A Tale of Two SOCs: Insights From Two Red Team Assessments

2026-08-25T14:23:51Zc5b2700fa96555b358a8bb323d4e7f680c64e0bc67b05d329db27ff205fef052
CVE-2025-66376CISAChina-nexusGunraHMIICSIranian-affiliatedLAUNDRY-BEARPLCRockwell-AutomationRussian-state-sponsoredSCADASchneider-ElectricSiemens-S7Zimbracloud-securitycritical-infrastructuredefense-in-depthdomain-compromisedouble-extortionnetwork-devicesoperational-technologyphishingransomwarered-team

What happened

CISA advisories describe active and emerging cyber threats affecting critical infrastructure, including full-domain compromise observed in red-team assessments, ransomware, exploitation of Siemens and other PLCs, Russian state-supported targeting of Zimbra and vulnerable network devices, China-nexus compromised-device networks, and Iranian-affiliated attacks on internet-exposed OT. Recommended defenses include asset inventory, patching, removal of internet exposure, strong access controls, network segmentation, tuned detection, incident-response coordination, threat hunting, and immutable/offข

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_alerts
Record identifier
c5b2700fa96555b358a8bb323d4e7f680c64e0bc67b05d329db27ff205fef052
Enrichment time
2026-08-25T14:23:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.