| 2026-09-08 |
China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S.
|
CISA
FBI
|
| 2026-08-26 |
Joint CSA: China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems
The Federal Bureau of Investigation, National Security Agency, and Cyber National Mission Force are releasing this joint cybersecurity advisory to alert organizations concerning China-linked cyber threat actors, who use the acronyms QTFY, QT, and QTCYBER for themselves and their tools and have developed malicious distributed platforms to compromise the networks of US and foreign organizations.
|
CNMF
FBI
|
| 2026-08-10 |
#StopRansomware: Gunra Ransomware
Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid.
|
CISA
DC3
FBI
KNPA
USSS
|
| 2026-07-29 |
2026 Minimum Elements for a Software Bill of Materials (SBOM)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the co-authoring organizations, updated the Minimum Elements for a Software Bill of Materials (SBOM) to reflect current SBOM needs, while preserving the core principles of the document published in 2021 by the National Telecommunications and Information Administration (NTIA).
|
ASD/ACSC
CISA
FBI
NTIA
|
| 2026-07-23 |
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Read our joint advisory on LAUNDRY BEAR's exploitation of Zimbra Collaboration Suite.
|
AISE
AISI
AIVD
ANSSI
ASD/ACSC
AW
CCCS
CISA
CNI
DC3
DCSA
DDIS
DGSI
EFIS
FBI
FDI
MIVD
NCIS
NCSC-NZ
NCSC-SE
NCSC-UK
NUKIB
SIS RM
SKW
SUPO
Treasury
|
| 2026-07-15 |
Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers
This guidance outlines best practices for suppliers to design and implement a coordinated vulnerability disclosure (CVD) program to effectively and transparently collaborate with security researchers to report and remediate vulnerabilities.
|
CISA
NCSC-NL
NCSC-UK
|
| 2026-07-13 |
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks.
|
ASD/ACSC
CCCS
CISA
FBI
NCSC-NZ
NCSC-UK
|
| 2026-06-22 |
The AI shift in cyber risk: why leaders must act now
Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk. As the leaders of the Five Eyes cyber security agencies, we are united in our call to action: the evolving landscape of artificial intelligence (AI) is rapidly transforming cyber risk, and we must act swiftly to remain ahead.
|
ASD/ACSC
CCCS
CISA
NCSC-UK
|
| 2026-06-02 |
CISA and Partners Urge Hardening Automatic Tank Gauge Systems
The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the (EPA), the Transportation Security Administration (TSA), the Department of Transportation (DOT), and the U.S. Department of Agriculture (USDA)—hereafter referred to as “the authoring organizations”—are aware of malicious cyber activity targeting U.S.-based automatic tank gauge (ATG) systems.
|
CISA
DOE
EPA
FBI
TSA
USDA
|
| 2026-04-23 |
Defending Against China-Nexus Covert Networks of Compromised Devices
Over the past few years there has been a major shift in the tactics, techniques and procedures (TTPs) used by China-nexus cyber actors, moving away from the use of individually procured infrastructure, and towards the use of externally provisioned, large-scale networks of compromised devices.
|
AIVD
ASD/ACSC
BSI
CCCS
CISA
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-SE
NCSC-UK
|
| 2026-04-23 |
International cyber agencies share fresh advice to defend against China-linked covert networks
GCHQ’s National Cyber Security Centre with UK industry and 15 international partners shine light on best protections against methods used by China-linked threat actors. Covert networks, often made up of compromised devices such as smart devices, are being used to disguise the origins and attributions of cyber attacks.
|
AIVD
ASD/ACSC
BSI
CCCS
CISA
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-SE
NCSC-UK
|
| 2026-04-07 |
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
This activity has led to PLC disruptions across several U.S. critical infrastructure sectors through malicious interactions with the project file and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss. U.S.
|
CISA
CNMF
DOE
EPA
FBI
NIST
|
| 2026-03-13 |
CSI: AI ML Supply Chain Risks and Mitigations
Supply chain risks and mitigations 2 Artificial intelligence and machine learning Supply chain risks and mitigations Artificial intelligence and machine learning Supply chain risks and mitigations 3 Artificial intelligence (AI) and machine with this, risks outlined in this guidance are learning (ML) systems allow organisations to mapped to the National Institute of Standards improve their efficiency in many areas.
