National Operating Picture

United States

Posture·Elevated Live
📋 30-Second Director Read · loading…
Open Source·Analyst-Reviewed

Loading today's national intelligence picture…

Compile narrative will appear here once hydration completes.
01b · National Weather & Alerts

Active Watches · Warnings · Wildfires · Animated Radar

NWS active alerts · NIFC active wildfires · RainViewer animated radar · refreshed every 15 minutes
— alerts
updated —
Warning · Extreme (Tornado / Hurricane / Flash Flood)
Warning · Severe (Severe Tstm / Red Flag / Winter)
Watch
Advisory · Statement
NEXRAD Radar (animated)
⛈️

National Weather Map

Loading NWS active alerts, NIFC wildfires, NEXRAD radar… If this persists, check the Google Maps API key referrer allowlist for this host. Polygons show active NWS alerts · pins show active wildfires (sized by acres) and major-city forecasts · animated NEXRAD radar overlays via RainViewer.

OSINT Pulse · Social Signal Monitoring · X + Telegram + RSS
Volume-velocity + sentiment analysis · 4h rolling window · agent-extracted signals, not raw feeds
✕ X / Beirut
▲ 11× normal

Beirut residents posting Hezbollah-positioned strike imagery from Dahiyeh

Geolocated posts 11× baseline volume in trailing 4 hours. Imagery consistent with prior strike-warning patterns. Sentiment skew: fear + departure-planning indicators rising. Cross-references Lebanon L3→L4 advisory escalation.
Maya · 18mSentiment ▲
▲ Telegram / REMVE
▲ 3.4× normal

Accelerationist channels coordinating around Pride parade routes — 6 city threads active

Patriot Front + Active Club adjacent channels showing coordinated tactical-planning vocabulary against June parade routes in flagged cities. Counter-protest mobilization tempo aligns with FBI national soft-target advisory.
Marcus · 47mThreat ▲
✕ X / Tehran-aligned
▲ 2.8× normal

IRGC-affiliated and Hezbollah-adjacent accounts amplifying retaliation rhetoric

Persian-language influencers and Hezbollah-aligned diaspora accounts amplifying retaliation framing at sustained elevated tempo. Targeting language references former US officials and Israeli-aligned facilities. Cross-references MuddyWater operational tempo.
Maya · 1hThreat ▲
✕ X / Campus
▲ 2.1× normal

Campus encampment commencement-disruption planning crystallizing

SJP + JVP affiliated accounts coordinating commencement-day disruption tactics across 4 named encampments. Counter-protest accounts mobilizing in parallel at 3 of those sites — the convergence is the elevation indicator.
Marcus · 2hMixed ◆
📡 Vendor / Cyber
▲ 8× normal

Salt Typhoon disclosure cycle accelerating — carrier confirmations cascading

Vendor and security-journalist accounts confirming 3 additional named carriers compromised in trailing 24h. Sustained reporting velocity suggests further disclosures imminent. Cross-references our convergence finding on telecom POP physical access.
Darius · 3hSeverity ▲
✕ X / Colombia
▼ 0.6× normal

Colombia northern-departments sentiment normalizing as security improvements take hold

Local accounts and journalists reporting reduced threat-condition vocabulary. Travel-industry accounts resuming Northern Colombia promotion. Validates State Dept L3→L2 downgrade we picked up 18 days ago.
Maya · 6hSentiment ▼
⚠ Social signals are indicators not assessments · raw posts are not displayed · all signals require agent extraction + human review before promotion to curated sections · platforms monitored under their public-API terms

