfZC1vMExzdTU2WVRkUmFCRkJKTmpJSERPeEt4X0Z0OVNYSm96SE8ydi1oSHhOTHpNMU0tUFVNM0tJMHhCaGhFeWJ3MnZYTTlSOUtIYXdu?oc=5","published_at":"2026-02-19T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Researchers warn Volt Typhoon still embedded in US utilities and some breaches may never be found&nbsp;&nbsp;therecord.media","title":"Researchers warn Volt Typhoon still embedded in US utilities and some breaches may never be found - therecord.media"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-37068a1372158368","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMilAFBVV95cUxQTThGcHFiM2hfX1JUQ18tUXZkcHJSdGFEa2RPZE9hUjIxZUFYaGg2ZURDWUZDaVdhTGtET0lXVk53clFjaEpfZC1vMExzdTU2WVRkUmFCRkJKTmpJSERPeEt4X0Z0OVNYSm96SE8ydi1oSHhOTHpNMU0tUFVNM0tJMHhCaGhFeWJ3MnZYTTlSOUtIYXdu?oc=5","published_at":"2026-02-19T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Researchers warn Volt Typhoon still embedded in US utilities and some breaches may never be found&nbsp;&nbsp;The Record from Recorded Future News","title":"Researchers warn Volt Typhoon still embedded in US utilities and some breaches may never be found - The Record from Recorded Future News"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-a0de1ccc2912132b","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiwgFBVV95cUxPNGJ3LWM4X2Uycm1IaHMxRTJJemlNcnFRNEtXRGRiT01BUVNXdUdnWnhRd1E4blJrdkJ6T1hqd1A2RzBRRUM1YkNqSzhRMlB6eHdZQkthZnE2Z0NhekI4dTJmbTJYSG1XWEhDbzN5TmhjVm9HMTdwUGRxY3ZRdU8wOEZqOGdJdW9EcVVpOXhzWnl6U0RRWW1pZ1pKRVF0WmlCMHNkYVlWQkJtb1IyRFVGX21keDNLWm9aYWticDFmSEhFdw?oc=5","published_at":"2026-02-18T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Dragos report: New threat groups target critical infrastructure&nbsp;&nbsp;scworld.com","title":"Dragos report: New threat groups target critical infrastructure - scworld.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-58135d09a5b00878","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiwgFBVV95cUxPNGJ3LWM4X2Uycm1IaHMxRTJJemlNcnFRNEtXRGRiT01BUVNXdUdnWnhRd1E4blJrdkJ6T1hqd1A2RzBRRUM1YkNqSzhRMlB6eHdZQkthZnE2Z0NhekI4dTJmbTJYSG1XWEhDbzN5TmhjVm9HMTdwUGRxY3ZRdU8wOEZqOGdJdW9EcVVpOXhzWnl6U0RRWW1pZ1pKRVF0WmlCMHNkYVlWQkJtb1IyRFVGX21keDNLWm9aYWticDFmSEhFdw?oc=5","published_at":"2026-02-18T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Dragos report: New threat groups target critical infrastructure&nbsp;&nbsp;SC Media","title":"Dragos report: New threat groups target critical infrastructure - SC Media"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f5767e394b3e6096","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiiAJBVV95cUxNWTA5NU5WQ1c4REUtb1ZzVy1uSGtDbFEtaWgzNTQ5RVJIYU03d3dkNDhWY3ZuN3Bfc0Y5OE5lSFBtMnVaWmw5b25Bc21hb24yTVBLbndsTDJaWEhEakY5cUZHVDNLWW53LTdrUU9CVGdFbnhzaHc4ZnF0dTdRY09hWXBCTDJaSU9QSy10SHVmNDVWQ0ZON2ZDZHRxRW9EVlBVUFBDMVE5RmVVNDNMQU9NamlXdzg2VVdkVE1NVUJab0RESjlBOXAyRzhJNHQ1aGtyRmNmMzB4NjBxTFN0SkhDVjIzb3JCMWw4RzRuR3VTOEw4bzNLbG42d2VyVEw4SXNHUlNPd29aaHc?oc=5","published_at":"2026-02-17T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Dragos OT Cybersecurity Report: Adversaries Increase Real-World Impact, Map Control Loops Across Industrial Infrastructure&nbsp;&nbsp;Business Wire","title":"Dragos OT Cybersecurity Report: Adversaries Increase Real-World Impact, Map Control Loops Across Industrial Infrastructure - Business Wire"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-573b6ece9aead2d6","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikgFBVV95cUxOdHdtQXFfWEdyTUVLSmNYVE9PTTExOEc1MnpwckFNQ2lKOFFmNnN6b0ttdzctNEdXLTkzamllckd3azFfU3VlSXhXclJLSmpoUDhIbVJIVEpvZDdodlZlYTN0VWVmN3hNd1A1OVhOc2Z1QjF4b0xHWFJFa00wT3MxLVZKNkNRNlpTd2FRX1c4M01qUQ?oc=5","published_at":"2026-02-17T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Newly identified hacking groups provide access to OT environments&nbsp;&nbsp;Cybersecurity Dive","title":"Newly identified hacking groups provide access to OT environments - Cybersecurity Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-035185f1baa06b35","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikgFBVV95cUxOdHdtQXFfWEdyTUVLSmNYVE9PTTExOEc1MnpwckFNQ2lKOFFmNnN6b0ttdzctNEdXLTkzamllckd3azFfU3VlSXhXclJLSmpoUDhIbVJIVEpvZDdodlZlYTN0VWVmN3hNd1A1OVhOc2Z1QjF4b0xHWFJFa00wT3MxLVZKNkNRNlpTd2FRX1c4M01qUQ?oc=5","published_at":"2026-02-17T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Newly identified hacking groups provide access to OT environments&nbsp;&nbsp;cybersecuritydive.com","title":"Newly identified hacking groups provide access to OT environments - cybersecuritydive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9b1d9cc2af56f5b3","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiiAJBVV95cUxNWTA5NU5WQ1c4REUtb1ZzVy1uSGtDbFEtaWgzNTQ5RVJIYU03d3dkNDhWY3ZuN3Bfc0Y5OE5lSFBtMnVaWmw5b25Bc21hb24yTVBLbndsTDJaWEhEakY5cUZHVDNLWW53LTdrUU9CVGdFbnhzaHc4ZnF0dTdRY09hWXBCTDJaSU9QSy10SHVmNDVWQ0ZON2ZDZHRxRW9EVlBVUFBDMVE5RmVVNDNMQU9NamlXdzg2VVdkVE1NVUJab0RESjlBOXAyRzhJNHQ1aGtyRmNmMzB4NjBxTFN0SkhDVjIzb3JCMWw4RzRuR3VTOEw4bzNLbG42d2VyVEw4SXNHUlNPd29aaHc?oc=5","published_at":"2026-02-17T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Dragos OT Cybersecurity Report: Adversaries Increase Real-World Impact, Map Control Loops Across Industrial Infrastructure&nbsp;&nbsp;businesswire.com","title":"Dragos OT Cybersecurity Report: Adversaries Increase Real-World Impact, Map Control Loops Across Industrial Infrastructure - businesswire.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c4f5eb6d9891c3a6","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiaEFVX3lxTE9xbWJEMU1XbEtiWk8yZnVHWWlnMnEyaUJDak9KR2RXbmZkV2tXQXFMS2Y2NVNEVks2dENrNzRXb1VhanFyemVMek9MRFEwSmhuSVdmNWtKZnJXUWUtUWZUSEt6UnNJd0Rx?oc=5","published_at":"2026-02-13T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"China may be rehearsing a digital siege, Taiwan warns&nbsp;&nbsp;The Record from Recorded Future News","title":"China may be rehearsing a digital siege, Taiwan warns - The Record from Recorded Future News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9c2e7ec43298322d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiaEFVX3lxTE9xbWJEMU1XbEtiWk8yZnVHWWlnMnEyaUJDak9KR2RXbmZkV2tXQXFMS2Y2NVNEVks2dENrNzRXb1VhanFyemVMek9MRFEwSmhuSVdmNWtKZnJXUWUtUWZUSEt6UnNJd0Rx?oc=5","published_at":"2026-02-13T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"China may be rehearsing a digital siege, Taiwan warns&nbsp;&nbsp;therecord.media","title":"China may be rehearsing a digital siege, Taiwan warns - therecord.media"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-49742bc19a2bdcaa","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi5gFBVV95cUxOWUlnWmE4MHdibG5WM2sxM3N6Mm1jTDlXdUVWQUVuMmFvbWxXYzBXNW1aLW9JcHgtV2NXTFF0cjFKYTBBbkR6S3RlcnB3ZFljZTBubzJEQkh2dTNkM1lHUzFPdTBQSWRFTjVoVEpkWmtaQ2stdlgtYnRSUzI5SS0tZThCOERsaVlkeXNfLU1UeVc5TE5Pc2pieVUyNm42X1hSaDdtNVRLTUk4TW1qdHhuM20zVnJmVWdZYXNVYWd3RzlDSy1GQTRyYllmZFF2cWhpRFlscWRFOHU5bi00RVc4VDBpaWtBUQ?oc=5","published_at":"2026-02-09T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"IISS notes Volt Typhoon\u2019s targeting of US infrastructure signals disruptive intent beyond espionage&nbsp;&nbsp;industrialcyber.co","title":"IISS notes Volt Typhoon\u2019s targeting of US infrastructure signals disruptive intent beyond espionage - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-3f68ab9cfe5d134a","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMidkFVX3lxTE9sTkVyQXdPc1RfN0JGRDdKTzhDdFpBWnRBbzRaR3A2Unlua1pDWllZakRUc0taTDAxWm1YRUp6NzdkNEUwd0lDNnBtR09EWGMzdFNFdTR2U01fNi03RUNSSXUzS3RaRDRSSzV6ZkxjSkVoa2dncFE?oc=5","published_at":"2026-02-09T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Singapore says China-linked hackers targeted telecom providers in major spying campaign&nbsp;&nbsp;therecord.media","title":"Singapore says China-linked hackers targeted telecom providers in major spying campaign - therecord.media"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2d3da35cc7b2531b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMingFBVV95cUxNTjBPTWt1YnlxVFhZVUNwcWZsU1ZqRXVpZTVPdGo4WkpfemZiajhtbUFKdHdMamZVMnFJem1tMENQVGI1UjlDV0VWbkxIZ2puc3AyMGlGdmJlY2llMklMYkNaMllSUlRGR0VKVmw2SkxCSTFwVmRWVDczT3NSM2JnRUdka2NWRWU0dURBQ3E5c1JuZW9RazVIZmo4ME42UQ?oc=5","published_at":"2026-02-09T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"How AI Is Transforming Industrial Automation Software Development&nbsp;&nbsp;Automation.com","title":"How AI Is Transforming Industrial Automation Software Development - Automation.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-fd516215ec7fbdf0","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMingFBVV95cUxNTjBPTWt1YnlxVFhZVUNwcWZsU1ZqRXVpZTVPdGo4WkpfemZiajhtbUFKdHdMamZVMnFJem1tMENQVGI1UjlDV0VWbkxIZ2puc3AyMGlGdmJlY2llMklMYkNaMllSUlRGR0VKVmw2SkxCSTFwVmRWVDczT3NSM2JnRUdka2NWRWU0dURBQ3E5c1JuZW9RazVIZmo4ME42UQ?oc=5","published_at":"2026-02-09T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"How AI Is Transforming Industrial Automation Software Development&nbsp;&nbsp;automation.com","title":"How AI Is Transforming Industrial Automation Software Development - automation.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8523e1bb9daa60bb","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMidkFVX3lxTE9sTkVyQXdPc1RfN0JGRDdKTzhDdFpBWnRBbzRaR3A2Unlua1pDWllZakRUc0taTDAxWm1YRUp6NzdkNEUwd0lDNnBtR09EWGMzdFNFdTR2U01fNi03RUNSSXUzS3RaRDRSSzV6ZkxjSkVoa2dncFE?oc=5","published_at":"2026-02-09T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Singapore says China-linked hackers targeted telecom providers in major spying campaign&nbsp;&nbsp;The Record from Recorded Future News","title":"Singapore says China-linked hackers targeted telecom providers in major spying campaign - The Record from Recorded Future News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9fd0e18dbf94f4ce","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihgFBVV95cUxQeFpYeUlwUS1pX2NEeTFZalFlWGNSbXpYNk1MdVdlUW5LVGZMTFNVQUhUS3BVcl9BNHc4WUhDNW5FdW1zT3ZZSXc3eW5RYXE0dDN0cXo1d1FfdFQzYWJhVzdMcVNDOFpZa19DS2U2YlptdzFibzBwdXhnX2ZLT1doNDJUWU9tdw?oc=5","published_at":"2026-02-09T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Industrial Automation Report: 4.3M Robots in Factories&nbsp;&nbsp;StartUs Insights","title":"Industrial Automation Report: 4.3M Robots in Factories - StartUs Insights"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7adf9c4af6364670","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihgFBVV95cUxQeFpYeUlwUS1pX2NEeTFZalFlWGNSbXpYNk1MdVdlUW5LVGZMTFNVQUhUS3BVcl9BNHc4WUhDNW5FdW1zT3ZZSXc3eW5RYXE0dDN0cXo1d1FfdFQzYWJhVzdMcVNDOFpZa19DS2U2YlptdzFibzBwdXhnX2ZLT1doNDJUWU9tdw?oc=5","published_at":"2026-02-09T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Industrial Automation Report: 4.3M Robots in Factories&nbsp;&nbsp;startus-insights.com","title":"Industrial Automation Report: 4.3M Robots in Factories - startus-insights.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-87c896d91a18b66b","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi5gFBVV95cUxOWUlnWmE4MHdibG5WM2sxM3N6Mm1jTDlXdUVWQUVuMmFvbWxXYzBXNW1aLW9JcHgtV2NXTFF0cjFKYTBBbkR6S3RlcnB3ZFljZTBubzJEQkh2dTNkM1lHUzFPdTBQSWRFTjVoVEpkWmtaQ2stdlgtYnRSUzI5SS0tZThCOERsaVlkeXNfLU1UeVc5TE5Pc2pieVUyNm42X1hSaDdtNVRLTUk4TW1qdHhuM20zVnJmVWdZYXNVYWd3RzlDSy1GQTRyYllmZFF2cWhpRFlscWRFOHU5bi00RVc4VDBpaWtBUQ?oc=5","published_at":"2026-02-09T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"IISS notes Volt Typhoon\u2019s targeting of US infrastructure signals disruptive intent beyond espionage&nbsp;&nbsp;Industrial Cyber","title":"IISS notes Volt Typhoon\u2019s targeting of US infrastructure signals disruptive intent beyond espionage - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4d72376837838ee7","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiW0FVX3lxTFBRWFM1NTF5ZHBwcE9KdlpVb09xbzhJeTZ0UjIxdlRELXg2SEZhdXIwNzhSeDFxSzROZGgwSm1Nb1IyUE9ldnNxdXM2X1FwTnl0VWVSbDZZV2J4X2c?oc=5","published_at":"2026-02-07T14:01:06+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Agentic AI for Cybersecurity: 10 Use Cases & Examples&nbsp;&nbsp;aimultiple.com","title":"Agentic AI for Cybersecurity: 10 Use Cases & Examples - aimultiple.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a17fdd28ce610c68","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiW0FVX3lxTFBRWFM1NTF5ZHBwcE9KdlpVb09xbzhJeTZ0UjIxdlRELXg2SEZhdXIwNzhSeDFxSzROZGgwSm1Nb1IyUE9ldnNxdXM2X1FwTnl0VWVSbDZZV2J4X2c?oc=5","published_at":"2026-02-07T14:01:06+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Agentic AI for Cybersecurity: 10 Use Cases & Examples&nbsp;&nbsp;AIMultiple","title":"Agentic AI for Cybersecurity: 10 Use Cases & Examples - AIMultiple"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-d737d38c1609775e","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi8gFBVV95cUxNWEpoNVJ4bllsaHh1Mmo5MXlMcWRzOF9wVXdNX2Q3TUtTTzRPbjdxTjNxYjJfZUszZWNGeVhsSGVZWmdGZDZuZmlUY1ZzRHU3OUNQWmcwUTF6cjZNbmtodWo0bWF3dFotLWlhSkt1M2JJT2ZCZy1zX3RmWU1uZ29Ia056LUJoR3hpYUFNLWs5dWxmc0hSZmhZbHVpYzY5VzZCYm5hNGJlbDcxYmRwX1lCYW5zSWN1aTMzcTRTcEtjM2F1MHd4N1c0OFlQR01MYUZuSm9kdzR3RE9XSHVmc2dJdmJoYVFkMldMMWlHUzlDQ0VZQQ?oc=5","published_at":"2026-02-05T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Senator demands public oversight hearing with AT&T, Verizon CEOs over Salt Typhoon cyber intrusion&nbsp;&nbsp;Industrial Cyber","title":"Senator demands public oversight hearing with AT&T, Verizon CEOs over Salt Typhoon cyber intrusion - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-ec3107f9acebf544","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi8gFBVV95cUxNWEpoNVJ4bllsaHh1Mmo5MXlMcWRzOF9wVXdNX2Q3TUtTTzRPbjdxTjNxYjJfZUszZWNGeVhsSGVZWmdGZDZuZmlUY1ZzRHU3OUNQWmcwUTF6cjZNbmtodWo0bWF3dFotLWlhSkt1M2JJT2ZCZy1zX3RmWU1uZ29Ia056LUJoR3hpYUFNLWs5dWxmc0hSZmhZbHVpYzY5VzZCYm5hNGJlbDcxYmRwX1lCYW5zSWN1aTMzcTRTcEtjM2F1MHd4N1c0OFlQR01MYUZuSm9kdzR3RE9XSHVmc2dJdmJoYVFkMldMMWlHUzlDQ0VZQQ?oc=5","published_at":"2026-02-05T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Senator demands public oversight hearing with AT&T, Verizon CEOs over Salt Typhoon cyber intrusion&nbsp;&nbsp;industrialcyber.co","title":"Senator demands public oversight hearing with AT&T, Verizon CEOs over Salt Typhoon cyber intrusion - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f470c7e2a124e7cc","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikgFBVV95cUxPSHhyS2NHeE90QkNuY3dCcnRDa2dkRzYxeW5MMFpkeXp2QUt3cDJQcHViUEpJTjFfM2hKTVNOZzdzLS1XUXk0SnF3VV9NLS1DVTlmWFFpZmN4TFV3SDNWaDlOenI3VzctdFlaR19sMktldFhCTWFCSjVueW5QOHJVOUFScDktdTlLT2lEUjAtOW1Edw?oc=5","published_at":"2026-02-02T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Why 'move fast and break things' is driving supply-chain cyber risk&nbsp;&nbsp;cyberscoop.com","title":"Why 'move fast and break things' is driving supply-chain cyber risk - cyberscoop.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e4bc78efce4ba52c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikgFBVV95cUxPSHhyS2NHeE90QkNuY3dCcnRDa2dkRzYxeW5MMFpkeXp2QUt3cDJQcHViUEpJTjFfM2hKTVNOZzdzLS1XUXk0SnF3VV9NLS1DVTlmWFFpZmN4TFV3SDNWaDlOenI3VzctdFlaR19sMktldFhCTWFCSjVueW5QOHJVOUFScDktdTlLT2lEUjAtOW1Edw?oc=5","published_at":"2026-02-02T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Why 'move fast and break things' is driving supply-chain cyber risk&nbsp;&nbsp;CyberScoop","title":"Why 'move fast and break things' is driving supply-chain cyber risk - CyberScoop"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-08ed624e783ec958","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi2AFBVV95cUxQVUNHelNzTXlpMGJIeC1wb0tDcGEzVmJWWV8tYjB1X0N0dFQ2UnZ4WmF3cTVMV2lnN2c2MFZ6a0M2ZXFaN2dSTmlsQjVSWkNuSzYxd0ZLbFp6TjlEU291ZzVUdm5uWXRvS3JET0R4dWIzLWU3ZlV1dzhWQ3pvSVd0VUxQYlNLVE5yVDhqMFpXQWx1MUdDWHJ0MFEyNTNWN3h0bXVzOERmaW1nWklydlBFWkZ3by1hZ0JMei14am5xM2tFNU51NzYzNXVoQTNZZUU1MGZfYUlodFY?oc=5","published_at":"2026-02-01T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"AI accelerates industrial cyber threats, transforms OT attack landscape to challenge traditional defenses&nbsp;&nbsp;industrialcyber.co","title":"AI accelerates industrial cyber threats, transforms OT attack landscape to challenge traditional defenses - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ed78dc00c6898694","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi2AFBVV95cUxQVUNHelNzTXlpMGJIeC1wb0tDcGEzVmJWWV8tYjB1X0N0dFQ2UnZ4WmF3cTVMV2lnN2c2MFZ6a0M2ZXFaN2dSTmlsQjVSWkNuSzYxd0ZLbFp6TjlEU291ZzVUdm5uWXRvS3JET0R4dWIzLWU3ZlV1dzhWQ3pvSVd0VUxQYlNLVE5yVDhqMFpXQWx1MUdDWHJ0MFEyNTNWN3h0bXVzOERmaW1nWklydlBFWkZ3by1hZ0JMei14am5xM2tFNU51NzYzNXVoQTNZZUU1MGZfYUlodFY?oc=5","published_at":"2026-02-01T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"AI accelerates industrial cyber threats, transforms OT attack landscape to challenge traditional defenses&nbsp;&nbsp;Industrial Cyber","title":"AI accelerates industrial cyber threats, transforms OT attack landscape to challenge traditional defenses - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-11c9862acfc83cd5","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxPTHpJN3MtcmhIaXlzQjhnd2h3Q1BqQ3lLUGZZblJFd0ZkMm9kclBwUlFjcUFDM1hPd1lMQ282TTdZQzhpeEpvd1d3RHJJUjdCZ2lGUDVQY2J4LTRTWDBmTUtZYjEwb0xueVhDWVQ4eWZBSkhrYlN1OS1ySkp1Zkljc0NWRC1KQjV1REYyT0FQbHJpRWpPYkJRWWVmRm96bjg?oc=5","published_at":"2026-01-30T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"China\u2019s Typhoon hackers have changed the rules of cybersecurity&nbsp;&nbsp;scworld.com","title":"China\u2019s Typhoon hackers have changed the rules of cybersecurity - scworld.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-dbac0e11a195c2fc","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxPTHpJN3MtcmhIaXlzQjhnd2h3Q1BqQ3lLUGZZblJFd0ZkMm9kclBwUlFjcUFDM1hPd1lMQ282TTdZQzhpeEpvd1d3RHJJUjdCZ2lGUDVQY2J4LTRTWDBmTUtZYjEwb0xueVhDWVQ4eWZBSkhrYlN1OS1ySkp1Zkljc0NWRC1KQjV1REYyT0FQbHJpRWpPYkJRWWVmRm96bjg?oc=5","published_at":"2026-01-30T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"China\u2019s Typhoon hackers have changed the rules of cybersecurity&nbsp;&nbsp;SC Media","title":"China\u2019s Typhoon hackers have changed the rules of cybersecurity - SC Media"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-cc1dc07ef922c597","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMid0FVX3lxTE5vN1JYeERPYTZod210R21zQ0swVThWZFJEcTB0YlB6aUFsVGF6b1UxaFUwUmhMZGdEX2UzYmZEalpoclNRcDlwSUE0UTdUXzVjZ25Ic2hKVTdMM0lJdGxUbzZCTnp2YkNKVDZRQXQ2RUd0OXFpYm0w?oc=5","published_at":"2026-01-29T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Is America\u2019s Cyber Weakness Self-Inflicted?&nbsp;&nbsp;warontherocks.com","title":"Is America\u2019s Cyber Weakness Self-Inflicted? - warontherocks.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1f17845b38f30a80","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi7wFBVV95cUxQOGt5eXBQYlVrM2ZDTmtxYlZLTFQweWh3TDJwckNKd1ZRd3dmaXd1WWxpZGNfWjctaXVGWnZNUTk0RXJlMERLVUFkMXc0S29RZzlqQXA1bDdjdTZtOXEtS2pmX2c3S1VjekpMRDBoQk9SWnJyOHl0R3FVVWViWkhUS19YYjNvWmZRY2FKeGFPNHNnUFNxTnFqN3NJV1lnSjBPV09MS19KRWYzUlA3dWpSV3ZoUkdYREJKLWFYdWg1eFAzTnNWYUphdWZJS0I1U19OZEdSZWhTLTJTcDRNOXhJVUFQRXdUT1Faem5lTUdTUQ?oc=5","published_at":"2026-01-29T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"La Ni\u00f1a, Climate change, high exposure and vulnerability combined led to devastating floods in parts of Southern Africa&nbsp;&nbsp;worldweatherattribution.org","title":"La Ni\u00f1a, Climate change, high exposure and vulnerability combined led to devastating floods in parts of Southern Africa - worldweatherattribution.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ee3ca77d3b8f9b6e","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMid0FVX3lxTE5vN1JYeERPYTZod210R21zQ0swVThWZFJEcTB0YlB6aUFsVGF6b1UxaFUwUmhMZGdEX2UzYmZEalpoclNRcDlwSUE0UTdUXzVjZ25Ic2hKVTdMM0lJdGxUbzZCTnp2YkNKVDZRQXQ2RUd0OXFpYm0w?oc=5","published_at":"2026-01-29T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Is America\u2019s Cyber Weakness Self-Inflicted?&nbsp;&nbsp;War on the Rocks","title":"Is America\u2019s Cyber Weakness Self-Inflicted? - War on the Rocks"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4eacac2077dad931","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi7wFBVV95cUxQOGt5eXBQYlVrM2ZDTmtxYlZLTFQweWh3TDJwckNKd1ZRd3dmaXd1WWxpZGNfWjctaXVGWnZNUTk0RXJlMERLVUFkMXc0S29RZzlqQXA1bDdjdTZtOXEtS2pmX2c3S1VjekpMRDBoQk9SWnJyOHl0R3FVVWViWkhUS19YYjNvWmZRY2FKeGFPNHNnUFNxTnFqN3NJV1lnSjBPV09MS19KRWYzUlA3dWpSV3ZoUkdYREJKLWFYdWg1eFAzTnNWYUphdWZJS0I1U19OZEdSZWhTLTJTcDRNOXhJVUFQRXdUT1Faem5lTUdTUQ?oc=5","published_at":"2026-01-29T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"La Ni\u00f1a, Climate change, high exposure and vulnerability combined led to devastating floods in parts of Southern Africa&nbsp;&nbsp;World Weather Attribution","title":"La Ni\u00f1a, Climate change, high exposure and vulnerability combined led to devastating floods in parts of Southern Africa - World Weather Attribution"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-12466b722d6f6dc0","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi3wFBVV95cUxOZGhqZEsyRkNwSTN1S21HZVEtaEZhUzhBc01XVDVoMS1sSVVVWm1aYVV5LThQTHZjMmR5RXozcm16em1IYjJzM3RHMTIzcjY3Y3FMNUtsOTJsV1FSbC1DRWVFdFc5VkNIZV9wbTZQdExyZmE5cHNmRm9ELXItNmRQQkE5eEtOeVRmUEpPbXZpVl81dmdvcFBkYUQ0TXlBU1FXWG9OaFBYTnFkVlNrYklPajVvcTAzZzluYl8zUkhzREV6UFZaQWxhbmJSZm1UWDVjb0FJU1VYOGFRVVJxRE9F?oc=5","published_at":"2026-01-28T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Local cybersecurity expert weighs in on TikTok U.S. ownership change&nbsp;&nbsp;cbs8.com","title":"Local cybersecurity expert weighs in on TikTok U.S. ownership change - cbs8.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-952340d546687139","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxORlRncjhMa1YtLWQ0azlONGdKRmZZTVlkMUxCWFdOOEdKdHJOOFJOZ2d6Y0drNmtBcjF2NmZVTWFrdGJhVFEtMmNGTFdseVI5N3dLQ01qQzdlN0xwMnQ0V1dLb2hSVHFld2lWMEJDVHNya2lxdjJmUU5NdmtTejk1c29FeG5qeE1qdmFfbmxPQXdNRXFjQi1Kd211S1VRaFk?oc=5","published_at":"2026-01-28T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Pentagon leaders expect Cybercom 2.0 to help thwart Chinese actors \u2018living off the land\u2019&nbsp;&nbsp;DefenseScoop","title":"Pentagon leaders expect Cybercom 2.0 to help thwart Chinese actors \u2018living off the land\u2019 - DefenseScoop"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9a86513e0800a23f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxORlRncjhMa1YtLWQ0azlONGdKRmZZTVlkMUxCWFdOOEdKdHJOOFJOZ2d6Y0drNmtBcjF2NmZVTWFrdGJhVFEtMmNGTFdseVI5N3dLQ01qQzdlN0xwMnQ0V1dLb2hSVHFld2lWMEJDVHNya2lxdjJmUU5NdmtTejk1c29FeG5qeE1qdmFfbmxPQXdNRXFjQi1Kd211S1VRaFk?oc=5","published_at":"2026-01-28T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Pentagon leaders expect Cybercom 2.0 to help thwart Chinese actors \u2018living off the land\u2019&nbsp;&nbsp;defensescoop.com","title":"Pentagon leaders expect Cybercom 2.0 to help thwart Chinese actors \u2018living off the land\u2019 - defensescoop.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e9fcf5b9cfe241ce","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisgFBVV95cUxPY013cXFWR0RkQUlZQ3FfbVZkSDE1UlF2YnVTZktBUHJIQXlNU3RjXzA4VldJWFE1VGdZTVpULVNIcWtEQkF5Z1FrdlRtYU1WRXRPaHVvUDAxUF9zWElhM1NhUnNmMTRXMlIxOTdSRHdpWWpWaHBvNUlrc2NaQWdRd211Q1YtYjMtM1EtdHYzUUliU2xUTzIydW5NWmY5bWR3Qk9hQ3B3LW12Yno2dFdjUW9R?oc=5","published_at":"2026-01-26T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"The New U.S. Cyber Strategy Misreads China\u2019s Threat&nbsp;&nbsp;cfr.org","title":"The New U.S. Cyber Strategy Misreads China\u2019s Threat - cfr.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b9afc1598ea3248f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisgFBVV95cUxPY013cXFWR0RkQUlZQ3FfbVZkSDE1UlF2YnVTZktBUHJIQXlNU3RjXzA4VldJWFE1VGdZTVpULVNIcWtEQkF5Z1FrdlRtYU1WRXRPaHVvUDAxUF9zWElhM1NhUnNmMTRXMlIxOTdSRHdpWWpWaHBvNUlrc2NaQWdRd211Q1YtYjMtM1EtdHYzUUliU2xUTzIydW5NWmY5bWR3Qk9hQ3B3LW12Yno2dFdjUW9R?oc=5","published_at":"2026-01-26T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"The New U.S. Cyber Strategy Misreads China\u2019s Threat&nbsp;&nbsp;Council on Foreign Relations","title":"The New U.S. Cyber Strategy Misreads China\u2019s Threat - Council on Foreign Relations"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-1ea6188e93358200","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiswFBVV95cUxNSWVaQ0ZUTmdfMl9EdmtYcklUVkJuS25uS1VfTmp3Ri10TnItRVM3eHJYSElNRTBXWHRkWklMZVdYYzFVOGgzLUEzdEFBSEg2MWNQTGg4Zi0zaEc2eGlkNmJsTExkMV9UdVR3WGhmZG95TW9ENHhLdDZ0dnJIaTMxa3NtNWZ0azdDRm5FSlJ1STFqRy16X1JCWVFzOGtBWlpMZTFRYkVxczJ1aEs4SGF5X21fQQ?oc=5","published_at":"2026-01-25T04:49:28+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"Kill Switch: Connected Cars Are Widely Hackable&nbsp;&nbsp;consumerwatchdog.org","title":"Kill Switch: Connected Cars Are Widely Hackable - consumerwatchdog.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-844f32a9b8028145","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiswFBVV95cUxNSWVaQ0ZUTmdfMl9EdmtYcklUVkJuS25uS1VfTmp3Ri10TnItRVM3eHJYSElNRTBXWHRkWklMZVdYYzFVOGgzLUEzdEFBSEg2MWNQTGg4Zi0zaEc2eGlkNmJsTExkMV9UdVR3WGhmZG95TW9ENHhLdDZ0dnJIaTMxa3NtNWZ0azdDRm5FSlJ1STFqRy16X1JCWVFzOGtBWlpMZTFRYkVxczJ1aEs4SGF5X21fQQ?oc=5","published_at":"2026-01-25T04:49:28+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"Kill Switch: Connected Cars Are Widely Hackable&nbsp;&nbsp;Consumer Watchdog","title":"Kill Switch: Connected Cars Are Widely Hackable - Consumer Watchdog"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-16a1fbf343b6591e","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi2AFBVV95cUxOWktaVV9kVU1mMWNxN2FUZWlOOUZISkc5UEpvUmtBa3BuSWY1TEwxN3pXQkowVE9hd2h2NG93VW85emFlblVOeDB1S3VtQVJqOGtTTmpZTnFnYUdyaEpTcDhBNnM1dlZ5ZFdja29FcmFVOGhMWVhtelUzZ09xM2hqNC1lanpFNWdHb0J1Vzg4ZW9VNHpuZ0JCbDFIZGdINzlYTkdlZGo0alBLSFRNbGtKQklSSDNXUUJhVjRDXzJxWnljZGtpb1lJRy0xUTBqZFIxY09qTGNNZnk?oc=5","published_at":"2026-01-23T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"NIST begins overhaul of SP 800-82 to strengthen OT cybersecurity guidance, align with updated NIST frameworks&nbsp;&nbsp;Industrial Cyber","title":"NIST begins overhaul of SP 800-82 to strengthen OT cybersecurity guidance, align with updated NIST frameworks - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-b5a43e286e0e168a","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMilAFBVV95cUxNMUF5di0zeTJMOHlMaEVUZkpXZC1HM1VqN3dtNVlJMUdxVW9GcnJVemZrQlE2Z0RkMkRuUmpUMm1Zei1QdjVrX1Z0YzROMjVpb0ZDblJ5Q3N2NThDWXd4VFZwRmdrREVfNk9oay12TW9NaTFOWEdpbldPUjJkWnRYbzN4MHhUMFdOMWV4V3FDcTZsX3o4?oc=5","published_at":"2026-01-23T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Volt Typhoon\u2019s long shadow&nbsp;&nbsp;iiss.org","title":"Volt Typhoon\u2019s long shadow - iiss.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-46aefe09883d785a","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMilAFBVV95cUxNMUF5di0zeTJMOHlMaEVUZkpXZC1HM1VqN3dtNVlJMUdxVW9GcnJVemZrQlE2Z0RkMkRuUmpUMm1Zei1QdjVrX1Z0YzROMjVpb0ZDblJ5Q3N2NThDWXd4VFZwRmdrREVfNk9oay12TW9NaTFOWEdpbldPUjJkWnRYbzN4MHhUMFdOMWV4V3FDcTZsX3o4?oc=5","published_at":"2026-01-23T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Volt Typhoon\u2019s long shadow&nbsp;&nbsp;The International Institute for Strategic Studies","title":"Volt Typhoon\u2019s long shadow - The International Institute for Strategic Studies"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-267a85478a5cddaa","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi2AFBVV95cUxOWktaVV9kVU1mMWNxN2FUZWlOOUZISkc5UEpvUmtBa3BuSWY1TEwxN3pXQkowVE9hd2h2NG93VW85emFlblVOeDB1S3VtQVJqOGtTTmpZTnFnYUdyaEpTcDhBNnM1dlZ5ZFdja29FcmFVOGhMWVhtelUzZ09xM2hqNC1lanpFNWdHb0J1Vzg4ZW9VNHpuZ0JCbDFIZGdINzlYTkdlZGo0alBLSFRNbGtKQklSSDNXUUJhVjRDXzJxWnljZGtpb1lJRy0xUTBqZFIxY09qTGNNZnk?oc=5","published_at":"2026-01-23T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"NIST begins overhaul of SP 800-82 to strengthen OT cybersecurity guidance, align with updated NIST frameworks&nbsp;&nbsp;industrialcyber.co","title":"NIST begins overhaul of SP 800-82 to strengthen OT cybersecurity guidance, align with updated NIST frameworks - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-43cb48d764b78680","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiogFBVV95cUxOby1COHUzZjl0V3lBVGpLQ3pncVhEVS1wMDRDelhiTXIwZXJzV1pBcmNBQ0EwVzlNYV9rMzhmZHdTOTdhd1hsZHFmMmVLUTRTblQ5azlKd3Q1VXhaY3VqbFdkNXp5YjBYeG90MG1RSWJkdXNLMFFVN2pzZWpBdU83MXF3dXFJcnF5TVRTLWlEQ29yQmJWbnNwMjZ4LUNxS0lrZ2c?oc=5","published_at":"2026-01-22T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Hacking the Grid: How Digital Sabotage Turns Infrastructure Into a Weapon&nbsp;&nbsp;Georgia Institute of Technology","title":"Hacking the Grid: How Digital Sabotage Turns Infrastructure Into a Weapon - Georgia Institute of Technology"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8b6b12f5ac199dc0","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxPSEJsV3I4d0xVdzBYQ1NDOXpVUGd5dk16TVd6RmNxa0s4SloyNDFHVGkxeW4wVjl0TXNqMHZuMG54OUlyTXROQmxmMTk4UEdSY3BfTFR3QkxUbTJYR3kwcGJGZkpXbVIzUTNwLWRVcE1QRVZlYnhBeVFhRHJ2NjJoRzB6ZXJ4Vi1ZN05DTHduaGNwU19PYXlEZVljeUYwWVF0Um5nM0xmeHRFZFk?oc=5","published_at":"2026-01-22T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Hacking the grid: How digital sabotage turns infrastructure into a weapon&nbsp;&nbsp;The Conversation","title":"Hacking the grid: How digital sabotage turns infrastructure into a weapon - The Conversation"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9912758fa1c040b6","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiogFBVV95cUxOby1COHUzZjl0V3lBVGpLQ3pncVhEVS1wMDRDelhiTXIwZXJzV1pBcmNBQ0EwVzlNYV9rMzhmZHdTOTdhd1hsZHFmMmVLUTRTblQ5azlKd3Q1VXhaY3VqbFdkNXp5YjBYeG90MG1RSWJkdXNLMFFVN2pzZWpBdU83MXF3dXFJcnF5TVRTLWlEQ29yQmJWbnNwMjZ4LUNxS0lrZ2c?oc=5","published_at":"2026-01-22T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Hacking the Grid: How Digital Sabotage Turns Infrastructure Into a Weapon&nbsp;&nbsp;gatech.edu","title":"Hacking the Grid: How Digital Sabotage Turns Infrastructure Into a Weapon - gatech.edu"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-d0a2f5a60e28b70f","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiswFBVV95cUxNUEtXYXBXVW1JeGNkdHl0Yld1c1RJR0xaQ0E0YjJWSUd0ZlNCYTYwMmtrSXdSSmRxUHM0OFZnampLWTJ3N0QyWnhQenZHRU55X2czNENDRHpLRTFjc1ZSYnMtWW94eElpSVpLcTBoQVlJTVZRQkNqeXFiQkh5TVd5Mm9QTmRBa0h5elpxOFBMSk8zZXV1bGdwMF9qWEloV1VOYlczMG9fMDJ4ajlWQ0VNSmFpWQ?oc=5","published_at":"2026-01-20T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Critical infrastructures face major threat from Chinese cyberattacks, nominee warns&nbsp;&nbsp;Washington Times","title":"Critical infrastructures face major threat from Chinese cyberattacks, nominee warns - Washington Times"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-384ecf3bcac2d1ff","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi0wFBVV95cUxPazQtblBNM2R1T3hTZ1A4LTcxcExGWV91NUwtM1dvaWs2WFczb1ZnWmVsUHFRWE9HTlo2TC1rbzU2VjNFMkdEaHJtWTdLbEM1bGh2UlhnalpVa1NPTllpWUxCZFV4bUdsRDZXWGVUWnUzbUJiS0cxM3RKV1Z2aXdaT0ZiNlR2Qk42LWNPc1J0VW1pcE9XSmN4enNZNmZ6UVlYamhZdTlpVXpkd1NaV2FZU0djaVhSdElDRXpudnFWUmcwUzVZYzFHZ1F5bThIdWtndm40?oc=5","published_at":"2026-01-20T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"Hacktivists and cybercriminals expand attacks on ICS, OT, and AI systems across critical infrastructure&nbsp;&nbsp;industrialcyber.co","title":"Hacktivists and cybercriminals expand attacks on ICS, OT, and AI systems across critical infrastructure - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-02c6f07a7f016d7b","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi0wFBVV95cUxPazQtblBNM2R1T3hTZ1A4LTcxcExGWV91NUwtM1dvaWs2WFczb1ZnWmVsUHFRWE9HTlo2TC1rbzU2VjNFMkdEaHJtWTdLbEM1bGh2UlhnalpVa1NPTllpWUxCZFV4bUdsRDZXWGVUWnUzbUJiS0cxM3RKV1Z2aXdaT0ZiNlR2Qk42LWNPc1J0VW1pcE9XSmN4enNZNmZ6UVlYamhZdTlpVXpkd1NaV2FZU0djaVhSdElDRXpudnFWUmcwUzVZYzFHZ1F5bThIdWtndm40?oc=5","published_at":"2026-01-20T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"Hacktivists and cybercriminals expand attacks on ICS, OT, and AI systems across critical infrastructure&nbsp;&nbsp;Industrial Cyber","title":"Hacktivists and cybercriminals expand attacks on ICS, OT, and AI systems across critical infrastructure - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-e82bb10749ab889d","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiswFBVV95cUxQV3g1aUduR0xXenNQTENXazRNUXhaOVgyeHotckJqMUJoWjZucDRPOUJPRmFRSzRWOFVVeUdYanh4WEpuYmQ1a2Z2elBzSmNLUmhGT2dIMUo0MHV0dW8wTlE2cm5wTHFBUkRiYnR0cEFFNGpfdldFUWZVUHZyT3Q0bHY1dmxCOFdVWXJYR1pvcW1NQ19MOUtUNXVnT0I2dzhqM3hHWlpLLWxCS1l4Q0Q5Z3ZpQQ?oc=5","published_at":"2026-01-20T08:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"ACT probes Chinese-made buses after 'kill switch' warning&nbsp;&nbsp;ABC News & Headlines \u2013 Australian Broadcasting Corporation","title":"ACT probes Chinese-made buses after 'kill switch' warning - ABC News & Headlines \u2013 Australian Broadcasting Corporation"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-f603798abbb98b9d","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiswFBVV95cUxNUEtXYXBXVW1JeGNkdHl0Yld1c1RJR0xaQ0E0YjJWSUd0ZlNCYTYwMmtrSXdSSmRxUHM0OFZnampLWTJ3N0QyWnhQenZHRU55X2czNENDRHpLRTFjc1ZSYnMtWW94eElpSVpLcTBoQVlJTVZRQkNqeXFiQkh5TVd5Mm9QTmRBa0h5elpxOFBMSk8zZXV1bGdwMF9qWEloV1VOYlczMG9fMDJ4ajlWQ0VNSmFpWQ?oc=5","published_at":"2026-01-20T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Critical infrastructures face major threat from Chinese cyberattacks, nominee warns&nbsp;&nbsp;washingtontimes.com","title":"Critical infrastructures face major threat from Chinese cyberattacks, nominee warns - washingtontimes.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ac7906b634ed52bf","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxObzVOZktnTUVId2tIWmtyZDNKYjVlcHNyLWpxY1FZdS1zLVZoMTEtS2wtWGhrSDl2Rm43SHNFd0c5a0JHdlE5ZlFYb1d0clBfOWtjMENVQjZsX2E3anFNNDZkS3pkTzdtTlpISTI1dGVTSGhDXzM0QjQ5WWZESmkza2drcTVwQ2hFSndHcFQ4ZDNxQlNjVWk5MTJNaEVMVFF0QUpiLU9vTlA?oc=5","published_at":"2026-01-15T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"The dragon in the grid: Limiting China\u2019s influence in Europe\u2019s energy system&nbsp;&nbsp;iss.europa.eu","title":"The dragon in the grid: Limiting China\u2019s influence in Europe\u2019s energy system - iss.europa.eu"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9b8ae87b4ab7c0d2","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxObzVOZktnTUVId2tIWmtyZDNKYjVlcHNyLWpxY1FZdS1zLVZoMTEtS2wtWGhrSDl2Rm43SHNFd0c5a0JHdlE5ZlFYb1d0clBfOWtjMENVQjZsX2E3anFNNDZkS3pkTzdtTlpISTI1dGVTSGhDXzM0QjQ5WWZESmkza2drcTVwQ2hFSndHcFQ4ZDNxQlNjVWk5MTJNaEVMVFF0QUpiLU9vTlA?oc=5","published_at":"2026-01-15T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"The dragon in the grid: Limiting China\u2019s influence in Europe\u2019s energy system&nbsp;&nbsp;European Union Institute for Security Studies |","title":"The dragon in the grid: Limiting China\u2019s influence in Europe\u2019s energy system - European Union Institute for Security Studies |"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-b81d8b9625471390","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMigAFBVV95cUxQQ3EwOFVkaGh1d2o5RGZ5OUFuVV9JOXdUa0dlUi1sNzlJZEdHLWNiTEZURjlsbHVoQjVHdTNZTXlDeTdnR1AzWHhwbUg0ajk0SEZpXzRhazBJRFlWclpMX3A2Q2lYYXc0a2JLWHgtanVWZUYxSW80d1pMU2FDSFFnaQ?oc=5","published_at":"2026-01-15T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Cyber Threat Actors Ramp Up Attacks on Industrial Environments&nbsp;&nbsp;infosecurity-magazine.com","title":"Cyber Threat Actors Ramp Up Attacks on Industrial Environments - infosecurity-magazine.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-cacb5c2cb47e7c33","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMigAFBVV95cUxQQ3EwOFVkaGh1d2o5RGZ5OUFuVV9JOXdUa0dlUi1sNzlJZEdHLWNiTEZURjlsbHVoQjVHdTNZTXlDeTdnR1AzWHhwbUg0ajk0SEZpXzRhazBJRFlWclpMX3A2Q2lYYXc0a2JLWHgtanVWZUYxSW80d1pMU2FDSFFnaQ?oc=5","published_at":"2026-01-15T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Cyber Threat Actors Ramp Up Attacks on Industrial Environments&nbsp;&nbsp;Infosecurity Magazine","title":"Cyber Threat Actors Ramp Up Attacks on Industrial Environments - Infosecurity Magazine"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-ed9be38427010fb6","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi5AFBVV95cUxPVXdFM3Zta2x5aThhOGZkNDFHdTMtQVV5MEJiMVJRU1czZXpNQ21SbjBzRVBTZ2RHVi0tVTlsZ0RzTzJIbWtUa2tnYkNsYXNsN08xZjZIeno0aUVwak12TTNESVo1aVh4Q2lXcmZCTWZNXy1oVUh2eWpEMkV6a1BJd3VfaEVWUE4tLWFzRVFuaXJNWVo5bFVSZXM4MWJfMWY5Y2hiOV85b280RjFYUE5OWkUwczI3aVk4c04wblRlVzVrSjlRVEhkUTVqOFA0SUpDNGZTWldqQmZBRzJVOGJFOTdPR3g?oc=5","published_at":"2026-01-14T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"CISA issues multiple ICS advisories, details DoS vulnerability risk in Rockwell devices used in critical manufacturing&nbsp;&nbsp;industrialcyber.co","title":"CISA issues multiple ICS advisories, details DoS vulnerability risk in Rockwell devices used in critical manufacturing - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-13c15f52b36d479d","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi5AFBVV95cUxPVXdFM3Zta2x5aThhOGZkNDFHdTMtQVV5MEJiMVJRU1czZXpNQ21SbjBzRVBTZ2RHVi0tVTlsZ0RzTzJIbWtUa2tnYkNsYXNsN08xZjZIeno0aUVwak12TTNESVo1aVh4Q2lXcmZCTWZNXy1oVUh2eWpEMkV6a1BJd3VfaEVWUE4tLWFzRVFuaXJNWVo5bFVSZXM4MWJfMWY5Y2hiOV85b280RjFYUE5OWkUwczI3aVk4c04wblRlVzVrSjlRVEhkUTVqOFA0SUpDNGZTWldqQmZBRzJVOGJFOTdPR3g?oc=5","published_at":"2026-01-14T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"CISA issues multiple ICS advisories, details DoS vulnerability risk in Rockwell devices used in critical manufacturing&nbsp;&nbsp;Industrial Cyber","title":"CISA issues multiple ICS advisories, details DoS vulnerability risk in Rockwell devices used in critical manufacturing - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-b308ce421c69f065","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMibkFVX3lxTFB3S1A1MnplTk5XRTlpSDdlV1BQSDZiNTMyNkxWMjNVb1U1ZHNxTnZQM3YwTXpXQzF1aEpyOXRyaTJJay00OFZ3d0Y3bXd5c0QtclZYb2ZBZlg2aXFPbFo4YlFpalpCZThCUjRTTEpB?oc=5","published_at":"2026-01-13T08:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Industrial Switch Security","summary":"Critical OpenSSH Vulnerability Exposes Moxa Ethernet Switches to Remote Code Execution&nbsp;&nbsp;CyberSecurityNews","title":"Critical OpenSSH Vulnerability Exposes Moxa Ethernet Switches to Remote Code Execution - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-71cb19650e9fa055","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMibkFVX3lxTFB3S1A1MnplTk5XRTlpSDdlV1BQSDZiNTMyNkxWMjNVb1U1ZHNxTnZQM3YwTXpXQzF1aEpyOXRyaTJJay00OFZ3d0Y3bXd5c0QtclZYb2ZBZlg2aXFPbFo4YlFpalpCZThCUjRTTEpB?oc=5","published_at":"2026-01-13T08:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Industrial Switch Security","summary":"Critical OpenSSH Vulnerability Exposes Moxa Ethernet Switches to Remote Code Execution&nbsp;&nbsp;cybersecuritynews.com","title":"Critical OpenSSH Vulnerability Exposes Moxa Ethernet Switches to Remote Code Execution - cybersecuritynews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-91d083f477da48d0","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimAFBVV95cUxNZVZTTDZhYWlCR1kwclRXYjVTNF9VOUlMZUNhQjFmQzNTNmZwRXFHMXFKNGFYdm5ES1BaNE9iSklwaEtFZTBvUFVZb1dMU0FIVXZiUGJQRFoyT0J0X0dwTHRCbktyMDFDSjAxSTVzdmRHanhqb1FudVdwcE1uQnZXUXJYMDQ0RmYzZGtyOVFsQmFkRFltaUMwWQ?oc=5","published_at":"2026-01-12T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Critical vulnerability found in n8n workflow automation platform&nbsp;&nbsp;cybersecuritydive.com","title":"Critical vulnerability found in n8n workflow automation platform - cybersecuritydive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-516a0adfa7b57ac5","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimAFBVV95cUxNZVZTTDZhYWlCR1kwclRXYjVTNF9VOUlMZUNhQjFmQzNTNmZwRXFHMXFKNGFYdm5ES1BaNE9iSklwaEtFZTBvUFVZb1dMU0FIVXZiUGJQRFoyT0J0X0dwTHRCbktyMDFDSjAxSTVzdmRHanhqb1FudVdwcE1uQnZXUXJYMDQ0RmYzZGtyOVFsQmFkRFltaUMwWQ?oc=5","published_at":"2026-01-12T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Critical vulnerability found in n8n workflow automation platform&nbsp;&nbsp;Cybersecurity Dive","title":"Critical vulnerability found in n8n workflow automation platform - Cybersecurity Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-fb311db0206fa09b","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuAFBVV95cUxOdjRhS3JRN0FTWXY0ajRIUVlSVXQ3MG5mWVBubk1GYVRscldoQWYwa2hrQ2ZNZXFsTFE4UG9KLVFJSEh0Z2pDdVRxb2R1Q2dIdFNzRnAtcl95cThHWmtJc01NaERjblh2RWx4RkM2OS05QXhtUkxTOGFyd1hCZ255eDRrb2pLR2ZpNUFJTl9mM281VndlS1UtaVhtNlU4RlVvOVBneFJsTHBfMTVuRG1aYVhyd1MwTnB4?oc=5","published_at":"2026-01-12T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"CISA director void leaves cyber agency embroiled in uncertainty&nbsp;&nbsp;Federal News Network","title":"CISA director void leaves cyber agency embroiled in uncertainty - Federal News Network"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8904d22e20c6732e","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuAFBVV95cUxOdjRhS3JRN0FTWXY0ajRIUVlSVXQ3MG5mWVBubk1GYVRscldoQWYwa2hrQ2ZNZXFsTFE4UG9KLVFJSEh0Z2pDdVRxb2R1Q2dIdFNzRnAtcl95cThHWmtJc01NaERjblh2RWx4RkM2OS05QXhtUkxTOGFyd1hCZ255eDRrb2pLR2ZpNUFJTl9mM281VndlS1UtaVhtNlU4RlVvOVBneFJsTHBfMTVuRG1aYVhyd1MwTnB4?oc=5","published_at":"2026-01-12T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"CISA director void leaves cyber agency embroiled in uncertainty&nbsp;&nbsp;federalnewsnetwork.com","title":"CISA director void leaves cyber agency embroiled in uncertainty - federalnewsnetwork.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-5b171a70af15c007","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxNbm9SY08tc0ZHaWJDYXdleXY5QTMySjZZOEwySDdMZks2RU9hUVVjckdkM0ZJSDNlSnhHbEFZWDh5SzduRm9EazR1TzhFMERxNDBjZU1tSFJya3p2bWJoUVJfS2I2cDNkTGxsZTk0QVFjdUE0V2tZd0E2cURNMU9hb3cxcFRRS0tGdm8zYzh6TUprRGt3elJIZ0JsR1Rnb09XVXZlT2pCdzUxQQ?oc=5","published_at":"2026-01-08T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"Critical infrastructure facing cyber surge in OT and supply chains in 2026&nbsp;&nbsp;SC Media","title":"Critical infrastructure facing cyber surge in OT and supply chains in 2026 - SC Media"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-35494a2f979b20f2","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiWEFVX3lxTFBkX1M5NVBSQ0dESHA0T0NRZEFqWnpjc1dhc1k2ZDZLLXRpblhtclFvSXRka0RxRFVlRkNJQ01Kc2lxTTJIR0c2SFVSWGdJeVVuMHBXeC15NWTSAVhBVV95cUxQZF9TOTVQUkNHREhwNE9DUWRBalp6Y3NXYXNZNmQ2Sy10aW5YbXJRb0l0ZGtEcURVZUZDSUNNSnNpcU0ySEdHNkhVUlhnSXlVbjBwV3gteTVk?oc=5","published_at":"2026-01-08T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"Ni8mare Vulnerability Allows Attackers to Hijack n8n Servers, Exploit Publicly Released&nbsp;&nbsp;cyberpress.org","title":"Ni8mare Vulnerability Allows Attackers to Hijack n8n Servers, Exploit Publicly Released - cyberpress.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-2d8105f6977242dc","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxNbm9SY08tc0ZHaWJDYXdleXY5QTMySjZZOEwySDdMZks2RU9hUVVjckdkM0ZJSDNlSnhHbEFZWDh5SzduRm9EazR1TzhFMERxNDBjZU1tSFJya3p2bWJoUVJfS2I2cDNkTGxsZTk0QVFjdUE0V2tZd0E2cURNMU9hb3cxcFRRS0tGdm8zYzh6TUprRGt3elJIZ0JsR1Rnb09XVXZlT2pCdzUxQQ?oc=5","published_at":"2026-01-08T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"Critical infrastructure facing cyber surge in OT and supply chains in 2026&nbsp;&nbsp;scworld.com","title":"Critical infrastructure facing cyber surge in OT and supply chains in 2026 - scworld.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9c7be13c7078c193","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMickFVX3lxTE9UQzJOZTJYckttMTVQNmY5Sy1hLVhPa1BJZmJrUDlHczE4em1GUGpyU01uSFZ1eXF2X19hUjEwX3JvcHh5RkdCMGNoczZlOG4wc1VLNHlvd1JvbEIxeHllR0FVQlR2QTJldXdfNEo4NWlpUQ?oc=5","published_at":"2026-01-06T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"How Threat Intelligence Will Change Cybersecurity in 2026&nbsp;&nbsp;CyberSecurityNews","title":"How Threat Intelligence Will Change Cybersecurity in 2026 - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7296a0d3fb41d240","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMickFVX3lxTE9UQzJOZTJYckttMTVQNmY5Sy1hLVhPa1BJZmJrUDlHczE4em1GUGpyU01uSFZ1eXF2X19hUjEwX3JvcHh5RkdCMGNoczZlOG4wc1VLNHlvd1JvbEIxeHllR0FVQlR2QTJldXdfNEo4NWlpUQ?oc=5","published_at":"2026-01-06T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"How Threat Intelligence Will Change Cybersecurity in 2026&nbsp;&nbsp;cybersecuritynews.com","title":"How Threat Intelligence Will Change Cybersecurity in 2026 - cybersecuritynews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-0d424e32006f43c3","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi8AFBVV95cUxPNnJyckczM3BFVHpTTnBDRnpEOHQwRHd4NXJlR195VjM2aFJ1X0R5VVhpQmZhQ2VzMlJfakU5eTBTOTJ6dGxiVGRiTlBIeGFsbVB4a3hrcUtGUnBnZW4yVUlzMnByRkNlS0JuTzMwUkJwcElmaEdEcnNNWEFBMGVwdUR6SnpiSm0xWEhiLWdBRkdFdFczVW94Vl9DU3FSVmdVbU1ZRTFtWDBwOWkyYWFmdWNENzRUcEJRUXltbkFKdV91UWNpcmFxaVB0RzBTWktqRzFyUjBra0JrVFNCQmFJanVVcmZ3Z05RQk1tVUJzR1I?oc=5","published_at":"2026-01-05T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Ampyx Cyber warns Volt Typhoon poses strategic threat to electric utilities despite quiet activity, calls for action&nbsp;&nbsp;Industrial Cyber","title":"Ampyx Cyber warns Volt Typhoon poses strategic threat to electric utilities despite quiet activity, calls for action - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-3de282be64e90523","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi2AFBVV95cUxQVEZHakE4YnBuS256Z3Y2U1haS3QtYW92MlRKZkE1b3RWN1hkTFlKMEdpekJCNUhYT0lMc18tcHQ5dkNmU1V3NWp2bHVMeFpEX2djeHNVMWlzeUsxYUU2MG9zUzN3cEdyM1FFTTc3cEZpaW9QNGZiSmkzWG1DUzI4Ull1ZEhYTWZuQl9GUlVUQWdGdjJzRHY1LXd4c2RRMTBzeTc3TWJBR2ZxcWZHc2huWHVPVTB5cVF5dk9QNzNHVllobGdfenN3c3kzcHNDX05MWVVzOVBaUnc?oc=5","published_at":"2026-01-05T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Taiwanese infrastructure suffered over 2.5 million Chinese cyberattacks per day in 2025, report reveals&nbsp;&nbsp;techradar.com","title":"Taiwanese infrastructure suffered over 2.5 million Chinese cyberattacks per day in 2025, report reveals - techradar.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-6460fa40fab889fd","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi8AFBVV95cUxPNnJyckczM3BFVHpTTnBDRnpEOHQwRHd4NXJlR195VjM2aFJ1X0R5VVhpQmZhQ2VzMlJfakU5eTBTOTJ6dGxiVGRiTlBIeGFsbVB4a3hrcUtGUnBnZW4yVUlzMnByRkNlS0JuTzMwUkJwcElmaEdEcnNNWEFBMGVwdUR6SnpiSm0xWEhiLWdBRkdFdFczVW94Vl9DU3FSVmdVbU1ZRTFtWDBwOWkyYWFmdWNENzRUcEJRUXltbkFKdV91UWNpcmFxaVB0RzBTWktqRzFyUjBra0JrVFNCQmFJanVVcmZ3Z05RQk1tVUJzR1I?oc=5","published_at":"2026-01-05T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Ampyx Cyber warns Volt Typhoon poses strategic threat to electric utilities despite quiet activity, calls for action&nbsp;&nbsp;industrialcyber.co","title":"Ampyx Cyber warns Volt Typhoon poses strategic threat to electric utilities despite quiet activity, calls for action - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f3e3fe6a420fc3d2","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi2AFBVV95cUxQVEZHakE4YnBuS256Z3Y2U1haS3QtYW92MlRKZkE1b3RWN1hkTFlKMEdpekJCNUhYT0lMc18tcHQ5dkNmU1V3NWp2bHVMeFpEX2djeHNVMWlzeUsxYUU2MG9zUzN3cEdyM1FFTTc3cEZpaW9QNGZiSmkzWG1DUzI4Ull1ZEhYTWZuQl9GUlVUQWdGdjJzRHY1LXd4c2RRMTBzeTc3TWJBR2ZxcWZHc2huWHVPVTB5cVF5dk9QNzNHVllobGdfenN3c3kzcHNDX05MWVVzOVBaUnc?oc=5","published_at":"2026-01-05T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Taiwanese infrastructure suffered over 2.5 million Chinese cyberattacks per day in 2025, report reveals&nbsp;&nbsp;TechRadar","title":"Taiwanese infrastructure suffered over 2.5 million Chinese cyberattacks per day in 2025, report reveals - TechRadar"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-dca5080185ec27eb","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMia0FVX3lxTFBmbldtQlA2M3ItOFhjN2lieVN6U25lRjEwcVlsYy1PV2d4dS1iMWg4QnU0YThlV2FfeG55X01GZHdLc3REeDVlTTlGQjlVYzh0X051OEJIUl9TRWh6OHNaSG5lZFQyNWtJYklJ?oc=5","published_at":"2025-12-30T22:08:22+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Top 10 Cyber Attacks of 2026&nbsp;&nbsp;CyberSecurityNews","title":"Top 10 Cyber Attacks of 2026 - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c7cae544cd439287","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMicEFVX3lxTE9PUktBeWhKeV9aa0hpNkVPdmVoZTZqX1N4aFJtUnoxTEdIU3hJT0xKNlI0N29yYWZjR3I2OUk5eHRqaUV4ME92S2hqSzdXNlFrLXNkT25OcFRwWElCMTRmVS12dWZpR2Q1VkJCQ2stbjk?oc=5","published_at":"2025-12-25T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Threat landscape for industrial automation systems in Q3 2025&nbsp;&nbsp;Securelist","title":"Threat landscape for industrial automation systems in Q3 2025 - Securelist"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2ab84b2abb4bf188","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiYEFVX3lxTFBha21LNXhKNVplaW5DTXExd2g1alZwOXd4VEczQ05qYXYybDk1OUFXUy1yNndJcHJHcEJiSXZLaG85YjRaWE1qRWNKb2hJay1oRHpJaXJyVHRHWE43VW9oRA?oc=5","published_at":"2025-12-25T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Google Now Allows Users to Change Their @gmail.com Email Address&nbsp;&nbsp;CyberSecurityNews","title":"Google Now Allows Users to Change Their @gmail.com Email Address - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-40dbbba81d202e74","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMicEFVX3lxTE9PUktBeWhKeV9aa0hpNkVPdmVoZTZqX1N4aFJtUnoxTEdIU3hJT0xKNlI0N29yYWZjR3I2OUk5eHRqaUV4ME92S2hqSzdXNlFrLXNkT25OcFRwWElCMTRmVS12dWZpR2Q1VkJCQ2stbjk?oc=5","published_at":"2025-12-25T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Threat landscape for industrial automation systems in Q3 2025&nbsp;&nbsp;securelist.com","title":"Threat landscape for industrial automation systems in Q3 2025 - securelist.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-988d128a72f2cbda","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMixgFBVV95cUxQLUk3VC1yRkozUUkwOVdQcHZGb3g3VTJzdjV6enpJaTFMV3pmenE1NjJfRmJiUzdIRjMxWGZma3VEWDBvMEhKN2JudlNrTlp1RE1jcF9BZjgwNGo4LU9veUhSRnlPWGM1eFphUUE2YUZmNkdLUmVjckpWWG9xbWI3bVRZZ05LQWdlSGpTbjA1N1dxdUZJOXpmMlVBZUZub19nazJ3MFBwZjd4U1NQUDJWaDA4QUszWC1QNWlpMFllTWVWYk5UVFE?oc=5","published_at":"2025-12-19T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA flags ICS vulnerabilities in products from Siemens, Schneider Electric, Rockwell, and others&nbsp;&nbsp;industrialcyber.co","title":"CISA flags ICS vulnerabilities in products from Siemens, Schneider Electric, Rockwell, and others - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-9d7d9b1afd8c6750","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMixgFBVV95cUxQLUk3VC1yRkozUUkwOVdQcHZGb3g3VTJzdjV6enpJaTFMV3pmenE1NjJfRmJiUzdIRjMxWGZma3VEWDBvMEhKN2JudlNrTlp1RE1jcF9BZjgwNGo4LU9veUhSRnlPWGM1eFphUUE2YUZmNkdLUmVjckpWWG9xbWI3bVRZZ05LQWdlSGpTbjA1N1dxdUZJOXpmMlVBZUZub19nazJ3MFBwZjd4U1NQUDJWaDA4QUszWC1QNWlpMFllTWVWYk5UVFE?oc=5","published_at":"2025-12-19T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA flags ICS vulnerabilities in products from Siemens, Schneider Electric, Rockwell, and others&nbsp;&nbsp;Industrial Cyber","title":"CISA flags ICS vulnerabilities in products from Siemens, Schneider Electric, Rockwell, and others - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-fde7d781ccf8b70f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMieEFVX3lxTFBIRHlpRGNoREFUWkF3MW1LQk1fcTNSQ2FaUUttNURTeFJxU3pkSURXemVmZHBXdzZpN2Q5OXRXOE5XVmxpWWdERWtSS3g3bTZMTjBPN0ppQUdKZ2FWelpKeG82OVFQNEZvLUVhR0dPU0dLZXp0V2czOQ?oc=5","published_at":"2025-12-16T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Advancing IP Interconnection&nbsp;&nbsp;Foundation for Defense of Democracies","title":"Advancing IP Interconnection - Foundation for Defense of Democracies"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-83b517598a7c79ea","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitAFBVV95cUxPSDJRTkExcHJrRGNnek5pQjdoUEFGejR6YzF3YTBJRDRPS094QWUyTVdUREhsU19JczY1aFBXclVTVnZSdDg3Q0lDN0ZOSzVndl9tMGpTbFMxamJYaUNoS2hSVmhBQVlrcXdxYWx0RnBlbVQ2N0dvOE0zeEo1OFpxQVdZRDVfc2NQTTdjdXhpNVRnRGpoaUZKQ2ljUFRQNVJhN241Y1VuaFdxZkR5RExfQjFDOTQ?oc=5","published_at":"2025-12-16T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"How the New National Security Strategy Misses the Mark on Cybersecurity&nbsp;&nbsp;nationalinterest.org","title":"How the New National Security Strategy Misses the Mark on Cybersecurity - nationalinterest.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a4e8f8769786de31","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitAFBVV95cUxPSDJRTkExcHJrRGNnek5pQjdoUEFGejR6YzF3YTBJRDRPS094QWUyTVdUREhsU19JczY1aFBXclVTVnZSdDg3Q0lDN0ZOSzVndl9tMGpTbFMxamJYaUNoS2hSVmhBQVlrcXdxYWx0RnBlbVQ2N0dvOE0zeEo1OFpxQVdZRDVfc2NQTTdjdXhpNVRnRGpoaUZKQ2ljUFRQNVJhN241Y1VuaFdxZkR5RExfQjFDOTQ?oc=5","published_at":"2025-12-16T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"How the New National Security Strategy Misses the Mark on Cybersecurity&nbsp;&nbsp;The National Interest","title":"How the New National Security Strategy Misses the Mark on Cybersecurity - The National Interest"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-346dff2c3823db13","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMieEFVX3lxTFBIRHlpRGNoREFUWkF3MW1LQk1fcTNSQ2FaUUttNURTeFJxU3pkSURXemVmZHBXdzZpN2Q5OXRXOE5XVmxpWWdERWtSS3g3bTZMTjBPN0ppQUdKZ2FWelpKeG82OVFQNEZvLUVhR0dPU0dLZXp0V2czOQ?oc=5","published_at":"2025-12-16T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Advancing IP Interconnection&nbsp;&nbsp;fdd.org","title":"Advancing IP Interconnection - fdd.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-67aa273ac4ba2e21","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMimgFBVV95cUxQVElLaGxaZVFNa0NzMkJJeGl4Nkd2QV8zYVpfX1YtNzJZb25WX1AwTG9QclJnVXRQT093YU9qc2lRcU1NQXdCeU5faEFxc0RhNm9BOGhoM0RBZzJub3BEMXMwNmJKUHBFUmp3aEgzRXRJYXc0eG0zUzcyM09mQ3BZeURVMjhwRXhOWUJ4VmpJS0prMzJtVUF5RjFB?oc=5","published_at":"2025-12-09T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"SPS 2025: How Siemens, Beckhoff, Rockwell, ABB, and peers are positioning for industrial automation\u2019s future&nbsp;&nbsp;IoT Analytics","title":"SPS 2025: How Siemens, Beckhoff, Rockwell, ABB, and peers are positioning for industrial automation\u2019s future - IoT Analytics"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-21c6ccc126497c4f","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMimgFBVV95cUxQVElLaGxaZVFNa0NzMkJJeGl4Nkd2QV8zYVpfX1YtNzJZb25WX1AwTG9QclJnVXRQT093YU9qc2lRcU1NQXdCeU5faEFxc0RhNm9BOGhoM0RBZzJub3BEMXMwNmJKUHBFUmp3aEgzRXRJYXc0eG0zUzcyM09mQ3BZeURVMjhwRXhOWUJ4VmpJS0prMzJtVUF5RjFB?oc=5","published_at":"2025-12-09T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"SPS 2025: How Siemens, Beckhoff, Rockwell, ABB, and peers are positioning for industrial automation\u2019s future&nbsp;&nbsp;iot-analytics.com","title":"SPS 2025: How Siemens, Beckhoff, Rockwell, ABB, and peers are positioning for industrial automation\u2019s future - iot-analytics.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-fb096a0022c633c2","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi6AFBVV95cUxNeGRFWEVBanJ4S1hvWmNvZWtsQWJFVmVmWWhfV00waE10TlZlZnAyS1haa1JxOXBtQWJjejlUVHlsMFVPUkp2Rm1qY09yaTE3a000Ukp3dEo1aElKSEZ4d1F0c3dwMFA3am1YM0ZFT3JZWUZleFRLUXg3Q2pMRjFERnFkVnFVVjdNWnpMNlNONkVrSFJmQ3VXUDM0RFZiNklNazk3WEJ3SHN4aXFOdFA3U1k0c1Q0VFZ5MTZKRDh3clNGOHE2ZVBPSm1QU1hJbzZYRUdJZ1RWWV94UlNsQkdOTjR4YWs2NlRK?oc=5","published_at":"2025-12-07T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Increasing attacks on field-level ICS devices highlight need for deeper visibility and granular OT security controls&nbsp;&nbsp;Industrial Cyber","title":"Increasing attacks on field-level ICS devices highlight need for deeper visibility and granular OT security controls - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-973c722c03581d30","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi6AFBVV95cUxNeGRFWEVBanJ4S1hvWmNvZWtsQWJFVmVmWWhfV00waE10TlZlZnAyS1haa1JxOXBtQWJjejlUVHlsMFVPUkp2Rm1qY09yaTE3a000Ukp3dEo1aElKSEZ4d1F0c3dwMFA3am1YM0ZFT3JZWUZleFRLUXg3Q2pMRjFERnFkVnFVVjdNWnpMNlNONkVrSFJmQ3VXUDM0RFZiNklNazk3WEJ3SHN4aXFOdFA3U1k0c1Q0VFZ5MTZKRDh3clNGOHE2ZVBPSm1QU1hJbzZYRUdJZ1RWWV94UlNsQkdOTjR4YWs2NlRK?oc=5","published_at":"2025-12-07T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Increasing attacks on field-level ICS devices highlight need for deeper visibility and granular OT security controls&nbsp;&nbsp;industrialcyber.co","title":"Increasing attacks on field-level ICS devices highlight need for deeper visibility and granular OT security controls - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2be5a794554a4809","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimAFBVV95cUxQMnNoR2I5b2FfZWF6MWlWQ0lMMlFFOURfdHV2bGZVQ1Z6ZXE0bUk0UmxQQ3lBd0l3R0M5c3Z5U0R1RERiUTk0R05fM1V0WEY4MFgtb3dWYVIya3NYNGh6YjZsMDhSbVNUQXFET0t1WWVzamZaRVc2aTdueVh1UHVaX2k1a2F4THI0LXppSTFVUjhLZVNtdDBoYQ?oc=5","published_at":"2025-12-05T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Smart Home, Big Risks: Top Cybersecurity Threats Homeowners Need To Know&nbsp;&nbsp;Realtor.com","title":"Smart Home, Big Risks: Top Cybersecurity Threats Homeowners Need To Know - Realtor.