Incidents

Validated operational events tracked by Watchkeeper

0SEV10SEV20SEV30SEV4
Coverage & Balance0 open · 724 signals (Last 7d)
Open Incidents · Region
Geographic skew of active incidents
No open incidents
Open Incidents · Domain
Which risk domains are active
No open incidents
Corroboration · Triage
Open incidents by external corroboration
No open incidents
Signals · Region
Inflow geo skew · Last 7d
US8
non-US656
global60
Signals · Category
Inflow by category · Last 7d
Cyber260
Travel131
Weather88
Financial57
Health53
Infrastructure34
Geopolitical33
Seismic20
DomainWeatherSeismicDisasterCyberHealthInfrastructureFinancialEnvironmentalGeopoliticalGeneral
StatusActiveDETECTEDDECLAREDOPENVALIDATEDESCALATEDDE-ESCALATEDRESOLVINGCLOSEDREOPENED
CorroborationAllCorroboratedSingle sourceUncorroborated

Closed Incidents47

SEV3CLOSEDCyberONGOING✓ Corroborated · 5 sources44d ago

Russian State-Sponsored Phishing Campaign Targeting Zimbra Collaboration Suite — Des Moines

Russian state-supported actors are conducting active phishing campaigns against users of Zimbra Collaboration Suite, with a companion advisory recommending isolation of vital syste...

3 eventsDeclared Jul 29, 07:30 PM UTC
SEV3CLOSEDCyber✓ Corroborated · 5 sources47d ago

Critical Cyber Advisories: ICS Vulnerability and Russian State Phishing Campaign — Denver

Two concurrent Severity-10 cyber alerts have been flagged for Denver: a critical vulnerability in MZ Automation's libIEC61850 library (commonly used in industrial and facility cont...

2 eventsDeclared Jul 27, 03:30 PM UTC
SEV3CLOSEDCyber✓ Corroborated · 5 sources49d ago

Russian State-Sponsored Phishing Campaign Targeting Zimbra Collaboration Suite — Denver Operations Footprint

Russian state-supported cyber actors are conducting an active phishing campaign targeting users of Zimbra Collaboration Suite, a widely deployed email and collaboration platform us...

8 eventsDeclared Jul 24, 08:00 PM UTC
SEV3CLOSEDCyber✓ Corroborated · 5 sources52d ago

Qilin Ransomware Exploiting Critical Palo Alto VPN Flaw — Contact-Center Operations at Risk

Qilin ransomware actors are actively exploiting a critical vulnerability in Palo Alto Networks VPN infrastructure to breach corporate networks, with 8 corroborating articles and a ...

36 eventsDeclared Jul 22, 01:00 PM UTC
SEV3CLOSEDCyber✓ Corroborated · 5 sources53d ago

HOLLOWGRAPH Espionage Campaign Exploits Microsoft 365 Calendars — Dallas-Fort Worth Contact-Center and Knowledge-Worker Operations

The HOLLOWGRAPH campaign is actively abusing Microsoft 365 calendar sharing features as covert communication channels, enabling threat actors to exfiltrate data and maintain persis...

Declared Jul 20, 10:00 PM UTC
SEV3CLOSEDCyber✓ Corroborated · 3 sources62d ago

Critical ICS/SCADA Vulnerabilities Flagged in Oklahoma City — Operations Footprint at Risk

Sentinel has flagged two severity-10 cyber alerts in Oklahoma City: a critical vulnerability in the Hydro-Québec Le Circuit Électrique EV charging station backend and a separate cr...

Oklahoma, US, US2 eventsDeclared Jul 12, 04:31 AM UTC
SEV3CLOSEDCyber✓ Corroborated · 4 sources62d ago

Critical ICS/SCADA Vulnerabilities Flagged in Denver — Operations Footprint at Risk

Two severity-10 sentinel alerts have fired for critical vulnerabilities in Hitachi Energy e-mesh EMS and OpenPLC v3 affecting the Denver metro area, which hosts an exceptionally la...

Denver, US, US2 eventsDeclared Jul 11, 10:30 PM UTC
SEV3CLOSEDCyber✓ Corroborated · 5 sources62d ago

Critical ICS/SCADA Vulnerabilities Flagged in Dallas-Fort Worth — Operations Footprint at Risk

Two Severity-10 cyber advisories have been triggered in the Dallas-Fort Worth metro, flagging critical vulnerabilities in Hitachi Energy e-mesh EMS and OpenPLC v3 — both industrial...

