| 2026-03-13 |
CSI: AI ML Supply Chain Risks and Mitigations
Supply chain risks and mitigations 2 Artificial intelligence and machine learning Supply chain risks and mitigations Artificial intelligence and machine learning Supply chain risks and mitigations 3 Artificial intelligence (AI) and machine with this, risks outlined in this guidance are learning (ML) systems allow organisations to mapped to the National Institute of Standards improve their efficiency in many areas.
|
ASD/ACSC
CCCS
NCO
NCSC-NZ
NCSC-UK
NIS
NSA
|
| 2025-09-03 |
Joint Guidance: A Shared Vision of Software Bill Of Materials For Cybersecurity
Widespread adoption of SBOM will strengthen security, reduce risk, and Most modern software is comprised of software components, modules, and libraries from open source and proprietary software worlds, rather than developers creating it from scratch. As concerns about the security and provenance of software grow, it is critical to understand the risks in the software’s supply chain— including the risks of the underlying software components.
|
ANSSI
ASD/ACSC
BSI
CCCS
CISA
NCO
NCSC-NL
NCSC-NZ
NIS
NSA
NUKIB
|
| 2025-01-22 |
CISA and FBI Release Advisory on How Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications
This advisory was crafted in response to exploitation of vulnerabilities— CVE-2024-8963 , an administrative bypass vulnerability; CVE-2024-9379 , a SQL injection vulnerability; and CVE-2024-8190 and CVE-2024-9380 , remote code execution vulnerabilities—in Ivanti Cloud Service Appliances (CSA) in September 2024.
|
CISA
FBI
|
| 2024-08-28 |
Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations
The FBI assesses a significant percentage of these threat actors’ operations against US organizations are intended to obtain and develop network access to then collaborate with ransomware affiliate actors to deploy ransomware. The FBI further assesses these Iran-based cyber actors are associated with the Government of Iran (GOI) and—separate from the ransomware activity—conduct computer network exploitation activity in support of the GOI (such as…
|
CISA
DC3
FBI
|
| 2024-08-21 |
ASD’s ACSC, CISA, FBI, and NSA, with the support of International Partners Release Best Practices for Event Logging and Threat Detection
Logging priorities for enterprise mobility using mobile computing devices 10 Protecting event logs from unauthorised access, modification and deletion 11 This publication defines a baseline for event logging best practices to mitigate cyber threats.
|
AIVD
ASD/ACSC
CCCS
CISA
MIVD
NCSC-NZ
NCSC-UK
NIS
NSA
|
| 2024-07-11 |
CISA Releases Advisory Detailing Red Team Activity During Assessment of US FCEB Organization, Highlighting Necessity of Defense-in-Depth
Today, CISA released CISA Red Team’s Operations Against a Federal Civilian Executive Branch Organization Highlights the Necessity of Defense-in-Depth in coordination with the assessed organization. This Cybersecurity Advisory (CSA) details key findings and lessons learned from a 2023 assessment, along with the red team’s tactics, techniques, and procedures (TTPs) and associated network defense activity.
|
CISA
|
| 2024-07-11 |
CISA Red Team’s Operations Against a Federal Civilian Executive Branch Organization Highlights the Necessity of Defense-in-Depth
During SILENTSHIELD assessments, the red team first performs a no-notice, long-term simulation of nation-state cyber operations. The team mimics the techniques, tradecraft, and behaviors of sophisticated threat actors and measures the potential dwell time actors have on a network, providing a realistic assessment of the organization’s security posture.
|
CISA
|
| 2024-05-10 |
CISA and Partners Release Advisory on Black Basta Ransomware
Today, CISA, in partnership with the Federal Bureau of Investigation (FBI), the Department of Health and Human Services (HHS), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) released joint Cybersecurity Advisory (CSA) #StopRansomware: Black Basta to provide cybersecurity defenders tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) used by known Black Basta ransomware affiliates and identified thr…
|
CISA
FBI
HHS
MS-ISAC
|
| 2024-02-15 |
Threat Actor Leverages Compromised Account of Former Employee to Access State Government Organization
CISA Analysis: Fiscal Year 2022 Risk and Vulnerability Assessments The Cybersecurity and Infrastructure Security Agency (CISA) conducts Risk and Vulnerability Assessments (RVAs) for the federal civilian executive branch (FCEB); high priority private and public sector critical infrastructure operators; and select state, local, tribal, and territorial (SLTT) stakeholders.
|
CISA
|
| 2024-01-23 |
CSI: Engaging with Artificial Intelligence
The purpose of this publication is to provide organisations with guidance on how to use AI systems securely. The paper summarises some important threats related to AI systems and prompts organisations to consider steps they can take to engage with AI while managing risk.
|
ASD/ACSC
BSI
CCCS
CISA
FBI
NCSC-NZ
NCSC-UK
NSA
|
| 2024-01-16 |
Known Indicators of Compromise Associated with Androxgh0st Malware
tactics, techniques, and procedures (TTPs) associated • Review and ensure only necessary with threat actors deploying Androxgh0st malware. servers and services are exposed to Multiple, ongoing investigations and trusted third party the internet. reporting yielded the IOCs and TTPs, and provided • Review platforms or services that information on Androxgh0st malware’s ability to have credentials listed in .
|
CISA
FBI
|