|
ASD/ACSC
CCCS
CSA
NCO
NCSC-NZ
NCSC-UK
NIS
|
| 2026-02-25 |
CISA and Partners Release Guidance for Ongoing Global Exploitation of Cisco SD-WAN Systems
CISA and partners have observed malicious cyber actors targeting and compromising Cisco SD-WAN systems of organizations, globally. These actors have been observed exploiting a previously undisclosed authentication bypass vulnerability, CVE-2026-20127, for initial access before escalating privileges using CVE-2022-20775 and establishing long-term persistence in Cisco SD-WAN systems.
|
ASD/ACSC
CCCS
CISA
NCSC-NZ
NCSC-UK
|
| 2026-02-25 |
CSA: Exploitation of SD-WAN Appliances
Malicious cyber threat actors are targeting Software-Defined Wide Area Networks (SDWANs) of organizations globally. These actors exploited a Cisco Catalyst SD-WAN controller authentication bypass vulnerability, CVE-2026-20127. After exploitation of this vulnerability the malicious actors add a rogue peer, and eventually gain root access to establish long-term persistence in SD-WANs.
|
ASD/ACSC
CCCS
CISA
NCSC-NZ
NCSC-UK
|
| 2026-01-30 |
CTR: Zero Trust Implementation Guideline Phase Two
Cybersecurity Technical Report Zero Trust Implementation Guideline January 2026 1.0 Initial publication The information and opinions contained in this document are provided "as is" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Gove…
|
CISA
|
| 2026-01-14 |
CTR: Zero Trust Implementation Guideline Primer
Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product This document was developed in furtherance of NSA’s cybersecurity missions, including its responsibilities to identify and disseminate threats, and to d…
|
CISA
|
| 2025-12-19 |
CISA and Partners Release Update to Malware Analysis Report BRICKSTORM Backdoor
This update provides information on additional samples, including Rust-based samples. These samples demonstrate advanced persistence and defense evasion mechanisms, such as running as background services, and enhanced command and control capabilities through encrypted WebSocket connections.
|
CCCS
CISA
|
| 2025-12-15 |
Principles for the Secure Integration of Artificial Intelligence in Operational Technology
CISA | ASD’s ACSC | NSA AISC | FBI | Cyber Centre | BSI | NCSC-NL | NCSC-NZ | NCSC-UK Introduction ................................................................................................................................................................... 3 Important Terminology ....................................................................................................................................... 3 Scope ...................
|
ASD/ACSC
BSI
CCCS
CISA
FBI
NCSC-NL
NCSC-NZ
NCSC-UK
|
| 2025-12-09 |
Opportunistic Pro-Russia Hacktivists Attack US and Global Critical Infrastructure
This advisory, published as an addition to the joint fact sheet on Primary Mitigations to Reduce Cyber Threats to Operational Technology (OT) released in May 2025 , details that pro-Russia hacktivist groups are conducting less sophisticated, lower-impact attacks against critical infrastructure entities, compared to advanced persistent threat groups.
|
CISA
DOE
EPA
FBI
|
| 2025-12-09 |
Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure
Actions for Operational Technology Owners and Operators to Take Today to Mitigate Cyber Threats Related to Pro-Russia Hacktivists Activity Reduce exposure of operational technology (OT) assets to the public-facing internet. Adopt mature asset management processes, including mapping data flows and access points. Ensure that OT assets are using robust authentication procedures.
|
ASD/ACSC
BSI
CCCS
CISA
DC3
DOE
EC3
EPA
FBI
NCSC-NZ
NCSC-UK
NUKIB
|
| 2025-12-09 |
Pro-Russia Hacktivists Conduct Opportunistic Attacks Against U.S. and Global Critical Infrastructure
FBI, CISA, National Security Agency (NSA), and the following partners—hereafter referred to as “the authoring organizations”—are releasing this joint advisory on the targeting of critical infrastructure by proRussia hacktivists: The authoring organizations assess pro-Russia hacktivist groups are conducting less sophisticated, lowerimpact attacks against critical infrastructure entities, compared to advanced persistent threat (APT) groups.
