Incidents
3 ACTIVEValidated operational events tracked by Watchkeeper
Coverage & Balance3 open · 2027 signals (Last 7d)
Closed Incidents46
Critical Cyber Advisories: ICS Vulnerability and Russian State Phishing Campaign — Denver
Two concurrent Severity-10 cyber alerts have been flagged for Denver: a critical vulnerability in MZ Automation's libIEC61850 library (commonly used in industrial and facility cont...
Russian State-Sponsored Phishing Campaign Targeting Zimbra Collaboration Suite — Denver Operations Footprint
Russian state-supported cyber actors are conducting an active phishing campaign targeting users of Zimbra Collaboration Suite, a widely deployed email and collaboration platform us...
Qilin Ransomware Exploiting Critical Palo Alto VPN Flaw — Contact-Center Operations at Risk
Qilin ransomware actors are actively exploiting a critical vulnerability in Palo Alto Networks VPN infrastructure to breach corporate networks, with 8 corroborating articles and a ...
HOLLOWGRAPH Espionage Campaign Exploits Microsoft 365 Calendars — Dallas-Fort Worth Contact-Center and Knowledge-Worker Operations
The HOLLOWGRAPH campaign is actively abusing Microsoft 365 calendar sharing features as covert communication channels, enabling threat actors to exfiltrate data and maintain persis...
Critical ICS/SCADA Vulnerabilities Flagged in Oklahoma City — Operations Footprint at Risk
Sentinel has flagged two severity-10 cyber alerts in Oklahoma City: a critical vulnerability in the Hydro-Québec Le Circuit Électrique EV charging station backend and a separate cr...
Critical ICS/SCADA Vulnerabilities Flagged in Denver — Operations Footprint at Risk
Two severity-10 sentinel alerts have fired for critical vulnerabilities in Hitachi Energy e-mesh EMS and OpenPLC v3 affecting the Denver metro area, which hosts an exceptionally la...
Critical ICS/SCADA Vulnerabilities Flagged in Dallas-Fort Worth — Operations Footprint at Risk
Two Severity-10 cyber advisories have been triggered in the Dallas-Fort Worth metro, flagging critical vulnerabilities in Hitachi Energy e-mesh EMS and OpenPLC v3 — both industrial...
Critical ICS/SCADA Vulnerabilities Flagged in Des Moines — Operations Footprint at Risk
Two Severity-10 cybersecurity alerts have been triggered in Des Moines, Iowa, flagging critical vulnerabilities in Hitachi Energy e-mesh EMS and OpenPLC v3 — both industrial contro...
Critical ICS/SCADA Vulnerabilities Flagged in Colorado Springs — Operations Footprint at Risk
Two severity-10 CVE alerts have been triggered for Labcenter Proteus 9 and OpenPLC v3 in Colorado Springs, both classified as critical ICS/SCADA vulnerabilities. Colorado Springs h...
Critical ICS/SCADA Vulnerability Flagged in Omaha — Contact-Center and Knowledge-Worker Operations Footprint at Risk
A Sev 10 sentinel alert flags a critical vulnerability in Hitachi Energy PROMOD V, an ICS/SCADA system with energy-sector relevance, centered on Omaha, Nebraska. With approximately...
Critical ICS/SCADA Vulnerability Flagged in Tulsa — Contact-Center and Knowledge-Worker Operations Footprint at Risk
A severity-10 sentinel alert flags a critical vulnerability in Hitachi Energy's e-mesh Energy Management System (EMS) affecting Tulsa, coinciding with news of a newly identified mu...
Critical ICS/SCADA Vulnerabilities Flagged in Colorado Springs — Contact-Center and Knowledge-Worker Operations Footprint at Risk
A severity-10 sentinel alert flags critical vulnerabilities in Digi International PortServer TS and Digi One SP IA serial-to-network device servers in Colorado Springs — hardware c...
