| 2026-09-23 |
Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators
The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)—hereafter referred to as the “authoring agencies”—have published this fact sheet to highlight considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working with third-party industrial control system (ICS) integrators.
|
FBI
|
| 2026-09-08 |
China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S.
|
FBI
NSA
|
| 2026-09-02 |
Communicating Under Pressure: Best Practices for Service Providers
Service outages impacting IT and operational technology (OT) systems can be damaging and disruptive for customers, network defenders, critical infrastructure owners and operators, and the general public. During incidents that reach or exceed established thresholds, whether caused by malicious activity or a nonmalicious event, service providers must communicate effectively so end users can minimize operational impact.
|
ASD/ACSC
CCCS
FBI
NCSC-NZ
NCSC-UK
|
| 2026-08-10 |
#StopRansomware: Gunra Ransomware
Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid.
|
DC3
FBI
KNPA
NSA
USSS
|
| 2026-07-30 |
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans.
|
EPA
FBI
|
| 2026-07-29 |
2026 Minimum Elements for a Software Bill of Materials (SBOM)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the co-authoring organizations, updated the Minimum Elements for a Software Bill of Materials (SBOM) to reflect current SBOM needs, while preserving the core principles of the document published in 2021 by the National Telecommunications and Information Administration (NTIA).
|
ASD/ACSC
FBI
NSA
NTIA
|
| 2026-07-28 |
CI Fortify – Advice for isolating vital systems
This guidance contains practical steps for critical infrastructure (CI) organizations to isolate vital operational technology and enabling systems from all other networks in the event of disruption or crisis and operate in isolation for an extended period. Developed to address escalating cyber threats, the guidance outlines key steps for identifying critical systems, mapping connections, and implementing effective separation points.
|
ASD/ACSC
FBI
|
| 2026-07-23 |
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Read our joint advisory on LAUNDRY BEAR's exploitation of Zimbra Collaboration Suite.
|
AISE
AISI
AIVD
ANSSI
ASD/ACSC
AW
CCCS
CNI
DC3
DCSA
DDIS
DGSI
EFIS
FBI
FDI
MIVD
NCIS
NCSC-NZ
NCSC-SE
NCSC-UK
NSA
NUKIB
SIS RM
SKW
SUPO
Treasury
|
| 2026-07-15 |
Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers
This guidance outlines best practices for suppliers to design and implement a coordinated vulnerability disclosure (CVD) program to effectively and transparently collaborate with security researchers to report and remediate vulnerabilities.
|
NCSC-NL
NCSC-UK
NSA
|
| 2026-07-13 |
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks.
|
ASD/ACSC
CCCS
FBI
NCSC-NZ
NCSC-UK
NSA
|
| 2026-06-26 |
Russian Intelligence Services Continue to Target Commercial Messaging Applications
This PSA is an update to the March 2026 Russian Intelligence Services Target Commercial Messaging Application Accounts and provides recent tactics, recommended mitigations, and samples of phishing messages.
|
FBI
|
| 2026-06-22 |
The AI shift in cyber risk: why leaders must act now
Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk. As the leaders of the Five Eyes cyber security agencies, we are united in our call to action: the evolving landscape of artificial intelligence (AI) is rapidly transforming cyber risk, and we must act swiftly to remain ahead.
|
ASD/ACSC
CCCS
NCSC-UK
NSA
|
| 2026-06-02 |
CISA and Partners Urge Hardening Automatic Tank Gauge Systems
The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the (EPA), the Transportation Security Administration (TSA), the Department of Transportation (DOT), and the U.S. Department of Agriculture (USDA)—hereafter referred to as “the authoring organizations”—are aware of malicious cyber activity targeting U.S.-based automatic tank gauge (ATG) systems.
|
DOE
EPA
FBI
NSA
TSA
USDA
|
| 2026-05-12 |
Software Bill of Materials for AI - Minimum Elements
A software bill of materials (SBOM) acts as an “ingredients list” for software that better positions organizations to understand their supply chains and make risk-informed decisions about how to protect their critical systems. The guidance builds on CISA’s previous work with federal and international partners to establish a shared vision for a software bill of materials and provides recommendations on minimum elements that should be included in a…
|
ACN
ANSSI
BSI
CCCS
CERT-EU
NCSC-UK
NISC
|
| 2026-05-01 |
Careful Adoption of Agentic AI Services
CISA, in collaboration with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and other international and U.S. partners, released guidance for organizations on adopting agentic artificial intelligence (AI) systems. This guide outlines key security challenges and risks associated with agentic AI, and provides actionable steps for designing, deploying, and operating these systems safely.
|
ASD/ACSC
|
| 2026-04-29 |
Adapting Zero Trust Principles to Operational Technology
Zero trust is a modern, adaptive approach to cybersecurity that eliminates implicit trust and requires continuously validating access based on identity, context, and risk. With advancements in technology, OT systems that were traditionally isolated or manually operated are now increasingly interconnected, digitally monitored, and remotely controlled.
|
DOE
FBI
|
| 2026-04-23 |
Defending Against China-Nexus Covert Networks of Compromised Devices
Over the past few years there has been a major shift in the tactics, techniques and procedures (TTPs) used by China-nexus cyber actors, moving away from the use of individually procured infrastructure, and towards the use of externally provisioned, large-scale networks of compromised devices.
|
AIVD
ASD/ACSC
BSI
CCCS
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-SE
NCSC-UK
NSA
|
| 2026-04-23 |
FIRESTARTER Backdoor
Malware Analysis Report at a Glance Malware Name FIRESTARTER Original Publication April 23, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) analyzed a sample of FIRESTARTER malware obtained from a forensic investigation.
|
NCSC
NCSC-UK
|
| 2026-04-23 |
International cyber agencies share fresh advice to defend against China-linked covert networks
GCHQ’s National Cyber Security Centre with UK industry and 15 international partners shine light on best protections against methods used by China-linked threat actors. Covert networks, often made up of compromised devices such as smart devices, are being used to disguise the origins and attributions of cyber attacks.
|
AIVD
ASD/ACSC
BSI
CCCS
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-SE
NCSC-UK
NSA
|
| 2026-04-07 |
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
This activity has led to PLC disruptions across several U.S. critical infrastructure sectors through malicious interactions with the project file and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss. U.S.
|
CNMF
DOE
EPA
FBI
NIST
NSA
|
| 2026-03-20 |
Russian Intelligence Services Target Commercial Messaging Application Accounts
CISA and the Federal Bureau of Investigation released a Public Service Announcement (PSA) warning about ongoing phishing campaigns by cyber actors associated with the Russian Intelligence Services targeting commercial messaging applications (CMAs). These campaigns aim to bypass encryption to compromise individual user accounts with targets including current and former U.S.
|
FBI
|
| 2026-02-25 |
CISA and Partners Release Guidance for Ongoing Global Exploitation of Cisco SD-WAN Systems
CISA and partners have observed malicious cyber actors targeting and compromising Cisco SD-WAN systems of organizations, globally. These actors have been observed exploiting a previously undisclosed authentication bypass vulnerability, CVE-2026-20127, for initial access before escalating privileges using CVE-2022-20775 and establishing long-term persistence in Cisco SD-WAN systems.
|
ASD/ACSC
CCCS
NCSC-NZ
NCSC-UK
NSA
|
| 2026-02-25 |
CSA: Exploitation of SD-WAN Appliances
Malicious cyber threat actors are targeting Software-Defined Wide Area Networks (SDWANs) of organizations globally. These actors exploited a Cisco Catalyst SD-WAN controller authentication bypass vulnerability, CVE-2026-20127. After exploitation of this vulnerability the malicious actors add a rogue peer, and eventually gain root access to establish long-term persistence in SD-WANs.
|
ASD/ACSC
CCCS
NCSC-NZ
NCSC-UK
NSA
|
| 2026-02-05 |
Reducing the Attack Surface for End-of-Support Edge Devices
The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.K.’s National Cyber Security Centre (NCSC) are releasing this fact sheet to urge defensive action against malicious cyber activity by nation-state threat actors. Nation-state threat actors exploit end-of-support (EOS) edge devices—including load balancers, firewalls, routers, and VPN gateways—to gain network access, maintain persistence, and compromise sensitive data.
|
ASD/ACSC
FBI
NCSC
|
| 2026-01-30 |
CTR: Zero Trust Implementation Guideline Phase Two
Cybersecurity Technical Report Zero Trust Implementation Guideline January 2026 1.0 Initial publication The information and opinions contained in this document are provided "as is" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Gove…
|
NSA
|
| 2026-01-14 |
Secure Connectivity Principles for Operational Technology (OT)
This guidance outlines eight principles to use as a framework to design, secure, and manage connectivity into OT environments. These principles are particularly critical for operators of essential services.
|
NCSC-UK
|
| 2026-01-14 |
CTR: Zero Trust Implementation Guideline Primer
Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product This document was developed in furtherance of NSA’s cybersecurity missions, including its responsibilities to identify and disseminate threats, and to d…
|
NSA
|
| 2025-12-19 |
CISA and Partners Release Update to Malware Analysis Report BRICKSTORM Backdoor
This update provides information on additional samples, including Rust-based samples. These samples demonstrate advanced persistence and defense evasion mechanisms, such as running as background services, and enhanced command and control capabilities through encrypted WebSocket connections.
