DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
BACK TO EXPLORE INDEX
CATEGORY ARCHIVE

Cybersecurity Incidents & Active Breaches

TOTAL ARCHIVED: 5 ENTRIES
04:12 UTC·incident
criticalTLP:AMBER+STRICT

Trans-Pacific & European Backbone Core Routing Compromise

Coordinated exploitation of carrier SS7/Diameter interconnects and edge hypervisors targeting government voice routes and subsea fiber management planes.

ACTOR: Volt Typhoon (Bronze Silhouette)ACTOR: UNC3236CVE-2026-1194CVE-2024-21887
San Francisco Peering Hub
IMPACT SCORE: 96/100
2 VERIFIED SOURCES
22:00 UTC·incident
highTLP:AMBER

Rotterdam & Antwerp Maritime Terminal Automation Freeze

Disruption of automated container crane telemetry and berth allocation SCADA controllers via malicious IEC-104 protocol packet floods.

ACTOR: Sandworm (Unit 74455)CVE-2026-3819
Rotterdam Port Complex
IMPACT SCORE: 88/100
1 VERIFIED SOURCES
18:30 UTC·incident
criticalTLP:WHITE

Singapore Multi-Chain Institutional Bridge $280M Extraction

Social engineering compromise of developer cryptographic signing keys by Lazarus Group leading to massive smart contract treasury liquidation.

ACTOR: Lazarus Group (APT38)CVE-2026-3819
Marina Bay Financial Center
IMPACT SCORE: 92/100
1 VERIFIED SOURCES
10:00 UTC·incident
highTLP:AMBER

National Electricity Market (NEM) Grid Ingress Triage

Discovery of persistent living-off-the-land footholds in regional Australian transmission substation relays.

ACTOR: Volt Typhoon (Bronze Silhouette)CVE-2024-21887
Sydney Substation Grid
IMPACT SCORE: 84/100
1 VERIFIED SOURCES
15:45 UTC·incident
mediumTLP:WHITE

Navi Mumbai Cloud Provider Hypervisor Lockout

BlackCat/ALPHV ransomware deployment targeting multi-tenant VMware ESXi virtualization clusters across Indian commercial hosting provider.

ACTOR: Scattered Spider (UNC3944)ACTOR: BlackCat AffiliatesCVE-2026-3819
Mumbai Hub
IMPACT SCORE: 76/100
1 VERIFIED SOURCES