Social Pulse · Last 24h · National Feed

About This Picture · How it's built · Why it's curated
● Live · Daily Refresh · Analyst-Reviewed
What This Is
Curated national operating picture · cross-domain fusion no single source produces: foreign state actors + terror groups + travel posture + civil unrest + cyber + KEVs + physical-cyber overlap, in one analyst-ready view.
Sources
CISA · FBI · NCTC · DHS · State Dept · OFAC · NERC E-ISAC · USMS · state + regional fusion centers · vetted OSINT · CISA KEV catalog. Curation by GSC intelligence agents with named human-analyst review.
Update Cadence
Foreign posture weekly · CONUS unrest + incidents 2× daily · state-aligned cyber + KEV hourly · convergence findings reviewed by human analyst before publication.
Confidence & Workflow
Per-item High/Med/Low assessment. Live product adds analyst search · sector lenses · watchlists · STIX/CSV/PDF export · API. This view is the curated daily synthesis — not the full workspace.
Emerging · Under Assessment
5 items in queue · last review 8m ago · agents auto-promote on confidence threshold
Reviewing
ICC arrest warrant issuance — assessing travel-advisory cascade for affected jurisdictions
Maya · 22mReuters wire
Pending
Salt Lake federal courthouse threat — confirm USMS pattern match before advisory promotion
Marcus · 41mUSMS / FBI SLC
Escalate
CVE-2026-1119 internal exploitation observed — pre-KEV escalation to Cyber Director
Noah · 1hVendor advisory
Reviewing
OFAC SDN list adds 12 entities re: PRC tech transfer — supply-chain impact assessment
Darius · 2hTreasury OFAC
Promoting
Climate activism: 3 cities planning refinery-site actions Friday — coordination assessed
Marcus · 3hOSINT + fusion
Intelligence Team · The AI workforce producing this picture · human-reviewed before publication
4 Directors · 6 Scouts · Named Human Review
Marcus Reed
Marcus Reed
Physical Threat Director
Civil unrest · domestic terror · soft-target advisories · convergence physical-side analysis
Darius Chen
Darius Chen
Cyber Threat Director
State-aligned APT activity · KEV exposure · convergence cyber-side analysis · CISA + sector ISACs
Maya Ellison
Maya Ellison
Threat Intelligence Director
FTO + DVE + HVE landscape · State Dept advisories · weekly ThreatWatch synthesis · cross-domain triage
Victoria Hale
Victoria Hale
Intelligence Director
Weekly executive briefings · forecasting · strategic synthesis · cross-LOB coordination · senior decision support
Scout + Research Team · 6 agents feeding the directors continuously
Caleb Brooks
Caleb Brooks
Federal Scout
Rafael Torres
Rafael Torres
CA / State + Local
Priya Shaw
Priya Shaw
Commercial Sector
Tessa Monroe
Tessa Monroe
Physical Threat
Noah Kim
Noah Kim
Cyber Threat
Amara Wells
Amara Wells
Research + Enrichment
Governance. All agents are AI workforce members trained on domain corpora, supervised by named human review. Convergence findings require human analyst sign-off before publication. AI-disclosure standard applied to all outputs. Source attribution carried on every finding.
03 · State Actors

Foreign-State Activity Affecting CONUS

Foreign-state operations and influence campaigns with measurable CONUS effect · IC + open-source synthesis
5 active
14d window
Analyst's Take
The throughline this cycle is patience. China's Volt and Salt operations are textbook state-actor pre-positioning — no kinetic action, just persistence in the right places, with strategic dormancy timed against a future Taiwan-contingency window. Russia is reactivating its 2024-vintage influence playbook 18 months early, which suggests Moscow is anchoring on the 2026 midterm cycle as its primary asymmetric lever; Sandworm energy targeting and APT28 spear-phishing of campaign infrastructure are the two indicators we'd weight most heavily. Iran remains the wildcard — capability is real, the post-Gaza retaliation rhetoric is real, but signal-to-noise on actual operational planning indicators is poor. We're watching former-official targeting, Iranian-American dissident threats, and Jewish/Israeli facility patterns as the leading edge. DPRK is doing what DPRK does: monetizing the West to fund the regime via crypto theft and IT-worker infiltration — Lazarus alone is a $800M+ trailing-12-month exposure across US victims.
People's Republic of China
State · APT
Elev
Volt Typhoon grid + water pre-positioning continues. Salt Typhoon expanding telecom carrier compromise. Tech export-control evasion via shell entities.
Ops ImpactCarrier + utility-vendor engagements carry IC sensitivity. Salt Typhoon IOC sweep at carrier-adjacent assets recommended.
3 named opsLast obs 14h
Russian Federation
State + Proxy
Active
Sandworm energy-sector targeting; APT28 election influence ops scaling 18 months ahead of 2026 cycle. Ransomware-as-state-cover patterns.
Ops ImpactEnergy-sector vendor posture review; election-cycle infrastructure hardening with 18-month forward window.
2 named opsLast obs 22h
Iran (IRGC + Affil)
State · APT
Elev
MuddyWater + APT34 targeting US-Israel-aligned orgs post-Gaza posture. Retaliation cycle elevated. Hezbollah-aligned soft-target rhetoric.
Ops ImpactFormer US officials · Iranian-American dissidents · Jewish/Israeli facilities are priority watch through retaliation cycle.
2 named opsLast obs 2d
DPRK
State · Crim
Active
Lazarus $800M+ crypto theft trailing 12 months. IT-worker insider threats confirmed at 12+ Fortune 500 entities.
Ops ImpactIT-worker insider screening at Fortune-tier hiring; sustained crypto-custody targeting; OFAC sanctions exposure.
1 named opLast obs 4d
State-Proxy Influence
Gray Zone · Coord
Watch
Demonstration coordination via state-affiliated information channels. Russia-aligned narrative amplification. PRC United Front activity on US campuses.
Ops ImpactPre-pulse demonstration channels worth tracking; campus engagement monitoring at named institutions.
Multi-sourceContinuous
04 · Terrorist Group Activity