|
CCCS
NSA
|
| 2025-12-19 |
Senior U.S. Officials Continue To Be Impersonated in Malicious Messaging Campaign
This is an update to Public Service Announcement I-051525-PSA , released May 15, 2025. Activity dating back to 2023 reveals malicious actors have impersonated senior U.S. state government, White House, and Cabinet level officials, as well as members of Congress to target individuals, including officials' family members and personal acquaintances. If you receive a message claiming to be from a current or former senior U.S.
|
FBI
|
| 2025-12-15 |
Principles for the Secure Integration of Artificial Intelligence in Operational Technology
CISA | ASD’s ACSC | NSA AISC | FBI | Cyber Centre | BSI | NCSC-NL | NCSC-NZ | NCSC-UK Introduction ................................................................................................................................................................... 3 Important Terminology ....................................................................................................................................... 3 Scope ...................
|
ASD/ACSC
BSI
CCCS
FBI
NCSC-NL
NCSC-NZ
NCSC-UK
NSA
|
| 2025-12-09 |
Opportunistic Pro-Russia Hacktivists Attack US and Global Critical Infrastructure
This advisory, published as an addition to the joint fact sheet on Primary Mitigations to Reduce Cyber Threats to Operational Technology (OT) released in May 2025 , details that pro-Russia hacktivist groups are conducting less sophisticated, lower-impact attacks against critical infrastructure entities, compared to advanced persistent threat groups.
|
DOE
EPA
FBI
NSA
|
| 2025-12-09 |
Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure
Actions for Operational Technology Owners and Operators to Take Today to Mitigate Cyber Threats Related to Pro-Russia Hacktivists Activity Reduce exposure of operational technology (OT) assets to the public-facing internet. Adopt mature asset management processes, including mapping data flows and access points. Ensure that OT assets are using robust authentication procedures.
|
ASD/ACSC
BSI
CCCS
DC3
DOE
EC3
EPA
FBI
NCSC-NZ
NCSC-UK
NSA
NUKIB
|
| 2025-12-04 |
BRICKSTORM Backdoor
Malware Analysis at a Glance Malware Name BRICKSTORM Original Publication Dec. 4, 2025 Last Update Feb. 11, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Canadian Centre for Cyber Security (Cyber Centre) assess People’s Republic of China (PRC) state-sponsored cyber actors are using BRICKSTORM malware for long-term persistence on victim systems.
|
CCCS
NSA
|
| 2025-12-03 |
CISA, Australia, and Partners Author Joint Guidance on Securely Integrating Artificial Intelligence in Operational Technology
CISA and the Australian Signals Directorate’s Australian Cyber Security Centre, in collaboration with federal and international partners, have released new cybersecurity guidance: Principles for the Secure Integration of Artificial Intelligence in Operational Technology .
|
ASD/ACSC
FBI
NSA
|
| 2025-11-19 |
Bulletproof Defense: Mitigating Risks from Bulletproof Hosting Providers
This document was developed through the Joint Ransomware Task Force (JRTF), a U.S. interagency body established by Congress in the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) to ensure unity of effort in combating the growing threat of ransomware attacks.
|
ASD/ACSC
CCCS
DC3
FBI
NCSC-NL
NCSC-NZ
NCSC-UK
NSA
|
| 2025-11-13 |
CISA and Partners Release Advisory Update on Akira Ransomware
Today, Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Federal Bureau of Investigation, Department of Defense Cyber Crime Center, Department of Health and Human Services, and international partners, released an updated joint Cybersecurity Advisory, #StopRansomware: Akira Ransomware , to provide network defenders with the latest indicators of compromise, tactics, techniques, and procedures, and detection methods…
|
FBI
HHS
|
| 2025-11-13 |
#StopRansomware: Akira Ransomware
#StopRansomware: Akira Ransomware Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Akira Prioritize remediating known exploited vulnerabilities. Enable and enforce phishing-resistant multifactor authentication (MFA).
|
DC3
EC3
FBI
HHS
NCSC-NL
|
| 2025-10-30 |
New Guidance Released on Microsoft Exchange Server Security Best Practices
Threat activity targeting Exchange continues to persist, and organizations with unprotected or misconfigured Exchange servers remain at high risk of compromise. This product is provided subject to this Notification and this Privacy & Use policy.
|
NSA
|
| 2025-09-29 |
CISA and UK NCSC Release Joint Guidance for Securing OT Systems
CISA, in collaboration with the Federal Bureau of Investigation, the United Kingdom’s National Cyber Security Centre, and other international partners has released new joint cybersecurity guidance: Creating and Maintaining a Definitive View of Your Operational Technology (OT) Architecture .
|
FBI
|
| 2025-09-29 |
CISA Strengthens Commitment to SLTT Governments
CISA is supporting our SLTT partners with access to grant funding, no-cost tools, and cybersecurity expertise to be resilient and lead at the local level. CISA’s cooperative agreement with the Center for Internet Security (CIS) will reach its planned end on September 30, 2025.
|
DHS
FEMA
|
| 2025-09-29 |
Creating and Maintaining a Definitive View of Your Operational Technology (OT) Architecture
It is aimed at cyber security professionals working in organisations that deploy or operate OT across greenfield and brownfield deployments. Integrators and device manufactures can also use these principles to ensure their solutions enable effective asset and configuration management.
|
ASD/ACSC
BSI
CCCS
FBI
NCSC-NL
NCSC-NZ
NCSC-UK
|
| 2025-09-03 |
CISA, NSA, and Global Partners Release a Shared Vision of Software Bill of Materials (SBOM) Guidance
This marks a significant step forward in strengthening software supply chain transparency and security worldwide. An SBOM is a formal record detailing the components and supply chain relationships used in building software. SBOMs act as a software “ingredients list” providing organizations with essential visibility into software dependencies, enabling them to identify components, assess risks, and take proactive measures to mitigate vulnerabiliti…
|
NSA
|
| 2025-09-03 |
Joint Guidance: A Shared Vision of Software Bill Of Materials For Cybersecurity
Widespread adoption of SBOM will strengthen security, reduce risk, and Most modern software is comprised of software components, modules, and libraries from open source and proprietary software worlds, rather than developers creating it from scratch. As concerns about the security and provenance of software grow, it is critical to understand the risks in the software’s supply chain— including the risks of the underlying software components.
|
ANSSI
ASD/ACSC
BSI
CCCS
CSA
NCO
NCSC-NL
NCSC-NZ
NIS
NSA
NUKIB
|
| 2025-08-27 |
Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System
Executive summary People’s Republic of China (PRC) state-sponsored cyber threat actors are targeting networks globally, including, but not limited to, telecommunications, government, transportation, lodging, and military infrastructure networks.
|
AISE
AISI
AIVD
ASD/ACSC
AW
BSI
CCCS
CNI
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-UK
NSA
NUKIB
SKW
SUPO
|
| 2025-08-27 |
CISA and Partners Release Joint Advisory on Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage Systems
CISA, along with the National Security Agency, Federal Bureau of Investigation, and international partners, released a joint Cybersecurity Advisory on People’s Republic of China (PRC) state-sponsored Advanced Persistent Threat (APT) actors targeting critical infrastructure across sectors and continents to maintain persistent, long-term access to networks.
|
FBI
NSA
|
| 2025-08-27 |
Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System
While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks.
|
AISE
AISI
AIVD
ASD/ACSC
AW
BSI
CCCS
CNI
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-UK
NSA
NUKIB
SKW
SUPO
|
| 2025-08-27 |
CSA: Countering China State Actors Compromise of Networks
While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks.
|
AISE
AISI
AIVD
ASD/ACSC
AW
BSI
CCCS
CNI
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-UK
NSA
NUKIB
SKW
SUPO
|
| 2025-08-13 |
CISA and Partners Release Asset Inventory Guidance for Operational Technology Owners and Operators
CISA, along with the National Security Agency, the Federal Bureau of Investigation, Environmental Protection Agency, and several international partners, released comprehensive guidance to help operational technology (OT) owners and operators across all critical infrastructure sectors create and maintain OT asset inventories and supplemental taxonomies.
|
EPA
FBI
NSA
|
| 2025-08-13 |
Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators
Using these tools helps owners and operators identify which assets in their environment should be secured and protected, and structure their defenses accordingly to reduce the risk a cybersecurity incident poses to the organization’s mission and service continuity. An asset inventory is an organized, regularly updated list of an organization’s systems, hardware, and software.
|
ASD/ACSC
BSI
CCCS
DOE
EPA
FBI
NCSC-NL
NCSC-NZ
NSA
|
| 2025-07-31 |
CISA and USCG Issue Joint Advisory to Strengthen Cyber Hygiene in Critical Infrastructure
This follows a proactive threat hunt engagement conducted at a U.S. critical infrastructure facility. During this engagement, CISA and USCG did not find evidence of malicious cyber activity or actor presence on the organization’s network but did identify several cybersecurity risks.
