Topic: Critical Infrastructure
11 items across the network · This site only · RSS
How fast CISA is adding known-exploited vulnerabilities
Additions to the CISA KEV catalog per month. Listing means confirmed exploitation, not merely a severe score.
Aug 17, 2026The gap between a CVE being published and being known-exploited
How long vulnerabilities take to reach the KEV catalog after publication — a distribution, not an average.
Aug 16, 2026Ransomware leak-site postings by sector
Victims claimed on extortion leak sites, by sector and month. These are claims made by the groups, not confirmed incidents.
Aug 15, 2026How the KEV catalog works
CISA's Known Exploited Vulnerabilities catalog lists flaws with evidence of active exploitation. It is not a severity ranking, and absence from it is ...
Aug 06, 2026Hague Talks Produce Draft Language on Critical Infrastructure Attacks
Negotiators reached provisional agreement on norms covering attacks against healthcare and energy systems in peacetime.
Jul 21, 2026Singapore Runs Largest Critical Infrastructure Cyber Drill to Date
Eleven sectors rehearsed simultaneous incident response, with grid and port operators testing manual fallback procedures.
Jul 14, 2026Prepositioning in Critical Infrastructure: Reading Intent from Access
Quiet persistence inside water, power and port systems is best understood as battlespace preparation, not espionage.
Jul 10, 2026AI Models Are Infrastructure Now — Secure Them Like It
Model weights, training pipelines and inference endpoints have quietly become critical dependencies for entire sectors.
Jun 26, 2026Washington Publishes Cyber Strategy Refresh
The updated strategy elevates resilience metrics for lifeline sectors and expands liability shields for rapid incident disclosure.
Jun 24, 2026The Grid Is the Battlefield Nobody Budgets For
Interconnectors, transformers and control systems have become strategic assets — priced, targeted and defended like them.
Jun 20, 2026Originally on Global Energy
Canberra Extends Critical Infrastructure Rules to Data Centres
New obligations bring large data centre operators under the security-of-critical-infrastructure regime, including incident reporting windows.
Jun 13, 2026