|
ASD/ACSC
BSI
CCCS
DC3
DOE
EC3
EPA
FBI
NCSC-NZ
NCSC-UK
NUKIB
|
| 2025-12-04 |
BRICKSTORM Backdoor
Malware Analysis at a Glance Malware Name BRICKSTORM Original Publication Dec. 4, 2025 Last Update Feb. 11, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Canadian Centre for Cyber Security (Cyber Centre) assess People’s Republic of China (PRC) state-sponsored cyber actors are using BRICKSTORM malware for long-term persistence on victim systems.
|
CCCS
CISA
|
| 2025-12-03 |
CISA, Australia, and Partners Author Joint Guidance on Securely Integrating Artificial Intelligence in Operational Technology
CISA and the Australian Signals Directorate’s Australian Cyber Security Centre, in collaboration with federal and international partners, have released new cybersecurity guidance: Principles for the Secure Integration of Artificial Intelligence in Operational Technology .
|
ASD/ACSC
CISA
FBI
|
| 2025-11-19 |
Bulletproof Defense: Mitigating Risks from Bulletproof Hosting Providers
This document was developed through the Joint Ransomware Task Force (JRTF), a U.S. interagency body established by Congress in the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) to ensure unity of effort in combating the growing threat of ransomware attacks.
|
ASD/ACSC
CCCS
CISA
DC3
FBI
NCSC-NL
NCSC-NZ
NCSC-UK
|
| 2025-10-30 |
New Guidance Released on Microsoft Exchange Server Security Best Practices
Threat activity targeting Exchange continues to persist, and organizations with unprotected or misconfigured Exchange servers remain at high risk of compromise. This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA
|
| 2025-09-03 |
Joint Guidance: A Shared Vision of Software Bill Of Materials For Cybersecurity
Widespread adoption of SBOM will strengthen security, reduce risk, and Most modern software is comprised of software components, modules, and libraries from open source and proprietary software worlds, rather than developers creating it from scratch. As concerns about the security and provenance of software grow, it is critical to understand the risks in the software’s supply chain— including the risks of the underlying software components.
|
ANSSI
ASD/ACSC
BSI
CCCS
CISA
CSA
NCO
NCSC-NL
NCSC-NZ
NIS
NUKIB
|
| 2025-09-03 |
CISA, NSA, and Global Partners Release a Shared Vision of Software Bill of Materials (SBOM) Guidance
This marks a significant step forward in strengthening software supply chain transparency and security worldwide. An SBOM is a formal record detailing the components and supply chain relationships used in building software. SBOMs act as a software “ingredients list” providing organizations with essential visibility into software dependencies, enabling them to identify components, assess risks, and take proactive measures to mitigate vulnerabiliti…
|
CISA
|
| 2025-08-27 |
Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System
Executive summary People’s Republic of China (PRC) state-sponsored cyber threat actors are targeting networks globally, including, but not limited to, telecommunications, government, transportation, lodging, and military infrastructure networks.
|
AISE
AISI
AIVD
ASD/ACSC
AW
BSI
CCCS
CISA
CNI
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-UK
NUKIB
SKW
SUPO
|
| 2025-08-27 |
CISA and Partners Release Joint Advisory on Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage Systems
CISA, along with the National Security Agency, Federal Bureau of Investigation, and international partners, released a joint Cybersecurity Advisory on People’s Republic of China (PRC) state-sponsored Advanced Persistent Threat (APT) actors targeting critical infrastructure across sectors and continents to maintain persistent, long-term access to networks.
|
CISA
FBI
|
| 2025-08-27 |
CSA: Countering China State Actors Compromise of Networks
While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks.
|
AISE
AISI
AIVD
ASD/ACSC
AW
BSI
CCCS
CISA
CNI
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-UK
NUKIB
SKW
SUPO
|
| 2025-08-27 |
Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System
While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks.