FTO · DVE · HVE Threat Picture

Foreign Terrorist Organizations · Domestic Violent Extremists · Homegrown Violent Extremists with CONUS-relevant activity · State Dept · FBI · NCTC + fusion-center synthesis
6 groups tracked
2 elev · 3 active · 1 watch
14d window
Analyst's Take
The picture this cycle skews domestic. Among the foreign-designated groups, ISIS-K remains the only one demonstrating both intent and capability to induce CONUS lone-actor attacks — the Moscow Crocus model (Mar 2024) confirms operational viability and inspiration material continues to circulate. Al-Qaeda core has degraded; AQAP is publishing but not operating. Iran-aligned (IRGC + Hezbollah) is the FTO category we'd weight up given DOJ-disclosed plot disruptions and the post-Gaza retaliation cycle. The active concern is REMVE accelerationism converging on the Pride Month + summer event cycle — Patriot Front mobilization, Active Club expansion, and Atomwaffen-derivative messaging are tracking against the same June-September calendar that historically produces lone-actor attacks. The FBI's national soft-target advisory issued 3 days ago raised our internal threshold, and the AGAAVE militia / sovereign-citizen category is independently elevating around 2026 election cycle rhetoric. The convergence section below flags where these domestic threats overlap with state-aligned OT activity — a pattern single-domain feeds miss.
FTO · Foreign
4
State Dept designated
DVE · Domestic
2
REMVE + AGAAVE
HVE · Homegrown
1
Lone-actor radicalization
Active Plots
3
Disruptions trailing 30d
ISIS / ISIS-K
FTO · State Dept Designated
Active
Inspiration-driven threats continue. ISIS-K propaganda driving lone-actor radicalization indicators. Recent FBI advisory references ISIS-K material in summer event-cycle targeting. Group retains capability/intent demonstrated by Moscow Crocus attack (Mar 2024).
CONUS Target Profile
Soft targets · mass gatherings · houses of worship · LGBTQ+ venues · military/LE
FBI · NCTC · NCTC Worldwide ThreatLast advisory 3d
Al-Qaeda / AQAP
FTO · State Dept Designated
Watch
Core AQ operational capacity diminished post-decapitation. AQAP continues publishing inspiration content. Ideology persistent; capability primarily regional, with CONUS threats inspiration-based.
CONUS Target Profile
Aviation sector · military/LE · US embassies abroad · Western interests broadly
NCTC · FBIRoutine monitoring
Iran-Aligned (IRGC + Hezbollah)
FTO · IRGC 2019 · Hezbollah 1997
Elev
Post-Gaza retaliation cycle elevated. DOJ-disclosed IRGC plot disruptions against former US officials. Hezbollah financial network operations continue in CONUS per Treasury OFAC actions. Houthis affecting maritime shipping interests.
CONUS Target Profile
Former US officials · Iranian-American dissidents · Jewish / Israeli facilities
DOJ · FBI · Treasury OFAC · NCTCLast obs 8d
Hamas-Affiliated
FTO · State Dept Designated
Active
Fundraising and influence operations rather than direct attack capability in CONUS. Sympathetic charity-network infrastructure remains under continued FBI/Treasury monitoring. Demonstration-coordination overlap with state-proxy influence ops.
CONUS Target Profile
Influence operations · fundraising networks · Jewish / Israeli facilities (rhetorical, not capability)
Treasury OFAC · FBIContinuous monitoring
REMVE — Accelerationist Networks
DVE · Racially/Ethnically Motivated
Elev
Pride Month + summer event cycle driving Patriot Front mobilization elevation. Active Club network expansion. Atomwaffen-derivative messaging tracked. Recent FBI national advisory specifically references accelerationist chatter targeting LGBTQ+ venues + houses of worship.
CONUS Target Profile
LGBTQ+ venues · Pride events · houses of worship · immigrant / minority communities
FBI · fusion centers · SPLC + ADL monitoringForward · 30d cycle
AGAAVE — Militia / Sovereign Citizens
DVE · Anti-Government / Anti-Authority
Active
Recent FBI JTTF Houston arrest of domestic extremist plotting against state capitol. Sovereign citizen LE encounter trends elevated. Militia rhetoric around 2026 election cycle elevating. Anti-government messaging on federal facilities.
CONUS Target Profile
State capitols · federal buildings · courthouse infrastructure · LE personnel · election-related facilities
FBI JTTF · state fusion · ATFLast arrest 5d
HVE — Lone-Actor Radicalization
HVE · Homegrown Violent Extremist
Active
FBI national soft-target advisory active (issued 3d ago). Lone-actor radicalization via online accelerationist content + ISIS-K inspiration material. Concern pattern aligns with summer event cycles. Cross-ideological pollination observed.
CONUS Target Profile
Variable · soft targets predominantly · mass gatherings · festivals/concerts
FBI national advisory · NCTCActive · 3d ago
05 · Foreign Posture