|
USCG
|
| 2025-07-31 |
CISA and USCG Identify Areas for Cyber Hygiene Improvement After Conducting Proactive Threat Hunt at US Critical Infrastructure Organization
Summary The Cybersecurity and Infrastructure Security Agency (CISA) and U.S. Coast Guard (USCG) are issuing this Cybersecurity Advisory to present findings from a recent CISA and USCG hunt engagement. The purpose of this advisory is to highlight identified cybersecurity issues, thereby informing security defenders in other organizations of potential similar issues and encouraging them to take proactive measures to enhance their cybersecurity post…
|
CGCYBER
NIST
USCG
|
| 2025-07-29 |
CISA and Partners Release Updated Advisory on Scattered Spider Group
CISA, along with the Federal Bureau of Investigation, Canadian Centre for Cyber Security, Royal Canadian Mounted Police, the Australian Cyber Security Centre’s Australian Signals Directorate, and the Australian Federal Police and National Cyber Security Centre, released an updated joint Cybersecurity Advisory on Scattered Spider—a cybercriminal group targeting commercial facilities sectors and subsectors.
|
AFP
ASD/ACSC
CCCS
FBI
RCMP
|
| 2025-07-29 |
Scattered Spider
Actions for Organizations to Take Today to Mitigate Malicious Cyber Activity The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Royal (ACSC), Australian Federal Police (AFP), Canadian Centre for Cyber Security (CCCS), and United Kingdom’s National Cyber Security Centre (NCSC-UK)—hereafter referred to as the authoring organizations—are releasing this joint Cybersecurity Advisory in response to recen…
|
AFP
ASD/ACSC
CCCS
FBI
NCSC-UK
|
| 2025-07-22 |
Joint Advisory Issued on Protecting Against Interlock Ransomware
This advisory highlights known Interlock ransomware indicators of compromise and tactics, techniques, and procedures identified through recent FBI investigations. Actions organizations can take today to mitigate Interlock ransomware threat activity include: Preventing initial access by implementing domain name system filtering and web access firewalls and training users to spot social engineering attempts.
|
FBI
HHS
MS-ISAC
|
| 2025-07-22 |
#StopRansomware: Interlock
Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Interlock Prevent initial access by implementing domain name system (DNS) filtering and web access firewalls, and training users to spot social engineering attempts.
|
FBI
HHS
MS-ISAC
NIST
|
| 2025-07-22 |
#StopRansomware: Interlock
Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Interlock Prevent initial access by implementing domain name system (DNS) filtering and web access firewalls, and training users to spot social engineering attempts.
|
FBI
HHS
MS-ISAC
|
| 2025-06-30 |
CISA and Partners Urge Critical Infrastructure to Stay Vigilant in the Current Geopolitical Environment
Today, CISA, in collaboration with the Federal Bureau of Investigation (FBI), the Department of Defense Cyber Crime Center (DC3), and the National Security Agency (NSA), released a Fact Sheet urging organizations to remain vigilant against potential targeted cyber operations by Iranian state-sponsored or affiliated threat actors.
|
DC3
FBI
NSA
|
| 2025-06-30 |
Iranian Cyber Actors May Target Vulnerable U.S. Networks and Entities of Interest
critical infrastructure and other U.S. entities by Iranian-affiliated cyber actors. Despite a declared ceasefire and ongoing negotiations towards a permanent solution, Iranian-affiliated cyber actors and hacktivist groups may still conduct malicious cyber activity.
|
DC3
FBI
NSA
|
| 2025-06-24 |
New Guidance Released for Reducing Memory-Related Vulnerabilities
Memory safety vulnerabilities pose serious risks to national security and critical infrastructure. Adopting memory safe languages (MSLs) offers the most comprehensive mitigation against this class of vulnerabilities and provides built-in safeguards that enhance security by design.
|
NSA
|
| 2025-06-24 |
CSI: Memory Safe Languages: Reducing Vulnerabilities in Modern Software Development
In 2022, the National Security Agency (NSA) released a cybersecurity information sheet (CSI), “Software Memory Safety.” [1] In 2023, the Cybersecurity and Infrastructure Security Agency (CISA) published the joint guide, “The Case for Memory Safe Roadmaps,” [2] and in 2024, the White House issued “Back to the Building Blocks: A Path Toward Secure and Measurable Software.
|
NSA
|
| 2025-06-04 |
#StopRansomware: Play Ransomware
Tools Leveraged by Play Ransomware Actors AdFind Used to query and retrieve information from Active Directory. Bloodhound Used to query and retrieve information from Active Directory. GMER A software tool intended to be used for detecting and removing rootkits.
|
ASD/ACSC
FBI
|
| 2025-05-22 |
AI Data Security
Joint Cybersecurity Information Best Practices for Securing Data Used to Train & Operate AI Systems This Cybersecurity Information Sheet (CSI) provides essential guidance on securing data used in artificial intelligence (AI) and machine learning (ML) systems.
|
ASD/ACSC
FBI
NCSC-NZ
NCSC-UK
NSA
|
| 2025-05-22 |
CSI: AI Data Security: Best Practices for Securing Data Used to Train & Operate AI Systems
Joint Cybersecurity Information This Cybersecurity Information Sheet (CSI) provides essential guidance on securing data used in artificial intelligence (AI) and machine learning (ML) systems. It also highlights the importance of data security in ensuring the accuracy and integrity of AI outcomes and outlines potential risks arising from data integrity issues in various stages of AI development and deployment.
|
ASD/ACSC
FBI
NCSC-NZ
NCSC-UK
NSA
|
| 2025-05-21 |
Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations
CISA and partners warn that threat actors are deploying LummaC2 infostealer malware to exfiltrate credentials, financial information, and sensitive data from organizations. LummaC2 is typically distributed through phishing, malvertising, and trojanized software downloads.
|
FBI
|
| 2025-05-21 |
Russian GRU Targeting Western Logistics Entities and Technology Companies
Executive Summary This joint cybersecurity advisory (CSA) highlights a Russian state-sponsored cyber campaign targeting Western logistics entities and technology companies. This includes those involved in the coordination, transport, and delivery of foreign assistance to Ukraine.
|
ASD/ACSC
CCCS
FBI
NCSC-UK
NSA
USCC
|
| 2025-05-21 |
Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations
LummaC2 malware is able to infiltrate victim computer networks and exfiltrate sensitive information, threatening vulnerable individuals’ and organizations’ computer networks across multiple U.S. critical infrastructure sectors. According to FBI information and trusted third-party reporting, this activity has been observed as recently as May 2025.
|
FBI
|
| 2025-05-15 |
Senior U.S. Officials Impersonated in Malicious Messaging Campaign
Since April 2025, malicious actors have impersonated senior U.S. officials to target individuals, many of whom are current or former senior U.S. federal or state government officials and their contacts. If you receive a message claiming to be from a senior U.S. official, do not assume it is authentic.
|
FBI
|
| 2025-05-06 |
Primary Mitigations to Reduce Cyber Threats to Operational Technology
The authoring organizations urge critical infrastructure entities to review and act now to improve their cybersecurity posture against cyber threat activities specifically and intentionally targeting internet connected OT and ICS. The authoring organizations recommend critical infrastructure asset owners and operators implement the following mitigations1 to defend against OT cyber threats. internet.
|
DOE
EPA
FBI
|
| 2025-04-29 |
Info Sheet: Selecting a Protective DNS Service (April 2025 Update)
Security Infrastructure Cybersecurity Information Selecting a Protective DNS Service The Domain Name System (DNS) is central to the operation of modern networks, translating human-readable domain names into machine-usable Internet Protocol (IP) addresses. DNS makes navigating to a website, sending an email, or making a secure shell connection easier, and is a key component of the Internet's resilience.
|
NCSC-UK
NSA
|
| 2025-04-03 |
NSA, CISA, FBI, and International Partners Release Cybersecurity Advisory on “Fast Flux,” a National Security Threat
Today, CISA—in partnership with the National Security Agency (NSA), Federal Bureau of Investigation (FBI), Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), Canadian Centre for Cyber Security (CCCS), and New Zealand’s National Cyber Security Centre (NCSC-NZ)—released joint Cybersecurity Advisory Fast Flux: A National Security Threat (PDF, 841 KB).
|
ASD/ACSC
CCCS
FBI
NCSC-NZ
NSA
|
| 2025-04-03 |
Fast Flux: A National Security Threat
The Protective Domain Name System (DNS) Resolver service allows the Cybersecurity and Infrastructure Security Agency (CISA) to detect and prevent cyberattacks and threats targeting federal civilian executive branch (FCEB) agency networks. Protective DNS also offers a range of capabilities to safeguard assets that may otherwise be challenging to protect such as cloud, mobile, and nomadic devices.
|
ASD/ACSC
CCCS
FBI
NCSC-NZ
NSA
|
| 2025-04-03 |
Fast Flux: A National Security Threat
Malicious cyber actors, including cybercriminals and nation-state actors, use fast flux to obfuscate the locations of malicious servers by rapidly changing Domain Name System (DNS) records. Additionally, they can create resilient, highly available command and control (C2) infrastructure, concealing their subsequent malicious operations.