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-c5be50b30d5981b1","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxPb2UyR0gtaFgzS1pLS05ydFdnOXdxb3A1QmswQ2dPdVJHZ05fMFZzUmNoSUpreE5QWEJ5Unp1cUoxY3liSkNGenQ1UHdyWnZxbHAwRE9nX1dCTGhvRERveUIzTVNKSlVrLWlhb3lkd0hhazREaXhpSkJfc3hVZWxtMGhFT2JIUGFZNWpQbUxlUVhiOFNZbEJQam15WWduX1k0eHVKZ0xlZFp0NmM?oc=5","published_at":"2025-12-04T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"CISA Warns of OpenPLC ScadaBR File Upload Vulnerability Exploited in Attacks&nbsp;&nbsp;CyberSecurityNews","title":"CISA Warns of OpenPLC ScadaBR File Upload Vulnerability Exploited in Attacks - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4acbbdf70c925562","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiigFBVV95cUxNY25rQS1wYjNWQkgxMGM5TnNaRjVTNk5PeEVzT2w3NV8tcDZCWXk1QmM2eU5PS0I3R0EyUF9RN2M4U2QzSXNMckxLWXhWdk1WWlZhM3hBNmVPNHJmVzV5UzVfYVo5eVpRbzlBTzNtOTRacXBEZHlsWmhLSXRDMFNXcEVPNzJuN0xIZkE?oc=5","published_at":"2025-12-03T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"China seeks long-term vulnerabilities in US energy systems: House panelists&nbsp;&nbsp;Utility Dive","title":"China seeks long-term vulnerabilities in US energy systems: House panelists - Utility Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7011a1c3a6342c27","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi5AFBVV95cUxQUlljcmFtMk1kWFBySjJJb21vMEVNY09oRTVIQ19OTVZiTjRZZlBSbDV6ZUtwQTFoY3BhNHFGbnhBYUU3N29HbzU4XzRaLWtYM1pOV25KT0dyaWo4S3pOWHQ4dXctaklhR3Z5VXpOaUxZWnRGeFNpX2ppeGl1QW5NT0dqU3BHaUd3OEJIX3h4MW1XZUpCUS1YUUdOQ3VQOGtROHQ4QlVYTVFfWnVlVURuSExUUkcxdU4wMmc2T3JXd3hMUFNSNmgwVFRTYkFqTTJWY1BCUjV2bE5kOFcwSmp4Yi11QnE?oc=5","published_at":"2025-12-03T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Critical Infra & APTs","summary":"Subcommittee on Energy Holds Hearing on the Security of our Energy Infrastructure, Including the Electric Grid&nbsp;&nbsp;House Committee on Energy and Commerce (.gov)","title":"Subcommittee on Energy Holds Hearing on the Security of our Energy Infrastructure, Including the Electric Grid - House Committee on Energy and Commerce (.gov)"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e856758907046958","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi5AFBVV95cUxQUlljcmFtMk1kWFBySjJJb21vMEVNY09oRTVIQ19OTVZiTjRZZlBSbDV6ZUtwQTFoY3BhNHFGbnhBYUU3N29HbzU4XzRaLWtYM1pOV25KT0dyaWo4S3pOWHQ4dXctaklhR3Z5VXpOaUxZWnRGeFNpX2ppeGl1QW5NT0dqU3BHaUd3OEJIX3h4MW1XZUpCUS1YUUdOQ3VQOGtROHQ4QlVYTVFfWnVlVURuSExUUkcxdU4wMmc2T3JXd3hMUFNSNmgwVFRTYkFqTTJWY1BCUjV2bE5kOFcwSmp4Yi11QnE?oc=5","published_at":"2025-12-03T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Critical Infra & APTs","summary":"Subcommittee on Energy Holds Hearing on the Security of our Energy Infrastructure, Including the Electric Grid&nbsp;&nbsp;energycommerce.house.gov","title":"Subcommittee on Energy Holds Hearing on the Security of our Energy Infrastructure, Including the Electric Grid - energycommerce.house.gov"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-43f0e7773e618b9a","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiigFBVV95cUxNY25rQS1wYjNWQkgxMGM5TnNaRjVTNk5PeEVzT2w3NV8tcDZCWXk1QmM2eU5PS0I3R0EyUF9RN2M4U2QzSXNMckxLWXhWdk1WWlZhM3hBNmVPNHJmVzV5UzVfYVo5eVpRbzlBTzNtOTRacXBEZHlsWmhLSXRDMFNXcEVPNzJuN0xIZkE?oc=5","published_at":"2025-12-03T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"China seeks long-term vulnerabilities in US energy systems: House panelists&nbsp;&nbsp;utilitydive.com","title":"China seeks long-term vulnerabilities in US energy systems: House panelists - utilitydive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e944d4f78c77df86","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipwFBVV95cUxPdnl4SmZLbVBxU3lpTTc2bzRiTC0tb0NvSjJWY1JSWHVPZVExMktsb1dkMld5Tm1fdTNoRXZBMHl3Qld0LWdseGpSVGE0eFViMFJnUU9qNDRRdV9jZHZBSF9vbEUwYXJCRzdhYnZ0RHVCZEd6S21qMjhackV1UkhLNjFNbUwyVGU2RHhoTlJRaldGWnl5ckIyc3ZWUzQ4VkhPeWE5b3RIRQ?oc=5","published_at":"2025-11-26T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Have you thought about how AI will change cybersecurity? You should.&nbsp;&nbsp;AJC.com","title":"Have you thought about how AI will change cybersecurity? You should. - AJC.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-22b5802ebebc2f19","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipwFBVV95cUxPdnl4SmZLbVBxU3lpTTc2bzRiTC0tb0NvSjJWY1JSWHVPZVExMktsb1dkMld5Tm1fdTNoRXZBMHl3Qld0LWdseGpSVGE0eFViMFJnUU9qNDRRdV9jZHZBSF9vbEUwYXJCRzdhYnZ0RHVCZEd6S21qMjhackV1UkhLNjFNbUwyVGU2RHhoTlJRaldGWnl5ckIyc3ZWUzQ4VkhPeWE5b3RIRQ?oc=5","published_at":"2025-11-26T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Have you thought about how AI will change cybersecurity? You should.&nbsp;&nbsp;ajc.com","title":"Have you thought about how AI will change cybersecurity? You should. - ajc.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7fe7e54f53ae92f8","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxPN01aOUV0RjQ0dXpDUFJNenVhR05BYnlDcHAzaW9pSl9pS2x5SjdQYnRJdXEwV3NxTjZfZlRkeUVEV3pPVUJZRzdNTVdwQzNXc1hraXRkM3B1V0pLUTU5TVE1SjUwdGpJbUtlYmNGdVZtckhxYk0yZm9KbFRQUVdTYXhheWYyODFBdzI3TjZpX1JnNVY5VXFjU1ZrOWN3UzBFT1pnVEx0Rzc?oc=5","published_at":"2025-11-25T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Chinese Electric Buses Trigger Cybersecurity Alarm Across Europe&nbsp;&nbsp;fdd.org","title":"Chinese Electric Buses Trigger Cybersecurity Alarm Across Europe - fdd.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-733903c8569deab2","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxPN01aOUV0RjQ0dXpDUFJNenVhR05BYnlDcHAzaW9pSl9pS2x5SjdQYnRJdXEwV3NxTjZfZlRkeUVEV3pPVUJZRzdNTVdwQzNXc1hraXRkM3B1V0pLUTU5TVE1SjUwdGpJbUtlYmNGdVZtckhxYk0yZm9KbFRQUVdTYXhheWYyODFBdzI3TjZpX1JnNVY5VXFjU1ZrOWN3UzBFT1pnVEx0Rzc?oc=5","published_at":"2025-11-25T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Chinese Electric Buses Trigger Cybersecurity Alarm Across Europe&nbsp;&nbsp;Foundation for Defense of Democracies","title":"Chinese Electric Buses Trigger Cybersecurity Alarm Across Europe - Foundation for Defense of Democracies"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-933a1fa53ef3c9d2","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMitAFBVV95cUxNdVA5ZmtuMUZTMThOdU50dmlyVEE5enY0Rkt4cHVEVXVDLUVKMWgycXdmWjN5d09FVjJ4UnFSZ2xwbkRWVWVyaWYxSmp1UXBqM3dCcFFvTTI1dGFRNVdvRTIwRnl1T2ZrVklvNmFpOEQ4Z196Umd2MWV5YzdYNHptSVJVRXN0OTZ6eUVWN0plNW10ZVhEVDVmQ1FGTzRCbmc1OE93NFUwYWZkT0ltS094NmZXdWI?oc=5","published_at":"2025-11-21T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"How Wipro PARI accelerates PLC code generation using Amazon Bedrock&nbsp;&nbsp;aws.amazon.com","title":"How Wipro PARI accelerates PLC code generation using Amazon Bedrock - aws.amazon.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-fc90d0a2142e54b8","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMitAFBVV95cUxNdVA5ZmtuMUZTMThOdU50dmlyVEE5enY0Rkt4cHVEVXVDLUVKMWgycXdmWjN5d09FVjJ4UnFSZ2xwbkRWVWVyaWYxSmp1UXBqM3dCcFFvTTI1dGFRNVdvRTIwRnl1T2ZrVklvNmFpOEQ4Z196Umd2MWV5YzdYNHptSVJVRXN0OTZ6eUVWN0plNW10ZVhEVDVmQ1FGTzRCbmc1OE93NFUwYWZkT0ltS094NmZXdWI?oc=5","published_at":"2025-11-21T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"How Wipro PARI accelerates PLC code generation using Amazon Bedrock&nbsp;&nbsp;Amazon Web Services (AWS)","title":"How Wipro PARI accelerates PLC code generation using Amazon Bedrock - Amazon Web Services (AWS)"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-4e37312be2d66836","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiigFBVV95cUxQU2QxUEJiMFJuX3hOa3FhQzRuUllON09ZbjdBVzRPOC14ZnBJMlBRbW1jY1ZaYnZZcHgxdERoWm1XRDMtSU05Y3hsaUdEYmlySzdSQVpOTnp2Zmt6aWcyNHFYQmh2RDBBZ0lvbzA0S2ZDbzVuRWFrTWhBdzdnSkZYYllpc2Y1aWFvdWc?oc=5","published_at":"2025-11-20T08:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Securing Europe\u2019s Critical Infrastructure by Tackling Technical Debt&nbsp;&nbsp;Cisco Blogs","title":"Securing Europe\u2019s Critical Infrastructure by Tackling Technical Debt - Cisco Blogs"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-fc026b88ada774cf","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijgFBVV95cUxNZHlsWXFLVFVzOF9Fakh0Ym03bGJJUDhPOV9tLVZMVjJ6eDY3WnkzczdiWTJ3X3ZOWERYcmxZT2FYb1M2TGRkYU1ReEhremlYTHA5dmh4cks2S1BrelFMZk4yeWhiNTZtN1dZamN1VF9wUUs3M2s3cXNpQW1RS01YclBSZmNTREU4R2Z4aW13?oc=5","published_at":"2025-11-20T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"CISA to prioritize new hires in 2026: report&nbsp;&nbsp;IT Brew","title":"CISA to prioritize new hires in 2026: report - IT Brew"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a641001554676f50","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijgFBVV95cUxNZHlsWXFLVFVzOF9Fakh0Ym03bGJJUDhPOV9tLVZMVjJ6eDY3WnkzczdiWTJ3X3ZOWERYcmxZT2FYb1M2TGRkYU1ReEhremlYTHA5dmh4cks2S1BrelFMZk4yeWhiNTZtN1dZamN1VF9wUUs3M2s3cXNpQW1RS01YclBSZmNTREU4R2Z4aW13?oc=5","published_at":"2025-11-20T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"CISA to prioritize new hires in 2026: report&nbsp;&nbsp;itbrew.com","title":"CISA to prioritize new hires in 2026: report - itbrew.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-68ab931e26fcb4f9","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiigFBVV95cUxQU2QxUEJiMFJuX3hOa3FhQzRuUllON09ZbjdBVzRPOC14ZnBJMlBRbW1jY1ZaYnZZcHgxdERoWm1XRDMtSU05Y3hsaUdEYmlySzdSQVpOTnp2Zmt6aWcyNHFYQmh2RDBBZ0lvbzA0S2ZDbzVuRWFrTWhBdzdnSkZYYllpc2Y1aWFvdWc?oc=5","published_at":"2025-11-20T08:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Securing Europe\u2019s Critical Infrastructure by Tackling Technical Debt&nbsp;&nbsp;blogs.cisco.com","title":"Securing Europe\u2019s Critical Infrastructure by Tackling Technical Debt - blogs.cisco.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-d285c525a8d65bc4","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMid0FVX3lxTE5PX1Y0QzhXVHQ3VVY2aV9yUktaT2JqeGVXZkk2QmIwVHk4R3daRFE2R0ZzdlUySTFBTU5lZ1JTeHI1Yk5FUzVBeFJ5bV9YM3dieGFSZ2JLbmFKU2dEcnVJTG4tY1A4MHg0MDNjcVJBMFlfTjZ3bEg4?oc=5","published_at":"2025-11-18T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"PLC Market Growth Fueled by Industrial IoT&nbsp;&nbsp;arcweb.com","title":"PLC Market Growth Fueled by Industrial IoT - arcweb.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-e38413a7abf40bf6","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMid0FVX3lxTE5PX1Y0QzhXVHQ3VVY2aV9yUktaT2JqeGVXZkk2QmIwVHk4R3daRFE2R0ZzdlUySTFBTU5lZ1JTeHI1Yk5FUzVBeFJ5bV9YM3dieGFSZ2JLbmFKU2dEcnVJTG4tY1A4MHg0MDNjcVJBMFlfTjZ3bEg4?oc=5","published_at":"2025-11-18T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"PLC Market Growth Fueled by Industrial IoT&nbsp;&nbsp;ARC Advisory","title":"PLC Market Growth Fueled by Industrial IoT - ARC Advisory"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-53681bf9540ef003","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMid0FVX3lxTE5PX1Y0QzhXVHQ3VVY2aV9yUktaT2JqeGVXZkk2QmIwVHk4R3daRFE2R0ZzdlUySTFBTU5lZ1JTeHI1Yk5FUzVBeFJ5bV9YM3dieGFSZ2JLbmFKU2dEcnVJTG4tY1A4MHg0MDNjcVJBMFlfTjZ3bEg4?oc=5","published_at":"2025-11-18T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"PLC Market Growth Fueled by Industrial IoT&nbsp;&nbsp;ARC Advisory Group","title":"PLC Market Growth Fueled by Industrial IoT - ARC Advisory Group"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-fc5f9cead32fd7f3","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMifkFVX3lxTE1ROXh3YU1zWGctajFLVU5VRUtHVGNPN1VvNmNYMWpEaGRGUjVKWnJPTjBZVXdJbXlZZjI1TUpnNGF2djlzSUx6dEVBcFNyanR5ei1QMl91bG1MajctWjYwd0t5dndIMnY5WE8xQVQyLXp4UEZna2pKWG1iZWxydw?oc=5","published_at":"2025-11-17T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Nebraska AG\u2019s Lawsuit Against Change Healthcare Survives Motion to Dismiss&nbsp;&nbsp;The HIPAA Journal","title":"Nebraska AG\u2019s Lawsuit Against Change Healthcare Survives Motion to Dismiss - The HIPAA Journal"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b106843199e1107d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMifkFVX3lxTE1ROXh3YU1zWGctajFLVU5VRUtHVGNPN1VvNmNYMWpEaGRGUjVKWnJPTjBZVXdJbXlZZjI1TUpnNGF2djlzSUx6dEVBcFNyanR5ei1QMl91bG1MajctWjYwd0t5dndIMnY5WE8xQVQyLXp4UEZna2pKWG1iZWxydw?oc=5","published_at":"2025-11-17T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Nebraska AG\u2019s Lawsuit Against Change Healthcare Survives Motion to Dismiss&nbsp;&nbsp;hipaajournal.com","title":"Nebraska AG\u2019s Lawsuit Against Change Healthcare Survives Motion to Dismiss - hipaajournal.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-f5fe0382b65ad9f2","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxNYWhyUms3U0J6eHBXclBtbHdiMjBTcHNCOEdWZG4wUExjVXhSTElVeHR3UWhuSl9ybTdPdGNuOHRFMF83MG9DS3E2M3NvOXRiY3QyVUl3bzRrWXNzMkUyNGlCLUQ4TDZ0dkxWVWYyeWZYNVp2YWRYQkg0V2dTczJjdmozUGZCWFVIZ256bzVYdGVWN2dWUnQyTEFONlZKcm0wbGtDY0xpQzNpcnN0WmfSAbMBQVVfeXFMTlRROFBody1HeHZSaWF4RGdOMFM5dVRNd0xKanZ1WHVXZUY2NVdleDJvV2o5aGdldnZveWo4RXNNMW5GamJCeGZ5UF9Pd3hoeFZqYXh1RnN2OEtQQWZ4RC1sZVF5WUphcEZjTjhMT2R6TlNGMmRqbFBxU1ExVDNDeF9ZbFpsRk1KNjJBcHFXNHY3Y0IzM1cwQ0VvVVhRckhmSW5nYlA0RnllZGVNM2VYM2x5amM?oc=5","published_at":"2025-11-12T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Rockwell, Aveva, Schneider&nbsp;&nbsp;securityweek.com","title":"ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Rockwell, Aveva, Schneider - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b8dca2dc80b41b9a","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiwwFBVV95cUxPRER0RlNDeDREM0o5QXBBUWQ2MlkwR1lSNF9QMDhtaFp0RDRhOGhvS0dxZklHN1dDTk9pWFJxRC1ZZkJsTWtxOEVuZXV0R2dXSzdxR2lZSy1fVEF3bkVTOGNtY0NjRUZ5OGRtY2NrdDlXZkxUOHphNmNLM1lTSWNsTEJMWXJIa1JILUhKcWMtUjVsdEdaMjBaR05WQ0NJbVZIYWRkSmEwcFF0bzJHY3JaZUMyMmZxaUZPZXQtc3I3QWZiRHM?oc=5","published_at":"2025-11-12T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"The Change Healthcare cybersecurity breach: Impact on healthcare providers&nbsp;&nbsp;nixonpeabody.com","title":"The Change Healthcare cybersecurity breach: Impact on healthcare providers - nixonpeabody.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-aa6fb3af1fe17dcd","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiwwFBVV95cUxPRER0RlNDeDREM0o5QXBBUWQ2MlkwR1lSNF9QMDhtaFp0RDRhOGhvS0dxZklHN1dDTk9pWFJxRC1ZZkJsTWtxOEVuZXV0R2dXSzdxR2lZSy1fVEF3bkVTOGNtY0NjRUZ5OGRtY2NrdDlXZkxUOHphNmNLM1lTSWNsTEJMWXJIa1JILUhKcWMtUjVsdEdaMjBaR05WQ0NJbVZIYWRkSmEwcFF0bzJHY3JaZUMyMmZxaUZPZXQtc3I3QWZiRHM?oc=5","published_at":"2025-11-12T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"The Change Healthcare cybersecurity breach: Impact on healthcare providers&nbsp;&nbsp;Nixon Peabody","title":"The Change Healthcare cybersecurity breach: Impact on healthcare providers - Nixon Peabody"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-c03bb56d37a74c4a","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxNYWhyUms3U0J6eHBXclBtbHdiMjBTcHNCOEdWZG4wUExjVXhSTElVeHR3UWhuSl9ybTdPdGNuOHRFMF83MG9DS3E2M3NvOXRiY3QyVUl3bzRrWXNzMkUyNGlCLUQ4TDZ0dkxWVWYyeWZYNVp2YWRYQkg0V2dTczJjdmozUGZCWFVIZ256bzVYdGVWN2dWUnQyTEFONlZKcm0wbGtDY0xpQzNpcnN0WmfSAbMBQVVfeXFMTlRROFBody1HeHZSaWF4RGdOMFM5dVRNd0xKanZ1WHVXZUY2NVdleDJvV2o5aGdldnZveWo4RXNNMW5GamJCeGZ5UF9Pd3hoeFZqYXh1RnN2OEtQQWZ4RC1sZVF5WUphcEZjTjhMT2R6TlNGMmRqbFBxU1ExVDNDeF9ZbFpsRk1KNjJBcHFXNHY3Y0IzM1cwQ0VvVVhRckhmSW5nYlA0RnllZGVNM2VYM2x5amM?oc=5","published_at":"2025-11-12T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Rockwell, Aveva, Schneider&nbsp;&nbsp;SecurityWeek","title":"ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Rockwell, Aveva, Schneider - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-867b7653ca569f74","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi3AFBVV95cUxPNjR2aUZiVUpUUmtYcDY4WGJEUXA2cnFWN2VwTDlCaGIwQVNfWlo1VXhjOThDVVdwdkU5d3liaThqUWZsenZYeVRXdjVfNDdiT0xpMl9CbTlVek1HSnFYV3ZQLUpnRjVkbS12bEdsSmlhdHZ6NEh2TmIwZThaSEZ0bUZaTTRGTGEyS29jTmdnMXhSTDFNcV9MNVF0SDhrNlFVc3hWdkFaRWVlM2tZTnZxbGdQNkd3MmJhbkxhaHJVU0M4QUt2UlVEa1djbVd0Z2hFdTVSRWpkUlpaME9I?oc=5","published_at":"2025-11-11T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"ISA position paper explores industrial AI in automation, covering opportunities, risks, cybersecurity considerations&nbsp;&nbsp;industrialcyber.co","title":"ISA position paper explores industrial AI in automation, covering opportunities, risks, cybersecurity considerations - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5cb23f2481077bb6","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi3AFBVV95cUxPNjR2aUZiVUpUUmtYcDY4WGJEUXA2cnFWN2VwTDlCaGIwQVNfWlo1VXhjOThDVVdwdkU5d3liaThqUWZsenZYeVRXdjVfNDdiT0xpMl9CbTlVek1HSnFYV3ZQLUpnRjVkbS12bEdsSmlhdHZ6NEh2TmIwZThaSEZ0bUZaTTRGTGEyS29jTmdnMXhSTDFNcV9MNVF0SDhrNlFVc3hWdkFaRWVlM2tZTnZxbGdQNkd3MmJhbkxhaHJVU0M4QUt2UlVEa1djbVd0Z2hFdTVSRWpkUlpaME9I?oc=5","published_at":"2025-11-11T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"ISA position paper explores industrial AI in automation, covering opportunities, risks, cybersecurity considerations&nbsp;&nbsp;Industrial Cyber","title":"ISA position paper explores industrial AI in automation, covering opportunities, risks, cybersecurity considerations - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-aa3592f77e2aa8e4","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi5AFBVV95cUxPVDdDbk5TV0ZMRzE2QmVWOENfOXpybmNLWEJ2YjNXUklMTTBFZzRncTZkZTBBSTF5Nm5lNGtuLXRlRjd4ZTZoQlFFZldTX0pWTjN5czJKeUZpb2tYYU1GN2VVMm1jTlhwajh6X3NwV3R2cnRJY2psS1lxU2d1ODZCZkJLWXJvd1VOdk80RHI3MkNicURDUng2N243Q3E3dnpXOUM0Q3NqR1B6Y1cwMjlBWDdTVUFxemw2S1RJOTNIT1h3YlRrUWUxRkNNUDA0VHNrQW52UGlGZUY2b2lWUjJKRWNtQkQ?oc=5","published_at":"2025-11-11T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Zscaler warns industrial operations face mounting risk as IoT, OT attacks surge across energy, manufacturing sectors&nbsp;&nbsp;industrialcyber.co","title":"Zscaler warns industrial operations face mounting risk as IoT, OT attacks surge across energy, manufacturing sectors - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-74e617da6e077ace","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi5AFBVV95cUxPVDdDbk5TV0ZMRzE2QmVWOENfOXpybmNLWEJ2YjNXUklMTTBFZzRncTZkZTBBSTF5Nm5lNGtuLXRlRjd4ZTZoQlFFZldTX0pWTjN5czJKeUZpb2tYYU1GN2VVMm1jTlhwajh6X3NwV3R2cnRJY2psS1lxU2d1ODZCZkJLWXJvd1VOdk80RHI3MkNicURDUng2N243Q3E3dnpXOUM0Q3NqR1B6Y1cwMjlBWDdTVUFxemw2S1RJOTNIT1h3YlRrUWUxRkNNUDA0VHNrQW52UGlGZUY2b2lWUjJKRWNtQkQ?oc=5","published_at":"2025-11-11T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Zscaler warns industrial operations face mounting risk as IoT, OT attacks surge across energy, manufacturing sectors&nbsp;&nbsp;Industrial Cyber","title":"Zscaler warns industrial operations face mounting risk as IoT, OT attacks surge across energy, manufacturing sectors - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4577dc449ba45509","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxPcEE2T2JMT1hiRlY4UzdlTDI5UW9YOEk3QlQ0b0xSNVFqbnVMeldLNmFUWHNqSFRWRWFkUGhGNDhJdnR3TkhZMlZleXVvU2IxVGVpdFJMUU5PTUNLSWw2bDEtYjZYblN6cTIteGxtc2tYUTRhSzhPZDhCWkhkMGpCWUcySTBPOGN6ZklnNXE2WlVFVmQ5X1Fnb3dHRHRqTmc?oc=5","published_at":"2025-11-07T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Top 10 Companies in Industrial Automation Industry Driving Smart Manufacturing in 2025&nbsp;&nbsp;LinkedIn","title":"Top 10 Companies in Industrial Automation Industry Driving Smart Manufacturing in 2025 - LinkedIn"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-717370a022fdfd32","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxPcEE2T2JMT1hiRlY4UzdlTDI5UW9YOEk3QlQ0b0xSNVFqbnVMeldLNmFUWHNqSFRWRWFkUGhGNDhJdnR3TkhZMlZleXVvU2IxVGVpdFJMUU5PTUNLSWw2bDEtYjZYblN6cTIteGxtc2tYUTRhSzhPZDhCWkhkMGpCWUcySTBPOGN6ZklnNXE2WlVFVmQ5X1Fnb3dHRHRqTmc?oc=5","published_at":"2025-11-07T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Top 10 Companies in Industrial Automation Industry Driving Smart Manufacturing in 2025&nbsp;&nbsp;linkedin.com","title":"Top 10 Companies in Industrial Automation Industry Driving Smart Manufacturing in 2025 - linkedin.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-5c03ffe82e067cda","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxOM0s3SmpRbU5sYXI0U19VMlgzUktqUXA2dGppTk9xQlhSbG5FUWxrY29YLW9xUmpWUi1DVDZrUzB0MFc3T3lxQ2FJYVBWRlhQSm5XS0VEaXBXZF83Z2lJT0JlZUJEejFKekJJZE91bmdUQS1XaFl0ODVlLUxXWGloUS1YZDlGU0JFbVprT3hlUTN6YmtTTzhPMVFQQWZiS3ZzR3hncWdVeHRrWElCS0s3ag?oc=5","published_at":"2025-11-06T23:20:52+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Leading Industrial Ethernet Switch Providers Converge Networking and Cybersecurity&nbsp;&nbsp;ARC Advisory","title":"Leading Industrial Ethernet Switch Providers Converge Networking and Cybersecurity - ARC Advisory"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-739e9d96cd5ac2a4","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxOM0s3SmpRbU5sYXI0U19VMlgzUktqUXA2dGppTk9xQlhSbG5FUWxrY29YLW9xUmpWUi1DVDZrUzB0MFc3T3lxQ2FJYVBWRlhQSm5XS0VEaXBXZF83Z2lJT0JlZUJEejFKekJJZE91bmdUQS1XaFl0ODVlLUxXWGloUS1YZDlGU0JFbVprT3hlUTN6YmtTTzhPMVFQQWZiS3ZzR3hncWdVeHRrWElCS0s3ag?oc=5","published_at":"2025-11-06T23:20:52+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"Leading Industrial Ethernet Switch Providers Converge Networking and Cybersecurity&nbsp;&nbsp;arcweb.com","title":"Leading Industrial Ethernet Switch Providers Converge Networking and Cybersecurity - arcweb.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-ac19539d2fe2939a","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxOM0s3SmpRbU5sYXI0U19VMlgzUktqUXA2dGppTk9xQlhSbG5FUWxrY29YLW9xUmpWUi1DVDZrUzB0MFc3T3lxQ2FJYVBWRlhQSm5XS0VEaXBXZF83Z2lJT0JlZUJEejFKekJJZE91bmdUQS1XaFl0ODVlLUxXWGloUS1YZDlGU0JFbVprT3hlUTN6YmtTTzhPMVFQQWZiS3ZzR3hncWdVeHRrWElCS0s3ag?oc=5","published_at":"2025-11-06T23:20:52+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Leading Industrial Ethernet Switch Providers Converge Networking and Cybersecurity&nbsp;&nbsp;ARC Advisory Group","title":"Leading Industrial Ethernet Switch Providers Converge Networking and Cybersecurity - ARC Advisory Group"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-46a8827172292166","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxPM1ZGMmRaeGtRUnpRbUZ0NXo5N0x6am1jUHJxTnVzemxQek9NUk1RYlBoRkdGd3FhM01ubnpRTl9kOTlZNHpFeE81aFdCVjBpeGQzZ2tDQmFramJWT0dnMDVGOXBlaDlKSXV5TTZzck8zTVptNFc2R1lYd2FwR3Y2R3NJclZXQ0V3N0hfTGJOSUprUFhZZ0hoZXY2STlxZWl5Q1Jocg?oc=5","published_at":"2025-11-06T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Industrial Switch Security","summary":"Who\u2019s Really Most Vulnerable to Climate Change? SIDS, LDCs, and Adaptation Finance&nbsp;&nbsp;cgdev.org","title":"Who\u2019s Really Most Vulnerable to Climate Change? SIDS, LDCs, and Adaptation Finance - cgdev.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-4f045278c25598b5","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMibEFVX3lxTFB1Z185c0JVQklaLTlUakpabEt6dXJCdFJQcHQ0RGxzU1pfSGVGblZUWkVzVTJRQUl4UjBybEZER0xvd0tqTXhBRTJBaDU2T2ZlX0ttQmwyX2hBaWFWaEJjTTdFQkZqU3pZX1VIMw?oc=5","published_at":"2025-11-05T08:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Death by a Thousand Prompts: Open Model Vulnerability Analysis&nbsp;&nbsp;Cisco Blogs","title":"Death by a Thousand Prompts: Open Model Vulnerability Analysis - Cisco Blogs"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-2fd29f8149e339d0","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMibEFVX3lxTFB1Z185c0JVQklaLTlUakpabEt6dXJCdFJQcHQ0RGxzU1pfSGVGblZUWkVzVTJRQUl4UjBybEZER0xvd0tqTXhBRTJBaDU2T2ZlX0ttQmwyX2hBaWFWaEJjTTdFQkZqU3pZX1VIMw?oc=5","published_at":"2025-11-05T08:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Death by a Thousand Prompts: Open Model Vulnerability Analysis&nbsp;&nbsp;blogs.cisco.com","title":"Death by a Thousand Prompts: Open Model Vulnerability Analysis - blogs.cisco.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-69d9b9a364daf228","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiiwFBVV95cUxPRmc3M21hY2JyWDlUYzA3NGZ5dEtQdUdVUHdOOTlWY1BFS1p6U0thNTBkX3RIbmhlSTNkc196MDJUN0poMFVxVW1ERERWTWlaSWtfZ0RVMW1fcWFWMmM4NjdRdGlJQWNBczZpLU1DYXFJY0R5TVlRNTFaZHE4MmI1TzlydmtRMnlwYTFN?oc=5","published_at":"2025-11-03T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Hackers are attacking Britain\u2019s drinking water suppliers&nbsp;&nbsp;therecord.media","title":"Hackers are attacking Britain\u2019s drinking water suppliers - therecord.media"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-59acf66fc41be040","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiiwFBVV95cUxPRmc3M21hY2JyWDlUYzA3NGZ5dEtQdUdVUHdOOTlWY1BFS1p6U0thNTBkX3RIbmhlSTNkc196MDJUN0poMFVxVW1ERERWTWlaSWtfZ0RVMW1fcWFWMmM4NjdRdGlJQWNBczZpLU1DYXFJY0R5TVlRNTFaZHE4MmI1TzlydmtRMnlwYTFN?oc=5","published_at":"2025-11-03T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Hackers are attacking Britain\u2019s drinking water suppliers&nbsp;&nbsp;The Record from Recorded Future News","title":"Hackers are attacking Britain\u2019s drinking water suppliers - The Record from Recorded Future News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ec42d26ecfa451f2","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxNOHp2S1o0RENLMG9MUWJSRG9hcDhaY1FhcDZfMXQ4TGppSUx2UHZZdFE2dTNieGZweERfLV9RYW4yRVRPSmpFT0VNV0dKdWJRT2IwSDRtaXN3QTZsVDRaMGxET0pCa0VvTm1xOWQ3TEZRQTVPQUlhUGE2YWt3Z2lKcEphdW5BTlBiMnJNSmJHaDllZzNYYmdRZmctR1B4enNNYW0tQlNPQzE0MVltUkRmeA?oc=5","published_at":"2025-10-31T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Government and industry must work together to secure America\u2019s cyber future&nbsp;&nbsp;cyberscoop.com","title":"Government and industry must work together to secure America\u2019s cyber future - cyberscoop.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ef4a9aaa918bde73","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxNOHp2S1o0RENLMG9MUWJSRG9hcDhaY1FhcDZfMXQ4TGppSUx2UHZZdFE2dTNieGZweERfLV9RYW4yRVRPSmpFT0VNV0dKdWJRT2IwSDRtaXN3QTZsVDRaMGxET0pCa0VvTm1xOWQ3TEZRQTVPQUlhUGE2YWt3Z2lKcEphdW5BTlBiMnJNSmJHaDllZzNYYmdRZmctR1B4enNNYW0tQlNPQzE0MVltUkRmeA?oc=5","published_at":"2025-10-31T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Government and industry must work together to secure America\u2019s cyber future&nbsp;&nbsp;CyberScoop","title":"Government and industry must work together to secure America\u2019s cyber future - CyberScoop"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-a2a9a69b21e2a8e4","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi4wFBVV95cUxOM1IxMG55OF9rV3UyYTk3MGZLZTRkXzE4X1dWZW1fSmR3Y1dLSURmOW1EM3FxcnlWZ25XZ2R2b2ZXeXpOcFY4NkQ3RGhqWlBoSm9tY0t1NlBpaE54MGZHR3pKX1p2dTd4TEk5Yk51MVJub0FRbmxFVFFUUE84VDRXVnc5Vm56UnZxLW1hVXBHX0lzSXFkM29sLXhyY2NkLUphbmVYdTd5Sk5IOUpoam9XWU41R2ZBRDh0WG00aE03Q2trX1FGVElSVlhZNlE5S0lNclgtMy0tRzBkbFBlVEJMWDBiTQ?oc=5","published_at":"2025-10-30T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"McCrary report flags China\u2019s escalating cyber tactics, warns of Typhoon cyber threats to US critical infrastructure&nbsp;&nbsp;industrialcyber.co","title":"McCrary report flags China\u2019s escalating cyber tactics, warns of Typhoon cyber threats to US critical infrastructure - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-c0694f160bfe2e56","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi4wFBVV95cUxOM1IxMG55OF9rV3UyYTk3MGZLZTRkXzE4X1dWZW1fSmR3Y1dLSURmOW1EM3FxcnlWZ25XZ2R2b2ZXeXpOcFY4NkQ3RGhqWlBoSm9tY0t1NlBpaE54MGZHR3pKX1p2dTd4TEk5Yk51MVJub0FRbmxFVFFUUE84VDRXVnc5Vm56UnZxLW1hVXBHX0lzSXFkM29sLXhyY2NkLUphbmVYdTd5Sk5IOUpoam9XWU41R2ZBRDh0WG00aE03Q2trX1FGVElSVlhZNlE5S0lNclgtMy0tRzBkbFBlVEJMWDBiTQ?oc=5","published_at":"2025-10-30T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"McCrary report flags China\u2019s escalating cyber tactics, warns of Typhoon cyber threats to US critical infrastructure&nbsp;&nbsp;Industrial Cyber","title":"McCrary report flags China\u2019s escalating cyber tactics, warns of Typhoon cyber threats to US critical infrastructure - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a79811588fd1fe23","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMixwFBVV95cUxOU2prVHBLdmNEUmpfd1laMTE2WUpIVGtDN1VxeWdEU3pZX2t4YnVBbXZPNHpKanhTV2QteFdGa3BMRFB2TEgySXBOeTd2aWJRLWkyTlpOZlNvWDhQV2hIX0JwWThlTmlBS0hkYUMzUmYyd082NE5fV1EtQUs1ZWlGREVVLVlFcFlnUGVGWVh5cWxSRnMzRG9kQ1ROSWRSQmxaazlMc1ByQWZteDA4SldHN1FfN2lIOC0tSVR0eXNjSE4xZGhnbVY0?oc=5","published_at":"2025-10-29T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"McCrary Institute releases paper to help Americans understand the cyber threat coming from China&nbsp;&nbsp;eng.auburn.edu","title":"McCrary Institute releases paper to help Americans understand the cyber threat coming from China - eng.auburn.edu"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4f9dfd94f0da98c3","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMixwFBVV95cUxOU2prVHBLdmNEUmpfd1laMTE2WUpIVGtDN1VxeWdEU3pZX2t4YnVBbXZPNHpKanhTV2QteFdGa3BMRFB2TEgySXBOeTd2aWJRLWkyTlpOZlNvWDhQV2hIX0JwWThlTmlBS0hkYUMzUmYyd082NE5fV1EtQUs1ZWlGREVVLVlFcFlnUGVGWVh5cWxSRnMzRG9kQ1ROSWRSQmxaazlMc1ByQWZteDA4SldHN1FfN2lIOC0tSVR0eXNjSE4xZGhnbVY0?oc=5","published_at":"2025-10-29T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"McCrary Institute releases paper to help Americans understand the cyber threat coming from China&nbsp;&nbsp;Auburn University Samuel Ginn College of Engineering","title":"McCrary Institute releases paper to help Americans understand the cyber threat coming from China - Auburn University Samuel Ginn College of Engineering"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d6b89c679ec1c815","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMixwFBVV95cUxOU2prVHBLdmNEUmpfd1laMTE2WUpIVGtDN1VxeWdEU3pZX2t4YnVBbXZPNHpKanhTV2QteFdGa3BMRFB2TEgySXBOeTd2aWJRLWkyTlpOZlNvWDhQV2hIX0JwWThlTmlBS0hkYUMzUmYyd082NE5fV1EtQUs1ZWlGREVVLVlFcFlnUGVGWVh5cWxSRnMzRG9kQ1ROSWRSQmxaazlMc1ByQWZteDA4SldHN1FfN2lIOC0tSVR0eXNjSE4xZGhnbVY0?oc=5","published_at":"2025-10-29T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"McCrary Institute releases paper to help Americans understand the cyber threat coming from China&nbsp;&nbsp;Auburn University","title":"McCrary Institute releases paper to help Americans understand the cyber threat coming from China - Auburn University"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8ef6f69ec6cdd147","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiowFBVV95cUxONVZJNzB0ZGVaZk9vMDdjUGNPTVRrNEw2bnFDclQ1Yl9hNG5lSnZYWnh3TFI5STNKamt4UVNmNEM1Z0pzYkt2STNvZnRCcFFJalZEYTlSWkVvNzhBSTlxbUlUQWVZamFyN00zSXlhRjAxTk1yNDJhMUlMTGVmOFpVcG9nc0VmZmFDejk2M0dXVzl0SklwaFNQRTdXM2pLRFY2X2Fz?oc=5","published_at":"2025-10-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Southeast Asia: China\u2019s Cyber Incubator and the Looming Day One Threat&nbsp;&nbsp;The Diplomat \u2013 Asia-Pacific","title":"Southeast Asia: China\u2019s Cyber Incubator and the Looming Day One Threat - The Diplomat \u2013 Asia-Pacific"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-0ec2d5d644506ff8","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMizgFBVV95cUxPNm1tbUNERGptRGZncjFWZDZscmozNmh2eHd3Q0YxWlg3dnZnZm52S0piMmUzaHJWSDBpbXF6dHlXbXpscmJFTnVLbjU1aTNRWGxZS1M0SnhHdXBWUkNfRlZsanBGRkMwelpfLVczU19BT0U4VzVKNEhDUURZV1A0S3NRMFRQMFBQU0VPeTVlc09DLUNYQ1ltTkF1Vk9sMElEamtQMmpkZVlLemQya3MtTHh2bVh0Y1FlQTNhbmgxa0pxUlZ6T0lWMjRlTElTdw?oc=5","published_at":"2025-10-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Cybersecurity experts warn OpenAI\u2019s ChatGPT Atlas is vulnerable to attacks that could turn it against a user\u2014revealing sensitive data, downloading malware, or worse&nbsp;&nbsp;Fortune","title":"Cybersecurity experts warn OpenAI\u2019s ChatGPT Atlas is vulnerable to attacks that could turn it against a user\u2014revealing sensitive data, downloading malware, or worse - Fortune"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2b36b7f9029a8b83","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiowFBVV95cUxONVZJNzB0ZGVaZk9vMDdjUGNPTVRrNEw2bnFDclQ1Yl9hNG5lSnZYWnh3TFI5STNKamt4UVNmNEM1Z0pzYkt2STNvZnRCcFFJalZEYTlSWkVvNzhBSTlxbUlUQWVZamFyN00zSXlhRjAxTk1yNDJhMUlMTGVmOFpVcG9nc0VmZmFDejk2M0dXVzl0SklwaFNQRTdXM2pLRFY2X2Fz?oc=5","published_at":"2025-10-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Southeast Asia: China\u2019s Cyber Incubator and the Looming Day One Threat&nbsp;&nbsp;The Diplomat \u2013 Asia-Pacific Current Affairs Magazine","title":"Southeast Asia: China\u2019s Cyber Incubator and the Looming Day One Threat - The Diplomat \u2013 Asia-Pacific Current Affairs Magazine"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a237b00b8161d7d6","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMizgFBVV95cUxPNm1tbUNERGptRGZncjFWZDZscmozNmh2eHd3Q0YxWlg3dnZnZm52S0piMmUzaHJWSDBpbXF6dHlXbXpscmJFTnVLbjU1aTNRWGxZS1M0SnhHdXBWUkNfRlZsanBGRkMwelpfLVczU19BT0U4VzVKNEhDUURZV1A0S3NRMFRQMFBQU0VPeTVlc09DLUNYQ1ltTkF1Vk9sMElEamtQMmpkZVlLemQya3MtTHh2bVh0Y1FlQTNhbmgxa0pxUlZ6T0lWMjRlTElTdw?oc=5","published_at":"2025-10-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Cybersecurity experts warn OpenAI\u2019s ChatGPT Atlas is vulnerable to attacks that could turn it against a user\u2014revealing sensitive data, downloading malware, or worse&nbsp;&nbsp;fortune.com","title":"Cybersecurity experts warn OpenAI\u2019s ChatGPT Atlas is vulnerable to attacks that could turn it against a user\u2014revealing sensitive data, downloading malware, or worse - fortune.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c906e37d1a5943e9","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiowFBVV95cUxONVZJNzB0ZGVaZk9vMDdjUGNPTVRrNEw2bnFDclQ1Yl9hNG5lSnZYWnh3TFI5STNKamt4UVNmNEM1Z0pzYkt2STNvZnRCcFFJalZEYTlSWkVvNzhBSTlxbUlUQWVZamFyN00zSXlhRjAxTk1yNDJhMUlMTGVmOFpVcG9nc0VmZmFDejk2M0dXVzl0SklwaFNQRTdXM2pLRFY2X2Fz?oc=5","published_at":"2025-10-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Southeast Asia: China\u2019s Cyber Incubator and the Looming Day One Threat&nbsp;&nbsp;thediplomat.com","title":"Southeast Asia: China\u2019s Cyber Incubator and the Looming Day One Threat - thediplomat.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-08498656ec00570e","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxQbEFDX1Z6MkF3WXZZY2h1cXhaSF9hcDJYZk1iZWwwR0NDTEw3VlpZQ0ZSQ3VQM2JvZlVyYXJRWmdBcjE3MjFnS1dQaF9vUWt0UVdoZ1hUTGJrZlREaG56QTVXOEhXNXkyZS0xcXdBalozdWxFcFRhc0VVQnhyMDIyLTFEWWJmeGt2aXZsQ3lLbFdoNHVUS3VVdFpLeVlobjJlZlhDX0d1Snk5UQ?oc=5","published_at":"2025-10-23T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"2024: When China\u2019s Salt Typhoon Made Cyberspace Tidal Waves&nbsp;&nbsp;New Lines Institute","title":"2024: When China\u2019s Salt Typhoon Made Cyberspace Tidal Waves - New Lines Institute"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-9d15ba37f5e7e2e3","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxQbEFDX1Z6MkF3WXZZY2h1cXhaSF9hcDJYZk1iZWwwR0NDTEw3VlpZQ0ZSQ3VQM2JvZlVyYXJRWmdBcjE3MjFnS1dQaF9vUWt0UVdoZ1hUTGJrZlREaG56QTVXOEhXNXkyZS0xcXdBalozdWxFcFRhc0VVQnhyMDIyLTFEWWJmeGt2aXZsQ3lLbFdoNHVUS3VVdFpLeVlobjJlZlhDX0d1Snk5UQ?oc=5","published_at":"2025-10-23T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"2024: When China\u2019s Salt Typhoon Made Cyberspace Tidal Waves&nbsp;&nbsp;newlinesinstitute.org","title":"2024: When China\u2019s Salt Typhoon Made Cyberspace Tidal Waves - newlinesinstitute.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2a4c4e91c8fff854","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxOSmJTV1dWWExPZ2R2VS1DWDRwVmxaa0taemdDdHdHT19hX2hVaUF2RGFRclFxb2h5ZmI1b2JBODN3Y2JqQnZ2YVV0V2w5SFFiZl9xYnVpY0NhYkhiYlBzQi1FdkVHMmNBd2xhWGNLR1FwSlptUnkxOUlNdnlkUHBqZjJCUXNyV3BOelhFU2k2UDJ0V0xJSGJSTHpGRm1BdHM?oc=5","published_at":"2025-10-22T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"AWS Outage triggers cyber threat concerns across the globe&nbsp;&nbsp;cybersecurity-insiders.com","title":"AWS Outage triggers cyber threat concerns across the globe - cybersecurity-insiders.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-cefada3ea1e86190","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxOWnU2R3dpZzJVSTRvdTYxaUxkaWVPTEprY2JNS3lqNGExbG5oRHdkTkhZMExmUnR3RHpNeHBXMy0wbEE0SFBoc3c2LVBYQkFEZFV0MHNsXzFLNnJoWkxtNVRYM3ZJNzQ3QUVlc29UZXk1dGRDbEZjR082RWlIR2cwX216aFh6UnJRWlBjTURSQTFsdlRlTGMwRHZPX3A0Q1E?oc=5","published_at":"2025-10-22T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Reconfiguring U.S. Cyber Strategy in the Wake of Salt Typhoon&nbsp;&nbsp;lawfaremedia.org","title":"Reconfiguring U.S. Cyber Strategy in the Wake of Salt Typhoon - lawfaremedia.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1c0d28f79c6c5b9e","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxOSmJTV1dWWExPZ2R2VS1DWDRwVmxaa0taemdDdHdHT19hX2hVaUF2RGFRclFxb2h5ZmI1b2JBODN3Y2JqQnZ2YVV0V2w5SFFiZl9xYnVpY0NhYkhiYlBzQi1FdkVHMmNBd2xhWGNLR1FwSlptUnkxOUlNdnlkUHBqZjJCUXNyV3BOelhFU2k2UDJ0V0xJSGJSTHpGRm1BdHM?oc=5","published_at":"2025-10-22T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"AWS Outage triggers cyber threat concerns across the globe&nbsp;&nbsp;Cybersecurity Insiders","title":"AWS Outage triggers cyber threat concerns across the globe - Cybersecurity Insiders"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-addf71a4d0297c7c","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxOWnU2R3dpZzJVSTRvdTYxaUxkaWVPTEprY2JNS3lqNGExbG5oRHdkTkhZMExmUnR3RHpNeHBXMy0wbEE0SFBoc3c2LVBYQkFEZFV0MHNsXzFLNnJoWkxtNVRYM3ZJNzQ3QUVlc29UZXk1dGRDbEZjR082RWlIR2cwX216aFh6UnJRWlBjTURSQTFsdlRlTGMwRHZPX3A0Q1E?oc=5","published_at":"2025-10-22T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Reconfiguring U.S. Cyber Strategy in the Wake of Salt Typhoon&nbsp;&nbsp;Lawfare","title":"Reconfiguring U.S. Cyber Strategy in the Wake of Salt Typhoon - Lawfare"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d6203e25d31d1f69","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMingFBVV95cUxQdF80b0Zkemg2cjB5eUJMMjJIbGxFQktPeThROGZSMV9MQ0hlQWctSlZYNlRVand5Z1k3OGxsblk4WUROeC1qeFV4RkVJY2V0d0lIZ2hsM0hjS29ldWdXZ0UwbW1sWTNfdEV5VXJMR3RTVm9qOUtxcXdGd042WHU4ekkydHBlbmwxLU5yWDVzd3pHa2RsUVc5b0xMei0xUQ?oc=5","published_at":"2025-10-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Why the US needs a total defense strategy based on resilience&nbsp;&nbsp;Brookings","title":"Why the US needs a total defense strategy based on resilience - Brookings"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-dbb1477cdd4b7907","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuwFBVV95cUxQMDVjX2FsemJSTHFRVHg0YzdPRnA5Z1V6MDFHbnFKaVg2U3dFZjdJUDNtazFNUEt2dmUwaWdhSV9DVGdER2c5Y0dQaWlOWkZyRUV1bzIwdms1bnpyeEtpeDZ4bVhjSkRINnFpbzZpaXlEdTR5MUlOT1c3SDZfVklGdDd4MmNWMnVld3JQaHdkYmRWc3FwYVVRZW1ENWUzMy1WUV8xT3Q3TjE2dWVrZy1nTFpfQ3hRUmdPMTZv?oc=5","published_at":"2025-10-20T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"2025 Cyber Incident Trends: What Your Business Needs to Know&nbsp;&nbsp;Mayer Brown","title":"2025 Cyber Incident Trends: What Your Business Needs to Know - Mayer Brown"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e72dbda8d890ec2f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuwFBVV95cUxQMDVjX2FsemJSTHFRVHg0YzdPRnA5Z1V6MDFHbnFKaVg2U3dFZjdJUDNtazFNUEt2dmUwaWdhSV9DVGdER2c5Y0dQaWlOWkZyRUV1bzIwdms1bnpyeEtpeDZ4bVhjSkRINnFpbzZpaXlEdTR5MUlOT1c3SDZfVklGdDd4MmNWMnVld3JQaHdkYmRWc3FwYVVRZW1ENWUzMy1WUV8xT3Q3TjE2dWVrZy1nTFpfQ3hRUmdPMTZv?oc=5","published_at":"2025-10-20T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"2025 Cyber Incident Trends: What Your Business Needs to Know&nbsp;&nbsp;mayerbrown.com","title":"2025 Cyber Incident Trends: What Your Business Needs to Know - mayerbrown.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-9b52766f8e775033","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMijgFBVV95cUxPRnMta2pNQVpYM0paWm5OZkhJa0xRcGltaUdMNzB6Z0trTnRPZVhOa1VOLWdaMXBGN0tldWJhRU5GdmlnY0dweDVQOXJqV09FOTNnTjh6THRLN3UxbHpScldRZlpZNXFjcHAxeFEwVVlpVkk5ZlBMVzdnU3BfSlEtT1lEbHMtUzJVTmdadlBB?oc=5","published_at":"2025-10-18T06:54:12+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Inductive Automation releases Ignition 8 update and Ignition Perspective Module&nbsp;&nbsp;Automation.com","title":"Inductive Automation releases Ignition 8 update and Ignition Perspective Module - Automation.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-1d5511f93b64c6bd","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMijgFBVV95cUxPRnMta2pNQVpYM0paWm5OZkhJa0xRcGltaUdMNzB6Z0trTnRPZVhOa1VOLWdaMXBGN0tldWJhRU5GdmlnY0dweDVQOXJqV09FOTNnTjh6THRLN3UxbHpScldRZlpZNXFjcHAxeFEwVVlpVkk5ZlBMVzdnU3BfSlEtT1lEbHMtUzJVTmdadlBB?oc=5","published_at":"2025-10-18T06:54:12+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Inductive Automation releases Ignition 8 update and Ignition Perspective Module&nbsp;&nbsp;automation.com","title":"Inductive Automation releases Ignition 8 update and Ignition Perspective Module - automation.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-40c488abf67c571e","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiekFVX3lxTE82VTNoSjJ0LXJtYXE0dnIxR1BORVU0Ti1kQXpwWDI4YzFkWnZNTEFZbEl2bnFhRHQzQnBQM2ZPZzlKQ0ozdkh0R3ZCX1I4a0NnZ09KU29EcWE2MWVmdU43R2RxdlpWaEUwV1BlajJRenZfTFZPNktmNmZR?oc=5","published_at":"2025-10-17T18:52:20+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Olis Robotics Launches New PLC Capabilities at IMTS&nbsp;&nbsp;Automation.com","title":"Olis Robotics Launches New PLC Capabilities at IMTS - Automation.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-bb29e16cf93f5ea4","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiekFVX3lxTE82VTNoSjJ0LXJtYXE0dnIxR1BORVU0Ti1kQXpwWDI4YzFkWnZNTEFZbEl2bnFhRHQzQnBQM2ZPZzlKQ0ozdkh0R3ZCX1I4a0NnZ09KU29EcWE2MWVmdU43R2RxdlpWaEUwV1BlajJRenZfTFZPNktmNmZR?oc=5","published_at":"2025-10-17T18:52:20+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Olis Robotics Launches New PLC Capabilities at IMTS&nbsp;&nbsp;automation.com","title":"Olis Robotics Launches New PLC Capabilities at IMTS - automation.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-346c9d4d71b9620e","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxNMTdEb29BU3FHNTlGbEpsQzdCNTB2c0JyWmYwbjVkdk5oVEFSSWw3NGc3UFFBWHRUU052RzFDd1A2eEh2N1FCZG1rSDlWb3dGSFdkdmZlQzZ4NWJQdjBQaWo3YV9hdUxHR0loOUMxZlUzYVAxanhFVG1KbnRtSWl2bVA1dw?oc=5","published_at":"2025-10-17T15:23:50+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Inductive Automation Releases Ignition 8.1&nbsp;&nbsp;Automation.com","title":"Inductive Automation Releases Ignition 8.1 - Automation.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-2ecab763e474b1c2","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxNMTdEb29BU3FHNTlGbEpsQzdCNTB2c0JyWmYwbjVkdk5oVEFSSWw3NGc3UFFBWHRUU052RzFDd1A2eEh2N1FCZG1rSDlWb3dGSFdkdmZlQzZ4NWJQdjBQaWo3YV9hdUxHR0loOUMxZlUzYVAxanhFVG1KbnRtSWl2bVA1dw?oc=5","published_at":"2025-10-17T15:23:50+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Inductive Automation Releases Ignition 8.1&nbsp;&nbsp;automation.com","title":"Inductive Automation Releases Ignition 8.1 - automation.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f765ff48ceab4402","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikwFBVV95cUxQdm90U1BMMlJGV3dPQ0F2SWpwZ3VpQXktVGlDSXRfYmUyV0tDd2hfRFhvM0UtX2ZyeVNTbmtCWVZVdW5EejRrWDN5TU5LR0dyT2RxR093QjM1aGVBSWNtZ1hILU1vbXdtSGtBd0VBZUt3Y3lzSXhHVmE0OU9FWXJVS1hzVzlodzFqQjVQMWJibkR4QTQ?oc=5","published_at":"2025-10-16T03:04:05+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Change Healthcare cyberattack&nbsp;&nbsp;American Medical Association | AMA","title":"Change Healthcare cyberattack - American Medical Association | AMA"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-28b26ddc37ab42b5","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikwFBVV95cUxQdm90U1BMMlJGV3dPQ0F2SWpwZ3VpQXktVGlDSXRfYmUyV0tDd2hfRFhvM0UtX2ZyeVNTbmtCWVZVdW5EejRrWDN5TU5LR0dyT2RxR093QjM1aGVBSWNtZ1hILU1vbXdtSGtBd0VBZUt3Y3lzSXhHVmE0OU9FWXJVS1hzVzlodzFqQjVQMWJibkR4QTQ?oc=5","published_at":"2025-10-16T03:04:05+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Change Healthcare cyberattack&nbsp;&nbsp;ama-assn.org","title":"Change Healthcare cyberattack - ama-assn.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-0be298412c2fc3cf","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMifkFVX3lxTE1MNGprc3RLT0Jrc01qeTladHZuMnF3N19sMFlOVVExd1lFZGxmMmdUYkJqUkMzandyZHZOSnhaVTc3Qlc5ZjFUSXhWeGNkZFE3b2FJUTAwcElpOUVOWEdRSmhnZ3dtTGpKU2Njd2lUeDZBR3pBOFZuUm9WQjkwUQ?oc=5","published_at":"2025-10-15T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control&nbsp;&nbsp;thehackernews.com","title":"Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-16863b54f09ef1f9","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijwJBVV95cUxQR1lpOTNLQy0zOEdJTGV2dG1yMDRhSjlESmk0T1hoNHg1cUIwZ041YUtJVGJ5SlhBYWt3X24ySGhGNkxkSUpLLUtud2VvRzk4YkJHQmtuRk5EOXR3TEo2STZzZWN0NHgxMVAtdUR4VzFXZ0FVZzdzMjdiU2wteHNnYUJxd204OVZyNDZaVU50OVBDQ09xeldMLW9ZYUhPRG5BQlpYYUNmeHRkU1JRMDZZRzZtU3BmazVURlZmTzg2cEtJbUFpNUVER3dEaWlvUnE4WkFlMGlhUUtpUFdIRmg3UUltT01YWjhiU2xGRzQwemZDT0N1U1ktd3dvc2VQZlhvTmYxQ0c4ODh0UHBIWTBF?oc=5","published_at":"2025-10-15T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Xsight Labs and Cyber Forza Partner to Deliver Breakthrough AI-Driven Cybersecurity Solutions for AI and Cloud Infrastructure&nbsp;&nbsp;Business Wire","title":"Xsight Labs and Cyber Forza Partner to Deliver Breakthrough AI-Driven Cybersecurity Solutions for AI and Cloud Infrastructure - Business Wire"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a4bb56024ea2f6df","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijwJBVV95cUxQR1lpOTNLQy0zOEdJTGV2dG1yMDRhSjlESmk0T1hoNHg1cUIwZ041YUtJVGJ5SlhBYWt3X24ySGhGNkxkSUpLLUtud2VvRzk4YkJHQmtuRk5EOXR3TEo2STZzZWN0NHgxMVAtdUR4VzFXZ0FVZzdzMjdiU2wteHNnYUJxd204OVZyNDZaVU50OVBDQ09xeldMLW9ZYUhPRG5BQlpYYUNmeHRkU1JRMDZZRzZtU3BmazVURlZmTzg2cEtJbUFpNUVER3dEaWlvUnE4WkFlMGlhUUtpUFdIRmg3UUltT01YWjhiU2xGRzQwemZDT0N1U1ktd3dvc2VQZlhvTmYxQ0c4ODh0UHBIWTBF?oc=5","published_at":"2025-10-15T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Xsight Labs and Cyber Forza Partner to Deliver Breakthrough AI-Driven Cybersecurity Solutions for AI and Cloud Infrastructure&nbsp;&nbsp;businesswire.com","title":"Xsight Labs and Cyber Forza Partner to Deliver Breakthrough AI-Driven Cybersecurity Solutions for AI and Cloud Infrastructure - businesswire.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e02033220d8b04c0","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMifkFVX3lxTE1MNGprc3RLT0Jrc01qeTladHZuMnF3N19sMFlOVVExd1lFZGxmMmdUYkJqUkMzandyZHZOSnhaVTc3Qlc5ZjFUSXhWeGNkZFE3b2FJUTAwcElpOUVOWEdRSmhnZ3dtTGpKU2Njd2lUeDZBR3pBOFZuUm9WQjkwUQ?oc=5","published_at":"2025-10-15T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control&nbsp;&nbsp;The Hacker News","title":"Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2fe8508a322f16a6","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiigJBVV95cUxPYzNUODBnWFVLbDY2RW1mSlg0SUlDZlBjaDVYamtlb0VTRHU0Uk9EMG9xX0VuaTVmVFJHRk5sVW1mcG5vSjd6OUh2eWN6eWo0YTdCeDN2NE9vbV9OUXpydXYwSnBTNUdrYUJQWUNUWFN1OFlqLU1UWHVUdE56MFMwV1ZhcDh3VEdNanRrZHFvTHpqLVJ4NTB0RnhkNkRLdjJBak9rV0QwV3lySkRKU0RVWXhRdTQtNXhsWXJLbHRjUTdZSWxBVEFRSkxYZXFIVU15azZOSEJCRW1ZRW8wNVNISGpwNWVSZ3NxYkQtUXFzUDdvWXZPTWpmSkRNanA3dk5FV2lWVmxQYW1lZw?oc=5","published_at":"2025-10-13T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Critical Infra & APTs","summary":"Senate bill proposes to reinforce cybersecurity collaboration, renew cybersecurity provisions, enhance cyber defense&nbsp;&nbsp;industrialcyber.co","title":"Senate bill proposes to reinforce cybersecurity collaboration, renew cybersecurity provisions, enhance cyber defense - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-fff6bfcf2f7cee4e","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiigJBVV95cUxPYzNUODBnWFVLbDY2RW1mSlg0SUlDZlBjaDVYamtlb0VTRHU0Uk9EMG9xX0VuaTVmVFJHRk5sVW1mcG5vSjd6OUh2eWN6eWo0YTdCeDN2NE9vbV9OUXpydXYwSnBTNUdrYUJQWUNUWFN1OFlqLU1UWHVUdE56MFMwV1ZhcDh3VEdNanRrZHFvTHpqLVJ4NTB0RnhkNkRLdjJBak9rV0QwV3lySkRKU0RVWXhRdTQtNXhsWXJLbHRjUTdZSWxBVEFRSkxYZXFIVU15azZOSEJCRW1ZRW8wNVNISGpwNWVSZ3NxYkQtUXFzUDdvWXZPTWpmSkRNanA3dk5FV2lWVmxQYW1lZw?oc=5","published_at":"2025-10-13T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Critical Infra & APTs","summary":"Senate bill proposes to reinforce cybersecurity collaboration, renew cybersecurity provisions, enhance cyber defense&nbsp;&nbsp;Industrial Cyber","title":"Senate bill proposes to reinforce cybersecurity collaboration, renew cybersecurity provisions, enhance cyber defense - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-e49688f68a44877b","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi2wFBVV95cUxPYS1CSUNhVEhDTE5HSE5FNk44LXlCVERwUV9zdkU3Z3Q1U0FMTGtuMjAycmJ2RGtiQl9TdVh6R0tTRmdpZjVIV0ZZZFVlenRGNTczZDRXNUpSOHJIVlJjSEpITlpUTy1hU2lQWWdzSlFOY1dXbGlCRkRHS280YmJfOUdPdndhdHFlcjNNakFjU2NxMFVvN2djVjMtT0s2SHdobUtyc1UzWG9COV9veVJqYWJoenBpZURCTWxva1pVRTJTSDRMbTFRSU00c1lGLU54eWRndW1wSE9QeEE?oc=5","published_at":"2025-10-09T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"CISA warns of critical ICS flaws in Delta Electronics DIAScreen, Rockwell Automation modules&nbsp;&nbsp;industrialcyber.co","title":"CISA warns of critical ICS flaws in Delta Electronics DIAScreen, Rockwell Automation modules - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-633d8ebfee76e08e","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi2wFBVV95cUxPYS1CSUNhVEhDTE5HSE5FNk44LXlCVERwUV9zdkU3Z3Q1U0FMTGtuMjAycmJ2RGtiQl9TdVh6R0tTRmdpZjVIV0ZZZFVlenRGNTczZDRXNUpSOHJIVlJjSEpITlpUTy1hU2lQWWdzSlFOY1dXbGlCRkRHS280YmJfOUdPdndhdHFlcjNNakFjU2NxMFVvN2djVjMtT0s2SHdobUtyc1UzWG9COV9veVJqYWJoenBpZURCTWxva1pVRTJTSDRMbTFRSU00c1lGLU54eWRndW1wSE9QeEE?oc=5","published_at":"2025-10-09T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"CISA warns of critical ICS flaws in Delta Electronics DIAScreen, Rockwell Automation modules&nbsp;&nbsp;Industrial Cyber","title":"CISA warns of critical ICS flaws in Delta Electronics DIAScreen, Rockwell Automation modules - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-181b5ddf09649cad","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMihgJBVV95cUxOYV90QUNvOEhKTm1YX194S0hWY29vZmJnanNoTUl0MXQ5dDNobm5TN1U2ZTRhSEVVc203eUthOVcyd1hZc0VuR2cwT0JKRXdwSF9fRGNET1JYNkpHSGQwcWkxV2dIRmxyYjZEUWdiQUtrMHhXcWtEV3JvQXZVZkU3VHBFR281bmIxR24zOU1zUzNYSzJyZE9oT19jREtUNG5ublZjY3JIU2FudVFOcXJUbzBkSURRTWhlT0YxYThxU3R0UjEzb05xZ0liMFc4Q2pNclNueFM4RWpmVm9hSjhKN24ydWFpMk9DdlQ0UDkyY05tclNSdGdVNF9weEZJc3hBUnlleGJ3?oc=5","published_at":"2025-10-08T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Cyber Leaders Exchange 2025: CISA\u2019s Matthew Rogers, INL\u2019s Ollie Gagnon on driving cyber resilience in critical infrastructure&nbsp;&nbsp;federalnewsnetwork.com","title":"Cyber Leaders Exchange 2025: CISA\u2019s Matthew Rogers, INL\u2019s Ollie Gagnon on driving cyber resilience in critical infrastructure - federalnewsnetwork.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-909afb70c0158081","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMihgJBVV95cUxOYV90QUNvOEhKTm1YX194S0hWY29vZmJnanNoTUl0MXQ5dDNobm5TN1U2ZTRhSEVVc203eUthOVcyd1hZc0VuR2cwT0JKRXdwSF9fRGNET1JYNkpHSGQwcWkxV2dIRmxyYjZEUWdiQUtrMHhXcWtEV3JvQXZVZkU3VHBFR281bmIxR24zOU1zUzNYSzJyZE9oT19jREtUNG5ublZjY3JIU2FudVFOcXJUbzBkSURRTWhlT0YxYThxU3R0UjEzb05xZ0liMFc4Q2pNclNueFM4RWpmVm9hSjhKN24ydWFpMk9DdlQ0UDkyY05tclNSdGdVNF9weEZJc3hBUnlleGJ3?oc=5","published_at":"2025-10-08T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Cyber Leaders Exchange 2025: CISA\u2019s Matthew Rogers, INL\u2019s Ollie Gagnon on driving cyber resilience in critical infrastructure&nbsp;&nbsp;Federal News Network","title":"Cyber Leaders Exchange 2025: CISA\u2019s Matthew Rogers, INL\u2019s Ollie Gagnon on driving cyber resilience in critical infrastructure - Federal News Network"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c39d2f8314b882c8","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxQU2FIUXRsRlJKZTJsaERZR3pyWGFtMHpqUjB4dE9hTGJsYjlRVXdZdkdQTFJXV2c2bkk4czRvb0V1ZmxwbHQxWmt1bG9sOFFIenk2RV8tbVBhdjNYR01wTzZMQ3h6eWw5TTZYT2NMQVZZRThqaDF1VGJxTG9jRG9TUEJXMmQ?oc=5","published_at":"2025-10-03T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Government flying partially blind to threats after key cyber law expires&nbsp;&nbsp;Politico","title":"Government flying partially blind to threats after key cyber law expires - Politico"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-95d65390e9ae2e98","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMixAFBVV95cUxPMGVDOGRvQm5Rbk5OUk4ySHR2ZlhDcVJKeFZTZEQ3cU1La2hlRVUxN1hoYzUxRXlXVktZUVlZeXcyNW1HX2hkbERwMkEwZThnNXZBWUZCTURXY1lJQlgtNkVMU043cVE5cXhrNnZvR1AzUVBjdl9rN2RxSlp5djg1Q05ZVW4zSHdZdjlvclRCMWpzbjlMa2RVV1JlOUZhcmJfbkZWY1pybkxvemNXVndrd3VvQS1OUENZSXI1THRyRDYyTS0t?oc=5","published_at":"2025-10-03T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"People, Nature, and Finance: Viet Nam\u2019s Opportunity to Turn Climate Vulnerability into Global Leadership&nbsp;&nbsp;undp.org","title":"People, Nature, and Finance: Viet Nam\u2019s Opportunity to Turn Climate Vulnerability into Global Leadership - undp.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a26efb229f3f1a7e","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxQU2FIUXRsRlJKZTJsaERZR3pyWGFtMHpqUjB4dE9hTGJsYjlRVXdZdkdQTFJXV2c2bkk4czRvb0V1ZmxwbHQxWmt1bG9sOFFIenk2RV8tbVBhdjNYR01wTzZMQ3h6eWw5TTZYT2NMQVZZRThqaDF1VGJxTG9jRG9TUEJXMmQ?oc=5","published_at":"2025-10-03T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Government flying partially blind to threats after key cyber law expires&nbsp;&nbsp;politico.com","title":"Government flying partially blind to threats after key cyber law expires - politico.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-849c3ed26238cf6f","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihgFBVV95cUxOQi1SaVIteG5xZkpvRV8tMmFXTWN5NzB5UUo4YXF2ekhEb0Rvai0zYkE3eTF3eG91LTJoWkRLREgzZmhFOGY4YmVPYTlTa183eUZQeVVqU05YYko4aWxJTm4tUjhVYUQ2VjZtUUJ1U3NvbjQ0UlQ1UXFhQjJXcThFelVKc3kwdw?oc=5","published_at":"2025-10-03T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Congress Needs to Shutdown-Proof CISA | Blogs | Oct 3, 2025&nbsp;&nbsp;itif.org","title":"Congress Needs to Shutdown-Proof CISA | Blogs | Oct 3, 2025 - itif.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b05bb73a01528e1f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMixAFBVV95cUxPMGVDOGRvQm5Rbk5OUk4ySHR2ZlhDcVJKeFZTZEQ3cU1La2hlRVUxN1hoYzUxRXlXVktZUVlZeXcyNW1HX2hkbERwMkEwZThnNXZBWUZCTURXY1lJQlgtNkVMU043cVE5cXhrNnZvR1AzUVBjdl9rN2RxSlp5djg1Q05ZVW4zSHdZdjlvclRCMWpzbjlMa2RVV1JlOUZhcmJfbkZWY1pybkxvemNXVndrd3VvQS1OUENZSXI1THRyRDYyTS0t?oc=5","published_at":"2025-10-03T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"People, Nature, and Finance: Viet Nam\u2019s Opportunity to Turn Climate Vulnerability into Global Leadership&nbsp;&nbsp;United Nations Development Programme","title":"People, Nature, and Finance: Viet Nam\u2019s Opportunity to Turn Climate Vulnerability into Global Leadership - United Nations Development Programme"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-172e6f69ad80de35","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihgFBVV95cUxOQi1SaVIteG5xZkpvRV8tMmFXTWN5NzB5UUo4YXF2ekhEb0Rvai0zYkE3eTF3eG91LTJoWkRLREgzZmhFOGY4YmVPYTlTa183eUZQeVVqU05YYko4aWxJTm4tUjhVYUQ2VjZtUUJ1U3NvbjQ0UlQ1UXFhQjJXcThFelVKc3kwdw?oc=5","published_at":"2025-10-03T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Congress Needs to Shutdown-Proof CISA | Blogs | Oct 3, 2025&nbsp;&nbsp;Information Technology and Innovation Foundation","title":"Congress Needs to Shutdown-Proof CISA | Blogs | Oct 3, 2025 - Information Technology and Innovation Foundation"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-534428309f9a5970","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikwFBVV95cUxPOWVudXF5amRXMzVucTR0aFNTdENabjdUN3JmcFlPekhEXzFHdV9sR1p6YzFaelZyV3ktZ3BiQm5wS0hCcnBvMnIzWnJuODFUVU1JbGNiOWpjTGNIWlhkaXhpYkdZZWE1emh2ZDN0eE5xLW5rMU5BanV0R3lsYmNWSzBqYkhhWGdFdHMta1RBQnlpTlk?oc=5","published_at":"2025-10-02T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Resilient Networks; Disruptions to Communications&nbsp;&nbsp;Foundation for Defense of Democracies","title":"Resilient Networks; Disruptions to Communications - Foundation for Defense of Democracies"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-fd269acd15e2fcba","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilwFBVV95cUxNSmlWT25rM1c1RlZENi1vVUVRYzhGZF8tUzd3RXhLZ282aDUyb21FMzBaSGFYOURTRnphQVpsS01kUnJSQTlaZndJdkZkaDIzSnd3YWJfSlQ5NGFmRlY0VU5ySEhVQ2lRdFdWWjN5R3c3aTlJbnJCemNSUzlpY3VWS3RvQ0NBUWw3UUFvSFJKcy1OV3Y1cUtz0gGcAUFVX3lxTFBBT0dETHBKcVQ0OXZ3d3BxbEktRnQxQ3pLNjNSQ2VBanltSFh1dkw5N2RoVHdVUE14ZEtweHNvZU8weVlFd1AwTktPZnpXQ185RFJOZXBnYmJHQUhTOHl1MHMtV0Y3SlZjc0ZxVjlzOWpVQWY4RHBseFRLcHN3aVVabUpxdVc0ZUx2VF9Cd0Z3X184dmxLdllCaGlObg?oc=5","published_at":"2025-10-02T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Many Attacks Aimed at EU Targeted OT, Says Cybersecurity Agency&nbsp;&nbsp;SecurityWeek","title":"Many Attacks Aimed at EU Targeted OT, Says Cybersecurity Agency - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b9c1572cfdd6d400","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilwFBVV95cUxNSmlWT25rM1c1RlZENi1vVUVRYzhGZF8tUzd3RXhLZ282aDUyb21FMzBaSGFYOURTRnphQVpsS01kUnJSQTlaZndJdkZkaDIzSnd3YWJfSlQ5NGFmRlY0VU5ySEhVQ2lRdFdWWjN5R3c3aTlJbnJCemNSUzlpY3VWS3RvQ0NBUWw3UUFvSFJKcy1OV3Y1cUtz0gGcAUFVX3lxTFBBT0dETHBKcVQ0OXZ3d3BxbEktRnQxQ3pLNjNSQ2VBanltSFh1dkw5N2RoVHdVUE14ZEtweHNvZU8weVlFd1AwTktPZnpXQ185RFJOZXBnYmJHQUhTOHl1MHMtV0Y3SlZjc0ZxVjlzOWpVQWY4RHBseFRLcHN3aVVabUpxdVc0ZUx2VF9Cd0Z3X184dmxLdllCaGlObg?oc=5","published_at":"2025-10-02T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Many Attacks Aimed at EU Targeted OT, Says Cybersecurity Agency&nbsp;&nbsp;securityweek.com","title":"Many Attacks Aimed at EU Targeted OT, Says Cybersecurity Agency - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a1e5a0b7b81d29d8","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiigFBVV95cUxQTFN0YUxoLVFlLWlKYVNObXQ2MlVCSklLTHN6NE5LS3RPMjViTDlvNTJpZWpxR19rMmFGQWRwVW5OVHVtY3RSc0t3YmxfcHVSbThmWWs5ZGhkcEZyOWsyQmtiU2tpa0NZXzNjUWMzWHprUTFVQ3k5V2NVRFRlWHlvTjdFbXY5aTFvRVE?oc=5","published_at":"2025-10-01T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Global analysis assesses livestock vulnerability to climate change&nbsp;&nbsp;phys.org","title":"Global analysis assesses livestock vulnerability to climate change - phys.