Travel & Personnel Advisories · Global View

US State Department travel advisories with personnel-deployment relevance · Level 3 (Reconsider Travel) and Level 4 (Do Not Travel) destinations mapped globally
19 L4
25 L3
4 changed 30d
Analyst's Take
Lebanon's L4 upgrade is the headline of the week. Hezbollah-Israel cross-border tempo has crossed State Department's threshold and personnel posture for anyone with Beirut or eastern Mediterranean presence needs review in the next 72 hours — including departure-route planning given how quickly commercial aviation contracted during the 2024 escalations. The broader pattern in the Sahel — Niger and Burkina Faso both deteriorating, Mali continuing — represents an 18-month sustained regional collapse driven by JNIM and ISIS-Sahel expansion against weakened post-coup state security, and we expect at least one more L3→L4 escalation in the band before Q3. Mexico's six-state L4 designations remain the highest-volume CONUS-adjacent risk given executive travel volume and the cartel-violence overlap with corporate operations across the border. Russia's L4 stands apart: the wrongful-detention pattern is now policy, not anomaly, and any travel for any reason carries documented hostage risk against US persons. We're watching Venezuela and Colombia divergence carefully — Colombia just stepped down from L3 to L2, Venezuela is trending the other direction.
Global Advisory Map · L3 + L4 Destinations
L4 · Do Not Travel
L3 · Reconsider Travel
Recently changed
🌍

Global Advisory Map

Loading map tiles… If this persists, the Google Maps API key may be quota-exceeded, revoked, or missing this host in its referrer allowlist. Open browser DevTools → Console for the exact error. Pins show State Dept L3 and L4 destinations · click for advisory details.

