A Tale of Two SOCs: Insights From Two Red Team Assessments
2026-08-25T14:23:51Z•c5b2700fa96555b358a8bb323d4e7f680c64e0bc67b05d329db27ff205fef052
CVE-2025-66376CISAChina-nexusGunraHMIICSIranian-affiliatedLAUNDRY-BEARPLCRockwell-AutomationRussian-state-sponsoredSCADASchneider-ElectricSiemens-S7Zimbracloud-securitycritical-infrastructuredefense-in-depthdomain-compromisedouble-extortionnetwork-devicesoperational-technologyphishingransomwarered-team
What happened
CISA advisories describe active and emerging cyber threats affecting critical infrastructure, including full-domain compromise observed in red-team assessments, ransomware, exploitation of Siemens and other PLCs, Russian state-supported targeting of Zimbra and vulnerable network devices, China-nexus compromised-device networks, and Iranian-affiliated attacks on internet-exposed OT. Recommended defenses include asset inventory, patching, removal of internet exposure, strong access controls, network segmentation, tuned detection, incident-response coordination, threat hunting, and immutable/offข
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_alerts
- Record identifier
- c5b2700fa96555b358a8bb323d4e7f680c64e0bc67b05d329db27ff205fef052
- Enrichment time
- 2026-08-25T14:23:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.