| 2026-05-12 |
Software Bill of Materials for AI - Minimum Elements
A software bill of materials (SBOM) acts as an “ingredients list” for software that better positions organizations to understand their supply chains and make risk-informed decisions about how to protect their critical systems. The guidance builds on CISA’s previous work with federal and international partners to establish a shared vision for a software bill of materials and provides recommendations on minimum elements that should be included in a…
|
ACN
ANSSI
CCCS
CERT-EU
CISA
NCSC-UK
NISC
|
| 2026-04-23 |
Defending Against China-Nexus Covert Networks of Compromised Devices
Over the past few years there has been a major shift in the tactics, techniques and procedures (TTPs) used by China-nexus cyber actors, moving away from the use of individually procured infrastructure, and towards the use of externally provisioned, large-scale networks of compromised devices.
|
AIVD
ASD/ACSC
CCCS
CISA
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-SE
NCSC-UK
NSA
|
| 2026-04-23 |
International cyber agencies share fresh advice to defend against China-linked covert networks
GCHQ’s National Cyber Security Centre with UK industry and 15 international partners shine light on best protections against methods used by China-linked threat actors. Covert networks, often made up of compromised devices such as smart devices, are being used to disguise the origins and attributions of cyber attacks.
|
AIVD
ASD/ACSC
CCCS
CISA
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-SE
NCSC-UK
NSA
|
| 2026-01-14 |
Secure Connectivity Principles for Operational Technology
SSeeccuurree CCoonnnneeccttiivviittyy PPrriinncciipplleess ffoorr OOppeerraattiioonnaall TTeecchhnnoollooggyy ((OOTT)) Operational technology (OT) environments - which have long been centred on safety, uptime, and operational continuity - are now more interconnected than ever.
|
ASD/ACSC
CCCS
FBI
NCSC-NL
NCSC-NZ
NCSC-UK
|
| 2025-12-15 |
Principles for the Secure Integration of Artificial Intelligence in Operational Technology
CISA | ASD’s ACSC | NSA AISC | FBI | Cyber Centre | BSI | NCSC-NL | NCSC-NZ | NCSC-UK Introduction ................................................................................................................................................................... 3 Important Terminology ....................................................................................................................................... 3 Scope ...................
|
ASD/ACSC
CCCS
CISA
FBI
NCSC-NL
NCSC-NZ
NCSC-UK
NSA
|
| 2025-12-09 |
Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure
Actions for Operational Technology Owners and Operators to Take Today to Mitigate Cyber Threats Related to Pro-Russia Hacktivists Activity Reduce exposure of operational technology (OT) assets to the public-facing internet. Adopt mature asset management processes, including mapping data flows and access points. Ensure that OT assets are using robust authentication procedures.
|
ASD/ACSC
CCCS
CISA
DC3
DOE
EC3
EPA
FBI
NCSC-NZ
NCSC-UK
NSA
NUKIB
|
| 2025-12-09 |
Pro-Russia Hacktivists Conduct Opportunistic Attacks Against U.S. and Global Critical Infrastructure
FBI, CISA, National Security Agency (NSA), and the following partners—hereafter referred to as “the authoring organizations”—are releasing this joint advisory on the targeting of critical infrastructure by proRussia hacktivists: The authoring organizations assess pro-Russia hacktivist groups are conducting less sophisticated, lowerimpact attacks against critical infrastructure entities, compared to advanced persistent threat (APT) groups.
|
ASD/ACSC
CCCS
DC3
DOE
EC3
EPA
FBI
NCSC-NZ
NCSC-UK
NSA
NUKIB
|
| 2025-09-29 |
Creating and Maintaining a Definitive View of Your Operational Technology (OT) Architecture
It is aimed at cyber security professionals working in organisations that deploy or operate OT across greenfield and brownfield deployments. Integrators and device manufactures can also use these principles to ensure their solutions enable effective asset and configuration management.
|
ASD/ACSC
CCCS
CISA
FBI
NCSC-NL
NCSC-NZ
NCSC-UK
|
| 2025-09-03 |
Joint Guidance: A Shared Vision of Software Bill Of Materials For Cybersecurity
Widespread adoption of SBOM will strengthen security, reduce risk, and Most modern software is comprised of software components, modules, and libraries from open source and proprietary software worlds, rather than developers creating it from scratch. As concerns about the security and provenance of software grow, it is critical to understand the risks in the software’s supply chain— including the risks of the underlying software components.
|
ANSSI
ASD/ACSC
CCCS
CISA
CSA
NCO
NCSC-NL
NCSC-NZ
NIS
NSA
NUKIB
|
| 2025-08-27 |
Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System
Executive summary People’s Republic of China (PRC) state-sponsored cyber threat actors are targeting networks globally, including, but not limited to, telecommunications, government, transportation, lodging, and military infrastructure networks.
|
AISE
AISI
AIVD
ASD/ACSC
AW
CCCS
CISA
CNI
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-UK
NSA
NUKIB
SKW
SUPO
|
| 2025-08-27 |
Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System
While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks.
|
AISE
AISI
AIVD
ASD/ACSC
AW
CCCS
CISA
CNI
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-UK
NSA
NUKIB
SKW
SUPO
|
| 2025-08-27 |
CSA: Countering China State Actors Compromise of Networks
While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks.
|
AISE
AISI
AIVD
ASD/ACSC
AW
CCCS
CISA
CNI
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-UK
NSA
NUKIB
SKW
SUPO
|
| 2025-08-13 |
Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators
Using these tools helps owners and operators identify which assets in their environment should be secured and protected, and structure their defenses accordingly to reduce the risk a cybersecurity incident poses to the organization’s mission and service continuity. An asset inventory is an organized, regularly updated list of an organization’s systems, hardware, and software.
|
ASD/ACSC
CCCS
CISA
DOE
EPA
FBI
NCSC-NL
NCSC-NZ
NSA
|
| 2025-05-21 |
Russian GRU Targeting Western Logistics Entities and Technology Companies
This joint cybersecurity advisory (CSA) highlights a Russian state-sponsored cyber those involved in the coordination, transport, and delivery of foreign assistance to Ukraine. Since 2022, Western logistics entities and IT companies have faced an elevated risk of targeting by the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (85th GTsSS), military unit 26165—tracked in the cybersecurity community under…
|
ANSSI
ASD/ACSC
CCCS
DC3
DDIS
EFIS
FBI
MIVD
NCSC-UK
NSA
NUKIB
SKW
USCC
|
| 2025-01-13 |
Secure by Demand: Priority Considerations for Operational Technology Owners and Operators When Selecting Digital Products
Many OT products are not designed and developed with Secure by Design principles1 and commonly have weaknesses, such as weak authentication, known software vulnerabilities, limited logging, insecure default settings and passwords, and insecure legacy protocols. Cyber threat actors can easily exploit these weaknesses across multiple victims to gain access to control systems.
|
ASD/ACSC
CCCS
CISA
EPA
FBI
NCSC-NL
NCSC-NZ
NCSC-UK
NSA
TSA
|
| 2024-01-23 |
CSI: Engaging with Artificial Intelligence
The purpose of this publication is to provide organisations with guidance on how to use AI systems securely. The paper summarises some important threats related to AI systems and prompts organisations to consider steps they can take to engage with AI while managing risk.
|
ASD/ACSC
CCCS
CISA
CSA
FBI
NCSC-NZ
NCSC-UK
NSA
|