Browse Destinations by Threat Level
Source · travel.state.gov
Global Advisory Posture
L4 · Do Not Travel
19
Countries
L3 · Reconsider
25
Countries
L2 · Caution
68
Countries
L1 · Normal
85
Countries
Recent Changes · 30d
Lebanon
▲ L3 → L4
Hezbollah-Israel tensions8d ago
Niger
▲ L3 → L4
Post-coup · ISIS-Sahel21d ago
Burkina Faso
L4 reaffirmed
JNIM activity30d ago
Colombia
▼ L3 → L2
Improved security N. depts18d ago
👔 Executive Travel Posture
If your principals or personnel are deploying to Lebanon, Mexico (Sinaloa / Tamaulipas / Colima / Michoacán / Guerrero / Zacatecas), Haiti, Israel / Gaza, or any Sahel L4 in the next 30 days, executive protection posture review is recommended. GSC can stand up tailored pre-deployment threat briefings + on-the-ground coordination for federal, corporate, and HNW principals through our CSG line.
Request Briefing
06 · Public Planned Activities

Civil Unrest & Demonstrations · CONUS

Active and planned protests, rallies, demonstrations with potential for crowd-management or public-safety impact · 14d active + 14d forward
23 active
8 planned 72h
3 elevated risk
Analyst's Take
May Day labor mobilization and the campus encampment cycle are the two volume drivers — together pushing the demonstration count above 23 active events with eight more planned in the next 72 hours. SEIU + UAW + AFL-CIO coordination on May 1 will produce 30K-50K turnout in Chicago alone, with smaller equivalents across 14 other metros. Campus encampments are entering their highest-risk window: commencement disruption potential is elevated at Columbia, UCLA, UMich, and Brown, and four sites have confirmed counter-protest, which is the indicator that historically correlates with on-the-ground escalation. Counter-protest indicators around Pride Month are the elevation we're watching most closely — REMVE-affiliated messaging tracks consistently against the June calendar, and six cities are currently flagged for confirmed counter-protest activity. The pattern that should concern physical security teams running venue operations: Patriot Front + Active Club messaging is timing-aligned with parade routes in metros where local law enforcement coordination is variable. Anti-ICE field-office protests will continue their weekly cadence; risk is medium, not elevating.
CONUS Demonstration Map · 14d Active + Forward
Campus
Political
Labor
Social
Counter-Protest
Faith
Other
📢

CONUS Demonstration Map

Loading map tiles… If this persists, the Google Maps API key may be quota-exceeded, revoked, or missing this host in its referrer allowlist. Open browser DevTools → Console for the exact error. Pins show active and planned demonstrations · click for organizer, crowd, and risk details.

Campus
12
Multi-state · finals overlap
Political
5
Trial cycles · pulses
Labor
15+
May Day · multi-city
Social / Issue
6
Immigration · climate · gun
Counter-Protest
2
Both elevated risk
Campus
Elev Risk

Pro-Palestine campus encampments — finals week + commencement disruption potential

Cities
Columbia · UCLA · UMich · Brown · 8 others
Window
Active · through commencement
Est. crowd
500-5,000 per site
Counter-protest
Confirmed at 4 sites
SJP, JVP coordTracking · 38d
Labor
Med Risk

May Day labor mobilization — UAW, SEIU, AFL-CIO coordinated rallies

Cities
15+ · Chicago · LA · Detroit · NY
Window
May 1 · 11:00-15:00 local
Est. crowd
10K-50K per major city
Counter-protest
Not anticipated
SEIU · UAW · AFL-CIOPlanned · 7d out
Med Risk

Anti-ICE enforcement protests — weekly cadence at ICE field offices

Cities
SF · LA · Chicago · NYC · Boston
Window
Weekly · Sat 12:00-16:00
Est. crowd
200-800 per site
Counter-protest
Sporadic at 2 sites
Multiple immigration orgsRecurring
Political
Elev Risk

Federal trial verdict windows — courthouse activity pulse-driven

Cities
DC · NYC · Atlanta · variable
Window
Verdict day + 48h
Est. crowd
100-2,000 per location
Counter-protest
Confirmed at 3 sites
Variable · partisan-affiliatedPulse-driven
Routine

Climate activism summer mobilization — Just Stop Oil + XR US chapters

Cities
NYC · DC · LA · Houston · Bay Area
Window
June-August · pulse cycles
Est. crowd
Small · disruption-focused
Counter-protest
Not anticipated
JSO · XR US chaptersPlanning · 30d
Counter-Protest
Elev Risk