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2e81b1440a688113","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiigFBVV95cUxQTFN0YUxoLVFlLWlKYVNObXQ2MlVCSklLTHN6NE5LS3RPMjViTDlvNTJpZWpxR19rMmFGQWRwVW5OVHVtY3RSc0t3YmxfcHVSbThmWWs5ZGhkcEZyOWsyQmtiU2tpa0NZXzNjUWMzWHprUTFVQ3k5V2NVRFRlWHlvTjdFbXY5aTFvRVE?oc=5","published_at":"2025-10-01T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Global analysis assesses livestock vulnerability to climate change&nbsp;&nbsp;Phys.org","title":"Global analysis assesses livestock vulnerability to climate change - Phys.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-cac9b4d037b577f2","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi2gFBVV95cUxNand1WkJpTk5kWXpBcVMwcmY5Sll5VXYwUlZzYWY5YWVZOG94OEF6Y3JpSUEyRFpmbDFWd1RtQ1R5andwSU03dnNyOUNOT0RTWmpCNkFnOHliQVVnQkdUWmk5NXVoa1cxYkc2U0cwWDZDdTMwTGU2a3JJWXVaNzBDYlo5SE5DbGhwMk5BU3lVMms4TUdhNWZvdjBZN1JfUEw3MmU3UXY0cjQ3LUtEVk1sUURROF9hRFR3bG5KT3RaZlFvbkc1X0k4UXRQZjdYaFpJMkZEcWl4Y3NyQQ?oc=5","published_at":"2025-09-26T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"BitSight warns of surge in ICS/OT Internet exposure, raising critical infrastructure cybersecurity concerns&nbsp;&nbsp;Industrial Cyber","title":"BitSight warns of surge in ICS/OT Internet exposure, raising critical infrastructure cybersecurity concerns - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-4dc84553b9a42861","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi2gFBVV95cUxNand1WkJpTk5kWXpBcVMwcmY5Sll5VXYwUlZzYWY5YWVZOG94OEF6Y3JpSUEyRFpmbDFWd1RtQ1R5andwSU03dnNyOUNOT0RTWmpCNkFnOHliQVVnQkdUWmk5NXVoa1cxYkc2U0cwWDZDdTMwTGU2a3JJWXVaNzBDYlo5SE5DbGhwMk5BU3lVMms4TUdhNWZvdjBZN1JfUEw3MmU3UXY0cjQ3LUtEVk1sUURROF9hRFR3bG5KT3RaZlFvbkc1X0k4UXRQZjdYaFpJMkZEcWl4Y3NyQQ?oc=5","published_at":"2025-09-26T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"BitSight warns of surge in ICS/OT Internet exposure, raising critical infrastructure cybersecurity concerns&nbsp;&nbsp;industrialcyber.co","title":"BitSight warns of surge in ICS/OT Internet exposure, raising critical infrastructure cybersecurity concerns - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-e4d182c49812d09d","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMitgFBVV95cUxQZ2lFTDMwU2plb0MzYmxUT0ZmbUxyMENhS2tFYm5xTUoxMnlRWWljOWpoc2drRFFmVXlaLXBwQzRkZXJ6NTJLWmFaR3BlOEg4bmRTX1NKejItQ1hjSmZNUG1uSEpjMzJUeXRocFdaUWhZblR3dURNZUJWd21KOHB6LU15NHBlaEdIR2JWZFNFVE9qRzM0MllBMVUzd0dfbnphQTlnS0dhVkxBVmQ1aUdTY2N6bGFqZw?oc=5","published_at":"2025-09-25T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Critical infrastructure operators add more insecure industrial equipment online&nbsp;&nbsp;Cybersecurity Dive","title":"Critical infrastructure operators add more insecure industrial equipment online - Cybersecurity Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-f674647e0ce21709","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMikgFBVV95cUxNdzh6ZzV3MzRNekZMRUZnXzVjRjNiWVB5TkFFcmV6bndFTU1kWU5CWVVPVGhpNEFUeG5pNVowQlJUM2UtUXZUWHowd3lqeTQ1SURldDhBWmJyeU5GTXc4LUFzRWd3TVE4OTZhMHFfb095SzJBN3prWmhkRWc4bnpwQXIyUm5ZVDE0aXlMbFVhTHhIUdIBlwFBVV95cUxPeEZPc0pZZHRyNUI0VnFRVGRGaFdHQjFsTnhPU2V2UkV1ei1LbzlVcGZka3BKNlFMTWV6VHF2emFhVFNtQUV0X2RiQXdMVkNNelUzN1d6eVZBa1I0azB6R3VseVVEQ0pIb2w1aFFoSFR2bTFoc3d4a3NlUGxtRUN3RVRscFBXNk1EbFRkM2wwNm5KbTFucUc4?oc=5","published_at":"2025-09-25T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Industrial Switch Security","summary":"Cisco Patches Zero-Day Flaw Affecting Routers and Switches&nbsp;&nbsp;SecurityWeek","title":"Cisco Patches Zero-Day Flaw Affecting Routers and Switches - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-0fd51a4983d1d617","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMikgFBVV95cUxNdzh6ZzV3MzRNekZMRUZnXzVjRjNiWVB5TkFFcmV6bndFTU1kWU5CWVVPVGhpNEFUeG5pNVowQlJUM2UtUXZUWHowd3lqeTQ1SURldDhBWmJyeU5GTXc4LUFzRWd3TVE4OTZhMHFfb095SzJBN3prWmhkRWc4bnpwQXIyUm5ZVDE0aXlMbFVhTHhIUdIBlwFBVV95cUxPeEZPc0pZZHRyNUI0VnFRVGRGaFdHQjFsTnhPU2V2UkV1ei1LbzlVcGZka3BKNlFMTWV6VHF2emFhVFNtQUV0X2RiQXdMVkNNelUzN1d6eVZBa1I0azB6R3VseVVEQ0pIb2w1aFFoSFR2bTFoc3d4a3NlUGxtRUN3RVRscFBXNk1EbFRkM2wwNm5KbTFucUc4?oc=5","published_at":"2025-09-25T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Industrial Switch Security","summary":"Cisco Patches Zero-Day Flaw Affecting Routers and Switches&nbsp;&nbsp;securityweek.com","title":"Cisco Patches Zero-Day Flaw Affecting Routers and Switches - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-5aeeba7335fdbecb","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMitgFBVV95cUxQZ2lFTDMwU2plb0MzYmxUT0ZmbUxyMENhS2tFYm5xTUoxMnlRWWljOWpoc2drRFFmVXlaLXBwQzRkZXJ6NTJLWmFaR3BlOEg4bmRTX1NKejItQ1hjSmZNUG1uSEpjMzJUeXRocFdaUWhZblR3dURNZUJWd21KOHB6LU15NHBlaEdIR2JWZFNFVE9qRzM0MllBMVUzd0dfbnphQTlnS0dhVkxBVmQ1aUdTY2N6bGFqZw?oc=5","published_at":"2025-09-25T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Critical infrastructure operators add more insecure industrial equipment online&nbsp;&nbsp;cybersecuritydive.com","title":"Critical infrastructure operators add more insecure industrial equipment online - cybersecuritydive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-cab43405030aee79","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMimwFBVV95cUxNaFRoejdSZXVtUUdidXVLeFdpVDF2NlpuZFNHTGQtQXR1ZnRzMC1neEV6NkhsRUxpa1dMMENuaEhkWmpuQjRXbjFvUm9adTZ0QW9lZzZjcDVHZ0ZjeFU3eDhvbjNJVzBObWhnUTJiWnowOEtHdDY5U29BWVllOFlRbGpGSHJLczVPRGVaSmtUMUJENVpsamZtaHhtdw?oc=5","published_at":"2025-09-23T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"HIGH","source":"Critical Infra & APTs","summary":"Air Force cyber leader warns threats like Volt Typhoon could enable China to wage \u2018total war\u2019 against US&nbsp;&nbsp;defensescoop.com","title":"Air Force cyber leader warns threats like Volt Typhoon could enable China to wage \u2018total war\u2019 against US - defensescoop.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-ef5a1be8aa6800c7","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMimwFBVV95cUxNaFRoejdSZXVtUUdidXVLeFdpVDF2NlpuZFNHTGQtQXR1ZnRzMC1neEV6NkhsRUxpa1dMMENuaEhkWmpuQjRXbjFvUm9adTZ0QW9lZzZjcDVHZ0ZjeFU3eDhvbjNJVzBObWhnUTJiWnowOEtHdDY5U29BWVllOFlRbGpGSHJLczVPRGVaSmtUMUJENVpsamZtaHhtdw?oc=5","published_at":"2025-09-23T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"HIGH","source":"Critical Infra & APTs","summary":"Air Force cyber leader warns threats like Volt Typhoon could enable China to wage \u2018total war\u2019 against US&nbsp;&nbsp;DefenseScoop","title":"Air Force cyber leader warns threats like Volt Typhoon could enable China to wage \u2018total war\u2019 against US - DefenseScoop"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5c2dacfc82081a70","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi3gFBVV95cUxOcWdHR0hHZ1NEaFMxVWVhR3gwczgzSF8xclJGeDdpT3pyRXp0alV6WF9VZ24xOGhBX2EzY2FXR2tHU0psdUdEal9GZ0tlUnE2T1puOFZJd3lnYVlVcENOUmNNNVVkcEt4UFVNZ1dSTmJpUG1SelhEVm9xazNLbFNhUFVaUEp4RVJyempZYVJkUmlLNnJlMFBhN1dndFVMd1FJOXlIOG5vSXZGOTZnTGFpUmVlTHpvOFZXUkE0SXJ6VnB3QnlSTnJWYU1tTFFuUGJmTnlJUW9YTDhULTlxSnc?oc=5","published_at":"2025-09-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Rising threats push industrial supply chains to adopt real-time monitoring, proactive cybersecurity practices&nbsp;&nbsp;Industrial Cyber","title":"Rising threats push industrial supply chains to adopt real-time monitoring, proactive cybersecurity practices - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9718868adcbb845d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi3gFBVV95cUxOcWdHR0hHZ1NEaFMxVWVhR3gwczgzSF8xclJGeDdpT3pyRXp0alV6WF9VZ24xOGhBX2EzY2FXR2tHU0psdUdEal9GZ0tlUnE2T1puOFZJd3lnYVlVcENOUmNNNVVkcEt4UFVNZ1dSTmJpUG1SelhEVm9xazNLbFNhUFVaUEp4RVJyempZYVJkUmlLNnJlMFBhN1dndFVMd1FJOXlIOG5vSXZGOTZnTGFpUmVlTHpvOFZXUkE0SXJ6VnB3QnlSTnJWYU1tTFFuUGJmTnlJUW9YTDhULTlxSnc?oc=5","published_at":"2025-09-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Rising threats push industrial supply chains to adopt real-time monitoring, proactive cybersecurity practices&nbsp;&nbsp;industrialcyber.co","title":"Rising threats push industrial supply chains to adopt real-time monitoring, proactive cybersecurity practices - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-148a06f6d0d41b62","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMif0FVX3lxTE5tbWJuY1A4bElrMGVlTFIxd3J3VlFJTUlTVGVMNngwSndyaXMwdE5XZnZlSm5KeUdRQS0yclZlQkJsWmUtT1gzcjE1aDNoUjVDaGI2LXEyZ2o1UXBlU1lpeGt1a0J2bnM3SkM1WExpSHNtOUJLaWZxYXJlTWV6T1E?oc=5","published_at":"2025-09-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Getting ready for CRA&nbsp;&nbsp;Control Engineering Europe","title":"Getting ready for CRA - Control Engineering Europe"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9ce4ae2c83bc51ea","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMicEFVX3lxTE1FSWtlU09xUE8zSmhLSjZLMFR0bHozVndua0NSdFhGNDl6ZlVZdVR4VEE5ZFlRcy1ydC0yVzB2Y1VrZjdZeURTck5YQmpBV0lxYWc2XzZMNzNreS1uanVWc2NtU0tueHNZdkM0V1hyTGk?oc=5","published_at":"2025-09-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Threat landscape for industrial automation systems in Q2 2025&nbsp;&nbsp;Securelist","title":"Threat landscape for industrial automation systems in Q2 2025 - Securelist"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8b00e276e4178068","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMicEFVX3lxTE1FSWtlU09xUE8zSmhLSjZLMFR0bHozVndua0NSdFhGNDl6ZlVZdVR4VEE5ZFlRcy1ydC0yVzB2Y1VrZjdZeURTck5YQmpBV0lxYWc2XzZMNzNreS1uanVWc2NtU0tueHNZdkM0V1hyTGk?oc=5","published_at":"2025-09-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Threat landscape for industrial automation systems in Q2 2025&nbsp;&nbsp;securelist.com","title":"Threat landscape for industrial automation systems in Q2 2025 - securelist.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-80c8fd86f41245cf","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuwFBVV95cUxQQzY3VTR6R0YtVF9xeUtsVUlRWVpRV3pjcTFRTGJyd2dtRTdtS3ZPbnY4Y01CcDNsMFJyemFSd2JYdzZRdWNBbnJOYnk5SFp5QVYwNWNiX3RLc2o4d09FVnhqaUtzUEVpMWg5WHRMWFJUTW9TMGJ4aXIyaUVjUko2d2pKQzBWczR2T3I3alJNT0daT2E3REQtZHlkM0FJQnVlLW52MXRDMTRTVzU4QkRYZldDSWZnVk1jYzdv?oc=5","published_at":"2025-09-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Facility managers on front lines amid rise in building-control cyber threats&nbsp;&nbsp;Facilities Dive","title":"Facility managers on front lines amid rise in building-control cyber threats - Facilities Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7cf0206cefd1dc35","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMif0FVX3lxTE5tbWJuY1A4bElrMGVlTFIxd3J3VlFJTUlTVGVMNngwSndyaXMwdE5XZnZlSm5KeUdRQS0yclZlQkJsWmUtT1gzcjE1aDNoUjVDaGI2LXEyZ2o1UXBlU1lpeGt1a0J2bnM3SkM1WExpSHNtOUJLaWZxYXJlTWV6T1E?oc=5","published_at":"2025-09-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Getting ready for CRA&nbsp;&nbsp;controlengeurope.com","title":"Getting ready for CRA - controlengeurope.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-badc4a67d0bd0f03","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuwFBVV95cUxQQzY3VTR6R0YtVF9xeUtsVUlRWVpRV3pjcTFRTGJyd2dtRTdtS3ZPbnY4Y01CcDNsMFJyemFSd2JYdzZRdWNBbnJOYnk5SFp5QVYwNWNiX3RLc2o4d09FVnhqaUtzUEVpMWg5WHRMWFJUTW9TMGJ4aXIyaUVjUko2d2pKQzBWczR2T3I3alJNT0daT2E3REQtZHlkM0FJQnVlLW52MXRDMTRTVzU4QkRYZldDSWZnVk1jYzdv?oc=5","published_at":"2025-09-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Facility managers on front lines amid rise in building-control cyber threats&nbsp;&nbsp;facilitiesdive.com","title":"Facility managers on front lines amid rise in building-control cyber threats - facilitiesdive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-0f849867511352a3","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMioAFBVV95cUxORHhnX2xoYzAtWk94YlpOc19Td0JqRXUyTjBEOHd2Q1ctNWpGQkdta3lVd3MzMXZaQ1VTempEZlplVWhWMmNUSVNUQ1d4SHZpbDFISU0wYUlaUjliR0JYZi1QWm5VOHR1bTEwc1hhdFplR3ZkaV9yWjVjZ0NXaW43U05fblVEazNkeXFZM1pnSXB2b0VPRERUVlZ4WHlrNEdW?oc=5","published_at":"2025-09-18T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"MEDIUM","source":"Ignition SCADA Security","summary":"MaintainX and Inductive Automation Launch Integration for Automated Maintenance&nbsp;&nbsp;ARC Advisory Group","title":"MaintainX and Inductive Automation Launch Integration for Automated Maintenance - ARC Advisory Group"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-542f6851fc34879e","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMioAFBVV95cUxORHhnX2xoYzAtWk94YlpOc19Td0JqRXUyTjBEOHd2Q1ctNWpGQkdta3lVd3MzMXZaQ1VTempEZlplVWhWMmNUSVNUQ1d4SHZpbDFISU0wYUlaUjliR0JYZi1QWm5VOHR1bTEwc1hhdFplR3ZkaV9yWjVjZ0NXaW43U05fblVEazNkeXFZM1pnSXB2b0VPRERUVlZ4WHlrNEdW?oc=5","published_at":"2025-09-18T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"MaintainX and Inductive Automation Launch Integration for Automated Maintenance&nbsp;&nbsp;arcweb.com","title":"MaintainX and Inductive Automation Launch Integration for Automated Maintenance - arcweb.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-80bfdef4be4db80f","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxPNWJCVFFET0sxTndnSW5OVHVrT1hYLWh4WUFpNEJ0c2o1N3lkaUQ2X2Nwc0N3SDdrMXhYRUpiRVR1Y21pR01iLWZ0S3BpVHluZGZDbTh4TmFSMzVWaGd3c1JPdFJXNFpzZVI0VXotQkNPdElRZ0JpTFc3T01BcFZwdmhGV2dBd1BBUFBXWkx6UlNucmZNTGdvc1BVN2JpRVdmbVA2LTFxMUEtZ2s?oc=5","published_at":"2025-09-17T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"MEDIUM","source":"Ignition SCADA Security","summary":"Inductive Automation Launches Ignition 8.3 with LTS, Advanced Modules, and Gateway Redesign&nbsp;&nbsp;ARC Advisory","title":"Inductive Automation Launches Ignition 8.3 with LTS, Advanced Modules, and Gateway Redesign - ARC Advisory"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-a2d57108c8b8608a","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxPNWJCVFFET0sxTndnSW5OVHVrT1hYLWh4WUFpNEJ0c2o1N3lkaUQ2X2Nwc0N3SDdrMXhYRUpiRVR1Y21pR01iLWZ0S3BpVHluZGZDbTh4TmFSMzVWaGd3c1JPdFJXNFpzZVI0VXotQkNPdElRZ0JpTFc3T01BcFZwdmhGV2dBd1BBUFBXWkx6UlNucmZNTGdvc1BVN2JpRVdmbVA2LTFxMUEtZ2s?oc=5","published_at":"2025-09-17T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"MEDIUM","source":"Ignition SCADA Security","summary":"Inductive Automation Launches Ignition 8.3 with LTS, Advanced Modules, and Gateway Redesign&nbsp;&nbsp;ARC Advisory Group","title":"Inductive Automation Launches Ignition 8.3 with LTS, Advanced Modules, and Gateway Redesign - ARC Advisory Group"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-6a2bcd0cc83df9d6","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxPNWJCVFFET0sxTndnSW5OVHVrT1hYLWh4WUFpNEJ0c2o1N3lkaUQ2X2Nwc0N3SDdrMXhYRUpiRVR1Y21pR01iLWZ0S3BpVHluZGZDbTh4TmFSMzVWaGd3c1JPdFJXNFpzZVI0VXotQkNPdElRZ0JpTFc3T01BcFZwdmhGV2dBd1BBUFBXWkx6UlNucmZNTGdvc1BVN2JpRVdmbVA2LTFxMUEtZ2s?oc=5","published_at":"2025-09-17T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Inductive Automation Launches Ignition 8.3 with LTS, Advanced Modules, and Gateway Redesign&nbsp;&nbsp;arcweb.com","title":"Inductive Automation Launches Ignition 8.3 with LTS, Advanced Modules, and Gateway Redesign - arcweb.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-5ab3808a17388d60","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiggJBVV95cUxNSVV5TUNzYzVmLVJES2tLcDFPLV8zMTZxSHBPM2NCT1otY05OV1FUX0NncmxfQmpqdzZ0SzA5d2lyVVIzaFE2UWw5blMzVGEzZ0E4VHdibHMzNUc5NWJzYkdxNk9UVmhJMHV4dzZiWS1QdkxCbmNyU3FvQTg5eW1rWFpvTV9Zcy1kRm9OZzRMM0FLaURFZ3FlNENRWm82QlpicGRqTFJ3NTYzQUIwQjUtdFNORTU1aGFZYzB1djY0RnRFRkNaY0dMUGZSNlcwSThEMFNjQ2c5ZWd6TzRRdDFldUp0Z0RPb2lVLUJ1eXo4SExPUkNKWENNZ3Rja2xON1h1bFE?oc=5","published_at":"2025-09-16T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"MaintainX and Inductive Automation Collaborate to Transform Equipment Data into Actionable Maintenance Intelligence&nbsp;&nbsp;businesswire.com","title":"MaintainX and Inductive Automation Collaborate to Transform Equipment Data into Actionable Maintenance Intelligence - businesswire.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-25522eb829ebc9c5","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiggJBVV95cUxNSVV5TUNzYzVmLVJES2tLcDFPLV8zMTZxSHBPM2NCT1otY05OV1FUX0NncmxfQmpqdzZ0SzA5d2lyVVIzaFE2UWw5blMzVGEzZ0E4VHdibHMzNUc5NWJzYkdxNk9UVmhJMHV4dzZiWS1QdkxCbmNyU3FvQTg5eW1rWFpvTV9Zcy1kRm9OZzRMM0FLaURFZ3FlNENRWm82QlpicGRqTFJ3NTYzQUIwQjUtdFNORTU1aGFZYzB1djY0RnRFRkNaY0dMUGZSNlcwSThEMFNjQ2c5ZWd6TzRRdDFldUp0Z0RPb2lVLUJ1eXo4SExPUkNKWENNZ3Rja2xON1h1bFE?oc=5","published_at":"2025-09-16T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"MaintainX and Inductive Automation Collaborate to Transform Equipment Data into Actionable Maintenance Intelligence&nbsp;&nbsp;Business Wire","title":"MaintainX and Inductive Automation Collaborate to Transform Equipment Data into Actionable Maintenance Intelligence - Business Wire"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-6cc83d59464b2fa9","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi-wFBVV95cUxNR0dDY19MUHZqNUFTTWZFV3pXa1o1T3dvMHVWTENjUjVqUmdrZmM2TmtMMVF0ZUtXaTB5akdzMTQ3NlZuTnBxdjZ4V1FkcTU2cE1wemttXzJKa0trZzk5OUZlOWgzRDZDdEFFR1NvcmJsN0ItdGxxLTgtQUNSeGEwT0tUQThqQzh1UVg1Tkx2dUgxS2s1NnBGUTBlU0FTRlNJWU1wZjJXdjZhU19FU180RTZiaEozNHN0SmtHRXFhTjNnM1JiM3NLX3NvLTFkQmtUTWRJRk14a2NOazdkSTlkaWkyT21BQmdULVBUS2QwZHpHaWlPZnJSbEJDTQ?oc=5","published_at":"2025-09-11T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"CISA flags critical ICS vulnerabilities across Rockwell and ABB Systems, exposing OT networks to potential exploits&nbsp;&nbsp;Industrial Cyber","title":"CISA flags critical ICS vulnerabilities across Rockwell and ABB Systems, exposing OT networks to potential exploits - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-2acab31013d50cd6","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi-wFBVV95cUxNR0dDY19MUHZqNUFTTWZFV3pXa1o1T3dvMHVWTENjUjVqUmdrZmM2TmtMMVF0ZUtXaTB5akdzMTQ3NlZuTnBxdjZ4V1FkcTU2cE1wemttXzJKa0trZzk5OUZlOWgzRDZDdEFFR1NvcmJsN0ItdGxxLTgtQUNSeGEwT0tUQThqQzh1UVg1Tkx2dUgxS2s1NnBGUTBlU0FTRlNJWU1wZjJXdjZhU19FU180RTZiaEozNHN0SmtHRXFhTjNnM1JiM3NLX3NvLTFkQmtUTWRJRk14a2NOazdkSTlkaWkyT21BQmdULVBUS2QwZHpHaWlPZnJSbEJDTQ?oc=5","published_at":"2025-09-11T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"CISA flags critical ICS vulnerabilities across Rockwell and ABB Systems, exposing OT networks to potential exploits&nbsp;&nbsp;industrialcyber.co","title":"CISA flags critical ICS vulnerabilities across Rockwell and ABB Systems, exposing OT networks to potential exploits - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-3b538aadc525dd71","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikwFBVV95cUxOUHBsejQtanBKV0J1SFdteGZ5S2dia2VrZ21mTUhodWtZWHhmd3k0OEVYRjU5WjRXRUJQWVJ5LWdZbnNFUGoxeHRnaWhIaGpralNJN0JLUTRsRmF0Nm1qTTN0aUV2bDNjYm81NWw5TVNKV2t2ZTZUWUs4OEJROXJFT3JUaFVKQ2hWR3NCSjVjbUJSNW8?oc=5","published_at":"2025-09-03T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"TYPHOON IN THE FIFTH DOMAIN : CHINA\u2019S EVOLVING CYBER STRATEGY&nbsp;&nbsp;cyfirma","title":"TYPHOON IN THE FIFTH DOMAIN : CHINA\u2019S EVOLVING CYBER STRATEGY - cyfirma"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c2e07db76a2ba394","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikwFBVV95cUxOUHBsejQtanBKV0J1SFdteGZ5S2dia2VrZ21mTUhodWtZWHhmd3k0OEVYRjU5WjRXRUJQWVJ5LWdZbnNFUGoxeHRnaWhIaGpralNJN0JLUTRsRmF0Nm1qTTN0aUV2bDNjYm81NWw5TVNKV2t2ZTZUWUs4OEJROXJFT3JUaFVKQ2hWR3NCSjVjbUJSNW8?oc=5","published_at":"2025-09-03T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"TYPHOON IN THE FIFTH DOMAIN : CHINA\u2019S EVOLVING CYBER STRATEGY&nbsp;&nbsp;cyfirma.com","title":"TYPHOON IN THE FIFTH DOMAIN : CHINA\u2019S EVOLVING CYBER STRATEGY - cyfirma.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-96d65ef097b1f555","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikwFBVV95cUxOUHBsejQtanBKV0J1SFdteGZ5S2dia2VrZ21mTUhodWtZWHhmd3k0OEVYRjU5WjRXRUJQWVJ5LWdZbnNFUGoxeHRnaWhIaGpralNJN0JLUTRsRmF0Nm1qTTN0aUV2bDNjYm81NWw5TVNKV2t2ZTZUWUs4OEJROXJFT3JUaFVKQ2hWR3NCSjVjbUJSNW8?oc=5","published_at":"2025-09-03T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"TYPHOON IN THE FIFTH DOMAIN : CHINA\u2019S EVOLVING CYBER STRATEGY&nbsp;&nbsp;Cyfirma","title":"TYPHOON IN THE FIFTH DOMAIN : CHINA\u2019S EVOLVING CYBER STRATEGY - Cyfirma"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-82de6e65e550253a","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxOSk9uMWZwZy1HOHRfajFwcmNIUGZrcmhoVFRvY3Z1QTVORzhnUUdMaU1BMzlwdmYzWFRQTm1tMDNta3FwM2NkczNnVFpvblFYUEdUZjVOcXp2QlF2V3Bwc251U25pZmZqZWFTNTJKUklSWDNLZ3RMcGNzMXA0Skx2RGlWQQ?oc=5","published_at":"2025-09-02T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Who is most at risk? Global index reveals climate vulnerability projections up to 2100&nbsp;&nbsp;Phys.org","title":"Who is most at risk? Global index reveals climate vulnerability projections up to 2100 - Phys.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ba4b363e041eb0d1","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE1LMS12OVM1RUJsZkFVTG5BZzc0MFIwWWhIZFVLSzJPQnVUbkQyX2N1NVhZajJGTEpFTEp6THNlTmRUMXN6TmxqSE5EaU8xSWttQVR1SUFYaExtWXlsazk4?oc=5","published_at":"2025-09-01T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Projections of climate change vulnerability along the Shared Socioeconomic Pathways 2020\u20132100 | Scientific Data&nbsp;&nbsp;Nature","title":"Projections of climate change vulnerability along the Shared Socioeconomic Pathways 2020\u20132100 | Scientific Data - Nature"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-88d36a4919e89fa0","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi0AFBVV95cUxQaDhLMzllOG8zNEZUM0dqaGwtdmlqWmwxdEpTbVhEd1Jfc3JoQ0FYVWlCaTl1NGJXTDdQbFFkV0Jad1FBVW9xSy14eVJvT3JVOGZDOHMyMkR5NzhxdmxmcDZVa01UaExMN1NRZ0J5dmdTbzktQlZCcGJsQjRPRUdiZV9MeEFMcTRpczk0NU1HaGk4MHV3WFozeUNYeURqbUdkbmdueUN2Rmc3eF9UWW4xMnA0dEpRYnlNSTdwekp5US1TR3ktQmJEdXl1N01VVzFh?oc=5","published_at":"2025-09-01T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Projections of climate change vulnerability along the Shared Socioeconomic Pathways 2020\u20132100&nbsp;&nbsp;Climate Analytics","title":"Projections of climate change vulnerability along the Shared Socioeconomic Pathways 2020\u20132100 - Climate Analytics"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e36ef675c4e39c92","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi0AFBVV95cUxQaDhLMzllOG8zNEZUM0dqaGwtdmlqWmwxdEpTbVhEd1Jfc3JoQ0FYVWlCaTl1NGJXTDdQbFFkV0Jad1FBVW9xSy14eVJvT3JVOGZDOHMyMkR5NzhxdmxmcDZVa01UaExMN1NRZ0J5dmdTbzktQlZCcGJsQjRPRUdiZV9MeEFMcTRpczk0NU1HaGk4MHV3WFozeUNYeURqbUdkbmdueUN2Rmc3eF9UWW4xMnA0dEpRYnlNSTdwekp5US1TR3ktQmJEdXl1N01VVzFh?oc=5","published_at":"2025-09-01T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Projections of climate change vulnerability along the Shared Socioeconomic Pathways 2020\u20132100&nbsp;&nbsp;climateanalytics.org","title":"Projections of climate change vulnerability along the Shared Socioeconomic Pathways 2020\u20132100 - climateanalytics.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a03d4d6974dbb146","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE1LMS12OVM1RUJsZkFVTG5BZzc0MFIwWWhIZFVLSzJPQnVUbkQyX2N1NVhZajJGTEpFTEp6THNlTmRUMXN6TmxqSE5EaU8xSWttQVR1SUFYaExtWXlsazk4?oc=5","published_at":"2025-09-01T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Projections of climate change vulnerability along the Shared Socioeconomic Pathways 2020\u20132100 | Scientific Data&nbsp;&nbsp;nature.com","title":"Projections of climate change vulnerability along the Shared Socioeconomic Pathways 2020\u20132100 | Scientific Data - nature.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9da2ea48327be5b7","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxQZ1ZjMzZzdlluRFVvTlFHemkzNEJEajdPMGdNdEZNcjQ5ZjI2UUhIclVxZWg1OVBKOUxjMDh1dm4wZTFseDhvS0VkWEF6OENuX0xLMTE1Q1RpeF94ZDRWcEZ5TkVGVXBZbFJIbFFhU3dxMlVkbmhlYXlaVjFaNGx5M09XQndUWVZKS0J0YkNEVG4tSlN1TkRLaXFYVVFnZEFTNHdZX1Q0VmM?oc=5","published_at":"2025-08-29T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"PoC Code in 15 Minutes? AI Turbocharges Exploitation&nbsp;&nbsp;darkreading.com","title":"PoC Code in 15 Minutes? AI Turbocharges Exploitation - darkreading.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f9eec2788ec05030","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxQZ1ZjMzZzdlluRFVvTlFHemkzNEJEajdPMGdNdEZNcjQ5ZjI2UUhIclVxZWg1OVBKOUxjMDh1dm4wZTFseDhvS0VkWEF6OENuX0xLMTE1Q1RpeF94ZDRWcEZ5TkVGVXBZbFJIbFFhU3dxMlVkbmhlYXlaVjFaNGx5M09XQndUWVZKS0J0YkNEVG4tSlN1TkRLaXFYVVFnZEFTNHdZX1Q0VmM?oc=5","published_at":"2025-08-29T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"PoC Code in 15 Minutes? AI Turbocharges Exploitation&nbsp;&nbsp;Dark Reading","title":"PoC Code in 15 Minutes? AI Turbocharges Exploitation - Dark Reading"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-563dff33520776fa","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE92eXBKN3BaTWlOSmtnSF9ERWhSendBUl9fbUUwS3VvSEhvN0pDYTFxSlhyNnlOSjF2NzRpRHlCeDVtMnV5UTdxcDM5MDhpVnUtVWdQQV9Fd0FBUi1BVl84?oc=5","published_at":"2025-08-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"A method for preliminary assessment of the vulnerability to climate change of tree species for urban afforestation&nbsp;&nbsp;nature.com","title":"A method for preliminary assessment of the vulnerability to climate change of tree species for urban afforestation - nature.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e2bb0c9f4658cf7f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE92eXBKN3BaTWlOSmtnSF9ERWhSendBUl9fbUUwS3VvSEhvN0pDYTFxSlhyNnlOSjF2NzRpRHlCeDVtMnV5UTdxcDM5MDhpVnUtVWdQQV9Fd0FBUi1BVl84?oc=5","published_at":"2025-08-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"A method for preliminary assessment of the vulnerability to climate change of tree species for urban afforestation&nbsp;&nbsp;Nature","title":"A method for preliminary assessment of the vulnerability to climate change of tree species for urban afforestation - Nature"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-4e53fa978cb40a8d","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMikgFBVV95cUxQWFBWRS0wMW9zVEFBMW9nVURnaGVjV2N0cmpzSXU3ZFRVRmdjU29PX3JjYUIyWjdqblZsLU1wbzNfbVdiZUdHNzBySnVJQjdTLXpuNjJuVlRuNEEtdjlwSHd2cTVqbjZpcURoTktMcXdCWV9WUVhQNWNkN002Q1FzNzRGcGNQSUFVVkZaa2hRVElIUQ?oc=5","published_at":"2025-08-20T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Industrial Switch Security","summary":"FBI, Cisco warn of Russia-linked hackers targeting critical infrastructure organizations&nbsp;&nbsp;cybersecuritydive.com","title":"FBI, Cisco warn of Russia-linked hackers targeting critical infrastructure organizations - cybersecuritydive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-863a04e767f2e973","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMikgFBVV95cUxQWFBWRS0wMW9zVEFBMW9nVURnaGVjV2N0cmpzSXU3ZFRVRmdjU29PX3JjYUIyWjdqblZsLU1wbzNfbVdiZUdHNzBySnVJQjdTLXpuNjJuVlRuNEEtdjlwSHd2cTVqbjZpcURoTktMcXdCWV9WUVhQNWNkN002Q1FzNzRGcGNQSUFVVkZaa2hRVElIUQ?oc=5","published_at":"2025-08-20T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Industrial Switch Security","summary":"FBI, Cisco warn of Russia-linked hackers targeting critical infrastructure organizations&nbsp;&nbsp;Cybersecurity Dive","title":"FBI, Cisco warn of Russia-linked hackers targeting critical infrastructure organizations - Cybersecurity Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-c72e9a12f199eb4a","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMigAFBVV95cUxOYS1STVhzQW4xaXFMMU01QXZBakZEUUpSV1gtZTdXZ2hkZXlCRUVrTFBEZThpcWJWTDFpMjJ6M0d1WE1lOEtxRjBTY3ZBbDEwWWE1SFQ3VllaUmZwaHI3eDM0SVNzbldQYnRwTkhvaGNPVmwzaURTQXJnc2MyLVFOcg?oc=5","published_at":"2025-08-18T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Rockwell ControlLogix Ethernet Vulnerability Let Attackers Execute Remote Code&nbsp;&nbsp;CyberSecurityNews","title":"Rockwell ControlLogix Ethernet Vulnerability Let Attackers Execute Remote Code - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-e991c0eecbad61cc","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxOX3hKZlJJbWJ4M2x1eVZ3NGszdnlYTVZseDlyVS1CZHdlbFh1RHNyZU5nbUNMa09QR0lSMk9sblc3MDJ4MHBfa1pFakxqdEwzTzJhX1BFd21XdGJIdjV3RDg0aC1zcGJfS0hrOGtXWlBpNmpTdXlNUm9LTllFNzFmVlJBd09rWkxqSnZyZ1NtOF9ISk80aThreTRseEhrSEM4bmtnSkVVRVpBQWfSAbABQVVfeXFMTWVoY0g4NXNTLTVMdldjaGk1MnZBSGRvV3Rxcm01a1I1WkpsWFRwMTdwdUVMWWdIT3A3ekNNOVR6TG9oSm5PY2QxLWt1ZHFnZnBtMy1rZjVZWG5USkdtTEwzTVlMYzdLd1Zjdlk0cHJ1VTR0cjVONEY4SEg4MDJidzN1NVEzUXduNk9WUDlveVpTbGxlUHM5NmFWSHZlR2hUOW5kcVlWajVBc2VuVk5XREU?oc=5","published_at":"2025-08-15T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Critical Flaws Patched in Rockwell FactoryTalk, Micro800, ControlLogix Products&nbsp;&nbsp;SecurityWeek","title":"Critical Flaws Patched in Rockwell FactoryTalk, Micro800, ControlLogix Products - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-a287c4a3f766e75e","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxOX3hKZlJJbWJ4M2x1eVZ3NGszdnlYTVZseDlyVS1CZHdlbFh1RHNyZU5nbUNMa09QR0lSMk9sblc3MDJ4MHBfa1pFakxqdEwzTzJhX1BFd21XdGJIdjV3RDg0aC1zcGJfS0hrOGtXWlBpNmpTdXlNUm9LTllFNzFmVlJBd09rWkxqSnZyZ1NtOF9ISk80aThreTRseEhrSEM4bmtnSkVVRVpBQWfSAbABQVVfeXFMTWVoY0g4NXNTLTVMdldjaGk1MnZBSGRvV3Rxcm01a1I1WkpsWFRwMTdwdUVMWWdIT3A3ekNNOVR6TG9oSm5PY2QxLWt1ZHFnZnBtMy1rZjVZWG5USkdtTEwzTVlMYzdLd1Zjdlk0cHJ1VTR0cjVONEY4SEg4MDJidzN1NVEzUXduNk9WUDlveVpTbGxlUHM5NmFWSHZlR2hUOW5kcVlWajVBc2VuVk5XREU?oc=5","published_at":"2025-08-15T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Critical Flaws Patched in Rockwell FactoryTalk, Micro800, ControlLogix Products&nbsp;&nbsp;securityweek.com","title":"Critical Flaws Patched in Rockwell FactoryTalk, Micro800, ControlLogix Products - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-49e99c2ccdcfed8a","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi0gFBVV95cUxNamZkeldhZnlzby04bzY1Mi00Y2FIUFFLQzlHZUFtYkRjdWlkSGJDTFdER01wTDNOSWFQemN3d3BONDJqM0JzTkxlbzYxQUhvc0doMU9VYTk1S1l6TkdZbTNZejhXTnNvYWhxRlNUWVpZaGkxMTBlWGJXNGY1bXg3VHFDcHVPNE5qeHU0di0tbW9ySTBBbXRmVXRWYm5DUXRkWlFaeDBCS0pXbmdPcGlQTC1Ba2tYN240ZXpJV2ZpUFpUU0tQbE9sUWJpVkJJRU9jRXc?oc=5","published_at":"2025-08-11T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"ICS systems face elevated cyber risk as CISA issues advisories covering multiple vendor vulnerabilities&nbsp;&nbsp;Industrial Cyber","title":"ICS systems face elevated cyber risk as CISA issues advisories covering multiple vendor vulnerabilities - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7f30aacc994b449e","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi0gFBVV95cUxNamZkeldhZnlzby04bzY1Mi00Y2FIUFFLQzlHZUFtYkRjdWlkSGJDTFdER01wTDNOSWFQemN3d3BONDJqM0JzTkxlbzYxQUhvc0doMU9VYTk1S1l6TkdZbTNZejhXTnNvYWhxRlNUWVpZaGkxMTBlWGJXNGY1bXg3VHFDcHVPNE5qeHU0di0tbW9ySTBBbXRmVXRWYm5DUXRkWlFaeDBCS0pXbmdPcGlQTC1Ba2tYN240ZXpJV2ZpUFpUU0tQbE9sUWJpVkJJRU9jRXc?oc=5","published_at":"2025-08-11T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"ICS systems face elevated cyber risk as CISA issues advisories covering multiple vendor vulnerabilities&nbsp;&nbsp;industrialcyber.co","title":"ICS systems face elevated cyber risk as CISA issues advisories covering multiple vendor vulnerabilities - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4a3b494d58faa700","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMigAFBVV95cUxNTWVTWFJLajRIeGhBZTZNdzd6ZmJPQkFVV3hHWVFJTVJ4WE1FTFF3bE1jeTQ0M1VYeHc5SVRhYmJDMU1QbFdidkliV3JYSWo2RVRFMEtZWVVCaUpaUUVnRWtzam0wT3VKVGE2VGRLT2M2NHhwLUVUVVlPZkppQXRhVw?oc=5","published_at":"2025-08-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Climate-Change Vulnerability and Climate Migration: Evidence from Guatemala&nbsp;&nbsp;american.edu","title":"Climate-Change Vulnerability and Climate Migration: Evidence from Guatemala - american.edu"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-89b47a7404e3aea1","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMigAFBVV95cUxNTWVTWFJLajRIeGhBZTZNdzd6ZmJPQkFVV3hHWVFJTVJ4WE1FTFF3bE1jeTQ0M1VYeHc5SVRhYmJDMU1QbFdidkliV3JYSWo2RVRFMEtZWVVCaUpaUUVnRWtzam0wT3VKVGE2VGRLT2M2NHhwLUVUVVlPZkppQXRhVw?oc=5","published_at":"2025-08-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Climate-Change Vulnerability and Climate Migration: Evidence from Guatemala&nbsp;&nbsp;American University","title":"Climate-Change Vulnerability and Climate Migration: Evidence from Guatemala - American University"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-4e073dd2843ddd3b","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMic0FVX3lxTFBCUjdnU2l2bmlIZTEwaGVMT2ZVa3lCaDhtd0c1RFBkMkpSTDZPbjBpSFpVZ0d5NHRKZnFlYnhJc256ZXF4NTU0aUFlT2NiVjNaRFg2b3RwSGxieF9OVkN0NGtrZTFDZnBtMGlLU0JBbmtHcmvSAXNBVV95cUxQQlI3Z1Npdm5pSGUxMGhlTE9mVWt5Qmg4bXdHNURQZDJKUkw2T24waUhaVWdHeTR0SmZxZWJ4SXNuemVxeDU1NGlBZU9jYlYzWkRYNm90cEhsYnhfTlZDdDRra2UxQ2ZwbTBpS1NCQW5rR3Jr?oc=5","published_at":"2025-08-06T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"HIGH","source":"Rockwell & CIP Security","summary":"Rockwell Arena Simulation Vulnerabilities Allow Remote Code Execution by Attackers&nbsp;&nbsp;cyberpress.org","title":"Rockwell Arena Simulation Vulnerabilities Allow Remote Code Execution by Attackers - cyberpress.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-03cc466965eab8ac","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiZEFVX3lxTE5JNUlBT052MEgwQ2JFR1lOTjVfa1NxVWJoTkFKODFPWWVxWnhJSGZSb2ktREpkTEpCUWQ5VlpUYkZRN1gxbHRzOFBsS1RDNlVERlM2T0d5cmh0RjVCaVdLTUpJVUI?oc=5","published_at":"2025-08-06T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Rockwell Arena Simulation Flaws Allow Remote Execution of Malicious Code&nbsp;&nbsp;gbhackers.com","title":"Rockwell Arena Simulation Flaws Allow Remote Execution of Malicious Code - gbhackers.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-5220df894d1388d8","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMikgFBVV95cUxNSXZFdHV0SVM0dDdKQm0yRGJEcnVkQThmVklNVWpfVGxYdWY5MzVZb21JLUdWUUlaTnRYSzRaXzFFVC1uRGdmZFRVV3JWWVMtT0lSY0VQMWc4ZDd3NzZsVjJROHhKMndPVExiaTNfTU5ZbmpxWllxcTRxOWNma2xsT0JGS3V5aVFIdW1XMFVlVDQ5dw?oc=5","published_at":"2025-07-31T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"Feds still trying to crack Volt Typhoon hackers\u2019 intentions, goals&nbsp;&nbsp;CyberScoop","title":"Feds still trying to crack Volt Typhoon hackers\u2019 intentions, goals - CyberScoop"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-89b094127000ed7e","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMia0FVX3lxTE9xSWV2dlhwdThxVmZfcC1VcENsdDRaMTBRVEpQOEhGTDdvWVpwMkNWV3dlYXozTmkyOVlwZDNiOFQ1ZHZxTWJJdHdtM1V4QlY5NkdDeHUzbWgyR01Pa2dWOWJWT2ZWbmd0MzUw?oc=5","published_at":"2025-07-30T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Laid Off From IT? How to Transfer to a Cybersecurity Role.&nbsp;&nbsp;builtin.com","title":"Laid Off From IT? How to Transfer to a Cybersecurity Role. - builtin.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-3b573969ce5d9df3","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMia0FVX3lxTE9xSWV2dlhwdThxVmZfcC1VcENsdDRaMTBRVEpQOEhGTDdvWVpwMkNWV3dlYXozTmkyOVlwZDNiOFQ1ZHZxTWJJdHdtM1V4QlY5NkdDeHUzbWgyR01Pa2dWOWJWT2ZWbmd0MzUw?oc=5","published_at":"2025-07-30T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Laid Off From IT? How to Transfer to a Cybersecurity Role.&nbsp;&nbsp;Built In","title":"Laid Off From IT? How to Transfer to a Cybersecurity Role. - Built In"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-cd5795ba14dba725","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi5wFBVV95cUxPaXh2WnJWU0JubzFMOXhsZTJOZFVzTGxvVmJ0VWdxSnptRW5NcDc2VlpLZUQwcXFHVzUzdDdtczBHdVhaMkp5MGF5VVQyUDJHUzFXR3liM25RbGM2ckk1TUU2bkNvS3FTOVQ4d21ieTEtN3h0c2p5X3UxR3JTcEh2TWNkSUVRQmY3TVVKckNLb1RtdlhRTUFmN1lTVDRzSER5UkNnUVdyWWtaU1ZXY3pEOG5jTS0xeW92UDVBRDB5Z1lySXpCeWtiTU0yWG9nQVdwR0k0cEczWnZqcXdvaTdPTDZnY0tvSm8?oc=5","published_at":"2025-07-29T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Nozomi uncovers 13 vulnerabilities in Tridium Niagara Framework affecting smart buildings, industrial systems&nbsp;&nbsp;industrialcyber.co","title":"Nozomi uncovers 13 vulnerabilities in Tridium Niagara Framework affecting smart buildings, industrial systems - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-71589480e73d585e","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi5wFBVV95cUxPaXh2WnJWU0JubzFMOXhsZTJOZFVzTGxvVmJ0VWdxSnptRW5NcDc2VlpLZUQwcXFHVzUzdDdtczBHdVhaMkp5MGF5VVQyUDJHUzFXR3liM25RbGM2ckk1TUU2bkNvS3FTOVQ4d21ieTEtN3h0c2p5X3UxR3JTcEh2TWNkSUVRQmY3TVVKckNLb1RtdlhRTUFmN1lTVDRzSER5UkNnUVdyWWtaU1ZXY3pEOG5jTS0xeW92UDVBRDB5Z1lySXpCeWtiTU0yWG9nQVdwR0k0cEczWnZqcXdvaTdPTDZnY0tvSm8?oc=5","published_at":"2025-07-29T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Nozomi uncovers 13 vulnerabilities in Tridium Niagara Framework affecting smart buildings, industrial systems&nbsp;&nbsp;Industrial Cyber","title":"Nozomi uncovers 13 vulnerabilities in Tridium Niagara Framework affecting smart buildings, industrial systems - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b8e1a480d93cd63f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMieEFVX3lxTE9oYUlMbmdPVFBoY1lsc01qZjd5a1RvN3dxX0FfaUtoMnZnYU5nOUF2WHpLbFpJQ1BQeFVZNkNDUjdIYVFPdEV2aWZ4WjRYM1BFb3RQcEdSSkdUVDJjckE3X2ZWNnd6eDZvaVZneDFiYXdiZlVWNjMzZA?oc=5","published_at":"2025-07-28T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Climate Change Vulnerability & Resilience&nbsp;&nbsp;storymaps.arcgis.com","title":"Climate Change Vulnerability & Resilience - storymaps.arcgis.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b09253aa49a8b2cf","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMif0FVX3lxTE9ZQWZmM0t6dW9iUTZud05IV2R3YXFiUU82Vl9pMTRMUERPeE94MEtLdkV3Qko2R3phZ0p1c204NDVYZ0lBWXNpV1lTckNlbGZVSGhLNXFiZkpsZldLRnd5OUR2d3R5aGdubExuRXNLR2c3bWN2VDBYaWdqSmh5Wk0?oc=5","published_at":"2025-07-28T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Critical Flaws in Niagara Framework Threaten Smart Buildings and Industrial Systems Worldwide&nbsp;&nbsp;The Hacker News","title":"Critical Flaws in Niagara Framework Threaten Smart Buildings and Industrial Systems Worldwide - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-27151dfc0b1960da","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMieEFVX3lxTE9oYUlMbmdPVFBoY1lsc01qZjd5a1RvN3dxX0FfaUtoMnZnYU5nOUF2WHpLbFpJQ1BQeFVZNkNDUjdIYVFPdEV2aWZ4WjRYM1BFb3RQcEdSSkdUVDJjckE3X2ZWNnd6eDZvaVZneDFiYXdiZlVWNjMzZA?oc=5","published_at":"2025-07-28T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Climate Change Vulnerability & Resilience&nbsp;&nbsp;ArcGIS StoryMaps","title":"Climate Change Vulnerability & Resilience - ArcGIS StoryMaps"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b8490b371543d2e7","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMif0FVX3lxTE9ZQWZmM0t6dW9iUTZud05IV2R3YXFiUU82Vl9pMTRMUERPeE94MEtLdkV3Qko2R3phZ0p1c204NDVYZ0lBWXNpV1lTckNlbGZVSGhLNXFiZkpsZldLRnd5OUR2d3R5aGdubExuRXNLR2c3bWN2VDBYaWdqSmh5Wk0?oc=5","published_at":"2025-07-28T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Critical Flaws in Niagara Framework Threaten Smart Buildings and Industrial Systems Worldwide&nbsp;&nbsp;thehackernews.com","title":"Critical Flaws in Niagara Framework Threaten Smart Buildings and Industrial Systems Worldwide - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d0b2ec84d8910c56","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxNV2YzamZ0ZTJ0YlQzZ05LRUFaRndrakw4SjFSVEk3Wlc4Q2czUzN6dWpRVkFrNWVEdk9pVmZRNE80TVpOQTVkbFpJSWxvU0RUeEVrTFFELWVSZF9qUS0yZmIyN0dOZi1mSEIzQ0pMbjE3dWdzWG5OX2FxMWYyRHJzaEdyUjV4VnRWVXJSNFlZT2lhRGFlY0xmbEZTZ0ZVdy1iY0FGaDFneHhtOVF0a2c?oc=5","published_at":"2025-07-25T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"Honeywell vulnerability exposes building systems to cyber attacks&nbsp;&nbsp;facilitiesdive.com","title":"Honeywell vulnerability exposes building systems to cyber attacks - facilitiesdive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-cf85ffe31336b45c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiZEFVX3lxTE8yV1BYTU5KR0JwckM4ODYwN2NPc0RRa1V6M3NSdHd1azBBZUpxLUdsbnFFeHNheVFSLWJ6ZWwwTGkxcExLSnZ5STJsSzg0emhFaDJvYjQyQUYwMDJsODloS2RISlo?oc=5","published_at":"2025-07-25T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"Tridium Niagara Framework Flaws Expose Sensitive Network Data&nbsp;&nbsp;gbhackers.com","title":"Tridium Niagara Framework Flaws Expose Sensitive Network Data - gbhackers.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b73ce734bf2f602a","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxNV2YzamZ0ZTJ0YlQzZ05LRUFaRndrakw4SjFSVEk3Wlc4Q2czUzN6dWpRVkFrNWVEdk9pVmZRNE80TVpOQTVkbFpJSWxvU0RUeEVrTFFELWVSZF9qUS0yZmIyN0dOZi1mSEIzQ0pMbjE3dWdzWG5OX2FxMWYyRHJzaEdyUjV4VnRWVXJSNFlZT2lhRGFlY0xmbEZTZ0ZVdy1iY0FGaDFneHhtOVF0a2c?oc=5","published_at":"2025-07-25T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"Honeywell vulnerability exposes building systems to cyber attacks&nbsp;&nbsp;Facilities Dive","title":"Honeywell vulnerability exposes building systems to cyber attacks - Facilities Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f0586f4e9f5b2c81","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijAFBVV95cUxPRWVlbmliVnBnTEJqcHNXSVBZYWVkNFZseXhLSkZpZ0taeU16LWd3NVR0bGJLYkFwb29VZzB3Vk5mcThQWlV5TXQyNzd3bGZXWDZpbFU2VkpndDFybzF6R0ZHc1o3akwyV0pOejZmU051QjJjUkc2RkRTOVNac0JmX3RnZi0ydFF2RkVXUA?oc=5","published_at":"2025-07-25T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Multiple Vulnerabilities in Tridium Niagara Framework Let Attacker to Collect Sensitive Data from the Network&nbsp;&nbsp;cybersecuritynews.com","title":"Multiple Vulnerabilities in Tridium Niagara Framework Let Attacker to Collect Sensitive Data from the Network - cybersecuritynews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-42019dec21177307","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijAFBVV95cUxPRWVlbmliVnBnTEJqcHNXSVBZYWVkNFZseXhLSkZpZ0taeU16LWd3NVR0bGJLYkFwb29VZzB3Vk5mcThQWlV5TXQyNzd3bGZXWDZpbFU2VkpndDFybzF6R0ZHc1o3akwyV0pOejZmU051QjJjUkc2RkRTOVNac0JmX3RnZi0ydFF2RkVXUA?oc=5","published_at":"2025-07-25T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Multiple Vulnerabilities in Tridium Niagara Framework Let Attacker to Collect Sensitive Data from the Network&nbsp;&nbsp;CyberSecurityNews","title":"Multiple Vulnerabilities in Tridium Niagara Framework Let Attacker to Collect Sensitive Data from the Network - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-a60b93f1810797a7","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi6AFBVV95cUxOTGQzd0RaQkxHYnRtMUlmcnlYdTZDNDdWby1GeUZITmVIZGxyTzdmc2trLTFuRWRIWGdFRDhHd1FWRmtpZE5ZMDZMWU10UXluOWNxbzMwUjZIVnRPU3VubTRacktpYWJzckZVRzZEd3hSZm1fVlZBVzc5SmM3dTd6ZGlxV3NDQjhRQklPZ0w0Q2dXVGE4blV2aHB6Vk1LczdHNHNLUHhhUHBFSGlRR3h2cjh4YWt0T29rZ000cE55bkRQVHhjY3JDVmtFejIzbGgzZDBuazB1TnljVkhuQ1JCbEc5R2pvMWps?oc=5","published_at":"2025-07-17T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"DHS: Salt Typhoon hackers breached Army National Guard, exposing admin credentials and network diagrams&nbsp;&nbsp;industrialcyber.co","title":"DHS: Salt Typhoon hackers breached Army National Guard, exposing admin credentials and network diagrams - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-21b0b75e1d442daf","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi6AFBVV95cUxOTGQzd0RaQkxHYnRtMUlmcnlYdTZDNDdWby1GeUZITmVIZGxyTzdmc2trLTFuRWRIWGdFRDhHd1FWRmtpZE5ZMDZMWU10UXluOWNxbzMwUjZIVnRPU3VubTRacktpYWJzckZVRzZEd3hSZm1fVlZBVzc5SmM3dTd6ZGlxV3NDQjhRQklPZ0w0Q2dXVGE4blV2aHB6Vk1LczdHNHNLUHhhUHBFSGlRR3h2cjh4YWt0T29rZ000cE55bkRQVHhjY3JDVmtFejIzbGgzZDBuazB1TnljVkhuQ1JCbEc5R2pvMWps?oc=5","published_at":"2025-07-17T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"DHS: Salt Typhoon hackers breached Army National Guard, exposing admin credentials and network diagrams&nbsp;&nbsp;Industrial Cyber","title":"DHS: Salt Typhoon hackers breached Army National Guard, exposing admin credentials and network diagrams - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-8dc44b118eb467ad","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMib0FVX3lxTE80ZWRFM2J5S3pYZWtPNmhlbEVVSkktTWx0WUJNQ2JjeWNvZ3pRUzFiZy1QajlSYjgxNVFCS0NGeDE0eWozVTJuZktyblFSbElEYzlBWUJwa3dITkhKSmFiTmJNaEZCN0YyOGdsb0RwNA?oc=5","published_at":"2025-07-15T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"NSA: Volt Typhoon was \u2018not successful\u2019 at persisting in critical infrastructure&nbsp;&nbsp;The Record from Recorded Future News","title":"NSA: Volt Typhoon was \u2018not successful\u2019 at persisting in critical infrastructure - The Record from Recorded Future News"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-655192e033b7ac5b","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMifkFVX3lxTFBrLTBwMzZHeDhrdGlWVUJHX3BkY25jWmFtcldPYUh2VmZEc0lST0dqWnU0RHZFTzlUQXAtcU9OSFZOdURXa3dVV0xfSEJtTWt4YmlIcWVDdW1xMUJGVVdWd2xCY1ZVMXRJM2s0cUwxWTl6WmRtdVk4M29lUldxQQ?oc=5","published_at":"2025-07-15T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"What It Takes to Stop the Next Salt Typhoon&nbsp;&nbsp;Just Security","title":"What It Takes to Stop the Next Salt Typhoon - Just Security"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-db48897edebc0885","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMitgFBVV95cUxNbGFkcU94ckJubVhORUk0V0Y2THJpWnJtTEYxTmhmYmpTRUJPTTJaZTlQSi1SM3M5eGZ1djVsYlFPbU1WMUFWZ2c3Tkg5N2JqdExhY2d5MU5nZW9lZkhFdndtOERrN2dfRWJWM1B4VlZPQS1FVjMyb1NkQ1VlS2VVa1c4Ylk5d180SG5XZnJQSFBkWDVsUklJUVpwei1JNF9ZRm91MW9nQUFfMnJfbXFnMXdRM08tQQ?oc=5","published_at":"2025-07-11T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Senate panel pushing DOD on strategy to deter Chinese cyber activity on critical infrastructure&nbsp;&nbsp;DefenseScoop","title":"Senate panel pushing DOD on strategy to deter Chinese cyber activity on critical infrastructure - DefenseScoop"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-cb73a5640b050ca9","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMioAFBVV95cUxQMkdEZUQ3dUxIdVFTampTeV9EVC1YWlBiM1FrZ2w3V3VRczlBT3pvNTAweXZTcG9JSWRrT2I0RlhmeGtvX2RETmlBbzdveERwTENWODNwYXdscGR2NVNDVGJXbEdUUE5rLTA0WUFTeW0xRjdneXV6ZE94U3dleDNQRzVEUktqeEVPODJjSWt6ZTFUV21ZeGtqSWVQOVZ3bFlQ?oc=5","published_at":"2025-07-09T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Editorial: Climate change vulnerability, adaptation, and human settlements&nbsp;&nbsp;Frontiers","title":"Editorial: Climate change vulnerability, adaptation, and human settlements - Frontiers"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-c2459d3af24c5ed6","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMioAFBVV95cUxQMkdEZUQ3dUxIdVFTampTeV9EVC1YWlBiM1FrZ2w3V3VRczlBT3pvNTAweXZTcG9JSWRrT2I0RlhmeGtvX2RETmlBbzdveERwTENWODNwYXdscGR2NVNDVGJXbEdUUE5rLTA0WUFTeW0xRjdneXV6ZE94U3dleDNQRzVEUktqeEVPODJjSWt6ZTFUV21ZeGtqSWVQOVZ3bFlQ?oc=5","published_at":"2025-07-09T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Editorial: Climate change vulnerability, adaptation, and human settlements&nbsp;&nbsp;frontiersin.org","title":"Editorial: Climate change vulnerability, adaptation, and human settlements - frontiersin.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c2a5d9754f5f7101","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijwFBVV95cUxNcXd3RURJU2JZVkdQXzhEaUE5NXBDVW4wdG9PZ0FWdk5zckR2RDhvZi1FdE1FMGJkMkhVaEVMeS1WbjNGcmtFZ2pZanZuX2RCaDZYdzVkUFdpVllJY3BMbm5tU1phQ1lqRGtxc3M0Ym5TOVh4a3M4LXNLb3NOVVBwYmJBZ3l2NkJ3YkVZaGdnZw?oc=5","published_at":"2025-07-04T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"The Cybersecurity Bomb Ticking in Smart Buildings&nbsp;&nbsp;bankinfosecurity.com","title":"The Cybersecurity Bomb Ticking in Smart Buildings - bankinfosecurity.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-3d9d01cfd2db3c23","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihwFBVV95cUxPNUhmVFNZRW9tQWRzMVpDLWIyMF9yMTc5NnhVd2ZIaVRlMWJSd0l0RUx4T3Z6M3RFTXlJczdEdjlSUlZJZllLd0djUzA1OTNWRHpFNC1rUGNkYUR1ZGxjRDVYSERCMFRXMkg3b1Y5NThqR0FrOFB2LXB0M0hrQWNtc3d5aVRWM1U?oc=5","published_at":"2025-07-04T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Exposed and unaware? Smart buildings need smarter risk controls&nbsp;&nbsp;Help Net Security","title":"Exposed and unaware? Smart buildings need smarter risk controls - Help Net Security"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c64fbd5f6435abe8","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijwFBVV95cUxNcXd3RURJU2JZVkdQXzhEaUE5NXBDVW4wdG9PZ0FWdk5zckR2RDhvZi1FdE1FMGJkMkhVaEVMeS1WbjNGcmtFZ2pZanZuX2RCaDZYdzVkUFdpVllJY3BMbm5tU1phQ1lqRGtxc3M0Ym5TOVh4a3M4LXNLb3NOVVBwYmJBZ3l2NkJ3YkVZaGdnZw?oc=5","published_at":"2025-07-04T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"The Cybersecurity Bomb Ticking in Smart Buildings&nbsp;&nbsp;BankInfoSecurity","title":"The Cybersecurity Bomb Ticking in Smart Buildings - BankInfoSecurity"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e1ca3ba225e40e2f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihwFBVV95cUxPNUhmVFNZRW9tQWRzMVpDLWIyMF9yMTc5NnhVd2ZIaVRlMWJSd0l0RUx4T3Z6M3RFTXlJczdEdjlSUlZJZllLd0djUzA1OTNWRHpFNC1rUGNkYUR1ZGxjRDVYSERCMFRXMkg3b1Y5NThqR0FrOFB2LXB0M0hrQWNtc3d5aVRWM1U?oc=5","published_at":"2025-07-04T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Exposed and unaware? Smart buildings need smarter risk controls&nbsp;&nbsp;helpnetsecurity.com","title":"Exposed and unaware? Smart buildings need smarter risk controls - helpnetsecurity.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-d2d78749fe6f2f98","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi9AFBVV95cUxPTWc0Q0laaTVNWlR5Z1RhSjZlS0thQzhFTDFxbXRvSEJGTW9HWW9fbmlsc3c3NmtndlNra2JZZnhBN21qUDZ3THhLM3pJZGkwZGlWR1ptLWU4TXhzYkZMNlpJSFAtal9td19jR3hzWGhOSUJneE12d1pJV3RmZFlDUFZQT0J4c2x6eFM3eWplMWZ0ajNaenNFRU1QNDk3bDl2djdrMGxVc1NjOE5iV1NjaFVjQUtFRmk3REwzY0lIbS1QTDdQOGlHNWQ0SDNrOEU1QWRZVkxJRGtqZVJKam41MGIyZGU4ME95SG94VmVFNkY2eUZ2?oc=5","published_at":"2025-07-01T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Lake Risevatnet dam hack exposes industrial cyber gaps as weak passwords risk critical infrastructure attacks&nbsp;&nbsp;Industrial Cyber","title":"Lake Risevatnet dam hack exposes industrial cyber gaps as weak passwords risk critical infrastructure attacks - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-d6dda590e38311bd","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi9AFBVV95cUxPTWc0Q0laaTVNWlR5Z1RhSjZlS0thQzhFTDFxbXRvSEJGTW9HWW9fbmlsc3c3NmtndlNra2JZZnhBN21qUDZ3THhLM3pJZGkwZGlWR1ptLWU4TXhzYkZMNlpJSFAtal9td19jR3hzWGhOSUJneE12d1pJV3RmZFlDUFZQT0J4c2x6eFM3eWplMWZ0ajNaenNFRU1QNDk3bDl2djdrMGxVc1NjOE5iV1NjaFVjQUtFRmk3REwzY0lIbS1QTDdQOGlHNWQ0SDNrOEU1QWRZVkxJRGtqZVJKam41MGIyZGU4ME95SG94VmVFNkY2eUZ2?oc=5","published_at":"2025-07-01T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Lake Risevatnet dam hack exposes industrial cyber gaps as weak passwords risk critical infrastructure attacks&nbsp;&nbsp;industrialcyber.co","title":"Lake Risevatnet dam hack exposes industrial cyber gaps as weak passwords risk critical infrastructure attacks - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-818ff22c3b0c7148","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMifkFVX3lxTE9kbldpQUxJbC1VUkNtcXg4cUNuTldWZHFLYkN1dVg3eEVacEloU0ZkajJiR19sRC1reTJWa3ZFcnV5SzFCVEZJc2xOd29icFV3RG1pZWQwbVlpZWkxazRlYzNLckYyOFRTQ3hFWnk5VkVIRk50aUJoVkwzOW5vQQ?oc=5","published_at":"2025-06-30T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"U.S. Agencies Warn of Rising Iranian Cyber Attacks on Defense, OT Networks, and Critical Infrastructure&nbsp;&nbsp;thehackernews.com","title":"U.S. Agencies Warn of Rising Iranian Cyber Attacks on Defense, OT Networks, and Critical Infrastructure - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-0b49cbffe111fee8","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMifkFVX3lxTE9kbldpQUxJbC1VUkNtcXg4cUNuTldWZHFLYkN1dVg3eEVacEloU0ZkajJiR19sRC1reTJWa3ZFcnV5SzFCVEZJc2xOd29icFV3RG1pZWQwbVlpZWkxazRlYzNLckYyOFRTQ3hFWnk5VkVIRk50aUJoVkwzOW5vQQ?oc=5","published_at":"2025-06-30T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"U.S. Agencies Warn of Rising Iranian Cyber Attacks on Defense, OT Networks, and Critical Infrastructure&nbsp;&nbsp;The Hacker News","title":"U.S. Agencies Warn of Rising Iranian Cyber Attacks on Defense, OT Networks, and Critical Infrastructure - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d1c264aae3f1c1ec","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMigAFBVV95cUxNTy1DLU9Fck5BbjJQc00wUmxmLTRNQm1Fa3ZrM2VleDBOWFNmN3UtU19nOVY5ZWFDQXVJaFZNWDg2STRLR2VqanJsTkZmeXJIUzliWkhwQ0NOMk1FV00wVU01Njl3cWhWUmZENG5YckFnMWNSX0c2UlpwWXVHYmxpUA?oc=5","published_at":"2025-06-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"Mitsubishi Electric AC Systems Vulnerability Allows Remote Control Without User Interaction&nbsp;&nbsp;CyberSecurityNews","title":"Mitsubishi Electric AC Systems Vulnerability Allows Remote Control Without User Interaction - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-400f68005ba1b121","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMigAFBVV95cUxNTy1DLU9Fck5BbjJQc00wUmxmLTRNQm1Fa3ZrM2VleDBOWFNmN3UtU19nOVY5ZWFDQXVJaFZNWDg2STRLR2VqanJsTkZmeXJIUzliWkhwQ0NOMk1FV00wVU01Njl3cWhWUmZENG5YckFnMWNSX0c2UlpwWXVHYmxpUA?oc=5","published_at":"2025-06-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"Mitsubishi Electric AC Systems Vulnerability Allows Remote Control Without User Interaction&nbsp;&nbsp;cybersecuritynews.com","title":"Mitsubishi Electric AC Systems Vulnerability Allows Remote Control Without User Interaction - cybersecuritynews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1a313da00e4fbf64","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuAFBVV95cUxNd2NOTWxnNTctMWNra3RydHNuWmlyOVVUXzhSTTgtald4SkJ3OGlORzRZNHEyYkdzbHo0VUIwckszR3RiRWN3V2FqZTRXZlJFaXhOeFRLTUFVTUxKMWp2LWNUQlAteVZkWjNlLTF6X0xMQjRhS0ZHVHdGSlUxY25CNUEyeVVlU2laNjd3eXdNaVVfU3lkR2ZBanpUblpYWWt2YXNiYlRadDFIVC15T2h6UTBVUmo5Nndw?oc=5","published_at":"2025-06-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Most building management systems exposed to cyber vulnerabilities, experts warn&nbsp;&nbsp;facilitiesdive.com","title":"Most building management systems exposed to cyber vulnerabilities, experts warn - facilitiesdive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-3a2858c61d49b0db","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi7wFBVV95cUxOQ21qenRkNjh6MGM4S3hycjdNa1g3T285Q1A0aXA4emNDQTJNUEhsM0VRc0pJV1hyQUxGWV9hVU0wc3hrMW4zcTF2R291RU9ZWHphN2JYTnl2SUljUzRBaXJaRkpWRW1Ody1jc0t5SG5WZXdqWlRpOHRPaXBQMktzbnNncnRSN1BBRFFXM0tfcnpoSXpTVmk0S2VQeFUtbzZpZGxHVHhaakNCVHczelFVSW1sVXVocVR5YXE0WnFqVVJ4d0F0NnZnbG9kQ2VwRWhHTGR0ZzBvQkVTN21pNG9zUGMwbFR5VE9FeXB3RDZDOA?oc=5","published_at":"2025-06-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Claroty detects widespread cyber risks in building management systems, including ransomware-linked KEVs&nbsp;&nbsp;Industrial Cyber","title":"Claroty detects widespread cyber risks in building management systems, including ransomware-linked KEVs - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-fb7e576277dce329","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuAFBVV95cUxNd2NOTWxnNTctMWNra3RydHNuWmlyOVVUXzhSTTgtald4SkJ3OGlORzRZNHEyYkdzbHo0VUIwckszR3RiRWN3V2FqZTRXZlJFaXhOeFRLTUFVTUxKMWp2LWNUQlAteVZkWjNlLTF6X0xMQjRhS0ZHVHdGSlUxY25CNUEyeVVlU2laNjd3eXdNaVVfU3lkR2ZBanpUblpYWWt2YXNiYlRadDFIVC15T2h6UTBVUmo5Nndw?oc=5","published_at":"2025-06-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Most building management systems exposed to cyber vulnerabilities, experts warn&nbsp;&nbsp;Facilities Dive","title":"Most building management systems exposed to cyber vulnerabilities, experts warn - Facilities Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b4f16cd01ff43d32","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi7wFBVV95cUxOQ21qenRkNjh6MGM4S3hycjdNa1g3T285Q1A0aXA4emNDQTJNUEhsM0VRc0pJV1hyQUxGWV9hVU0wc3hrMW4zcTF2R291RU9ZWHphN2JYTnl2SUljUzRBaXJaRkpWRW1Ody1jc0t5SG5WZXdqWlRpOHRPaXBQMktzbnNncnRSN1BBRFFXM0tfcnpoSXpTVmk0S2VQeFUtbzZpZGxHVHhaakNCVHczelFVSW1sVXVocVR5YXE0WnFqVVJ4d0F0NnZnbG9kQ2VwRWhHTGR0ZzBvQkVTN21pNG9zUGMwbFR5VE9FeXB3RDZDOA?oc=5","published_at":"2025-06-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Claroty detects widespread cyber risks in building management systems, including ransomware-linked KEVs&nbsp;&nbsp;industrialcyber.co","title":"Claroty detects widespread cyber risks in building management systems, including ransomware-linked KEVs - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f4ba7006ffea2f64","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxNZUpVNEtzZG92akJONXJfS2pQcjhPQ2t4RlliN0o4RFZXOV9TTF9FUHlISzE2YkQ0TUlRNmRuZmRrcmVKU2VGa0FYRl9CZlZfU0ZzLVdpY21UX2hJSVZhQjhFbjNMaGZsSmN3NE9MNGI0VWNkZkI4d3I0VG8tLUVPNDFCUU5tbzVQOElvSGM2d3phX2tSekRXNkd5UFBSY0VGNkw0TkhZSzA?oc=5","published_at":"2025-06-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Cybersecurity: main and emerging threats&nbsp;&nbsp;europarl.europa.eu","title":"Cybersecurity: main and emerging threats - europarl.europa.eu"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-756557b529d299ca","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxNZUpVNEtzZG92akJONXJfS2pQcjhPQ2t4RlliN0o4RFZXOV9TTF9FUHlISzE2YkQ0TUlRNmRuZmRrcmVKU2VGa0FYRl9CZlZfU0ZzLVdpY21UX2hJSVZhQjhFbjNMaGZsSmN3NE9MNGI0VWNkZkI4d3I0VG8tLUVPNDFCUU5tbzVQOElvSGM2d3phX2tSekRXNkd5UFBSY0VGNkw0TkhZSzA?oc=5","published_at":"2025-06-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Cybersecurity: main and emerging threats&nbsp;&nbsp;European Parliament","title":"Cybersecurity: main and emerging threats - European Parliament"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-4a6fc0d6592872a2","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi8wFBVV95cUxNdm10U21Mei1yOEF2dEpUbmlxVmFhRGhiQ3BPV3FwOUk0SW1RQkFVeElHUXlYSWh2YlZTVjVyc0Z1OUgwQ0lHbVNUN1FsUEJESEhxaTl2WU5hQ04xQzlWQWNnVnlEWXFtT000eDVnVURZZXR6TFNKakkwb2xXTUJGQjFESzg3T2E5T0xBdVRCM09zQ3FLNFp0ZlBrbVpTVmVnT0dXSzhMY3lLTDZVMGhmWnp5cHE5clhtcEFpdXJiaDEtZlluUHgxNnZDUHZNWFEtVVBxOTlxYjlEOGNNRkk5d1RWRUh4VXluSkdvRko5UkoxNkU?oc=5","published_at":"2025-06-18T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"US offers $10 million for intel on Iran-linked hacker in ICS malware campaign against critical infrastructure&nbsp;&nbsp;industrialcyber.co","title":"US offers $10 million for intel on Iran-linked hacker in ICS malware campaign against critical infrastructure - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-b13b59544597a084","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi8wFBVV95cUxNdm10U21Mei1yOEF2dEpUbmlxVmFhRGhiQ3BPV3FwOUk0SW1RQkFVeElHUXlYSWh2YlZTVjVyc0Z1OUgwQ0lHbVNUN1FsUEJESEhxaTl2WU5hQ04xQzlWQWNnVnlEWXFtT000eDVnVURZZXR6TFNKakkwb2xXTUJGQjFESzg3T2E5T0xBdVRCM09zQ3FLNFp0ZlBrbVpTVmVnT0dXSzhMY3lLTDZVMGhmWnp5cHE5clhtcEFpdXJiaDEtZlluUHgxNnZDUHZNWFEtVVBxOTlxYjlEOGNNRkk5d1RWRUh4VXluSkdvRko5UkoxNkU?oc=5","published_at":"2025-06-18T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"US offers $10 million for intel on Iran-linked hacker in ICS malware campaign against critical infrastructure&nbsp;&nbsp;Industrial Cyber","title":"US offers $10 million for intel on Iran-linked hacker in ICS malware campaign against critical infrastructure - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b054d5245afe1a01","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi2gFBVV95cUxPYzBQVl9sYlluZjBjZmNpbVF2MnZGUkFmZjlMTm10TEVQcDI3ZlFLVWg2MmljNUZqODYzV2F0LWh5Z0FKc0ZXTGtmSURkcTF3OEVGWDhEMEtkdWJFNEVGMEV1djFUUTg1WEs5Z2F6SXcyOXJzQ2pHVDVjWXhQOV8yVUZrUWNJcEZmREJVdXRnMnV0S0hTWG5CUnlqMWZSdWtjUzBnVkZOOWNROTVpRlppV3BtSFQ4LXVDaXJFWkdvR21zQ3VQbFVWZ05xYkhwTlFlNnYtU2Rxb2RrQQ?oc=5","published_at":"2025-06-17T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"NIST flags rising cybersecurity challenges as IT and OT systems increasingly converge through IoT integration&nbsp;&nbsp;Industrial Cyber","title":"NIST flags rising cybersecurity challenges as IT and OT systems increasingly converge through IoT integration - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5c487f5f7657ccea","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi2gFBVV95cUxPYzBQVl9sYlluZjBjZmNpbVF2MnZGUkFmZjlMTm10TEVQcDI3ZlFLVWg2MmljNUZqODYzV2F0LWh5Z0FKc0ZXTGtmSURkcTF3OEVGWDhEMEtkdWJFNEVGMEV1djFUUTg1WEs5Z2F6SXcyOXJzQ2pHVDVjWXhQOV8yVUZrUWNJcEZmREJVdXRnMnV0S0hTWG5CUnlqMWZSdWtjUzBnVkZOOWNROTVpRlppV3BtSFQ4LXVDaXJFWkdvR21zQ3VQbFVWZ05xYkhwTlFlNnYtU2Rxb2RrQQ?oc=5","published_at":"2025-06-17T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"NIST flags rising cybersecurity challenges as IT and OT systems increasingly converge through IoT integration&nbsp;&nbsp;industrialcyber.co","title":"NIST flags rising cybersecurity challenges as IT and OT systems increasingly converge through IoT integration - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-090de5e41950808e","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMif0FVX3lxTE52TWJMdnNHTnVQRy1SVFZ6NU1na214ZGc3V2kzNlQzd29tamJkQVo4dEk0NkdSN1VSSkFiMW5TdW9NUmgxSnVFc0xDdUZFd2VZLXc2TGNreG51RnRlYWN0NTc1a3laczdXOVFIV3lCMUtpNE1YZjNqNmdfNFhPcUU?oc=5","published_at":"2025-06-16T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"US offering $10 million for info on Iranian hackers behind IOControl malware&nbsp;&nbsp;The Record from Recorded Future News","title":"US offering $10 million for info on Iranian hackers behind IOControl malware - The Record from Recorded Future News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7eaf808a19aeb02c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMif0FVX3lxTE52TWJMdnNHTnVQRy1SVFZ6NU1na214ZGc3V2kzNlQzd29tamJkQVo4dEk0NkdSN1VSSkFiMW5TdW9NUmgxSnVFc0xDdUZFd2VZLXc2TGNreG51RnRlYWN0NTc1a3laczdXOVFIV3lCMUtpNE1YZjNqNmdfNFhPcUU?oc=5","published_at":"2025-06-16T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"US offering $10 million for info on Iranian hackers behind IOControl malware&nbsp;&nbsp;therecord.media","title":"US offering $10 million for info on Iranian hackers behind IOControl malware - therecord.media"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9a374dd611be68fe","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxPZnA0MDRFUkpwMlRWLUYybl95OTFybTFZS1ZmZGotTUlOWWNUcjBVaGtYN1VfSmJEa25OWEs4VzRFcjBHcFZnV3ItRlk1NTlPYk92eko2MTFpTDRsWDhyTi1iZkNlNTBMbnRYbk1hQ3pYWkE0bTBBdC1HYlBJWGNVUHlwb1NvMFk4OTZWeE0ySlAwYkRQRGUyRVgycXBsazA?oc=5","published_at":"2025-06-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"OT Cybersecurity Learnings from Building Automations Industry | Cyber and Data Resilience&nbsp;&nbsp;Kroll","title":"OT Cybersecurity Learnings from Building Automations Industry | Cyber and Data Resilience - Kroll"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d2e7faa28b425b80","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxPZnA0MDRFUkpwMlRWLUYybl95OTFybTFZS1ZmZGotTUlOWWNUcjBVaGtYN1VfSmJEa25OWEs4VzRFcjBHcFZnV3ItRlk1NTlPYk92eko2MTFpTDRsWDhyTi1iZkNlNTBMbnRYbk1hQ3pYWkE0bTBBdC1HYlBJWGNVUHlwb1NvMFk4OTZWeE0ySlAwYkRQRGUyRVgycXBsazA?oc=5","published_at":"2025-06-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"OT Cybersecurity Learnings from Building Automations Industry | Cyber and Data Resilience&nbsp;&nbsp;kroll.com","title":"OT Cybersecurity Learnings from Building Automations Industry | Cyber and Data Resilience - kroll.