|
ASD/ACSC
CCCS
FBI
NCSC-NZ
NSA
|
| 2025-03-24 |
Info Sheet: Selecting a Protective DNS Service (March 2025 Update)
Security Infrastructure Cybersecurity Information Selecting a Protective DNS Service The Domain Name System (DNS) is central to the operation of modern networks, translating human-readable domain names into machine-usable Internet Protocol (IP) addresses. DNS makes navigating to a website, sending an email, or making a secure shell connection easier, and is a key component of the Internet's resilience.
|
NCSC-UK
NSA
|
| 2025-03-12 |
CISA and Partners Release Cybersecurity Advisory on Medusa Ransomware
This advisory provides tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and detection methods associated with known Medusa ransomware activity. Medusa is a ransomware-as-a-service variant used to conduct ransomware attacks; as of December 2024, over 300 victims from critical infrastructure sectors have been impacted.
|
FBI
MS-ISAC
|
| 2025-03-12 |
#StopRansomware: Medusa Ransomware
CISA, FBI, and MS-ISAC warn that Medusa ransomware has targeted over 300 victims across critical infrastructure sectors since 2021 using a double-extortion model. Operators gain initial access via phishing and unpatched vulnerabilities, then encrypt systems and threaten to leak stolen data unless ransom is paid.
|
FBI
MS-ISAC
|
| 2025-03-12 |
#StopRansomware: Medusa Ransomware
Finally, the registry is modified to allow Remote Desktop connections: fDenyTSConnections /t REG_DWORD /d 0 /f Mimikatz has also been observed in use for Local Security Authority Subsystem Service (LSASS) dumping [T1003.001] to harvest credentials [TA0006] and aid lateral movement. Medusa actors install and use Rclone to facilitate exfiltration of data to the Medusa C2 servers [T1567.002] used by actors and affiliates.
|
FBI
MS-ISAC
|
| 2025-03-06 |
FBI Warns of Data Extortion Scam Targeting Corporate Executives
The Federal Bureau of Investigation (FBI) Internet Crime Complaint Center (IC3) has released an alert warning of a scam involving criminal actors masquerading as the “BianLian Group.” The cyber criminals target corporate executives by sending extortion letters threatening to release victims’ sensitive information unless payment is received.
|
FBI
|
| 2025-02-19 |
CISA and Partners Release Advisory on Ghost (Cring) Ransomware
Today, CISA—in partnership with the Federal Bureau of Investigation (FBI) and Multi-State Information Sharing and Analysis Center (MS-ISAC)—released a joint Cybersecurity Advisory, #StopRansomware: Ghost (Cring) Ransomware . This advisory provides network defenders with indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and detection methods associated with Ghost ransomware activity identified through FBI investigations.
|
FBI
MS-ISAC
|
| 2025-02-19 |
#StopRansomware: Ghost (Cring) Ransomware
Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Ghost
|
FBI
MS-ISAC
|
| 2025-02-19 |
#StopRansomware: Ghost (Cring) Ransomware
Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Ghost
|
FBI
MS-ISAC
|
| 2025-02-12 |
CISA and FBI Warn of Malicious Cyber Actors Using Buffer Overflow Vulnerabilities to Compromise Software
CISA and the Federal Bureau of Investigation (FBI) have released a Secure by Design Alert, Eliminating Buffer Overflow Vulnerabilities , as part of their cooperative Secure by Design Alert series —an ongoing series aimed at advancing industry-wide best practices to eliminate entire classes of vulnerabilities during the design and development phases of the product lifecycle.
|
FBI
|
| 2025-02-12 |
Secure by Design Alert: Eliminating Buffer Overflow Vulnerabilities
The Secure by Design initiative seeks to foster a cultural shift across the technology industry, normalizing the development of the Secure by Design Pledge, and stay informed on the latest Secure by Design Alerts. Buffer overflow vulnerabilities are a prevalent type of memory The software development community has safety software design defect that regularly lead to system compromise.
|
FBI
NSA
|
| 2025-02-04 |
CISA Partners with ASD’s ACSC, CCCS, NCSC-UK, and Other International and US Organizations to Release Guidance on Edge Devices
CISA—in partnership with international and U.S. organizations—released guidance to help organizations protect their network edge devices and appliances , such as firewalls, routers, virtual private networks (VPN) gateways, Internet of Things (IoT) devices, internet-facing servers, and internet-facing operational technology (OT) systems.
|
ASD/ACSC
CCCS
NCSC-UK
|
| 2025-02-04 |
Guidance on digital forensics and protective monitoring specifications for producers of network devices and appliances
This guidance has been developed with contributions from partnering agencies and is included in a series of publications aiming to draw attention to the importance of edge device cyber security measures. It is produced by the UK National Cyber Security Centre (NCSC) in partnership with the Australian Signals Directorate (ASD), US Cybersecurity and Infrastructure Security Agency (CISA), the Canadian Centre for Cyber Security – part of the Communic…
|
ASD/ACSC
CCCS
FBI
NCSC-NZ
NCSC-UK
|
| 2025-02-03 |
CSI: Security Considerations for Edge Devices: Executive Guidance
Mitigation strategies for edge Malicious actors are increasingly targeting internet-facing edge devices to gain unauthorised access to networks; therefore, it is vital that organisations prioritise securing edge devices in their environments. Edge devices are critical network components that serve as security boundaries between internal enterprise networks and the internet.
|
ASD/ACSC
CCCS
FBI
NCSC-NZ
NCSC-UK
NSA
|
| 2025-01-28 |
A method to assess 'forgivable' vs 'unforgivable' vulnerabilities
In fact, the number of Common Vulnerabilities and Exposures (CVEs) in commodity technology continues to rise. While there are a number of factors that are driving the increasing numbers, the NCSC expect this trend to continue unless interventions are made.
|
NCSC-UK
|
| 2025-01-22 |
CISA and FBI Release Advisory on How Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications
This advisory was crafted in response to exploitation of vulnerabilities— CVE-2024-8963 , an administrative bypass vulnerability; CVE-2024-9379 , a SQL injection vulnerability; and CVE-2024-8190 and CVE-2024-9380 , remote code execution vulnerabilities—in Ivanti Cloud Service Appliances (CSA) in September 2024.
|
CSA
FBI
|
| 2025-01-22 |
Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications
For more information on mitigating CVE -2025-0282 and CVE-2025-0283, see Ivanti Releases Security Updates for Connect Secure, Policy Secure, and ZTA Gateways . Summary The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) are releasing this joint Cybersecurity Advisory in response to exploitation in September 2024 of vulnerabilities in Ivanti Cloud Service Appliances (CSA): CVE-2024-8963 , an admini…
|
FBI
|
| 2025-01-22 |
Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications
For more information on mitigating CVE-20250282 and CVE-2025-0283, see Ivanti Releases Security Updates for Connect Secure, Policy Secure, and The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) are releasing this joint Cybersecurity Advisory in response to exploitation in September 2024 of vulnerabilities in Ivanti Cloud Service Appliances (CSA): CVE-2024-8963, an administrative bypass vulnerabil…
|
FBI
|
| 2025-01-17 |
CISA and FBI Release Updated Guidance on Product Security Bad Practices
This updated guidance incorporates public comments CISA received in response to a Request for Information, adding additional bad practices, context regarding memory-safe languages, clarifying timelines for patching Known Exploited Vulnerabilities (KEVs) , and other recommendations.
|
FBI
|
| 2025-01-17 |
Product Security Bad Practices
Feedback incorporated from the 78 public comments CISA received in response to our Request for insecure or outdated cryptographic functions, hardcoded credentials, and product support actions to prevent SQL injection vulnerabilities. Updates actions to prevent command injection (MFA) specific to operational technology support phishing-resistant MFA.
|
FBI
|
| 2025-01-16 |
CISA and Partners Release Call to Action to Close the National Software Understanding Gap
Today, CISA—in partnership with the Defense Advanced Research Projects Agency (DARPA), the Office of the Under Secretary of Defense for Research and Engineering (OUSD R&E), and the National Security Agency (NSA)—published Closing the Software Understanding Gap . This report urgently implores the U.S. government to take decisive and coordinated action. Software understanding refers to assessing software-controlled systems across all conditions.
|
DARPA
NSA
|
| 2025-01-16 |
CSI: Closing the Software Understanding Gap
Software is embedded in countless systems responsible for providing U.S. critical infrastructure services that Americans rely on as well as systems providing national security capabilities. To maintain confidence in national security and critical infrastructure systems, mission owners and operators should be able to trust the system is functional, safe, and secure.
|
DOE
FBI
NSA
|
| 2025-01-14 |
Microsoft Releases January 2025 Security Updates
Microsoft released security updates to address vulnerabilities in multiple Microsoft products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Microsoft Security Update Guide for January This product is provided subject to this Notification and this Privacy & Use policy.
