Skip to content
Bulwark BlackBulwark Black LLC
Threat Intel
  • Latest reporting
  • Russian CTI
  • Chinese CTI
  • North Korean CTI
  • Iranian CTI
  • Global / Anomalous
  • Malware
Intel Workbench
  • Workbench home
  • IOC Passport
  • Campaign Constellation · Beta
  • Indicator Database
  • Verified Threat Feeds
  • IOC Extractor
  • Threat Alerts
Software
  • Contractor Codex↗
  • SAMscout AI↗
  • VA Disability Calc & Track
  • What we build
  • All software
Services
  • Websites & Web Apps
  • Custom iOS Apps
  • AI & Automation
  • Small-Business IT & Cybersecurity
Company
  • About
  • Community
  • Contact
The BriefBlog
Threat Intel →Work with us →
All Threat Intel →Latest reportingRussian CTIChinese CTINorth Korean CTIIranian CTIGlobal / AnomalousMalware
All Intel Workbench →Workbench homeIOC PassportCampaign Constellation · BetaIndicator DatabaseVerified Threat FeedsIOC ExtractorThreat Alerts
All Software →Contractor Codex↗SAMscout AI↗VA Disability Calc & TrackWhat we buildAll software
All Services →Websites & Web AppsCustom iOS AppsAI & AutomationSmall-Business IT & Cybersecurity
All Company →AboutCommunityContact
The BriefBlogWork with us →
RSS
Latest
Antino Backdoor Shows Why Microsoft 365 C2 Needs Cloud-Aware DetectionSession Cookie Bypass Shows Why SSO Is Not the Whole Trust BoundaryWarlock Ransomware Shows SharePoint Is Still Critical Infrastructure RiskFortiMail Zero-Day Shows Email Security Appliances Need Incident ResponseDragonForce TURN and MQTT Backdoors Show Why Ransomware Defense Needs Egress VisibilityTA419 Shows AI Policy Is Now an Espionage Phishing TargetAI Is Turning Vulnerability Triage Into a Threat-Intel Problem2CLoader Shows Why Malware Loader Alerts Need Identity ResponseZimbra CVE-2026-73570 Shows Mail Servers Need Full Incident ReviewRMM Phishing Turns Trusted Admin Tools Into Persistent AccessApache MINA SSHD Auth Bypasses Show Why Embedded SSH Needs InventoryCustom GPT ClickFix Shows Why AI Trust Needs Browser-to-Shell ControlsNetScaler Zero-Days Show Why Edge Devices Need Incident Response, Not Just PatchingNeedyMantis Shows Why Post-Compromise Malware Needs Full Intrusion ReviewAntino Backdoor Shows Why Microsoft 365 C2 Needs Cloud-Aware DetectionSession Cookie Bypass Shows Why SSO Is Not the Whole Trust BoundaryWarlock Ransomware Shows SharePoint Is Still Critical Infrastructure RiskFortiMail Zero-Day Shows Email Security Appliances Need Incident ResponseDragonForce TURN and MQTT Backdoors Show Why Ransomware Defense Needs Egress VisibilityTA419 Shows AI Policy Is Now an Espionage Phishing TargetAI Is Turning Vulnerability Triage Into a Threat-Intel Problem2CLoader Shows Why Malware Loader Alerts Need Identity ResponseZimbra CVE-2026-73570 Shows Mail Servers Need Full Incident ReviewRMM Phishing Turns Trusted Admin Tools Into Persistent AccessApache MINA SSHD Auth Bypasses Show Why Embedded SSH Needs InventoryCustom GPT ClickFix Shows Why AI Trust Needs Browser-to-Shell ControlsNetScaler Zero-Days Show Why Edge Devices Need Incident Response, Not Just PatchingNeedyMantis Shows Why Post-Compromise Malware Needs Full Intrusion Review

Threat Intel·Business·Jan 11, 2024·ByBulwark Bravo

Review: Engineering-grade OT security: A manager’s guide

Review: Engineering-grade OT security: A manager’s guide
Review: Engineering-grade OT security: A manager’s guide

← Older report

DreamBus Unleashes Metabase Mayhem With New Exploit Module

Newer report →

SCADA systems: How secure are the systems running our infrastructure?⎥Malav Vyas (Security Researcher at Palo Alto Networks)

Next step

Want this turned into detection for your environment?

We build the defenses we write about: detection rules, hardening, and incident response for small businesses and government contractors. Or take the indicators above and run them yourself, every report ships with machine-readable downloads.

Work With Us →Get the IOC Feeds →

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

readers get The Brief

Double opt-in. One-click unsubscribe on every issue. We never share your address.

Bulwark Black

Veteran-Owned · SDVOSB

Bulwark Black LLC
Cyber threat intelligence, custom software, and remote tech help.
Remote across the United States.

Registered agent address (mailing only):
522 W Riverside Ave, Ste N
Spokane, WA 99201

Intel & Tools

  • Intel Workbench
  • Cyber Threat Intelligence
  • Indicator Database
  • Verified Threat Feeds
  • Campaign Constellation Beta
  • IOC Extractor
  • Threat Alerts
  • The Brief

Services

  • Websites & Web Apps
  • Custom iOS Apps
  • AI & Automation
  • IT + Cybersecurity

Company

  • About
  • Software
  • VA Disability Calc & Track
  • Community
  • Blog
  • How I Work
  • Contact
  • Privacy
  • Terms
  • VA Calc Privacy Policy

For agencies & primes

  • Capability statement
  • CAGE: 17UL6
  • UEI: DVNTWBJ2HMP8
  • SDVOSB · SAM Registered

support@bulwarkblack.com

Connect

  • LinkedIn
  • GitHub

© 2026 Bulwark Black LLC. All rights reserved.

Privacy·Terms·Cookie choices

We use Google Analytics to measure site traffic, which sets cookies. No ads and no cross-site tracking. See our privacy policy.