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-603d3e1c621dae04","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilgFBVV95cUxQVGVhSVJqQTdwbTB2YVZNSURISjk4M3JwcnZJRkE5eElZdzFvSkFlMDhOUW9wcTJabnRaNnNSUV9kUkltOXFxV1BJeGFDZ1FNSTFoTnd6MzlaSHh3VkJ2ajBqOHdVNExwajdsMXRBc2ktNVBTeTFETHoybzZDQ2d3ZGxLdTlpeWg1LXZjbmhNeEFWUndUcEE?oc=5","published_at":"2025-06-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Validation of a questionnaire for assessing household vulnerability to climate change and health among small island communities&nbsp;&nbsp;frontiersin.org","title":"Validation of a questionnaire for assessing household vulnerability to climate change and health among small island communities - frontiersin.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a440c842ed56e58d","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijgFBVV95cUxPQms0a2w5ME5Xcll1Z1VMUkladzhkR2FQSEgzMlVOWFNGVUE3M1BmMTJ1YS1weGFoajBOcHFMVDlmNHlWR3lUYVVvWlRIN0x5djNWLWUxN1M5TVdlRHZpbHdUSHViZ1ZZR0JKWFZYX2ZERDJPTFRFYjJkWWV6UFFxTXY5QjMxOUcxREdtQkJn?oc=5","published_at":"2025-06-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"An index-based approach to assess the vulnerability of coffee-based farmers to climate change and variability across districts in Western Ethiopia&nbsp;&nbsp;Frontiers","title":"An index-based approach to assess the vulnerability of coffee-based farmers to climate change and variability across districts in Western Ethiopia - Frontiers"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9b5798c339e12a39","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilgFBVV95cUxQVGVhSVJqQTdwbTB2YVZNSURISjk4M3JwcnZJRkE5eElZdzFvSkFlMDhOUW9wcTJabnRaNnNSUV9kUkltOXFxV1BJeGFDZ1FNSTFoTnd6MzlaSHh3VkJ2ajBqOHdVNExwajdsMXRBc2ktNVBTeTFETHoybzZDQ2d3ZGxLdTlpeWg1LXZjbmhNeEFWUndUcEE?oc=5","published_at":"2025-06-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Validation of a questionnaire for assessing household vulnerability to climate change and health among small island communities&nbsp;&nbsp;Frontiers","title":"Validation of a questionnaire for assessing household vulnerability to climate change and health among small island communities - Frontiers"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-865e1caced5e2eb8","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijgFBVV95cUxPQms0a2w5ME5Xcll1Z1VMUkladzhkR2FQSEgzMlVOWFNGVUE3M1BmMTJ1YS1weGFoajBOcHFMVDlmNHlWR3lUYVVvWlRIN0x5djNWLWUxN1M5TVdlRHZpbHdUSHViZ1ZZR0JKWFZYX2ZERDJPTFRFYjJkWWV6UFFxTXY5QjMxOUcxREdtQkJn?oc=5","published_at":"2025-06-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"An index-based approach to assess the vulnerability of coffee-based farmers to climate change and variability across districts in Western Ethiopia&nbsp;&nbsp;frontiersin.org","title":"An index-based approach to assess the vulnerability of coffee-based farmers to climate change and variability across districts in Western Ethiopia - frontiersin.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4f9a2f53179d7a10","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMieEFVX3lxTFBWX3hGUElrcmo4ZTFfaHR2RWt3V29NTVJZa3IzZXNtZlVvMzQ0Zk94b0F2TWFXcUtkOU9rZDIwR2lRSFdsUi0xY3h3a1h5cjJZSi1FY2tYSVV3b2dqUmstMnktTGJtQUxBM3FuZFRzSXpUdnhiVUl5Uw?oc=5","published_at":"2025-05-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Climate Change Vulnerability Assessments Across the Nation&nbsp;&nbsp;storymaps.arcgis.com","title":"Climate Change Vulnerability Assessments Across the Nation - storymaps.arcgis.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f2a9a88230c10bce","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMieEFVX3lxTFBWX3hGUElrcmo4ZTFfaHR2RWt3V29NTVJZa3IzZXNtZlVvMzQ0Zk94b0F2TWFXcUtkOU9rZDIwR2lRSFdsUi0xY3h3a1h5cjJZSi1FY2tYSVV3b2dqUmstMnktTGJtQUxBM3FuZFRzSXpUdnhiVUl5Uw?oc=5","published_at":"2025-05-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Climate Change Vulnerability Assessments Across the Nation&nbsp;&nbsp;ArcGIS StoryMaps","title":"Climate Change Vulnerability Assessments Across the Nation - ArcGIS StoryMaps"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-db045170d9501aed","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiowFBVV95cUxQZE43eWV5cmlpVWlzQW1jbkdPbG5sUlhTSXRUdEstNW0xSFBKc0RtSERLZnVpdXUxZ1dMY2V5ZjhtdjVmcXNUQjJEcjJYaHhONEIyNlVQcUdtRzFMUm0xSWJnelpXY3BNdXp6TzlCb1hVbHdXOEtMS3dqckstRl8wREtMU0ZQUzhiNmI0ekpMckRodG5jLXhKSTN5bmE2a2FtblNF?oc=5","published_at":"2025-05-22T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"National Guardsmen receive brief from Volt Typhoon utility victim at cyber exercise&nbsp;&nbsp;DefenseScoop","title":"National Guardsmen receive brief from Volt Typhoon utility victim at cyber exercise - DefenseScoop"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d92ac763c8af5aa0","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisgFBVV95cUxNeXcyLW01WmF0RFpXdXk3ZXhienRMOVdneFVjZ3hHZjJIZURjRl9aczgyd3Y2MkZ2eXNVVmtzdnRpWkMtS2hwSkNvUVpaRGVMMVRlUDREV05KaEswVFNGQlpmcXM4NmlGT045SGphZ1h3UGc4cVAtMTlOMnUzTlRiS0k3MldHQnBnbXpUd0ZlejR0UkNrc3NSdHdrZlhLRkV3OGxvWEFIVFF5MVk1Sks4ajR3?oc=5","published_at":"2025-05-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Breaking the vicious cycle between climate change & cybersecurity&nbsp;&nbsp;cshub.com","title":"Breaking the vicious cycle between climate change & cybersecurity - cshub.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2e264811ce321c97","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisgFBVV95cUxNeXcyLW01WmF0RFpXdXk3ZXhienRMOVdneFVjZ3hHZjJIZURjRl9aczgyd3Y2MkZ2eXNVVmtzdnRpWkMtS2hwSkNvUVpaRGVMMVRlUDREV05KaEswVFNGQlpmcXM4NmlGT045SGphZ1h3UGc4cVAtMTlOMnUzTlRiS0k3MldHQnBnbXpUd0ZlejR0UkNrc3NSdHdrZlhLRkV3OGxvWEFIVFF5MVk1Sks4ajR3?oc=5","published_at":"2025-05-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Breaking the vicious cycle between climate change & cybersecurity&nbsp;&nbsp;Cyber Security Hub","title":"Breaking the vicious cycle between climate change & cybersecurity - Cyber Security Hub"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-443d9030f7b7efec","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiswFBVV95cUxOVkgwSVdDVzI3dnprODExSElxVVE2TnJ5ZXY2VWktMklfSUxhTmFkNjhaeE1KbzF1NDlzYU5heGVPc3VNVTI2WG9Ta1BSdnZyQVlka0ZYb0t2Yms2dXoyNUhBUXMxUWNrMUN3d1Q5LTdERjdybEdPVEFPYnhLZ0NWVEQ4N2ZxekZBV1BQbE9KZkw0Rzc3V25oRlhFX3VMcDk5a0N1QXlnWnRpQ1VOdlhGWWItVQ?oc=5","published_at":"2025-05-16T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"DOD Leaders Urge Congress to Bolster Cyberdefenses&nbsp;&nbsp;U.S. Department of War (.gov)","title":"DOD Leaders Urge Congress to Bolster Cyberdefenses - U.S. Department of War (.gov)"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-5cd6317660205f0a","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxOb1JhTVR2bDNTVTR5Z2RNWkNMcGlNR3hnTVRKVG43Y2ZnbUs3aFZ3cFVzQkdOY0prX0ZvNlNGTGxzaTd5d1VuQkFicjF3bE5sbEsxZ0YwclZ2ejRoSzFuZy1jTi00RzdfNl8wcmtDdlZIUTBTUVRjWmpsaTM2ckljcUFlb0kzNzF2OFd6TEp6M2tLQmFQSjd5dTUxUHdlR0HSAaQBQVVfeXFMT1BpZjhnNzNaQTBVVEFpb3RkcVl1MXgzdHNvQ19PeGx4aUZNUzR0S0NtYW45M0V2VWxBOUxqaUE3UF8zOHJGSjRMM0wtZ3VwcEdIWlE4WkpTa05OR2EzYkZ6eTd2eE02bTFyN0plMGhDb3M2cVJXVmVUSXJJa2xUYzkxaXZSbFdJT2o3b1M4UElBbEpLTEpiQTZMVzNKaXc3UHpEN2g?oc=5","published_at":"2025-05-07T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"US Warns of Hackers Targeting ICS/SCADA at Oil and Gas Organizations&nbsp;&nbsp;SecurityWeek","title":"US Warns of Hackers Targeting ICS/SCADA at Oil and Gas Organizations - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-76c87f0452bd0ff5","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi3gFBVV95cUxPWEFBR2x0UFNWU3dvQlNPUUdxaUphQ3BENlZJQlFjVVB0SGdhcW50cFhKb05uSjA0VlVHVXNNR2NCWWlveF9OemZONzE2VW00R05xR3ZxTkFCd0I2anZpVmJtREFjbGpEYnAzMjB2LWs0UVMzUlRxN1dHT0tkM0lRVFNCcElHcW8tTHY2V0NZTGJfMnNzRDV2cTFfZE03Yk80WHloTG9veFRvdmlKNFFOSVFKVHp0RHhJX1ZYbUhqOEQxWElvelU4eUg5U0VLWm80M19lOFdwSzdsblNBYUE?oc=5","published_at":"2025-04-25T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"INFO","source":"Critical Infra & APTs","summary":"FBI issues IC3 alert on \u2018Salt Typhoon\u2019 activity, seeks public help in investigating PRC-linked cyber campaign&nbsp;&nbsp;Industrial Cyber","title":"FBI issues IC3 alert on \u2018Salt Typhoon\u2019 activity, seeks public help in investigating PRC-linked cyber campaign - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-9945a8d29359b2ef","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiuAFBVV95cUxPckxrTFRjeWd0bnlYUVprNWh2dTFUN3VOZnFadXB0VGVFSnBETENkNzBQMWFURmxPQVRZMlloTDV1VDJwTHhfQzEyRjJOS2lEWmFTTjZuaV9kS1h3R1ZqLUpKWElDSlZVay0xZk1WRTkxMjdxUnNaR3BNZGFFYzBoSUJqRE5pNTBEcks4NEdWNmZZUE5aT0tlYUs3Y3FCeWhJS3NqZW5NMXF5SG1ucDVkdDNYbXdpMnlp?oc=5","published_at":"2025-04-20T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"Switching to Cybersecurity: Advice for Midcareer Professionals&nbsp;&nbsp;GovTech","title":"Switching to Cybersecurity: Advice for Midcareer Professionals - GovTech"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-7d35cd2af463b1b2","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiuAFBVV95cUxPckxrTFRjeWd0bnlYUVprNWh2dTFUN3VOZnFadXB0VGVFSnBETENkNzBQMWFURmxPQVRZMlloTDV1VDJwTHhfQzEyRjJOS2lEWmFTTjZuaV9kS1h3R1ZqLUpKWElDSlZVay0xZk1WRTkxMjdxUnNaR3BNZGFFYzBoSUJqRE5pNTBEcks4NEdWNmZZUE5aT0tlYUs3Y3FCeWhJS3NqZW5NMXF5SG1ucDVkdDNYbXdpMnlp?oc=5","published_at":"2025-04-20T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"Switching to Cybersecurity: Advice for Midcareer Professionals&nbsp;&nbsp;govtech.com","title":"Switching to Cybersecurity: Advice for Midcareer Professionals - govtech.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-e361a8bf66fc2ce4","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMinAFBVV95cUxPYUwtU3AtZ2paNGdxRUF4eGxqVk1wQWMxUGI1Tnk1dVBROFNCX3M4NE5pRDJOUUVBc2Y5dGhTbVpKWlVfdUc3SkZob2xMT01jZmNEa1I0cmNiLXI2WnNBOXpYZDRrN1VvT0F3YzFVNGszWHpaQ1I0SHJGSHNPWUZWZnNSUjAxMTBHMmJxSHVGSUtzMlFzZk5sdGVsWkrSAaIBQVVfeXFMT1gxNHpobEFVcXhISlJWTzV6NHRzcHl2ZVppdkFrbUV5YXNhYzA1MU52bENlUXFGcUdORTB4WllRVGM0VWtLQnd4MWhObFhCWFFuN3lDbVpycTJvaXF5VUgxX1B0QWdDcUZqZkZ6SlhucU93aXlVaFhtbUlxbmlDV3Q2TkVoelRuaUs1VU1BME5yLWFBcEdacDh1bGt0NDNuZEVB?oc=5","published_at":"2025-04-11T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"China Admitted to Volt Typhoon Cyberattacks on US Critical Infrastructure: Report&nbsp;&nbsp;securityweek.com","title":"China Admitted to Volt Typhoon Cyberattacks on US Critical Infrastructure: Report - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-84bde1c6d556cc7d","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMinAFBVV95cUxPYUwtU3AtZ2paNGdxRUF4eGxqVk1wQWMxUGI1Tnk1dVBROFNCX3M4NE5pRDJOUUVBc2Y5dGhTbVpKWlVfdUc3SkZob2xMT01jZmNEa1I0cmNiLXI2WnNBOXpYZDRrN1VvT0F3YzFVNGszWHpaQ1I0SHJGSHNPWUZWZnNSUjAxMTBHMmJxSHVGSUtzMlFzZk5sdGVsWkrSAaIBQVVfeXFMT1gxNHpobEFVcXhISlJWTzV6NHRzcHl2ZVppdkFrbUV5YXNhYzA1MU52bENlUXFGcUdORTB4WllRVGM0VWtLQnd4MWhObFhCWFFuN3lDbVpycTJvaXF5VUgxX1B0QWdDcUZqZkZ6SlhucU93aXlVaFhtbUlxbmlDV3Q2TkVoelRuaUs1VU1BME5yLWFBcEdacDh1bGt0NDNuZEVB?oc=5","published_at":"2025-04-11T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"China Admitted to Volt Typhoon Cyberattacks on US Critical Infrastructure: Report&nbsp;&nbsp;SecurityWeek","title":"China Admitted to Volt Typhoon Cyberattacks on US Critical Infrastructure: Report - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8a2fbdb137553f22","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMib0FVX3lxTE5zbmVTNnRUYjRuNmFCeEQ4WS1IWUJUbjU2YXJXTG45amU4eHg0aTBfZjU0cVdVVElIU1BBZ0hGbzR6R3Q2S2tPZHlkT0RvX0MtWWJDY3NMTG5IWEo3Q2lfUkhndlBiM0ZaNlR1QUxlbw?oc=5","published_at":"2025-04-11T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"CISA Releases 10 ICS Advisories Covering Vulnerabilities & Exploits&nbsp;&nbsp;CyberSecurityNews","title":"CISA Releases 10 ICS Advisories Covering Vulnerabilities & Exploits - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1574b41c7586fcb7","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi5wFBVV95cUxPQTQ0MEFGYUVwSzBYN29TMU5Wd1RrX0Z6T2wxcU0xVnFhdWtjbEdYVkY2M1dkTktEd3pKbUE3Y2R6MHlUMDFheHlFZy1oMU1ndk9mUjhrTEx3RGJrZW03NGpFeDFVT2stMzlvLWNnSjVHcWsyQWZ4dGFjaTRzUXhsdkNFLVJueExaWHM2RkZWelhqd1pIN2xHcHRjVXVBMXMwbHN2bDRtcExWODNZUy1sTm9Odlg5TGR4cjVsaG5GT2x3dzRxUHp4YTRYRkFnRFpWd3ZzdDhxd0diMzJrTm9ORHBxOFJjZU0?oc=5","published_at":"2025-04-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Urgent need for resilient industrial cybersecurity professionals to defend ICS/OT systems from rising cyber attacks&nbsp;&nbsp;Industrial Cyber","title":"Urgent need for resilient industrial cybersecurity professionals to defend ICS/OT systems from rising cyber attacks - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4a9941cb12e905e7","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi5wFBVV95cUxPQTQ0MEFGYUVwSzBYN29TMU5Wd1RrX0Z6T2wxcU0xVnFhdWtjbEdYVkY2M1dkTktEd3pKbUE3Y2R6MHlUMDFheHlFZy1oMU1ndk9mUjhrTEx3RGJrZW03NGpFeDFVT2stMzlvLWNnSjVHcWsyQWZ4dGFjaTRzUXhsdkNFLVJueExaWHM2RkZWelhqd1pIN2xHcHRjVXVBMXMwbHN2bDRtcExWODNZUy1sTm9Odlg5TGR4cjVsaG5GT2x3dzRxUHp4YTRYRkFnRFpWd3ZzdDhxd0diMzJrTm9ORHBxOFJjZU0?oc=5","published_at":"2025-04-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Urgent need for resilient industrial cybersecurity professionals to defend ICS/OT systems from rising cyber attacks&nbsp;&nbsp;industrialcyber.co","title":"Urgent need for resilient industrial cybersecurity professionals to defend ICS/OT systems from rising cyber attacks - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-8686f7f49d59a5bb","category":"PLC & Controller Firmware","cve_ids":["CVE-2025-1449"],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMif0FVX3lxTFBBRzFiQkJOQnVHZ1k1SzRJR2U0c1lvRkpxTlF5Y2l6ZGRSQ0FjUTJrdXpFUl9QazBjT2FZQ0gzY1ZYN0NJTkc0Ymlyc2J5QnJJYkY5OFpxOEVDc05yQ09zZlB3VmNRd3QteFUxbi1sbEtzZlZLTVJXU2RLUVcyeUU?oc=5","published_at":"2025-04-02T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"CVE-2025-1449: Rockwell Automation Verve Asset Manager Vulnerability Enables Adversaries to Gain Access to Run Arbitrary Commands&nbsp;&nbsp;socprime.com","title":"CVE-2025-1449: Rockwell Automation Verve Asset Manager Vulnerability Enables Adversaries to Gain Access to Run Arbitrary Commands - socprime.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-52aa18766f3c7100","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi3wFBVV95cUxPQVRsTEp0RkJMMnU2Z0xieU93bmx3bENkaDRUSnY0LXdscTRkaTV4N29yNFpIaUVMV3BEWFhSLVMwaHZHSFVYQVZlbnRjN09qV2hBY3pBYXh1ZmREM293MkpDcXVtWHZGVTEwY0Zhd21BTElYY1lmNVdSOExpV0Z0SFpfaW0yakY2M2RnT3dDckJQSU5mcGxBd0JqUHBXMzVpbDItLWtEOFg4OEVxMUVGWE8tQ1hBVkM4cEZacDZHUWI1Vk9GVDNub0RsTVlnZzA2VW1wYW5NT3BMa1p4cnl3?oc=5","published_at":"2025-04-02T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"Hearing Wrap Up: U.S. Federal Agencies Need Proactive Cybersecurity Strategy to Counter State-Sponsored Threats&nbsp;&nbsp;House.gov","title":"Hearing Wrap Up: U.S. Federal Agencies Need Proactive Cybersecurity Strategy to Counter State-Sponsored Threats - House.gov"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-40bca3988eae68b1","category":"PLC & Controller Firmware","cve_ids":["CVE-2025-1449"],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMif0FVX3lxTFBBRzFiQkJOQnVHZ1k1SzRJR2U0c1lvRkpxTlF5Y2l6ZGRSQ0FjUTJrdXpFUl9QazBjT2FZQ0gzY1ZYN0NJTkc0Ymlyc2J5QnJJYkY5OFpxOEVDc05yQ09zZlB3VmNRd3QteFUxbi1sbEtzZlZLTVJXU2RLUVcyeUU?oc=5","published_at":"2025-04-02T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"CVE-2025-1449: Rockwell Automation Verve Asset Manager Vulnerability Enables Adversaries to Gain Access to Run Arbitrary Commands&nbsp;&nbsp;SOC Prime","title":"CVE-2025-1449: Rockwell Automation Verve Asset Manager Vulnerability Enables Adversaries to Gain Access to Run Arbitrary Commands - SOC Prime"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-d8df1dafa641ef53","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMilAFBVV95cUxPLUd1TWU4eEdic0h3bWphUS1nREJuMXVxLXc0Z3FNckdJenBzbFU0QUtOaWQ4aUJlQk5sSWhVVzgwRWhLNXRqa2NQY0hzTEc0TEMyNFpsZy1lZ0ZCUml6dVNvdEZOMmJ2WEE3SVc2WjNnYURKSEpmOVdXbHNJQk5VTk9CX1ROQ2RWUFZBUzlRX1l2SzVX?oc=5","published_at":"2025-04-01T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Rockwell Automation Vulnerability Let Attackers Gain Access to Run Arbitrary Commands&nbsp;&nbsp;CyberSecurityNews","title":"Rockwell Automation Vulnerability Let Attackers Gain Access to Run Arbitrary Commands - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-61ba3f6af215635c","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMilAFBVV95cUxPLUd1TWU4eEdic0h3bWphUS1nREJuMXVxLXc0Z3FNckdJenBzbFU0QUtOaWQ4aUJlQk5sSWhVVzgwRWhLNXRqa2NQY0hzTEc0TEMyNFpsZy1lZ0ZCUml6dVNvdEZOMmJ2WEE3SVc2WjNnYURKSEpmOVdXbHNJQk5VTk9CX1ROQ2RWUFZBUzlRX1l2SzVX?oc=5","published_at":"2025-04-01T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Rockwell Automation Vulnerability Let Attackers Gain Access to Run Arbitrary Commands&nbsp;&nbsp;cybersecuritynews.com","title":"Rockwell Automation Vulnerability Let Attackers Gain Access to Run Arbitrary Commands - cybersecuritynews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-dbf42a92c6aea1b7","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiswFBVV95cUxPdV9YNmpYNzNNUTJLTWRTb1FvdDVydUFpYnJnUkM2VUIya3F1Wkg2SjZHZHRPRXBFMTFBXy1fUTFpcmpETHFnNGIxc2ZwS0podFdHQnltYjFHVDZ0RkFZZTdqT0NoeDBNeXZ6MEpoU2NsMTdQeG51RFVqVk5hWHFYU1hSdkFsbnJKRXp3Ry1uQUpxTHFOQ3Fzb1JMSFdhVzdTNWtNd1ltMDliazRPRzhvbnM2cw?oc=5","published_at":"2025-03-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"National security leaders: Combating cyber threats from China takes collaboration&nbsp;&nbsp;Healthcare IT News","title":"National security leaders: Combating cyber threats from China takes collaboration - Healthcare IT News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f8e3dd35cf530761","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxNWHI1OWVlTWJBcDhLV3h0QlhNRnVYaXhZM1JVVWJseTBDQ1NPdGZhNXpzREp2WERGbWJkU25taXNOM3JwT1BHY2JETmNxRHNaQmd3UDVPbnVYanlJeG1KYXNIbFhiY0JBXzVsQmJReUd0NkVrRV9xZFB4cEF5RWs5ZmtCY20?oc=5","published_at":"2025-03-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA Warns of Four Vulnerabilities, and Exploits Surrounding ICS&nbsp;&nbsp;CyberSecurityNews","title":"CISA Warns of Four Vulnerabilities, and Exploits Surrounding ICS - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-be3f260e5e36406b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuwFBVV95cUxPSG5UQkN1WDlSTDR1TzZqd0NiU3FnX0NjTzV2VzRPRnRBZHZqUWM5ZWQ1MGtvU1R4X3dzTWo1ZmFMcUlfd3AxOEhPYU9ZY1BRRXdYTVV0ZWstLXNmRmtkQzBtc3dCODlSdlRMUGdra2lYRVhrYkYwQXNHcFdGclpuSWlYZkZoWkc5UEo3emtZd2RBVFJ2RExYM29NMVZBRGgzTlZRdnFBQjFEUHViR2VzY3RWMzhmTV9jOWo4?oc=5","published_at":"2025-03-24T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Smart home devices are an easy backdoor for cyber attackers&nbsp;&nbsp;IOT Insider","title":"Smart home devices are an easy backdoor for cyber attackers - IOT Insider"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f0e44ea0539f1094","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikgFBVV95cUxOVTAyRUNLdlJHTE5Ob3dTVFYzYXk3SUZFaktDOGVIRXpNUC14SWZsQWlBdXJ4amxOSkpBS3hkV0k3SlZpZGh5RWZkWXhHVmVVUFdfTnhld2dpMTBPYVNhWk95Z2N1LXV3TE5iZjdFMkdWa2dVX1hsSEhUbkEwOUIzRTlabzRyRWVOVEtxTWhrX09tZw?oc=5","published_at":"2025-03-21T13:32:09+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Protecting Industrial Control Systems in the Cloud&nbsp;&nbsp;darktrace.com","title":"Protecting Industrial Control Systems in the Cloud - darktrace.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4b2e24a701b46ba9","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikgFBVV95cUxOVTAyRUNLdlJHTE5Ob3dTVFYzYXk3SUZFaktDOGVIRXpNUC14SWZsQWlBdXJ4amxOSkpBS3hkV0k3SlZpZGh5RWZkWXhHVmVVUFdfTnhld2dpMTBPYVNhWk95Z2N1LXV3TE5iZjdFMkdWa2dVX1hsSEhUbkEwOUIzRTlabzRyRWVOVEtxTWhrX09tZw?oc=5","published_at":"2025-03-21T13:32:09+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Protecting Industrial Control Systems in the Cloud&nbsp;&nbsp;Darktrace","title":"Protecting Industrial Control Systems in the Cloud - Darktrace"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f8c6abdc4ef4bc6d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiZEFVX3lxTE84SHV1YXVaVnQ5eHVaaFQ3TTdkSzAxa1g0d2RwVzJrSHdMQWFTdlRiNTAwQlNMTzBSMFpGX1RubGREcl9tV2JFbmIzaExRbnZvcjJKYWY0cXpMQjhObTlXa3RoNUE?oc=5","published_at":"2025-03-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Kaspersky industrial threat report for Q4 2024&nbsp;&nbsp;Securelist","title":"Kaspersky industrial threat report for Q4 2024 - Securelist"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d9848d130d006a47","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikAFBVV95cUxOc0puUzFzQk5TaXdrU3JwR0toSU1RTzB2b1pzS1N3d2k4QnZXVnhacEQ4VFVvWVBja0lxT20yWXh3QXd3N1JISHJSMUFfUFpndUwxSUFBME4wWndfNlBiOGlLRkpCRDdzZEZ5NF9oYTRlZ09OZ3FVTnVNY0RwRVlaSnJFWmt5V0VtNVIwVVdoM20?oc=5","published_at":"2025-03-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Hard lessons learned from Change Healthcare breach&nbsp;&nbsp;American Medical Association | AMA","title":"Hard lessons learned from Change Healthcare breach - American Medical Association | AMA"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b11c22177ea247cd","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikAFBVV95cUxOc0puUzFzQk5TaXdrU3JwR0toSU1RTzB2b1pzS1N3d2k4QnZXVnhacEQ4VFVvWVBja0lxT20yWXh3QXd3N1JISHJSMUFfUFpndUwxSUFBME4wWndfNlBiOGlLRkpCRDdzZEZ5NF9oYTRlZ09OZ3FVTnVNY0RwRVlaSnJFWmt5V0VtNVIwVVdoM20?oc=5","published_at":"2025-03-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Hard lessons learned from Change Healthcare breach&nbsp;&nbsp;ama-assn.org","title":"Hard lessons learned from Change Healthcare breach - ama-assn.org"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-e451026ec972fbe5","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxQR0NJUzBWN1dFaGRIUnpqdDJKVGdUNTFLODdRaHRXTmI4dWQtSjBZQzlsS3NnZ3B5Z2ZQa0RyczM0dW8xMllQd2ZUYUx1UldaR3Z0OFRiN21PMGNDNm1rbjJEX1gyMS1kTTFxbmhkUjIzRWxSeXBmWXlEUXJ3aUFqdDBETGpZZU44clhpN3ktMlUwV3hyX0RpV1ROMkw2QlBRRF9PNlBvU0NLdw?oc=5","published_at":"2025-03-13T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"SCADA Disaster Recovery on AWS for Inductive Automation\u2019s Ignition&nbsp;&nbsp;Amazon Web Services (AWS)","title":"SCADA Disaster Recovery on AWS for Inductive Automation\u2019s Ignition - Amazon Web Services (AWS)"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-c9c7328012453c0a","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxQR0NJUzBWN1dFaGRIUnpqdDJKVGdUNTFLODdRaHRXTmI4dWQtSjBZQzlsS3NnZ3B5Z2ZQa0RyczM0dW8xMllQd2ZUYUx1UldaR3Z0OFRiN21PMGNDNm1rbjJEX1gyMS1kTTFxbmhkUjIzRWxSeXBmWXlEUXJ3aUFqdDBETGpZZU44clhpN3ktMlUwV3hyX0RpV1ROMkw2QlBRRF9PNlBvU0NLdw?oc=5","published_at":"2025-03-13T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"SCADA Disaster Recovery on AWS for Inductive Automation\u2019s Ignition&nbsp;&nbsp;aws.amazon.com","title":"SCADA Disaster Recovery on AWS for Inductive Automation\u2019s Ignition - aws.amazon.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-73bbd019d192e9c9","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxNZURzMGxUd0ZET0JBRDRHZy1tdmV4WVlLUHA2S0lfbEVBUno2OGF1WXBDWU9oWTRhcTVRSmRTRnFGNUJuVjZWbHhuZkZoaXQzRUR1NS14UzlwdWNyT0k0OVhDVmlKVFItbHp5REJyUG94alFXOEhJNHNjbVV4R2NhSVB6ejc?oc=5","published_at":"2025-03-10T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Moxa Industrial Ethernet Switches Vulnerability Let Attackers Gain Admin Access&nbsp;&nbsp;CyberSecurityNews","title":"Moxa Industrial Ethernet Switches Vulnerability Let Attackers Gain Admin Access - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-f0bbe1c26e09a9f3","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxQQXo1V0hKdUdEQUJucGc1UGZIREFmS2dSQ3RMSmk1dVg1MUh6SFpGSTRKazltREpOZXlBUmcyVFJIeUF3YkRMLUVEeWxHWTcyTmV4Qmlac01QLXdLVjF0U05JN0Zxd2dfazA1cXJWeXVRTDFwVi14NXlBMUhCTDVGNUNJMzA?oc=5","published_at":"2025-03-07T08:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Multiple Vulnerabilities Discovered in a SCADA System&nbsp;&nbsp;Unit 42","title":"Multiple Vulnerabilities Discovered in a SCADA System - Unit 42"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-e8a7b01aa4bceb78","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxQQXo1V0hKdUdEQUJucGc1UGZIREFmS2dSQ3RMSmk1dVg1MUh6SFpGSTRKazltREpOZXlBUmcyVFJIeUF3YkRMLUVEeWxHWTcyTmV4Qmlac01QLXdLVjF0U05JN0Zxd2dfazA1cXJWeXVRTDFwVi14NXlBMUhCTDVGNUNJMzA?oc=5","published_at":"2025-03-07T08:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Multiple Vulnerabilities Discovered in a SCADA System&nbsp;&nbsp;unit42.paloaltonetworks.com","title":"Multiple Vulnerabilities Discovered in a SCADA System - unit42.paloaltonetworks.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-64a87d0144221994","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMioAFBVV95cUxNUFVsNXJ2ck5LRktwOUs4UTkxa0M2R3VHd3lWUzNoRFZYYkJOUXRvTy02eHQzSVJ6UVJKMkNMSE9FSk9UUDBLQVhUNWtRREFFd1pRaVJyNEw0ZkFIY25ZRFVhLVJrdXFsZi11aW9Idjl2ZEd3Rm91WG1rQUs5UjZoZ01lMnlCUjFmMFBjc1QxR0QzcFBoXy1pLUFkcEI1Ml8z?oc=5","published_at":"2025-03-06T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"60% of cybersecurity pros looking to change employers&nbsp;&nbsp;csoonline.com","title":"60% of cybersecurity pros looking to change employers - csoonline.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7f8102ae39fbdfab","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiiwFBVV95cUxPSTJwUWNYcTZscmItY29sa3JNMzJLZ1B5QUUxWTFZN2M2eW1GM1lXWnBnZi1kNXpMZmc0YnFwcTExTnBRd1lESWlXTDZxaDV1aG5rYlFlTXlLWlB2WjZWdTYtcExEcjlVYXV5WE9rTk0tSTNrV0szT3ZqM2hKSG04WnNKQVljUFRNTE1V?oc=5","published_at":"2025-02-28T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"OT/ICS cyber threats escalate as geopolitical conflicts intensify&nbsp;&nbsp;Help Net Security","title":"OT/ICS cyber threats escalate as geopolitical conflicts intensify - Help Net Security"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-24796f27f7d9870f","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxPRUt6b2tvNW1JTk5STkJjNjM1QUV0U3dOc05tQ0U2ME0zUGxYSGV1Q3pSdXpTREFtTHVyZ0dmUDYxMHdsSzgtZFVBSC14R1VvS09GdW40S1A5NWYybWdWcUw0TERmaF8zN1dCbVVHbk13TGJWenpDTHZacldTODd2aU83d9IBiAFBVV95cUxPaktFTUIyWUdjQVVkdVRoc2d5SnB4UTVNOHBNVDhUd0ZOREpiSEM1SWtvb2FBbXNtVkJ4bEJpa3BjRmxtWW9LT2ZaQzhvZlc3Z3djYzVDQzdiNE90S2hRUkpMeTlBR0lyWUZTNFhqZk9DZkJxa3JEalBrMHl1N0Ftd2Y0UlRXalpy?oc=5","published_at":"2025-02-27T08:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Cisco Patches Vulnerabilities in Nexus Switches&nbsp;&nbsp;SecurityWeek","title":"Cisco Patches Vulnerabilities in Nexus Switches - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-c5e0786568f19ae2","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxPRUt6b2tvNW1JTk5STkJjNjM1QUV0U3dOc05tQ0U2ME0zUGxYSGV1Q3pSdXpTREFtTHVyZ0dmUDYxMHdsSzgtZFVBSC14R1VvS09GdW40S1A5NWYybWdWcUw0TERmaF8zN1dCbVVHbk13TGJWenpDTHZacldTODd2aU83d9IBiAFBVV95cUxPaktFTUIyWUdjQVVkdVRoc2d5SnB4UTVNOHBNVDhUd0ZOREpiSEM1SWtvb2FBbXNtVkJ4bEJpa3BjRmxtWW9LT2ZaQzhvZlc3Z3djYzVDQzdiNE90S2hRUkpMeTlBR0lyWUZTNFhqZk9DZkJxa3JEalBrMHl1N0Ftd2Y0UlRXalpy?oc=5","published_at":"2025-02-27T08:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Cisco Patches Vulnerabilities in Nexus Switches&nbsp;&nbsp;securityweek.com","title":"Cisco Patches Vulnerabilities in Nexus Switches - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-bf7f44f72e7eed4a","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxOOXJaRmNzTGFOR0FtN3VfcG8wVFQxOXVhMzJGUE16YTExZ3ZhalB4NGxiT0J5R0xIclM5RDJoWnRDNFFpM2d4azZiM2dIWTBwbDdJV3JVWDlHVC1JUjVHUmJjTWUzVWwyRDNob2VIVFUzcVpoWWdUM0RPcWNUa2FTQUgzWUk5OHp2TTQyLXJVVzZDeW5xZWFWTktMRXIxbFo0VjVBTQ?oc=5","published_at":"2025-02-26T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Using climate vulnerability assessments to implement and mainstream adaptation by the forest industry into forest management in Canada&nbsp;&nbsp;frontiersin.org","title":"Using climate vulnerability assessments to implement and mainstream adaptation by the forest industry into forest management in Canada - frontiersin.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-26ac65385cdd54c2","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxOOXJaRmNzTGFOR0FtN3VfcG8wVFQxOXVhMzJGUE16YTExZ3ZhalB4NGxiT0J5R0xIclM5RDJoWnRDNFFpM2d4azZiM2dIWTBwbDdJV3JVWDlHVC1JUjVHUmJjTWUzVWwyRDNob2VIVFUzcVpoWWdUM0RPcWNUa2FTQUgzWUk5OHp2TTQyLXJVVzZDeW5xZWFWTktMRXIxbFo0VjVBTQ?oc=5","published_at":"2025-02-26T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Using climate vulnerability assessments to implement and mainstream adaptation by the forest industry into forest management in Canada&nbsp;&nbsp;Frontiers","title":"Using climate vulnerability assessments to implement and mainstream adaptation by the forest industry into forest management in Canada - Frontiers"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7cf2b4c7073f4357","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitgFBVV95cUxPZnpvZW9Sck04WEJOVGRaUlBEX3hoT3lyWWp3UWItdmZSYVdCV0hPSVRHMXVjZFBpSGZsNENmQ1RPbDZuSmpGbm82TDBXUnVheWNlNm11U29oOEhXRmdXWEhXWFQwUVFFc3hxNVdveDZadnR4MWNzZFhBb1ZYeXJITUNUaEpZQ2t5eUZQUGNtTTZiMVd0MGZudklkenBzdzNuZXd0QXhIS2drM283V1JSZWg4WUZldw?oc=5","published_at":"2025-02-26T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Understanding cyber risk in smart building tech&nbsp;&nbsp;Facilities Dive","title":"Understanding cyber risk in smart building tech - Facilities Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d7b0f199f17d22b6","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitgFBVV95cUxPZnpvZW9Sck04WEJOVGRaUlBEX3hoT3lyWWp3UWItdmZSYVdCV0hPSVRHMXVjZFBpSGZsNENmQ1RPbDZuSmpGbm82TDBXUnVheWNlNm11U29oOEhXRmdXWEhXWFQwUVFFc3hxNVdveDZadnR4MWNzZFhBb1ZYeXJITUNUaEpZQ2t5eUZQUGNtTTZiMVd0MGZudklkenBzdzNuZXd0QXhIS2drM283V1JSZWg4WUZldw?oc=5","published_at":"2025-02-26T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Understanding cyber risk in smart building tech&nbsp;&nbsp;facilitiesdive.com","title":"Understanding cyber risk in smart building tech - facilitiesdive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-60688141f72db30f","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMidkFVX3lxTE1CejFCOEl4S0VZWWRfMFZNVVI2RUlzTDZnRFhLMk1vRW1hVzFoUEVmbzVRMHZIbFdBWDRBYXM4Tjcyb0JqSk9remg2ZzU0UWczUmZTS2UyREZSRllUZTg5VnZ5UUZFQkFjY1VmWG5pUmRXYTl5LVE?oc=5","published_at":"2025-02-19T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"CISA Releases Two New ICS Advisories Exploits Following Vulnerabilities&nbsp;&nbsp;CyberSecurityNews","title":"CISA Releases Two New ICS Advisories Exploits Following Vulnerabilities - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-82310b4f1793c9a7","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMidkFVX3lxTE1CejFCOEl4S0VZWWRfMFZNVVI2RUlzTDZnRFhLMk1vRW1hVzFoUEVmbzVRMHZIbFdBWDRBYXM4Tjcyb0JqSk9remg2ZzU0UWczUmZTS2UyREZSRllUZTg5VnZ5UUZFQkFjY1VmWG5pUmRXYTl5LVE?oc=5","published_at":"2025-02-19T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"CISA Releases Two New ICS Advisories Exploits Following Vulnerabilities&nbsp;&nbsp;cybersecuritynews.com","title":"CISA Releases Two New ICS Advisories Exploits Following Vulnerabilities - cybersecuritynews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-0aaf0c57deb85a1e","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiYEFVX3lxTE84dnpHT2JyZ3VOZGdVTkJtc0Q3WkRJZVVteGtGUzVWYlUteVg0dk1MT2o3Z2xhWEZhbzdUa2IzZ0lBSTJoMHh3cEo0cUxSUUpYNU5RU0RjWDVoa213MkJ5bQ?oc=5","published_at":"2025-02-14T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"CISA Publishes 20 Advisories on ICS Security Flaws and Exploits&nbsp;&nbsp;gbhackers.com","title":"CISA Publishes 20 Advisories on ICS Security Flaws and Exploits - gbhackers.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-37ea2e1a0a0db1c1","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiakFVX3lxTFAxcE5Ra0ZodTh6T0trdTE3dDhFNjJ1Z3NkY2dYRU5EVGI3OUUwN0w2MEF6RHc2Wi1TOWJnYlJ1WjJ3R2wycDB2QW1tdkNDU2Z1SlNhWF9KQXlpcGkzakY1RzBWNEFydUFzRFE?oc=5","published_at":"2025-02-13T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"CYD Campus BACS Hackathon 2025 - Exploring Security for Building Automation and Control Systems&nbsp;&nbsp;Armasuisse","title":"CYD Campus BACS Hackathon 2025 - Exploring Security for Building Automation and Control Systems - Armasuisse"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5e653418edf04c89","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiakFVX3lxTFAxcE5Ra0ZodTh6T0trdTE3dDhFNjJ1Z3NkY2dYRU5EVGI3OUUwN0w2MEF6RHc2Wi1TOWJnYlJ1WjJ3R2wycDB2QW1tdkNDU2Z1SlNhWF9KQXlpcGkzakY1RzBWNEFydUFzRFE?oc=5","published_at":"2025-02-13T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"CYD Campus BACS Hackathon 2025 - Exploring Security for Building Automation and Control Systems&nbsp;&nbsp;ar.admin.ch","title":"CYD Campus BACS Hackathon 2025 - Exploring Security for Building Automation and Control Systems - ar.admin.ch"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-402ed8a7c2c4ba08","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiiAFBVV95cUxPZkpRa3c5anBhUmZ1TXlXeXVYRGw3WGxaZXU3ZHNPQzBIUUljdWRNMFp1VkRtZ1k3S1RJX1ZrSWZ4ZXlQa0laLVU2cnFnUE0xaU1aS0lEQTgwVVRWYzA0UXR4Qy1GWUM4QTlHNUs3ZEkxS0gwNk84UVpBVHI3cS1acUVITWNIa1NZ?oc=5","published_at":"2025-01-30T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Climate Change Vulnerability in Southeast Myanmar&nbsp;&nbsp;DIIS","title":"Climate Change Vulnerability in Southeast Myanmar - DIIS"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-69f64d1fdeb4d009","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiiAFBVV95cUxPZkpRa3c5anBhUmZ1TXlXeXVYRGw3WGxaZXU3ZHNPQzBIUUljdWRNMFp1VkRtZ1k3S1RJX1ZrSWZ4ZXlQa0laLVU2cnFnUE0xaU1aS0lEQTgwVVRWYzA0UXR4Qy1GWUM4QTlHNUs3ZEkxS0gwNk84UVpBVHI3cS1acUVITWNIa1NZ?oc=5","published_at":"2025-01-30T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Climate Change Vulnerability in Southeast Myanmar&nbsp;&nbsp;diis.dk","title":"Climate Change Vulnerability in Southeast Myanmar - diis.dk"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-f89bebd3e7035f7c","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi3gFBVV95cUxOWmNMWFloWlJIMmkzbURDLXEtNnhUOEZLY1oyd050MXRTRFgwZzZGemFESFIwZmtIQndfRk5NWUxYbldGVVU2NmdoU0U4bVlDTC1tZl82b2EtcWN2VGVpNHZLMkNoMDFCM0lKdFpzYTZjdUF2ZlM1MEJOU0tnVVlyR1hyYXRTMm9kbUo4c2VZek1MNmFWSGsyOFZoM2xhMEZJT3VCZV9Lc0E0QkxQR1BYOTJMX2d6RmhTUWlsRW5Vb3NTa2NTVXZnMTV2NFpmYjVtMm1HWlQ4SW9USHU1Smc?oc=5","published_at":"2025-01-29T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA flags hardware vulnerabilities in ICS and medical devices; affects B&R, Schneider Electric, Rockwell, BD Systems&nbsp;&nbsp;industrialcyber.co","title":"CISA flags hardware vulnerabilities in ICS and medical devices; affects B&R, Schneider Electric, Rockwell, BD Systems - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-7d419ec1edb01edf","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxQeDZUZFJDTThFdGxpejlhUHdlbGNFZGJ1RFF0S1pmSjVHaEpGNHhnR2g3SW1rRWRXRDU5SDR5ak9OWDlMUDZNa2RHcG0yc3RRazBqOVF6SlQ5N0F6VVVhMExaRWY3Q0RaYUR0NFJMN285MXI4bWdXTHBPUWhOdUdaSmVXbDBJY1AwRUE4OXk2SmVxcGpZemxkdmU2aFJaTXhkWXVvdzVZSEbSAa4BQVVfeXFMTmZwZ05aOExDUzdnQ29sb21SejF1b2FEdU95V0VPWF94aUpLT3BpWDR5UzNuTVZQb01nZWdMY1VBcEhyS3ZiUllmWm5NUUxFYnJJLU9KeUlFbnFXX3JxVHU5WFl1TUxIZG9TMGp5c2pEV0lyZFJ5ZzJuX2xTTlBHanpMTHpTZi05aUJfS2JTeGJENHRfOFp1ZDhpOXVIQVFnQURYcHpIYUFuSG9oSWdn?oc=5","published_at":"2025-01-29T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Rockwell Patches Critical, High-Severity Vulnerabilities in Several Products&nbsp;&nbsp;SecurityWeek","title":"Rockwell Patches Critical, High-Severity Vulnerabilities in Several Products - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-63a5318ada1253b9","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi3gFBVV95cUxOWmNMWFloWlJIMmkzbURDLXEtNnhUOEZLY1oyd050MXRTRFgwZzZGemFESFIwZmtIQndfRk5NWUxYbldGVVU2NmdoU0U4bVlDTC1tZl82b2EtcWN2VGVpNHZLMkNoMDFCM0lKdFpzYTZjdUF2ZlM1MEJOU0tnVVlyR1hyYXRTMm9kbUo4c2VZek1MNmFWSGsyOFZoM2xhMEZJT3VCZV9Lc0E0QkxQR1BYOTJMX2d6RmhTUWlsRW5Vb3NTa2NTVXZnMTV2NFpmYjVtMm1HWlQ4SW9USHU1Smc?oc=5","published_at":"2025-01-29T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA flags hardware vulnerabilities in ICS and medical devices; affects B&R, Schneider Electric, Rockwell, BD Systems&nbsp;&nbsp;Industrial Cyber","title":"CISA flags hardware vulnerabilities in ICS and medical devices; affects B&R, Schneider Electric, Rockwell, BD Systems - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-c16e8b9c7afb8c68","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxQeDZUZFJDTThFdGxpejlhUHdlbGNFZGJ1RFF0S1pmSjVHaEpGNHhnR2g3SW1rRWRXRDU5SDR5ak9OWDlMUDZNa2RHcG0yc3RRazBqOVF6SlQ5N0F6VVVhMExaRWY3Q0RaYUR0NFJMN285MXI4bWdXTHBPUWhOdUdaSmVXbDBJY1AwRUE4OXk2SmVxcGpZemxkdmU2aFJaTXhkWXVvdzVZSEbSAa4BQVVfeXFMTmZwZ05aOExDUzdnQ29sb21SejF1b2FEdU95V0VPWF94aUpLT3BpWDR5UzNuTVZQb01nZWdMY1VBcEhyS3ZiUllmWm5NUUxFYnJJLU9KeUlFbnFXX3JxVHU5WFl1TUxIZG9TMGp5c2pEV0lyZFJ5ZzJuX2xTTlBHanpMTHpTZi05aUJfS2JTeGJENHRfOFp1ZDhpOXVIQVFnQURYcHpIYUFuSG9oSWdn?oc=5","published_at":"2025-01-29T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Rockwell Patches Critical, High-Severity Vulnerabilities in Several Products&nbsp;&nbsp;securityweek.com","title":"Rockwell Patches Critical, High-Severity Vulnerabilities in Several Products - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-632234d33e3a779f","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiowFBVV95cUxQSW9ndWhkdlRzRHJ4eGp4dVZaX1Y2cE5CZ1ZyZS1nd3Izc24zaUV0N3ZDcTRBWXN0SG94TXVUTEVJd3hxQ2pLUXdtXzJtclJBZVVBSWJlRElScjlQWXgzeXBYSUNqeS1ZLTNoeHp5RmhENUFhdlNqSDVOUC1XSlliWjRELTd3Q3Z4MzhVRmxJVFpfS3NNbDJ3WVJTYTNNVWloT2Nz?oc=5","published_at":"2025-01-28T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Cybeats Signs Multi-Year Contract with Rockwell Automation&nbsp;&nbsp;newsfilecorp.com","title":"Cybeats Signs Multi-Year Contract with Rockwell Automation - newsfilecorp.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-fbcc72e23fb79d5b","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiowFBVV95cUxQSW9ndWhkdlRzRHJ4eGp4dVZaX1Y2cE5CZ1ZyZS1nd3Izc24zaUV0N3ZDcTRBWXN0SG94TXVUTEVJd3hxQ2pLUXdtXzJtclJBZVVBSWJlRElScjlQWXgzeXBYSUNqeS1ZLTNoeHp5RmhENUFhdlNqSDVOUC1XSlliWjRELTd3Q3Z4MzhVRmxJVFpfS3NNbDJ3WVJTYTNNVWloT2Nz?oc=5","published_at":"2025-01-28T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Cybeats Signs Multi-Year Contract with Rockwell Automation&nbsp;&nbsp;TMX Newsfile","title":"Cybeats Signs Multi-Year Contract with Rockwell Automation - TMX Newsfile"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-77ff57d3ae3e053a","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxNZWNua2diU0QzRVM5ZFVPX2M5VUl3cm8wRTN4OE5ZZk9scEg2M1VYWTNVX1kwU0t5TVNSMEZnelFaXy12WEI2QWpaRUtGbEJVWjNtREtSNFVjNnd1b2Y0NWVOakZZeTVVWVNiM2Q1ZnctemV6cVNCX2J5a1k4TC1SbUFkZUoyVDhkVFVrOVljYVpPVEVhbVJVUnA3Skxram0zOUFqUNIBqgFBVV95cUxPZVgzX0JIcXRQS2xvOWtMQTB6MUs4WWpxcFhrMWtJalVLZWx4YTRVdTZNY25WNkRCamZRUGJvVXNJbzA3cDlJRGRuYkNadmVxdnV1ellBZ0p4NkxOaXNvcjZNcUFRVkFQVnNuOXBGajZ0XzFLeDhBbVJRalk4WVB4N0ltcUtoZ3BKa3A1bGxaakdwdFZuZi11RU80azJuMFhuWG5GelhfQzFKUQ?oc=5","published_at":"2025-01-27T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Building Automation Protocols Increasingly Targeted in OT Attacks: Report&nbsp;&nbsp;SecurityWeek","title":"Building Automation Protocols Increasingly Targeted in OT Attacks: Report - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d14e4296ff567b70","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxNZWNua2diU0QzRVM5ZFVPX2M5VUl3cm8wRTN4OE5ZZk9scEg2M1VYWTNVX1kwU0t5TVNSMEZnelFaXy12WEI2QWpaRUtGbEJVWjNtREtSNFVjNnd1b2Y0NWVOakZZeTVVWVNiM2Q1ZnctemV6cVNCX2J5a1k4TC1SbUFkZUoyVDhkVFVrOVljYVpPVEVhbVJVUnA3Skxram0zOUFqUNIBqgFBVV95cUxPZVgzX0JIcXRQS2xvOWtMQTB6MUs4WWpxcFhrMWtJalVLZWx4YTRVdTZNY25WNkRCamZRUGJvVXNJbzA3cDlJRGRuYkNadmVxdnV1ellBZ0p4NkxOaXNvcjZNcUFRVkFQVnNuOXBGajZ0XzFLeDhBbVJRalk4WVB4N0ltcUtoZ3BKa3A1bGxaakdwdFZuZi11RU80azJuMFhuWG5GelhfQzFKUQ?oc=5","published_at":"2025-01-27T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Building Automation Protocols Increasingly Targeted in OT Attacks: Report&nbsp;&nbsp;securityweek.com","title":"Building Automation Protocols Increasingly Targeted in OT Attacks: Report - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f05ba4b4471cab35","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirAFBVV95cUxNdjhoMGNIMTJnX2l1NEVYYzVna1JoZmliODVzdzg0bTVCVEtqZVdxWEpDQVdWYkUxUFJmSUdKVHJOUGdQZWVzSFFpN0NfeXgxUGRkRENrZUt3YzMxb3pkbHZwMHVXMHU2UFNvVXlOU0ZEQnk2NU5LUjNKR0lLNVF4Z1BKQ1ZsdWV4cVY3MGlvREhPbHhXamh4NnhTdF9xWWxRX1RzX1VXbFNfTlJT0gGyAUFVX3lxTE00cHlmRE5kVEhVczhUT0JtRjhnN01iWjRhY2tOSklEODE5UWxyc2JOY19MOGtFZDU3YnlyVUpmQU01UmhiS1VndlVLb1piQ2tkQzMwblAxNVBtdTFEdlNnbng5T3JoYkk4TUV3OGF2b3Z6a1ZEdjFqZGV6VzRBcnAxaDQ2Y3FDRTk2ZlZsWXRkRV9iRDcxeHN0d3diOUdXdExfT0lMbTl1NjR1Q0l2UFFVUlE?oc=5","published_at":"2025-01-22T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Researcher Says ABB Building Control Products Affected by 1,000 Vulnerabilities&nbsp;&nbsp;SecurityWeek","title":"Researcher Says ABB Building Control Products Affected by 1,000 Vulnerabilities - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7ec841c1cc9ff4cb","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirAFBVV95cUxNdjhoMGNIMTJnX2l1NEVYYzVna1JoZmliODVzdzg0bTVCVEtqZVdxWEpDQVdWYkUxUFJmSUdKVHJOUGdQZWVzSFFpN0NfeXgxUGRkRENrZUt3YzMxb3pkbHZwMHVXMHU2UFNvVXlOU0ZEQnk2NU5LUjNKR0lLNVF4Z1BKQ1ZsdWV4cVY3MGlvREhPbHhXamh4NnhTdF9xWWxRX1RzX1VXbFNfTlJT0gGyAUFVX3lxTE00cHlmRE5kVEhVczhUT0JtRjhnN01iWjRhY2tOSklEODE5UWxyc2JOY19MOGtFZDU3YnlyVUpmQU01UmhiS1VndlVLb1piQ2tkQzMwblAxNVBtdTFEdlNnbng5T3JoYkk4TUV3OGF2b3Z6a1ZEdjFqZGV6VzRBcnAxaDQ2Y3FDRTk2ZlZsWXRkRV9iRDcxeHN0d3diOUdXdExfT0lMbTl1NjR1Q0l2UFFVUlE?oc=5","published_at":"2025-01-22T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Researcher Says ABB Building Control Products Affected by 1,000 Vulnerabilities&nbsp;&nbsp;securityweek.com","title":"Researcher Says ABB Building Control Products Affected by 1,000 Vulnerabilities - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-01958779315d5da9","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxNVW9EN1VzSXFMZUo0T3NnZHdQYWtHaWFrUFhpcFJWN05GbkhJYUdGTm1ZNU0zVHp0Ym5MN3BfSkFRNTNwTFAwN2FURHFzNWF4NzV0SW1mejFFQ1RKZnJ2cUtwYUQ5ZXFvanZDN1h4UXpqWlZRVDd6ejJkLV90MzZZWC1n?oc=5","published_at":"2025-01-17T08:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Critical Flaws in WGS-804HPT Switches Enable RCE and Network Exploitation&nbsp;&nbsp;thehackernews.com","title":"Critical Flaws in WGS-804HPT Switches Enable RCE and Network Exploitation - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-162b796d5993f6cc","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxNVW9EN1VzSXFMZUo0T3NnZHdQYWtHaWFrUFhpcFJWN05GbkhJYUdGTm1ZNU0zVHp0Ym5MN3BfSkFRNTNwTFAwN2FURHFzNWF4NzV0SW1mejFFQ1RKZnJ2cUtwYUQ5ZXFvanZDN1h4UXpqWlZRVDd6ejJkLV90MzZZWC1n?oc=5","published_at":"2025-01-17T08:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Critical Flaws in WGS-804HPT Switches Enable RCE and Network Exploitation&nbsp;&nbsp;The Hacker News","title":"Critical Flaws in WGS-804HPT Switches Enable RCE and Network Exploitation - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-be2b871796bd9b03","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi_AFBVV95cUxOM2wzeEJZZ0o1WTBwb2V5U0Z3X3JpU3c0VmhlelBxUkltcDNYSnFQekVUWFo4MFFKSDl3RDhLS1ozdDU5MjNMZV9xUlg3VDhoS3ZTU0V4QktYR3BMdDhlVG52a05GLWVUUUM1RGYwLW10TGlvM3VxaklGQ2MyV2hhQ1lGSXU3VFo5TmFFelQtRTJySFJ2bTB2emJYWDBsbjFESmg2MWhPaWkyczB6SllyRGcxVlAyb1pza1B3UDhDT2tuSWlGMjJRRjgtSi15b25TSzE0cURfNmt5OENqYWpUbnVJTEdYUTRCRzJDc21TelBDQU4wdTR3T2pka2M?oc=5","published_at":"2025-01-13T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA reports security vulnerabilities in ICS equipment from Schneider Electric, Delta Electronics, Rockwell Automation&nbsp;&nbsp;Industrial Cyber","title":"CISA reports security vulnerabilities in ICS equipment from Schneider Electric, Delta Electronics, Rockwell Automation - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-465cd0751e639eea","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi_AFBVV95cUxOM2wzeEJZZ0o1WTBwb2V5U0Z3X3JpU3c0VmhlelBxUkltcDNYSnFQekVUWFo4MFFKSDl3RDhLS1ozdDU5MjNMZV9xUlg3VDhoS3ZTU0V4QktYR3BMdDhlVG52a05GLWVUUUM1RGYwLW10TGlvM3VxaklGQ2MyV2hhQ1lGSXU3VFo5TmFFelQtRTJySFJ2bTB2emJYWDBsbjFESmg2MWhPaWkyczB6SllyRGcxVlAyb1pza1B3UDhDT2tuSWlGMjJRRjgtSi15b25TSzE0cURfNmt5OENqYWpUbnVJTEdYUTRCRzJDc21TelBDQU4wdTR3T2pka2M?oc=5","published_at":"2025-01-13T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA reports security vulnerabilities in ICS equipment from Schneider Electric, Delta Electronics, Rockwell Automation&nbsp;&nbsp;industrialcyber.co","title":"CISA reports security vulnerabilities in ICS equipment from Schneider Electric, Delta Electronics, Rockwell Automation - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-dfd05ec2e3f39756","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMizgFBVV95cUxNLWtFaU1DdXNnQkhPdWZxR3UwbllWaEtJUjJfbmFNQlR4d3BIRzNRWlFvclJoUGtOSVNLRURNaUFHcDJWWHlBVF9RMW1fLWNkZEowOEo1Q3htWXdNaHZnSkJJejAyZW9BSTZMcWQ5Y1k4VFExRkRoaDFiaUFvcHV1MmNMTV9iTnNmd3AzbDFYdjJsM0hOaS1kVDV4YkppSHdvQXUwX1N2T2hmUWVEb1R3SFBfaW96X3NTa2YydVpra0F6bW9lQ0k5R2ZDaVFZQQ?oc=5","published_at":"2025-01-08T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Technology Spotlight on industrial cybersecurity&nbsp;&nbsp;Canadian Metalworking","title":"Technology Spotlight on industrial cybersecurity - Canadian Metalworking"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f3c2064b311180f1","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiZ0FVX3lxTE5UMEhYMV9Gd2xDbG16MXZlNGx4dC1ObUNYQm9NbUVvZ3Z3OVpJclRuT0U1UnpoVlE0RVR4d0p6RWd2QzhhUTFTcU8yOWJRdm1RNm5JZDJfV1BObGlrWkwxazh2UG96Z0U?oc=5","published_at":"2024-12-20T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Building Automation & LoRaWAN","summary":"Siemens UMC Vulnerability Let Remote Attacker Execute Arbitrary Code&nbsp;&nbsp;CyberSecurityNews","title":"Siemens UMC Vulnerability Let Remote Attacker Execute Arbitrary Code - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-94503156bc9bac60","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitAFBVV95cUxPUkd6Q3l3VjZEdXJWT3YyTkN2QUNPaEw5TG9Ic3M5eUhycm9rWlhoX2JJNk5IbXJqdVE2NTZrYWxHTVlBOElmdGluVTNwY0J5dkVLaFBwb3hQcWM5T3k1LWVsYVpaV3NPZGdFUVNBOFQ1R2dYeXdMVUpDMWVxcXd2OVM2RGpKV2hVOWh2SEhGSGFWbW12SFFpZF8zQkdPbUFxX0pqd1F1ZGdVdDA0SFgwdEJaSzQ?oc=5","published_at":"2024-12-13T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"Iran-linked IOCONTROL malware targets critical IoT/OT infrastructure in Israel, US&nbsp;&nbsp;Industrial Cyber","title":"Iran-linked IOCONTROL malware targets critical IoT/OT infrastructure in Israel, US - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e66b2ce2ab8e7b8b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitAFBVV95cUxPUkd6Q3l3VjZEdXJWT3YyTkN2QUNPaEw5TG9Ic3M5eUhycm9rWlhoX2JJNk5IbXJqdVE2NTZrYWxHTVlBOElmdGluVTNwY0J5dkVLaFBwb3hQcWM5T3k1LWVsYVpaV3NPZGdFUVNBOFQ1R2dYeXdMVUpDMWVxcXd2OVM2RGpKV2hVOWh2SEhGSGFWbW12SFFpZF8zQkdPbUFxX0pqd1F1ZGdVdDA0SFgwdEJaSzQ?oc=5","published_at":"2024-12-13T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"Iran-linked IOCONTROL malware targets critical IoT/OT infrastructure in Israel, US&nbsp;&nbsp;industrialcyber.co","title":"Iran-linked IOCONTROL malware targets critical IoT/OT infrastructure in Israel, US - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-946bfb59eedb8165","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE9JNEFCeUY5TFVmYW1kRl9YRjI2UV9rOVF6WGU0LWpjTUk2bE9yXzVkd25ma21ZMjY5d3JmQ0tubDlTQmJ5VHFqZU9ZWXI3YWpIaXMtUUZybFlJZFBCOVlv?oc=5","published_at":"2024-11-26T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Transforming industrial automation: voice recognition control via containerized PLC device&nbsp;&nbsp;Nature","title":"Transforming industrial automation: voice recognition control via containerized PLC device - Nature"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-4ce044d17cecd2c9","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE9JNEFCeUY5TFVmYW1kRl9YRjI2UV9rOVF6WGU0LWpjTUk2bE9yXzVkd25ma21ZMjY5d3JmQ0tubDlTQmJ5VHFqZU9ZWXI3YWpIaXMtUUZybFlJZFBCOVlv?oc=5","published_at":"2024-11-26T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Transforming industrial automation: voice recognition control via containerized PLC device&nbsp;&nbsp;nature.com","title":"Transforming industrial automation: voice recognition control via containerized PLC device - nature.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-6f7d2a0ad33aebc9","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE91VGFWYlliaThQUzRkSmJaMFdZVDk0b3NoYi1senBENTM4ZTNBYWxsTDJHd3FtYUtKSmFDY2x6aDBpYmNzTGhEODRPMW5qdmdhUUtwczVJRDU1QXBPWC1n?oc=5","published_at":"2024-11-16T08:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Sex-specific GABAergic microcircuits that switch vulnerability into resilience to stress and reverse the effects of chronic stress exposure | Molecular Psychiatry&nbsp;&nbsp;Nature","title":"Sex-specific GABAergic microcircuits that switch vulnerability into resilience to stress and reverse the effects of chronic stress exposure | Molecular Psychiatry - Nature"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-1f3ae481299d04ea","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE91VGFWYlliaThQUzRkSmJaMFdZVDk0b3NoYi1senBENTM4ZTNBYWxsTDJHd3FtYUtKSmFDY2x6aDBpYmNzTGhEODRPMW5qdmdhUUtwczVJRDU1QXBPWC1n?oc=5","published_at":"2024-11-16T08:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Sex-specific GABAergic microcircuits that switch vulnerability into resilience to stress and reverse the effects of chronic stress exposure | Molecular Psychiatry&nbsp;&nbsp;nature.com","title":"Sex-specific GABAergic microcircuits that switch vulnerability into resilience to stress and reverse the effects of chronic stress exposure | Molecular Psychiatry - nature.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-09b1fb12531af8dd","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMigAFBVV95cUxOSVQ5Y1lkQVB2eTFKV3luaGFZLW9KdVZJd2M0LVBLNUZ1cUN0THNMWkJlNGlCbGlMbFJqS2RxZGhuOTlLbFRlUHNLSm5ORmhiUWsyS2stUmtONy04aTJpZzQ0U3dWQUZYRnA2enFXTUw5NDJ5bEY2QmdCUURMUVlwbA?oc=5","published_at":"2024-11-13T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"OvrC Platform Vulnerabilities Expose IoT Devices to Remote Attacks and Code Execution&nbsp;&nbsp;The Hacker News","title":"OvrC Platform Vulnerabilities Expose IoT Devices to Remote Attacks and Code Execution - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5d7d239e3bc4e143","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiY0FVX3lxTE5rVm4yckRMcjZiSkt6OXJJTEZMc25nQWxBTnNSOHVFY1dMLThvV0ZfMG1mTUFOT1hSblRLM2gyenQ4ZWN0MHVRMFdvemdFcFk3QmNfWG0zUzNvLTBYTWRwOFN5NA?oc=5","published_at":"2024-11-12T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"ICS Security Is a Team Sport&nbsp;&nbsp;bitsight.com","title":"ICS Security Is a Team Sport - bitsight.