Critical ICS/SCADA Vulnerabilities Flagged in Des Moines — Contact-Center and Knowledge-Worker Operations Footprint at Risk
Two severity-10 advisories have been flagged for Des Moines targeting OpenPLC v3 and Digi International PortServer/One SP IA — industrial control and serial-device-server products ...
Critical ICS/SCADA Vulnerabilities Flagged in Dallas-Fort Worth — Contact-Center and Knowledge-Worker Operations Footprint at Risk
Two Severity-10 Sentinel signals have flagged critical vulnerabilities in OpenPLC v3 and Digi International PortServer TS/Digi One SP IA — industrial control and serial-device-serv...
Critical ICS/SCADA Vulnerabilities Flagged in Denver — Contact-Center and Knowledge-Worker Operations Footprint at Risk
Two severity-10 sentinel alerts have triggered in Denver targeting Hitachi Energy e-mesh EMS and OpenPLC v3 — industrial control system and programmable logic controller platforms ...
Claimed Accenture Breach Exposes Source Code, SSH Keys, and Azure Tokens — Contact-Center Operations Footprint at Risk
A hacker is claiming to have breached Accenture, allegedly exfiltrating source code, SSH keys, and Azure authentication tokens. Accenture is a major managed-services and outsourcin...
Critical Cyber Vulnerabilities: XZ Utils and StoneFly Storage Concentrator — Colorado Springs
Two severity-10 cyber alerts have been flagged for Colorado Springs, covering the XZ Utils supply-chain vulnerability (affecting B&R Products) and a StoneFly Storage Concentrator f...
Critical Cyber Alerts: StoneFly Storage Concentrator and XZ Utils Vulnerabilities Detected in Denver
Two Severity-10 cyber alerts have been triggered in Denver flagging critical vulnerabilities in StoneFly Storage Concentrator and XZ Utils (impacting Backup & Recovery products). D...
Critical Cyber Vulnerabilities: XZ Utils and H.VIEW IP Camera — Denver
Two severity-10 cyber alerts have been flagged in Denver, covering a critical vulnerability in XZ Utils (affecting Backup & Recovery products widely used in enterprise environments...
Critical Cyber Alerts on StoneFly Storage and FUXA SCADA/HMI Systems — Colorado Springs
Two severity-10 sentinel alerts have fired in Colorado Springs targeting StoneFly Storage Concentrator and Frangoteam FUXA SCADA/HMI systems — both critical infrastructure componen...
Critical Cyber Vulnerabilities: StoneFly Storage and Daktronics Controller Firmware — Tulsa
Two Severity 10 cyber alerts have been detected in Tulsa targeting StoneFly Storage Concentrator and Daktronics Controller Firmware, with no accompanying news coverage suggesting t...
Critical Severity Cyber Alerts on IP Camera and Cellular Web Interface Devices in Denver Operations Hub
Two Severity 10 sentinel alerts have fired against network-connected devices in Denver — an H.VIEW HV-500S6 IP camera and a Hubbell Aclara Metrum cellular web interface — suggestin...
SimpleHelp Remote Access Flaw Actively Exploited for Malware Deployment Across Windows, macOS, and Linux — Dallas-Fort Worth Operations Hub Exposure
A vulnerability in SimpleHelp, a widely-used remote support and access tool, is being actively exploited to deploy malware across Windows, macOS, and Linux endpoints. With Dallas-F...
IP Camera Intrusion Sensor Alert at DFW Operations Hub Coincides with Regional Malware Campaign
A Severity 10 sentinel alert has fired against an H.VIEW HV-500S6 IP camera asset in the Dallas-Fort Worth area, a high-density hub with nearly 790,000 combined contact-center, bac...
Fileless Ransomware & Browser-Based Exploit Campaigns Targeting US Enterprise Environments
Symantec has flagged a fileless ransomware backdoor ('Mistic') that evades traditional file-based scans by erasing itself post-execution, while a separate malicious Edge extension ...