|
AISE
AISI
AIVD
ASD/ACSC
AW
BSI
CCCS
CISA
CNI
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-UK
NUKIB
SKW
SUPO
|
| 2025-08-13 |
CISA and Partners Release Asset Inventory Guidance for Operational Technology Owners and Operators
CISA, along with the National Security Agency, the Federal Bureau of Investigation, Environmental Protection Agency, and several international partners, released comprehensive guidance to help operational technology (OT) owners and operators across all critical infrastructure sectors create and maintain OT asset inventories and supplemental taxonomies.
|
CISA
EPA
FBI
|
| 2025-08-13 |
Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators
Using these tools helps owners and operators identify which assets in their environment should be secured and protected, and structure their defenses accordingly to reduce the risk a cybersecurity incident poses to the organization’s mission and service continuity. An asset inventory is an organized, regularly updated list of an organization’s systems, hardware, and software.
|
ASD/ACSC
BSI
CCCS
CISA
DOE
EPA
FBI
NCSC-NL
NCSC-NZ
|
| 2025-06-30 |
CISA and Partners Urge Critical Infrastructure to Stay Vigilant in the Current Geopolitical Environment
Today, CISA, in collaboration with the Federal Bureau of Investigation (FBI), the Department of Defense Cyber Crime Center (DC3), and the National Security Agency (NSA), released a Fact Sheet urging organizations to remain vigilant against potential targeted cyber operations by Iranian state-sponsored or affiliated threat actors.
|
CISA
DC3
FBI
|
| 2025-06-30 |
Iranian Cyber Actors May Target Vulnerable U.S. Networks and Entities of Interest
critical infrastructure and other U.S. entities by Iranian-affiliated cyber actors. Despite a declared ceasefire and ongoing negotiations towards a permanent solution, Iranian-affiliated cyber actors and hacktivist groups may still conduct malicious cyber activity.
|
CISA
DC3
FBI
|
| 2025-06-24 |
New Guidance Released for Reducing Memory-Related Vulnerabilities
Memory safety vulnerabilities pose serious risks to national security and critical infrastructure. Adopting memory safe languages (MSLs) offers the most comprehensive mitigation against this class of vulnerabilities and provides built-in safeguards that enhance security by design.
|
CISA
|
| 2025-06-24 |
CSI: Memory Safe Languages: Reducing Vulnerabilities in Modern Software Development
In 2022, the National Security Agency (NSA) released a cybersecurity information sheet (CSI), “Software Memory Safety.” [1] In 2023, the Cybersecurity and Infrastructure Security Agency (CISA) published the joint guide, “The Case for Memory Safe Roadmaps,” [2] and in 2024, the White House issued “Back to the Building Blocks: A Path Toward Secure and Measurable Software.
|
CISA
|
| 2025-05-27 |
Implementing SIEM and SOAR Platforms: Practitioners Guidance
4. Best practice principles for implementing a SIEM and/or SOAR 12 This publication provides high-level guidance for cyber security practitioners on Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms.
|
ASD/ACSC
|
| 2025-05-22 |
AI Data Security
Joint Cybersecurity Information Best Practices for Securing Data Used to Train & Operate AI Systems This Cybersecurity Information Sheet (CSI) provides essential guidance on securing data used in artificial intelligence (AI) and machine learning (ML) systems.
|
ASD/ACSC
CISA
FBI
NCSC-NZ
NCSC-UK
|
| 2025-05-22 |
CSI: AI Data Security: Best Practices for Securing Data Used to Train & Operate AI Systems
Joint Cybersecurity Information This Cybersecurity Information Sheet (CSI) provides essential guidance on securing data used in artificial intelligence (AI) and machine learning (ML) systems. It also highlights the importance of data security in ensuring the accuracy and integrity of AI outcomes and outlines potential risks arising from data integrity issues in various stages of AI development and deployment.
|
ASD/ACSC
CISA
FBI
NCSC-NZ
NCSC-UK
|
| 2025-05-21 |
Russian GRU Targeting Western Logistics Entities and Technology Companies
Executive Summary This joint cybersecurity advisory (CSA) highlights a Russian state-sponsored cyber campaign targeting Western logistics entities and technology companies. This includes those involved in the coordination, transport, and delivery of foreign assistance to Ukraine.