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-cb042d5a8e541a93","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiY0FVX3lxTE5rVm4yckRMcjZiSkt6OXJJTEZMc25nQWxBTnNSOHVFY1dMLThvV0ZfMG1mTUFOT1hSblRLM2gyenQ4ZWN0MHVRMFdvemdFcFk3QmNfWG0zUzNvLTBYTWRwOFN5NA?oc=5","published_at":"2024-11-12T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"ICS Security Is a Team Sport&nbsp;&nbsp;Bitsight","title":"ICS Security Is a Team Sport - Bitsight"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-91fed433d1bc1ad1","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxQaFZaWUZlWGVkcjJ2SE9GV0NtYmtxWlZXTDAyOFRMc3NUbDBPd1BNYU8zVjE0bF9JNTJZX3R5SXduMjJwMXQ5SGNrZlB3dTZJRTVldDhzY1JXY3lTa2RIMXZEUndydVVFVmNGd1VCUzlZTGZBb0pFVEZZNnd5aXBHMFVB?oc=5","published_at":"2024-11-05T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Rockwell ThinManager Vulnerability Exposes Systems To DoS Condition&nbsp;&nbsp;cybersecuritynews.com","title":"Rockwell ThinManager Vulnerability Exposes Systems To DoS Condition - cybersecuritynews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-eeeba60a29a332a8","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxQaFZaWUZlWGVkcjJ2SE9GV0NtYmtxWlZXTDAyOFRMc3NUbDBPd1BNYU8zVjE0bF9JNTJZX3R5SXduMjJwMXQ5SGNrZlB3dTZJRTVldDhzY1JXY3lTa2RIMXZEUndydVVFVmNGd1VCUzlZTGZBb0pFVEZZNnd5aXBHMFVB?oc=5","published_at":"2024-11-05T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Rockwell ThinManager Vulnerability Exposes Systems To DoS Condition&nbsp;&nbsp;CyberSecurityNews","title":"Rockwell ThinManager Vulnerability Exposes Systems To DoS Condition - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-f4adfd173da44688","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxQazVuMUZQQkhHSWhWQVp4UDZiZTI2Qnl5ZHc4MmR2UFp1ODhwbUEwdFBTakVIYzNjc3cwVHZKV3liQ2NacDFHT2NEZXRqRFFfYmlQMGY2Z1VycmJfTWZVTU1TYWpHLTNjSEZsQ3BCdGZLeXZoelVWZDJtNmR5YWtmcEt3LURWMDVLSnd0a1l1RVZKdFdHNThFNlJGN1pWM1VxVlU4dzJVVENBVVlEblN4LdIBtgFBVV95cUxONFNkajhhNGZJRWltRmR3SnRoaEY2dXk1VjZqbTVoR1preElpUmRqQTF6b3owQjhscFpmUGRKMEhNUUJubC1yVzFlZURvbldwTFlnbE9XMkRzMHNKRlowRVltTUNlSzVHb3NteFVISlNtTXRfYXdlQUl2ckM3WXFoVkNjX25qUDBLRGhqX2RTR3VlaDZIckpzQXJ2ZHltT0wyRjRud2tuSXEtMGdFR2JjZ0I4SE1UQQ?oc=5","published_at":"2024-11-04T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Siemens and Rockwell Tackle Industrial Cybersecurity, but Face Customer Hesitation&nbsp;&nbsp;securityweek.com","title":"Siemens and Rockwell Tackle Industrial Cybersecurity, but Face Customer Hesitation - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-ab5e3808afec645d","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxQazVuMUZQQkhHSWhWQVp4UDZiZTI2Qnl5ZHc4MmR2UFp1ODhwbUEwdFBTakVIYzNjc3cwVHZKV3liQ2NacDFHT2NEZXRqRFFfYmlQMGY2Z1VycmJfTWZVTU1TYWpHLTNjSEZsQ3BCdGZLeXZoelVWZDJtNmR5YWtmcEt3LURWMDVLSnd0a1l1RVZKdFdHNThFNlJGN1pWM1VxVlU4dzJVVENBVVlEblN4LdIBtgFBVV95cUxONFNkajhhNGZJRWltRmR3SnRoaEY2dXk1VjZqbTVoR1preElpUmRqQTF6b3owQjhscFpmUGRKMEhNUUJubC1yVzFlZURvbldwTFlnbE9XMkRzMHNKRlowRVltTUNlSzVHb3NteFVISlNtTXRfYXdlQUl2ckM3WXFoVkNjX25qUDBLRGhqX2RTR3VlaDZIckpzQXJ2ZHltT0wyRjRud2tuSXEtMGdFR2JjZ0I4SE1UQQ?oc=5","published_at":"2024-11-04T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Siemens and Rockwell Tackle Industrial Cybersecurity, but Face Customer Hesitation&nbsp;&nbsp;SecurityWeek","title":"Siemens and Rockwell Tackle Industrial Cybersecurity, but Face Customer Hesitation - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1d27bafdc4f50039","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiigFBVV95cUxOdEZlLW5uWldPT0FWLXVZWGx0Y1NIV0hKNm5WUzFRbkp0cmhhZi1PRzlXSDM4NldwNmhzNlJWNE44MzFGQ1RDQ212bmgtQkJraG5JMzNodm03MGYtM1Vwa0llNkV0U09pWVc3MzBRTVdrLUtHczZqQ3NxcWJmeWk3RFVMeEZwMWNWd3c?oc=5","published_at":"2024-10-31T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"How Will Generative AI Change Cybersecurity Teams?&nbsp;&nbsp;GovTech","title":"How Will Generative AI Change Cybersecurity Teams? - GovTech"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6fc5f051ce3312ce","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiigFBVV95cUxOdEZlLW5uWldPT0FWLXVZWGx0Y1NIV0hKNm5WUzFRbkp0cmhhZi1PRzlXSDM4NldwNmhzNlJWNE44MzFGQ1RDQ212bmgtQkJraG5JMzNodm03MGYtM1Vwa0llNkV0U09pWVc3MzBRTVdrLUtHczZqQ3NxcWJmeWk3RFVMeEZwMWNWd3c?oc=5","published_at":"2024-10-31T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"How Will Generative AI Change Cybersecurity Teams?&nbsp;&nbsp;govtech.com","title":"How Will Generative AI Change Cybersecurity Teams? - govtech.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-1d6567c5d7aa32ea","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTFB4c0RhdUNBZFJHd0Fjel9JUjJWY3huWnFCNEc2VmRFTVNqZWhQenVTbkJhT2xpWmp3X3JhZGcwSXJJUEplLWxaRTJaUHNEellla05YbDkyUmNsYlNYU1pV?oc=5","published_at":"2024-10-27T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Non-adaptedness and vulnerability to climate change threaten Plathymenia trees (Fabaceae) from the Cerrado and Atlantic Forest&nbsp;&nbsp;Nature","title":"Non-adaptedness and vulnerability to climate change threaten Plathymenia trees (Fabaceae) from the Cerrado and Atlantic Forest - Nature"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-85d4cf5a99474f99","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTFB4c0RhdUNBZFJHd0Fjel9JUjJWY3huWnFCNEc2VmRFTVNqZWhQenVTbkJhT2xpWmp3X3JhZGcwSXJJUEplLWxaRTJaUHNEellla05YbDkyUmNsYlNYU1pV?oc=5","published_at":"2024-10-27T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Non-adaptedness and vulnerability to climate change threaten Plathymenia trees (Fabaceae) from the Cerrado and Atlantic Forest&nbsp;&nbsp;nature.com","title":"Non-adaptedness and vulnerability to climate change threaten Plathymenia trees (Fabaceae) from the Cerrado and Atlantic Forest - nature.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-0f46d92aca62577b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi1wFBVV95cUxNWnhUX0VjeUlZcW1paHA1VzRqQVIzcWYxZXI4bS1vNVVHWnlxWkN6eHhibzcyS1pNV1hoUHE4YUhvTVo4UWJyYXhUWFRRNGpaQ0ZmeE9hci0ySXVlY2p2RlkwTXplOHZrbzJfVVIzUjNvT1hGb0J1d2RjTzdFa2hnM3RDakVQMEdNTEhQM2RScFJWRUZHdTltelltOG5LZGN1VlcyZ3gxODhfQURBbldGM2MwVV9hVTlFRk5TSHFiZVpYdnlYNGNpc0lRdXhRTUhQaTQwLUxvcw?oc=5","published_at":"2024-10-01T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Providers Boost Cybersecurity Spending in Wake of Change Healthcare Breach&nbsp;&nbsp;aha.org","title":"Providers Boost Cybersecurity Spending in Wake of Change Healthcare Breach - aha.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b6d209482728210d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi1wFBVV95cUxNWnhUX0VjeUlZcW1paHA1VzRqQVIzcWYxZXI4bS1vNVVHWnlxWkN6eHhibzcyS1pNV1hoUHE4YUhvTVo4UWJyYXhUWFRRNGpaQ0ZmeE9hci0ySXVlY2p2RlkwTXplOHZrbzJfVVIzUjNvT1hGb0J1d2RjTzdFa2hnM3RDakVQMEdNTEhQM2RScFJWRUZHdTltelltOG5LZGN1VlcyZ3gxODhfQURBbldGM2MwVV9hVTlFRk5TSHFiZVpYdnlYNGNpc0lRdXhRTUhQaTQwLUxvcw?oc=5","published_at":"2024-10-01T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Providers Boost Cybersecurity Spending in Wake of Change Healthcare Breach&nbsp;&nbsp;American Hospital Association","title":"Providers Boost Cybersecurity Spending in Wake of Change Healthcare Breach - American Hospital Association"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2abe0d36ece807d3","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMidEFVX3lxTE5UbWhMbUZaSjh5Vnh3ZmFocGFoVUUxY1ZhS3hRZnVMY293NEtpejlmdGFKUTdzQ2xoMUROYmtLeWVCVlZWZWdHUF93SHo4S3B6dGxwNENGSERiSDlaN3J1VTQ1TmdYZEVvT0E1cnZqLUVDRGsw?oc=5","published_at":"2024-09-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Threat landscape for industrial automation systems, Q2 2024&nbsp;&nbsp;Securelist","title":"Threat landscape for industrial automation systems, Q2 2024 - Securelist"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-63664e1b094cc243","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMie0FVX3lxTE0yaFFFcEpqcjBaX0pNYkFFUHFaaEl2bFNEd0hzbHc2aXBaSnZDMlBWSGF6eVVEMU8wWEdNMk13SVM0Q3BXTldTUnFPM0NXemQ3ZlNhSDBQeFZXZk01YkVZOTZJN2lwY0M5cGRIdDE4V01nRmtkMVFFWExpa9IBgAFBVV95cUxNeDdTdVJNTVppLW83dXEtcVJWa0x3ZkdjY3BnaEZ3Rm96b2dzTW92bVBLaUxwbXEwTGxWVnN2U19xUmRVZ1BWUEFKeXEwRWdHaHV4ejlmc1VMR2JfU1NnOFl0dnZUVXVBeWN6RFpuNklES0s3VHhSVVFoZE9FaUhQVQ?oc=5","published_at":"2024-09-26T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"Critical RCE vulnerability found in OpenPLC&nbsp;&nbsp;Security Affairs","title":"Critical RCE vulnerability found in OpenPLC - Security Affairs"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-87e17ed26977c2cb","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMie0FVX3lxTE0yaFFFcEpqcjBaX0pNYkFFUHFaaEl2bFNEd0hzbHc2aXBaSnZDMlBWSGF6eVVEMU8wWEdNMk13SVM0Q3BXTldTUnFPM0NXemQ3ZlNhSDBQeFZXZk01YkVZOTZJN2lwY0M5cGRIdDE4V01nRmtkMVFFWExpa9IBgAFBVV95cUxNeDdTdVJNTVppLW83dXEtcVJWa0x3ZkdjY3BnaEZ3Rm96b2dzTW92bVBLaUxwbXEwTGxWVnN2U19xUmRVZ1BWUEFKeXEwRWdHaHV4ejlmc1VMR2JfU1NnOFl0dnZUVXVBeWN6RFpuNklES0s3VHhSVVFoZE9FaUhQVQ?oc=5","published_at":"2024-09-26T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"Critical RCE vulnerability found in OpenPLC&nbsp;&nbsp;securityaffairs.com","title":"Critical RCE vulnerability found in OpenPLC - securityaffairs.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-15427fc2f95c3b72","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMijwFBVV95cUxOOXNtdUlwOXUwRWtieVNWaVowLVp2c1loNkowZ05zYmwwZW5ScFJMVy1xcVlqVWh1RDRBZXJuR2xpV2dnWW9LQ0xfS2dQMExZa1RzeHFSM2FqUnZKc1F2OWdOS2ZXU2VQNEtyUWFqUW56NDdsWlJEM1NmVUlRNHROQ0JacXdoS2RWRG1JTFZLQQ?oc=5","published_at":"2024-09-24T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"HIGH","source":"Rockwell & CIP Security","summary":"Rockwell Automation PLC Software Contains RCE Flaw&nbsp;&nbsp;bankinfosecurity.com","title":"Rockwell Automation PLC Software Contains RCE Flaw - bankinfosecurity.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-e8d37ad3bbaf2100","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMijwFBVV95cUxOOXNtdUlwOXUwRWtieVNWaVowLVp2c1loNkowZ05zYmwwZW5ScFJMVy1xcVlqVWh1RDRBZXJuR2xpV2dnWW9LQ0xfS2dQMExZa1RzeHFSM2FqUnZKc1F2OWdOS2ZXU2VQNEtyUWFqUW56NDdsWlJEM1NmVUlRNHROQ0JacXdoS2RWRG1JTFZLQQ?oc=5","published_at":"2024-09-24T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"HIGH","source":"Rockwell & CIP Security","summary":"Rockwell Automation PLC Software Contains RCE Flaw&nbsp;&nbsp;BankInfoSecurity","title":"Rockwell Automation PLC Software Contains RCE Flaw - BankInfoSecurity"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-5a7604f7abe9f990","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiigFBVV95cUxON0xOeVg0aHVJSUsyQVNoZTAtNXRkeW40eE96a0tjQ3FZd0owdEIwM290Wl9QNkt1YWF4TUxRLVRmT1ltSEZLSWlWSFZmb1hBLTM1NUpycEJFRV9kZWs5UUNtYWx3VWpUZi1YU2ZWbXgzVjdTcnk3TGYtZzlQX1NIU2tXRUNOMkh6RGc?oc=5","published_at":"2024-09-23T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Inductive Automation Previews Upcoming Ignition 8.3 Release, Announces 2024 Ignition Firebrand Award Winners&nbsp;&nbsp;Automation.com","title":"Inductive Automation Previews Upcoming Ignition 8.3 Release, Announces 2024 Ignition Firebrand Award Winners - Automation.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-4aa715de783db1d7","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiigFBVV95cUxON0xOeVg0aHVJSUsyQVNoZTAtNXRkeW40eE96a0tjQ3FZd0owdEIwM290Wl9QNkt1YWF4TUxRLVRmT1ltSEZLSWlWSFZmb1hBLTM1NUpycEJFRV9kZWs5UUNtYWx3VWpUZi1YU2ZWbXgzVjdTcnk3TGYtZzlQX1NIU2tXRUNOMkh6RGc?oc=5","published_at":"2024-09-23T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Inductive Automation Previews Upcoming Ignition 8.3 Release, Announces 2024 Ignition Firebrand Award Winners&nbsp;&nbsp;automation.com","title":"Inductive Automation Previews Upcoming Ignition 8.3 Release, Announces 2024 Ignition Firebrand Award Winners - automation.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-8f98129a469b38ed","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiywFBVV95cUxPV2RvcVlQeklhX3FJdnV2a0NKclFrdWc3TmstRXFORy03MF9UZXpjQkU4R2kxck1zZkRkQmc5QU5EQ2lvY082dVlORklnNjZldmJhNURhWF8xYjd2SnQ3UlJXbUdmdDY2bVI5c1laQU1ibWhHMmdxY0xqOTVKUXJmR0EwbmtST1cxanVmaG5XNVFET3BXc1RVXzJxX2VYNFN3VV9yREd2dkFhVk1tSi1KT3l2N3p5MG1yQkpFaUE0RmxTLVdkbXlmYnlmQQ?oc=5","published_at":"2024-09-12T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA warns of ICS vulnerabilities in Viessmann, iniNet, Rockwell Automation, BPL Medical Technologies&nbsp;&nbsp;industrialcyber.co","title":"CISA warns of ICS vulnerabilities in Viessmann, iniNet, Rockwell Automation, BPL Medical Technologies - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b5bc060f1e8e0bbf","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiwwFBVV95cUxNSGE1a2F5c010V1VWMk9lSHBwQklxb1c5UHVHSHZ5MWV0QTJsVnV3MW42MmkxZk9hNHpRZGw3SDNZX2RudTN2SkU0azFjSXluRFBNWVVneFdMNldTbFpnaHRNMkFCTzRPZ2dWaEpLd3l4Y0oxMEdDNnlPc1Z0Rmo3ell0QXVubHZPYkJLQjl2Q3JSY3JNbDFZS3VfN1ZwWmVQVEdzN2dES2RIblowczMwQ2lGbnVLR3IydmhYUzdwbHAyQk0?oc=5","published_at":"2024-09-12T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"How the Secure by Design initiative can change cybersecurity strategies&nbsp;&nbsp;Washington Technology","title":"How the Secure by Design initiative can change cybersecurity strategies - Washington Technology"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8045465e229ac283","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiwwFBVV95cUxNSGE1a2F5c010V1VWMk9lSHBwQklxb1c5UHVHSHZ5MWV0QTJsVnV3MW42MmkxZk9hNHpRZGw3SDNZX2RudTN2SkU0azFjSXluRFBNWVVneFdMNldTbFpnaHRNMkFCTzRPZ2dWaEpLd3l4Y0oxMEdDNnlPc1Z0Rmo3ell0QXVubHZPYkJLQjl2Q3JSY3JNbDFZS3VfN1ZwWmVQVEdzN2dES2RIblowczMwQ2lGbnVLR3IydmhYUzdwbHAyQk0?oc=5","published_at":"2024-09-12T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"How the Secure by Design initiative can change cybersecurity strategies&nbsp;&nbsp;washingtontechnology.com","title":"How the Secure by Design initiative can change cybersecurity strategies - washingtontechnology.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-66bd01cb1291d9b8","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiywFBVV95cUxPV2RvcVlQeklhX3FJdnV2a0NKclFrdWc3TmstRXFORy03MF9UZXpjQkU4R2kxck1zZkRkQmc5QU5EQ2lvY082dVlORklnNjZldmJhNURhWF8xYjd2SnQ3UlJXbUdmdDY2bVI5c1laQU1ibWhHMmdxY0xqOTVKUXJmR0EwbmtST1cxanVmaG5XNVFET3BXc1RVXzJxX2VYNFN3VV9yREd2dkFhVk1tSi1KT3l2N3p5MG1yQkpFaUE0RmxTLVdkbXlmYnlmQQ?oc=5","published_at":"2024-09-12T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA warns of ICS vulnerabilities in Viessmann, iniNet, Rockwell Automation, BPL Medical Technologies&nbsp;&nbsp;Industrial Cyber","title":"CISA warns of ICS vulnerabilities in Viessmann, iniNet, Rockwell Automation, BPL Medical Technologies - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-34084baeb2385e19","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi2gFBVV95cUxOenNudzZMd25CNEJTVjlDcUt2bmFoNTcxcU85UzNlOFB1Wks3bFB4YUNZU3lhUUMxUF9zTXhKY3hDdWNkeGc5ZTlNbUhwQkF6Y0FVWkh6ZWNacWswbjBGZjZLU1JEOTZJZmZQcm1zaE9fMXdTM203dE5zS3VRajNkSEpZczZSeGxfcFJodTJaMU5KNWtub2Zybml3OGZZdl9CaUJBSFo1bHFFeTItbktfa25TN2tHeVdkOVlFLXhtUl8yd1hVRWdqa2lqb1JCQUlqaHp6LUMzaFRNUQ?oc=5","published_at":"2024-09-11T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"GSA advances Building Automation Systems and connectivity to reduce security risk and promote small business contract opportunities&nbsp;&nbsp;gsa.gov","title":"GSA advances Building Automation Systems and connectivity to reduce security risk and promote small business contract opportunities - gsa.gov"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ffda71866de0e987","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi2gFBVV95cUxOenNudzZMd25CNEJTVjlDcUt2bmFoNTcxcU85UzNlOFB1Wks3bFB4YUNZU3lhUUMxUF9zTXhKY3hDdWNkeGc5ZTlNbUhwQkF6Y0FVWkh6ZWNacWswbjBGZjZLU1JEOTZJZmZQcm1zaE9fMXdTM203dE5zS3VRajNkSEpZczZSeGxfcFJodTJaMU5KNWtub2Zybml3OGZZdl9CaUJBSFo1bHFFeTItbktfa25TN2tHeVdkOVlFLXhtUl8yd1hVRWdqa2lqb1JCQUlqaHp6LUMzaFRNUQ?oc=5","published_at":"2024-09-11T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"GSA advances Building Automation Systems and connectivity to reduce security risk and promote small business contract opportunities&nbsp;&nbsp;GSA (.gov)","title":"GSA advances Building Automation Systems and connectivity to reduce security risk and promote small business contract opportunities - GSA (.gov)"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-0eeb3e5d45103c08","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxQeGNoaDhaX3ZqSGJrVVF0OG9WbkxsVG1oeFJuNjBpdTVDTkxkS1hNNHlILWk1N1liMGZXNWo5TFRXdGV6VEVMVGdEYW5ZMzFrcVlBSTc5NWlPeEl3WDJJZmVKWGRVTXRwSWE1Tll3RUo1em1uZ3BRd2lvb0NhQ1VSZ3FB?oc=5","published_at":"2024-09-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Climate change, vulnerability and migration: impacts on children and youth in Southeast Asia&nbsp;&nbsp;sei.org","title":"Climate change, vulnerability and migration: impacts on children and youth in Southeast Asia - sei.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-525c0c172bd56e16","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxQeGNoaDhaX3ZqSGJrVVF0OG9WbkxsVG1oeFJuNjBpdTVDTkxkS1hNNHlILWk1N1liMGZXNWo5TFRXdGV6VEVMVGdEYW5ZMzFrcVlBSTc5NWlPeEl3WDJJZmVKWGRVTXRwSWE1Tll3RUo1em1uZ3BRd2lvb0NhQ1VSZ3FB?oc=5","published_at":"2024-09-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Climate change, vulnerability and migration: impacts on children and youth in Southeast Asia&nbsp;&nbsp;Stockholm Environment Institute","title":"Climate change, vulnerability and migration: impacts on children and youth in Southeast Asia - Stockholm Environment Institute"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-a012e0a3e43630ea","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiywFBVV95cUxNdGw3OE03MVlNc0RadThpLXZFYkl2T1dYdHZ1b0lwTjhuMWpJUjMzUEMtb3lRQ3BsTXJHd3FsLUFpSHp6M29EX3NkRGlpRm9zeEdNd0xULWwtM0VYM2VaUnNMcFVrTjdRNUc1NmoyVTB5OEROSjFITG9JMHFTXy1kdjdaUi1rWk90U2lsLUFteDI4Q3ZKTHYwUXNPekF6cVJLcjB4Zld1S1V2Q1hDTVFzcTJwU0swNEYzdEZJT3hZVFYwLXZzVEFqTE5WWQ?oc=5","published_at":"2024-08-18T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Rising cybersecurity demands reshape ICS procurement strategies across critical infrastructure&nbsp;&nbsp;Industrial Cyber","title":"Rising cybersecurity demands reshape ICS procurement strategies across critical infrastructure - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-04a888058000bc88","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiywFBVV95cUxNdGw3OE03MVlNc0RadThpLXZFYkl2T1dYdHZ1b0lwTjhuMWpJUjMzUEMtb3lRQ3BsTXJHd3FsLUFpSHp6M29EX3NkRGlpRm9zeEdNd0xULWwtM0VYM2VaUnNMcFVrTjdRNUc1NmoyVTB5OEROSjFITG9JMHFTXy1kdjdaUi1rWk90U2lsLUFteDI4Q3ZKTHYwUXNPekF6cVJLcjB4Zld1S1V2Q1hDTVFzcTJwU0swNEYzdEZJT3hZVFYwLXZzVEFqTE5WWQ?oc=5","published_at":"2024-08-18T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Rising cybersecurity demands reshape ICS procurement strategies across critical infrastructure&nbsp;&nbsp;industrialcyber.co","title":"Rising cybersecurity demands reshape ICS procurement strategies across critical infrastructure - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d01161c740e94891","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxQdFRYdWk3ZXktSDlVTFUwYkRkclpzZTV6SFluaFJjN3V0eVJLNkoycVVHYzR0UzJJUWdsa2dLMGlmMVdUQkZES1RQa2J4Z1ZZQXo2TUNPN0N5ODgtX19URUdLOUVQVmxFbmFseEQzN1NIa2hHM0M2SFJrWFdUSjFaQXJnbG1xWWZXSkxLQmhYNUliWDJqSzZiMWxIT0stY1RWN01iZWhZaUI?oc=5","published_at":"2024-08-16T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Industrial control systems are increasingly vulnerable to cyberattacks&nbsp;&nbsp;securitybrief.com.au","title":"Industrial control systems are increasingly vulnerable to cyberattacks - securitybrief.com.au"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8b4cca8a9230d39c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxQdFRYdWk3ZXktSDlVTFUwYkRkclpzZTV6SFluaFJjN3V0eVJLNkoycVVHYzR0UzJJUWdsa2dLMGlmMVdUQkZES1RQa2J4Z1ZZQXo2TUNPN0N5ODgtX19URUdLOUVQVmxFbmFseEQzN1NIa2hHM0M2SFJrWFdUSjFaQXJnbG1xWWZXSkxLQmhYNUliWDJqSzZiMWxIT0stY1RWN01iZWhZaUI?oc=5","published_at":"2024-08-16T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Industrial control systems are increasingly vulnerable to cyberattacks&nbsp;&nbsp;SecurityBrief Australia","title":"Industrial control systems are increasingly vulnerable to cyberattacks - SecurityBrief Australia"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-9773d0c8b0862899","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi4AFBVV95cUxOZThEWnJ3QnBaOFF3Uk4yVk1uR3BXbGhRVjZWQkw3bGFhVDk4RE03bnFiZ1JsR1Z1SGl6TlJ3aHZ1UkpZbHdYdUxfUjhkMno4MjZSeno3dVVyMS1WdW5ycE1uU0x5TjBCbmU1R0hJR3V3VlhnOGJJSGg2UXpQaDNLcWFJRkhiRDhDajNicENWbTdZV01NUWppazAzMDB5cmt1b2xtRzY4QWxfbzFPNkc5VEpSd1c3NHdGTHN4eDRUbG9pMUk3SUZqNlItR3p1alFlZWFQcExyNEZjX0NPTzhIZQ?oc=5","published_at":"2024-08-15T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"CISA reveals security flaws in critical infrastructure equipment from AVEVA, Ocean Data, Rockwell Automation&nbsp;&nbsp;Industrial Cyber","title":"CISA reveals security flaws in critical infrastructure equipment from AVEVA, Ocean Data, Rockwell Automation - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-2c0a8375d1611c37","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi4AFBVV95cUxOZThEWnJ3QnBaOFF3Uk4yVk1uR3BXbGhRVjZWQkw3bGFhVDk4RE03bnFiZ1JsR1Z1SGl6TlJ3aHZ1UkpZbHdYdUxfUjhkMno4MjZSeno3dVVyMS1WdW5ycE1uU0x5TjBCbmU1R0hJR3V3VlhnOGJJSGg2UXpQaDNLcWFJRkhiRDhDajNicENWbTdZV01NUWppazAzMDB5cmt1b2xtRzY4QWxfbzFPNkc5VEpSd1c3NHdGTHN4eDRUbG9pMUk3SUZqNlItR3p1alFlZWFQcExyNEZjX0NPTzhIZQ?oc=5","published_at":"2024-08-15T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"CISA reveals security flaws in critical infrastructure equipment from AVEVA, Ocean Data, Rockwell Automation&nbsp;&nbsp;industrialcyber.co","title":"CISA reveals security flaws in critical infrastructure equipment from AVEVA, Ocean Data, Rockwell Automation - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9361daf0b0d614ce","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihgFBVV95cUxPQ01VZnM0cm03clRRbkI3VzluUVduZVFpcGpKX3F5ek5HS1h0QTFVb0RkLUIzYjlqSjVqVWl4Zk1LcTJlTzJzbmVpYktKT0FxUmlBQklRWlZpaUZUVkZEN2tSY1R4elpwRmQzeTh6MmQ3Wm1BN3JzZGtJbGJORkQzdkV1MlNoQQ?oc=5","published_at":"2024-08-14T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Project Profile: Reduce Forest Vulnerability to Drought, Fire, and Other Effects of Climate Change in Sierra Parks&nbsp;&nbsp;National Park Service (.gov)","title":"Project Profile: Reduce Forest Vulnerability to Drought, Fire, and Other Effects of Climate Change in Sierra Parks - National Park Service (.gov)"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-155dabfd2c08f805","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMivAFBVV95cUxPaFZoRlZRa0Z0RlQyUjZ5WGRKbGQ3YUJXc2w4eExEU2RhVDV3VTc2cjVJTl85a19jX2RlTzgzelNINE5sLXV5cXhsTTZRMDZoZV9haXo2ZWlBVXhxUDJwX1FQOFJsaVRacUJlVF91YTZkaEtWYlpBaWkzaFRYdXF6V0tBWTUtY2VjU1ZLaC0wVFhkSWVIT3J6dWtnUG50MEFkTnVXT0swWWRfenFJTUtNX0NoODZJX08zLUt0aQ?oc=5","published_at":"2024-08-12T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Critical vulnerabilities found in Ewon Cosy+ industrial VPN gateways&nbsp;&nbsp;industrialcyber.co","title":"Critical vulnerabilities found in Ewon Cosy+ industrial VPN gateways - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-c9d66abae1a26ec3","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMivAFBVV95cUxPaFZoRlZRa0Z0RlQyUjZ5WGRKbGQ3YUJXc2w4eExEU2RhVDV3VTc2cjVJTl85a19jX2RlTzgzelNINE5sLXV5cXhsTTZRMDZoZV9haXo2ZWlBVXhxUDJwX1FQOFJsaVRacUJlVF91YTZkaEtWYlpBaWkzaFRYdXF6V0tBWTUtY2VjU1ZLaC0wVFhkSWVIT3J6dWtnUG50MEFkTnVXT0swWWRfenFJTUtNX0NoODZJX08zLUt0aQ?oc=5","published_at":"2024-08-12T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Critical vulnerabilities found in Ewon Cosy+ industrial VPN gateways&nbsp;&nbsp;Industrial Cyber","title":"Critical vulnerabilities found in Ewon Cosy+ industrial VPN gateways - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-24f088b48b6e34ab","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxPWHN5RFNtQkktZjNhXzNtWF9QcEVmajI2dWxGTklRSU5GbXlIYmV5X3ZTTEFCWkFEOHQ5X3hram5SOU1fdFJZY3ZudjlqYkp0SXFpWlRCSXl2SXNRQVdnREFRQXRCeE5TNVhpZzhmUTFKaWQ1X1ZrN3hiS185TTNGclR3ZTdQVTNYNmQyTGJyZ3JhZ0lObzJTTWtTeWxYc0xCQms1TWg5cWtHdw?oc=5","published_at":"2024-08-06T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell PLC Security Bypass Threatens Manufacturing Processes&nbsp;&nbsp;darkreading.com","title":"Rockwell PLC Security Bypass Threatens Manufacturing Processes - darkreading.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-a77751bb68e8b95f","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxPWHN5RFNtQkktZjNhXzNtWF9QcEVmajI2dWxGTklRSU5GbXlIYmV5X3ZTTEFCWkFEOHQ5X3hram5SOU1fdFJZY3ZudjlqYkp0SXFpWlRCSXl2SXNRQVdnREFRQXRCeE5TNVhpZzhmUTFKaWQ1X1ZrN3hiS185TTNGclR3ZTdQVTNYNmQyTGJyZ3JhZ0lObzJTTWtTeWxYc0xCQms1TWg5cWtHdw?oc=5","published_at":"2024-08-06T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell PLC Security Bypass Threatens Manufacturing Processes&nbsp;&nbsp;Dark Reading","title":"Rockwell PLC Security Bypass Threatens Manufacturing Processes - Dark Reading"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-d016bedc648fa39b","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiogFBVV95cUxOZDNtTk1BM1h1RFhpM3dxYnRKM0wxcGlhVC1fRTZNWHhzaTZLdE1QQ0UtZUhqaWtnSTJzWExUVVdMMUcxNWszX09LY0VIa2NncEJtSVlpZm9xSW1YZnNERGJ4a285NW9lMWpueHRjSGhhOHAtNGI4RGZ0MGR6WV9xUzRXdGxiNnMtZS1GUEZDZWFBRF9HTTZhaUE5bl9GUllMUkE?oc=5","published_at":"2024-08-05T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Rockwell Automation Devices Flaw Let Hackers Gain Unauthorized Access&nbsp;&nbsp;CyberSecurityNews","title":"Rockwell Automation Devices Flaw Let Hackers Gain Unauthorized Access - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-396ed3ac3efb36db","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMigAFBVV95cUxQb00wdDUtYnFiMHFQV1NHemNVWWNsVHg1WXFXSHYzZDNzcUJMVk1YSzFmbWdRNEpxSlhRYVdFVmxjc3ZjcWVlOUd2TU15T3B4NUhqTmVfZVFkTklQTGtYd0g1N2owX05BazdfakpGbzRQV1lZXzc0NGVQbmZwNHhQbA?oc=5","published_at":"2024-08-05T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Critical Flaw in Rockwell Automation Devices Allows Unauthorized Access&nbsp;&nbsp;thehackernews.com","title":"Critical Flaw in Rockwell Automation Devices Allows Unauthorized Access - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-e5a5d83e68b0f31f","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMigAFBVV95cUxQb00wdDUtYnFiMHFQV1NHemNVWWNsVHg1WXFXSHYzZDNzcUJMVk1YSzFmbWdRNEpxSlhRYVdFVmxjc3ZjcWVlOUd2TU15T3B4NUhqTmVfZVFkTklQTGtYd0g1N2owX05BazdfakpGbzRQV1lZXzc0NGVQbmZwNHhQbA?oc=5","published_at":"2024-08-05T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Critical Flaw in Rockwell Automation Devices Allows Unauthorized Access&nbsp;&nbsp;The Hacker News","title":"Critical Flaw in Rockwell Automation Devices Allows Unauthorized Access - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-1b4281dd01f3e7cc","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiogFBVV95cUxOZDNtTk1BM1h1RFhpM3dxYnRKM0wxcGlhVC1fRTZNWHhzaTZLdE1QQ0UtZUhqaWtnSTJzWExUVVdMMUcxNWszX09LY0VIa2NncEJtSVlpZm9xSW1YZnNERGJ4a285NW9lMWpueHRjSGhhOHAtNGI4RGZ0MGR6WV9xUzRXdGxiNnMtZS1GUEZDZWFBRF9HTTZhaUE5bl9GUllMUkE?oc=5","published_at":"2024-08-05T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Rockwell Automation Devices Flaw Let Hackers Gain Unauthorized Access&nbsp;&nbsp;cybersecuritynews.com","title":"Rockwell Automation Devices Flaw Let Hackers Gain Unauthorized Access - cybersecuritynews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-a53e277ac469c288","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMivwFBVV95cUxPWFlfOTBiM016S01RLUUtYlUxaGRSUE4tSHViN2lfVHRpVkVuejhsRHRIRGJnUnJxX2hVdXVQTUl4WVVtUVJGVG1XVFpuUlpHakNHM3d2YVJZMnpsNnRGSjZVR2pGR1cyclRMVGxlT21CU09sN3J5X3dJNDV5Q0N2V0E4VzJWQ1V3eGQtdGktTG0taDZkY3ZKallhT0lTMmVxQXIzWldCSDZhQnQxc3h6cDdaaUNmM0ZpY0Mza0trZw?oc=5","published_at":"2024-08-02T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Security flaw in Rockwell ControlLogix 1756 devices exposed by Claroty\u2019s Team82&nbsp;&nbsp;industrialcyber.co","title":"Security flaw in Rockwell ControlLogix 1756 devices exposed by Claroty\u2019s Team82 - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-82fe9ef18b4b5f72","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMivwFBVV95cUxPWFlfOTBiM016S01RLUUtYlUxaGRSUE4tSHViN2lfVHRpVkVuejhsRHRIRGJnUnJxX2hVdXVQTUl4WVVtUVJGVG1XVFpuUlpHakNHM3d2YVJZMnpsNnRGSjZVR2pGR1cyclRMVGxlT21CU09sN3J5X3dJNDV5Q0N2V0E4VzJWQ1V3eGQtdGktTG0taDZkY3ZKallhT0lTMmVxQXIzWldCSDZhQnQxc3h6cDdaaUNmM0ZpY0Mza0trZw?oc=5","published_at":"2024-08-02T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Security flaw in Rockwell ControlLogix 1756 devices exposed by Claroty\u2019s Team82&nbsp;&nbsp;Industrial Cyber","title":"Security flaw in Rockwell ControlLogix 1756 devices exposed by Claroty\u2019s Team82 - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b795d76e3f565592","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxPTnRyT0xUcnA2UTRmOWYwRF9sLWxaVF9XUXIyclV0VU84WHVhVFNfUEkwT2JNZHByaDJSRU1hYUdzYnpEVkJjZHJNOVdkM2lLZWMxQ2xZeHU0ZTdqLUctMUdPSnJmOFkyTVBnTFd2T2xmYjVuNWtQZExHWUlYNExVWVgxZWZyLW92LXJ1UVAxelFBUlNrSE90d0lqN3AxVndCaGg3VFRSWHMxQQ?oc=5","published_at":"2024-07-30T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"SMEs can turn cybersecurity risk into opportunity. Here's how&nbsp;&nbsp;The World Economic Forum","title":"SMEs can turn cybersecurity risk into opportunity. Here's how - The World Economic Forum"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-eca05222fd113577","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxPTnRyT0xUcnA2UTRmOWYwRF9sLWxaVF9XUXIyclV0VU84WHVhVFNfUEkwT2JNZHByaDJSRU1hYUdzYnpEVkJjZHJNOVdkM2lLZWMxQ2xZeHU0ZTdqLUctMUdPSnJmOFkyTVBnTFd2T2xmYjVuNWtQZExHWUlYNExVWVgxZWZyLW92LXJ1UVAxelFBUlNrSE90d0lqN3AxVndCaGg3VFRSWHMxQQ?oc=5","published_at":"2024-07-30T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"SMEs can turn cybersecurity risk into opportunity. Here's how&nbsp;&nbsp;weforum.org","title":"SMEs can turn cybersecurity risk into opportunity. Here's how - weforum.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1ffd702755efe8ce","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMioAFBVV95cUxQb3pvcjRNY2FsMVZkdDFLVXhYS2ZuMkI3dUo0Q0pZQjVVbWRXaWJfS0pVTHVSMFZXLXkzMEdLUE9YSGRhY2R6OTIyQUE5Q3NXTEZRV1A0cXE0TzNhTEhFQU43aWpySG1JR1cxaWNLaVR6eGFBRENzNHN6U3prME4tRE80UWtsTUg5bzNOUDBiMUlQZ1lSYWMwWTVGOGxTVFMw0gGmAUFVX3lxTFBiYnRuUTM1bnYzXzZBdlBEbzJ5M3JTb0laTnNHQnM2Z3hqX3JEZmxBTlo3dG9iMW0wTG9PZVZKajVoNXB2WkxxTGR6a3VSX3JhcWtUVXVhOVFUaUFfbF9SeXVKQkFvVlhVZV90VU84MDZzN0o5MU05aDVvc1BPWGFjMmFxTFh3TXBodEx5b3FWRFZCeWRQank5QkQxTFRLMVBCbjk2SEE?oc=5","published_at":"2024-07-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"FrostyGoop ICS Malware Left Ukrainian City\u2019s Residents Without Heating&nbsp;&nbsp;securityweek.com","title":"FrostyGoop ICS Malware Left Ukrainian City\u2019s Residents Without Heating - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f88cb4ac195129b9","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMioAFBVV95cUxQb3pvcjRNY2FsMVZkdDFLVXhYS2ZuMkI3dUo0Q0pZQjVVbWRXaWJfS0pVTHVSMFZXLXkzMEdLUE9YSGRhY2R6OTIyQUE5Q3NXTEZRV1A0cXE0TzNhTEhFQU43aWpySG1JR1cxaWNLaVR6eGFBRENzNHN6U3prME4tRE80UWtsTUg5bzNOUDBiMUlQZ1lSYWMwWTVGOGxTVFMw0gGmAUFVX3lxTFBiYnRuUTM1bnYzXzZBdlBEbzJ5M3JTb0laTnNHQnM2Z3hqX3JEZmxBTlo3dG9iMW0wTG9PZVZKajVoNXB2WkxxTGR6a3VSX3JhcWtUVXVhOVFUaUFfbF9SeXVKQkFvVlhVZV90VU84MDZzN0o5MU05aDVvc1BPWGFjMmFxTFh3TXBodEx5b3FWRFZCeWRQank5QkQxTFRLMVBCbjk2SEE?oc=5","published_at":"2024-07-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"FrostyGoop ICS Malware Left Ukrainian City\u2019s Residents Without Heating&nbsp;&nbsp;SecurityWeek","title":"FrostyGoop ICS Malware Left Ukrainian City\u2019s Residents Without Heating - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4dbfc11dbce19f58","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxQSFphUFRjdy1mZjBjcG9CT1ZuYXF0Q0Y0SzRySXJUSnowekgzTXdEN0ZRVkoyZFBkTlIyODJLMWx6dFQ1TUwtVmN5VVJEcFVYYTc3dkF5X1JOY29ZWTJpcF9COTBaYlVJRjB6QjZFOEJjRkNMR0dLb0dzU0RUbThLSlo1UUdCajRIaFdMb1pGeEMxMVYxWGE1dmlSOGVyWGFRMzV3NDBUVnc?oc=5","published_at":"2024-07-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Novel ICS Malware Sabotaged Water-Heating Services in Ukraine&nbsp;&nbsp;darkreading.com","title":"Novel ICS Malware Sabotaged Water-Heating Services in Ukraine - darkreading.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-3c3b1f4a461cd522","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxQSFphUFRjdy1mZjBjcG9CT1ZuYXF0Q0Y0SzRySXJUSnowekgzTXdEN0ZRVkoyZFBkTlIyODJLMWx6dFQ1TUwtVmN5VVJEcFVYYTc3dkF5X1JOY29ZWTJpcF9COTBaYlVJRjB6QjZFOEJjRkNMR0dLb0dzU0RUbThLSlo1UUdCajRIaFdMb1pGeEMxMVYxWGE1dmlSOGVyWGFRMzV3NDBUVnc?oc=5","published_at":"2024-07-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Novel ICS Malware Sabotaged Water-Heating Services in Ukraine&nbsp;&nbsp;Dark Reading","title":"Novel ICS Malware Sabotaged Water-Heating Services in Ukraine - Dark Reading"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-fe19566f1d46244a","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTFBqa195T05kTXpnUjV3Z1U0eUpnSVlyZXM4SHhFdXJjMlBrZ2tCRlU4X202bGRTMmtoa3ZoUmJNRTBXREc4cTRhajhUbjN2SVRZX0hGaGc2NkdZSEFSSV9J?oc=5","published_at":"2024-07-13T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"A climate vulnerability assessment of the fish community in the Western Baltic Sea&nbsp;&nbsp;Nature","title":"A climate vulnerability assessment of the fish community in the Western Baltic Sea - Nature"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f42caf274c857291","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTFBqa195T05kTXpnUjV3Z1U0eUpnSVlyZXM4SHhFdXJjMlBrZ2tCRlU4X202bGRTMmtoa3ZoUmJNRTBXREc4cTRhajhUbjN2SVRZX0hGaGc2NkdZSEFSSV9J?oc=5","published_at":"2024-07-13T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"A climate vulnerability assessment of the fish community in the Western Baltic Sea&nbsp;&nbsp;nature.com","title":"A climate vulnerability assessment of the fish community in the Western Baltic Sea - nature.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-32eaa3a259b41a32","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMilAFBVV95cUxOeG1DOGhadUQtUW4zQ3EwTEZ2VVM5S1BfNjVDWnJSUlhoU0xaRmU2ZGNzc2JIbXZGaXlWWDdGS3ZKZWFnclZzVWJFN21qamhrN2V0T1NCak5BN3d1ZEVRdFZfZTVaZk0ydTVTX3U2ZGhuU2s3U0xRY1ZPOVk0N3lKczRROXBFeDM5RXVKRDluUHdNOUF40gGaAUFVX3lxTFB4d2E0YTlHWW01Q2JNeVRZUXNkcVVEVVBJVW5kM21LY0pJWURoQUotR3AyS1FoYVlJeVBTNDV2VFF5dF9xcWJLTExWSDYzQURKazRrZ21QUjBVWTltRjZRV3B0aTJNSWlRY1lNZE94MkVqckFBOTZrdFdwX19id1VlNzYwV3ZKZ3lGV21ZaG9IZjMxT21yXzdvaGc?oc=5","published_at":"2024-07-05T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Microsoft discloses 2 flaws in Rockwell Automation PanelView Plus&nbsp;&nbsp;Security Affairs","title":"Microsoft discloses 2 flaws in Rockwell Automation PanelView Plus - Security Affairs"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-40c2ae8e24482b32","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMilAFBVV95cUxOeG1DOGhadUQtUW4zQ3EwTEZ2VVM5S1BfNjVDWnJSUlhoU0xaRmU2ZGNzc2JIbXZGaXlWWDdGS3ZKZWFnclZzVWJFN21qamhrN2V0T1NCak5BN3d1ZEVRdFZfZTVaZk0ydTVTX3U2ZGhuU2s3U0xRY1ZPOVk0N3lKczRROXBFeDM5RXVKRDluUHdNOUF40gGaAUFVX3lxTFB4d2E0YTlHWW01Q2JNeVRZUXNkcVVEVVBJVW5kM21LY0pJWURoQUotR3AyS1FoYVlJeVBTNDV2VFF5dF9xcWJLTExWSDYzQURKazRrZ21QUjBVWTltRjZRV3B0aTJNSWlRY1lNZE94MkVqckFBOTZrdFdwX19id1VlNzYwV3ZKZ3lGV21ZaG9IZjMxT21yXzdvaGc?oc=5","published_at":"2024-07-05T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Microsoft discloses 2 flaws in Rockwell Automation PanelView Plus&nbsp;&nbsp;securityaffairs.com","title":"Microsoft discloses 2 flaws in Rockwell Automation PanelView Plus - securityaffairs.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-e95e6e5c4c855901","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMikAFBVV95cUxNZ3hxTnIxc0lwRExoMW5MR0g0NVNrR0E4NVplTkJaMm02c1FweUg5OFhIVGJrQmkza2p6SEIzTFFDUXhLdS1hQ1hhTDEyaGVyeEdIcWhpTHFpMHRkcFItUER2ZUlmclNTd0pvWk9Ga1BDVjJ5S1RjLUVONVI1cXhxVGo2Q1ZOU2xTMjdPV2ZHMTg?oc=5","published_at":"2024-07-03T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Microsoft warns of elevated risk in Rockwell Automation PanelView Plus CVEs&nbsp;&nbsp;Cybersecurity Dive","title":"Microsoft warns of elevated risk in Rockwell Automation PanelView Plus CVEs - Cybersecurity Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-25aa2c16471691a7","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMikAFBVV95cUxNZ3hxTnIxc0lwRExoMW5MR0g0NVNrR0E4NVplTkJaMm02c1FweUg5OFhIVGJrQmkza2p6SEIzTFFDUXhLdS1hQ1hhTDEyaGVyeEdIcWhpTHFpMHRkcFItUER2ZUlmclNTd0pvWk9Ga1BDVjJ5S1RjLUVONVI1cXhxVGo2Q1ZOU2xTMjdPV2ZHMTg?oc=5","published_at":"2024-07-03T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Microsoft warns of elevated risk in Rockwell Automation PanelView Plus CVEs&nbsp;&nbsp;cybersecuritydive.com","title":"Microsoft warns of elevated risk in Rockwell Automation PanelView Plus CVEs - cybersecuritydive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1b2ead18b9551cbe","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi0AFBVV95cUxPa0xQMzF2WlNDdVhma0tmazVScy11VmthR21LSC04Z29HeVhIb1ZkV3FKbGtTNy1jRmZuUVpuMHpJWWlINkZtYk53SGRSakJZZmZVdEYweWpBaVUzcjAxOHhUb3NFUFhuTE9jNE83VGphX0gtUEZrZHNpZTZNWlUydzdJVUkzVEJBc0FwUlR2UkV2YnJqMmxHeWFPeEZjVjRzZG93TEx2R3VrUy1MNktibVpYUkhlTFUzWUpOS0FnN1VtenltWkx0cVNFVjhySjlM?oc=5","published_at":"2024-07-02T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Rockwell & CIP Security","summary":"Vulnerabilities in PanelView Plus devices could lead to remote code execution&nbsp;&nbsp;Microsoft","title":"Vulnerabilities in PanelView Plus devices could lead to remote code execution - Microsoft"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-33e25e06d77e3dd1","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMioAFBVV95cUxOa0NvaG5CRjV2eWFGY3A3cHF5YTlNTmJSNmZZVEFzQ1hXVTB6bU1haG8wOFVNSFdKbU5KT3NCbGhsYjkzTkN3dElwRXV0a01kdTVSTS00c1EzdjJuVldPUnZBejlhV3VtVWxiYlRmeUxtVUs1a0lVNS1EQU1QT09NbEc3Y05UVXIzLUZPQzVSYUNlNzRuanltQ3M2czlIUngz?oc=5","published_at":"2024-07-02T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"CISO Explains Switch from Microsoft to CrowdStrike for Cybersecurity&nbsp;&nbsp;crowdstrike.com","title":"CISO Explains Switch from Microsoft to CrowdStrike for Cybersecurity - crowdstrike.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-efcaf9c376173903","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMioAFBVV95cUxOa0NvaG5CRjV2eWFGY3A3cHF5YTlNTmJSNmZZVEFzQ1hXVTB6bU1haG8wOFVNSFdKbU5KT3NCbGhsYjkzTkN3dElwRXV0a01kdTVSTS00c1EzdjJuVldPUnZBejlhV3VtVWxiYlRmeUxtVUs1a0lVNS1EQU1QT09NbEc3Y05UVXIzLUZPQzVSYUNlNzRuanltQ3M2czlIUngz?oc=5","published_at":"2024-07-02T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"INFO","source":"Industrial Switch Security","summary":"CISO Explains Switch from Microsoft to CrowdStrike for Cybersecurity&nbsp;&nbsp;CrowdStrike","title":"CISO Explains Switch from Microsoft to CrowdStrike for Cybersecurity - CrowdStrike"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-119cffbc6fd8b5d3","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi0AFBVV95cUxPa0xQMzF2WlNDdVhma0tmazVScy11VmthR21LSC04Z29HeVhIb1ZkV3FKbGtTNy1jRmZuUVpuMHpJWWlINkZtYk53SGRSakJZZmZVdEYweWpBaVUzcjAxOHhUb3NFUFhuTE9jNE83VGphX0gtUEZrZHNpZTZNWlUydzdJVUkzVEJBc0FwUlR2UkV2YnJqMmxHeWFPeEZjVjRzZG93TEx2R3VrUy1MNktibVpYUkhlTFUzWUpOS0FnN1VtenltWkx0cVNFVjhySjlM?oc=5","published_at":"2024-07-02T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Rockwell & CIP Security","summary":"Vulnerabilities in PanelView Plus devices could lead to remote code execution&nbsp;&nbsp;microsoft.com","title":"Vulnerabilities in PanelView Plus devices could lead to remote code execution - microsoft.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-53fcff0673a16425","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMivgFBVV95cUxONVhtWGw3ZnVZeXNiNVlid19LVTJacURzb1RMYnFPbjA1RzZnVHpNeXp3MGh0VzJ6RWFnNGZuRk83VGhCRTV3VDJ4REZEekJRbzlBUGdOVlFQa0pzODNUX29OQUg5bktTOGkydjVGaThQSTQwMUhhbzdCa3UzaUY0WlBtWGF6SUtaNGVNZ1BCWFJpbTNrRFZLWmRSU2ZJZGJZX3Ftc3FBaWFIVU1rSG5kU3VRNjhRbmYtLW1pc3pR?oc=5","published_at":"2024-06-28T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Critical Cybersecurity Vulnerabilities in Smart Home Devices Uncovered in New Research&nbsp;&nbsp;CE Pro","title":"Critical Cybersecurity Vulnerabilities in Smart Home Devices Uncovered in New Research - CE Pro"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-992456ea4f78af79","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMivgFBVV95cUxONVhtWGw3ZnVZeXNiNVlid19LVTJacURzb1RMYnFPbjA1RzZnVHpNeXp3MGh0VzJ6RWFnNGZuRk83VGhCRTV3VDJ4REZEekJRbzlBUGdOVlFQa0pzODNUX29OQUg5bktTOGkydjVGaThQSTQwMUhhbzdCa3UzaUY0WlBtWGF6SUtaNGVNZ1BCWFJpbTNrRFZLWmRSU2ZJZGJZX3Ftc3FBaWFIVU1rSG5kU3VRNjhRbmYtLW1pc3pR?oc=5","published_at":"2024-06-28T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Critical Cybersecurity Vulnerabilities in Smart Home Devices Uncovered in New Research&nbsp;&nbsp;cepro.com","title":"Critical Cybersecurity Vulnerabilities in Smart Home Devices Uncovered in New Research - cepro.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f0d96b9f7a7f2132","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMic0FVX3lxTE1rMGJqcGMyZ3ZtOGRxbWNVUFVSMXQwQTVoVi10OGFmX2RUYldpaUlFT3ZZZGlYWHpWdGFsenpPbjlQUzJmQ0hUcWZZLVFjYlJCODhoQlp5Ujk0dnN6RkE2V1JxSU9SZnNwNEc2dG1kVVhTTG8?oc=5","published_at":"2024-06-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"From TV news to cybersecurity: the 5 steps I took to completely change careers&nbsp;&nbsp;Fast Company","title":"From TV news to cybersecurity: the 5 steps I took to completely change careers - Fast Company"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f2cc9acb0debb886","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMic0FVX3lxTE1rMGJqcGMyZ3ZtOGRxbWNVUFVSMXQwQTVoVi10OGFmX2RUYldpaUlFT3ZZZGlYWHpWdGFsenpPbjlQUzJmQ0hUcWZZLVFjYlJCODhoQlp5Ujk0dnN6RkE2V1JxSU9SZnNwNEc2dG1kVVhTTG8?oc=5","published_at":"2024-06-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"From TV news to cybersecurity: the 5 steps I took to completely change careers&nbsp;&nbsp;fastcompany.com","title":"From TV news to cybersecurity: the 5 steps I took to completely change careers - fastcompany.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2a0439f723e889f5","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiXEFVX3lxTE94UFhZVlV1NEFQQlljak0wT1V2S2I3X3gzTmlaWVROR2hkQy13VWZoTGlrSkswSVR6d280RzN3RnRhaTNMZnF1Z24xTW9zeXN5MHJ2SGNiRVVVZTUy?oc=5","published_at":"2024-06-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"CISA Issues New Advisory for Industrial Control Systems&nbsp;&nbsp;CyberSecurityNews","title":"CISA Issues New Advisory for Industrial Control Systems - CyberSecurityNews"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ec3a0c0ee04a683a","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimAFBVV95cUxNQ0d2R3ViNWtqY2Nqd25LUWdXQmVZM19ubDNJbG92eDVUT21pVl9GbFVOR2RoTm50RVk5MHpxOUpkNGJrby1nSFhmcUVaNk5zRmYyVDFvR3N3MnVrZW1LeUZpZ1VsNE92eDF6dVk2clhEdmMxYUxfS2czUzdpZkFrNjdwNHphd0xFLXpuOFhMa3dFSjA2Q2hDLQ?oc=5","published_at":"2024-06-20T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Climate Change in the Middle East and North Africa: Mitigating Vulnerabilities and Designing Effective Policies&nbsp;&nbsp;Carnegie Endowment for International Peace","title":"Climate Change in the Middle East and North Africa: Mitigating Vulnerabilities and Designing Effective Policies - Carnegie Endowment for International Peace"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a2bf3937a6e32477","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimAFBVV95cUxNQ0d2R3ViNWtqY2Nqd25LUWdXQmVZM19ubDNJbG92eDVUT21pVl9GbFVOR2RoTm50RVk5MHpxOUpkNGJrby1nSFhmcUVaNk5zRmYyVDFvR3N3MnVrZW1LeUZpZ1VsNE92eDF6dVk2clhEdmMxYUxfS2czUzdpZkFrNjdwNHphd0xFLXpuOFhMa3dFSjA2Q2hDLQ?oc=5","published_at":"2024-06-20T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Climate Change in the Middle East and North Africa: Mitigating Vulnerabilities and Designing Effective Policies&nbsp;&nbsp;carnegieendowment.org","title":"Climate Change in the Middle East and North Africa: Mitigating Vulnerabilities and Designing Effective Policies - carnegieendowment.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-40172fe13ef02332","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMirwFBVV95cUxPVnVocHloMFVwY3gtU0k1TkpEcHBkSjFYMFpCbHNvWkVJcXVqOUhHNm9YSGw5TjJtMkx6a2JyMnltZnJPS3l6RTJqTTBtR2dPVVlmN2EzMGRyNENDbUExWGN6dms0SkZKNTRGSm9OdGcwaEpKS2pnT3A0dEl1QmhpbF9Ta1FtSjQxNjE1QjMwRHUxV3p6UVNtaHZSSEJGRm5KV21ldHdDMUFZckl4YU440gG0AUFVX3lxTFBmU0NfamVDVl93SW94dFh2emtKODVKVTU2N216a09LamNSenZ0ZjJlY0RSWDJ3ZEc4UmhKUm5lOWgtVTA0S0NBSnlnVndYYllwQUkzcFVVLTNHeHd6SWRFaWF4UHhhOVhrOFUweU4wMzJJZEl6Zm5SWVdKaGFpTWV2MlRLSHlreGlqa2NwNlVkcFdvRzV0eGJ5WExMVm5LSFo1ZERILV9JNjVMa2RBNGE2d09zQg?oc=5","published_at":"2024-06-14T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Rockwell Automation Patches High-Severity Vulnerabilities in FactoryTalk View SE&nbsp;&nbsp;securityweek.com","title":"Rockwell Automation Patches High-Severity Vulnerabilities in FactoryTalk View SE - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-5896111876b7793f","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMirwFBVV95cUxPVnVocHloMFVwY3gtU0k1TkpEcHBkSjFYMFpCbHNvWkVJcXVqOUhHNm9YSGw5TjJtMkx6a2JyMnltZnJPS3l6RTJqTTBtR2dPVVlmN2EzMGRyNENDbUExWGN6dms0SkZKNTRGSm9OdGcwaEpKS2pnT3A0dEl1QmhpbF9Ta1FtSjQxNjE1QjMwRHUxV3p6UVNtaHZSSEJGRm5KV21ldHdDMUFZckl4YU440gG0AUFVX3lxTFBmU0NfamVDVl93SW94dFh2emtKODVKVTU2N216a09LamNSenZ0ZjJlY0RSWDJ3ZEc4UmhKUm5lOWgtVTA0S0NBSnlnVndYYllwQUkzcFVVLTNHeHd6SWRFaWF4UHhhOVhrOFUweU4wMzJJZEl6Zm5SWVdKaGFpTWV2MlRLSHlreGlqa2NwNlVkcFdvRzV0eGJ5WExMVm5LSFo1ZERILV9JNjVMa2RBNGE2d09zQg?oc=5","published_at":"2024-06-14T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Rockwell Automation Patches High-Severity Vulnerabilities in FactoryTalk View SE&nbsp;&nbsp;SecurityWeek","title":"Rockwell Automation Patches High-Severity Vulnerabilities in FactoryTalk View SE - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-f40e06e3ef56108b","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi6wFBVV95cUxOY1dpY19BeXpZTlJuTDE5RXAwY2cwaVdwb1JVb21OVllpemtoM3JUMG5POVlJSW5QZDRXemxMbUF4QW9Ua29MeWpFVUQ0WFNhVUdyZDZTclFnSlUxX2VZYm10NENBOXhmTWR3RDlfOThPV1BYdmtJWG5WZTV3eWd4Q09mRGc2dXNtSm1NUHdRYWU1S3pnS3VYQjlBeG41b1EwcDBxbnB0YXptVDRJUE5uUWJNekEwNnZpdzZaaTlHTm9ZdUN1NnRWS1NVdUpfVE9RNU04aGJzcDBCR0o2MC05U0dXWGNUZ1FkdW9v?oc=5","published_at":"2024-06-13T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Rockwell warns ICS sector of FactoryTalk View SE v11 vulnerability, recommends upgrade to patched v14.0&nbsp;&nbsp;Industrial Cyber","title":"Rockwell warns ICS sector of FactoryTalk View SE v11 vulnerability, recommends upgrade to patched v14.0 - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-73329b2c94e05f69","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi6wFBVV95cUxOY1dpY19BeXpZTlJuTDE5RXAwY2cwaVdwb1JVb21OVllpemtoM3JUMG5POVlJSW5QZDRXemxMbUF4QW9Ua29MeWpFVUQ0WFNhVUdyZDZTclFnSlUxX2VZYm10NENBOXhmTWR3RDlfOThPV1BYdmtJWG5WZTV3eWd4Q09mRGc2dXNtSm1NUHdRYWU1S3pnS3VYQjlBeG41b1EwcDBxbnB0YXptVDRJUE5uUWJNekEwNnZpdzZaaTlHTm9ZdUN1NnRWS1NVdUpfVE9RNU04aGJzcDBCR0o2MC05U0dXWGNUZ1FkdW9v?oc=5","published_at":"2024-06-13T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Rockwell warns ICS sector of FactoryTalk View SE v11 vulnerability, recommends upgrade to patched v14.0&nbsp;&nbsp;industrialcyber.co","title":"Rockwell warns ICS sector of FactoryTalk View SE v11 vulnerability, recommends upgrade to patched v14.0 - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-234d2bae0d4a1b21","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimwFBVV95cUxQWHpsbHNUbmxhQnZTaVNtQ0Q2aEpCOTE5TDlpUUE3MkRIODAtS0NJdGlMdkEwMU5BQmhUTjNBSTR3VTY3dWpRa09WWnVGdnc5bDJaVExENnVNdk51aFN4c1ZaaDJXRk9BUm5uRGFWbmNkanpQWWVEQ01iNWQ4dHRfZWdpc05KZ3RqejFFVGo1RUVma1h5bHFjWEF3OA?oc=5","published_at":"2024-06-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Climate Vulnerability in Libya: Building Resilience Through Local Empowerment&nbsp;&nbsp;carnegieendowment.org","title":"Climate Vulnerability in Libya: Building Resilience Through Local Empowerment - carnegieendowment.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-0c32968f4dffb698","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimwFBVV95cUxQWHpsbHNUbmxhQnZTaVNtQ0Q2aEpCOTE5TDlpUUE3MkRIODAtS0NJdGlMdkEwMU5BQmhUTjNBSTR3VTY3dWpRa09WWnVGdnc5bDJaVExENnVNdk51aFN4c1ZaaDJXRk9BUm5uRGFWbmNkanpQWWVEQ01iNWQ4dHRfZWdpc05KZ3RqejFFVGo1RUVma1h5bHFjWEF3OA?oc=5","published_at":"2024-06-06T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Climate Vulnerability in Libya: Building Resilience Through Local Empowerment&nbsp;&nbsp;Carnegie Endowment for International Peace","title":"Climate Vulnerability in Libya: Building Resilience Through Local Empowerment - Carnegie Endowment for International Peace"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-72c97b76ce0d81a2","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMi1gFBVV95cUxOOUFPM2pDOUtFNEl4MzNjcGdrNkw2WkpxRzB1WlB6RE1jNU9ra3o5Y29lcE9DNng3ZTRvTkNhNG5hNW8xeXpXcXZDNGh3VDZJYWRjdnBRQXJNOEMyT01HUXJCOUxtQlloWXVzUXRfOHVuYzJTUDE0QW05NnZickhEUmoyYWdWVE9MZGlOaE9taXJleG9MR2dIcFJBZWs2d3dKclF1cWxFNkRtT2RBS056RFNWMmpfc1JzYXZjdWltOENGdUpSNWJyNDhxVkpMZTJScGF2bFdn?oc=5","published_at":"2024-05-23T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Sligo company SL Controls achieves Premier Integrator status for Ignition platform&nbsp;&nbsp;independent.ie","title":"Sligo company SL Controls achieves Premier Integrator status for Ignition platform - independent.ie"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1c01111a1f90f700","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilwFBVV95cUxNNXlLVEN6MmNuQ3BVVXMtTi0wMVZxb3duQ3BDUFRQXzJfT2JsVzNPVE1XYUNPVzJRbTVfWUhQUkNlQVBwTUhSSDJhWlUyTFB4enlMY2VBZ1hmUmladlBaekhZV2VaWldXTnFZRWQwTzUzdGd4VG5uamRiSXluTU5mNXktRDNlOVhPb1FHbXdRUUl3TGwzOFUw?oc=5","published_at":"2024-05-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Assessing Climate Vulnerabilities in Amman City&nbsp;&nbsp;carnegieendowment.org","title":"Assessing Climate Vulnerabilities in Amman City - carnegieendowment.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-0000df46627ef038","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilwFBVV95cUxNNXlLVEN6MmNuQ3BVVXMtTi0wMVZxb3duQ3BDUFRQXzJfT2JsVzNPVE1XYUNPVzJRbTVfWUhQUkNlQVBwTUhSSDJhWlUyTFB4enlMY2VBZ1hmUmladlBaekhZV2VaWldXTnFZRWQwTzUzdGd4VG5uamRiSXluTU5mNXktRDNlOVhPb1FHbXdRUUl3TGwzOFUw?oc=5","published_at":"2024-05-23T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Assessing Climate Vulnerabilities in Amman City&nbsp;&nbsp;Carnegie Endowment for International Peace","title":"Assessing Climate Vulnerabilities in Amman City - Carnegie Endowment for International Peace"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-63438eeb49a7112b","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMi1gFBVV95cUxOOUFPM2pDOUtFNEl4MzNjcGdrNkw2WkpxRzB1WlB6RE1jNU9ra3o5Y29lcE9DNng3ZTRvTkNhNG5hNW8xeXpXcXZDNGh3VDZJYWRjdnBRQXJNOEMyT01HUXJCOUxtQlloWXVzUXRfOHVuYzJTUDE0QW05NnZickhEUmoyYWdWVE9MZGlOaE9taXJleG9MR2dIcFJBZWs2d3dKclF1cWxFNkRtT2RBS056RFNWMmpfc1JzYXZjdWltOENGdUpSNWJyNDhxVkpMZTJScGF2bFdn?oc=5","published_at":"2024-05-23T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Sligo company SL Controls achieves Premier Integrator status for Ignition platform&nbsp;&nbsp;Irish Independent","title":"Sligo company SL Controls achieves Premier Integrator status for Ignition platform - Irish Independent"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-5abeb1dab231e2ed","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMingFBVV95cUxOX3U2WHJmaTNNX2lwa1V0UFVYeThsQWdWQ00wNnJQelhHZTNQM0tJU3dZbW93VE1UQkkyNTd1MXNGUWVjdUQyUl82ejZtbTFOWXQtbElFcm1EZXM3UVdxTHhOX1pudXNuVHB3VnJyWFh2LWgxZFhWOVhfZVhoQnJ3MXNHZWVTTG5sU2hPV204cmZuRDlub3o0djQweGFRQdIBowFBVV95cUxOXzN0cUs0c0o1X0c0cTBHZERSeDc3QmFvbnpnb0RTWVlYRFdmSzZBR2JNbzJCSGpKTFJ2STAzZ0E0dk5ndWRQclB3Uk5nNGpnYTBvQkZDV3VvNmVIWWV4ZUFxdzI2Vm4yMWluOHlvY0tNQWtXYVVTR1hXQm1rd0pKMzhBRTk3Qjd3alE0RmdocndEcVVlT0VxVW1IeHB0ZXA5MEhZ?oc=5","published_at":"2024-05-22T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell Automation Urges Customers to Disconnect ICS From Internet&nbsp;&nbsp;securityweek.com","title":"Rockwell Automation Urges Customers to Disconnect ICS From Internet - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-d332758330bed3e3","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMingFBVV95cUxOX3U2WHJmaTNNX2lwa1V0UFVYeThsQWdWQ00wNnJQelhHZTNQM0tJU3dZbW93VE1UQkkyNTd1MXNGUWVjdUQyUl82ejZtbTFOWXQtbElFcm1EZXM3UVdxTHhOX1pudXNuVHB3VnJyWFh2LWgxZFhWOVhfZVhoQnJ3MXNHZWVTTG5sU2hPV204cmZuRDlub3o0djQweGFRQdIBowFBVV95cUxOXzN0cUs0c0o1X0c0cTBHZERSeDc3QmFvbnpnb0RTWVlYRFdmSzZBR2JNbzJCSGpKTFJ2STAzZ0E0dk5ndWRQclB3Uk5nNGpnYTBvQkZDV3VvNmVIWWV4ZUFxdzI2Vm4yMWluOHlvY0tNQWtXYVVTR1hXQm1rd0pKMzhBRTk3Qjd3alE0RmdocndEcVVlT0VxVW1IeHB0ZXA5MEhZ?oc=5","published_at":"2024-05-22T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell Automation Urges Customers to Disconnect ICS From Internet&nbsp;&nbsp;SecurityWeek","title":"Rockwell Automation Urges Customers to Disconnect ICS From Internet - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-9d3cc6b7cfb3004f","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxNZEdDVnFXN0ZzR3JfQ24tZlpwbHZobUNiZ21DZHlHTGdqVUpQV1kwcnFXZ2ZTajAyV0QzSF8wV0FWeDd3N3VEUUVoemlTN0hXWUFUZ3JsN0N5cUJkRzhJN2oxc1RPWmZKdW1IRUw5cURwZU1PelJGMDEtTlpqVUlMeHdmbGg?oc=5","published_at":"2024-05-22T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell Advises Disconnecting Internet-Facing ICS Devices Amid Cyber Threats&nbsp;&nbsp;The Hacker News","title":"Rockwell Advises Disconnecting Internet-Facing ICS Devices Amid Cyber Threats - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-510a4aeb404bae60","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMihAFBVV95cUxNZEdDVnFXN0ZzR3JfQ24tZlpwbHZobUNiZ21DZHlHTGdqVUpQV1kwcnFXZ2ZTajAyV0QzSF8wV0FWeDd3N3VEUUVoemlTN0hXWUFUZ3JsN0N5cUJkRzhJN2oxc1RPWmZKdW1IRUw5cURwZU1PelJGMDEtTlpqVUlMeHdmbGg?oc=5","published_at":"2024-05-22T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell Advises Disconnecting Internet-Facing ICS Devices Amid Cyber Threats&nbsp;&nbsp;thehackernews.com","title":"Rockwell Advises Disconnecting Internet-Facing ICS Devices Amid Cyber Threats - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c6fe3f576a1e034c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilgFBVV95cUxOTVFBeTZONkFQczVFRVh3SFh2dkxMLTBTWll5YlhaSE9VSFZwcXpxd2p4TWc4NkpQaEdLakpuVTJtdEcwSEt4eGlVbjlYS3BtSmVKRzFJWm5qMG9jdGpFTTV1T1RQeWhXSFkwRDBMOWxpTmpSek5GT0laY0haM3lfdGc5ZVZrUHNfTUx5Z0Vhd0RpSjNMVHc?oc=5","published_at":"2024-05-16T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Vulnerability and Governance in the Context of Climate Change in Jordan&nbsp;&nbsp;Carnegie Endowment for International Peace","title":"Vulnerability and Governance in the Context of Climate Change in Jordan - Carnegie Endowment for International Peace"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-379765fcb72d08a2","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilgFBVV95cUxOTVFBeTZONkFQczVFRVh3SFh2dkxMLTBTWll5YlhaSE9VSFZwcXpxd2p4TWc4NkpQaEdLakpuVTJtdEcwSEt4eGlVbjlYS3BtSmVKRzFJWm5qMG9jdGpFTTV1T1RQeWhXSFkwRDBMOWxpTmpSek5GT0laY0haM3lfdGc5ZVZrUHNfTUx5Z0Vhd0RpSjNMVHc?oc=5","published_at":"2024-05-16T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Vulnerability and Governance in the Context of Climate Change in Jordan&nbsp;&nbsp;carnegieendowment.org","title":"Vulnerability and Governance in the Context of Climate Change in Jordan - carnegieendowment.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-dcbfe935853384a4","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi3gFBVV95cUxOMDdCN3U4enBEVld3ZzZrNmZUbTNidkhKb2dmS1VnNkxDbDJBa21QUy1ub21oTjJubi1YSTBFTS1fMG1UenZxd0xIMUwzUEFReVpoTkxBRml2bUUyY1Itc18xMHltQU1BeDRwWExTQ3JGT3FSYWw4cXRrTmI4a3RKYmg0amQtN0hIY3ptNmUyeXllRjBpd3YyZjl6a1RWemdEako2OS0xQ1YwREw1X3VSdWNKVXZ3Yk5MSTZFRVlWVnlONF9CMF9oQTU5dDlFcmlmNkRZZEIzSzdoeU1vcFE?oc=5","published_at":"2024-05-15T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA issues ICS advisories on hardware vulnerabilities from Rockwell, SUBNET, Johnson Controls, Mitsubishi Electric&nbsp;&nbsp;Industrial Cyber","title":"CISA issues ICS advisories on hardware vulnerabilities from Rockwell, SUBNET, Johnson Controls, Mitsubishi Electric - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-138bc2b8c476e90c","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi3gFBVV95cUxOMDdCN3U4enBEVld3ZzZrNmZUbTNidkhKb2dmS1VnNkxDbDJBa21QUy1ub21oTjJubi1YSTBFTS1fMG1UenZxd0xIMUwzUEFReVpoTkxBRml2bUUyY1Itc18xMHltQU1BeDRwWExTQ3JGT3FSYWw4cXRrTmI4a3RKYmg0amQtN0hIY3ptNmUyeXllRjBpd3YyZjl6a1RWemdEako2OS0xQ1YwREw1X3VSdWNKVXZ3Yk5MSTZFRVlWVnlONF9CMF9oQTU5dDlFcmlmNkRZZEIzSzdoeU1vcFE?oc=5","published_at":"2024-05-15T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA issues ICS advisories on hardware vulnerabilities from Rockwell, SUBNET, Johnson Controls, Mitsubishi Electric&nbsp;&nbsp;industrialcyber.co","title":"CISA issues ICS advisories on hardware vulnerabilities from Rockwell, SUBNET, Johnson Controls, Mitsubishi Electric - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-22bd79b34f8b201c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimwFBVV95cUxOdkpwMk90bzA2RXFBYjlnQlluTlMwNjI0N0w5eWJuSVpLTHlTbTRXTFExMHZETDRYVDhsenpjLVFxdzZrMHpRTG1kMTE2M29ETml2Z0VZSVpJZGtnUndDRGRoOUhWMHozR2RTLUpjanBWNG1FanVRcFNVQkEwVktDZV9yLVVpZ0d2UTNBZzFnYWlWbEdBNzdjMkl0Yw?oc=5","published_at":"2024-05-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Can Interventions Turn Teens from Cyber Crime to Cybersecurity?&nbsp;&nbsp;govtech.com","title":"Can Interventions Turn Teens from Cyber Crime to Cybersecurity? - govtech.