|
JPCERT/CC
|
| 2025-01-13 |
CISA and US and International Partners Publish Guidance on Priority Considerations in Product Selection for OT Owners and Operators
As part of CISA’s Secure by Demand series, this guidance focuses on helping customers identify manufacturers dedicated to continuous improvement and achieving a better cost balance, as well as how Operational Technology (OT) owners and operators should integrate secure by design elements into their procurement process. Critical infrastructure and industrial control systems are prime targets for cyberattacks.
|
FBI
NSA
|
| 2025-01-13 |
Secure by Demand: Priority Considerations for Operational Technology Owners and Operators When Selecting Digital Products
Many OT products are not designed and developed with Secure by Design principles1 and commonly have weaknesses, such as weak authentication, known software vulnerabilities, limited logging, insecure default settings and passwords, and insecure legacy protocols. Cyber threat actors can easily exploit these weaknesses across multiple victims to gain access to control systems.
|
ASD/ACSC
BSI
CCCS
EPA
FBI
NCSC-NL
NCSC-NZ
NCSC-UK
NSA
TSA
|
| 2025-01-10 |
CISA Releases the Cybersecurity Performance Goals Adoption Report
As the nation’s cyber defense agency, one of CISA’s most important roles is to understand the challenges facing organizations, both large and small, in order to make progress on the shared goal of reducing cyber risk to the critical infrastructure Americans rely on every day.
|
NSM
|
| 2024-12-18 |
CSA: IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including U.S. Water and Wastewater Systems Facilities (December 2024 update)
IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and
|
CCCS
EPA
FBI
NCSC
NSA
|
| 2024-12-17 |
CISA and ONCD Release Playbook for Strengthening Cybersecurity in Federal Grant Programs for Critical Infrastructure
This guide is for federal grant program managers, critical infrastructure owners and operators, and organizations such as state, local, tribal, and territorial governments who subaward grant program funds, and grant program recipients. The guide includes: Recommended actions to incorporate cybersecurity into grant programs throughout the grant management lifecycle.
|
ONCD
|
| 2024-12-16 |
CISA Requests Public Comment for Draft National Cyber Incident Response Plan Update
The draft requests public comment on the National Cyber Incident Response Plan (NCIRP)—public comment period begins today and concludes on January 15, 2025. As of January 3, 2025: The public comment period has been extended and now concludes on February 14, 2025.
|
ONCD
|
| 2024-12-13 |
CISA and EPA Release Joint Fact Sheet Detailing Risks Internet-Exposed HMIs Pose to WWS Sector
This joint fact sheet provides Water and Wastewater Systems (WWS) facilities with recommendations for limiting the exposure of Human Machine Interfaces (HMIs) and securing them against malicious cyber activity. HMIs enable operational technology owners and operators to read supervisory control and data acquisition systems connected to programmable logic controllers.
|
EPA
|
| 2024-12-10 |
Microsoft Releases December 2024 Security Updates
Microsoft released security updates to address vulnerabilities in multiple Microsoft products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Microsoft Security Update Guide for December This product is provided subject to this Notification and this Privacy & Use policy.
|
JPCERT/CC
|
| 2024-12-05 |
ASD’s ACSC, CISA, and US and International Partners Release Guidance on Choosing Secure and Verifiable Technologies
Today, CISA—in partnership with the Australian Signals Directorate Australian Cyber Security Centre (ASD ACSC), and other international partners—released updates to a Secure by Design Alert, Choosing Secure and Verifiable Technologies . Partners that provided recommendations in this alert include: The Canadian Centre for Cyber Security (CCCS).
|
ASD/ACSC
|
| 2024-12-03 |
CISA and Partners Release Joint Guidance on PRC-Affiliated Threat Actor Compromising Networks of Global Telecommunications Providers
Today, CISA—in partnership with the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and international partners—released joint guidance, Enhanced Visibility and Hardening Guidance for Communications Infrastructure .
|
FBI
NSA
|
| 2024-12-03 |
Enhanced Visibility and Hardening Guidance for Communications Infrastructure
The authoring agencies are releasing this guide to highlight this threat and provide network engineers and defenders of communications infrastructure with best practices to strengthen their visibility and harden their network devices against successful exploitation carried out by PRC-affiliated and other malicious cyber actors.
|
ASD/ACSC
FBI
NCSC-NZ
NSA
|
| 2024-11-20 |
CISA and Partners Release Update to BianLian Ransomware Cybersecurity Advisory
Today, CISA, the Federal Bureau of Investigation (FBI), and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) released updates to #StopRansomware: BianLian Ransomware Group on observed tactics, techniques, and procedures (TTPs) and indicators of compromise attributed to data extortion group, BianLian.
|
ASD/ACSC
FBI
|
| 2024-11-12 |
Microsoft Releases November 2024 Security Updates
Microsoft released security updates to address vulnerabilities in multiple products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Microsoft Security Update Guide for November This product is provided subject to this Notification and this Privacy & Use policy.
|
JPCERT/CC
|
| 2024-11-12 |
CISA, FBI, NSA, and International Partners Release Joint Advisory on 2023 Top Routinely Exploited Vulnerabilities
This advisory supplies details on the top Common Vulnerabilities and Exposures (CVEs) routinely exploited by malicious cyber actors and their associated Common Weakness Enumeration(s) (CWE) to help organizations better understand the impact of exploitation.
|
FBI
NSA
|
| 2024-11-12 |
2023 Top Routinely Exploited Vulnerabilities
Summary The following cybersecurity agencies coauthored this joint Cybersecurity Advisory (hereafter collectively referred to as the authoring agencies): United States: The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and National Security Agency (NSA) Australia: Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) Canada: Canadian Centre for Cyber Security (CCCS) New Zeal…
|
ASD/ACSC
CCCS
NCSC-NZ
NCSC-UK
NIST
NSA
|
| 2024-10-24 |
CISA, US, and International Partners Release Joint Guidance to Assist Software Manufacturers with Safe Software Deployment Processes
This guide aids software manufacturers in establishing secure software deployment processes to help ensure software is reliable and safe for customers. Additionally, it offers guidance on how to deploy in an efficient manner as part of the software development lifecycle (SDLC).
|
ASD/ACSC
FBI
|
| 2024-10-16 |
CISA and FBI Release Joint Guidance on Product Security Bad Practices for Public Comment
This joint guidance supplies an overview of exceptionally risky product security bad practices for software manufacturers who produce software in support of critical infrastructure or national critical functions. The bad practices presented in this guidance are organized into three categories: product properties, security features, and organizational processes and policies.
|
FBI
|
| 2024-10-16 |
CISA, FBI, NSA, and International Partners Release Advisory on Iranian Cyber Actors Targeting Critical Infrastructure Organizations Using Brute Force
This advisory provides known indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) used by Iranian actors to impact organizations across multiple critical infrastructure sectors. Since October 2023, Iranian actors have used brute force and password spraying to compromise user accounts and obtain access to organizations in the healthcare and public health (HPH), government, information technology, engineering, and energy s…
|
FBI
NSA
|
| 2024-10-16 |
Iranian Cyber Actors’ Brute Force and Credential Access Activity Compromises Critical Infrastructure Organizations
Summary The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Communications Security Establishment Canada (CSE), the Australian Federal Police (AFP), and Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) are releasing this joint Cybersecurity Advisory to warn network defenders of Iranian cyber actors’ use of brute force and othe…
|
AFP
ASD/ACSC
CCCS
CSE
FBI
NIST
NSA
|
| 2024-10-08 |
Microsoft Releases October 2024 Security Updates
Microsoft released security updates to address vulnerabilities in multiple products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Microsoft Security Update Guide for October This product is provided subject to this Notification and this Privacy & Use policy.
|
JPCERT/CC
|
| 2024-10-08 |
CISA and FBI Release Fact Sheet on Protecting Against Iranian Targeting of Accounts Associated with National Political Organizations
This fact sheet provides information about threat actors affiliated with the Iranian Government’s Islamic Revolutionary Guard Corps (IRGC) targeting and compromising accounts of Americans to stoke discord and undermine confidence in U.S. democratic institutions. IRGC actors have previously gained and continue to seek access to personal and business accounts using social engineering techniques by targeting victims across email and chat.
|
FBI
|
| 2024-10-01 |
ASD’s ACSC, CISA, FBI, NSA, and International Partners Release Guidance on Principles of OT Cybersecurity for Critical Infrastructure Organizations
Today, the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)—in partnership with CISA, U.S. government and international partners—released the guide Principles of Operational Technology Cybersecurity . This guidance provides critical information on how to create and maintain a safe, secure operational technology (OT) environment.
|
ASD/ACSC
|
| 2024-09-26 |
ASD’s ACSC, CISA, and US and International Partners Release Guidance on Detecting and Mitigating Active Directory Compromises
First published: September 2024 This guidance – authored by the Australian Signals Directorate (ASD), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NCSC-NZ), and the United Kingdom’s National Cyber Security Centre (NCSC-UK) – aims to inform organisations about 17 common techniques used to target Active…
|
ASD/ACSC
CCCS
NCSC-NZ
NCSC-UK
NSA
|
| 2024-09-17 |
CISA and FBI Release Secure by Design Alert on Eliminating Cross-Site Scripting Vulnerabilities
Vulnerabilities like cross-site scripting (XSS) continue to appear in software, enabling threat actors to exploit them. However, cross-site scripting vulnerabilities are preventable and should not be present in software products.
