Firewall integrations

Fortinet

Elevate the power of your Fortinet Fortigate Firewall using by adding our Intelligence.

Palo Alto

Palo Alto Firewalls can be hardened with our threat intelligence as well.

Sophos XGS

Enhance the Sophos XGS Firewall with our threat intelligence.

OPNsense

Enhance your OPNsense Firewall with our threat intelligence using the native plugin.

SIEM integrations

Splunk

Splunk is a great platform, but without the right Threat Intelligence it's just a log server. Try our threat intelligence today. 

Microsoft Sentinel

One of the most used SIEM solutions should be enriched with the right Intelligence. At Q-Feeds you're at the right place!

Other

Luckily there are many other SIEM vendors whom support 3rd party threat intelligence.

Threat Intelligence Portal

Darkweb Monitoring

Darkweb monitoring is one of our services, not only for threat intelligence but also for you most important assets.

Threat Lookup

With Threat Lookup you get full insights in our IOC database, including full MITRE ATT&K mapping.

External Attack Surface Management

A toolset to check your external facing assets exposed on the internet

Vulnerability Scanner

A comprehensive vulnerability scanner which can scan your infrastructure and web applications

Brand Protection

Protect your brand for look-a-likes and potential phishing attempts

Services

TAXII Feeds & Server Software

TAXII/STIX2.1 standard. Both in form of feeds and server software available

Implementation

Need help with implementations? No worries, we have a strong network of partners who are able to help you.

Solutions

Enrich my SIEM

Elevate the power of your SIEM solution using by adding our Intelligence.

Enrich my Firewall

Firewalls can be hardened with our threat intelligence as well.

Prevent phishing

Enhance your protection against phishing

Achieve compliancy

Achieve compliancy by correlating the best threat intelligence to your logs

Futuristic eye design with circuits and geometric shapes.

Company

About

Read here all about Q-Feeds

News and Updates

Cybersecurity news and updates about us

Publications

All of our media coverage in one place

Become a reseller

Strengthen your portfolio with our comprehensive reseller program

Partner locator

Find our certified partners here

Contact

For all your questions or inquiries

Neural network representation of a human brain

Support

My Account

Access your account and manage your licenses

Downloads & Manuals

On this page you find white papers and manuals

Knowledge base

Our knowledge base full of implementation instructions

Start for free

Start your cyber security intelligence journey here

Abstract geometric wireframe human head

Inside cybersecurity with Tony Anscombe – May 2026 insights and updates

May 30, 2026 | Threat Intelligence Research

Poland Faces Cyber Intrusions in Water Treatment Facilities

TL;DR
Recent breaches targeting Poland’s water treatment facilities highlight vulnerabilities in industrial control systems. A related AI-directed attack in Mexico demonstrates challenges in bridging gaps between IT and operational technology systems.

Main Analysis
Tony Anscombe, ESET’s Chief Security Evangelist, in his recent overview, underscores significant cyber-intrusions experienced by five water treatment plants in Poland, reported by the Internal Security Agency (ABW). These breaches occurred in 2024 and 2025, primarily leveraging weak passwords and direct internet exposure as attack vectors. This aligns with similar attack patterns previously observed in the Polish energy sector, specifically utilizing the DynoWiper malware.

In Mexico, an alleged AI-directed attack targeted governmental systems, successfully exfiltrating substantial data. However, this attack notably failed to penetrate operational technology (OT) systems at a water utility plant, illustrating the ongoing difficulties attackers face when attempting to breach the divide between IT and OT environments. The vulnerabilities that facilitated the initial breach of government services suggest a need for enhanced security measures across sectors reliant on such technologies.

The revelation from Google regarding an AI-generated zero-day exploit marks a pivotal moment in the cybersecurity landscape. This development signifies a potential escalation in the sophistication and capabilities of threat actors leveraging AI tools to create novel cyber threats, which could pose significant challenges for defenders in any sector.

Defensive Context
Organizations operating within critical infrastructure sectors, particularly those involving water treatment and other OT environments, must be especially vigilant in light of these incidents. The reported methodologies indicate that entities relying on weak security practices, such as poor password management and inadequate network segmentation, remain at high risk of similar attacks.

Why This Matters
The breaches in Poland point to a growing threat against critical infrastructure entities that may not be fully prepared to defend against cyber intrusions. The dual exposure of both ICS and IT systems implies a need for robust defense strategies to mitigate risks associated with these vulnerabilities.

Defender Considerations
Focus should be placed on evaluating access controls, enforcing strong password policies, and ensuring that critical systems are not exposed to the internet. Understanding the implications of AI-driven attacks can inform incident response strategies, enabling faster detection and containment.

Indicators of Compromise (IOCs)
The article does not detail specific IOCs, but the findings highlight general vulnerabilities linked to weak passwords and the exposure of ICS to the internet as key vectors in these types of attacks.

Click here for the full article

Try our Intelligence today!

Streamline your security operations with a free Q-Feeds trial and see the difference.

Other articles