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-2bde6bc53348d9f1","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi2gFBVV95cUxQcHNvaG9seEo5VF9iZEpEU1gtVlAzVHNZdTBnWXJIRHd5UTMxWUVYS1JQdi1zZVR0a2hxQTI0aGdRWDNfLWpqUHVnTkpVTWZzOEl3V01mMUJlQkVSU2tJMFN4aWdyYnRTU2JhYnhnR1hpOFJSODRLQ080M0lxdEEwQ2VnbHgwVk5MMy1Na3ZTUjlkZHNURWRHa24yWW1fbV8tWnhzc3BieTIyTVBETGxkYjJJWF91Sl9NbWZQMTY3RnpuSEhBeU44RXE4WDFFQlZRVk82em45RlRzQQ?oc=5","published_at":"2024-05-10T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"US CISA issues ICS advisories on hardware vulnerabilities in Rockwell Automation, alpitronic, Delta Electronics&nbsp;&nbsp;Industrial Cyber","title":"US CISA issues ICS advisories on hardware vulnerabilities in Rockwell Automation, alpitronic, Delta Electronics - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-70134e24b1cafec2","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi2gFBVV95cUxQcHNvaG9seEo5VF9iZEpEU1gtVlAzVHNZdTBnWXJIRHd5UTMxWUVYS1JQdi1zZVR0a2hxQTI0aGdRWDNfLWpqUHVnTkpVTWZzOEl3V01mMUJlQkVSU2tJMFN4aWdyYnRTU2JhYnhnR1hpOFJSODRLQ080M0lxdEEwQ2VnbHgwVk5MMy1Na3ZTUjlkZHNURWRHa24yWW1fbV8tWnhzc3BieTIyTVBETGxkYjJJWF91Sl9NbWZQMTY3RnpuSEhBeU44RXE4WDFFQlZRVk82em45RlRzQQ?oc=5","published_at":"2024-05-10T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"US CISA issues ICS advisories on hardware vulnerabilities in Rockwell Automation, alpitronic, Delta Electronics&nbsp;&nbsp;industrialcyber.co","title":"US CISA issues ICS advisories on hardware vulnerabilities in Rockwell Automation, alpitronic, Delta Electronics - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a6e0035c5b2c428b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimwFBVV95cUxOdkpwMk90bzA2RXFBYjlnQlluTlMwNjI0N0w5eWJuSVpLTHlTbTRXTFExMHZETDRYVDhsenpjLVFxdzZrMHpRTG1kMTE2M29ETml2Z0VZSVpJZGtnUndDRGRoOUhWMHozR2RTLUpjanBWNG1FanVRcFNVQkEwVktDZV9yLVVpZ0d2UTNBZzFnYWlWbEdBNzdjMkl0Yw?oc=5","published_at":"2024-05-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Can Interventions Turn Teens from Cyber Crime to Cybersecurity?&nbsp;&nbsp;GovTech","title":"Can Interventions Turn Teens from Cyber Crime to Cybersecurity? - GovTech"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-0e96a7d43a26ba4d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxOOS1Gd0xjWmQ5WGFzX2kwRjMzeXI0bDVaXzJ4cGFiSUN5bXc0R2JoZXZnQ25fd0plV1hLMHdYRG1XV1BvSUpZVGRrN0xMYlhua3VTNWs1SC1kRzJsa0Vkdm4wUzYzbnRkZzBmZmI3bDZ2d2lWYm93TXNXUmRsYm9YakFyVmVIWXpwOFVVWlJGM0g2dUxsNWRHaVlkaTNoVmhuQlNkcFk4YVRWTjBndlE?oc=5","published_at":"2024-05-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"New Siemens software automatically identifies vulnerable production assets&nbsp;&nbsp;Design World","title":"New Siemens software automatically identifies vulnerable production assets - Design World"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1fa72efcc6727f62","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxOOS1Gd0xjWmQ5WGFzX2kwRjMzeXI0bDVaXzJ4cGFiSUN5bXc0R2JoZXZnQ25fd0plV1hLMHdYRG1XV1BvSUpZVGRrN0xMYlhua3VTNWs1SC1kRzJsa0Vkdm4wUzYzbnRkZzBmZmI3bDZ2d2lWYm93TXNXUmRsYm9YakFyVmVIWXpwOFVVWlJGM0g2dUxsNWRHaVlkaTNoVmhuQlNkcFk4YVRWTjBndlE?oc=5","published_at":"2024-05-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"New Siemens software automatically identifies vulnerable production assets&nbsp;&nbsp;designworldonline.com","title":"New Siemens software automatically identifies vulnerable production assets - designworldonline.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c5fea1e09e0b3eca","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijAFBVV95cUxQMVNyUk9EMHQ3Y1hpTC05T0NqRmlBQ2otT21GM1JOSHJOZVFobm5leGU4aVI1ZjdMQllPMGZzOUFMVzdxZGtsWnVWU08xeF9KTHZkeW5IR1haUVR5WEVSUFpkYTBBLTBWc3ppSDhiTkt1eDIyaTM4eWdEUjRuenRPQVpwT1RscXJUbFhUeg?oc=5","published_at":"2024-04-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Life in Cybersecurity: From Nursing to Threat Analyst&nbsp;&nbsp;Tripwire","title":"Life in Cybersecurity: From Nursing to Threat Analyst - Tripwire"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-29caf6c15e361da7","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxPNTBlTlJ4eGNMNGNpZElyQU9sVUlhd29pb1lTTEtJWlZ5TGpyal9RVVk0Y3BTOUpWNDA0SnhQVllYQzkwc1pBTlVLQkI4X2l0WUhUdEcwSm1PY0JpOG53WHEtZnBnMlRiOEZCbVlDWHk0a0JqaW1aaGg4NFZIbmp3aFNkRzdhUXYzX2IwRXlWOUxkNUx5SFZZTTZRMldrNVVOYnNnWmdjbHYxMTQ?oc=5","published_at":"2024-04-04T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Change cyberattack serves as wake-up call for healthcare cybersecurity&nbsp;&nbsp;Healthcare Dive","title":"Change cyberattack serves as wake-up call for healthcare cybersecurity - Healthcare Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e8c4d6e473b65433","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxPNTBlTlJ4eGNMNGNpZElyQU9sVUlhd29pb1lTTEtJWlZ5TGpyal9RVVk0Y3BTOUpWNDA0SnhQVllYQzkwc1pBTlVLQkI4X2l0WUhUdEcwSm1PY0JpOG53WHEtZnBnMlRiOEZCbVlDWHk0a0JqaW1aaGg4NFZIbmp3aFNkRzdhUXYzX2IwRXlWOUxkNUx5SFZZTTZRMldrNVVOYnNnWmdjbHYxMTQ?oc=5","published_at":"2024-04-04T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Industrial Switch Security","summary":"Change cyberattack serves as wake-up call for healthcare cybersecurity&nbsp;&nbsp;healthcaredive.com","title":"Change cyberattack serves as wake-up call for healthcare cybersecurity - healthcaredive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-ceda0dcfa3d91ec2","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxQUDZIUW83SHpuVjdmbEtmcHpDLW1iTnV3SU1TOGxmaEI4Wk5lbXdPNVQ1TFhmdEdOWmJYVXdNdEF1bTQ4THhNRTlUYjNYbzd5aEZHYXFYd1MyYnhjTmlRN21pLXhCTW9yUmtBaXpIeVdZTGVQZURqQjhZNUVGeFVZZmZueVYtSVZHYUcwWTBDY0hlMFVSR3QzRTZRb2ZDd2RiNWJ1UkR4dWdsQdIBrwFBVV95cUxOVVNlS2dOSjhoNms5YmktbGh5dTBqbTZvYk1KWTdjN3dFejdtMnN6TklzQjY4c3JRSklrV2Y4T2JLM0g2Nm1rbm9RQl95Y01qR0N3U2ozaGdHdzFlcnl1V3o4RE5OUldLdVNZZDRqcFpyMEFWRDZTMGlGZkoybXBfUVp1OThDeF90dXJub2FDclJOcG92N01ISVRaUGRHNFVlNlBkU2hUcnA4RnJkZy1z?oc=5","published_at":"2024-03-27T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Organizations Informed of 10 Vulnerabilities in Rockwell Automation Products&nbsp;&nbsp;SecurityWeek","title":"Organizations Informed of 10 Vulnerabilities in Rockwell Automation Products - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-e25673befb89310f","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxQUDZIUW83SHpuVjdmbEtmcHpDLW1iTnV3SU1TOGxmaEI4Wk5lbXdPNVQ1TFhmdEdOWmJYVXdNdEF1bTQ4THhNRTlUYjNYbzd5aEZHYXFYd1MyYnhjTmlRN21pLXhCTW9yUmtBaXpIeVdZTGVQZURqQjhZNUVGeFVZZmZueVYtSVZHYUcwWTBDY0hlMFVSR3QzRTZRb2ZDd2RiNWJ1UkR4dWdsQdIBrwFBVV95cUxOVVNlS2dOSjhoNms5YmktbGh5dTBqbTZvYk1KWTdjN3dFejdtMnN6TklzQjY4c3JRSklrV2Y4T2JLM0g2Nm1rbm9RQl95Y01qR0N3U2ozaGdHdzFlcnl1V3o4RE5OUldLdVNZZDRqcFpyMEFWRDZTMGlGZkoybXBfUVp1OThDeF90dXJub2FDclJOcG92N01ISVRaUGRHNFVlNlBkU2hUcnA4RnJkZy1z?oc=5","published_at":"2024-03-27T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Organizations Informed of 10 Vulnerabilities in Rockwell Automation Products&nbsp;&nbsp;securityweek.com","title":"Organizations Informed of 10 Vulnerabilities in Rockwell Automation Products - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-50db110f2d281774","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxNVTl3b2Y5RzN0SklYOExEOTVRMG9XNHoyRE9OYnd4TW04WDZ3UGJBNDJ1dnNvN21kMUx0QVJQUWY2SG5fVUxYeHBvNjBzOWhFZnQ0M2ZYUy1TMEdzT0Y0ODRKQktqeGtEMVFfRmVTRVIxZlJYVlgzWjQ1NWRtcGx0UUwtQ1gzY2R1dC1tV3g4SXl0M2doVzZJcG56eVdneUVjZTlhWnNyXzdKMnfSAbABQVVfeXFMTzJpNzR0b2RZRTdtOE5MSlEtQUJkb3BMMjBCVDl1LVg5Vmd4UnJYRGd0VnNSNE5xQW1DX2sybDhTU25CdjIwaXUzbGJiWDR5TGo3d1NBTDRic1N2YjFrelJrYVVCOWtDeU1ieC04bV9iNHhwMXVlX2FrODUtR1pxeW14a1JWUVBvdWFWejdmWXhMQzJKa0JuQVdkMW5KZlZKdUh3N3pldldYcWZfeWxhWHg?oc=5","published_at":"2024-03-12T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"Exploited Building Access System Vulnerability Patched 5 Years After Disclosure&nbsp;&nbsp;securityweek.com","title":"Exploited Building Access System Vulnerability Patched 5 Years After Disclosure - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f42c3957fac9d717","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxNVTl3b2Y5RzN0SklYOExEOTVRMG9XNHoyRE9OYnd4TW04WDZ3UGJBNDJ1dnNvN21kMUx0QVJQUWY2SG5fVUxYeHBvNjBzOWhFZnQ0M2ZYUy1TMEdzT0Y0ODRKQktqeGtEMVFfRmVTRVIxZlJYVlgzWjQ1NWRtcGx0UUwtQ1gzY2R1dC1tV3g4SXl0M2doVzZJcG56eVdneUVjZTlhWnNyXzdKMnfSAbABQVVfeXFMTzJpNzR0b2RZRTdtOE5MSlEtQUJkb3BMMjBCVDl1LVg5Vmd4UnJYRGd0VnNSNE5xQW1DX2sybDhTU25CdjIwaXUzbGJiWDR5TGo3d1NBTDRic1N2YjFrelJrYVVCOWtDeU1ieC04bV9iNHhwMXVlX2FrODUtR1pxeW14a1JWUVBvdWFWejdmWXhMQzJKa0JuQVdkMW5KZlZKdUh3N3pldldYcWZfeWxhWHg?oc=5","published_at":"2024-03-12T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"Exploited Building Access System Vulnerability Patched 5 Years After Disclosure&nbsp;&nbsp;SecurityWeek","title":"Exploited Building Access System Vulnerability Patched 5 Years After Disclosure - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-e903e4c46f278ff1","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMic0FVX3lxTE5acGpYSjZCZ3VsVmhOUzZZVFl3X2dSS3VmYVF1T05aRklpWGF6V18xSG1GZVZUSGlyWXM2RkdjODlERnFYeVB1QkhZVzN6S2lUaWVWbXVtNGkxNEd5OTN5bjc2ZS1qaDlneUFHakU5OW0tYTg?oc=5","published_at":"2024-03-07T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"Web-based PLC malware: A new potential threat to critical infrastructure&nbsp;&nbsp;Help Net Security","title":"Web-based PLC malware: A new potential threat to critical infrastructure - Help Net Security"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-c19dd507b7dd4786","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMic0FVX3lxTE5acGpYSjZCZ3VsVmhOUzZZVFl3X2dSS3VmYVF1T05aRklpWGF6V18xSG1GZVZUSGlyWXM2RkdjODlERnFYeVB1QkhZVzN6S2lUaWVWbXVtNGkxNEd5OTN5bjc2ZS1qaDlneUFHakU5OW0tYTg?oc=5","published_at":"2024-03-07T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"Web-based PLC malware: A new potential threat to critical infrastructure&nbsp;&nbsp;helpnetsecurity.com","title":"Web-based PLC malware: A new potential threat to critical infrastructure - helpnetsecurity.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-512f059d4c0de877","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiswFBVV95cUxQeWhpX1ZCV2pCZDdBZTBrNmNTaDJ4UGEyaWFmUERBVmZwYmt4RkM2SWRLWkktWFBSZGZtNjlKamtyTms1NlJVcFhmM1VOaFRUUnp4djl4NkxSQ2xSX3hScHpkZ0RNRVA1eGJIOUtEVGhIN09MTW5ySUQ4dTQ0VzVPLVlCY2dVNnYtTjZ3bFdXRmVEN1ZYaXpZQmNLZ2ZMaEkwN3ZRVXJEVmtYcDVtdzJmbFFBWQ?oc=5","published_at":"2024-02-29T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Use AWS services to build secure, resilient, and global OT and IT networks&nbsp;&nbsp;Amazon Web Services (AWS)","title":"Use AWS services to build secure, resilient, and global OT and IT networks - Amazon Web Services (AWS)"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-fecac710385584d6","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTFA1TExERk9QNUNoMm1rTGI5Q0s2eWZzWWVVV1VpRERFMmFOQTFQV3lSaEdseDdGdFFwQjNkWEJXQU9OU0YtelBublJfU2xtaHowTk4wTHFRUmYyTTNqbGZZ?oc=5","published_at":"2024-02-27T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Flexible foraging behaviour increases predator vulnerability to climate change&nbsp;&nbsp;nature.com","title":"Flexible foraging behaviour increases predator vulnerability to climate change - nature.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-bdfd168b8f3b8b32","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTFA1TExERk9QNUNoMm1rTGI5Q0s2eWZzWWVVV1VpRERFMmFOQTFQV3lSaEdseDdGdFFwQjNkWEJXQU9OU0YtelBublJfU2xtaHowTk4wTHFRUmYyTTNqbGZZ?oc=5","published_at":"2024-02-27T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Flexible foraging behaviour increases predator vulnerability to climate change&nbsp;&nbsp;Nature","title":"Flexible foraging behaviour increases predator vulnerability to climate change - Nature"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-aefb05a33fcfbacc","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipwFBVV95cUxOX21zQm1lOUNycDIybDFxbFpoXzgzbUM4N3NfT2ZZX0JfdTBFdXM2SllTZlBhYlllbFdUN3dRVHk2Y2tzY3R5VkxMVTVBLXdRWTZ4LTZOdWtSRU9lTDBTVmUtd3R4TmFkZmhGbWY0RTRMVE9zZjVMdXh6aU5OaHRFSlVqX1dOaEhqQnQ2VmZuMTJ4N1hESmk5Wl9TMFl0am9DOTdlUGtOQQ?oc=5","published_at":"2024-02-12T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Ignition SCADA Security","summary":"Software donation benefits Penn College automation students [2024-02-12]&nbsp;&nbsp;pct.edu","title":"Software donation benefits Penn College automation students [2024-02-12] - pct.edu"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-839bf8b850d3e6a8","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipwFBVV95cUxOX21zQm1lOUNycDIybDFxbFpoXzgzbUM4N3NfT2ZZX0JfdTBFdXM2SllTZlBhYlllbFdUN3dRVHk2Y2tzY3R5VkxMVTVBLXdRWTZ4LTZOdWtSRU9lTDBTVmUtd3R4TmFkZmhGbWY0RTRMVE9zZjVMdXh6aU5OaHRFSlVqX1dOaEhqQnQ2VmZuMTJ4N1hESmk5Wl9TMFl0am9DOTdlUGtOQQ?oc=5","published_at":"2024-02-12T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Ignition SCADA Security","summary":"Software donation benefits Penn College automation students [2024-02-12]&nbsp;&nbsp;Pennsylvania College of Technology","title":"Software donation benefits Penn College automation students [2024-02-12] - Pennsylvania College of Technology"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-ab018257d85b72d4","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMidkFVX3lxTE9zTlVWbF8yOTJWay16QV9qY1N0d2FhMVVia3BfRmdNNENHX2s1b1U1VGJmal9PNTU3OC1HQThrMGNBQWMxN0h1MnF0T3NuaXlRQlBONWl5QzktOHpkeVpjVnBMVVUzV19kYm5tc24yeVFkN3Jxdmc?oc=5","published_at":"2024-02-07T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure&nbsp;&nbsp;CISA (.gov)","title":"PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure - CISA (.gov)"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-31341b2a25635f46","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMixgFBVV95cUxPNlhkMFlocTVSQ2dvYng0dHFOUElpeEVjRmwyMHRPZ1l5UE9fdnNxSWpiNlBhVzZ1U21pZlA4S0RCWFhvNVZUalpBTjh6TFJxXzB3aXd5MEdXZlhCdzBZMnNUMWFxbEpjcFpMalBNT2IxX0V4U19TMHUxdTYyLTZHMkV4bzlHc2Q0UXZDNkFIZFphaUVmdUN1ZFh2VHdCNG1wUVkwV1BsQkRBQ3lUTUFBamxrVktvWEJGSENuUmJsSHNEc01Na1E?oc=5","published_at":"2024-01-29T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"World's Critical Infrastructure Suffered 13 Cyber Attacks Every Second in 2023&nbsp;&nbsp;securitytoday.com","title":"World's Critical Infrastructure Suffered 13 Cyber Attacks Every Second in 2023 - securitytoday.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-057f161a3630b8c2","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMixgFBVV95cUxPNlhkMFlocTVSQ2dvYng0dHFOUElpeEVjRmwyMHRPZ1l5UE9fdnNxSWpiNlBhVzZ1U21pZlA4S0RCWFhvNVZUalpBTjh6TFJxXzB3aXd5MEdXZlhCdzBZMnNUMWFxbEpjcFpMalBNT2IxX0V4U19TMHUxdTYyLTZHMkV4bzlHc2Q0UXZDNkFIZFphaUVmdUN1ZFh2VHdCNG1wUVkwV1BsQkRBQ3lUTUFBamxrVktvWEJGSENuUmJsSHNEc01Na1E?oc=5","published_at":"2024-01-29T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"World's Critical Infrastructure Suffered 13 Cyber Attacks Every Second in 2023&nbsp;&nbsp;Security Today","title":"World's Critical Infrastructure Suffered 13 Cyber Attacks Every Second in 2023 - Security Today"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-dd7ac64b617c1945","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMivwFBVV95cUxPSmNXOXQxNVBjTTcwdFpNSzJaSDhTemJUVjBadzdLdW9YQThpM2t0N1g4SUF3WmJSbm95VmdlWW1Oc25JNFozUWZ0R0dyUzFVSDBLT1lqZmY5el9DOWV4LTAtMVdzSlJPTEl6NVowV1BqeDFFU2IwNVZicEc2S3JqTXpORENDQ1B3dGlkUkMxemtyZDRndm9FWllQMGJMajZ0ZkVuWFJLZVhfRThEUmYyd2xncUpsMWI4NWw2U1pNMA?oc=5","published_at":"2024-01-24T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"At 13 Attacks Per Second, Critical Infrastructure is Under Siege&nbsp;&nbsp;financialcontent.com","title":"At 13 Attacks Per Second, Critical Infrastructure is Under Siege - financialcontent.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-01e2fd8f45a902d3","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMivwFBVV95cUxPSmNXOXQxNVBjTTcwdFpNSzJaSDhTemJUVjBadzdLdW9YQThpM2t0N1g4SUF3WmJSbm95VmdlWW1Oc25JNFozUWZ0R0dyUzFVSDBLT1lqZmY5el9DOWV4LTAtMVdzSlJPTEl6NVowV1BqeDFFU2IwNVZicEc2S3JqTXpORENDQ1B3dGlkUkMxemtyZDRndm9FWllQMGJMajZ0ZkVuWFJLZVhfRThEUmYyd2xncUpsMWI4NWw2U1pNMA?oc=5","published_at":"2024-01-24T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"At 13 Attacks Per Second, Critical Infrastructure is Under Siege&nbsp;&nbsp;FinancialContent","title":"At 13 Attacks Per Second, Critical Infrastructure is Under Siege - FinancialContent"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7339bf1458962dd5","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi8AFBVV95cUxPekRoT25FSFZhYTIzQUVPa2oxVTVRSEQtM2hiaGt6VDFvMzVBc3Zta0lpMnVqNXg1alA2cEJfYWdBYUQ1VEx5M0d5bHRUaEpWV0VWUkZwQnA4a3Vnb05pTVphZEFjaEZCUmFUNmlZa3BLQlJzZjg0d3FoWFFRaXgxNW0wUndYUlMzekxIYS1tczE3SjZXMXZma1NNOWlXYXVjUFdNNlMxZldFa0dhVVRjM1VrWkR0SjlMcUNvcklZUFFPajVRSlJLeVlkWXZzZGd6cjRvR1Q3M0x0ei1pVmkyZ1ZnQW42NnFFMmhSM0dBZ1fSAfYBQVVfeXFMTWtuYlVFbkpYQ1h3eUpKdkN3YjBBNTlFZS1yNVFEejhycDVvQlVvRVIxMUFpMGxzbjc0cGZVZDdGeklKYk5wS1Z5Ry1XX0ZSTzZMbWF3NzJsa055TVJnTU9wYjZpbnlvNV9VV0RNa0ZvSFZCczZHanBoQkIzem5XeFNzZU8zS3JtMHRsR0xpWG96NG5xTlJTSUQ4bzNpb2tCRWNTMVZfNDFhQkNmcnd4V1BSN09Qckp1RUpOYXRxcnNTeW1hYjNEMGdSWnRFN0RJWmxycUFEbUZtWnlXYmd4TUpqWldDcE9pYmM2UExyU2xVQUoxQ1h3?oc=5","published_at":"2024-01-10T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Cyber-security management landscape of the Indian automation industry: Overview, challenges, action points&nbsp;&nbsp;Forbes India","title":"Cyber-security management landscape of the Indian automation industry: Overview, challenges, action points - Forbes India"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f683d9d0de5a35cc","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi8AFBVV95cUxPekRoT25FSFZhYTIzQUVPa2oxVTVRSEQtM2hiaGt6VDFvMzVBc3Zta0lpMnVqNXg1alA2cEJfYWdBYUQ1VEx5M0d5bHRUaEpWV0VWUkZwQnA4a3Vnb05pTVphZEFjaEZCUmFUNmlZa3BLQlJzZjg0d3FoWFFRaXgxNW0wUndYUlMzekxIYS1tczE3SjZXMXZma1NNOWlXYXVjUFdNNlMxZldFa0dhVVRjM1VrWkR0SjlMcUNvcklZUFFPajVRSlJLeVlkWXZzZGd6cjRvR1Q3M0x0ei1pVmkyZ1ZnQW42NnFFMmhSM0dBZ1fSAfYBQVVfeXFMTWtuYlVFbkpYQ1h3eUpKdkN3YjBBNTlFZS1yNVFEejhycDVvQlVvRVIxMUFpMGxzbjc0cGZVZDdGeklKYk5wS1Z5Ry1XX0ZSTzZMbWF3NzJsa055TVJnTU9wYjZpbnlvNV9VV0RNa0ZvSFZCczZHanBoQkIzem5XeFNzZU8zS3JtMHRsR0xpWG96NG5xTlJTSUQ4bzNpb2tCRWNTMVZfNDFhQkNmcnd4V1BSN09Qckp1RUpOYXRxcnNTeW1hYjNEMGdSWnRFN0RJWmxycUFEbUZtWnlXYmd4TUpqWldDcE9pYmM2UExyU2xVQUoxQ1h3?oc=5","published_at":"2024-01-10T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Cyber-security management landscape of the Indian automation industry: Overview, challenges, action points&nbsp;&nbsp;forbesindia.com","title":"Cyber-security management landscape of the Indian automation industry: Overview, challenges, action points - forbesindia.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-aae92447661cdcc6","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi0AFBVV95cUxONUxoRnEtT3BfTzF2OUR2c3k0cHJJWTdRelE3RlZiVlZscWxFcHBjVUFLX0lxa1VfQzlUbkVjcnc2enVCdEdCU3ZVSktfbEFURGIzM0dGZmNJWUxlcDM2QnVQS0xuUmVKSnhuRklPVUM1aUtjOXhIWllFSUE3VlU0cndGVTNpQmdRNy10QVlwUFUyNU9wOFdBX1djdlpCekNMNW4wVFpXdU54ZC0zY2lmZGdqQ21BaVhsRDlxcVg0dkJQeEhGVzRLd3l3aW9ULUZ4?oc=5","published_at":"2024-01-05T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA issues ICS advisories covering hardware vulnerabilities in Rockwell, Mitsubishi Electric equipment&nbsp;&nbsp;industrialcyber.co","title":"CISA issues ICS advisories covering hardware vulnerabilities in Rockwell, Mitsubishi Electric equipment - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-5fcea05b8f491d80","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi0AFBVV95cUxONUxoRnEtT3BfTzF2OUR2c3k0cHJJWTdRelE3RlZiVlZscWxFcHBjVUFLX0lxa1VfQzlUbkVjcnc2enVCdEdCU3ZVSktfbEFURGIzM0dGZmNJWUxlcDM2QnVQS0xuUmVKSnhuRklPVUM1aUtjOXhIWllFSUE3VlU0cndGVTNpQmdRNy10QVlwUFUyNU9wOFdBX1djdlpCekNMNW4wVFpXdU54ZC0zY2lmZGdqQ21BaVhsRDlxcVg0dkJQeEhGVzRLd3l3aW9ULUZ4?oc=5","published_at":"2024-01-05T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA issues ICS advisories covering hardware vulnerabilities in Rockwell, Mitsubishi Electric equipment&nbsp;&nbsp;Industrial Cyber","title":"CISA issues ICS advisories covering hardware vulnerabilities in Rockwell, Mitsubishi Electric equipment - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ef916cb6aad01908","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiYEFVX3lxTE1DNTdrVU5vdUprRWdUUkVDSXloUlV5ZUhic19Td1hsNVloMWdmSkthaTB4eVN3SHF5YUgwVXhTWDNjdjlqcnU4Vmt6dDN3Y09NVzIwcElRUHJGTXJudTFwbw?oc=5","published_at":"2023-12-07T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"RETRACTED: Drought sensitivity in mesic forests heightens their vulnerability to climate change&nbsp;&nbsp;Science | AAAS","title":"RETRACTED: Drought sensitivity in mesic forests heightens their vulnerability to climate change - Science | AAAS"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2302156e46bb1ab8","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiYEFVX3lxTE1DNTdrVU5vdUprRWdUUkVDSXloUlV5ZUhic19Td1hsNVloMWdmSkthaTB4eVN3SHF5YUgwVXhTWDNjdjlqcnU4Vmt6dDN3Y09NVzIwcElRUHJGTXJudTFwbw?oc=5","published_at":"2023-12-07T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"RETRACTED: Drought sensitivity in mesic forests heightens their vulnerability to climate change&nbsp;&nbsp;science.org","title":"RETRACTED: Drought sensitivity in mesic forests heightens their vulnerability to climate change - science.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6fcbd53c6c5ae8f7","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilwFBVV95cUxPVmRSd2VkWXJFd2FhRkRpVlU0TndhY3kyRWtkaGdkeDhGWXF1NUE1VVZjdE9JQkNRZzFRYmVEUGJjMUUwaU5OMGtUMG1kbzF0TUpxVUdlaXk5QkdMUEQybkpnOVVVUTMwVkhKeFl1eG91bVJoa3ZPWnZjSVVhZDhTS1haRjFBYXJJc1NNMTNDbl9iMnRpNDNj?oc=5","published_at":"2023-11-22T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Social-ecological vulnerability to climate change and risk governance in coastal fishing communities of Bangladesh&nbsp;&nbsp;Frontiers","title":"Social-ecological vulnerability to climate change and risk governance in coastal fishing communities of Bangladesh - Frontiers"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8c5d4073c087324c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilwFBVV95cUxPVmRSd2VkWXJFd2FhRkRpVlU0TndhY3kyRWtkaGdkeDhGWXF1NUE1VVZjdE9JQkNRZzFRYmVEUGJjMUUwaU5OMGtUMG1kbzF0TUpxVUdlaXk5QkdMUEQybkpnOVVVUTMwVkhKeFl1eG91bVJoa3ZPWnZjSVVhZDhTS1haRjFBYXJJc1NNMTNDbl9iMnRpNDNj?oc=5","published_at":"2023-11-22T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Social-ecological vulnerability to climate change and risk governance in coastal fishing communities of Bangladesh&nbsp;&nbsp;frontiersin.org","title":"Social-ecological vulnerability to climate change and risk governance in coastal fishing communities of Bangladesh - frontiersin.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c0dd2cd41a54c26e","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiwAFBVV95cUxNdS1iUVFwemtZQTljWTVmSlZfUkJhc3daZjhYN3RhZ3k5cHJsOWM0WFUtcWFEVVV4SkhiaURIOThNemIxN2xudjJrcFhZeTdEVWJEaVowVHZfVUVlYkFySHU1TENteS1pY0Rwdk5iRm5YQW9OWDhlUlduTndEd1J6aFlXWVFqcEdkQnhzcUJNbXlRM0tNYy1HOWlWbzRUOGs4SUhqU01rS184ZExxLVJyWGtZZHVzZTdFRGNJbHJxR2s?oc=5","published_at":"2023-11-06T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Industrial Switch Security","summary":"Winds of Change: SEC's SolarWinds Lawsuit Signals Hotter Cybersecurity Enforcement&nbsp;&nbsp;hklaw.com","title":"Winds of Change: SEC's SolarWinds Lawsuit Signals Hotter Cybersecurity Enforcement - hklaw.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-062fb95380b645ba","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiwAFBVV95cUxNdS1iUVFwemtZQTljWTVmSlZfUkJhc3daZjhYN3RhZ3k5cHJsOWM0WFUtcWFEVVV4SkhiaURIOThNemIxN2xudjJrcFhZeTdEVWJEaVowVHZfVUVlYkFySHU1TENteS1pY0Rwdk5iRm5YQW9OWDhlUlduTndEd1J6aFlXWVFqcEdkQnhzcUJNbXlRM0tNYy1HOWlWbzRUOGs4SUhqU01rS184ZExxLVJyWGtZZHVzZTdFRGNJbHJxR2s?oc=5","published_at":"2023-11-06T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Industrial Switch Security","summary":"Winds of Change: SEC's SolarWinds Lawsuit Signals Hotter Cybersecurity Enforcement&nbsp;&nbsp;Holland & Knight","title":"Winds of Change: SEC's SolarWinds Lawsuit Signals Hotter Cybersecurity Enforcement - Holland & Knight"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-a35e11967f7c5af3","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMimwFBVV95cUxOM2VaVnV6RUdIQl9naldjUkhDUGFOVllUcFkzV1hnSTZDQ1ROZXd4NVR2clVqSU1UcmQxa2J3VWVxVkVYcXZJdTJyQ1JURXQ5U0NZOFF5M1N2Ym1TUkFvU3dKMHM3U09yT2tzbjNZQmJha3puNFZzaG52N1VCOXUwWWRnN29YaFl3Yy12ZTVibHQ1akF2RDlrbk56RQ?oc=5","published_at":"2023-10-26T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Rockwell's Verve Buy Enlivens Critical Infrastructure Security&nbsp;&nbsp;Dark Reading","title":"Rockwell's Verve Buy Enlivens Critical Infrastructure Security - Dark Reading"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-72bd7be9212a616e","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMirwFBVV95cUxQV29oc05wMmFEMU5KNjd2SmVNOXk3NGRKTWxTNDRJaWkyMm1OTEFINGcxMm1vMENMRTZIcjlUNWZWOTcxN2dVaDRfWkctMm9SYmJibUVTYlJHSk9VY2tTblQ4bUZIUmRaQW0ySUkyWjZHcmc5OEEzZXlNRVByNTlMS241RUdEU2Rqam85V0ctTEJyeFpyZHVWeDUyekdkSGxESFR5dU9SZ05ZVkRsSm5N0gG0AUFVX3lxTE1HeVBYZVJlMHlOUlNiMjF4TXB6YVhTcTRKZURScGQ5NnBUXzRlbllFRUdUT0tlRUFQUEpGTW1La21JMmtla19rUGpOV0NjeVhpUnAzS19TNnNnanZXYTdhT2lubERZVzhwOXJVMGNJaU8ydFo5bDJsXzJnVDNIV2VPOHl1c1ozZzNVVHNHbTM0QlR3UTVrX21GRm1scVIycGRhUEVqZzA3a3lOOGdsRkZoZTdmdA?oc=5","published_at":"2023-10-24T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Rockwell Automation Warns Customers of Cisco Zero-Day Affecting Stratix Switches&nbsp;&nbsp;SecurityWeek","title":"Rockwell Automation Warns Customers of Cisco Zero-Day Affecting Stratix Switches - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-70ac787563a7c0b1","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMirwFBVV95cUxQV29oc05wMmFEMU5KNjd2SmVNOXk3NGRKTWxTNDRJaWkyMm1OTEFINGcxMm1vMENMRTZIcjlUNWZWOTcxN2dVaDRfWkctMm9SYmJibUVTYlJHSk9VY2tTblQ4bUZIUmRaQW0ySUkyWjZHcmc5OEEzZXlNRVByNTlMS241RUdEU2Rqam85V0ctTEJyeFpyZHVWeDUyekdkSGxESFR5dU9SZ05ZVkRsSm5N0gG0AUFVX3lxTE1HeVBYZVJlMHlOUlNiMjF4TXB6YVhTcTRKZURScGQ5NnBUXzRlbllFRUdUT0tlRUFQUEpGTW1La21JMmtla19rUGpOV0NjeVhpUnAzS19TNnNnanZXYTdhT2lubERZVzhwOXJVMGNJaU8ydFo5bDJsXzJnVDNIV2VPOHl1c1ozZzNVVHNHbTM0QlR3UTVrX21GRm1scVIycGRhUEVqZzA3a3lOOGdsRkZoZTdmdA?oc=5","published_at":"2023-10-24T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Rockwell Automation Warns Customers of Cisco Zero-Day Affecting Stratix Switches&nbsp;&nbsp;securityweek.com","title":"Rockwell Automation Warns Customers of Cisco Zero-Day Affecting Stratix Switches - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-ca5ad1468fac9b04","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxNVWtCSk5PTGFpLW9ib29lWkJfUjRyd3cwLVMzNHFOVlJCMmFJci1zMy1EcWVrTEJvLWN3Q3ZqUUctU1RsZE9lSDA3T0lkVEplakNqMlkwa21memJCazhRVHpPSlJSZlR0aHFaN0xsbUFqX25jRmdpM3BzcmxpdG1ja1o1QnlDTndWNEo4ejhnQTVja0V4VFJCRUNNY2VEa0k?oc=5","published_at":"2023-10-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell Automation agrees to acquire Verve Industrial Protection&nbsp;&nbsp;Industrial Cyber","title":"Rockwell Automation agrees to acquire Verve Industrial Protection - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-15e3c858b475f2ca","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiywFBVV95cUxQZEJrS3hOMkg1RUpJSVppeVlvYlJLaHJkcWJWQlpCTVJrZVdtSDlVVVZOZkJ3SDNkRTRpNEdEWmZwREQtdzhlU2dXclhnay1jTnN3LWlsSHJkc1ZTNHh2Ums5bUQ4RWo1eUpieXdXckpHWS1RODlQNVFpQjBDdk5BLTJyeDRPYTc4WkRmSXNrOHhMMDdzMHhaTktwbVdiZ19TTWdiN1VNckI0QVgxNWo1SEwzUlNCOXlRemZBZXJLOFNWU3Y3NXFkQ1lnUQ?oc=5","published_at":"2023-10-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell Automation Signs Agreement to Acquire Verve Industrial Protection&nbsp;&nbsp;businesswire.com","title":"Rockwell Automation Signs Agreement to Acquire Verve Industrial Protection - businesswire.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-de10bc5ac4cfacca","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiywFBVV95cUxQZEJrS3hOMkg1RUpJSVppeVlvYlJLaHJkcWJWQlpCTVJrZVdtSDlVVVZOZkJ3SDNkRTRpNEdEWmZwREQtdzhlU2dXclhnay1jTnN3LWlsSHJkc1ZTNHh2Ums5bUQ4RWo1eUpieXdXckpHWS1RODlQNVFpQjBDdk5BLTJyeDRPYTc4WkRmSXNrOHhMMDdzMHhaTktwbVdiZ19TTWdiN1VNckI0QVgxNWo1SEwzUlNCOXlRemZBZXJLOFNWU3Y3NXFkQ1lnUQ?oc=5","published_at":"2023-10-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell Automation Signs Agreement to Acquire Verve Industrial Protection&nbsp;&nbsp;Business Wire","title":"Rockwell Automation Signs Agreement to Acquire Verve Industrial Protection - Business Wire"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-a075645cccf5c8a8","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxNVWtCSk5PTGFpLW9ib29lWkJfUjRyd3cwLVMzNHFOVlJCMmFJci1zMy1EcWVrTEJvLWN3Q3ZqUUctU1RsZE9lSDA3T0lkVEplakNqMlkwa21memJCazhRVHpPSlJSZlR0aHFaN0xsbUFqX25jRmdpM3BzcmxpdG1ja1o1QnlDTndWNEo4ejhnQTVja0V4VFJCRUNNY2VEa0k?oc=5","published_at":"2023-10-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell Automation agrees to acquire Verve Industrial Protection&nbsp;&nbsp;industrialcyber.co","title":"Rockwell Automation agrees to acquire Verve Industrial Protection - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-14a11210538ba646","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiowFBVV95cUxOdzhJajgwNFZXN2RTaXhIUEY5d0pBYmlyU1FPT2Q0eUU0TlRkRkI0Y0ZxY0hEcTdFWFRSbG9yZ1FyT1RxTWJKRk5MOHB0UHF1Y25vVDhBRXRCeW1sU3VxSmJrMy1pelJwaWtMRUJfMjY0SzlOQVlaR05nbXF2SmxNUUNuQ2lULWIweUI0cDV3Skt0c0h2NFZRUEVYZ2JtWW4xcFJz?oc=5","published_at":"2023-09-28T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"NIST Publishes Guide to Operational Technology (OT) Security&nbsp;&nbsp;nist.gov","title":"NIST Publishes Guide to Operational Technology (OT) Security - nist.gov"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e86eb05322d047ab","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiowFBVV95cUxOdzhJajgwNFZXN2RTaXhIUEY5d0pBYmlyU1FPT2Q0eUU0TlRkRkI0Y0ZxY0hEcTdFWFRSbG9yZ1FyT1RxTWJKRk5MOHB0UHF1Y25vVDhBRXRCeW1sU3VxSmJrMy1pelJwaWtMRUJfMjY0SzlOQVlaR05nbXF2SmxNUUNuQ2lULWIweUI0cDV3Skt0c0h2NFZRUEVYZ2JtWW4xcFJz?oc=5","published_at":"2023-09-28T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"NIST Publishes Guide to Operational Technology (OT) Security&nbsp;&nbsp;National Institute of Standards and Technology (.gov)","title":"NIST Publishes Guide to Operational Technology (OT) Security - National Institute of Standards and Technology (.gov)"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-c7f8523908d59158","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMizAFBVV95cUxPeG5RTmNmZEw2eGF1bmxLanhha3hOZ0RHREI0VVVpLWFKa2NUdUhKbU45UlBBNG81aUtNcU9FZ2hGcFNYQUd1SnZkdnFLUGlMWW93c3hjVV9hNk5jdlg1QUFyQkJXc1dTV3RNS2lsc0VndC1JRG1qX0xmQ0VTOG4xdmhnUDJ4aW9RclFfRUNuTUVOWUxHeUtMUmx4MksxSlBtMUp2QWFLd1J6ZlFlS29vQ1RYaHlBa1RFaGZ4RDFiS3FpTGYwYzlfRWNPbDU?oc=5","published_at":"2023-09-21T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Rockwell reports surge in cyberattacks on critical infrastructure, intense focus on energy sector&nbsp;&nbsp;industrialcyber.co","title":"Rockwell reports surge in cyberattacks on critical infrastructure, intense focus on energy sector - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-a633d4b7fdc02daf","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMizAFBVV95cUxPeG5RTmNmZEw2eGF1bmxLanhha3hOZ0RHREI0VVVpLWFKa2NUdUhKbU45UlBBNG81aUtNcU9FZ2hGcFNYQUd1SnZkdnFLUGlMWW93c3hjVV9hNk5jdlg1QUFyQkJXc1dTV3RNS2lsc0VndC1JRG1qX0xmQ0VTOG4xdmhnUDJ4aW9RclFfRUNuTUVOWUxHeUtMUmx4MksxSlBtMUp2QWFLd1J6ZlFlS29vQ1RYaHlBa1RFaGZ4RDFiS3FpTGYwYzlfRWNPbDU?oc=5","published_at":"2023-09-21T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Rockwell reports surge in cyberattacks on critical infrastructure, intense focus on energy sector&nbsp;&nbsp;Industrial Cyber","title":"Rockwell reports surge in cyberattacks on critical infrastructure, intense focus on energy sector - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-34832dafa3b3a491","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxPblB6R2JtTmJnZlMtWGFsdDhOdkNjQXptTFU3eDI0akJDNy1jeUNETGpOSGZsOWg2RlFPSnpNX1dTVWZDSEQ5YnZFY2t6Ylp1N1NLaHR6ak00YVFCVGZkU1ItUG9ubE5IeGhtMEY2cUhSaXNsTjRockg5QVV2bjJ4ci1sQ2M5eGl6cy1zb0dPX2NtR3IwNXJKRnZMcXc2bnV5V2hJNk0xUlV2UQ?oc=5","published_at":"2023-09-15T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Inductive Automation Launches New Partner Program&nbsp;&nbsp;Automation World","title":"Inductive Automation Launches New Partner Program - Automation World"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-5e51026b0b833dd1","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxPblB6R2JtTmJnZlMtWGFsdDhOdkNjQXptTFU3eDI0akJDNy1jeUNETGpOSGZsOWg2RlFPSnpNX1dTVWZDSEQ5YnZFY2t6Ylp1N1NLaHR6ak00YVFCVGZkU1ItUG9ubE5IeGhtMEY2cUhSaXNsTjRockg5QVV2bjJ4ci1sQ2M5eGl6cy1zb0dPX2NtR3IwNXJKRnZMcXc2bnV5V2hJNk0xUlV2UQ?oc=5","published_at":"2023-09-15T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Inductive Automation Launches New Partner Program&nbsp;&nbsp;automationworld.com","title":"Inductive Automation Launches New Partner Program - automationworld.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-ac0007c8e1d9ef04","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiiAJBVV95cUxOZ2FiM0hiYTdyWWgxTmNCMXVzbkQyMWRSeDZJNWRHNDNBMV9yZ0FRVWNxZlo1MHAybk41TzdwbXJxbk53WlBNekcwZTl1aUkyaWE5Rm53djlLOVZ2bzhMbDVVUVJ1VmZxSHZNbmlfcFZLUXhndEliLWNsUFdaUUxEMVpManF0eTM5d3VaTUhUYkt5SFlPM05XUTJ2c2dHbl9wUzgxZEdERVBCOEppYzg3dWdIZHplWmpkNEZJVXViSGIwRlRoNVBvaE9jWi13NmpxNnJMWXhLZEs0c0dwZXZPOVZIRnA1bks4UXFFSTZiTVlxOWZMY3RabGhPYnZaUk9abGc0UXBWb1g?oc=5","published_at":"2023-09-13T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Siemens, Rockwell Automation, Bosch Rexroth, and ABB Named Market Leaders in ABI Research's PLC Solutions Competitive Ranking&nbsp;&nbsp;prnewswire.com","title":"Siemens, Rockwell Automation, Bosch Rexroth, and ABB Named Market Leaders in ABI Research's PLC Solutions Competitive Ranking - prnewswire.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-79290be827576ae6","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiiAJBVV95cUxOZ2FiM0hiYTdyWWgxTmNCMXVzbkQyMWRSeDZJNWRHNDNBMV9yZ0FRVWNxZlo1MHAybk41TzdwbXJxbk53WlBNekcwZTl1aUkyaWE5Rm53djlLOVZ2bzhMbDVVUVJ1VmZxSHZNbmlfcFZLUXhndEliLWNsUFdaUUxEMVpManF0eTM5d3VaTUhUYkt5SFlPM05XUTJ2c2dHbl9wUzgxZEdERVBCOEppYzg3dWdIZHplWmpkNEZJVXViSGIwRlRoNVBvaE9jWi13NmpxNnJMWXhLZEs0c0dwZXZPOVZIRnA1bks4UXFFSTZiTVlxOWZMY3RabGhPYnZaUk9abGc0UXBWb1g?oc=5","published_at":"2023-09-13T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Siemens, Rockwell Automation, Bosch Rexroth, and ABB Named Market Leaders in ABI Research's PLC Solutions Competitive Ranking&nbsp;&nbsp;PR Newswire","title":"Siemens, Rockwell Automation, Bosch Rexroth, and ABB Named Market Leaders in ABI Research's PLC Solutions Competitive Ranking - PR Newswire"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-aa585e2988b0cb72","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilwFBVV95cUxPWlQyTGJEcHBGRWVPNmFSUXN0V3dVZnpwSkNwbXlEZzNaUVFKVW1JUVM4eXJod1V2T2w5aEtQU0tnS2dUYmZBRlhxUWtYcVRERFZ2dGZzY004aTVzTml4MUNDR1RfWW80OXRxUHMxcEVQaV9KdzV3a290QUItWF9QR0VvVm10OU56ZTdkYzdPZ21EV3NBakxj?oc=5","published_at":"2023-08-31T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"A Brief History of ICS-Tailored Attacks&nbsp;&nbsp;Dark Reading","title":"A Brief History of ICS-Tailored Attacks - Dark Reading"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-087396f0194b38e9","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilwFBVV95cUxPWlQyTGJEcHBGRWVPNmFSUXN0V3dVZnpwSkNwbXlEZzNaUVFKVW1JUVM4eXJod1V2T2w5aEtQU0tnS2dUYmZBRlhxUWtYcVRERFZ2dGZzY004aTVzTml4MUNDR1RfWW80OXRxUHMxcEVQaV9KdzV3a290QUItWF9QR0VvVm10OU56ZTdkYzdPZ21EV3NBakxj?oc=5","published_at":"2023-08-31T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"A Brief History of ICS-Tailored Attacks&nbsp;&nbsp;darkreading.com","title":"A Brief History of ICS-Tailored Attacks - darkreading.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-7fa9223e825ac8ce","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi4wFBVV95cUxOZTNwNG5FbFRuYmNFTm5KTjFacThNRHZRX25zd2wtRjIyLW0ybEFfN1puSU1pMVNoWF9GNHBONWQtZ2haOFI0bVNzdWtFMU02aHZRQlJPYi10SktGLW81NFNIRjVES25jYVdySVI0cEh6N3lOeEV3Uk9FUmhVdy1wdVpUNlpqYjFIWDRDUjI1MDRQT1hRVHVjSS1pbXJNcmJFNU9DRmEycFlCdnRObENyd2VLel9icGpRVWVvU3AzWHV2TGx5Z2FEQy1Pc2ZxRjZOSkZ1UlhUTkpfZ0YzTDZFT1NpOA?oc=5","published_at":"2023-08-25T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA publishes ICS advisories covering hardware vulnerabilities in KNX, Opto 22, Rockwell Automation, CODESYS equipment&nbsp;&nbsp;industrialcyber.co","title":"CISA publishes ICS advisories covering hardware vulnerabilities in KNX, Opto 22, Rockwell Automation, CODESYS equipment - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-c4172a72593e6162","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi4wFBVV95cUxOZTNwNG5FbFRuYmNFTm5KTjFacThNRHZRX25zd2wtRjIyLW0ybEFfN1puSU1pMVNoWF9GNHBONWQtZ2haOFI0bVNzdWtFMU02aHZRQlJPYi10SktGLW81NFNIRjVES25jYVdySVI0cEh6N3lOeEV3Uk9FUmhVdy1wdVpUNlpqYjFIWDRDUjI1MDRQT1hRVHVjSS1pbXJNcmJFNU9DRmEycFlCdnRObENyd2VLel9icGpRVWVvU3AzWHV2TGx5Z2FEQy1Pc2ZxRjZOSkZ1UlhUTkpfZ0YzTDZFT1NpOA?oc=5","published_at":"2023-08-25T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA publishes ICS advisories covering hardware vulnerabilities in KNX, Opto 22, Rockwell Automation, CODESYS equipment&nbsp;&nbsp;Industrial Cyber","title":"CISA publishes ICS advisories covering hardware vulnerabilities in KNX, Opto 22, Rockwell Automation, CODESYS equipment - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-947f419a33404a3a","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMixgFBVV95cUxOYXRxVVcyOWswemR0Q1ZmNmlPTlRsTUlkSWZkUW9BeU13bnhNWnJkS0VfVzljMlNaS25hTTdOMmpCZTFHQXQtX3hGZkVVNzFtSkM2bVNQY1FHb09TSlhRRW9qaE4xNXlidnpncmpweHBBdjFqOVdtU2QydzJxaTNGa2NwcjF2TFdWR1dyQzRNckFueU12ODh6RktIR3NnajBkbEotOHc4cGhBTkZiMmpobWVYdGJPOHlqMTFZMWhCWmMyUWNqZlE?oc=5","published_at":"2023-08-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA discloses presence of ICS vulnerabilities in equipment from Hitachi Energy, Trane, Rockwell&nbsp;&nbsp;Industrial Cyber","title":"CISA discloses presence of ICS vulnerabilities in equipment from Hitachi Energy, Trane, Rockwell - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-768d5e0b774bf04c","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi3AFBVV95cUxPdFZJN1czQU5TU3F3TEZ4YXNmSldBV0JuZVpsTHk3SWVYU1VRc0dteDFQcHpGc0R3dGZUazN6V3hiSUpUbG5SVFF3Sm1MMVpPeTE3R2N5RHZTeGJuV2RNblVCVWEzWFZaODJOLUh0NkNYdFZWTWRza1gwR2dNZnY5ODN4eHRJNk9aX3pqN0J5NU4wWU5qY21iRnFSazhnUWl3cF9VQnc1MTJQQ1RxTXpZSU5faGIyX1Q3dFlmSmtnTDJwNzhlVVhvVW4wbGlOSnZIVlZNRndKLU5wZ2Jh?oc=5","published_at":"2023-08-16T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA discloses security vulnerabilities in Schneider Electric EcoStruxure and Modicon, Rockwell\u2019s Armor PowerFlex&nbsp;&nbsp;industrialcyber.co","title":"CISA discloses security vulnerabilities in Schneider Electric EcoStruxure and Modicon, Rockwell\u2019s Armor PowerFlex - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-cf7934bb916e728d","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi3AFBVV95cUxPdFZJN1czQU5TU3F3TEZ4YXNmSldBV0JuZVpsTHk3SWVYU1VRc0dteDFQcHpGc0R3dGZUazN6V3hiSUpUbG5SVFF3Sm1MMVpPeTE3R2N5RHZTeGJuV2RNblVCVWEzWFZaODJOLUh0NkNYdFZWTWRza1gwR2dNZnY5ODN4eHRJNk9aX3pqN0J5NU4wWU5qY21iRnFSazhnUWl3cF9VQnc1MTJQQ1RxTXpZSU5faGIyX1Q3dFlmSmtnTDJwNzhlVVhvVW4wbGlOSnZIVlZNRndKLU5wZ2Jh?oc=5","published_at":"2023-08-16T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA discloses security vulnerabilities in Schneider Electric EcoStruxure and Modicon, Rockwell\u2019s Armor PowerFlex&nbsp;&nbsp;Industrial Cyber","title":"CISA discloses security vulnerabilities in Schneider Electric EcoStruxure and Modicon, Rockwell\u2019s Armor PowerFlex - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-c8106b23b8a84df6","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiaEFVX3lxTFBOc1VvaGFJOUJVR2Q0VXlHLWtWWlhyVU9Sc0tUU0dnOXBtRVplbl9Qb2pCWXJ3R2JxTHQwb09pX3NuMnVsdXlqTWY4Xy12NXpNd3lmZ0dFZ2xCMUx5c0RVbjhucXlNVVAy?oc=5","published_at":"2023-08-13T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Two faces of vulnerability: Distinguishing susceptibility to harm and system resilience in climate adaptation&nbsp;&nbsp;Wiley Interdisciplinary Reviews","title":"Two faces of vulnerability: Distinguishing susceptibility to harm and system resilience in climate adaptation - Wiley Interdisciplinary Reviews"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-decea7e3515b2d97","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiaEFVX3lxTFBOc1VvaGFJOUJVR2Q0VXlHLWtWWlhyVU9Sc0tUU0dnOXBtRVplbl9Qb2pCWXJ3R2JxTHQwb09pX3NuMnVsdXlqTWY4Xy12NXpNd3lmZ0dFZ2xCMUx5c0RVbjhucXlNVVAy?oc=5","published_at":"2023-08-13T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Two faces of vulnerability: Distinguishing susceptibility to harm and system resilience in climate adaptation&nbsp;&nbsp;wires.onlinelibrary.wiley.com","title":"Two faces of vulnerability: Distinguishing susceptibility to harm and system resilience in climate adaptation - wires.onlinelibrary.wiley.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-5db052bf82e22edb","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiuwFBVV95cUxQMWhEd2JOeDk3azJRWTF2YnYzUTYxRWp5b1U3RTZ5MnI2VERVQVptWG0xZml4N0NTaGNYNVZQbllnX1ZBbDRxLVhyeWNTWFczWnFXcEVCejBGVDc4cngzS0JsSnJxdDhpOWVSSlM2REtNcFg4M3p4VGZpN2RxX25XekhwYm1jbllEbVRZNnMwV29HNEdfSk9jTTRPMEJZRTNtY0IwZmh2SmtZMUlfYV9wY3dKZmkxdGw3ZW1V?oc=5","published_at":"2023-07-20T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"The Rising Importance of PLC Cybersecurity: An Essential Look into Industrial Vulnerability&nbsp;&nbsp;engineering.com","title":"The Rising Importance of PLC Cybersecurity: An Essential Look into Industrial Vulnerability - engineering.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-67d9cab645505158","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiuwFBVV95cUxQMWhEd2JOeDk3azJRWTF2YnYzUTYxRWp5b1U3RTZ5MnI2VERVQVptWG0xZml4N0NTaGNYNVZQbllnX1ZBbDRxLVhyeWNTWFczWnFXcEVCejBGVDc4cngzS0JsSnJxdDhpOWVSSlM2REtNcFg4M3p4VGZpN2RxX25XekhwYm1jbllEbVRZNnMwV29HNEdfSk9jTTRPMEJZRTNtY0IwZmh2SmtZMUlfYV9wY3dKZmkxdGw3ZW1V?oc=5","published_at":"2023-07-20T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"The Rising Importance of PLC Cybersecurity: An Essential Look into Industrial Vulnerability&nbsp;&nbsp;Engineering.com","title":"The Rising Importance of PLC Cybersecurity: An Essential Look into Industrial Vulnerability - Engineering.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5f9b8bc44ca50006","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxPZTZoMzd5S202VTBtUWMxRmU0YXpDX29xSFAxR0NZbUVkSV9RRkVWbm5wTE9MZl8wM3k3ZXA5MzNvWE02LU9PZTFzMUtETDZ4Y0pWSUNYUl9HUXdqckFlTGdwckl1dk82eTVyMmE0X21NWXhtVWVQbkktM0VjSm5oeEctYkxJOHJENklkcnhfQ1Zfa3BMcjFNUXRFRWpIQlppU05pTS1Lbk4ydnc2bmo4dNIBtgFBVV95cUxQRk1FSFo4a1JsSnFDaFl5TFR2cGh2dzA3TlNBbl9YMG9PTFRJdjRQQ0Z0ZlhlcnJNLXF0cnVjT19hVFNXYkZRb1Z5cnVmTVhyTmwxSWNPaDRPMkVKdzViZ01ySjh2ZmYtT19SeHk1cEpWS0xVaUdKUmduekZSTEpwZFRUclF4Z21SZUtwd0p3S3pQRWx2YWt3V3JIbngwZUE3dklyaWt0a0otMEZpZ3pmRG5BNFNtZw?oc=5","published_at":"2023-07-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"OT ICS Malware & Zero-Days","summary":"Recently Patched GE Cimplicity Vulnerabilities Reminiscent of Russian ICS Attacks&nbsp;&nbsp;SecurityWeek","title":"Recently Patched GE Cimplicity Vulnerabilities Reminiscent of Russian ICS Attacks - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-7922229880716ccc","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi3wJBVV95cUxPajQydklkMXJMQnllOWVQWFJzT1pLLWtuZVNUbjhKdnFoTE03WmZvN2tLLVQ4dnQteUNMSERhVXpMVXBweFBPZVRlald1d3pXRV9EVTB4NktjMVQyekthb2Ytak9TaHg2YzVYNXZ6bF9zYWVvZjNoajR2TU53YlBMLVNRZW5VZXNCS1UzY1VJcHQzZGM3WHpENEVsSTBpTVRoZV9ScnNUMG9UeUQzdHplNFVaNjFzNjRpUTV2Y0U2LXNrRTlnelNIRldISUtZNWVvMVVBMlpVbWNfOFA3MjhNZDd6SmxBb2ZUeGpuVWhKTTh1UjZ1NGpvODZqLXJBcDllWlU2Y1JCYU9DSnZJZENiNDl5X1VaM3kwcFRJV0FuR0kzUVl0cGs5M1R3NGN0RlN3WTFwWnVHOFE1c0o0amcyMHg2SHdyNFRPemxpYnlTUnJPTkc0cmZyNlR3d24yWkk?oc=5","published_at":"2023-07-18T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA reveals ICS hardware vulnerabilities across Siemens RUGGEDCOM ROX, SIMATIC, Rockwell Automation equipment&nbsp;&nbsp;industrialcyber.co","title":"CISA reveals ICS hardware vulnerabilities across Siemens RUGGEDCOM ROX, SIMATIC, Rockwell Automation equipment - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-776f648a8cff9d5f","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi3wJBVV95cUxPajQydklkMXJMQnllOWVQWFJzT1pLLWtuZVNUbjhKdnFoTE03WmZvN2tLLVQ4dnQteUNMSERhVXpMVXBweFBPZVRlald1d3pXRV9EVTB4NktjMVQyekthb2Ytak9TaHg2YzVYNXZ6bF9zYWVvZjNoajR2TU53YlBMLVNRZW5VZXNCS1UzY1VJcHQzZGM3WHpENEVsSTBpTVRoZV9ScnNUMG9UeUQzdHplNFVaNjFzNjRpUTV2Y0U2LXNrRTlnelNIRldISUtZNWVvMVVBMlpVbWNfOFA3MjhNZDd6SmxBb2ZUeGpuVWhKTTh1UjZ1NGpvODZqLXJBcDllWlU2Y1JCYU9DSnZJZENiNDl5X1VaM3kwcFRJV0FuR0kzUVl0cGs5M1R3NGN0RlN3WTFwWnVHOFE1c0o0amcyMHg2SHdyNFRPemxpYnlTUnJPTkc0cmZyNlR3d24yWkk?oc=5","published_at":"2023-07-18T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA reveals ICS hardware vulnerabilities across Siemens RUGGEDCOM ROX, SIMATIC, Rockwell Automation equipment&nbsp;&nbsp;Industrial Cyber","title":"CISA reveals ICS hardware vulnerabilities across Siemens RUGGEDCOM ROX, SIMATIC, Rockwell Automation equipment - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-8f26a70f6d272fec","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiuwFBVV95cUxPNWJEWTVWYU5ackgydHdYY2lLdHN5TllZZUItVDFqQWdyYXBjU3RLRnBCUklVUG9QZElldVJ5UEZTMlVJMFZydVVBVkhkSlVnc19VTjNPSUNLM3NWdGk5MGY2LVZfcUNzU2dnclRmdVc5aHNWZGFSdDRuaDJqajlZTFNXeTdrcWxSa2I2ckNHVmxENDhYRTZzNWpyNnlwZmxDNENmajNpcXpiWlpLMXluZVRWSjlrRnJBX1FF0gHAAUFVX3lxTE81TkpZWkttclMwN1lWVzM2SnNFdGlFN0xmS3hpbEpyZE9VSnZYenV1QS1kMDNWM1kzdUNpZWF1Mmw0REVPb3EzTHhYSlI4SzFOWGFQTkFBOFZZSHlkQjU1Ym9jeVBPS2pvYmY1ek9WOVJvNFJubUREeUNCS2ZsYjRoWjJKdUZkemRqNXdYN1U5dzJ1SXM1cDZFMDhPdHhsalhqbXYwa1ZjMHVCV2g5NENZRW1DZXNBRlg5U0k3LWZGTw?oc=5","published_at":"2023-07-14T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Rockwell warns of new APT RCE exploit targeting critical infrastructure&nbsp;&nbsp;bleepingcomputer.com","title":"Rockwell warns of new APT RCE exploit targeting critical infrastructure - bleepingcomputer.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-35d18382d81a827d","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiuwFBVV95cUxPNWJEWTVWYU5ackgydHdYY2lLdHN5TllZZUItVDFqQWdyYXBjU3RLRnBCUklVUG9QZElldVJ5UEZTMlVJMFZydVVBVkhkSlVnc19VTjNPSUNLM3NWdGk5MGY2LVZfcUNzU2dnclRmdVc5aHNWZGFSdDRuaDJqajlZTFNXeTdrcWxSa2I2ckNHVmxENDhYRTZzNWpyNnlwZmxDNENmajNpcXpiWlpLMXluZVRWSjlrRnJBX1FF0gHAAUFVX3lxTE81TkpZWkttclMwN1lWVzM2SnNFdGlFN0xmS3hpbEpyZE9VSnZYenV1QS1kMDNWM1kzdUNpZWF1Mmw0REVPb3EzTHhYSlI4SzFOWGFQTkFBOFZZSHlkQjU1Ym9jeVBPS2pvYmY1ek9WOVJvNFJubUREeUNCS2ZsYjRoWjJKdUZkemRqNXdYN1U5dzJ1SXM1cDZFMDhPdHhsalhqbXYwa1ZjMHVCV2g5NENZRW1DZXNBRlg5U0k3LWZGTw?oc=5","published_at":"2023-07-14T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Rockwell warns of new APT RCE exploit targeting critical infrastructure&nbsp;&nbsp;BleepingComputer","title":"Rockwell warns of new APT RCE exploit targeting critical infrastructure - BleepingComputer"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-84bd138798e8c1d8","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMilAFBVV95cUxPbUFqby1LVjBYQjA4SWFvMlJpYkV3SGVJd0RwdC04YkFJbHlWb1VNQWhhVkJlTGlSbDQ2ZG1yM0xlcGZOZXhOTlNjTVlnRUYzemZ5QkZ2M19URDZjTml0YU1RQ2dqZllxRFZLanlSVXduVHY2cHhmVHhaSjlKTmtVdktXZ2J3QnFlX3RmTmdKbXlRNEJB?oc=5","published_at":"2023-07-14T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Rockwell Automation, Honeywell warned of critical vulnerabilities in industrial products&nbsp;&nbsp;Cybersecurity Dive","title":"Rockwell Automation, Honeywell warned of critical vulnerabilities in industrial products - Cybersecurity Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-848fb2f5416ead50","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMijgJBVV95cUxOUmtPUkdCUjdWLXpNNzZINkFHd0NvZmxNdDRJN3RYWElLZ09mRlBWcGRDbHQ4WTlmaW4talFkTU93Nkk1LUhVcEhhNHBQR2RhYVpjdm1ZOWdYSjl0SXJXdEtRRXBuOGJNeTNCRTNkTEVXUElLbzh0SGxuMHhaYjZiZFhsakFDMHRJbTBCa3RtWUZINFpxSm1NV3VUQS1JRVp4X2VhcVpKcE5pMlZ5blI3a1JycW5UUWFEYTRHbWN5X19CcWF5MlotRXgwNXZKWlB1d3dsdW9paHVFd2toQ0ktTHNlU01OWTktWW51bE80Y0tJY0VNNjRob25UZnZJYmRGVkxKcW1zMFE2VThqLWc?oc=5","published_at":"2023-07-14T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell Automation\u2019s AB Micro850 and Micro870 PLC Systems Provide Connectivity, Design Efficiency&nbsp;&nbsp;Machine Design","title":"Rockwell Automation\u2019s AB Micro850 and Micro870 PLC Systems Provide Connectivity, Design Efficiency - Machine Design"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-4f8dc28573913294","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMilAFBVV95cUxPbUFqby1LVjBYQjA4SWFvMlJpYkV3SGVJd0RwdC04YkFJbHlWb1VNQWhhVkJlTGlSbDQ2ZG1yM0xlcGZOZXhOTlNjTVlnRUYzemZ5QkZ2M19URDZjTml0YU1RQ2dqZllxRFZLanlSVXduVHY2cHhmVHhaSjlKTmtVdktXZ2J3QnFlX3RmTmdKbXlRNEJB?oc=5","published_at":"2023-07-14T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Rockwell Automation, Honeywell warned of critical vulnerabilities in industrial products&nbsp;&nbsp;cybersecuritydive.com","title":"Rockwell Automation, Honeywell warned of critical vulnerabilities in industrial products - cybersecuritydive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-d1ab433b6714d278","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMijgJBVV95cUxOUmtPUkdCUjdWLXpNNzZINkFHd0NvZmxNdDRJN3RYWElLZ09mRlBWcGRDbHQ4WTlmaW4talFkTU93Nkk1LUhVcEhhNHBQR2RhYVpjdm1ZOWdYSjl0SXJXdEtRRXBuOGJNeTNCRTNkTEVXUElLbzh0SGxuMHhaYjZiZFhsakFDMHRJbTBCa3RtWUZINFpxSm1NV3VUQS1JRVp4X2VhcVpKcE5pMlZ5blI3a1JycW5UUWFEYTRHbWN5X19CcWF5MlotRXgwNXZKWlB1d3dsdW9paHVFd2toQ0ktTHNlU01OWTktWW51bE80Y0tJY0VNNjRob25UZnZJYmRGVkxKcW1zMFE2VThqLWc?oc=5","published_at":"2023-07-14T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell Automation\u2019s AB Micro850 and Micro870 PLC Systems Provide Connectivity, Design Efficiency&nbsp;&nbsp;machinedesign.com","title":"Rockwell Automation\u2019s AB Micro850 and Micro870 PLC Systems Provide Connectivity, Design Efficiency - machinedesign.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-45fc7b7f83e96d05","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMitwFBVV95cUxPc2NJNEpTb3pITEFFdW9vZEE5Tzg5QnI1WE03ZGY3OWhHa2E0b3ZBWUd2T3JOU1NzN0Z2RFJQOHZHOGd4LU1wTWhDaHd1Nm9KdXVkQ3I2cXlrVVNzRGtuWWpveE1yTFpGMklVZXNDZUpwc1Ficl9tRjdvd2tsdDRMaVFRNFRkSGhodEstaGh5NnEyVlpudUZSdXFFN2szQU9PbF9YVG1Fc0xyYjQ4b1VuMTltenQ1UWPSAbwBQVVfeXFMUG8xX2llMTN3N0hxc2wxLWZ5VWU0WUVTZjNNeU5jUkhOOTRQTUpwNzhxSTJuLUVIc21tNEVTbTJ6VHJyWWlKM2xMNUJlSld6WmJRYmtSQ1QtZHREVnB2MHNPRnZ5N2MzUVdtYUdES3gwb1NIWDRhdGxEcENCbDdoeFZwSXRQV1hfemVUejNJUXpmNHNxWm9XYmFIdjFEc2ttYnA3ZC05WFJRY2JhLU1HQ2tCVUp4NFdsQkYteVQ?oc=5","published_at":"2023-07-13T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"APT Exploit Targeting Rockwell Automation Flaws Threatens Critical Infrastructure&nbsp;&nbsp;securityweek.com","title":"APT Exploit Targeting Rockwell Automation Flaws Threatens Critical Infrastructure - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-ae962146bb68d9dc","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxOX1d5bnN5TUR1a3Z3dGtGTFh3cW0xMGtGb0k4V3BMUXNWakhkc3M5UUZnUC1kV3VKS0dyeTUxZlVobC0xdnlmckRCMnhRbExQX19lYmFWSHF4SzhfazM4enc4ZnRRbE11NU85cl9YMjNjSDdYem5YRUpLeU1WUWliYWNB?oc=5","published_at":"2023-07-13T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell Automation ControlLogix Bugs Expose Industrial Systems to Remote Attacks&nbsp;&nbsp;The Hacker News","title":"Rockwell Automation ControlLogix Bugs Expose Industrial Systems to Remote Attacks - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-fd745e072da7ba99","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxOX1d5bnN5TUR1a3Z3dGtGTFh3cW0xMGtGb0k4V3BMUXNWakhkc3M5UUZnUC1kV3VKS0dyeTUxZlVobC0xdnlmckRCMnhRbExQX19lYmFWSHF4SzhfazM4enc4ZnRRbE11NU85cl9YMjNjSDdYem5YRUpLeU1WUWliYWNB?oc=5","published_at":"2023-07-13T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Rockwell Automation ControlLogix Bugs Expose Industrial Systems to Remote Attacks&nbsp;&nbsp;thehackernews.com","title":"Rockwell Automation ControlLogix Bugs Expose Industrial Systems to Remote Attacks - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-18604b37171eaae7","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMitwFBVV95cUxPc2NJNEpTb3pITEFFdW9vZEE5Tzg5QnI1WE03ZGY3OWhHa2E0b3ZBWUd2T3JOU1NzN0Z2RFJQOHZHOGd4LU1wTWhDaHd1Nm9KdXVkQ3I2cXlrVVNzRGtuWWpveE1yTFpGMklVZXNDZUpwc1Ficl9tRjdvd2tsdDRMaVFRNFRkSGhodEstaGh5NnEyVlpudUZSdXFFN2szQU9PbF9YVG1Fc0xyYjQ4b1VuMTltenQ1UWPSAbwBQVVfeXFMUG8xX2llMTN3N0hxc2wxLWZ5VWU0WUVTZjNNeU5jUkhOOTRQTUpwNzhxSTJuLUVIc21tNEVTbTJ6VHJyWWlKM2xMNUJlSld6WmJRYmtSQ1QtZHREVnB2MHNPRnZ5N2MzUVdtYUdES3gwb1NIWDRhdGxEcENCbDdoeFZwSXRQV1hfemVUejNJUXpmNHNxWm9XYmFIdjFEc2ttYnA3ZC05WFJRY2JhLU1HQ2tCVUp4NFdsQkYteVQ?oc=5","published_at":"2023-07-13T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"APT Exploit Targeting Rockwell Automation Flaws Threatens Critical Infrastructure&nbsp;&nbsp;SecurityWeek","title":"APT Exploit Targeting Rockwell Automation Flaws Threatens Critical Infrastructure - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-24759e4856df6c66","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi-wFBVV95cUxQQUkwYkwtUE9vMHZGemJPRENJUWlxOWxxVUNQcm56TGFtYkF1T01TX1hfUmlrbnJLamxFWlQ0Y3hUaV9jV3lzRFY2Nms5VmIyMXNpQ2xsaWxRYnpLZmR6aUlPOWpBRzhFMGcyc3hFN1dHdGRsa1lxWnNXcEJsVzd5TDFDT00zTFVqT0VDN1h0S1cydlgyVUJnSUVYOG10dnVNZm0wbF9uRjRTTWxEcmNvZXVoOUdsWXdRTXUzMGVhQ0lmR1Y2R3VmWm5MVER2VUJ2bWxiRnNrQWpCUW9HdVpDaThrZkVkU1BZLWRWTnhKX05veVEtUjRpa21ZWQ?oc=5","published_at":"2023-07-13T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Rockwell reveals ControlLogix vulnerabilities affect communication modules deployed across critical infrastructure&nbsp;&nbsp;industrialcyber.co","title":"Rockwell reveals ControlLogix vulnerabilities affect communication modules deployed across critical infrastructure - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-cf2a3a23e6ef668e","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxPbDNQamI4ZU1qdHFod2FqTG9xTzBwUzBrVzRCMzcybU1wbmdrcEx5UFFkSTNVSXRVcFdiUHExUU8zZkp2NHJ3dXFQVy0wTkJQaVM1aWJUMW5YTU14RGdRUHR2OVFtQzlHNkpCYTVvdW00Y1M3TUttRl9rellOZHBiUGZ6aHJRbTFFaVRhaWRNeC1JWHR5N01BZVRXdGQ0cUxzaEt6OXlrVXM?oc=5","published_at":"2023-07-13T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Critical RCE Bug in Rockwell Automation PLCs Zaps Industrial Sites&nbsp;&nbsp;Dark Reading","title":"Critical RCE Bug in Rockwell Automation PLCs Zaps Industrial Sites - Dark Reading"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-1054dbd710deb5ef","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMi-wFBVV95cUxQQUkwYkwtUE9vMHZGemJPRENJUWlxOWxxVUNQcm56TGFtYkF1T01TX1hfUmlrbnJLamxFWlQ0Y3hUaV9jV3lzRFY2Nms5VmIyMXNpQ2xsaWxRYnpLZmR6aUlPOWpBRzhFMGcyc3hFN1dHdGRsa1lxWnNXcEJsVzd5TDFDT00zTFVqT0VDN1h0S1cydlgyVUJnSUVYOG10dnVNZm0wbF9uRjRTTWxEcmNvZXVoOUdsWXdRTXUzMGVhQ0lmR1Y2R3VmWm5MVER2VUJ2bWxiRnNrQWpCUW9HdVpDaThrZkVkU1BZLWRWTnhKX05veVEtUjRpa21ZWQ?oc=5","published_at":"2023-07-13T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Rockwell reveals ControlLogix vulnerabilities affect communication modules deployed across critical infrastructure&nbsp;&nbsp;Industrial Cyber","title":"Rockwell reveals ControlLogix vulnerabilities affect communication modules deployed across critical infrastructure - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-bc40084e19b11d0c","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMibEFVX3lxTE1ZZ3gtaldlOHlRZ05PR1YtV2lob0JoSkxGdGNza1phNi0ycm5xOWY2MGpqdnpCOUVKSnd3emZsUk9IWlVTUnAwbzlwVmNZU0hPTjJNN0ZmQUhpQ0YtSDdoRm9uYTAwMEVmSWV3UQ?oc=5","published_at":"2023-07-12T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA warns of dangerous Rockwell industrial bug being exploited by gov\u2019t group&nbsp;&nbsp;therecord.media","title":"CISA warns of dangerous Rockwell industrial bug being exploited by gov\u2019t group - therecord.media"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-178470d47e18314b","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMibEFVX3lxTE1ZZ3gtaldlOHlRZ05PR1YtV2lob0JoSkxGdGNza1phNi0ycm5xOWY2MGpqdnpCOUVKSnd3emZsUk9IWlVTUnAwbzlwVmNZU0hPTjJNN0ZmQUhpQ0YtSDdoRm9uYTAwMEVmSWV3UQ?oc=5","published_at":"2023-07-12T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"CISA warns of dangerous Rockwell industrial bug being exploited by gov\u2019t group&nbsp;&nbsp;The Record from Recorded Future News","title":"CISA warns of dangerous Rockwell industrial bug being exploited by gov\u2019t group - The Record from Recorded Future News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-bd335b69dc1575e9","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE9ZNURpVzlvZnZacWlEUVBseGUtR3BmcTQxYnBqSWJsVVZnYkR3T0djY3d6TlZ5ckdZdlhwQm1TQWdONHBhRkt1bWx5eWpUQjlzaHZiQzY5bF96R2J2X2Mw?oc=5","published_at":"2023-06-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Vulnerability of blue foods to human-induced environmental change&nbsp;&nbsp;Nature","title":"Vulnerability of blue foods to human-induced environmental change - Nature"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c4fd782ba474c6fd","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE9ZNURpVzlvZnZacWlEUVBseGUtR3BmcTQxYnBqSWJsVVZnYkR3T0djY3d6TlZ5ckdZdlhwQm1TQWdONHBhRkt1bWx5eWpUQjlzaHZiQzY5bF96R2J2X2Mw?oc=5","published_at":"2023-06-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Vulnerability of blue foods to human-induced environmental change&nbsp;&nbsp;nature.com","title":"Vulnerability of blue foods to human-induced environmental change - nature.