|
FBI
|
| 2024-09-10 |
Microsoft Releases September 2024 Security Updates
Microsoft released security updates to address vulnerabilities in multiple products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Microsoft Security Update Guide for September This product is provided subject to this Notification and this Privacy & Use policy.
|
JPCERT/CC
|
| 2024-09-05 |
FBI, CISA, NSA, and US and International Partners Release Advisory on Russian Military Cyber Actors Targeting US and Global Critical Infrastructure
Today, the Federal Bureau of Investigation (FBI)—in partnership with CISA, the National Security Agency (NSA), and other U.S. and international partners—released a joint Cybersecurity Advisory Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure .
|
FBI
NSA
|
| 2024-09-05 |
Russian Military Cyber Actors Target US and Global Critical Infrastructure
GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and Prioritize routine system updates and remediate known exploited vulnerabilities. Segment networks to prevent the spread of malicious activity.
|
ASD/ACSC
CCCS
CNMF
FBI
MIVD
NCSC-UK
NIST
NSA
Treasury
USCC
|
| 2024-09-05 |
Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure
GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and Prioritize routine system updates and remediate known exploited vulnerabilities. Segment networks to prevent the spread of malicious activity.
|
ASD/ACSC
CCCS
CNMF
FBI
MIVD
NCSC-UK
NSA
Treasury
USCC
|
| 2024-08-29 |
CISA and Partners Release Advisory on RansomHub Ransomware
Today, CISA—in partnership with the Federal Bureau of Investigation (FBI), Multi-State Information Sharing and Analysis Center (MS-ISAC), and Department of Health and Human Services (HHS)—released a joint Cybersecurity Advisory, #StopRansomware: RansomHub Ransomware .
|
FBI
HHS
MS-ISAC
|
| 2024-08-29 |
#StopRansomware: RansomHub Ransomware
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. An improper neutralization of special elements used in an SQL command (SQL injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and FortiClientEMS 7.0.1 through 7.0.
|
FBI
HHS
MS-ISAC
|
| 2024-08-28 |
CISA and Partners Release Advisory on Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations
Organizations . This joint advisory warns of cyber actors, known in the private sector as Pioneer Kitten, UNC757, Parisite, Rubidium, and Lemon Sandstorm, targeting and exploiting U.S. and foreign organizations across multiple sectors in the U.S.
|
DC3
FBI
|
| 2024-08-28 |
Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations
The FBI assesses a significant percentage of these threat actors’ operations against US organizations are intended to obtain and develop network access to then collaborate with ransomware affiliate actors to deploy ransomware. The FBI further assesses these Iran-based cyber actors are associated with the Government of Iran (GOI) and—separate from the ransomware activity—conduct computer network exploitation activity in support of the GOI (such as…
|
CSA
DC3
FBI
|
| 2024-08-28 |
Iran-Based Cyber Actors Enabling Ransomware Attacks on U.S. Organizations
The FBI assesses a significant percentage of these threat actors’ operations against US organizations are intended to obtain and develop network access to then collaborate with ransomware affiliate actors to deploy ransomware. The FBI further assesses these Iran-based cyber actors are associated with the Government of Iran (GOI) and—separate from the ransomware activity—conduct computer network exploitation activity in support of the GOI (such as…
|
DC3
FBI
|
| 2024-08-21 |
ASD’s ACSC, CISA, FBI, and NSA, with the support of International Partners Release Best Practices for Event Logging and Threat Detection
Logging priorities for enterprise mobility using mobile computing devices 10 Protecting event logs from unauthorised access, modification and deletion 11 This publication defines a baseline for event logging best practices to mitigate cyber threats.
|
AIVD
ASD/ACSC
CCCS
CSA
MIVD
NCSC-NZ
NCSC-UK
NIS
NSA
|
| 2024-08-13 |
Microsoft Releases August 2024 Security Updates
Microsoft released security updates to address vulnerabilities in multiple products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Microsoft Security Update Guide for August This product is provided subject to this Notification and this Privacy & Use policy.
|
JPCERT/CC
|
| 2024-08-07 |
Royal Ransomware Actors Rebrand as “BlackSuit,” FBI and CISA Release Update to Advisory
The updated advisory provides network defenders with recent and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) associated with BlackSuit and legacy Royal activity. FBI investigations identified these TTPs and IOCs as recently as July 2024.
|
FBI
|
| 2024-07-25 |
North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear Programs
Cyber National Mission Force (CNMF) U.S. Cybersecurity and Infrastructure Security Agency (CISA) U.S. Department of Defense Cyber Crime Center (DC3) U.S. National Security Agency (NSA) Republic of Korea’s National Intelligence Service (NIS) Republic of Korea’s National Police Agency (NPA) United Kingdom’s National Cyber Security Centre (NCSC) The RGB 3rd Bureau includes a DPRK (aka North Korean) state-sponsored cyber group known publi…
|
CNMF
DC3
FBI
NCSC-UK
NIS
NSA
|
| 2024-07-25 |
FBI, CISA, and Partners Release Advisory Highlighting North Korean Cyber Espionage Activity
Today, CISA—in partnership with the Federal Bureau of Investigation (FBI)—released a joint Cybersecurity Advisory, North Korea State-Sponsored Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear Programs . The advisory was coauthored with the following organizations: U.S. Cyber National Mission Force (CNMF); U.S. Department of Defense Cyber Crime Center (DC3); U.S.
|
FBI
|
| 2024-07-25 |
North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs
The group primarily targets defense, aerospace, nuclear, and engineering entities to obtain sensitive and classified type of activity; number of people affected; type of equipment used for the activity; the name of the submitting company or organization; and a designated point of contact.
|
CNMF
DC3
FBI
NCSC-UK
NIS
NSA
|
| 2024-07-11 |
CISA Releases Advisory Detailing Red Team Activity During Assessment of US FCEB Organization, Highlighting Necessity of Defense-in-Depth
Today, CISA released CISA Red Team’s Operations Against a Federal Civilian Executive Branch Organization Highlights the Necessity of Defense-in-Depth in coordination with the assessed organization. This Cybersecurity Advisory (CSA) details key findings and lessons learned from a 2023 assessment, along with the red team’s tactics, techniques, and procedures (TTPs) and associated network defense activity.
|
CSA
|
| 2024-07-11 |
CISA Red Team’s Operations Against a Federal Civilian Executive Branch Organization Highlights the Necessity of Defense-in-Depth
During SILENTSHIELD assessments, the red team first performs a no-notice, long-term simulation of nation-state cyber operations. The team mimics the techniques, tradecraft, and behaviors of sophisticated threat actors and measures the potential dwell time actors have on a network, providing a realistic assessment of the organization’s security posture.
|
CSA
|
| 2024-07-10 |
CISA and FBI Release Secure by Design Alert on Eliminating OS Command Injection Vulnerabilities
These vulnerabilities allowed unauthenticated malicious actors to remotely execute code on network edge devices. OS command injection vulnerabilities have long been preventable by clearly separating user input from the contents of a command.
|
FBI
|
| 2024-07-09 |
Microsoft Releases July 2024 Security Updates
Microsoft released security updates to address vulnerabilities in multiple products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Microsoft Security Update Guide for July This product is provided subject to this Notification and this Privacy & Use policy.
|
JPCERT/CC
|
| 2024-07-08 |
CISA and Partners join ASD’S ACSC to Release Advisory on PRC State-Sponsored Group, APT 40
CISA has collaborated with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD's ACSC) to release an advisory, People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action outlining a PRC state-sponsored cyber group’s activity.
|
ASD/ACSC
|
| 2024-07-08 |
People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action
The advisory draws on the authoring agencies’ shared understanding of the threat as well as ASD’s ACSC incident response investigations. The PRC state-sponsored cyber group has previously targeted organizations in various countries, including Australia and the United States, and the techniques highlighted below are regularly used by other PRC state-sponsored actors globally.
|
ASD/ACSC
BND
CCCS
FBI
NCSC-NZ
NCSC-UK
NIS
NISC
NPA
NSA
|
| 2024-06-26 |
CISA and Partners Release Guidance for Exploring Memory Safety in Critical Open Source Projects
Today, CISA, in partnership with the Federal Bureau of Investigation, Australian Signals Directorate’s Australian Cyber Security Centre, and Canadian Cyber Security Center, released Exploring Memory Safety in Critical Open Source Projects . This guidance was crafted to provide organizations with findings on the scale of memory safety risk in selected open source software (OSS).
|
ASD/ACSC
FBI
|
| 2024-06-18 |
CISA and Partners Release Guidance for Modern Approaches to Network Access Security
The guidance urges business owners of all sizes to move toward more robust security solutions—such as Zero Trust, Secure Service Edge (SSE), and Secure Access Service Edge (SASE)—that provide greater visibility of network activity.