|
ASD/ACSC
CCCS
CISA
FBI
NCSC-UK
USCC
|
| 2025-05-21 |
Russian GRU Targeting Western Logistics Entities and Technology Companies
This joint cybersecurity advisory (CSA) highlights a Russian state-sponsored cyber those involved in the coordination, transport, and delivery of foreign assistance to Ukraine. Since 2022, Western logistics entities and IT companies have faced an elevated risk of targeting by the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (85th GTsSS), military unit 26165—tracked in the cybersecurity community under…
|
ANSSI
ASD/ACSC
BSI
CCCS
DC3
DDIS
EFIS
FBI
MIVD
NCSC-UK
NUKIB
SKW
USCC
|
| 2025-04-29 |
Info Sheet: Selecting a Protective DNS Service (April 2025 Update)
Security Infrastructure Cybersecurity Information Selecting a Protective DNS Service The Domain Name System (DNS) is central to the operation of modern networks, translating human-readable domain names into machine-usable Internet Protocol (IP) addresses. DNS makes navigating to a website, sending an email, or making a secure shell connection easier, and is a key component of the Internet's resilience.
|
CISA
NCSC-UK
|
| 2025-04-09 |
CSA: BADBAZAAR and MOONSHINE: Technical analysis and mitigations
BADBAZAAR and MOONSHINE: Technical With support from the UK Cyber League, this advisory has been jointly produced by the National Cyber Security Centre (NCSC UK) and international partners: > The Australian Cyber Security Centre, part of the Australian Signals > The Canadian Centre for Cyber Security, part of the Communications > The German Federal Intelligence Service > The German Federal Office for the Protection of the Constitution > The New Z…
|
ASD/ACSC
CCCS
FBI
NCSC-NZ
NCSC-UK
|
| 2025-04-09 |
BADBAZAAR and MOONSHINE: Spyware Targeting Uyghur, Taiwanese, and Tibetan Groups and Civil Society Actors
This advisory includes two case studies detailing techniques used by malicious cyber actors using spyware known as BADBAZAAR and MOONSHINE to target data on mobile devices including smartphones that could be of interest to the Chinese state.
|
ASD/ACSC
CCCS
FBI
NCSC-NZ
NCSC-UK
|
| 2025-04-03 |
NSA, CISA, FBI, and International Partners Release Cybersecurity Advisory on “Fast Flux,” a National Security Threat
Today, CISA—in partnership with the National Security Agency (NSA), Federal Bureau of Investigation (FBI), Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), Canadian Centre for Cyber Security (CCCS), and New Zealand’s National Cyber Security Centre (NCSC-NZ)—released joint Cybersecurity Advisory Fast Flux: A National Security Threat (PDF, 841 KB).
|
ASD/ACSC
CCCS
CISA
FBI
NCSC-NZ
|
| 2025-04-03 |
Fast Flux: A National Security Threat
The Protective Domain Name System (DNS) Resolver service allows the Cybersecurity and Infrastructure Security Agency (CISA) to detect and prevent cyberattacks and threats targeting federal civilian executive branch (FCEB) agency networks. Protective DNS also offers a range of capabilities to safeguard assets that may otherwise be challenging to protect such as cloud, mobile, and nomadic devices.
|
ASD/ACSC
CCCS
CISA
FBI
NCSC-NZ
|
| 2025-04-03 |
Fast Flux: A National Security Threat
Malicious cyber actors, including cybercriminals and nation-state actors, use fast flux to obfuscate the locations of malicious servers by rapidly changing Domain Name System (DNS) records. Additionally, they can create resilient, highly available command and control (C2) infrastructure, concealing their subsequent malicious operations.
|
ASD/ACSC
CCCS
CISA
FBI
NCSC-NZ
|
| 2025-03-24 |
Info Sheet: Selecting a Protective DNS Service (March 2025 Update)
Security Infrastructure Cybersecurity Information Selecting a Protective DNS Service The Domain Name System (DNS) is central to the operation of modern networks, translating human-readable domain names into machine-usable Internet Protocol (IP) addresses. DNS makes navigating to a website, sending an email, or making a secure shell connection easier, and is a key component of the Internet's resilience.