Dallas-Fort Worth, US, US2 eventsDeclared Jul 11, 10:31 PM UTC
SEV3CLOSEDCyber✓ Corroborated · 3 sources62d ago

Critical ICS/SCADA Vulnerabilities Flagged in Des Moines — Operations Footprint at Risk

Two Severity-10 cybersecurity alerts have been triggered in Des Moines, Iowa, flagging critical vulnerabilities in Hitachi Energy e-mesh EMS and OpenPLC v3 — both industrial contro...

Des Moines, US, US2 eventsDeclared Jul 11, 10:30 PM UTC
SEV3CLOSEDCyber✓ Corroborated · 3 sources63d ago

Critical ICS/SCADA Vulnerabilities Flagged in Colorado Springs — Operations Footprint at Risk

Two severity-10 CVE alerts have been triggered for Labcenter Proteus 9 and OpenPLC v3 in Colorado Springs, both classified as critical ICS/SCADA vulnerabilities. Colorado Springs h...

Colorado Springs, US, US2 eventsDeclared Jul 11, 05:00 PM UTC
SEV3CLOSEDCyber✓ Corroborated · 5 sources63d ago

Critical ICS/SCADA Vulnerability Flagged in Omaha — Contact-Center and Knowledge-Worker Operations Footprint at Risk

A Sev 10 sentinel alert flags a critical vulnerability in Hitachi Energy PROMOD V, an ICS/SCADA system with energy-sector relevance, centered on Omaha, Nebraska. With approximately...

Omaha, US, USDeclared Jul 11, 02:31 AM UTC
SEV3CLOSEDCyber✓ Corroborated · 5 sources63d ago

Critical ICS/SCADA Vulnerability Flagged in Tulsa — Contact-Center and Knowledge-Worker Operations Footprint at Risk

A severity-10 sentinel alert flags a critical vulnerability in Hitachi Energy's e-mesh Energy Management System (EMS) affecting Tulsa, coinciding with news of a newly identified mu...

Tulsa, US, USDeclared Jul 10, 08:30 PM UTC
SEV3CLOSEDCyber✓ Corroborated · 5 sources64d ago

Critical ICS/SCADA Vulnerabilities Flagged in Colorado Springs — Contact-Center and Knowledge-Worker Operations Footprint at Risk

A severity-10 sentinel alert flags critical vulnerabilities in Digi International PortServer TS and Digi One SP IA serial-to-network device servers in Colorado Springs — hardware c...

Colorado Springs, US, USDeclared Jul 10, 12:30 AM UTC
SEV3CLOSEDCyber✓ Corroborated · 4 sources64d ago

Critical ICS/SCADA Vulnerabilities Flagged in Des Moines — Contact-Center and Knowledge-Worker Operations Footprint at Risk

Two severity-10 advisories have been flagged for Des Moines targeting OpenPLC v3 and Digi International PortServer/One SP IA — industrial control and serial-device-server products ...

Des Moines, US, US2 eventsDeclared Jul 10, 12:00 AM UTC
SEV3CLOSEDCyber✓ Corroborated · 5 sources64d ago

Critical ICS/SCADA Vulnerabilities Flagged in Dallas-Fort Worth — Contact-Center and Knowledge-Worker Operations Footprint at Risk

Two Severity-10 Sentinel signals have flagged critical vulnerabilities in OpenPLC v3 and Digi International PortServer TS/Digi One SP IA — industrial control and serial-device-serv...

Dallas-Fort Worth, US, US2 eventsDeclared Jul 10, 12:00 AM UTC
SEV3CLOSEDCyber✓ Corroborated · 5 sources64d ago

Critical ICS/SCADA Vulnerabilities Flagged in Denver — Contact-Center and Knowledge-Worker Operations Footprint at Risk

Two severity-10 sentinel alerts have triggered in Denver targeting Hitachi Energy e-mesh EMS and OpenPLC v3 — industrial control system and programmable logic controller platforms ...