Pride Month flashpoints — Proud Boys / Patriot Front messaging elevated

Cities
28 major + 80+ smaller events
Window
June 1-30 · weekend pulses
Risk pattern
6 cities flagged for counter-protest
LE coord
Increased at flagged sites
Multi-source · OSINTForward · 14d
07 · Significant Incidents

Public Safety Brief · 14-Day Window

Mass-casualty events, threats of violence, transit incidents, soft-target advisories · FBI · DHS · regional fusion centers · open source
7 active
5 investigation
2 cleared
🌀 All-Hazards Watch · Environmental + Operational
CONUS scope · NWS · USGS · CalFire · regional EOCs · 7d window
🔥 Wildfire
Active
CA · OR · WA Red Flag Warnings · 3-county OES pre-stage
🌪 Severe Weather
Watch
Plains tornado outlook elev · 4-state convective risk Wed
🌊 Hurricane
Routine
Pre-season · NHC tracking · no organized systems
⛰ Seismic
Watch
CA: 4 M4.0+ events trailing 14d · USGS routine cadence
🚰 Drought
Active
SW US D3/D4 · CA + AZ + NV agricultural impact
Analyst's Take
The 14-day window shows a tempo elevated by pattern-driven advisories rather than singular kinetic events. The USMS courthouse threat pattern is the operational concern: VoIP-spoofed bomb threats against western district federal buildings have now produced six incidents in trailing 30 days using consistent TTPs — this is a coordinated harassment campaign, not isolated callers, and we expect it to continue. The FBI national soft-target advisory issued three days ago is the broader threshold-setter: lone-actor accelerationist chatter is trending up against summer event cycles, with houses of worship and LGBTQ+ venues specifically flagged. Transit incidents in NYC MTA and Chicago CTA share TTP profile and are under joint investigation — this is the kind of pattern that often resolves as a single actor traveling. The Phoenix workplace shooting was non-pattern (former employee, no ideological nexus) and should not influence broader posture assessments. Pacific NW wildfire mobilization is the operational sleeper: Red Flag Warnings across CA / OR / WA combined with mass-evacuation pre-staging at three county OES centers suggests the season is opening earlier and harder than 2025 — physical-security teams with facilities in those AORs should validate continuity plans now, not after first deployment.
CONUS Incident Map · 14d Window
Shooting
Threat
Transit
Arrest
Advisory
🚨

CONUS Incident Map

Loading map tiles… If this persists, the Google Maps API key may be quota-exceeded, revoked, or missing this host in its referrer allowlist. Open browser DevTools → Console for the exact error. Pins show significant incidents in 14d window · click for incident details and status.

08 · State-Aligned Cyber Activity

APTs & Criminal Operations · Active

Currently active threat actor sets with recent CONUS observations · state-aligned listed first, criminal second
4 active
14 tracked total
Analyst's Take
The PRC pair — Volt Typhoon and Salt Typhoon — are the operational dominant concern. Volt's living-off-the-land tradecraft in grid and water OT is purpose-built for dormancy through a US response cycle; we have no high-confidence kinetic timeline, which is precisely the point — pre-positioning is the operation, not a prelude to one. Salt Typhoon has now reached nine named US carriers and the lawful-intercept system access is the troubling vector: it provides counterintelligence value (who is being monitored by whom) far beyond a typical telecom compromise. MuddyWater's tempo is the Iran retaliation barometer — operations up 40% post-Gaza, and any rapid escalation in MuddyWater spear-phishing against US-Israel-aligned targets would correlate strongly with a kinetic Iran decision. Scattered Spider remains the most operationally damaging non-state actor in CONUS by dollar impact — help-desk social engineering and MFA-fatigue work because they exploit human and process gaps that no amount of EDR tuning fixes. MITRE ATT&CK technique IDs below each card are clickable in the production product; map to your detection coverage and prioritize gaps against your sector exposure.
Volt Typhoon
PRC · State-aligned APT
Active
TTP: Living-off-the-land pre-positioning across grid, water, telecom OT. Credential theft, dormancy, careful EDR evasion. Strategic patience.
Targets: Crit Infra · EnergyObs 14h ago
MITRET1133T1078T1059.001T1562
Salt Typhoon
PRC · State-aligned APT
Active
TTP: Telecom carrier targeting; lawful-intercept system access; metadata exfil at scale. Has reached 9 named US carriers.
Targets: Telecom · GovtObs 22h ago
MITRET1190T1078.004T1098T1041
MuddyWater
Iran (MOIS) · State APT
Active
TTP: Spear-phishing US-Israel-aligned orgs; PowerShell-based backdoors; opportunistic credential collection. Post-Gaza retaliation cycle.
Targets: Govt · Defense · NGOObs 2d ago
MITRET1566.001T1059.001T1027T1003
Scattered Spider
English-speaking · Criminal
Active
TTP: Help-desk social engineering, MFA-fatigue, ransomware via Okta / AzureAD pivot. Insurance + finance heavy.
Targets: Finance · Retail · HospObs 8h ago
MITRET1566.004T1621T1556.006T1486
09 · CISA KEV