|
FBI
|
| 2024-06-11 |
Microsoft Releases June 2024 Security Updates
Microsoft has released security updates to address vulnerabilities in multiple products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Users and administrators are encouraged to review the following advisory and apply the necessary updates: Microsoft Security Update Guide for June This product is provided subject to this Notification and this Privacy & Use policy.
|
JPCERT/CC
|
| 2024-05-22 |
CSI: Advancing Zero Trust Maturity Throughout the Application and Workload Pillar
Information Technology (IT) professionals are keenly aware of the security challenges facing applications, but workloads are every bit as important to consider in this domain. Workloads represent computational tasks, which encompass multiple programs or applications performing those tasks by utilizing computing, data, networking, and storage resources.
|
NSA
NSM
|
| 2024-05-14 |
Microsoft Releases May 2024 Security Updates
Microsoft has released security updates to address vulnerabilities in multiple products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Users and administrators are encouraged to review the following advisory and apply the necessary updates: Microsoft Security Update Guide for May This product is provided subject to this Notification and this Privacy & Use policy.
|
JPCERT/CC
|
| 2024-05-14 |
CISA and Partners Release Guidance for Civil Society Organizations on Mitigating Cyber Threats with Limited Resources
The joint guidance provides civil society organizations and individuals with recommended actions and mitigations to reduce the risk of cyber intrusions. Additionally, the guide encourages software manufactures to actively implement and publicly commit to Secure by Design practices that are necessary to help protect vulnerable and high-risk communities.
|
DHS
FBI
|
| 2024-05-10 |
CISA and Partners Release Advisory on Black Basta Ransomware
Today, CISA, in partnership with the Federal Bureau of Investigation (FBI), the Department of Health and Human Services (HHS), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) released joint Cybersecurity Advisory (CSA) #StopRansomware: Black Basta to provide cybersecurity defenders tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) used by known Black Basta ransomware affiliates and identified thr…
|
CSA
FBI
HHS
MS-ISAC
|
| 2024-05-10 |
#StopRansomware: Black Basta
These #StopRansomware advisories include recently and historically observed tactics, Install updates for operating techniques, and procedures (TTPs) and indicators of systems, software, and firmware compromise (IOCs) to help organizations protect against as soon as they are released.
|
FBI
HHS
MS-ISAC
|
| 2024-05-09 |
ASD’s ACSC, CISA, and Partners Release Secure by Design Guidance on Choosing Secure and Verifiable Technologies
Today, the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), together with CISA, the Canadian Centre for Cyber Security (CCCS), the United Kingdom’s National Cyber Security Centre (NCSC-UK), and the New Zealand National Cyber Security Centre (NCSC-NZ) are releasing the following guidance: Secure by Design Choosing Secure and Verifiable Technologies .
|
ASD/ACSC
CCCS
NCSC-NZ
NCSC-UK
|
| 2024-05-02 |
CISA and FBI Release Secure by Design Alert to Urge Manufacturers to Eliminate Directory Traversal Vulnerabilities
This Alert was crafted in response to recent well-publicized threat actor campaigns that exploited directory traversal vulnerabilities in software (e.g., CVE-2024-1708 , CVE-2024-20345 ) to compromise users of the software—impacting critical infrastructure sectors, including the Healthcare and Public Health Sector. Additionally, this Alert highlights the prevalence, and continued threat actor exploitation of, directory traversal defects.
|
FBI
|
| 2024-05-01 |
CISA and Partners Release Fact Sheet on Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity
This fact sheet provides information and mitigations associated with cyber operations conducted by pro-Russia hacktivists who seek to compromise industrial control systems (ICS) and small-scale operational technology (OT) systems in North American and European critical infrastructure sectors, including Water and Wastewater Systems, Dams, Energy, and Food and Agriculture Sectors.
|
CCCS
MS-ISAC
NCSC-UK
USDA
|
| 2024-05-01 |
Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity
|
CCCS
DOE
EPA
FBI
MS-ISAC
NCSC-UK
NSA
USDA
|
| 2024-04-18 |
CISA and Partners Release Advisory on Akira Ransomware
Today, CISA, the Federal Bureau of Investigation (FBI), Europol’s European Cybercrime Centre (EC3), and the Netherlands’ National Cyber Security Centre (NCSC-NL) released a joint Cybersecurity Advisory (CSA), #StopRansomware: Akira Ransomware , to disseminate known Akira ransomware tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) identified through FBI investigations as recently as February 2024.
|
EC3
FBI
NCSC-NL
|
| 2024-04-18 |
#StopRansomware: Akira Ransomware
#StopRansomware: Akira Ransomware Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Akira Prioritize remediating known exploited vulnerabilities. Enable and enforce phishing-resistant multifactor authentication (MFA).
|
DC3
EC3
FBI
HHS
NCSC-NL
OFAC
|
| 2024-04-15 |
Joint Guidance on Deploying AI Systems Securely
Provide methodologies and controls to protect, detect, and respond to malicious activity against AI systems and related data and services. This product is provided subject to this Notification and this Privacy & Use policy.
|
FBI
NSA
|
| 2024-04-09 |
Microsoft Releases April 2024 Security Updates
Microsoft released security updates to address vulnerabilities in multiple products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Users and administrators are encouraged to review the following and apply the necessary updates: Microsoft Security Update Guide for April This product is provided subject to this Notification and this Privacy & Use policy.
|
JPCERT/CC
|
| 2024-04-09 |
CSI: Advancing Zero Trust Maturity Throughout the Data Pillar
This cybersecurity information sheet (CSI) provides recommendations for maturing data security and enforcing access to data at rest and in transit, ensuring that only those with authorization can access the data. It further discusses how these capabilities integrate into a comprehensive Zero Trust (ZT) framework, as described in Embracing a Zero Trust Security Model.
|
NSA
NSM
|
| 2024-03-25 |
CISA and FBI Release Secure by Design Alert to Urge Manufacturers to Eliminate SQL Injection Vulnerabilities
This Alert was crafted in response to a recent, well-publicized exploitation of SQL injection (SQLi) defects in a managed file transfer application that impacted thousands of organizations. Additionally, the Alert highlights the prevalence of this class of vulnerability.
|
FBI
|
| 2024-03-21 |
CISA, FBI, and MS-ISAC Release Update to Joint Guidance on Distributed Denial-of-Service Techniques
The guidance now includes detailed insight into three different types of DDoS techniques: Volumetric, attacks aiming to consume available bandwidth. Protocol, attacks which exploit vulnerabilities in network protocols.
|
FBI
MS-ISAC
|
| 2024-03-19 |
CISA and Partners Release Joint Fact Sheet for Leaders on PRC-sponsored Volt Typhoon Cyber Activity
and international partners are issuing a joint fact sheet, People’s Republic of China State-Sponsored Cyber Activity: Actions for Critical Infrastructure Leaders . Partners of this publication include: U.S. Department of Energy (DOE) U.S. Environmental Protection Agency (EPA) U.S. Transportation Security Administration (TSA) U.S.
|
FBI
NSA
|
| 2024-03-12 |
Microsoft Releases Security Updates for Multiple Products
A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Microsoft Security Update Guide for March Microsoft Security Update Guide for March This product is provided subject to this Notification and this Privacy & Use policy.
|
JPCERT/CC
|
| 2024-03-07 |
CISA and NSA Release Cybersecurity Information Sheets on Cloud Security Best Practices
Use Secure Cloud Identity and Access Management Practices Use Secure Cloud Key Management Practices Mitigate Risks from Managed Service Providers in Cloud Environments This product is provided subject to this Notification and this Privacy & Use policy.
|
NSA
|
| 2024-03-07 |
CSI: Mitigate Risks from Managed Service Providers in Cloud Environments
The growth of the public cloud has encouraged the development of numerous MSPs that primarily provide these services within the cloud rather than in customer on-premises networks. Both cloud resellers and other IT vendors offer such third-party services.
|
ASD/ACSC
NSA
|
| 2024-03-05 |
CSI: Advancing Zero Trust Maturity Throughout the Network and Environment Pillar
The Zero Trust network and environment pillar curtails adversarial lateral movement by employing controls and capabilities to logically and physically segment, isolate, and control access (on-premises and off-premises) through granular policy restrictions.
|
NSA
NSM
|
| 2024-02-29 |
CISA, FBI, and MS-ISAC Release Advisory on Phobos Ransomware
Structured as a ransomware as a service (RaaS) model, Phobos ransomware actors have targeted entities including municipal and county governments, emergency services, education, public healthcare, and critical infrastructure to successfully ransom several million in U.S. dollars. This product is provided subject to this Notification and this Privacy & Use policy.
|
FBI
MS-ISAC
|
| 2024-02-29 |
#StopRansomware: Phobos Ransomware
INDICATORS OF COMPROMISE (IOCs) See Table 1 through 6 for IOCs obtained from CISA and the FBI investigations from September through Table 1: Associated Phobos Domains Table 2: Observed Phobos Shell Commands vssadmin delete shadows /all /quiet [T1490] netsh advfirewall set currentprofile state off netsh firewall set opmode mode=disable [T1562.004] bcdedit /set {default} bootstatuspolicy ignoreallfailures [T1547.