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-86205923b210e9e4","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxQTWVwZGozSG9FWEhfSDA5ejNzUVlmSndmYjd4Z2dBUTN0MEI5Vm8yRkJZdWFOclV5eTZFMzVWaWZhVnFuRFM4SUN5enIxTGVRU2w4UG9jSlppaGxDUUoxVElYSTVhRVhHRlNROE5US3JrX1BabHpNLWREeUpmN25WbXNB?oc=5","published_at":"2023-05-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"New COSMICENERGY Malware Exploits ICS Protocol to Sabotage Power Grids&nbsp;&nbsp;thehackernews.com","title":"New COSMICENERGY Malware Exploits ICS Protocol to Sabotage Power Grids - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a9632a30afaf0f52","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxQTWVwZGozSG9FWEhfSDA5ejNzUVlmSndmYjd4Z2dBUTN0MEI5Vm8yRkJZdWFOclV5eTZFMzVWaWZhVnFuRFM4SUN5enIxTGVRU2w4UG9jSlppaGxDUUoxVElYSTVhRVhHRlNROE5US3JrX1BabHpNLWREeUpmN25WbXNB?oc=5","published_at":"2023-05-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"New COSMICENERGY Malware Exploits ICS Protocol to Sabotage Power Grids&nbsp;&nbsp;The Hacker News","title":"New COSMICENERGY Malware Exploits ICS Protocol to Sabotage Power Grids - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4d5d7529645daea4","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMidkFVX3lxTE1mYzYwWGhNQjl5aGg2Sm1oeUFOOTZCa19kMVNfZDBMZmZiYXBZTmdEcHR4YVdaZFJteGZxTWZUQWNockhnaVB3emVKcDJ6UGg5OXBQWjNmZjlRenJ2MXgzX29BLW16ZzFZNTVnSXpxbldMTU4wT2c?oc=5","published_at":"2023-05-24T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Critical Infra & APTs","summary":"People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection&nbsp;&nbsp;CISA (.gov)","title":"People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection - CISA (.gov)"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-5105bb2e88cafd7e","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMi2AFBVV95cUxNczdCTUo1azRVUldpajd4Mk1fLWduU0JLbDZGdGtsNTR1Y1l5WW9uMC01cnhqQ2Jhay04RjQtNVk0LXN1VVQ5MllYdldBOEQ4TDJVUEJSSlVfaG1LSVJFX0t5Zzh6ekNZeVFnWEhWZGhqMlV2YkEzQnlCa3N6S3AyajRkSkZ4X2NiTG93Snk0a2JLOWwwZy1EdnFBcko0bXRRZEZLdHRQX25JajRpMVFJVEV3VGFnY1BZTGpqT1U3Zlg4OGc2b0xpVy1BMGJRTHM5bHV2akJvZy0?oc=5","published_at":"2023-05-24T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"Critical Infra & APTs","summary":"Volt Typhoon targets US critical infrastructure with living-off-the-land techniques&nbsp;&nbsp;Microsoft","title":"Volt Typhoon targets US critical infrastructure with living-off-the-land techniques - Microsoft"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-67da1a81b5a16c2f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitgFBVV95cUxQd1BsUzF5ZE8xdUd5TTVFSzB0WVNsNFp0M1c3VW9iWFVSeUtmRTZkR1JBeTNvRDZGNjNMcEs0aUhTMFpLcVRHS0kzNjgxR1pMZm5BRldEQVJwaXRZek5vaUw1REpaOXA2cF9LSnJOUzNyXzhReWw5MXVGYVNZTEczd1pFajByZWFPeFhRSXNTcjhVc3RYMnBuc3IyTjlQMHdoR0NxNjNuamlSdzFqdkJISi01RWNrUdIBuwFBVV95cUxOUXd4WW9xT0p5V0hKOE5wN3NrY0xjSG5fclpWaGliNWJIYm9pc3cxRzh6VXpucmswUzljQmRTLW9DckF5dkdwZ3A5WE1fY0lxU1RGWmhITGVqZXEzRmlKOWtIS3pRTjNyNHpCVmlBQ3B2Nzl1NzVmUUZtWmZvMVFKYVB1R3U5dTMzMXRmQk1ZQm5MOHA2N05Zb2J0ZzJPU2NHQ0lZWXE3SVNkanB2RUtKbUpSREpnUTN2Tktr?oc=5","published_at":"2023-05-16T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Teltonika Vulnerabilities Could Expose Thousands of Industrial Organizations to Remote Attacks&nbsp;&nbsp;securityweek.com","title":"Teltonika Vulnerabilities Could Expose Thousands of Industrial Organizations to Remote Attacks - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4bdf2e46de931355","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitgFBVV95cUxQd1BsUzF5ZE8xdUd5TTVFSzB0WVNsNFp0M1c3VW9iWFVSeUtmRTZkR1JBeTNvRDZGNjNMcEs0aUhTMFpLcVRHS0kzNjgxR1pMZm5BRldEQVJwaXRZek5vaUw1REpaOXA2cF9LSnJOUzNyXzhReWw5MXVGYVNZTEczd1pFajByZWFPeFhRSXNTcjhVc3RYMnBuc3IyTjlQMHdoR0NxNjNuamlSdzFqdkJISi01RWNrUdIBuwFBVV95cUxOUXd4WW9xT0p5V0hKOE5wN3NrY0xjSG5fclpWaGliNWJIYm9pc3cxRzh6VXpucmswUzljQmRTLW9DckF5dkdwZ3A5WE1fY0lxU1RGWmhITGVqZXEzRmlKOWtIS3pRTjNyNHpCVmlBQ3B2Nzl1NzVmUUZtWmZvMVFKYVB1R3U5dTMzMXRmQk1ZQm5MOHA2N05Zb2J0ZzJPU2NHQ0lZWXE3SVNkanB2RUtKbUpSREpnUTN2Tktr?oc=5","published_at":"2023-05-16T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Teltonika Vulnerabilities Could Expose Thousands of Industrial Organizations to Remote Attacks&nbsp;&nbsp;SecurityWeek","title":"Teltonika Vulnerabilities Could Expose Thousands of Industrial Organizations to Remote Attacks - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-25a7a1a398932218","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxNSzhBN2xTaGMyREJldTR5X1IwSkVrUUZzMFpyWGtlVFQyWmIyZmRGa1dJV0NfMEtMc3pTUjdiRHBYQWhuTl9rdVRlb2FBVEEyUlQ1MGtfcFZiS2lrc2h4VVY4VlJ1S1dVX2xhN29vTEpIbFFnLVJPSExOandUNzRjTTlDWnVDY3d3Y1NNQl9teVdBOXFlY1MxakNfTHJHMmc3aGJratIBqgFBVV95cUxNek1mSjNnMFN2RTRuUTRCZGRIVDFJTnkzb1NMUnRYSTAtU1RSdThjVGhyaC1UbzYtV0Yta1pSSmtocXFERzhBSVktbWZ5RWlhTGpBd090bnVzSkg1YnJzUDllUlF1OEZqYXItdVV1UTFmd1VlQ2V4djRUaGtORXotSW9mN2s3SHVsY2g0ZFhSMl81R09wa1pyc3k2WlY2NnJUR0xhSkdoNUYtdw?oc=5","published_at":"2023-05-09T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Building Automation System Exploit Brings KNX Security Back in Spotlight&nbsp;&nbsp;SecurityWeek","title":"Building Automation System Exploit Brings KNX Security Back in Spotlight - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a190c8e66f7ae81d","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxNSzhBN2xTaGMyREJldTR5X1IwSkVrUUZzMFpyWGtlVFQyWmIyZmRGa1dJV0NfMEtMc3pTUjdiRHBYQWhuTl9rdVRlb2FBVEEyUlQ1MGtfcFZiS2lrc2h4VVY4VlJ1S1dVX2xhN29vTEpIbFFnLVJPSExOandUNzRjTTlDWnVDY3d3Y1NNQl9teVdBOXFlY1MxakNfTHJHMmc3aGJratIBqgFBVV95cUxNek1mSjNnMFN2RTRuUTRCZGRIVDFJTnkzb1NMUnRYSTAtU1RSdThjVGhyaC1UbzYtV0Yta1pSSmtocXFERzhBSVktbWZ5RWlhTGpBd090bnVzSkg1YnJzUDllUlF1OEZqYXItdVV1UTFmd1VlQ2V4djRUaGtORXotSW9mN2s3SHVsY2g0ZFhSMl81R09wa1pyc3k2WlY2NnJUR0xhSkdoNUYtdw?oc=5","published_at":"2023-05-09T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Building Automation System Exploit Brings KNX Security Back in Spotlight&nbsp;&nbsp;securityweek.com","title":"Building Automation System Exploit Brings KNX Security Back in Spotlight - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c5b74129bc3a415c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE5RaGt2ZExFT0pFMmMyRGlnbUNuY0hqWGZfdXIyUlNkZmFrN0NHdURVOUFjRzVrTVdVblpKY0w5VjRfcnlxVUxjQ1FzWE9RRnpJTUNnbTlrbTJ1TnoyX3VN?oc=5","published_at":"2023-04-12T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Assessing ecosystem vulnerability under severe uncertainty of global climate change&nbsp;&nbsp;Nature","title":"Assessing ecosystem vulnerability under severe uncertainty of global climate change - Nature"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1a3b59e4a804965c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE5RaGt2ZExFT0pFMmMyRGlnbUNuY0hqWGZfdXIyUlNkZmFrN0NHdURVOUFjRzVrTVdVblpKY0w5VjRfcnlxVUxjQ1FzWE9RRnpJTUNnbTlrbTJ1TnoyX3VN?oc=5","published_at":"2023-04-12T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Assessing ecosystem vulnerability under severe uncertainty of global climate change&nbsp;&nbsp;nature.com","title":"Assessing ecosystem vulnerability under severe uncertainty of global climate change - nature.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-2cb4bbbf0b622dfe","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMivAFBVV95cUxPMVB3U09XYnp6ajQ3aUVtSUhXYTVpSWtiVzg0RHNkWERMbFd5QjhMR0h3RFdHanVZZEtfZnNTRGJsWnJpVS1LZFU5WHg4ay1jTWkxOUg2WEJUR2tYVGV3NjFwQnpVdkluNElhYTlsdVFfeDRSZ1NpaXplaHBWZEFVa3I0TXRSd29JU2lrZFc4ZUlQWTYyRVZMaFFRZlRTa2JQUTJCcVl6aFVqS3hzUVJiUE82VDhCcVdBenUtVdIBwgFBVV95cUxNQzZLdG55cWVhMXM0SUdEU1JNOXM4c2FMa2lyUExUbXN1Z3ViVTNua0lSeHdZbVhDbzNkTG9CY0NlV1FmTEhLYkdOa1NvVERXdTFvSFB5VG1IcWVvVi0zVWxrQ203MEJYQWo3VGliaV9xMTVNeF9ucERyczBaRmM3V1Y1NDA4WTRDVXh6X084SFU5TFBvWHNMNlhoWXVtZWpiMUZ4V2dHbzRPekFFWmFZbG4zUkc5d0YzSlE4dW96THJ1Zw?oc=5","published_at":"2023-03-21T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Organizations Notified of Remotely Exploitable Vulnerabilities in Aveva HMI, SCADA Products&nbsp;&nbsp;SecurityWeek","title":"Organizations Notified of Remotely Exploitable Vulnerabilities in Aveva HMI, SCADA Products - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-46ed05744398db0a","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE9CY2VwQzdOVlV2THNTWEgzQ3hBUUY4N0FqaE5iQU1tVWNhWTdtRkw5eW9heWxOeE05Zmw3WGRTeEJDNmtXQ2ZsSXRfdXlKVXdtNk1hZzZKNDZDTFNzX1dV?oc=5","published_at":"2023-01-30T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Natural hybridization reduces vulnerability to climate change&nbsp;&nbsp;nature.com","title":"Natural hybridization reduces vulnerability to climate change - nature.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-50c95897a74ececf","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE9CY2VwQzdOVlV2THNTWEgzQ3hBUUY4N0FqaE5iQU1tVWNhWTdtRkw5eW9heWxOeE05Zmw3WGRTeEJDNmtXQ2ZsSXRfdXlKVXdtNk1hZzZKNDZDTFNzX1dV?oc=5","published_at":"2023-01-30T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Natural hybridization reduces vulnerability to climate change&nbsp;&nbsp;Nature","title":"Natural hybridization reduces vulnerability to climate change - Nature"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-79a97b9c27f50a5f","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE1DVkZWMGpKNVVUUGI1WWFaV1ZaeTFDNDFmWXgwM3dOUFZnR2RfUE1LY3paMDF2Z1hOcXNuV0ludFl0YThRLWYzb1BPekJEMzl3dUtBZ0h4TVloMU90RmRF?oc=5","published_at":"2023-01-04T08:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"The cortisol switch between vulnerability and resilience - Molecular Psychiatry&nbsp;&nbsp;Nature","title":"The cortisol switch between vulnerability and resilience - Molecular Psychiatry - Nature"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-d64e9b37bd4f6b3e","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE1DVkZWMGpKNVVUUGI1WWFaV1ZaeTFDNDFmWXgwM3dOUFZnR2RfUE1LY3paMDF2Z1hOcXNuV0ludFl0YThRLWYzb1BPekJEMzl3dUtBZ0h4TVloMU90RmRF?oc=5","published_at":"2023-01-04T08:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"The cortisol switch between vulnerability and resilience - Molecular Psychiatry&nbsp;&nbsp;nature.com","title":"The cortisol switch between vulnerability and resilience - Molecular Psychiatry - nature.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6bba847efd88ba1c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE4zUVRVNERtRDZGWUYzVmU0dVRHZlRwb29BZU5lSzMtYkZJRDRRUlRmMmR1ak5WVmxKRjdMNGVIVTBHbzBzN1Q2RFBKdGgwUVlad0dRWjMzQmFQNWhUZVlV?oc=5","published_at":"2022-10-17T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Ecological sensitivity and vulnerability of fishing fleet landings to climate change across regions&nbsp;&nbsp;Nature","title":"Ecological sensitivity and vulnerability of fishing fleet landings to climate change across regions - Nature"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8e87bf1e6bd6f794","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE4zUVRVNERtRDZGWUYzVmU0dVRHZlRwb29BZU5lSzMtYkZJRDRRUlRmMmR1ak5WVmxKRjdMNGVIVTBHbzBzN1Q2RFBKdGgwUVlad0dRWjMzQmFQNWhUZVlV?oc=5","published_at":"2022-10-17T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Ecological sensitivity and vulnerability of fishing fleet landings to climate change across regions&nbsp;&nbsp;nature.com","title":"Ecological sensitivity and vulnerability of fishing fleet landings to climate change across regions - nature.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9c874142e953c393","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxNRTFhWXBwTElWdTN2SlBUQUNSbUNjVTJIOURXWW9XYWEwLWFmbVljMGFLTm1IYWtGV0U4Z3ZKYmdHdTRLYXBkOXVFVzJsMEZ4YkJoRklMVjhIUDJqeDBTcFp4a1BpLWg0ZUJCWVplYmw4UFZKY21TeFA3Qm5IM0I5QXc5YjNaUVlIdnRoaVp0MmxzdGdiVG9sUXNIOTBOczNEelRtRNIBqgFBVV95cUxNOThvWkt3bWxWNHo5TFNJaXN5OGpNRi1iNEo5RW9aUWd3cmlUTU9OSWlTRXlhUUZYWnZUU0hxRWZBNDY3M2l0cnVvU05nN0g1Y1JoM09fYVM3NGNQQzFXV2JIU1BUMVg1c0pYYkhPY1dSM3N2ZGlGNE4wZHI2T0ZaeS16WU1tdkd6djRDMnpwVDlZY0RZUHZHMm1Wa0VBZTR6eDVEeXI3MFp3UQ?oc=5","published_at":"2022-10-04T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Critical Vulnerabilities Expose Parking Management System to Hacker Attacks&nbsp;&nbsp;securityweek.com","title":"Critical Vulnerabilities Expose Parking Management System to Hacker Attacks - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-bc851c4ee6b613e9","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipAFBVV95cUxNRTFhWXBwTElWdTN2SlBUQUNSbUNjVTJIOURXWW9XYWEwLWFmbVljMGFLTm1IYWtGV0U4Z3ZKYmdHdTRLYXBkOXVFVzJsMEZ4YkJoRklMVjhIUDJqeDBTcFp4a1BpLWg0ZUJCWVplYmw4UFZKY21TeFA3Qm5IM0I5QXc5YjNaUVlIdnRoaVp0MmxzdGdiVG9sUXNIOTBOczNEelRtRNIBqgFBVV95cUxNOThvWkt3bWxWNHo5TFNJaXN5OGpNRi1iNEo5RW9aUWd3cmlUTU9OSWlTRXlhUUZYWnZUU0hxRWZBNDY3M2l0cnVvU05nN0g1Y1JoM09fYVM3NGNQQzFXV2JIU1BUMVg1c0pYYkhPY1dSM3N2ZGlGNE4wZHI2T0ZaeS16WU1tdkd6djRDMnpwVDlZY0RZUHZHMm1Wa0VBZTR6eDVEeXI3MFp3UQ?oc=5","published_at":"2022-10-04T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Critical Vulnerabilities Expose Parking Management System to Hacker Attacks&nbsp;&nbsp;SecurityWeek","title":"Critical Vulnerabilities Expose Parking Management System to Hacker Attacks - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-9d8ed0f74bdcc59a","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiwwFBVV95cUxQMGN5bm9LN0U5YU5iRms0ckM5elJSak5xeVhhYXo3QzlFYk5BQVpZX21Ccmx5TFRoTGFlSVRCWUd5Q3NVR1lwcWw3VndQZ3JDSUt4dFFmVmZKcW9ISk9iYi1iczNUZGZORFBlZGgtNWNiYkxSUm0yclB1aDRqa1pUdjdFVVpOQ2hzejZES2FicDNsQWw4THlWdzcwM3NBVzNJczIzOExDLVNNZklpQ0tSMldrd0RuUTV6WVFQempNOW10X0k?oc=5","published_at":"2022-08-12T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"SCADAfence detects vulnerabilities in Alerton BMS devices, calls for isolation of OT networks&nbsp;&nbsp;industrialcyber.co","title":"SCADAfence detects vulnerabilities in Alerton BMS devices, calls for isolation of OT networks - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-69a145f1b9cf6c93","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiwwFBVV95cUxQMGN5bm9LN0U5YU5iRms0ckM5elJSak5xeVhhYXo3QzlFYk5BQVpZX21Ccmx5TFRoTGFlSVRCWUd5Q3NVR1lwcWw3VndQZ3JDSUt4dFFmVmZKcW9ISk9iYi1iczNUZGZORFBlZGgtNWNiYkxSUm0yclB1aDRqa1pUdjdFVVpOQ2hzejZES2FicDNsQWw4THlWdzcwM3NBVzNJczIzOExDLVNNZklpQ0tSMldrd0RuUTV6WVFQempNOW10X0k?oc=5","published_at":"2022-08-12T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"SCADAfence detects vulnerabilities in Alerton BMS devices, calls for isolation of OT networks&nbsp;&nbsp;Industrial Cyber","title":"SCADAfence detects vulnerabilities in Alerton BMS devices, calls for isolation of OT networks - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e1244a72fe7524f9","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxQTEFUMVhjUGFObjc5TVBKeWl6QlVUVFBkYk5WN2NEN3ZPTUtNTk5uSXJLUTZXUkJjNWpFRGpfMEEyUEFOUTdqSFBjQ0F0YWcwS2w0clBZUXJ4WXhCcDN5bXVtZWU4S3lSaGtmVVFmZWFMc3NWd0l5S2Q2VV90X0NEV05NQkdLZ3FEdzJIbjNjVmp5d0RlMDA1M1RtT1NscU9abGtmOVBlQklJSGs2cTNTb9IBtgFBVV95cUxQOUt3REwxUmpFcVhGRnBjNEc5ZEJaWjdnSlktS2RlTUdoZkl1UXhZUHRJbkxJcnVVSDg4bHFKRWVYTlBjQjVxckFlMG40c29pYXF5alhKY2Q5dlBWQ21RbTRNYmFWelY1U1poZGdUQzhtS3BrSzNTSF9hbk9ibWhmak1OazZYTk43WmNIQWYxUVItNG8zQ2JZeVFKWWc3bzJ0TDdQMWVXYUdyUUdwVzRwOE9zUldWQQ?oc=5","published_at":"2022-08-11T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"OT Security Firm Warns of Safety Risks Posed by Alerton Building System Vulnerabilities&nbsp;&nbsp;securityweek.com","title":"OT Security Firm Warns of Safety Risks Posed by Alerton Building System Vulnerabilities - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ddedfd44f63f3c73","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxQTEFUMVhjUGFObjc5TVBKeWl6QlVUVFBkYk5WN2NEN3ZPTUtNTk5uSXJLUTZXUkJjNWpFRGpfMEEyUEFOUTdqSFBjQ0F0YWcwS2w0clBZUXJ4WXhCcDN5bXVtZWU4S3lSaGtmVVFmZWFMc3NWd0l5S2Q2VV90X0NEV05NQkdLZ3FEdzJIbjNjVmp5d0RlMDA1M1RtT1NscU9abGtmOVBlQklJSGs2cTNTb9IBtgFBVV95cUxQOUt3REwxUmpFcVhGRnBjNEc5ZEJaWjdnSlktS2RlTUdoZkl1UXhZUHRJbkxJcnVVSDg4bHFKRWVYTlBjQjVxckFlMG40c29pYXF5alhKY2Q5dlBWQ21RbTRNYmFWelY1U1poZGdUQzhtS3BrSzNTSF9hbk9ibWhmak1OazZYTk43WmNIQWYxUVItNG8zQ2JZeVFKWWc3bzJ0TDdQMWVXYUdyUUdwVzRwOE9zUldWQQ?oc=5","published_at":"2022-08-11T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"OT Security Firm Warns of Safety Risks Posed by Alerton Building System Vulnerabilities&nbsp;&nbsp;SecurityWeek","title":"OT Security Firm Warns of Safety Risks Posed by Alerton Building System Vulnerabilities - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c484fd21eccc371a","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMingFBVV95cUxPOWlYcmx5cUZnZ254VUtPbm5PV2RHWk9HVHcwTy1jc2NVVVlZaDN3TnEwYktGc1Q0aVlFVUNiU080cG4weEZQZEhaVTJTZWFpV3dmVXVuODBfVnBRaVN1cllFRzVTaFhRTVhmREdCVWtNbG82Ukx1aWlOMURwSmlBYWljR3g0U01CZzZqWUQ3Y2xNa2ZJdVFnSW5JY1o1Zw?oc=5","published_at":"2022-08-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Stegomalware Surge \u2013 Attackers Using File, Video, Image & Others To Hide Malware&nbsp;&nbsp;gbhackers.com","title":"Stegomalware Surge \u2013 Attackers Using File, Video, Image & Others To Hide Malware - gbhackers.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b6017286f936fc4f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE1mTWJsdFRKdWdYQktkMEhjSjJXdU5sQ3NYaVI5STVhYlNoQ29rZEhxWTczYWRxcmxTcGxRZ1lZdzMzN1N5U28wQWdqNlZtOV83LVRSX1NTeFRicEhnVkY0?oc=5","published_at":"2022-07-29T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Tackling Africa\u2019s climate change vulnerability through resilient crops&nbsp;&nbsp;Nature","title":"Tackling Africa\u2019s climate change vulnerability through resilient crops - Nature"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-23b8c00a8d665007","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE1mTWJsdFRKdWdYQktkMEhjSjJXdU5sQ3NYaVI5STVhYlNoQ29rZEhxWTczYWRxcmxTcGxRZ1lZdzMzN1N5U28wQWdqNlZtOV83LVRSX1NTeFRicEhnVkY0?oc=5","published_at":"2022-07-29T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Tackling Africa\u2019s climate change vulnerability through resilient crops&nbsp;&nbsp;nature.com","title":"Tackling Africa\u2019s climate change vulnerability through resilient crops - nature.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-662c08280d5638ed","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiyAFBVV95cUxOMEthTTd6SjhLbWc1ZEZ5Y2hhQVc0S1Y1NTRwVzNxY2htSFFDRGVNakxDeFN3UU0tdllKdGtSRGgtcHJtVW0zS1FZblg3SE1IUDJUUV91NXlvMjlldEFJaWpqUzRTY20xZ2dkV0NXRE9ST3QtYnIxYzQ0R2ZqVURHTjhIQXNaVGNvN3h1UlBqTVk2MmdxRVc0Rk9odWI5bXFIWUN6UmpFeVJXRm01czhiMVlwVWdkcDk5c2NsdFV3NXo1c2U2djR5aQ?oc=5","published_at":"2022-07-17T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Building ICS cyberdefenses using NIST guidelines, Purdue Model, IEC 62443 standards&nbsp;&nbsp;industrialcyber.co","title":"Building ICS cyberdefenses using NIST guidelines, Purdue Model, IEC 62443 standards - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-044fc7c027ec2b0c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiyAFBVV95cUxOMEthTTd6SjhLbWc1ZEZ5Y2hhQVc0S1Y1NTRwVzNxY2htSFFDRGVNakxDeFN3UU0tdllKdGtSRGgtcHJtVW0zS1FZblg3SE1IUDJUUV91NXlvMjlldEFJaWpqUzRTY20xZ2dkV0NXRE9ST3QtYnIxYzQ0R2ZqVURHTjhIQXNaVGNvN3h1UlBqTVk2MmdxRVc0Rk9odWI5bXFIWUN6UmpFeVJXRm01czhiMVlwVWdkcDk5c2NsdFV3NXo1c2U2djR5aQ?oc=5","published_at":"2022-07-17T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Building ICS cyberdefenses using NIST guidelines, Purdue Model, IEC 62443 standards&nbsp;&nbsp;Industrial Cyber","title":"Building ICS cyberdefenses using NIST guidelines, Purdue Model, IEC 62443 standards - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-22da4414b7eab854","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi6AFBVV95cUxOVUY5MU5velRPUFZOQXo5RTI1eno3V3pmRjlrakVPQ2dObHdkcVdVei02b3ZHQ3pXeEk0UWhrWGhJbHNLZE9XRnZYU2JXMTNpZGY1eDN3NWJSbG9acmphaEd4WWxzM0NsLUtnWTJxWkFzUk1ucUh5X3BRb1h4MldvRmZqQkltQzNVQWd0WURjWXYwTm9zcklWQ2VGLTVkRjFXeEtsN1pKNWFCbWJiQWFYUVNnX1ZQcER3dkE1MktPS0xpd3psRzhVMWFtRU16SEdnbFp1eVNQRmltWERNbjVaN3pNS1E0WmF4?oc=5","published_at":"2022-07-05T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"Chinese hackers breach ProxyLogon flaws across building automation systems in Asian organizations&nbsp;&nbsp;industrialcyber.co","title":"Chinese hackers breach ProxyLogon flaws across building automation systems in Asian organizations - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ec25c1353b2ce410","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi6AFBVV95cUxOVUY5MU5velRPUFZOQXo5RTI1eno3V3pmRjlrakVPQ2dObHdkcVdVei02b3ZHQ3pXeEk0UWhrWGhJbHNLZE9XRnZYU2JXMTNpZGY1eDN3NWJSbG9acmphaEd4WWxzM0NsLUtnWTJxWkFzUk1ucUh5X3BRb1h4MldvRmZqQkltQzNVQWd0WURjWXYwTm9zcklWQ2VGLTVkRjFXeEtsN1pKNWFCbWJiQWFYUVNnX1ZQcER3dkE1MktPS0xpd3psRzhVMWFtRU16SEdnbFp1eVNQRmltWERNbjVaN3pNS1E0WmF4?oc=5","published_at":"2022-07-05T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Building Automation & LoRaWAN","summary":"Chinese hackers breach ProxyLogon flaws across building automation systems in Asian organizations&nbsp;&nbsp;Industrial Cyber","title":"Chinese hackers breach ProxyLogon flaws across building automation systems in Asian organizations - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-f4ee0da4d8d5f0e6","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijAFBVV95cUxNbktpdjdsNkthd2lHWHBrcHViZU5TQmFvdnVBTUNNczR4Zm9kbWphS0o5MVgta0ZlN0NGZ1dhMXJGX0xvNmNDTS1GYTROdnNpSWh1TTAxQnBEVktPb3E3WEVaejZIdkpPNTEtazJHMEtlU2RYY0dlZ0pucjNOZHRVMzZjSEtrSjZlSWZwadIBkgFBVV95cUxPemlObmEta1FqMmN3cC1yU1diZVdtQnkxRno0NEZ4NU1WSDN6X2ZlRFdLMjBKa0tWazZ6bkN1LUNwN2h4OV8xTElMS1JBVWtDejNCdGg3RFpkRWJrMm9NdTloU0h3eGE1T0Zia1VvZnVUVUdLZ3pzd3M0czhfNmNFM2NRa1Y4RFo4MDgzWi10SV9VZw?oc=5","published_at":"2022-06-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"From Basecamp to Icefall: Secure by Design OT Makes Little Headway&nbsp;&nbsp;securityweek.com","title":"From Basecamp to Icefall: Secure by Design OT Makes Little Headway - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ac4975a7ba1e52e8","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMijAFBVV95cUxNbktpdjdsNkthd2lHWHBrcHViZU5TQmFvdnVBTUNNczR4Zm9kbWphS0o5MVgta0ZlN0NGZ1dhMXJGX0xvNmNDTS1GYTROdnNpSWh1TTAxQnBEVktPb3E3WEVaejZIdkpPNTEtazJHMEtlU2RYY0dlZ0pucjNOZHRVMzZjSEtrSjZlSWZwadIBkgFBVV95cUxPemlObmEta1FqMmN3cC1yU1diZVdtQnkxRno0NEZ4NU1WSDN6X2ZlRFdLMjBKa0tWazZ6bkN1LUNwN2h4OV8xTElMS1JBVWtDejNCdGg3RFpkRWJrMm9NdTloU0h3eGE1T0Zia1VvZnVUVUdLZ3pzd3M0czhfNmNFM2NRa1Y4RFo4MDgzWi10SV9VZw?oc=5","published_at":"2022-06-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"From Basecamp to Icefall: Secure by Design OT Makes Little Headway&nbsp;&nbsp;SecurityWeek","title":"From Basecamp to Icefall: Secure by Design OT Makes Little Headway - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-786a70d8fe34eefd","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimAFBVV95cUxObVlJV1lZeGFMVDNvSjl1OVpwX1FrS2xUaVE2cnJxMk91UlphZ3VXdHJrbHJEZG1Fa3JZR1V1YXRQYjNISXFiMTRoYUhuX0FMRS02aC1fUFRtTDFyUm01bEo3WWdUaDJ0WmViOGlva1VnOFF1dkdtSTBoTGNKMk5iNGpsTUVXa2V2eUhBMXRUZ1ktbG9fZDJJUg?oc=5","published_at":"2022-06-17T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Reevaluating Ecosystems on the Basis of Climate Change Vulnerability&nbsp;&nbsp;eos.org","title":"Reevaluating Ecosystems on the Basis of Climate Change Vulnerability - eos.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-3c4c1801f94f8190","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxQMXVMVi1pSE84NDJRczhIaHhSbGF5dlpjMy16MTVhZks0aGNmYzNPaGxCVEZzQkJkUmdveEk1blZTbEJPS1J2d0NocVliY2l2cHlYX005WHdPbnlETi0xdEpGUjhDd2xyclVyUk5OaFJuUG94RGhhX3pRMTVxTHBuaFB5SQ?oc=5","published_at":"2022-06-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Researchers Disclose Critical Flaws in Industrial Access Controllers from HID Mercury&nbsp;&nbsp;The Hacker News","title":"Researchers Disclose Critical Flaws in Industrial Access Controllers from HID Mercury - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8427ee32d2395cb7","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxQMXVMVi1pSE84NDJRczhIaHhSbGF5dlpjMy16MTVhZks0aGNmYzNPaGxCVEZzQkJkUmdveEk1blZTbEJPS1J2d0NocVliY2l2cHlYX005WHdPbnlETi0xdEpGUjhDd2xyclVyUk5OaFJuUG94RGhhX3pRMTVxTHBuaFB5SQ?oc=5","published_at":"2022-06-10T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Researchers Disclose Critical Flaws in Industrial Access Controllers from HID Mercury&nbsp;&nbsp;thehackernews.com","title":"Researchers Disclose Critical Flaws in Industrial Access Controllers from HID Mercury - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6dd9b08bfbee1cda","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxPSUhqaXBDTi1YLXBIa3FfSDJSZjNJeTRHSzVMU2ZPeHNmNlVRTThoS2ROUVRGZGpITVI2a3NCSF9XMFEwRVFSaDNkamlaRXRvVkxXejZvck5FU0sxNVpoOWxMeGw4RWVtLTM5Y25RbU5YQkNORFhUSHRGMHlrZEFqbDBocjRrMzlnNHlmZVlhd2dJbU5MZkIyOEhYNVE1Rll1REtNdENpZERveXQwXzZkeg?oc=5","published_at":"2022-06-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Several zero-day vulnerabilities discovered in popular industrial control system&nbsp;&nbsp;The Record from Recorded Future News","title":"Several zero-day vulnerabilities discovered in popular industrial control system - The Record from Recorded Future News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-668a12b520867a5a","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisAFBVV95cUxPSUhqaXBDTi1YLXBIa3FfSDJSZjNJeTRHSzVMU2ZPeHNmNlVRTThoS2ROUVRGZGpITVI2a3NCSF9XMFEwRVFSaDNkamlaRXRvVkxXejZvck5FU0sxNVpoOWxMeGw4RWVtLTM5Y25RbU5YQkNORFhUSHRGMHlrZEFqbDBocjRrMzlnNHlmZVlhd2dJbU5MZkIyOEhYNVE1Rll1REtNdENpZERveXQwXzZkeg?oc=5","published_at":"2022-06-08T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Several zero-day vulnerabilities discovered in popular industrial control system&nbsp;&nbsp;therecord.media","title":"Several zero-day vulnerabilities discovered in popular industrial control system - therecord.media"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-3aef688d2bd34b02","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMihgFBVV95cUxOZlpCMVlrdGNZYVJZRS00YXVGc1k1LXZqSTh3cmRuR0RWY3J0Y0MwZDg1Q1MwRUw3QVFHTVFqMlFBTTBYTG96THlvVXlXZU84NS1VR1NZMTByd0R5SVpuRUU0RnpvRk1yNUFzNVdjaWtNc08xQkYtaW9DcXYxZlU2QjlsTWlHUQ?oc=5","published_at":"2022-05-03T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Industrial Switch Security","summary":"Critical CVEs put Aruba Networks, Avaya enterprise switches at risk&nbsp;&nbsp;Cybersecurity Dive","title":"Critical CVEs put Aruba Networks, Avaya enterprise switches at risk - Cybersecurity Dive"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["WireGuard Kernel Mesh (xx.xx.xx.0/24)","K3s Traefik L7 Ingress","Edge Gateway SG"],"alert_id":"intel-38c65fb76e91d9ac","category":"Industrial Network & Switches","cve_ids":[],"impact_assessment":"VLAN hop, ARP poisoning, unauthorized WireGuard tunnel handshake attempts, or L7 proxy routing spoofing.","link":"https://news.google.com/rss/articles/CBMihgFBVV95cUxOZlpCMVlrdGNZYVJZRS00YXVGc1k1LXZqSTh3cmRuR0RWY3J0Y0MwZDg1Q1MwRUw3QVFHTVFqMlFBTTBYTG96THlvVXlXZU84NS1VR1NZMTByd0R5SVpuRUU0RnpvRk1yNUFzNVdjaWtNc08xQkYtaW9DcXYxZlU2QjlsTWlHUQ?oc=5","published_at":"2022-05-03T07:00:00+00:00","purdue_level":"Level 2 Network Fabric & Level 4 Cloud DMZ","recommended_action":"Lock WireGuard to Curve25519 public keys with preshared keys (PSK), enforce AWS Security Group ingress boundaries, and verify MAC tables on switch ports.","severity":"CRITICAL","source":"Industrial Switch Security","summary":"Critical CVEs put Aruba Networks, Avaya enterprise switches at risk&nbsp;&nbsp;cybersecuritydive.com","title":"Critical CVEs put Aruba Networks, Avaya enterprise switches at risk - cybersecuritydive.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-92d2f6ea6c9a6ed9","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiiAFBVV95cUxNbW5LVW10b2ExTnVYWHZKek1xS1d0NXdOM3dHQ3BRMDUxM2lSNjQzN3RUckRSYUUza25zd0h6WU90MjNwOHVYNlgyOUF2UHhIUVh4UWhOZkhacVdYTUp3OWR4LWM5RlktY3RINjQtbmFGUnVld1ZiT3ZZdDZKRmtvTmkxbkUteXdm?oc=5","published_at":"2022-04-25T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"6 Major SCADA Attacks That Happened And Their Consequences&nbsp;&nbsp;HackerNoon","title":"6 Major SCADA Attacks That Happened And Their Consequences - HackerNoon"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-43b863f666bfd2ef","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiiAFBVV95cUxNbW5LVW10b2ExTnVYWHZKek1xS1d0NXdOM3dHQ3BRMDUxM2lSNjQzN3RUckRSYUUza25zd0h6WU90MjNwOHVYNlgyOUF2UHhIUVh4UWhOZkhacVdYTUp3OWR4LWM5RlktY3RINjQtbmFGUnVld1ZiT3ZZdDZKRmtvTmkxbkUteXdm?oc=5","published_at":"2022-04-25T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"6 Major SCADA Attacks That Happened And Their Consequences&nbsp;&nbsp;hackernoon.com","title":"6 Major SCADA Attacks That Happened And Their Consequences - hackernoon.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a946de0752801f41","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxQazVLZjUxQmRKN3RqTGRUZzJGV1VzWlpvSVk4MmJuRFluV0dKc3lVbTY4Uzg5MEo0MjhoVV93WVRGbkt4ZGtoWHpXTE9ld1Qyd3lhdHlsX2U3cVNudjF6YTdTZ2IxYWlBeksxNEMzd0pTUDA2YVM5Nnd5cDNLOHJ3UjVzVUNzalRUUzlzZGlmeUlGU0dtS2o2YjZOM3YyellEelFzSGFxbGNzYWFTckHSAbMBQVVfeXFMUGZOa1dPb1p1MjBuUDlFaW11MDhCT3FOMzZrUW13SU1TS1AzTUNVdHR5Vk1tVEFETy1YbVdJR3B4V2dVdUlodDY0a3hEd1lDRDVnaEpKZFdFTWNZMHoxQi1Nb203c0p2UnBXcU5leml1V0tid0lxRFU5aEM2THRkVXNINnRBbXN4bnp3TWgzM3R0Q19KM1VwaWs1M1lNZVU1S3Q0TUx5dEVFb1F0OVo5eG5aZ1k?oc=5","published_at":"2022-04-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"Hackers earn $400K for zero-day ICS exploits demoed at Pwn2Own&nbsp;&nbsp;bleepingcomputer.com","title":"Hackers earn $400K for zero-day ICS exploits demoed at Pwn2Own - bleepingcomputer.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4dd05d4f72854321","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxQazVLZjUxQmRKN3RqTGRUZzJGV1VzWlpvSVk4MmJuRFluV0dKc3lVbTY4Uzg5MEo0MjhoVV93WVRGbkt4ZGtoWHpXTE9ld1Qyd3lhdHlsX2U3cVNudjF6YTdTZ2IxYWlBeksxNEMzd0pTUDA2YVM5Nnd5cDNLOHJ3UjVzVUNzalRUUzlzZGlmeUlGU0dtS2o2YjZOM3YyellEelFzSGFxbGNzYWFTckHSAbMBQVVfeXFMUGZOa1dPb1p1MjBuUDlFaW11MDhCT3FOMzZrUW13SU1TS1AzTUNVdHR5Vk1tVEFETy1YbVdJR3B4V2dVdUlodDY0a3hEd1lDRDVnaEpKZFdFTWNZMHoxQi1Nb203c0p2UnBXcU5leml1V0tid0lxRFU5aEM2THRkVXNINnRBbXN4bnp3TWgzM3R0Q19KM1VwaWs1M1lNZVU1S3Q0TUx5dEVFb1F0OVo5eG5aZ1k?oc=5","published_at":"2022-04-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"Hackers earn $400K for zero-day ICS exploits demoed at Pwn2Own&nbsp;&nbsp;BleepingComputer","title":"Hackers earn $400K for zero-day ICS exploits demoed at Pwn2Own - BleepingComputer"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-75fa517e5f52292e","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiwgFBVV95cUxOTlBXZ2pOM0pySlY1V1BiT2lHaG5IRmxTazA2U09vZFVXTlFtQzVxQzlyRGhFbndEdVJucjQwS3pPbjNBWVV1NlhvZjRTLUJfMHJCQURfYlVteVlZN3o2Vkx1S2NOUFZDWXVXeFBhYzR1RTdlUnk0WjdxOS1mV2ZPUkRoYkNZaWpHUzNDdzcxNXRKYWZaek9RRjR4Z1ZveGVULWxCUmQxTFU5ZDVVUXNRMUp0Z0VZWEFFdExMa3pZQmhWUQ?oc=5","published_at":"2022-04-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Pipedream/INCONTROLLER Detection: New Attack Framework and Tools Target Industrial Control Systems&nbsp;&nbsp;socprime.com","title":"Pipedream/INCONTROLLER Detection: New Attack Framework and Tools Target Industrial Control Systems - socprime.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-84879ab6d19dc30c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiwgFBVV95cUxOTlBXZ2pOM0pySlY1V1BiT2lHaG5IRmxTazA2U09vZFVXTlFtQzVxQzlyRGhFbndEdVJucjQwS3pPbjNBWVV1NlhvZjRTLUJfMHJCQURfYlVteVlZN3o2Vkx1S2NOUFZDWXVXeFBhYzR1RTdlUnk0WjdxOS1mV2ZPUkRoYkNZaWpHUzNDdzcxNXRKYWZaek9RRjR4Z1ZveGVULWxCUmQxTFU5ZDVVUXNRMUp0Z0VZWEFFdExMa3pZQmhWUQ?oc=5","published_at":"2022-04-19T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Pipedream/INCONTROLLER Detection: New Attack Framework and Tools Target Industrial Control Systems&nbsp;&nbsp;SOC Prime","title":"Pipedream/INCONTROLLER Detection: New Attack Framework and Tools Target Industrial Control Systems - SOC Prime"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7cccf0e8cece89d4","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi7wFBVV95cUxORy1CWFNQMHRNcTNVVk1heW43TWZ3VlZjRzNldklUNXV6RU50OVV3M3lnR3ZZSGJEZnhpb0pCV0xvcy1iZy1abWctUGJFNGNYZWZJOHFZeUJBVmg1Q3NSUEVmdWhPZUhPbk9OcUNRUGhkOXZkSTRzNFF0Q252U2FLdHVYTUY2QmhwcTNhbG9EVTBVcWdkX28xXzVBRDF0dVpoQncwcF9XdC1VY0RtMkZEaVcxenJzZ1lpekdMcGRzeFplOFl5S3pTTGMzRUltZllVVVc5bXUteGY2UnR4WFNXd1QyS1czYndVUVF3WmZtUQ?oc=5","published_at":"2022-04-15T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"No Longer a PIPEDREAM: Seventh ICS-Focused Malware Discovered&nbsp;&nbsp;ASIS International","title":"No Longer a PIPEDREAM: Seventh ICS-Focused Malware Discovered - ASIS International"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-31af9c5117c20432","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi7wFBVV95cUxORy1CWFNQMHRNcTNVVk1heW43TWZ3VlZjRzNldklUNXV6RU50OVV3M3lnR3ZZSGJEZnhpb0pCV0xvcy1iZy1abWctUGJFNGNYZWZJOHFZeUJBVmg1Q3NSUEVmdWhPZUhPbk9OcUNRUGhkOXZkSTRzNFF0Q252U2FLdHVYTUY2QmhwcTNhbG9EVTBVcWdkX28xXzVBRDF0dVpoQncwcF9XdC1VY0RtMkZEaVcxenJzZ1lpekdMcGRzeFplOFl5S3pTTGMzRUltZllVVVc5bXUteGY2UnR4WFNXd1QyS1czYndVUVF3WmZtUQ?oc=5","published_at":"2022-04-15T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"No Longer a PIPEDREAM: Seventh ICS-Focused Malware Discovered&nbsp;&nbsp;asisonline.org","title":"No Longer a PIPEDREAM: Seventh ICS-Focused Malware Discovered - asisonline.org"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-bec0b3adb3c1f193","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMifEFVX3lxTE9YclNMYmNmcGQ2UGJwTnJzQmhVWXMtOWtuS0ZtQ1RnSTNOcWxtRGZ1aE1lWVFIUmh5ZkNSTDYxbk1icGYxNWMtX0ZvT001VnJTN3ZtZ0tGeXp1RERWZHFmX2t6eUtuRE5JTTJqaGNuSDBqRnJSUlpwb0lXYms?oc=5","published_at":"2022-04-14T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"U.S. Warns of APT Hackers Targeting ICS/SCADA Systems with Specialized Malware&nbsp;&nbsp;thehackernews.com","title":"U.S. Warns of APT Hackers Targeting ICS/SCADA Systems with Specialized Malware - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-4c3c62c0a4729adf","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiaEFVX3lxTE5rcm9RVks0dzRURkRydE9aLUJXTS0yVW5QTFJqbUYwbDA3N2Q2c3ZveWh0SXFoMWhBUHpJMTdjYzZYTXpheFdZWTRyMU0zVnRucGxES05xRjcyamhuRzZuNUZoTlZVMWMz?oc=5","published_at":"2022-04-14T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"APT group has developed custom-made tools for targeting ICS/SCADA devices&nbsp;&nbsp;Help Net Security","title":"APT group has developed custom-made tools for targeting ICS/SCADA devices - Help Net Security"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-e87daf3420662442","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiaEFVX3lxTE5rcm9RVks0dzRURkRydE9aLUJXTS0yVW5QTFJqbUYwbDA3N2Q2c3ZveWh0SXFoMWhBUHpJMTdjYzZYTXpheFdZWTRyMU0zVnRucGxES05xRjcyamhuRzZuNUZoTlZVMWMz?oc=5","published_at":"2022-04-14T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"APT group has developed custom-made tools for targeting ICS/SCADA devices&nbsp;&nbsp;helpnetsecurity.com","title":"APT group has developed custom-made tools for targeting ICS/SCADA devices - helpnetsecurity.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-39ff85c124bef9c5","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMifEFVX3lxTE9YclNMYmNmcGQ2UGJwTnJzQmhVWXMtOWtuS0ZtQ1RnSTNOcWxtRGZ1aE1lWVFIUmh5ZkNSTDYxbk1icGYxNWMtX0ZvT001VnJTN3ZtZ0tGeXp1RERWZHFmX2t6eUtuRE5JTTJqaGNuSDBqRnJSUlpwb0lXYms?oc=5","published_at":"2022-04-14T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"U.S. Warns of APT Hackers Targeting ICS/SCADA Systems with Specialized Malware&nbsp;&nbsp;The Hacker News","title":"U.S. Warns of APT Hackers Targeting ICS/SCADA Systems with Specialized Malware - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-cf8f74afe9d7cfed","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxQWG9mN0NhSFRvaFJrUFBZYnFlR2NJTFVtUGZLV0ZDck9rSEJyRHVNUm9WSE9BZWUwT0dhYlptcHRXU3p3aEJUTDZsLUNRN1hpcWduQlJOWVJfbVVlTmtTdi12U0RTeXZNV1dpcEtFWWNybVN1cDNXdkFBUmxiQW8xUWI4UXJHZkV2NHdPTE5pcC1DdVhvVTlxV1NnYTVwWUI0NFhnSkpMckt0cXIxMWfSAbMBQVVfeXFMTnE3VGZLQTVTaHRTc2JSUHl1MERCa0EyTkFJVkJrUktNd2FDTi1VSVBrMzRiUVB6cTZacVVwYjNMTEwzTHoxWGZzdm4xbnhrX01LYXJuclMxcV9RenNqTVVQSXMxa0s1dGNZS28zY2RGaVBhemtYakFhSVpTSlN0cXd5b1I4U1NOU2ZRMDBnbnlkV3gzVHpqUnBUYkRHb3lNMU9jUlZROGR4b1Vybk1QeVhTa3c?oc=5","published_at":"2022-04-13T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"US warns of govt hackers targeting industrial control systems&nbsp;&nbsp;BleepingComputer","title":"US warns of govt hackers targeting industrial control systems - BleepingComputer"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-919efa6504d510b5","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxQWG9mN0NhSFRvaFJrUFBZYnFlR2NJTFVtUGZLV0ZDck9rSEJyRHVNUm9WSE9BZWUwT0dhYlptcHRXU3p3aEJUTDZsLUNRN1hpcWduQlJOWVJfbVVlTmtTdi12U0RTeXZNV1dpcEtFWWNybVN1cDNXdkFBUmxiQW8xUWI4UXJHZkV2NHdPTE5pcC1DdVhvVTlxV1NnYTVwWUI0NFhnSkpMckt0cXIxMWfSAbMBQVVfeXFMTnE3VGZLQTVTaHRTc2JSUHl1MERCa0EyTkFJVkJrUktNd2FDTi1VSVBrMzRiUVB6cTZacVVwYjNMTEwzTHoxWGZzdm4xbnhrX01LYXJuclMxcV9RenNqTVVQSXMxa0s1dGNZS28zY2RGaVBhemtYakFhSVpTSlN0cXd5b1I4U1NOU2ZRMDBnbnlkV3gzVHpqUnBUYkRHb3lNMU9jUlZROGR4b1Vybk1QeVhTa3c?oc=5","published_at":"2022-04-13T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"US warns of govt hackers targeting industrial control systems&nbsp;&nbsp;bleepingcomputer.com","title":"US warns of govt hackers targeting industrial control systems - bleepingcomputer.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-0a3a3420f602f425","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMioAFBVV95cUxOVDBBazREUVdud2F1THl5Tnh0d3NDMk1VbDdWXzBZS3VtWkRZM2FLdHRUVlR2V185NXpmZDBGNkdjOWlWbWRoT2tjcDUzRXJnN09IR2tSQjN1V1pRakd2VUpVMXNUbXVxTGVhUTh3bExzRmRSY0JxUm0zaGVkNVMwQ3RmdlNoMGRCUXIyeTNtTjZvVHpKaXdIVjAwODYxSE8z0gGmAUFVX3lxTE5jYVBSSFg3SmpJTGN2UXRESnVkMmtMeTVZZFFGVWFfMEJFakxVY3o2dS16YU5KNmxkT0JFbkRIUWlpdEQ4eTFxUV8wYldYZlBXMHA4dWVMLUpuT3NNTDVENENSZml4Q1QzblpYcWJxbnMtSEVMc2ZxM1NaSXVEd3Ixbjk2Y29kRjViWk5mX3hTOWxnYV8xUkJQdVlIcXVIRlBqbmFKMGc?oc=5","published_at":"2022-04-01T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"New Vulnerabilities Allow Stuxnet-Style Attacks Against Rockwell PLCs&nbsp;&nbsp;securityweek.com","title":"New Vulnerabilities Allow Stuxnet-Style Attacks Against Rockwell PLCs - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-2c331e0fed592bd0","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMif0FVX3lxTFBmZEQtVnBYRWhJV2ZaMi1jaW1GM1RpNld4X1ZSU0JObkxRdXFfSVhDNmdUZmtoZWtEejZ6ajhtRWxTenVhZS0tUGNSS3ctQ0dKLTI1VHQ2ZlFZSFZ0d2xncDdVV0dldTVzOVJUT2RKZS05U1B3S0FnRHRnbkdGZGc?oc=5","published_at":"2022-04-01T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"CRITICAL","source":"Rockwell & CIP Security","summary":"Critical Bugs in Rockwell PLC Could Allow Hackers to Implant Malicious Code&nbsp;&nbsp;The Hacker News","title":"Critical Bugs in Rockwell PLC Could Allow Hackers to Implant Malicious Code - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-e484880d17888992","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiyAFBVV95cUxPcXhoQ0Z4dUxqaGdjV1ZLVXROLVpXRHY3eVNnbG5iSFBQRkdLaFBwaVdUbmgtZGY0OXdCeGIwa09GTm5nZE1Zdnp4Q0VlWGZJTS1CYUc0Y2N0QWpHNVJqemdSeWtUek1RdzZEU0xJMFU3YmJobmNDbDR6QXB0YjNwaUZxWnR6V2Ixd1dleFlROXhsMk9IYnZDYUpMdndmVnFCeDFtWnY5cUU0MzE5bXpqMk9YYmNVVkdzajQ3bjhTNEJWZU5UWGRQcQ?oc=5","published_at":"2022-04-01T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Team82 finds that vulnerabilities in Rockwell PLCs could trigger Stuxnet-like attacks&nbsp;&nbsp;Industrial Cyber","title":"Team82 finds that vulnerabilities in Rockwell PLCs could trigger Stuxnet-like attacks - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-214084019c4c09ea","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMioAFBVV95cUxOVDBBazREUVdud2F1THl5Tnh0d3NDMk1VbDdWXzBZS3VtWkRZM2FLdHRUVlR2V185NXpmZDBGNkdjOWlWbWRoT2tjcDUzRXJnN09IR2tSQjN1V1pRakd2VUpVMXNUbXVxTGVhUTh3bExzRmRSY0JxUm0zaGVkNVMwQ3RmdlNoMGRCUXIyeTNtTjZvVHpKaXdIVjAwODYxSE8z0gGmAUFVX3lxTE5jYVBSSFg3SmpJTGN2UXRESnVkMmtMeTVZZFFGVWFfMEJFakxVY3o2dS16YU5KNmxkT0JFbkRIUWlpdEQ4eTFxUV8wYldYZlBXMHA4dWVMLUpuT3NNTDVENENSZml4Q1QzblpYcWJxbnMtSEVMc2ZxM1NaSXVEd3Ixbjk2Y29kRjViWk5mX3hTOWxnYV8xUkJQdVlIcXVIRlBqbmFKMGc?oc=5","published_at":"2022-04-01T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"New Vulnerabilities Allow Stuxnet-Style Attacks Against Rockwell PLCs&nbsp;&nbsp;SecurityWeek","title":"New Vulnerabilities Allow Stuxnet-Style Attacks Against Rockwell PLCs - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-589a3e90e734dd0b","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiyAFBVV95cUxPcXhoQ0Z4dUxqaGdjV1ZLVXROLVpXRHY3eVNnbG5iSFBQRkdLaFBwaVdUbmgtZGY0OXdCeGIwa09GTm5nZE1Zdnp4Q0VlWGZJTS1CYUc0Y2N0QWpHNVJqemdSeWtUek1RdzZEU0xJMFU3YmJobmNDbDR6QXB0YjNwaUZxWnR6V2Ixd1dleFlROXhsMk9IYnZDYUpMdndmVnFCeDFtWnY5cUU0MzE5bXpqMk9YYmNVVkdzajQ3bjhTNEJWZU5UWGRQcQ?oc=5","published_at":"2022-04-01T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Team82 finds that vulnerabilities in Rockwell PLCs could trigger Stuxnet-like attacks&nbsp;&nbsp;industrialcyber.co","title":"Team82 finds that vulnerabilities in Rockwell PLCs could trigger Stuxnet-like attacks - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-9f2fa11801037093","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiogFBVV95cUxOUVFxQjl6UUNMZlVBR0R1UlJDdTlxX3RsZDFsNEF4eHVXOURwVUQ3RkRESTVxTG10NHdaUWF4RU53cjNiOTJtdUtBSFJSRkljNENfU2pYYWM4bWMtNG9hZTJFaUh4NXVQNlVEdmk0am5QRWN5VUdWZzY0YjBVeEgtU3FPWDVrZVFQNHZ5ZmRmcmZaQ0RyVF9YWnc1WGI0RFVDMWc?oc=5","published_at":"2022-04-01T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"The spectre of Stuxnet: CISA issues alert on Rockwell Automation ICS vulnerabilities&nbsp;&nbsp;ZDNET","title":"The spectre of Stuxnet: CISA issues alert on Rockwell Automation ICS vulnerabilities - ZDNET"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-584d9f2ef6ecf25c","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiogFBVV95cUxOUVFxQjl6UUNMZlVBR0R1UlJDdTlxX3RsZDFsNEF4eHVXOURwVUQ3RkRESTVxTG10NHdaUWF4RU53cjNiOTJtdUtBSFJSRkljNENfU2pYYWM4bWMtNG9hZTJFaUh4NXVQNlVEdmk0am5QRWN5VUdWZzY0YjBVeEgtU3FPWDVrZVFQNHZ5ZmRmcmZaQ0RyVF9YWnc1WGI0RFVDMWc?oc=5","published_at":"2022-04-01T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"The spectre of Stuxnet: CISA issues alert on Rockwell Automation ICS vulnerabilities&nbsp;&nbsp;zdnet.com","title":"The spectre of Stuxnet: CISA issues alert on Rockwell Automation ICS vulnerabilities - zdnet.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b1f51c62eda84adc","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi2AFBVV95cUxPRlZoa2IwaWNjdlpBVXpFRVRjZzJzbGM5eUtnYkF3NHB5cEJ1Qi1temVJQjNqcXNxNkRNSDRRS1dUTXlXNXE1dmdaUnpiWVhoWXllVzdwbGFSdFVqTVJ6NmpkUHJndGVPVnhPbDJkT044Q1NKZTFuRlozZ3JDeElzTmg0czZzTkJxZVlSRG4xdldwVDBiR2kzUXBQU1lNdnd2MTNSTjdQQ0dNb1VoNlFaaGM3RVhUTXRFb1hDemVJRzlrWmxyemZ2NFktTjFXcXExNXk5Mi1xM0w?oc=5","published_at":"2022-03-29T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"US charges Russian agents over cyber attacks on oil refineries and nuclear power plants&nbsp;&nbsp;Bitdefender","title":"US charges Russian agents over cyber attacks on oil refineries and nuclear power plants - Bitdefender"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-efbada70342b375a","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi2AFBVV95cUxPRlZoa2IwaWNjdlpBVXpFRVRjZzJzbGM5eUtnYkF3NHB5cEJ1Qi1temVJQjNqcXNxNkRNSDRRS1dUTXlXNXE1dmdaUnpiWVhoWXllVzdwbGFSdFVqTVJ6NmpkUHJndGVPVnhPbDJkT044Q1NKZTFuRlozZ3JDeElzTmg0czZzTkJxZVlSRG4xdldwVDBiR2kzUXBQU1lNdnd2MTNSTjdQQ0dNb1VoNlFaaGM3RVhUTXRFb1hDemVJRzlrWmxyemZ2NFktTjFXcXExNXk5Mi1xM0w?oc=5","published_at":"2022-03-29T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"US charges Russian agents over cyber attacks on oil refineries and nuclear power plants&nbsp;&nbsp;bitdefender.com","title":"US charges Russian agents over cyber attacks on oil refineries and nuclear power plants - bitdefender.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-24dcf25d41fa41f5","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikgFBVV95cUxNaWNxUE4zZHRtdnVyekh0QUV1NGdqUkd0R2otMGpKX2tYN1lxb0xPa1k0ZlFBTWhRNFZHNXFXM3FJY19kRlVxWFNBTnd4ZndhbmZfOEd4cGpHR3ZsN0FfcF9hbWlIaEJ2cUozM2VsRE9aV2ZrbDcyQ3kxSzBSN2dKM2d0TmNaUk1hOTBYbndiSHEwQQ?oc=5","published_at":"2022-03-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"DOJ Reveals Indictments Against Russian Energy Hackers&nbsp;&nbsp;rtoinsider.com","title":"DOJ Reveals Indictments Against Russian Energy Hackers - rtoinsider.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c7081ef653588d5c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikgFBVV95cUxNaWNxUE4zZHRtdnVyekh0QUV1NGdqUkd0R2otMGpKX2tYN1lxb0xPa1k0ZlFBTWhRNFZHNXFXM3FJY19kRlVxWFNBTnd4ZndhbmZfOEd4cGpHR3ZsN0FfcF9hbWlIaEJ2cUozM2VsRE9aV2ZrbDcyQ3kxSzBSN2dKM2d0TmNaUk1hOTBYbndiSHEwQQ?oc=5","published_at":"2022-03-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"DOJ Reveals Indictments Against Russian Energy Hackers&nbsp;&nbsp;RTO Insider","title":"DOJ Reveals Indictments Against Russian Energy Hackers - RTO Insider"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7da17cb163feb107","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimwFBVV95cUxNNHp6YUVmWEZRQmloSDZhYzZFalpmVTJOYmVkWTFaYm8wamRyRVpaNEhnMm54ckMyeEluN3N2YTlHRk5TLVdrV0xtZFJWZWFQUHdNUVRySzBiSnEwY1BjVDhoSUFsVjdUT0tETEJCUE5KRHdvMlVnc3F1WUt3UXN6TkZ3alZSMjlGNWdGcjhvbHpseHRSZnhwZ0xzcw?oc=5","published_at":"2022-02-16T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"How Vulnerability Creates Change&nbsp;&nbsp;YES! Magazine","title":"How Vulnerability Creates Change - YES! Magazine"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4e8483eded4c3120","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimwFBVV95cUxNNHp6YUVmWEZRQmloSDZhYzZFalpmVTJOYmVkWTFaYm8wamRyRVpaNEhnMm54ckMyeEluN3N2YTlHRk5TLVdrV0xtZFJWZWFQUHdNUVRySzBiSnEwY1BjVDhoSUFsVjdUT0tETEJCUE5KRHdvMlVnc3F1WUt3UXN6TkZ3alZSMjlGNWdGcjhvbHpseHRSZnhwZ0xzcw?oc=5","published_at":"2022-02-16T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"How Vulnerability Creates Change&nbsp;&nbsp;yesmagazine.org","title":"How Vulnerability Creates Change - yesmagazine.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9440acbd97a4b06b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipgFBVV95cUxOQWZnUjRITkltNjNGMzdadDlHMEVwSVVQVTJYcDVmdlhoRFRkS09wOW1QWGhqRVdWYTE5RURjZkRXYlF1YTJjQU54blhibGtEb2YxLUhFanBTeTg5bG9NODc5LTdiNDFWVUNLME11RGQxckNfT0dBV2d3SlNWZ2ItS1cyQUpUQ044bURRLVpqbllleXlROW51NXNvMmtORlZTWUJSUERB?oc=5","published_at":"2022-01-15T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Cybersecurity for Industrial Control Systems: Part 1&nbsp;&nbsp;trendmicro.com","title":"Cybersecurity for Industrial Control Systems: Part 1 - trendmicro.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9de69d2b76bf821b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipgFBVV95cUxQcmYyb1ZSd25ZMExVUThMZEVHVjhqdUJMX2toMXRvQ1VRTkhvRTIzSEl4Nlp0cDdmQWxwNmEtYzhaM19VdFhlNndWSUFFZjNhS0FWT1dhMDBBbmtJZ2FrVm42R1J1YjZWOERRX3FzSjBGVC0wUWVBVXBkVW13cF9TdmxBWlhfRG4tUkpta1JMc3FEb3FaQWJSSHhpS0NLY3QyWjMyQXVB?oc=5","published_at":"2022-01-15T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Cybersecurity for Industrial Control Systems: Part 1&nbsp;&nbsp;trendmicro.com","title":"Cybersecurity for Industrial Control Systems: Part 1 - trendmicro.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5b78a53867390610","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipgFBVV95cUxQcmYyb1ZSd25ZMExVUThMZEVHVjhqdUJMX2toMXRvQ1VRTkhvRTIzSEl4Nlp0cDdmQWxwNmEtYzhaM19VdFhlNndWSUFFZjNhS0FWT1dhMDBBbmtJZ2FrVm42R1J1YjZWOERRX3FzSjBGVC0wUWVBVXBkVW13cF9TdmxBWlhfRG4tUkpta1JMc3FEb3FaQWJSSHhpS0NLY3QyWjMyQXVB?oc=5","published_at":"2022-01-15T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Cybersecurity for Industrial Control Systems: Part 1&nbsp;&nbsp;www.trendmicro.com","title":"Cybersecurity for Industrial Control Systems: Part 1 - www.trendmicro.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-bdea91900ff4592e","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMipgFBVV95cUxOQWZnUjRITkltNjNGMzdadDlHMEVwSVVQVTJYcDVmdlhoRFRkS09wOW1QWGhqRVdWYTE5RURjZkRXYlF1YTJjQU54blhibGtEb2YxLUhFanBTeTg5bG9NODc5LTdiNDFWVUNLME11RGQxckNfT0dBV2d3SlNWZ2ItS1cyQUpUQ044bURRLVpqbllleXlROW51NXNvMmtORlZTWUJSUERB?oc=5","published_at":"2022-01-15T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Cybersecurity for Industrial Control Systems: Part 1&nbsp;&nbsp;www.trendmicro.com","title":"Cybersecurity for Industrial Control Systems: Part 1 - www.trendmicro.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7a0f3e57b09dbe6d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirAFBVV95cUxNZHdDSjY5T2VCZ2JOQjNPa0hleGNRcnhSc250aWVORkFSa2xUZWs3TnZiVkJ5LXVmbmxMRXI4dmNYTjlYWE5ob2tGLTZUVVo3djRXa2JaR25mVVhibjVoY0VVSVZFdFc2VWpTYUNYbWs5NTM3eWFxc3VMMXdHSm1PZ0dkci1ZWDBoQXY0Zk1RWHpfWERkYmNTYkdMS0hBTFNmQTdRdWd0dnhlU0tW?oc=5","published_at":"2021-12-26T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"The Essential Guide to the IEC 62443 industrial cybersecurity standards&nbsp;&nbsp;industrialcyber.co","title":"The Essential Guide to the IEC 62443 industrial cybersecurity standards - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-22a531470820a89c","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMirAFBVV95cUxNZHdDSjY5T2VCZ2JOQjNPa0hleGNRcnhSc250aWVORkFSa2xUZWs3TnZiVkJ5LXVmbmxMRXI4dmNYTjlYWE5ob2tGLTZUVVo3djRXa2JaR25mVVhibjVoY0VVSVZFdFc2VWpTYUNYbWs5NTM3eWFxc3VMMXdHSm1PZ0dkci1ZWDBoQXY0Zk1RWHpfWERkYmNTYkdMS0hBTFNmQTdRdWd0dnhlU0tW?oc=5","published_at":"2021-12-26T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"The Essential Guide to the IEC 62443 industrial cybersecurity standards&nbsp;&nbsp;Industrial Cyber","title":"The Essential Guide to the IEC 62443 industrial cybersecurity standards - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-4f4917ce0a1ed49e","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMizAFBVV95cUxQcVNod2RGeTNGdDItMEZ3WDhFcGhoeTh6XzVSNzlUN1k1elk3blJXVXdRelYyTVItcXgtcGlUWlQwTWJvOEk0a0EwTXBXOGl4ZVpqOW5BbWxMbHhtenZDcVlUeG9wMTJROXgtMDRrSk4wQS04eE91dGZhOG1nWm9fUEIzUFJRSXVwWVEwTWdKMVdZaVAzbExHczU2TzU3LUFjNDEzazU5ZDFaQ1dmTGFlUVIxclo3RjBVdFBPU0VXbHRtbkxKR3JWb1FUWG0?oc=5","published_at":"2021-11-17T08:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Modern SCADA system improves feed mill operations at Smithfield operations in Utah | 2021-11-17&nbsp;&nbsp;foodengineeringmag.com","title":"Modern SCADA system improves feed mill operations at Smithfield operations in Utah | 2021-11-17 - foodengineeringmag.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-a2dc776e4ba5d43a","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxPcGo1a2swS2tiLVB1V19YQXdzMW5tXzhmSGdXdkJyWEhNb0JtU19NUEpiY2Raa1hRRlBLeGJHMzBsVE1vb2JQUkVfVnZBUUIyRmNKOW5xSkdZQU5Xem5pVEZDSF96cWNiaHVCdnowSC1veGVvSXgxZUxhbGdybmJJY09DSjhEdVdHUVhyVWJZOHNDUDZlc0lFZ0I0czItd2s5SjRFRmowQmFMUQ?oc=5","published_at":"2021-11-12T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"The ICS/OT Landscape: How CrowdStrike Supports Through Partnerships With Rockwell and Others&nbsp;&nbsp;crowdstrike.com","title":"The ICS/OT Landscape: How CrowdStrike Supports Through Partnerships With Rockwell and Others - crowdstrike.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-c740339d1999a8b8","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxPcGo1a2swS2tiLVB1V19YQXdzMW5tXzhmSGdXdkJyWEhNb0JtU19NUEpiY2Raa1hRRlBLeGJHMzBsVE1vb2JQUkVfVnZBUUIyRmNKOW5xSkdZQU5Xem5pVEZDSF96cWNiaHVCdnowSC1veGVvSXgxZUxhbGdybmJJY09DSjhEdVdHUVhyVWJZOHNDUDZlc0lFZ0I0czItd2s5SjRFRmowQmFMUQ?oc=5","published_at":"2021-11-12T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"The ICS/OT Landscape: How CrowdStrike Supports Through Partnerships With Rockwell and Others&nbsp;&nbsp;CrowdStrike","title":"The ICS/OT Landscape: How CrowdStrike Supports Through Partnerships With Rockwell and Others - CrowdStrike"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6819a114d719e549","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMifEFVX3lxTE5kaUI3OHVuWkRsQ00xNDhaRjlhVGpLSV9jQUM4Sk5UU0c4Q2YwZGIyS0szaW41dUxBZl9TTmtPUUdnVXlOb29LUWNkU2R2YV9ZeVI1emZYS0pUWnllc0R5ZFAweHpSUF82V2RNZUVFUXdpV1RMSHN0ZllSR3o?oc=5","published_at":"2021-07-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Several New Critical Flaws Affect CODESYS Industrial Automation Software&nbsp;&nbsp;The Hacker News","title":"Several New Critical Flaws Affect CODESYS Industrial Automation Software - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-94b2c97bffc817bd","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMifEFVX3lxTE5kaUI3OHVuWkRsQ00xNDhaRjlhVGpLSV9jQUM4Sk5UU0c4Q2YwZGIyS0szaW41dUxBZl9TTmtPUUdnVXlOb29LUWNkU2R2YV9ZeVI1emZYS0pUWnllc0R5ZFAweHpSUF82V2RNZUVFUXdpV1RMSHN0ZllSR3o?oc=5","published_at":"2021-07-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Several New Critical Flaws Affect CODESYS Industrial Automation Software&nbsp;&nbsp;thehackernews.com","title":"Several New Critical Flaws Affect CODESYS Industrial Automation Software - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-6c780d596d047d01","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMixwFBVV95cUxQZll2a1JjSGN3RmVMd3hJOVlzcFI2MC0zdUozT0VGTks0MVVmd001UEtxcWxXYU55YV82dHB6V1hJMWFPcm4yT3NpT3RkT09aeWNoQVAzM0dqSnVVT2VEN05Cb3h5cUNtWWhTbjNUYjhJNWlLNVdpT0RRbnFzSkNFRFVRaG5sclJDMFRKaW5MOHkzV01ZbHozcG5uTzg2VHp2ZzRhZUxFX0EtZHVNZnpidVRFdzVNRU8xaXNvbTJ4Q3NpVjhFVDVn?oc=5","published_at":"2021-06-11T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Security issues identified in Rockwell, Siemens, Schneider Electric equipment in ICS environments&nbsp;&nbsp;industrialcyber.co","title":"Security issues identified in Rockwell, Siemens, Schneider Electric equipment in ICS environments - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-e57c13c5e27ceb20","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMixwFBVV95cUxQZll2a1JjSGN3RmVMd3hJOVlzcFI2MC0zdUozT0VGTks0MVVmd001UEtxcWxXYU55YV82dHB6V1hJMWFPcm4yT3NpT3RkT09aeWNoQVAzM0dqSnVVT2VEN05Cb3h5cUNtWWhTbjNUYjhJNWlLNVdpT0RRbnFzSkNFRFVRaG5sclJDMFRKaW5MOHkzV01ZbHozcG5uTzg2VHp2ZzRhZUxFX0EtZHVNZnpidVRFdzVNRU8xaXNvbTJ4Q3NpVjhFVDVn?oc=5","published_at":"2021-06-11T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Security issues identified in Rockwell, Siemens, Schneider Electric equipment in ICS environments&nbsp;&nbsp;Industrial Cyber","title":"Security issues identified in Rockwell, Siemens, Schneider Electric equipment in ICS environments - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-24610c1e25bab0ea","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMifkFVX3lxTE9GY3ZkU0owWlhKZXZVOHBNanZmT1N3Mm5BbmduQVAzMEE1UURjeVFIRHE3MGZTejBIWF9vWWp2NHFScDZxOUNpN3lyckdpR09nem9ad2JFeFVpTURaWHlIdkpDbFNYb2pyWThYd3R1U0hUYkpuc1RhQ3pDRGRmZw?oc=5","published_at":"2021-06-04T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"10 Critical Flaws Found in CODESYS Industrial Automation Software&nbsp;&nbsp;thehackernews.com","title":"10 Critical Flaws Found in CODESYS Industrial Automation Software - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-04f75254d95764bc","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMifkFVX3lxTE9GY3ZkU0owWlhKZXZVOHBNanZmT1N3Mm5BbmduQVAzMEE1UURjeVFIRHE3MGZTejBIWF9vWWp2NHFScDZxOUNpN3lyckdpR09nem9ad2JFeFVpTURaWHlIdkpDbFNYb2pyWThYd3R1U0hUYkpuc1RhQ3pDRGRmZw?oc=5","published_at":"2021-06-04T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"10 Critical Flaws Found in CODESYS Industrial Automation Software&nbsp;&nbsp;The Hacker News","title":"10 Critical Flaws Found in CODESYS Industrial Automation Software - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-49eb266d76b516f2","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimgFBVV95cUxPRFdFNnZKeFJ2QjJKNEdaNjRuaE1Mb2I3OWN2SjQzaUliakpUbEQ5NE95RU5ZdGVkdGhTaEgzOEpHWllYYlhDSWh3enVkWUNpUkdzVC1lLU9GaVczMDA0bF9XZ09VTll6WDZ4QmJoOXphX2Z2VFdKVlJXR1BTUUxTaGZLd3JqNzRndTZWc05nM2Y2cnRnbTBkQlB3?oc=5","published_at":"2021-05-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Cybersecurity in Construction: Where Do We Stand and How Do We Get Better Prepared&nbsp;&nbsp;Frontiers","title":"Cybersecurity in Construction: Where Do We Stand and How Do We Get Better Prepared - Frontiers"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-caf1348ede8aebaa","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMimgFBVV95cUxPRFdFNnZKeFJ2QjJKNEdaNjRuaE1Mb2I3OWN2SjQzaUliakpUbEQ5NE95RU5ZdGVkdGhTaEgzOEpHWllYYlhDSWh3enVkWUNpUkdzVC1lLU9GaVczMDA0bF9XZ09VTll6WDZ4QmJoOXphX2Z2VFdKVlJXR1BTUUxTaGZLd3JqNzRndTZWc05nM2Y2cnRnbTBkQlB3?oc=5","published_at":"2021-05-26T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Cybersecurity in Construction: Where Do We Stand and How Do We Get Better Prepared&nbsp;&nbsp;frontiersin.org","title":"Cybersecurity in Construction: Where Do We Stand and How Do We Get Better Prepared - frontiersin.org"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c09ca78f2f1355b6","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE16YTNjRzMwRU5GZFVSbXduWHZjc280NXdCbmE4dGNzVzVwU3BoeXgyOXl5bHljeGNBeTBSZkdBMXlyVUNCMmJGeTNmaTBVLV9tWjg5bzJsWmxsUExJaVBv?oc=5","published_at":"2021-04-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Unveiling African rainforest composition and vulnerability to global change&nbsp;&nbsp;Nature","title":"Unveiling African rainforest composition and vulnerability to global change - Nature"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-414e28f2d88e90a8","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiX0FVX3lxTE16YTNjRzMwRU5GZFVSbXduWHZjc280NXdCbmE4dGNzVzVwU3BoeXgyOXl5bHljeGNBeTBSZkdBMXlyVUNCMmJGeTNmaTBVLV9tWjg5bzJsWmxsUExJaVBv?oc=5","published_at":"2021-04-21T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"Industrial Switch Security","summary":"Unveiling African rainforest composition and vulnerability to global change&nbsp;&nbsp;nature.com","title":"Unveiling African rainforest composition and vulnerability to global change - nature.