Active CVEs · Critical Infrastructure Exposure

Currently exploited vulnerabilities with critical-infrastructure exposure · sorted by KEV addition date desc
8 KEV
23 tracked
Analyst's Take
Eight CVEs sit on CISA's Known Exploited Vulnerabilities list with critical-infrastructure exposure in the current cycle — but the headline isn't the count, it's the vendor concentration. Cisco IOS XE, Schneider Modicon, Citrix NetScaler, Ivanti Connect Secure, and Fortinet FortiOS together account for five of the eight — all are edge-network or OT vendors with deployment density across federal, energy, water, and finance sectors. That concentration is structural, not coincidental: state-aligned actors aggressively pursue widely-deployed appliance vulnerabilities because patching cadence in these categories is poor and exposure persists for months after disclosure. CVE-2026-0817 in Schneider Modicon is the one we'd patch first — water and energy ICS exposure, CVSS 9.4, observed in active state-aligned exploitation by both Sandworm and Volt Typhoon clusters per CISA AA bulletins. The two-day gap between KEV add date and now means most organizations are still vulnerable: BOD 22-01 federal patch deadlines are 14 days for KEV criticals, but commercial cadence trails federal by 3-6 weeks on average. Schneider, Citrix, and Ivanti exposures correlate with the Volt Typhoon and MuddyWater operations called out above — patching these is convergence response, not just hygiene.
CVECVSSVendor / ProductKEVSectorsAdded
CVE-2026-10429.8Cisco IOS XEKEV ✓Crit Infra · Energy · Govt2d ago
CVE-2026-08179.4Schneider ModiconKEV ✓Crit Infra · Water · Energy3d ago
CVE-2026-05998.6Citrix NetScaler ADCKEV ✓Finance · Healthcare · Govt4d ago
CVE-2026-03818.1Ivanti Connect SecureKEV ✓Govt · Finance · Crit Infra5d ago
CVE-2025-98769.1Fortinet FortiOSKEV ✓All sectors7d ago
10 · Physical + Cyber Overlap

Cross-Domain Convergence Events

Incidents where physical security and cyber operations require joint coordination · the GSC differentiator
4 active
Trending up
Analyst's Take
Convergence findings are where federal and commercial threat products almost always miss the story. Adversaries don't respect the physical/cyber boundary, but our entire intelligence apparatus is organized by it — CISA does cyber, FBI does FBI, NCTC does terrorism, fusion centers do geography. When a DVE accelerationist target set overlaps with a Volt Typhoon OT pre-positioning target set in the same utility scope, that overlap is the operative concern, and neither single-domain feed will surface it. Election infrastructure is the canonical example: polling-place physical security and voter-registration database integrity are two different vendors, two different posture reviews, and two different incident-response paths — but adversaries treat them as one attack surface. The Salt Typhoon + telecom POP convergence we flag below is the kind of finding that wouldn't exist in any single-source TI feed — it requires cyber attribution from CISA, physical-access risk modeling from carrier security teams, and an analyst willing to connect them. This is the section federal customers ask us about first. A senior CISO running pure-cyber and a senior PSD running pure-physical, even at the same organization, would each miss what this section surfaces when read alone.
⚡ Critical Infra Convergence
High

