Skip to content
Bulwark Black Bulwark Black LLC
Threat Intel
  • Latest reporting
  • Russian CTI
  • Chinese CTI
  • North Korean CTI
  • Iranian CTI
  • Global / Anomalous
  • Malware
  • IOC / YARA downloads
Software
  • Contractor Codex ↗
  • SAMscout AI ↗
  • VA Disability Calc & Track
  • What we build
  • All software
Services
  • Websites & Web Apps
  • Custom iOS Apps
  • AI & Automation
  • Small-Business IT & Cybersecurity
Company
  • About
  • Community
  • Contact
IOC Extractor Indicators Feeds The Brief Blog
Threat Intel → Work with us →
All Threat Intel → Latest reporting Russian CTI Chinese CTI North Korean CTI Iranian CTI Global / Anomalous Malware IOC / YARA downloads
All Software → Contractor Codex ↗ SAMscout AI ↗ VA Disability Calc & Track What we build All software
All Services → Websites & Web Apps Custom iOS Apps AI & Automation Small-Business IT & Cybersecurity
All Company → About Community Contact
IOC Extractor Indicators Feeds The Brief Blog Work with us →
RSS
Latest
WeedHack Shows SEO Poisoning Is Malware Delivery InfrastructureAI Agent Incidents Need Task-Scoped Incident ResponseSDLC Supply-Chain Attacks Show Why Developer Tools Need Runtime ControlsRussian Auth-Flow Phishing Shows MFA Can Be Bypassed Without ExploitsFake AI Tools Show Brand Trust Has Become Malware DeliveryStopAndProtect Shows Why WordPress Sites Are Attack InfrastructureMacSync Stealer Shows Why Behavioral Pivots Beat Rotating DomainsPurpleDelta Shows Why Remote Hiring Is Now an Insider-Risk ControlGitLab GraphQL Flaw Shows Why DevSecOps Platforms Need Emergency Patch RunbooksForminator RCE Shows Why WordPress Plugin Risk Needs Runtime ControlsC2Looper Shows Why GitHub-Based C2 Belongs in Ransomware TriageVMware vCenter Exploitation Shows Why Patching Is Not Incident ClosureRansomware’s Long Tail Means Defenders Need Faster TriageAzure Directory Dumps Show Why Identity Data Is Attack InfrastructureWeedHack Shows SEO Poisoning Is Malware Delivery InfrastructureAI Agent Incidents Need Task-Scoped Incident ResponseSDLC Supply-Chain Attacks Show Why Developer Tools Need Runtime ControlsRussian Auth-Flow Phishing Shows MFA Can Be Bypassed Without ExploitsFake AI Tools Show Brand Trust Has Become Malware DeliveryStopAndProtect Shows Why WordPress Sites Are Attack InfrastructureMacSync Stealer Shows Why Behavioral Pivots Beat Rotating DomainsPurpleDelta Shows Why Remote Hiring Is Now an Insider-Risk ControlGitLab GraphQL Flaw Shows Why DevSecOps Platforms Need Emergency Patch RunbooksForminator RCE Shows Why WordPress Plugin Risk Needs Runtime ControlsC2Looper Shows Why GitHub-Based C2 Belongs in Ransomware TriageVMware vCenter Exploitation Shows Why Patching Is Not Incident ClosureRansomware’s Long Tail Means Defenders Need Faster TriageAzure Directory Dumps Show Why Identity Data Is Attack Infrastructure

Threat Intel·Business·Jan 11, 2024·By Albert LaScola

Review: Engineering-grade OT security: A manager’s guide

Review: Engineering-grade OT security: A manager’s guide
Review: Engineering-grade OT security: A manager’s guide

Indicators of Compromise

2 indicators, auto-extracted and defanged.

TXTCSVJSON

CVEs (2)

CVE-2026-15409CVE-2026-15410

Auto-extracted from this report. Indicators shown are defanged for safe viewing. The downloads contain live values plus a YARA rule for tooling. Verify before acting.

← Older report

DreamBus Unleashes Metabase Mayhem With New Exploit Module

Newer report →

SCADA systems: How secure are the systems running our infrastructure?⎥Malav Vyas (Security Researcher at Palo Alto Networks)

Next step

Want this turned into detection for your environment?

We build the defenses we write about: detection rules, hardening, and incident response for small businesses and government contractors. Or take the indicators above and run them yourself, every report ships with machine-readable downloads.

Work With Us →Get the IOC Feeds →

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

readers get The Brief

Double opt-in. One-click unsubscribe on every issue. We never share your address.

Bulwark Black

Veteran-Owned · SDVOSB

Bulwark Black LLC
Cyber threat intelligence, custom software, and remote tech help.
Remote across the United States.

Registered agent address (mailing only):
522 W Riverside Ave, Ste N
Spokane, WA 99201

Two front doors

  • Cyber Threat Intelligence
  • Indicator Database
  • Threat Feeds
  • Shared Infrastructure
  • Threat Alerts
  • The Brief
  • Tech Services & Apps

Services

  • Websites & Web Apps
  • Custom iOS Apps
  • AI & Automation
  • IT + Cybersecurity

Company

  • About
  • Software
  • VA Disability Calc & Track
  • Community
  • Blog
  • How I Work
  • Contact
  • Privacy
  • Terms
  • VA Calc Privacy Policy

For agencies & primes

  • Capability statement
  • CAGE: 17UL6
  • UEI: DVNTWBJ2HMP8
  • SDVOSB · SAM Registered

support@bulwarkblack.com

Connect

  • LinkedIn
  • GitHub

© 2026 Bulwark Black LLC. All rights reserved.

Privacy · Terms · Cookie choices

We use Google Analytics to measure site traffic, which sets cookies. No ads and no cross-site tracking. See our privacy policy.