|
FBI
MS-ISAC
|
| 2024-02-29 |
CISA and Partners Release Advisory on Threat Actors Exploiting Ivanti Connect Secure and Policy Secure Gateways Vulnerabilities
Additionally, the advisory describes two key CISA findings: The Ivanti Integrity Checker Tool is not sufficient to detect compromise due to the ability of threat actors to deceive it, and A cyber threat actor may be able to gain root-level persistence despite the victim having issued factory resets on the Ivanti device.
|
ASD/ACSC
CCCS
FBI
MS-ISAC
NCSC-NZ
NCSC-UK
|
| 2024-02-29 |
Threat Actors Exploit Multiple Vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways
CISA and authoring organizations appreciate the cooperation of Volexity, Ivanti, Mandiant and other industry partners in the development of this advisory and ongoing incident response activities. Authoring organizations: Of particular concern, the authoring organizations and industry partners have determined that cyber threat actors are able to deceive Ivanti’s internal and external Integrity Checker Tool (ICT), resulting in a failure to detect c…
|
ASD/ACSC
CCCS
FBI
MS-ISAC
NCSC-NZ
NCSC-UK
|
| 2024-02-27 |
CISA, FBI, and HHS Release an Update to #StopRansomware Advisory on ALPHV Blackcat
ALPHV Blackcat affiliates have been observed primarily targeting the healthcare sector. CISA, the FBI, and HHS urge network defenders to review the updated joint advisory to protect and detect against malicious activity.
|
FBI
HHS
|
| 2024-02-26 |
CISA, NCSC-UK, and Partners Release Advisory on Russian SVR Actors Targeting Cloud Infrastructure
This advisory provides recent tactics, techniques, and procedures (TTPs) used by Russian Foreign Intelligence Service (SVR) cyber actors—also known as APT29, the Dukes, CozyBear, and NOBELIUM/Midnight Blizzard—to gain initial access into a cloud environment. The authoring agencies encourage network defenders and organizations review the joint advisory for recommended mitigations.
|
NCSC
NCSC-UK
|
| 2024-02-26 |
SVR Cyber Actors Adapt Tactics for Initial Cloud Access
How SVR-Attributed Actors are Adapting to the Move of Government and Corporations to Cloud Infrastructure OVERVIEW This advisory details recent tactics, techniques, and procedures (TTPs) of the group commonly known as APT29, also known as Midnight Blizzard, the Dukes, or Cozy Bear.
|
FBI
NSA
|
| 2024-02-26 |
SVR Cyber Actors Adapt Tactics for Initial Cloud Access
The US National Security Agency (NSA), the US Cybersecurity and Infrastructure Security Agency (CISA), the US the Canadian Centre for Cyber Security (CCCS) and the New Zealand National Cyber Security Centre (NCSC) agree with this attribution and the details This advisory provides an overview of TTPs deployed by the actor to gain initial access into the cloud environment and includes advice to detect and mitigate The NCSC has previously detailed h…
|
ASD/ACSC
CCCS
CNMF
FBI
NCSC-UK
NSA
|
| 2024-02-21 |
CISA, EPA, and FBI Release Top Cyber Actions for Securing Water Systems
This fact sheet outlines the following practical actions Water and Wastewater Systems (WWS) Sector entities can take to better protect water systems from malicious cyber activity and provides actionable guidance to implement concurrently: Reduce Exposure to the Public-Facing Internet Conduct Regular Cybersecurity Assessments Change Default Passwords Immediately Conduct an Inventory of Operational Technology/Information Technology Assets Develop a…
|
FBI
|
| 2024-02-15 |
CISA and MS-ISAC Release Advisory on Compromised Account Used to Access State Government Organization
Following an incident response assessment of a state government organization’s network environment, analysis confirmed compromise through network administrator credentials of a former employee. This allowed the threat actor to successfully authenticate to an internal virtual private network (VPN) access point.
|
MS-ISAC
|
| 2024-02-15 |
Threat Actor Leverages Compromised Account of Former Employee to Access State Government Organization
CISA Analysis: Fiscal Year 2022 Risk and Vulnerability Assessments The Cybersecurity and Infrastructure Security Agency (CISA) conducts Risk and Vulnerability Assessments (RVAs) for the federal civilian executive branch (FCEB); high priority private and public sector critical infrastructure operators; and select state, local, tribal, and territorial (SLTT) stakeholders.
|
CSA
|
| 2024-02-13 |
Microsoft Releases Security Updates for Multiple Products
A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy.
|
JPCERT/CC
|
| 2024-02-07 |
CISA and Partners Release Advisory on PRC-sponsored Volt Typhoon Activity and Supplemental Living Off the Land Guidance
Today, CISA, the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) released a joint Cybersecurity Advisory (CSA), PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure alongside supplemental Joint Guidance: Identifying and Mitigating Living off the Land Techniques .
|
FBI
NSA
|
| 2024-02-07 |
PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure
For a downloadable copy of indicators of compromise (IOCs), see: MAR-10448362.c1.v2.CLEAR_stix2.json (JSON, 51.
|
ASD/ACSC
CCCS
DOE
EPA
FBI
NCSC-NZ
NCSC-UK
NIST
NSA
TSA
|
| 2024-02-07 |
PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure
Prioritize patching critical sponsored cyber actors are seeking to prevulnerabilities in appliances known to be position themselves on IT networks for disruptive frequently exploited by Volt Typhoon. or destructive cyberattacks against U.S. critical infrastructure in the event of a major crisis or conflict with the United States.
|
ASD/ACSC
CCCS
DOE
EPA
FBI
NCSC-NZ
NCSC-UK
NSA
TSA
|
| 2024-02-07 |
CTR: Joint Guidance: Identifying and Mitigating Living Off the Land Techniques
This guide, authored by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), agencies (hereafter referred to as the authoring agencies), provides information on common living off the land (LOTL) techniques and common gaps in cyber defense capabilities. U.S. Department of Energy (DOE) U.S. Environmental Protection Agency (EPA) U.S.
|
ASD/ACSC
CCCS
DOE
EPA
FBI
NCSC-NZ
NCSC-UK
NSA
TSA
|
| 2024-01-31 |
CISA and FBI Release Secure by Design Alert Urging Manufacturers to Eliminate Defects in SOHO Routers
Today, CISA and the Federal Bureau of Investigation (FBI) published guidance on Security Design Improvements for SOHO Device Manufacturers as a part of the new Secure by Design (SbD) Alert series that focuses on how manufacturers should shift the burden of security away from customers by integrating security into product design and development.
|
FBI
|
| 2024-01-23 |
CISA Joins ACSC-led Guidance on How to Use AI Systems Securely
The following organizations also collaborated with ACSC on the guidance: Israel National Cyber Directorate (INCD) Japan National Center of Incident Readiness and Strategy for Cybersecurity (NISC) and the Secretariat of Science, Technology and Innovation Policy, Cabinet Office Norway National Cyber Security Centre (NCSC-NO) Sweden National Cybersecurity Center The guidance provides AI systems users with an overview of AI-related threats as well as…
|
ASD/ACSC
|
| 2024-01-23 |
CSI: Engaging with Artificial Intelligence
The purpose of this publication is to provide organisations with guidance on how to use AI systems securely. The paper summarises some important threats related to AI systems and prompts organisations to consider steps they can take to engage with AI while managing risk.
|
ASD/ACSC
BSI
CCCS
CSA
FBI
NCSC-NZ
NCSC-UK
NSA
|
| 2024-01-18 |
Oracle Releases Critical Patch Update Advisory for January 2024
A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy.
|
JPCERT/CC
|
| 2024-01-16 |
CISA and FBI Release Known IOCs Associated with Androxgh0st Malware
Androxgh0st malware establishes a botnet for victim identification and exploitation in vulnerable networks, and targets files that contain confidential information, such as credentials, for various high profile applications. Threat actors deploying Androxgh0st malware have been observed exploiting specific vulnerabilities which could lead to remote code execution, including: CVE-2017-9841 (PHP Unit Command) CVE-2021-41773 (Apache HTTP Server vers…
|
FBI
|
| 2024-01-16 |
Known Indicators of Compromise Associated with Androxgh0st Malware
tactics, techniques, and procedures (TTPs) associated • Review and ensure only necessary with threat actors deploying Androxgh0st malware. servers and services are exposed to Multiple, ongoing investigations and trusted third party the internet. reporting yielded the IOCs and TTPs, and provided • Review platforms or services that information on Androxgh0st malware’s ability to have credentials listed in .
|
CSA
FBI
|
| 2024-01-09 |
Microsoft Releases Security Updates for Multiple Products
A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy.
|
JPCERT/CC
|
| 2024-01-04 |
CSI: Recommendations for Software Bill of Materials (SBOM) Management (Jan 2024 Update)
Recommendations for Software Bill of Materials The dramatic increase in cyber compromises over the past five years, specifically of software supply chains, prompted intense scrutiny of measures to strengthen the resilience of supply chains for software used throughout government and critical infrastructure. Several policies and working groups at multiple levels within the U.S.
|
NSA
NSM
|