Volt Typhoon pre-positioning at water utility SCADA — physical perimeter posture review required at affected sites

Physical
Perimeter access review · CCTV log audit · maintenance-window vendor verification
Cyber
IOC ingest · SCADA segmentation review · DC credential reset · vendor remote-access audit
Recommended. Coordinated 72-hr exercise combining physical perimeter walk + cyber IOC sweep. CISA AA24-038A IOCs distributed to subscribers.
NERC E-ISAC + CISA · 14h agovia Marcus Reed + Darius Chen
🗳️ Election Infrastructure
High

Election cycle ramp — physical polling-place security + voter-reg system integrity coordinated posture

Physical
Polling-place vendor walkthrough · drop-box camera audit · ballot transport chain-of-custody
Cyber
Voter-reg DB integrity check · EMS air-gap verification · poll-worker phishing training
Recommended. Joint physical + cyber tabletop with Registrar of Voters across affected jurisdictions. CA SOS advisory provides framework.
CA SOS Advisory 2026-04 · 7d agovia Marcus Reed + Darius Chen
⚡ Energy · DVE + OT Convergence
Med

REMVE accelerationist physical-threat indicators against substations overlap with Volt Typhoon OT pre-positioning in same utility scope

Physical
Substation perimeter access review · physical reconnaissance-pattern detection · grounds-keeper / contractor vetting
Cyber
OT segmentation audit · Volt Typhoon IOC sweep · SCADA + EMS credential review · vendor remote-access logs
Recommended. 14-day coordinated exercise at substations flagged in FBI advisories. Pattern of cross-domain pre-positioning is the operative concern — neither posture alone is sufficient when actors from both threat groups are in the same target set.
FBI national advisory + NERC E-ISAC + CISA · 3d agovia Marcus Reed + Darius Chen
📡 Telecom · Cyber + Physical Access
High

Salt Typhoon carrier compromise elevates physical-access posture concerns at telco POP facilities

Physical
POP perimeter + cage access review · vendor + maintenance access logs · CCTV audit at named carriers · key-management review
Cyber
Lawful-intercept system audit · network segmentation check · privileged-access review · long-dormant credential rotation
Recommended. Concurrent physical + cyber audit at affected carrier POPs. Many telco facilities have known under-protected physical access paths; a sophisticated cyber actor with insider physical access dramatically expands attack surface.
CISA Salt Typhoon advisory + carrier security · 12h agovia Marcus Reed + Darius Chen
Continue · Build Your Own AOR

This is the national picture. Your tailored AOR is the next step.

Federal contracting officers, critical-infrastructure CISOs, and physical security directors subscribe to receive a version of this picture scoped to their facilities, jurisdictions, vendor stack, and personnel posture — with the same agent team behind it. Existing customers include the City of Redding / Shasta County operating picture and Canyon Lake / Bexar County deployments.
What Subscribers See · Beyond this preview · live product features
Live Product
🔍
Search + Sector Lenses
Full-text across findings; sector filters (Energy · Telecom · Water · Election · Finance · Healthcare · Govt)
Watchlists + Alerts
Save entities, geographies, actors, CVEs · push notifications when assessments change
📥
Export + API
STIX 2.1 · CSV · PDF executive briefs · REST API with audit logging for tool integration
🎯
Tailored AOR
Your jurisdictions, facilities, vendor stack, personnel posture · agent team scoped to your AOR
📈
Historical + Trending
Trend analysis across all findings · 90-day retention default · longer for compliance
📅
Weekly Briefings
President's Weekly Briefing video + transcript · executive synthesis · forecasting + decisions
📱
Mobile + Field Ops
Responsive portal · push to mobile · Teams integration · field-staff role views
🔒
Federal Workflows
FOUO handling · SAM/CAGE-aligned reporting · classification-appropriate distribution · ATO path
GSC ThreatWatch · National · State of the Nation · CONUS + global advisory scope · 9 sections · sample data
Preview · May 17, 2026 · gscsec.com