|
CISA
NCSC-UK
|
| 2025-02-12 |
Secure by Design Alert: Eliminating Buffer Overflow Vulnerabilities
The Secure by Design initiative seeks to foster a cultural shift across the technology industry, normalizing the development of the Secure by Design Pledge, and stay informed on the latest Secure by Design Alerts. Buffer overflow vulnerabilities are a prevalent type of memory The software development community has safety software design defect that regularly lead to system compromise.
|
CISA
FBI
|
| 2025-02-03 |
CSI: Security Considerations for Edge Devices: Executive Guidance
Mitigation strategies for edge Malicious actors are increasingly targeting internet-facing edge devices to gain unauthorised access to networks; therefore, it is vital that organisations prioritise securing edge devices in their environments. Edge devices are critical network components that serve as security boundaries between internal enterprise networks and the internet.
|
ASD/ACSC
CCCS
CISA
FBI
NCSC-NZ
NCSC-UK
|
| 2025-01-29 |
CSI: Content Credentials: Strengthening Multimedia Integrity in the Generative AI Era
The ability to manipulate media is not new, but the accessibility, speed, and quality of these modifications today, powered by artificial intelligence (AI) and machine learning tools, have reached unprecedented levels and may not be caught by traditional verification methods.
|
ASD/ACSC
CCCS
NCSC-UK
|
| 2025-01-16 |
CISA and Partners Release Call to Action to Close the National Software Understanding Gap
Today, CISA—in partnership with the Defense Advanced Research Projects Agency (DARPA), the Office of the Under Secretary of Defense for Research and Engineering (OUSD R&E), and the National Security Agency (NSA)—published Closing the Software Understanding Gap . This report urgently implores the U.S. government to take decisive and coordinated action. Software understanding refers to assessing software-controlled systems across all conditions.
|
CISA
DARPA
|
| 2025-01-16 |
CSI: Closing the Software Understanding Gap
Software is embedded in countless systems responsible for providing U.S. critical infrastructure services that Americans rely on as well as systems providing national security capabilities. To maintain confidence in national security and critical infrastructure systems, mission owners and operators should be able to trust the system is functional, safe, and secure.
|
CISA
DOE
FBI
|
| 2025-01-13 |
Secure by Demand: Priority Considerations for Operational Technology Owners and Operators When Selecting Digital Products
Many OT products are not designed and developed with Secure by Design principles1 and commonly have weaknesses, such as weak authentication, known software vulnerabilities, limited logging, insecure default settings and passwords, and insecure legacy protocols. Cyber threat actors can easily exploit these weaknesses across multiple victims to gain access to control systems.
|
ASD/ACSC
BSI
CCCS
CISA
EPA
FBI
NCSC-NL
NCSC-NZ
NCSC-UK
TSA
|
| 2025-01-13 |
CISA and US and International Partners Publish Guidance on Priority Considerations in Product Selection for OT Owners and Operators
As part of CISA’s Secure by Demand series, this guidance focuses on helping customers identify manufacturers dedicated to continuous improvement and achieving a better cost balance, as well as how Operational Technology (OT) owners and operators should integrate secure by design elements into their procurement process. Critical infrastructure and industrial control systems are prime targets for cyberattacks.
|
CISA
FBI
|
| 2024-12-31 |
CSI: Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) FAQ (December 2024 Update)
This information may be useful more generally, especially for those who interact with NSS, DoD, or DIB systems. Future cryptographic algorithms Q: To whom are these requirements addressed? These are mainly addressed to the following audiences: National Security System (NSS) owners and operators, who need to know the requirements for their systems Vendors, who need to know what to implement to meet NSS requirements NSA is not using these req…
|
NSM
|
| 2024-12-18 |
CSA: IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including U.S. Water and Wastewater Systems Facilities (December 2024 update)
IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and
|
CCCS
CISA
EPA
FBI
NCSC
|
| 2024-12-03 |
CISA and Partners Release Joint Guidance on PRC-Affiliated Threat Actor Compromising Networks of Global Telecommunications Providers
Today, CISA—in partnership with the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and international partners—released joint guidance, Enhanced Visibility and Hardening Guidance for Communications Infrastructure .