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-dc65449af1ba7297","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiwwFBVV95cUxQTGY4aUxqdkk0S2V4TFR3Zm52VDB1TzVNUUUyUFYwQXdvM2dwdjZNRXRyVU1VRlRhbnBYLThteFJfRVUtTGc2UTZFSWE5TW5JZzZybGhfWGg3RDJTMU5BTzVmblVmcUh4dDFKaGpnYkFjTmN3NW1yMkl3amVuWk1LdGlTeE1ZcnYxcU9TRFJQdmsxMnFFMkpOdEhQXy1MaU9JM0tvbWtTNVZMSkdLYWd4Rko5LUhTcUFLeUQ2ZzFBcllmbkU?oc=5","published_at":"2021-02-26T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Claroty finds vulnerability in communications between Rockwell PLCs and engineering stations&nbsp;&nbsp;industrialcyber.co","title":"Claroty finds vulnerability in communications between Rockwell PLCs and engineering stations - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-12480cc5f22988a5","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiwwFBVV95cUxQTGY4aUxqdkk0S2V4TFR3Zm52VDB1TzVNUUUyUFYwQXdvM2dwdjZNRXRyVU1VRlRhbnBYLThteFJfRVUtTGc2UTZFSWE5TW5JZzZybGhfWGg3RDJTMU5BTzVmblVmcUh4dDFKaGpnYkFjTmN3NW1yMkl3amVuWk1LdGlTeE1ZcnYxcU9TRFJQdmsxMnFFMkpOdEhQXy1MaU9JM0tvbWtTNVZMSkdLYWd4Rko5LUhTcUFLeUQ2ZzFBcllmbkU?oc=5","published_at":"2021-02-26T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Claroty finds vulnerability in communications between Rockwell PLCs and engineering stations&nbsp;&nbsp;Industrial Cyber","title":"Claroty finds vulnerability in communications between Rockwell PLCs and engineering stations - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ad24d90fb2e2b059","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilgFBVV95cUxQZkhJSlI1d0dBZlFqUXVjYkw0ZHFHbDdVOE5pU2pIeVhIWDB1OTdna1lSRzJKNF9vYXJuZ0hBMmFjbnV6UmpVRmRrSXphdlJCcWtsMTNHN1EwaFN2VGxrZ2lNNHlvYUdfUDRPcGJMZllaUWJBdUJuSW5IUjRHSlBTV2YyWWhfR2J3aFF6alMta0llLWpCeGc?oc=5","published_at":"2021-01-21T11:33:02+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Protecting Industrial Control Systems in the Cloud&nbsp;&nbsp;Darktrace","title":"Protecting Industrial Control Systems in the Cloud - Darktrace"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-70f18d8f9a365931","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilgFBVV95cUxQZkhJSlI1d0dBZlFqUXVjYkw0ZHFHbDdVOE5pU2pIeVhIWDB1OTdna1lSRzJKNF9vYXJuZ0hBMmFjbnV6UmpVRmRrSXphdlJCcWtsMTNHN1EwaFN2VGxrZ2lNNHlvYUdfUDRPcGJMZllaUWJBdUJuSW5IUjRHSlBTV2YyWWhfR2J3aFF6alMta0llLWpCeGc?oc=5","published_at":"2021-01-21T11:33:02+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Protecting Industrial Control Systems in the Cloud&nbsp;&nbsp;darktrace.com","title":"Protecting Industrial Control Systems in the Cloud - darktrace.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-12290212094b56fa","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMijwFBVV95cUxQVmNVMU1PN1lPUTFCYzRiUFcxWnI0SE1sZGhpRUVNeHVqVndDX2xvWGNTek1hSTRsU0UzSGxmaUdmLWRfV0ROeHFtMmZCSWZRLUp2VzFyQ1M5QVlkQWQ2aEx3d1A1LUJXUGcyV0NpaHBXZk9LTF8tdFRPdVdRYkJUMkg2SC1hRnpZYVg3YldCRQ?oc=5","published_at":"2021-01-07T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Vulnerability Spotlight: Denial-of-service vulnerability in Rockwell Automation RSLinx&nbsp;&nbsp;Cisco Talos Blog","title":"Vulnerability Spotlight: Denial-of-service vulnerability in Rockwell Automation RSLinx - Cisco Talos Blog"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-8555ef7fc1c6637f","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMijwFBVV95cUxQVmNVMU1PN1lPUTFCYzRiUFcxWnI0SE1sZGhpRUVNeHVqVndDX2xvWGNTek1hSTRsU0UzSGxmaUdmLWRfV0ROeHFtMmZCSWZRLUp2VzFyQ1M5QVlkQWQ2aEx3d1A1LUJXUGcyV0NpaHBXZk9LTF8tdFRPdVdRYkJUMkg2SC1hRnpZYVg3YldCRQ?oc=5","published_at":"2021-01-07T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Vulnerability Spotlight: Denial-of-service vulnerability in Rockwell Automation RSLinx&nbsp;&nbsp;blog.talosintelligence.com","title":"Vulnerability Spotlight: Denial-of-service vulnerability in Rockwell Automation RSLinx - blog.talosintelligence.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a8dd9ee3dfa31ede","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikwFBVV95cUxQaC1jVWtvTnRRWm5pTEltbGpPV3VfSjZhLVZpVWZidDB0VURTTmVlVEpGOVJLcVBFSURZdkhzMldnYWtob3hlMXVsbUs1Z3dwVXJEMGtvTkN2TzMzY0V0bTQwelpMTGh4bmpTM0ZuT09OMndSVnBQYWxqWlZQQnVXaXFZSVFpSVBYcnJBQ3hpTHJCNkk?oc=5","published_at":"2020-12-30T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"What is ICS Security? How to Defend Against Attacks&nbsp;&nbsp;securityboulevard.com","title":"What is ICS Security? How to Defend Against Attacks - securityboulevard.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-97a007fcaff08320","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMikwFBVV95cUxQaC1jVWtvTnRRWm5pTEltbGpPV3VfSjZhLVZpVWZidDB0VURTTmVlVEpGOVJLcVBFSURZdkhzMldnYWtob3hlMXVsbUs1Z3dwVXJEMGtvTkN2TzMzY0V0bTQwelpMTGh4bmpTM0ZuT09OMndSVnBQYWxqWlZQQnVXaXFZSVFpSVBYcnJBQ3hpTHJCNkk?oc=5","published_at":"2020-12-30T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"What is ICS Security? How to Defend Against Attacks&nbsp;&nbsp;Security Boulevard","title":"What is ICS Security? How to Defend Against Attacks - Security Boulevard"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-1059e67d1fdda54b","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxQOVpvU3RSemFqY3MyWTRkdHQxWktvTXh0ZE9iUkxMSUhrUlEzRng1Mk1aQkJKTEwzcmsxWlhFVjNjRVg0d0tGQ3JRWHRka05MTFBBandDQU8xWlhjaDd2Z1BhajZNNzY5VnBBR0VNREJaeTdnX3NZRGtGRXR5Sm1tNzVZLWYxdEQtdERjeG9jczB5dGlQTWFvUU1SZ0o1S3ZhaXMxZ3Q2aVlJX3QzYUE?oc=5","published_at":"2020-11-27T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Security vulnerabilities identified in Rockwell Automation\u2019s FactoryTalk Linx&nbsp;&nbsp;industrialcyber.co","title":"Security vulnerabilities identified in Rockwell Automation\u2019s FactoryTalk Linx - industrialcyber.co"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-8a51aa5eefda9444","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMirgFBVV95cUxQOVpvU3RSemFqY3MyWTRkdHQxWktvTXh0ZE9iUkxMSUhrUlEzRng1Mk1aQkJKTEwzcmsxWlhFVjNjRVg0d0tGQ3JRWHRka05MTFBBandDQU8xWlhjaDd2Z1BhajZNNzY5VnBBR0VNREJaeTdnX3NZRGtGRXR5Sm1tNzVZLWYxdEQtdERjeG9jczB5dGlQTWFvUU1SZ0o1S3ZhaXMxZ3Q2aVlJX3QzYUE?oc=5","published_at":"2020-11-27T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"Rockwell & CIP Security","summary":"Security vulnerabilities identified in Rockwell Automation\u2019s FactoryTalk Linx&nbsp;&nbsp;Industrial Cyber","title":"Security vulnerabilities identified in Rockwell Automation\u2019s FactoryTalk Linx - Industrial Cyber"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-7cd3bd036b22d3a6","category":"ICS / SCADA Controls","cve_ids":["CVE-2020-10611"],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiwAFBVV95cUxNTl9hTnRfWHlQaEUwck5fcmpKdG05SU1XR1V3VlcwNlExVmVvX0RsMXd3eVRGNjRKUUlzUEc3RTNPeFJRVXd3czJra0pwbFc5QW5tanJPYzB2QU9PcU9jdUNDNTFBZGtYamFfY3hpcTBkZjUtV1hpaHRFeVJjdXdWX2h6emkxaGxPQkl6R0ZLdFI4ZkdnSkY1RXVFQWFvdU5EWjdVTG5qLU5QRHdDNU43enhRZ0J2YTU4ZkxZbENIMmU?oc=5","published_at":"2020-08-25T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"CVE-2020-10611: Achieving Code Execution on the Triangle MicroWorks SCADA Data Gateway&nbsp;&nbsp;thezdi.com","title":"CVE-2020-10611: Achieving Code Execution on the Triangle MicroWorks SCADA Data Gateway - thezdi.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-1bd507086a524bcd","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiogFBVV95cUxOQ1NWRWZJVzhuekhCYVdZRVJuQkdqdWRSeE9jdFVtckl4U2FWR3JHT093cHdUTVZpU0NFWFRSWndNVFNhSUNSaEFSU2FYWE1vZWZBUFVER3o2YkxtTUtzWERVME1uQ1VyZkp5VUZFcU4tZkgwTmcxeWRsTHNzWnd2TjRoanJOb3lZOU9WbjFySWJPY2lXaVBLaV82RjZNNERBdkE?oc=5","published_at":"2020-04-22T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Connecting disparate industrial systems to AWS using Ignition Edge&nbsp;&nbsp;Amazon Web Services (AWS)","title":"Connecting disparate industrial systems to AWS using Ignition Edge - Amazon Web Services (AWS)"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-7ffab535901c337c","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiogFBVV95cUxOQ1NWRWZJVzhuekhCYVdZRVJuQkdqdWRSeE9jdFVtckl4U2FWR3JHT093cHdUTVZpU0NFWFRSWndNVFNhSUNSaEFSU2FYWE1vZWZBUFVER3o2YkxtTUtzWERVME1uQ1VyZkp5VUZFcU4tZkgwTmcxeWRsTHNzWnd2TjRoanJOb3lZOU9WbjFySWJPY2lXaVBLaV82RjZNNERBdkE?oc=5","published_at":"2020-04-22T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Connecting disparate industrial systems to AWS using Ignition Edge&nbsp;&nbsp;aws.amazon.com","title":"Connecting disparate industrial systems to AWS using Ignition Edge - aws.amazon.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-3d042f02be777284","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMifkFVX3lxTE5oazFZclNOVnZNMXp3eUlIMWpYdERnRHZDOXNGd0FyQjFlaFhlODlhbkhoRGxqcXpieUpXVGNxWmdwVmprR1lDWFpoR2R5MWxXMjNRSzU3YU9vYjctMExDTnlkMFROdlRQeFpUcHl3azdvSEVzNUF4amh0dXppZ9IBgwFBVV95cUxQWkZLTlA3c3hYMG9HdHNWSTl3YTdTeG53TUVfY1I0OVZIdVY2RzJoMG5pRXROSHRrMU1aYnFQcWU2MUgwdkJuVGFuNFhtN3ZnckxhQXh3UW1mLURTVmc3ZEhIM2xxNExUb0NuaGlFUThtand1c3kyajgzODhDZmpZak4yRQ?oc=5","published_at":"2019-12-13T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"OT ICS Malware & Zero-Days","summary":"Flaws in Siemens SPPA-T3000 control system expose power plants to hack&nbsp;&nbsp;Security Affairs","title":"Flaws in Siemens SPPA-T3000 control system expose power plants to hack - Security Affairs"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-070683e6ba996c36","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMifkFVX3lxTE5oazFZclNOVnZNMXp3eUlIMWpYdERnRHZDOXNGd0FyQjFlaFhlODlhbkhoRGxqcXpieUpXVGNxWmdwVmprR1lDWFpoR2R5MWxXMjNRSzU3YU9vYjctMExDTnlkMFROdlRQeFpUcHl3azdvSEVzNUF4amh0dXppZ9IBgwFBVV95cUxQWkZLTlA3c3hYMG9HdHNWSTl3YTdTeG53TUVfY1I0OVZIdVY2RzJoMG5pRXROSHRrMU1aYnFQcWU2MUgwdkJuVGFuNFhtN3ZnckxhQXh3UW1mLURTVmc3ZEhIM2xxNExUb0NuaGlFUThtand1c3kyajgzODhDZmpZak4yRQ?oc=5","published_at":"2019-12-13T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"OT ICS Malware & Zero-Days","summary":"Flaws in Siemens SPPA-T3000 control system expose power plants to hack&nbsp;&nbsp;securityaffairs.com","title":"Flaws in Siemens SPPA-T3000 control system expose power plants to hack - securityaffairs.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e4ee603405413ced","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi1wFBVV95cUxNYl9TVlp6RTNJX0VWckxtRl9adWREVG9pak9YVG54eFRjYVlNUS1fYUFCa0l0Vnc0eW5ZR1VXR1R4RktLQ0gxMHk2X2RjYjduejV6d2l1a19XZnR1ekdhX0xVamptWFEzV1NwM2VkVHNvNlZESmJUWGpJMV9hOHRsdG9nS1Z0UTAxQlQ2TlJRS2NleG55STJUc1Y4RWNmYTNwU0wzUFJpeVRfaXhYRThPbVRUZW0xaGxBV1YzelpVVkN1YjNsZXVSbGJNcHpOUlpXc012VHBYbw?oc=5","published_at":"2019-07-18T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Building Automation & LoRaWAN","summary":"Radiflow recognised as Global Customer Value Leader in IT/OT Security for Smart Buildings by Frost & Sullivan&nbsp;&nbsp;sourcesecurity.com","title":"Radiflow recognised as Global Customer Value Leader in IT/OT Security for Smart Buildings by Frost & Sullivan - sourcesecurity.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d5ca7f54a65b8c70","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMi1wFBVV95cUxNYl9TVlp6RTNJX0VWckxtRl9adWREVG9pak9YVG54eFRjYVlNUS1fYUFCa0l0Vnc0eW5ZR1VXR1R4RktLQ0gxMHk2X2RjYjduejV6d2l1a19XZnR1ekdhX0xVamptWFEzV1NwM2VkVHNvNlZESmJUWGpJMV9hOHRsdG9nS1Z0UTAxQlQ2TlJRS2NleG55STJUc1Y4RWNmYTNwU0wzUFJpeVRfaXhYRThPbVRUZW0xaGxBV1YzelpVVkN1YjNsZXVSbGJNcHpOUlpXc012VHBYbw?oc=5","published_at":"2019-07-18T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"Building Automation & LoRaWAN","summary":"Radiflow recognised as Global Customer Value Leader in IT/OT Security for Smart Buildings by Frost & Sullivan&nbsp;&nbsp;SourceSecurity.com","title":"Radiflow recognised as Global Customer Value Leader in IT/OT Security for Smart Buildings by Frost & Sullivan - SourceSecurity.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-27b5a9223ff781b3","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMivwFBVV95cUxQekEzUEJQaFU5cmRCeWFGNVlkNzBPVDZMR3g0Z1JDclprZ3NyM0RtNjgtLVNTekJpOWpEaldpeW9sMFBISDBTOFBaa3U1WVk5LWVsQlRlTG0yUEdESTA1VjY1elFmcnNncDBIMnVaTmxCNWZkSzVPaVV6aGdMWlhwNXZ4SkxNNlBWWVo2dTF5SHdGYW9mMnVmSWlzZGhqcmJVcTFKY19ZNG5ZMWdTM21YSDFRYVdRa1ZYdy1oMUtfdw?oc=5","published_at":"2019-06-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Increasing resiliency by segmenting the OT network based on the Purdue model -&nbsp;&nbsp;enterprisetimes.co.uk","title":"Increasing resiliency by segmenting the OT network based on the Purdue model - - enterprisetimes.co.uk"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-6778a68ddf575659","category":"Building Automation & IoT","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMivwFBVV95cUxQekEzUEJQaFU5cmRCeWFGNVlkNzBPVDZMR3g0Z1JDclprZ3NyM0RtNjgtLVNTekJpOWpEaldpeW9sMFBISDBTOFBaa3U1WVk5LWVsQlRlTG0yUEdESTA1VjY1elFmcnNncDBIMnVaTmxCNWZkSzVPaVV6aGdMWlhwNXZ4SkxNNlBWWVo2dTF5SHdGYW9mMnVmSWlzZGhqcmJVcTFKY19ZNG5ZMWdTM21YSDFRYVdRa1ZYdy1oMUtfdw?oc=5","published_at":"2019-06-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Increasing resiliency by segmenting the OT network based on the Purdue model -&nbsp;&nbsp;Enterprise Times","title":"Increasing resiliency by segmenting the OT network based on the Purdue model - - Enterprise Times"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-fcdd8a37967fc3ff","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMif0FVX3lxTE1iUWZwNWdMQXpHX0NsbnkzN2hkU2VnYm1YNXRyVzQtRlRLaHpYcHZEUGUxVGpBcXRIbkkwenhraXFoZEdvaHpaZW1pOVhwZ0ZhYlYyc0ZlWHNJU1RqTW1DbDhhOVByTHd1Qi1jaVR2Z3NVQ0ZMS0FHQlN2S2JQcjQ?oc=5","published_at":"2019-04-01T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"OT ICS Malware & Zero-Days","summary":"Main threat source to industrial computers? Mass-distributed malware&nbsp;&nbsp;Help Net Security","title":"Main threat source to industrial computers? Mass-distributed malware - Help Net Security"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7c7aa6c6c4c9dcfa","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMif0FVX3lxTE1iUWZwNWdMQXpHX0NsbnkzN2hkU2VnYm1YNXRyVzQtRlRLaHpYcHZEUGUxVGpBcXRIbkkwenhraXFoZEdvaHpaZW1pOVhwZ0ZhYlYyc0ZlWHNJU1RqTW1DbDhhOVByTHd1Qi1jaVR2Z3NVQ0ZMS0FHQlN2S2JQcjQ?oc=5","published_at":"2019-04-01T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"OT ICS Malware & Zero-Days","summary":"Main threat source to industrial computers? Mass-distributed malware&nbsp;&nbsp;helpnetsecurity.com","title":"Main threat source to industrial computers? Mass-distributed malware - helpnetsecurity.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-4721365465b8e821","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiuAFBVV95cUxNMUl2Q3EwQXhuWnN0X0w2c2xUQ2VKdmlWU1gxaWJ2VFZxbjNXNmhrSEVLMjBsckVBSWgzN0NWRmhpNlVDWTQtVjN4eDNXZXVDWHYxeDhwOGJYQzNyZEZRZFpSYkRqN08xaW5aWGJRd3d6VUlWZTRzeENZd0lmM1ZoS2VvbjJxcUw1MGlnampheXp3OHRYMGdJVS1yTzl5dnpVeGM0LWtRSUpCeUxvelFwQUxTbVRSaHcw?oc=5","published_at":"2019-02-20T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Rockwell Automation industrial energy meter vulnerable to public exploits&nbsp;&nbsp;Help Net Security","title":"Rockwell Automation industrial energy meter vulnerable to public exploits - Help Net Security"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-d1e18e4d05849eab","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMiuAFBVV95cUxNMUl2Q3EwQXhuWnN0X0w2c2xUQ2VKdmlWU1gxaWJ2VFZxbjNXNmhrSEVLMjBsckVBSWgzN0NWRmhpNlVDWTQtVjN4eDNXZXVDWHYxeDhwOGJYQzNyZEZRZFpSYkRqN08xaW5aWGJRd3d6VUlWZTRzeENZd0lmM1ZoS2VvbjJxcUw1MGlnampheXp3OHRYMGdJVS1yTzl5dnpVeGM0LWtRSUpCeUxvelFwQUxTbVRSaHcw?oc=5","published_at":"2019-02-20T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Rockwell Automation industrial energy meter vulnerable to public exploits&nbsp;&nbsp;helpnetsecurity.com","title":"Rockwell Automation industrial energy meter vulnerable to public exploits - helpnetsecurity.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-e979db9e42b57b7a","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitwFBVV95cUxPRlNDODIxTjBweEFDa2xYNlY3enlMSFNwd0t6ZzJhOWVSYUF6cEljM3BKbHZFQWVCRUdTcml0MW80UEJqNWV2dG1tU1lBOU85UUdUN0puRFktdEdMMzlTeW1xVXFDNnd1Q3M3Q1lDeDVtYkNqRjBUM0Jjenl2eEZlcXFFOC1tbXBzUGxWMDFDcGZjQnhVdUtLT1BJeU83Yi1CMXJjMnZhTHdQRV91ZHBlQy05T2RJNnM?oc=5","published_at":"2019-01-15T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Zero-Day Vulnerabilities Leave Smart Buildings Open to Cyber Attacks&nbsp;&nbsp;bleepingcomputer.com","title":"Zero-Day Vulnerabilities Leave Smart Buildings Open to Cyber Attacks - bleepingcomputer.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-c4c19f742c4b85f8","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMitwFBVV95cUxPRlNDODIxTjBweEFDa2xYNlY3enlMSFNwd0t6ZzJhOWVSYUF6cEljM3BKbHZFQWVCRUdTcml0MW80UEJqNWV2dG1tU1lBOU85UUdUN0puRFktdEdMMzlTeW1xVXFDNnd1Q3M3Q1lDeDVtYkNqRjBUM0Jjenl2eEZlcXFFOC1tbXBzUGxWMDFDcGZjQnhVdUtLT1BJeU83Yi1CMXJjMnZhTHdQRV91ZHBlQy05T2RJNnM?oc=5","published_at":"2019-01-15T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"CRITICAL","source":"Building Automation & LoRaWAN","summary":"Zero-Day Vulnerabilities Leave Smart Buildings Open to Cyber Attacks&nbsp;&nbsp;BleepingComputer","title":"Zero-Day Vulnerabilities Leave Smart Buildings Open to Cyber Attacks - BleepingComputer"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a2776ad9ed9da276","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMie0FVX3lxTFB4Rk91N1NYTlBZeG1aUXlOT0VDOU1LZFZnN252emJTUllmb0h1R0FRMm9PRVIydTR0Zko5ZmVxVVlBY3NqbWFZUzlTYjRHMVBsUkRtUVdqSU9Ia0tJY2NlZW5yV2Y4SUFocWVWUUpIbnlNOGxnUVdOQ19LUQ?oc=5","published_at":"2018-12-21T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"FBI warns industry that hackers could probe vulnerable connections in building systems&nbsp;&nbsp;CyberScoop","title":"FBI warns industry that hackers could probe vulnerable connections in building systems - CyberScoop"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b6553fc5beade059","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMie0FVX3lxTFB4Rk91N1NYTlBZeG1aUXlOT0VDOU1LZFZnN252emJTUllmb0h1R0FRMm9PRVIydTR0Zko5ZmVxVVlBY3NqbWFZUzlTYjRHMVBsUkRtUVdqSU9Ia0tJY2NlZW5yV2Y4SUFocWVWUUpIbnlNOGxnUVdOQ19LUQ?oc=5","published_at":"2018-12-21T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"FBI warns industry that hackers could probe vulnerable connections in building systems&nbsp;&nbsp;cyberscoop.com","title":"FBI warns industry that hackers could probe vulnerable connections in building systems - cyberscoop.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-693fb4aff6304a6e","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxNMHRjd2Z0dHJWcnZ1SjFQcDhUa0Y3bG56M0NoRzN2NXdzT2FqUUZnSEZ5ZFprTnY2RTNYWXJpd1ItOVdVdjM0Z3Nmei1KVzk1Smlna3lkQnZVZWtLUVhoRzVLWEtmTlY0eGRsLUFWeVBGZzdEM0Z5bmZVdmJqY1BOVjJRUURzeWd3bXM1SGd5TlBRT21CaUN1R1JXS1lQeGNlNTFUQThXdkYwdw?oc=5","published_at":"2018-11-05T08:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Inductive Automation announces Ignition Firebrand awards&nbsp;&nbsp;foodengineeringmag.com","title":"Inductive Automation announces Ignition Firebrand awards - foodengineeringmag.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-0bac2b366ff3212f","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMickFVX3lxTE9zaXZKblFzTjgyY2FjdExESnpqdFZuVnJ3T2FJMUU4dlUzcWpVZFZtRzhnTnFsdTEtLXFKcmxST2lQMVhmX0I3YUpGalNjQjU2dEZZdzlsTmd1MXdmR0lwZS1zeVVCRE9lWE5NSGsxcjN4UQ?oc=5","published_at":"2018-10-24T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"FireEye: Russian Research Lab Aided the Development of TRITON Industrial Malware&nbsp;&nbsp;thehackernews.com","title":"FireEye: Russian Research Lab Aided the Development of TRITON Industrial Malware - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-48de473c95afb4e7","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMickFVX3lxTE9zaXZKblFzTjgyY2FjdExESnpqdFZuVnJ3T2FJMUU4dlUzcWpVZFZtRzhnTnFsdTEtLXFKcmxST2lQMVhmX0I3YUpGalNjQjU2dEZZdzlsTmd1MXdmR0lwZS1zeVVCRE9lWE5NSGsxcjN4UQ?oc=5","published_at":"2018-10-24T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"FireEye: Russian Research Lab Aided the Development of TRITON Industrial Malware&nbsp;&nbsp;The Hacker News","title":"FireEye: Russian Research Lab Aided the Development of TRITON Industrial Malware - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-b0ea2f71ae0de177","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiuAFBVV95cUxQRVFSS2c3dVdqRWFlYVhVVHRjSWRPc29rMVpDWmlvNWdXUDFCNjlHLWZGRzRNbzRRb3A1VjVNR2tSRkNCR3VxMjVBMERmeW8tNm1yWEowQmUxNjlUR1FZVWpuM25ERkpYNDVUeUZTem9aU0R2cy04cUQ0UG83V2wzemlyUUZlU1N3eUlpOTRud0ZIWkdsTDlRVFhvWW94cDVVRzVSSnN6bXdkR2ZZLVYwTE1ZRzhPWlVI?oc=5","published_at":"2018-10-17T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"New GreyEnergy Malware Targets ICS, Tied with BlackEnergy and TeleBots&nbsp;&nbsp;bleepingcomputer.com","title":"New GreyEnergy Malware Targets ICS, Tied with BlackEnergy and TeleBots - bleepingcomputer.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-29cdc8a33e348582","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMieEFVX3lxTE95LVJOTzBvbU91ZVlqRHlBWWowT0RhMWQ3YTduYWN0VXY2M1lOdHNEVTFFSkJ3NWE1Q0hpaFRqTGg1emZBOTdzcWRtRjM1REVUbl9rZlI4bnNoQkJISm5fRlVkcm16MWlySG1QX2NxYk9rUVpndEFJQQ?oc=5","published_at":"2018-10-11T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Researchers link Industroyer to NotPetya&nbsp;&nbsp;helpnetsecurity.com","title":"Researchers link Industroyer to NotPetya - helpnetsecurity.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2be35dc701bd0d13","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMieEFVX3lxTE95LVJOTzBvbU91ZVlqRHlBWWowT0RhMWQ3YTduYWN0VXY2M1lOdHNEVTFFSkJ3NWE1Q0hpaFRqTGg1emZBOTdzcWRtRjM1REVUbl9rZlI4bnNoQkJISm5fRlVkcm16MWlySG1QX2NxYk9rUVpndEFJQQ?oc=5","published_at":"2018-10-11T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Researchers link Industroyer to NotPetya&nbsp;&nbsp;Help Net Security","title":"Researchers link Industroyer to NotPetya - Help Net Security"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-276356f9efbae7fe","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiqwFBVV95cUxNVlo0YWVCZFFvZmQ1a1FyUjZ6QmpXbktNdzlhUGFXOTV4dmhSWG1ncV94eW1TX3I4dUo1M184Z004T1h3NmNwbFlXc2lPWm1NZFFCTGZPRlpZYWtCSlE4WFdtU2lkM21IUmt3Mkg2MkFUc0JPc2JKbGJIZjhQYjZySzlFRUxoWkpGSEx1Ty1jWE1IOTNQdnFHUHZDV2lWbVkyd0VPS094ZkdHVVU?oc=5","published_at":"2018-09-18T07:17:06+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Seeq To Sponsor Ignition Community Conference (ICC) And Demonstrate Expanded Integration Features&nbsp;&nbsp;Water Online","title":"Seeq To Sponsor Ignition Community Conference (ICC) And Demonstrate Expanded Integration Features - Water Online"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-20a6f6e071ed9e32","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiakFVX3lxTE91SzZMZTlnV0JIQUJIYjhsNzZoSUZpWlBKSEE2WUZGODNoa1U1QlNhTTFUV1lpRG5ibkY3QlhNbm45eUJEdTV6OGZQSnVVcDJTSzE0a05CTmhLR0VnclBqODJRQVRRQURQS2c?oc=5","published_at":"2018-09-11T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"OT ICS Malware & Zero-Days","summary":"Advantech WebAccess RCE flaw still exploitable, exploit code available&nbsp;&nbsp;helpnetsecurity.com","title":"Advantech WebAccess RCE flaw still exploitable, exploit code available - helpnetsecurity.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-5be2422da4bd4ff1","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiakFVX3lxTE91SzZMZTlnV0JIQUJIYjhsNzZoSUZpWlBKSEE2WUZGODNoa1U1QlNhTTFUV1lpRG5ibkY3QlhNbm45eUJEdTV6OGZQSnVVcDJTSzE0a05CTmhLR0VnclBqODJRQVRRQURQS2c?oc=5","published_at":"2018-09-11T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"HIGH","source":"OT ICS Malware & Zero-Days","summary":"Advantech WebAccess RCE flaw still exploitable, exploit code available&nbsp;&nbsp;Help Net Security","title":"Advantech WebAccess RCE flaw still exploitable, exploit code available - Help Net Security"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-a4aab42a00324019","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiswFBVV95cUxPSy1oeWQ1cTJfS21PcjdqMHJJOTBxa1V4Q0NHcnFzbGo0RHRrSk9zNFI3MTgxTllyNmtuYVJEMGNQN0lDODVLVTgyLUhGai00a2g3c1JmRGJvcm9kamkyTU9xZWM5U3RxSkZVcTNtMGtIaGFvZUlfRXI1clBpVTVvUDRaRFVvdTNQSzRkYUFTSHlXQXc5Qnp1VkJ3NWlwQklFbktBT0tXcWk0emxPZGozbTJtUQ?oc=5","published_at":"2018-08-14T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Rice Mill Upgrades Operations With Modern SCADA&nbsp;&nbsp;automationworld.com","title":"Rice Mill Upgrades Operations With Modern SCADA - automationworld.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-f4727f994b25eed3","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiswFBVV95cUxPSy1oeWQ1cTJfS21PcjdqMHJJOTBxa1V4Q0NHcnFzbGo0RHRrSk9zNFI3MTgxTllyNmtuYVJEMGNQN0lDODVLVTgyLUhGai00a2g3c1JmRGJvcm9kamkyTU9xZWM5U3RxSkZVcTNtMGtIaGFvZUlfRXI1clBpVTVvUDRaRFVvdTNQSzRkYUFTSHlXQXc5Qnp1VkJ3NWlwQklFbktBT0tXcWk0emxPZGozbTJtUQ?oc=5","published_at":"2018-08-14T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Rice Mill Upgrades Operations With Modern SCADA&nbsp;&nbsp;Automation World","title":"Rice Mill Upgrades Operations With Modern SCADA - Automation World"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-2b9e20bef9dfe824","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiiwFBVV95cUxPdkt2YVpzS1dZSlJ3M3hhalF0OER5NE9lTmpCSzFaZ1RoeDRhS0F3TThBamxhUWZWMFdWdGxlUTJVc2NkTHg3OWY3cm1HRWRfcUZranFZTFl5bkxYendjSkRVYWRoczF5eDRZM3k2VnJ1Y3hRYTkzRFhUeEZNYkxvZG1mUzBPSjhYd240?oc=5","published_at":"2018-07-19T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"How hackers exploit critical infrastructure&nbsp;&nbsp;Help Net Security","title":"How hackers exploit critical infrastructure - Help Net Security"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-ccfddb598e9ab27d","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMiiwFBVV95cUxPdkt2YVpzS1dZSlJ3M3hhalF0OER5NE9lTmpCSzFaZ1RoeDRhS0F3TThBamxhUWZWMFdWdGxlUTJVc2NkTHg3OWY3cm1HRWRfcUZranFZTFl5bkxYendjSkRVYWRoczF5eDRZM3k2VnJ1Y3hRYTkzRFhUeEZNYkxvZG1mUzBPSjhYd240?oc=5","published_at":"2018-07-19T07:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"How hackers exploit critical infrastructure&nbsp;&nbsp;helpnetsecurity.com","title":"How hackers exploit critical infrastructure - helpnetsecurity.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8507990508837e94","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiZkFVX3lxTE1sWDVuVi03WFo5VU81MUVSYlZWbEpyaEF4czhOa2g3ZEFjNi1FcW9uU1Vya21OcHR6TmVyOTJidnBCbjM2UXZEUW5XNWdfejE2ejQ4eW1hb0QzZzgtZU1ZX2V3ZnpwZw?oc=5","published_at":"2018-01-16T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Trisis has the security world spooked, stumped and searching for answers&nbsp;&nbsp;cyberscoop.com","title":"Trisis has the security world spooked, stumped and searching for answers - cyberscoop.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8988880e7c32a37a","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiZkFVX3lxTE1sWDVuVi03WFo5VU81MUVSYlZWbEpyaEF4czhOa2g3ZEFjNi1FcW9uU1Vya21OcHR6TmVyOTJidnBCbjM2UXZEUW5XNWdfejE2ejQ4eW1hb0QzZzgtZU1ZX2V3ZnpwZw?oc=5","published_at":"2018-01-16T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Trisis has the security world spooked, stumped and searching for answers&nbsp;&nbsp;CyberScoop","title":"Trisis has the security world spooked, stumped and searching for answers - CyberScoop"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-919a7bf9f2ce751d","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMilAFBVV95cUxNSFlEcTFpU1pfa2paMC1sV09HSnRvMDl2dTgwTU9yQ0xCRmR6OVpNbERpamkwM0ZETVhJejZ1Y3VhUE5PSkdPY1lHV2w0cDBQQzRCT211ME5lN1U2YUdaVlowWm9SYkZBUkhMRGtDUVJOX2V3b1plZzh6WWpVSWFVU1cwRGd3NkJfNk85SnQtb2NiQ3Nw0gGaAUFVX3lxTE10QTVxaVNrWG5MdDFVb1pkelpwbEpCSDZvVGdLd2RiaDlFTzJzbU1xLTlhMU5TTVF3WHBEZE5tR2U3SzZyd2JPXzJjMDFJLVdoOV9JWW1IWlZaZk16cmZST2VnSHI4MHV2RGVTTkJDbDVpeFlXbUs3QzhiaUNwWHY2OXJ1ODFvOGdXdGxsZ3RycDUwRkoxSkVYWFE?oc=5","published_at":"2018-01-10T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Rockwell Automation Patches Serious Flaw in MicroLogix 1400 PLC&nbsp;&nbsp;SecurityWeek","title":"Rockwell Automation Patches Serious Flaw in MicroLogix 1400 PLC - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-302d405c8c78f8b6","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMilAFBVV95cUxNSFlEcTFpU1pfa2paMC1sV09HSnRvMDl2dTgwTU9yQ0xCRmR6OVpNbERpamkwM0ZETVhJejZ1Y3VhUE5PSkdPY1lHV2w0cDBQQzRCT211ME5lN1U2YUdaVlowWm9SYkZBUkhMRGtDUVJOX2V3b1plZzh6WWpVSWFVU1cwRGd3NkJfNk85SnQtb2NiQ3Nw0gGaAUFVX3lxTE10QTVxaVNrWG5MdDFVb1pkelpwbEpCSDZvVGdLd2RiaDlFTzJzbU1xLTlhMU5TTVF3WHBEZE5tR2U3SzZyd2JPXzJjMDFJLVdoOV9JWW1IWlZaZk16cmZST2VnSHI4MHV2RGVTTkJDbDVpeFlXbUs3QzhiaUNwWHY2OXJ1ODFvOGdXdGxsZ3RycDUwRkoxSkVYWFE?oc=5","published_at":"2018-01-10T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"MEDIUM","source":"Rockwell & CIP Security","summary":"Rockwell Automation Patches Serious Flaw in MicroLogix 1400 PLC&nbsp;&nbsp;securityweek.com","title":"Rockwell Automation Patches Serious Flaw in MicroLogix 1400 PLC - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-fffbef76557e5133","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMicEFVX3lxTE5ZekxiZ1pOVUdLM1JXdWt6NDJ0S0VlTnVEMkpIdURKMlZ4c2N1bnlfemIwMDBvSkpVUmd4Ymt0YVMzYXdfZFg0UlFUSGJhcHlLSGk1ai1VUkZZeklfZGhCaUFPb2J6MmwxOEZFaDBlWDE?oc=5","published_at":"2017-12-15T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"TRITON Malware Targeting Critical Infrastructure Could Cause Physical Damage&nbsp;&nbsp;thehackernews.com","title":"TRITON Malware Targeting Critical Infrastructure Could Cause Physical Damage - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)","aws-hub (xx.xx.xx.95)"],"affected_services":["Full XWORKS Sovereign Enclave","Suricata ICS DPI","Pi-hole Perimeter DNS","Datadog / Splunk Shipper"],"alert_id":"intel-9c8d1ceaeef9c09e","category":"Critical Infrastructure & APT","cve_ids":[],"impact_assessment":"Living-off-the-land (LotL) reconnaissance, administrative credential harvesting, or lateral traversal across industrial segments.","link":"https://news.google.com/rss/articles/CBMicEFVX3lxTE5ZekxiZ1pOVUdLM1JXdWt6NDJ0S0VlTnVEMkpIdURKMlZ4c2N1bnlfemIwMDBvSkpVUmd4Ymt0YVMzYXdfZFg0UlFUSGJhcHlLSGk1ai1VUkZZeklfZGhCaUFPb2J6MmwxOEZFaDBlWDE?oc=5","published_at":"2017-12-15T08:00:00+00:00","purdue_level":"Comprehensive Purdue Architecture (L1 through L4)","recommended_action":"Audit SSH key-only logins, disable local password auth, inspect Pi-hole upstream query anomalies, and review Suricata telemetry alerts.","severity":"CRITICAL","source":"OT ICS Malware & Zero-Days","summary":"TRITON Malware Targeting Critical Infrastructure Could Cause Physical Damage&nbsp;&nbsp;The Hacker News","title":"TRITON Malware Targeting Critical Infrastructure Could Cause Physical Damage - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1b07e81077c98c1b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMicEFVX3lxTE1DcVZfYzJHZ0ZDZWxObG5YRnlIWWNqZWV1QXNVVmJiUzVZV2NmcUZrWEMwdjR3MFFGUGJHaFRYY0NlU0ZpaWgtazVBbVNXd3ByNzRxeTdzbFd2VVY5dV9PcG1vNWVDWE5GbXVHTDNRWkg?oc=5","published_at":"2017-12-14T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Triton: New Malware Threatens Industrial Safety Systems&nbsp;&nbsp;security.com","title":"Triton: New Malware Threatens Industrial Safety Systems - security.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9e1d626d96458ee0","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMicEFVX3lxTE1DcVZfYzJHZ0ZDZWxObG5YRnlIWWNqZWV1QXNVVmJiUzVZV2NmcUZrWEMwdjR3MFFGUGJHaFRYY0NlU0ZpaWgtazVBbVNXd3ByNzRxeTdzbFd2VVY5dV9PcG1vNWVDWE5GbXVHTDNRWkg?oc=5","published_at":"2017-12-14T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Triton: New Malware Threatens Industrial Safety Systems&nbsp;&nbsp;SECURITY.COM","title":"Triton: New Malware Threatens Industrial Safety Systems - SECURITY.COM"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9ed8374e3c5ed06d","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiwwFBVV95cUxPX2twc29tSDNBclZQNzE4QzdNOHBLNlBLNGtGcS1VQUFZRi04eVUycHNvaHZQd2lYcWdIU2hfV0FvNGt1ZTVhd05aWUVJYzc2RHA5NE1TV3ZsQ2VpcGl0VlFoQnJUeUI5XzUwTkQ5SXg5VV9fOXJxVVFLTTZ6RU5Lak1vRTFWUjc3eTA2eTVTa2NoMENSanZhaHdLNmRyemdaQ211MTc5SVVhSndxSXRqUkVteXJPckVOeGVuOEl4VTR2am8?oc=5","published_at":"2017-11-20T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"2018 Predictions & Recommendations: Automated Threat Response Technology in OT Grows Up&nbsp;&nbsp;paloaltonetworks.com","title":"2018 Predictions & Recommendations: Automated Threat Response Technology in OT Grows Up - paloaltonetworks.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d5f114e61fe98968","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiwwFBVV95cUxPX2twc29tSDNBclZQNzE4QzdNOHBLNlBLNGtGcS1VQUFZRi04eVUycHNvaHZQd2lYcWdIU2hfV0FvNGt1ZTVhd05aWUVJYzc2RHA5NE1TV3ZsQ2VpcGl0VlFoQnJUeUI5XzUwTkQ5SXg5VV9fOXJxVVFLTTZ6RU5Lak1vRTFWUjc3eTA2eTVTa2NoMENSanZhaHdLNmRyemdaQ211MTc5SVVhSndxSXRqUkVteXJPckVOeGVuOEl4VTR2am8?oc=5","published_at":"2017-11-20T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"2018 Predictions & Recommendations: Automated Threat Response Technology in OT Grows Up&nbsp;&nbsp;Palo Alto Networks","title":"2018 Predictions & Recommendations: Automated Threat Response Technology in OT Grows Up - Palo Alto Networks"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-80bda69a84a98cff","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxNLWRld1V0ZW81cWFmcldiQTNmUl9ubmZvT0ZBa2NFRXp6Q1ZnalVqTEh3dWtBMkNUWk9nZ3FDSm9HcnZxU0dHMXhfZlpOc1FXb0pOUTNJQ1BxQy04VHZySExwQVNtU29HdEdCeTY5Y0c1T3ZDSm0zV25lVnpxLTRQZU5TNGxtMElrbHlrNGRYdXUwYUE1b3hwWDE4S2RHVG8?oc=5","published_at":"2017-07-12T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Keys in Ignition&nbsp;&nbsp;Wastewater Digest","title":"Keys in Ignition - Wastewater Digest"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-ef53d8455be9017e","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMinwFBVV95cUxNLWRld1V0ZW81cWFmcldiQTNmUl9ubmZvT0ZBa2NFRXp6Q1ZnalVqTEh3dWtBMkNUWk9nZ3FDSm9HcnZxU0dHMXhfZlpOc1FXb0pOUTNJQ1BxQy04VHZySExwQVNtU29HdEdCeTY5Y0c1T3ZDSm0zV25lVnpxLTRQZU5TNGxtMElrbHlrNGRYdXUwYUE1b3hwWDE4S2RHVG8?oc=5","published_at":"2017-07-12T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"Ignition SCADA Security","summary":"Keys in Ignition&nbsp;&nbsp;wwdmag.com","title":"Keys in Ignition - wwdmag.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-bf64b0a8bdff8a19","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisgFBVV95cUxPcFJNajVBYllnUFNHRzlIRlJhc1ZEUXA5d0o1SVpuaDU2Y0JOd1VpeERyaUdJd0JwbHdmeXIzVVE0RG1PeHBiNjhMUjZmSFktUEY0b1l6c3p4UkpuaUFEbk5JNDBlY1BIYW9MWU1MRnFLSHpSV3VlZDhiSS1RM0ZGSFZnWWR1aXJiYmRyWmlZTktkQWIxQ0dFVzJCR1MzNWVDUF83WEk4MUxOZEZTdmpMVkZB?oc=5","published_at":"2017-06-14T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"CrashOverride/Industroyer: Protections for Palo Alto Networks Customers&nbsp;&nbsp;paloaltonetworks.com","title":"CrashOverride/Industroyer: Protections for Palo Alto Networks Customers - paloaltonetworks.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-ac91eef83de5c040","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMisgFBVV95cUxPcFJNajVBYllnUFNHRzlIRlJhc1ZEUXA5d0o1SVpuaDU2Y0JOd1VpeERyaUdJd0JwbHdmeXIzVVE0RG1PeHBiNjhMUjZmSFktUEY0b1l6c3p4UkpuaUFEbk5JNDBlY1BIYW9MWU1MRnFLSHpSV3VlZDhiSS1RM0ZGSFZnWWR1aXJiYmRyWmlZTktkQWIxQ0dFVzJCR1MzNWVDUF83WEk4MUxOZEZTdmpMVkZB?oc=5","published_at":"2017-06-14T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"CrashOverride/Industroyer: Protections for Palo Alto Networks Customers&nbsp;&nbsp;Palo Alto Networks","title":"CrashOverride/Industroyer: Protections for Palo Alto Networks Customers - Palo Alto Networks"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-4b4be618e4f3a076","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilgFBVV95cUxPV0M3NWVuQ2dkdmczSXNZOENhTVV5WXZEWWx3LTZnclpXa0pvb2kxQ0ZBSmpNM0VFdEZ6cFNvX09aRmdpRkd3endveFYwV0tibWVBX1NyNEVGOHdwajJCTk1SRmZ6LVowX3cyN3VMZnFuZDZIQWJNaVZfeXl0VmRyT2VzUmJsU19EN3J1b09XX3B6TjBwREE?oc=5","published_at":"2017-06-12T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"New \"Industroyer\" Malware Targets Power Grids&nbsp;&nbsp;bleepingcomputer.com","title":"New \"Industroyer\" Malware Targets Power Grids - bleepingcomputer.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-8d8ef2019dea9071","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMilgFBVV95cUxPV0M3NWVuQ2dkdmczSXNZOENhTVV5WXZEWWx3LTZnclpXa0pvb2kxQ0ZBSmpNM0VFdEZ6cFNvX09aRmdpRkd3endveFYwV0tibWVBX1NyNEVGOHdwajJCTk1SRmZ6LVowX3cyN3VMZnFuZDZIQWJNaVZfeXl0VmRyT2VzUmJsU19EN3J1b09XX3B6TjBwREE?oc=5","published_at":"2017-06-12T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"New \"Industroyer\" Malware Targets Power Grids&nbsp;&nbsp;BleepingComputer","title":"New \"Industroyer\" Malware Targets Power Grids - BleepingComputer"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-ae2b2cef63531bb1","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMifEFVX3lxTE5RVGNyMmhZTXdDZVBfSGxOVHpXTDY2SFlyTHVrbWl4eU5kWVBBTjBVaXR0azd3dmlwbmlOekl2SnlSZXM3Z0hzaTBsSnlXVmlPWXJGeFNPSnRDSURteWNlb2lXd2JsdWxQb0E4LTJZTG0wblA1V2p6WHJGY3Q?oc=5","published_at":"2017-03-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Malware posing as Siemens PLC software is hitting industrial environments&nbsp;&nbsp;helpnetsecurity.com","title":"Malware posing as Siemens PLC software is hitting industrial environments - helpnetsecurity.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-98dabf15729bb928","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMifEFVX3lxTE5RVGNyMmhZTXdDZVBfSGxOVHpXTDY2SFlyTHVrbWl4eU5kWVBBTjBVaXR0azd3dmlwbmlOekl2SnlSZXM3Z0hzaTBsSnlXVmlPWXJGeFNPSnRDSURteWNlb2lXd2JsdWxQb0E4LTJZTG0wblA1V2p6WHJGY3Q?oc=5","published_at":"2017-03-23T07:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Malware posing as Siemens PLC software is hitting industrial environments&nbsp;&nbsp;Help Net Security","title":"Malware posing as Siemens PLC software is hitting industrial environments - Help Net Security"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-fc1b1a4d99035a92","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMia0FVX3lxTE44SHBFM1V2UFRERldPTlJBSlp3S21NQVpNZ0JVbmNxNk5vRWhwT3dXTGY1TWNJZzA2MjRPV0tpR1lDU3hPanNGZ1V0Z01vc3RZalAwY3B5OWJ5VWxkaW5zUEVrd1hMcExDSnhJ?oc=5","published_at":"2017-02-21T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Detecting PLC malware in industrial control systems&nbsp;&nbsp;Help Net Security","title":"Detecting PLC malware in industrial control systems - Help Net Security"},{"affected_nodes":["x1 (xx.xx.xx.139)","x2 (xx.xx.xx.146)"],"affected_services":["EMQ Neuron Edge Gateway (30700)","Node-RED CIP Driver","Suricata ICS DPI"],"alert_id":"intel-751ba571ec846822","category":"PLC & Controller Firmware","cve_ids":[],"impact_assessment":"Manipulated industrial protocol command injection, unauthorized PLC operational mode toggle, or memory buffer overflow.","link":"https://news.google.com/rss/articles/CBMia0FVX3lxTE44SHBFM1V2UFRERldPTlJBSlp3S21NQVpNZ0JVbmNxNk5vRWhwT3dXTGY1TWNJZzA2MjRPV0tpR1lDU3hPanNGZ1V0Z01vc3RZalAwY3B5OWJ5VWxkaW5zUEVrd1hMcExDSnhJ?oc=5","published_at":"2017-02-21T08:00:00+00:00","purdue_level":"Level 1 Basic Control & Level 2 Area Supervisory","recommended_action":"Enforce Purdue L2/L3 firewall boundary via Suricata ICS DPI rules, disable public PLC traversal, and restrict Neuron to internal isolated subnets.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Detecting PLC malware in industrial control systems&nbsp;&nbsp;helpnetsecurity.com","title":"Detecting PLC malware in industrial control systems - helpnetsecurity.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-7f7987b3c624f6e2","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMibkFVX3lxTE9XVGhSVlVXLWJhaFNudHZKMVY3MldFWmNGLXB2NTRHWnpOWHFkLXJyRFBEbEpkUWhob01JWmZocmEwQVRwS0c4Qm53Y0duUzcteE5fdlN2N282N0ZlZExPVlRxQTRfZ19ZRmY4X2lR?oc=5","published_at":"2017-02-17T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"This Ransomware Malware Could Poison Your Water Supply If Not Paid&nbsp;&nbsp;thehackernews.com","title":"This Ransomware Malware Could Poison Your Water Supply If Not Paid - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-9b1d523e90d1b54a","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMibkFVX3lxTE9XVGhSVlVXLWJhaFNudHZKMVY3MldFWmNGLXB2NTRHWnpOWHFkLXJyRFBEbEpkUWhob01JWmZocmEwQVRwS0c4Qm53Y0duUzcteE5fdlN2N282N0ZlZExPVlRxQTRfZ19ZRmY4X2lR?oc=5","published_at":"2017-02-17T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"This Ransomware Malware Could Poison Your Water Supply If Not Paid&nbsp;&nbsp;The Hacker News","title":"This Ransomware Malware Could Poison Your Water Supply If Not Paid - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-a3bea1f53f204314","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMisgFBVV95cUxQS0w4UlR3TkZ1cXM4cHNoQ3RocV9xSmFGdGR1Q2tZbEFTTzQ1TTRTaDdHUFMtWlJ6YjhrTi1jeTZLSE5jWlI0TFlLZEF5S18zMGI4MVlOQjlETlRmRU95TmhNUDVQaVdrcHlCWkRGdU5BT1Zid1NHdnM1UTNNNXFVUGM5RnF5cEMtWHdIZlg1NkxFZUo3ZElRMzZkNXZkUWJRUUdmcjVKOWJodDFoTVg5WFVR?oc=5","published_at":"2017-02-14T08:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Researchers Create PoC Ransomware That Targets ICS/SCADA Systems&nbsp;&nbsp;bleepingcomputer.com","title":"Researchers Create PoC Ransomware That Targets ICS/SCADA Systems - bleepingcomputer.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-494b872e1dbbfd76","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMisgFBVV95cUxQS0w4UlR3TkZ1cXM4cHNoQ3RocV9xSmFGdGR1Q2tZbEFTTzQ1TTRTaDdHUFMtWlJ6YjhrTi1jeTZLSE5jWlI0TFlLZEF5S18zMGI4MVlOQjlETlRmRU95TmhNUDVQaVdrcHlCWkRGdU5BT1Zid1NHdnM1UTNNNXFVUGM5RnF5cEMtWHdIZlg1NkxFZUo3ZElRMzZkNXZkUWJRUUdmcjVKOWJodDFoTVg5WFVR?oc=5","published_at":"2017-02-14T08:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Researchers Create PoC Ransomware That Targets ICS/SCADA Systems&nbsp;&nbsp;BleepingComputer","title":"Researchers Create PoC Ransomware That Targets ICS/SCADA Systems - BleepingComputer"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-76417e218a6baa75","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxNWERuanVqbWZ4MEcwbGpuSUMwX0Q2UWU0WUl6NTlLYkVNalg0S2c1c0x2QUZQcUY2endVb243YlRINF9tZnR6LVpCbURVWWlWZWVwQWpwWjhWMm90NE44eDYzTmFKM1daWWpwRVZyWHF2Z2FuRXNqNHJwajdnOWU1VTd30gGKAUFVX3lxTE5xTl9NblM5eHpkdnctZG9PYVpBd1RSNHphYUhQbXYyZm1LLVgybXlUN3RkR1RETlowWGFJM2I0SHlIMDFrRVhUYS1EOXYzclVEZGUxRTFwSWpaaHFoVEY0WVhNQ0E0cXB3TlpQWU0ybnMxeFNjdi1iWkJGbjVZYVkyb3dHZFJJNDMyUQ?oc=5","published_at":"2016-12-30T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Industrial Network Security&nbsp;&nbsp;techtarget.com","title":"Industrial Network Security - techtarget.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1840dd3fa5afc628","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiggFBVV95cUxNWERuanVqbWZ4MEcwbGpuSUMwX0Q2UWU0WUl6NTlLYkVNalg0S2c1c0x2QUZQcUY2endVb243YlRINF9tZnR6LVpCbURVWWlWZWVwQWpwWjhWMm90NE44eDYzTmFKM1daWWpwRVZyWHF2Z2FuRXNqNHJwajdnOWU1VTd30gGKAUFVX3lxTE5xTl9NblM5eHpkdnctZG9PYVpBd1RSNHphYUhQbXYyZm1LLVgybXlUN3RkR1RETlowWGFJM2I0SHlIMDFrRVhUYS1EOXYzclVEZGUxRTFwSWpaaHFoVEY0WVhNQ0E0cXB3TlpQWU0ybnMxeFNjdi1iWkJGbjVZYVkyb3dHZFJJNDMyUQ?oc=5","published_at":"2016-12-30T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Industrial Network Security&nbsp;&nbsp;TechTarget","title":"Industrial Network Security - TechTarget"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-5a376d3a436c9b83","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMigAFBVV95cUxOLVdVbXhoOEFPOTMxMkJrNzl4Z0U2NDBKRElER0l0OE0tSXd2WWFVWmFERGdSYlZ5TzhZYUR6NTU1S25mMkFVMlZUX0JHRVZLY0FQZmQ3Q1hVSVZjWGpKbFNLYWxEYXBUanI4Z09IRUFEX1ROd1c3amZ2UUM4Z2lubtIBhgFBVV95cUxOSFc3ampzalN5Q2FPRXV2a3g3Rmk3OTBIRWpGckxhY2FLTVVDVnJWN19pTk8wVFRMZjZpWVpSdzlQSHJIbDlONG9zamc4MUpYNHJ6X3U2blVfbjV0XzU5Sm1zR0ZyNS1FRzF0U3BSVmg0cGtrbEQ1TVNvWWdiQjg3U3ZQY1Njdw?oc=5","published_at":"2016-08-09T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Air Gap or Not, Why ICS/SCADA Networks Are at Risk&nbsp;&nbsp;SecurityWeek","title":"Air Gap or Not, Why ICS/SCADA Networks Are at Risk - SecurityWeek"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-4548fe5ade33c7ff","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMigAFBVV95cUxOLVdVbXhoOEFPOTMxMkJrNzl4Z0U2NDBKRElER0l0OE0tSXd2WWFVWmFERGdSYlZ5TzhZYUR6NTU1S25mMkFVMlZUX0JHRVZLY0FQZmQ3Q1hVSVZjWGpKbFNLYWxEYXBUanI4Z09IRUFEX1ROd1c3amZ2UUM4Z2lubtIBhgFBVV95cUxOSFc3ampzalN5Q2FPRXV2a3g3Rmk3OTBIRWpGckxhY2FLTVVDVnJWN19pTk8wVFRMZjZpWVpSdzlQSHJIbDlONG9zamc4MUpYNHJ6X3U2blVfbjV0XzU5Sm1zR0ZyNS1FRzF0U3BSVmg0cGtrbEQ1TVNvWWdiQjg3U3ZQY1Njdw?oc=5","published_at":"2016-08-09T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Air Gap or Not, Why ICS/SCADA Networks Are at Risk&nbsp;&nbsp;securityweek.com","title":"Air Gap or Not, Why ICS/SCADA Networks Are at Risk - securityweek.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-97c3c20e85a940bd","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMie0FVX3lxTFBSdERCaHVNLVNqSEFiOVYtN1I4NlNRUFJ2YWtsVTc0UXkxRC1NcDROU29WNWRFT3JLaFlOZHBRM0lpeThnRUFtYXdhS0tSQjFIODZLSWF6Z3paai02S0FOUVBjd3V2LXM4dHBIRnpzODdKQlAxTnoxUFlMbw?oc=5","published_at":"2016-07-11T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Industrial cybersecurity threat landscape&nbsp;&nbsp;Securelist","title":"Industrial cybersecurity threat landscape - Securelist"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-43bb77c19496511d","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxNaEdlMnJWMldIQlFrcm0tTlpVejJuU1M5UHo2VkhFOWpwMC1vcG93QnV6SGNiQXJRbEoyWTdTWGR5QUVmTXBIRGRvRWVsOVdaV1dOWlpTeGxORzllMGNHbnFka3NxMHlLXzBFSHlzbWhZTWtCWU8tRUdmTk5ITng4dTVGSEVXaUgwbWlFXzNvc2NiN1czd1NGbWFvTXJHWThvcDhJNkhaZ245dw?oc=5","published_at":"2016-06-02T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Shades Of Stuxnet Spotted In Newly Found ICS/SCADA Malware&nbsp;&nbsp;darkreading.com","title":"Shades Of Stuxnet Spotted In Newly Found ICS/SCADA Malware - darkreading.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-2596bec08af1b9fd","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMidkFVX3lxTFBUZkEtWjF2aVdzNzBpSG8zNjhMTUE0SW1PQUNwY21xUlJseVVyTUNjUmM1V2VXT1JUbmJ0SV9IRm9QWWp1bkdlWE1IRGVhVnQ0ZVZvaG8wRUlLMzJvZmg4YzdLWWMwTHMyekNIOC1oVG1aRUVQT1HSAXtBVV95cUxNZGtwZlE5TmpWWlBzcUp4R0RZblBpNnE0MXZLWFhWaGZZUjBQenFuTTlRUGRiQ2NwRGRkVndfRVp2UTRacnhkbmJtNFpzT1J5YUN4LUZDSWFrbV9pSlVJRWxGcE03TVR1OGhLQzBhWnhab0hsczhESmQyaHc?oc=5","published_at":"2016-06-02T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"IRONGATE, a mysterious ICS Malware discovered in the wild&nbsp;&nbsp;securityaffairs.com","title":"IRONGATE, a mysterious ICS Malware discovered in the wild - securityaffairs.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-6b54319f759c987f","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxNaEdlMnJWMldIQlFrcm0tTlpVejJuU1M5UHo2VkhFOWpwMC1vcG93QnV6SGNiQXJRbEoyWTdTWGR5QUVmTXBIRGRvRWVsOVdaV1dOWlpTeGxORzllMGNHbnFka3NxMHlLXzBFSHlzbWhZTWtCWU8tRUdmTk5ITng4dTVGSEVXaUgwbWlFXzNvc2NiN1czd1NGbWFvTXJHWThvcDhJNkhaZ245dw?oc=5","published_at":"2016-06-02T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Shades Of Stuxnet Spotted In Newly Found ICS/SCADA Malware&nbsp;&nbsp;Dark Reading","title":"Shades Of Stuxnet Spotted In Newly Found ICS/SCADA Malware - Dark Reading"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-a2d2eef8ec01f66b","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMidkFVX3lxTFBUZkEtWjF2aVdzNzBpSG8zNjhMTUE0SW1PQUNwY21xUlJseVVyTUNjUmM1V2VXT1JUbmJ0SV9IRm9QWWp1bkdlWE1IRGVhVnQ0ZVZvaG8wRUlLMzJvZmg4YzdLWWMwTHMyekNIOC1oVG1aRUVQT1HSAXtBVV95cUxNZGtwZlE5TmpWWlBzcUp4R0RZblBpNnE0MXZLWFhWaGZZUjBQenFuTTlRUGRiQ2NwRGRkVndfRVp2UTRacnhkbmJtNFpzT1J5YUN4LUZDSWFrbV9pSlVJRWxGcE03TVR1OGhLQzBhWnhab0hsczhESmQyaHc?oc=5","published_at":"2016-06-02T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"IRONGATE, a mysterious ICS Malware discovered in the wild&nbsp;&nbsp;Security Affairs","title":"IRONGATE, a mysterious ICS Malware discovered in the wild - Security Affairs"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-d1a7edaca4e2d1ef","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMifEFVX3lxTE1tT3lZODdZeUZZT1g3TE8wLVJHRlFpR0NzT00zNUdfVGpIWFVaMUoxR2t1MTFNTHduMnBIYWU0Tl9fUHBVUlNJWF9EbHVUVnpOeUNSQVh3OTRpdllNaWVqLS1YZlhWOVY2OGZ5OGhld0VpTGRpRzhRaEhEMzA?oc=5","published_at":"2016-04-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Malware at German Nuke Plant Leads to Shutdown&nbsp;&nbsp;POWER Magazine","title":"Malware at German Nuke Plant Leads to Shutdown - POWER Magazine"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-1bf5c393f81813f8","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMifEFVX3lxTE1tT3lZODdZeUZZT1g3TE8wLVJHRlFpR0NzT00zNUdfVGpIWFVaMUoxR2t1MTFNTHduMnBIYWU0Tl9fUHBVUlNJWF9EbHVUVnpOeUNSQVh3OTRpdllNaWVqLS1YZlhWOVY2OGZ5OGhld0VpTGRpRzhRaEhEMzA?oc=5","published_at":"2016-04-27T07:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Malware at German Nuke Plant Leads to Shutdown&nbsp;&nbsp;powermag.com","title":"Malware at German Nuke Plant Leads to Shutdown - powermag.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-36f55f3713b968f5","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxPX3ZhaG1JS0FlbjdlQ0xPUERFdUhyMklSTmFTVzVjOUM0OHA0NHBveHl5ZUNXZ0MtZDZFQ3h6bkQ4c2xWblZLN2lVNmdkZTRyV3RtcThETVZkLTd1bUh4R2g4dWozSDZYZFhYcEJLdDJESEh0OUJvRXZMYTN6a05OMTJhUDJwc3p3NUtfcVY2bFpnTmN6ZE0xam9BX2NfdUFxNTlBczZtcXY?oc=5","published_at":"2016-04-02T07:23:58+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Industrial Control System (ICS) Security Market Report 2026-2031, By Application, Geo, Tech&nbsp;&nbsp;marketsandmarkets.com","title":"Industrial Control System (ICS) Security Market Report 2026-2031, By Application, Geo, Tech - marketsandmarkets.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-cd41990f6f3db112","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqAFBVV95cUxPX3ZhaG1JS0FlbjdlQ0xPUERFdUhyMklSTmFTVzVjOUM0OHA0NHBveHl5ZUNXZ0MtZDZFQ3h6bkQ4c2xWblZLN2lVNmdkZTRyV3RtcThETVZkLTd1bUh4R2g4dWozSDZYZFhYcEJLdDJESEh0OUJvRXZMYTN6a05OMTJhUDJwc3p3NUtfcVY2bFpnTmN6ZE0xam9BX2NfdUFxNTlBczZtcXY?oc=5","published_at":"2016-04-02T07:23:58+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Industrial Control System (ICS) Security Market Report 2026-2031, By Application, Geo, Tech&nbsp;&nbsp;MarketsandMarkets","title":"Industrial Control System (ICS) Security Market Report 2026-2031, By Application, Geo, Tech - MarketsandMarkets"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-3376a615a22feb33","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxPcVgwd1JDY3YxSXRXZ0tFVk5RQUQxRzc3RFc3dWFuOGxDbmhDeE9DaWdSTkNoWGVuMUtJMFZJLUdUeEFMX0p5eENXSWRiWFlGblBQWUJEYlJCcldvSDU5NmtUS3dHbEdNbzlENEZVbl9KSzc4QmlTTUdBV09QN3MyMl82NHM0ZnY0eXFRbFR4MFRIR2JkVEcwUERhcDI2YllteF9KeV9nbkV5QQ?oc=5","published_at":"2016-01-22T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Condortech Services, Inc. Continues Commitment to Protect the Homeland and to Bolster National Defense Through Cyber Security Awareness at Building Control Systems Cyber Resilience Workshop&nbsp;&nbsp;Newswire.com","title":"Condortech Services, Inc. Continues Commitment to Protect the Homeland and to Bolster National Defense Through Cyber Security Awareness at Building Control Systems Cyber Resilience Workshop - Newswire.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-53b9b0b74319d2f6","category":"Perimeter & Cloud Security","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxPcVgwd1JDY3YxSXRXZ0tFVk5RQUQxRzc3RFc3dWFuOGxDbmhDeE9DaWdSTkNoWGVuMUtJMFZJLUdUeEFMX0p5eENXSWRiWFlGblBQWUJEYlJCcldvSDU5NmtUS3dHbEdNbzlENEZVbl9KSzc4QmlTTUdBV09QN3MyMl82NHM0ZnY0eXFRbFR4MFRIR2JkVEcwUERhcDI2YllteF9KeV9nbkV5QQ?oc=5","published_at":"2016-01-22T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"INFO","source":"Building Automation & LoRaWAN","summary":"Condortech Services, Inc. Continues Commitment to Protect the Homeland and to Bolster National Defense Through Cyber Security Awareness at Building Control Systems Cyber Resilience Workshop&nbsp;&nbsp;newswire.com","title":"Condortech Services, Inc. Continues Commitment to Protect the Homeland and to Bolster National Defense Through Cyber Security Awareness at Building Control Systems Cyber Resilience Workshop - newswire.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-17fb2643512dcc70","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihgFBVV95cUxNcHpmc3hMQnA0OWk4UVVQc1dLd3lpN3pkdzBhUkszWDJqb3h3bDZ4OERMZUZuazBHaU1hU2xnMnBDa3ktaHZ1bVh0SXJ1T1VjTkU3djUzdFpWUU9rWmZJVVpEM29OczU2UDk2aVpwLVpuYUZ1RnRkc1pkQzJGRlpHeW9rLTNGQdIBiwFBVV95cUxNWDZhZWtnQ3lBY2JnZ3d6eDRKN1hDRjdXdWN2LURtRHZiYzdzek4tNWRyZ3BFamtRVGJUUDAyak9BNl9FNzY2SWhLMHlMbDMweGlObGtXeTZtQnNZUTNlVlNPeVBxZEJoUTl0SU1KdEJBZ3QyZG5NRHBOR3lpaFNWUklDcFMyWi00S1Vj?oc=5","published_at":"2014-12-12T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"OT ICS Malware & Zero-Days","summary":"BlackEnergy exploits recently fixed flaws in Siemens WinCC&nbsp;&nbsp;securityaffairs.com","title":"BlackEnergy exploits recently fixed flaws in Siemens WinCC - securityaffairs.com"},{"affected_nodes":["x1 (xx.xx.xx.139)","aws-hub (xx.xx.xx.95)"],"affected_services":["Pi-hole DNS Sinkhole","PostgreSQL Database (5432)","Cloudflare SSL Proxy"],"alert_id":"intel-554813eeed1df031","category":"Zero-Day & CISA KEV","cve_ids":[],"impact_assessment":"DNS cache poisoning attempts, external scanning against HTTP/HTTPS ports, or database connection brute-force.","link":"https://news.google.com/rss/articles/CBMihgFBVV95cUxNcHpmc3hMQnA0OWk4UVVQc1dLd3lpN3pkdzBhUkszWDJqb3h3bDZ4OERMZUZuazBHaU1hU2xnMnBDa3ktaHZ1bVh0SXJ1T1VjTkU3djUzdFpWUU9rWmZJVVpEM29OczU2UDk2aVpwLVpuYUZ1RnRkc1pkQzJGRlpHeW9rLTNGQdIBiwFBVV95cUxNWDZhZWtnQ3lBY2JnZ3d6eDRKN1hDRjdXdWN2LURtRHZiYzdzek4tNWRyZ3BFamtRVGJUUDAyak9BNl9FNzY2SWhLMHlMbDMweGlObGtXeTZtQnNZUTNlVlNPeVBxZEJoUTl0SU1KdEJBZ3QyZG5NRHBOR3lpaFNWUklDcFMyWi00S1Vj?oc=5","published_at":"2014-12-12T08:00:00+00:00","purdue_level":"Level 3 Enterprise Boundary & DMZ","recommended_action":"Maintain Cloudflare proxy isolation, verify Pi-hole blacklist sinkhole status, and restrict PostgreSQL to internal cluster IPs.","severity":"MEDIUM","source":"OT ICS Malware & Zero-Days","summary":"BlackEnergy exploits recently fixed flaws in Siemens WinCC&nbsp;&nbsp;Security Affairs","title":"BlackEnergy exploits recently fixed flaws in Siemens WinCC - Security Affairs"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-d6f48795c0af4369","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxQNGotSWhMWWFITllCRVBXTmhJM0diT0oyWWowSXNOcmJSQldKREVhZ3d1VjhPZzR5N09wdnZ3eXRUNFVjVXdRRzMxZVViTVFZalVqWVBqMHNka1JiNHJ1ZDJLMGtVZlRyVUl6UVpvQ3p3TzAtcllLalZFZFl3cEdQRVZlWQ?oc=5","published_at":"2014-07-19T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"New Variant of Havex Malware Scans for OPC Servers at SCADA Systems&nbsp;&nbsp;The Hacker News","title":"New Variant of Havex Malware Scans for OPC Servers at SCADA Systems - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-c9cad47de2b1678d","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMigwFBVV95cUxQNGotSWhMWWFITllCRVBXTmhJM0diT0oyWWowSXNOcmJSQldKREVhZ3d1VjhPZzR5N09wdnZ3eXRUNFVjVXdRRzMxZVViTVFZalVqWVBqMHNka1JiNHJ1ZDJLMGtVZlRyVUl6UVpvQ3p3TzAtcllLalZFZFl3cEdQRVZlWQ?oc=5","published_at":"2014-07-19T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"New Variant of Havex Malware Scans for OPC Servers at SCADA Systems&nbsp;&nbsp;thehackernews.com","title":"New Variant of Havex Malware Scans for OPC Servers at SCADA Systems - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-ffb353307f9210d0","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMifkFVX3lxTFA0ekJEWWJ6eEIzN25JVHNKbXJCanB2RDRoMy1IdGswdjhrS2l3dTJqckhOTmloemlPSG1KdGZPbmRnWEh4a2JHS0tDTExfWWNlNUx0U0xlR1dNc0xfWGNfUTgzbFFaU0xPQ2dKZ0FFdkVpSmNBcC1JZ18zTkFMdw?oc=5","published_at":"2014-06-26T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Stuxnet-like 'Havex' Malware Strikes European SCADA Systems&nbsp;&nbsp;thehackernews.com","title":"Stuxnet-like 'Havex' Malware Strikes European SCADA Systems - thehackernews.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-521786b408ba464d","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMifkFVX3lxTFA0ekJEWWJ6eEIzN25JVHNKbXJCanB2RDRoMy1IdGswdjhrS2l3dTJqckhOTmloemlPSG1KdGZPbmRnWEh4a2JHS0tDTExfWWNlNUx0U0xlR1dNc0xfWGNfUTgzbFFaU0xPQ2dKZ0FFdkVpSmNBcC1JZ18zTkFMdw?oc=5","published_at":"2014-06-26T07:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Stuxnet-like 'Havex' Malware Strikes European SCADA Systems&nbsp;&nbsp;The Hacker News","title":"Stuxnet-like 'Havex' Malware Strikes European SCADA Systems - The Hacker News"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-4d67f4228870300a","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiogFBVV95cUxPNXlmZ1RpNXdkXzNLN1hiZ3lVQTN2aUxJc0kyMVdmenBxV19CNldQX3BWMkMtMXFjTDFFX2d2ZUd0NUxQY3E1OEVBSDZ0UVNqQUYydEwxejhSYm55UDYzU3RTVjJ4WE5ocnBKcnJLRjdvSTI2NzZ5ekE0THBtVUpNV2pkWUs5RmhqMk1xWnBkeXQtU2hEdXBCazlpTkJHQl9lWXc?oc=5","published_at":"2013-01-16T08:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Malware Infecting US Power Plant SCADA Systems&nbsp;&nbsp;bitdefender.com","title":"Malware Infecting US Power Plant SCADA Systems - bitdefender.com"},{"affected_nodes":["x1 (xx.xx.xx.139)"],"affected_services":["x-ign-prod-master","x-ign-prod-backup","x-ign-dev","x-ign-eam"],"alert_id":"intel-70340eb6e2351af8","category":"ICS / SCADA Controls","cve_ids":[],"impact_assessment":"Potential unauthenticated API session hijack, unauthorized tag DB modification, or WebDev remote execution attempt.","link":"https://news.google.com/rss/articles/CBMiogFBVV95cUxPNXlmZ1RpNXdkXzNLN1hiZ3lVQTN2aUxJc0kyMVdmenBxV19CNldQX3BWMkMtMXFjTDFFX2d2ZUd0NUxQY3E1OEVBSDZ0UVNqQUYydEwxejhSYm55UDYzU3RTVjJ4WE5ocnBKcnJLRjdvSTI2NzZ5ekE0THBtVUpNV2pkWUs5RmhqMk1xWnBkeXQtU2hEdXBCazlpTkJHQl9lWXc?oc=5","published_at":"2013-01-16T08:00:00+00:00","purdue_level":"Level 3 SCADA Supervisory & Operations","recommended_action":"Enforce strict Gateway mTLS (GAN port 8060), require Multi-Factor Authentication on IdP profiles, and maintain 1h 59m automated trial reset watchdog.","severity":"INFO","source":"OT ICS Malware & Zero-Days","summary":"Malware Infecting US Power Plant SCADA Systems&nbsp;&nbsp;Bitdefender","title":"Malware Infecting US Power Plant SCADA Systems - Bitdefender"}]