Denver, US, US2 eventsDeclared Jul 9, 11:30 PM UTC
SEV3CLOSEDCyber✓ Corroborated · 5 sources65d ago

Claimed Accenture Breach Exposes Source Code, SSH Keys, and Azure Tokens — Contact-Center Operations Footprint at Risk

A hacker is claiming to have breached Accenture, allegedly exfiltrating source code, SSH keys, and Azure authentication tokens. Accenture is a major managed-services and outsourcin...

Denver, US, USDeclared Jul 9, 02:00 AM UTC
SEV3CLOSEDCyber✓ Corroborated · 4 sources69d ago

Critical Cyber Vulnerabilities: XZ Utils and StoneFly Storage Concentrator — Colorado Springs

Two severity-10 cyber alerts have been flagged for Colorado Springs, covering the XZ Utils supply-chain vulnerability (affecting B&R Products) and a StoneFly Storage Concentrator f...

Colorado Springs, US, US2 eventsDeclared Jul 5, 09:00 AM UTC
SEV3CLOSEDCyber✓ Corroborated · 3 sources69d ago

Critical Cyber Alerts: StoneFly Storage Concentrator and XZ Utils Vulnerabilities Detected in Denver

Two Severity-10 cyber alerts have been triggered in Denver flagging critical vulnerabilities in StoneFly Storage Concentrator and XZ Utils (impacting Backup & Recovery products). D...

Denver, US, US2 eventsDeclared Jul 5, 09:00 AM UTC
SEV3CLOSEDCyber✓ Corroborated · 5 sources72d ago

Critical Cyber Vulnerabilities: XZ Utils and H.VIEW IP Camera — Denver

Two severity-10 cyber alerts have been flagged in Denver, covering a critical vulnerability in XZ Utils (affecting Backup & Recovery products widely used in enterprise environments...

Denver, US, US2 eventsDeclared Jul 2, 10:31 AM UTC
SEV3CLOSEDCyber✓ Corroborated · 4 sources72d ago

Critical Cyber Alerts on StoneFly Storage and FUXA SCADA/HMI Systems — Colorado Springs

Two severity-10 sentinel alerts have fired in Colorado Springs targeting StoneFly Storage Concentrator and Frangoteam FUXA SCADA/HMI systems — both critical infrastructure componen...

Colorado Springs, US, US4 eventsDeclared Jul 1, 08:00 PM UTC
SEV3CLOSEDCyber✓ Corroborated · 3 sources72d ago

Critical Cyber Vulnerabilities: StoneFly Storage and Daktronics Controller Firmware — Tulsa

Two Severity 10 cyber alerts have been detected in Tulsa targeting StoneFly Storage Concentrator and Daktronics Controller Firmware, with no accompanying news coverage suggesting t...

Tulsa, US, US2 eventsDeclared Jul 2, 09:00 AM UTC
SEV3CLOSEDCyber✓ Corroborated · 4 sources75d ago

Critical Severity Cyber Alerts on IP Camera and Cellular Web Interface Devices in Denver Operations Hub

Two Severity 10 sentinel alerts have fired against network-connected devices in Denver — an H.VIEW HV-500S6 IP camera and a Hubbell Aclara Metrum cellular web interface — suggestin...

Denver, US, US3 eventsDeclared Jun 29, 03:01 PM UTC
SEV3CLOSEDCyber✓ Corroborated · 5 sources73d ago

SimpleHelp Remote Access Flaw Actively Exploited for Malware Deployment Across Windows, macOS, and Linux — Dallas-Fort Worth Operations Hub Exposure

A vulnerability in SimpleHelp, a widely-used remote support and access tool, is being actively exploited to deploy malware across Windows, macOS, and Linux endpoints. With Dallas-F...

Dallas-Fort Worth, US, USDeclared Jun 30, 05:31 PM UTC
SEV3CLOSEDCyber✓ Corroborated · 5 sources75d ago

IP Camera Intrusion Sensor Alert at DFW Operations Hub Coincides with Regional Malware Campaign

A Severity 10 sentinel alert has fired against an H.VIEW HV-500S6 IP camera asset in the Dallas-Fort Worth area, a high-density hub with nearly 790,000 combined contact-center, bac...

Dallas-Fort Worth, US, USDeclared Jun 28, 05:31 PM UTC
Page 1 of 2Older