|
CISA
FBI
|
| 2024-12-03 |
Enhanced Visibility and Hardening Guidance for Communications Infrastructure
The authoring agencies are releasing this guide to highlight this threat and provide network engineers and defenders of communications infrastructure with best practices to strengthen their visibility and harden their network devices against successful exploitation carried out by PRC-affiliated and other malicious cyber actors.
|
ASD/ACSC
CISA
FBI
NCSC-NZ
|
| 2024-11-12 |
2023 Top Routinely Exploited Vulnerabilities
Summary The following cybersecurity agencies coauthored this joint Cybersecurity Advisory (hereafter collectively referred to as the authoring agencies): United States: The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and National Security Agency (NSA) Australia: Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) Canada: Canadian Centre for Cyber Security (CCCS) New Zeal…
|
ASD/ACSC
CCCS
CISA
NCSC-NZ
NCSC-UK
NIST
|
| 2024-11-12 |
CISA, FBI, NSA, and International Partners Release Joint Advisory on 2023 Top Routinely Exploited Vulnerabilities
This advisory supplies details on the top Common Vulnerabilities and Exposures (CVEs) routinely exploited by malicious cyber actors and their associated Common Weakness Enumeration(s) (CWE) to help organizations better understand the impact of exploitation.
|
CISA
FBI
|
| 2024-10-16 |
Iranian Cyber Actors’ Brute Force and Credential Access Activity Compromises Critical Infrastructure Organizations
Summary The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Communications Security Establishment Canada (CSE), the Australian Federal Police (AFP), and Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) are releasing this joint Cybersecurity Advisory to warn network defenders of Iranian cyber actors’ use of brute force and othe…
|
AFP
ASD/ACSC
CCCS
CISA
CSE
FBI
NIST
|
| 2024-10-16 |
CISA, FBI, NSA, and International Partners Release Advisory on Iranian Cyber Actors Targeting Critical Infrastructure Organizations Using Brute Force
This advisory provides known indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) used by Iranian actors to impact organizations across multiple critical infrastructure sectors. Since October 2023, Iranian actors have used brute force and password spraying to compromise user accounts and obtain access to organizations in the healthcare and public health (HPH), government, information technology, engineering, and energy s…
|
CISA
FBI
|
| 2024-10-10 |
Update on SVR Cyber Operations and Vulnerability Exploitation
The Federal Bureau of Investigation (FBI), the The authoring agencies recommend the following mitigations to protect their networks. Mission Force (CNMF), and the United See the Mitigations section for the complete Kingdom’s National Cyber Security Centre (NCSC-UK) are releasing this joint Cybersecurity Advisory (CSA) to highlight the tactics, • Reduce attack surface by disabling techniques, and procedures (TTPs) employed by Internet-accessible s…
|
CNMF
FBI
NCSC-UK
|
| 2024-09-26 |
ASD’s ACSC, CISA, and US and International Partners Release Guidance on Detecting and Mitigating Active Directory Compromises
First published: September 2024 This guidance – authored by the Australian Signals Directorate (ASD), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NCSC-NZ), and the United Kingdom’s National Cyber Security Centre (NCSC-UK) – aims to inform organisations about 17 common techniques used to target Active…
|
ASD/ACSC
CCCS
CISA
NCSC-NZ
NCSC-UK
|
| 2024-09-05 |
FBI, CISA, NSA, and US and International Partners Release Advisory on Russian Military Cyber Actors Targeting US and Global Critical Infrastructure
Today, the Federal Bureau of Investigation (FBI)—in partnership with CISA, the National Security Agency (NSA), and other U.S. and international partners—released a joint Cybersecurity Advisory Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure .
|
CISA
FBI
|
| 2024-09-05 |
Russian Military Cyber Actors Target US and Global Critical Infrastructure
GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and Prioritize routine system updates and remediate known exploited vulnerabilities. Segment networks to prevent the spread of malicious activity.
|
ASD/ACSC
CCCS
CISA
CNMF
FBI
MIVD
NCSC-UK
NIST
Treasury
USCC
|
| 2024-09-05 |
Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure
GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and Prioritize routine system updates and remediate known exploited vulnerabilities. Segment networks to prevent the spread of malicious activity.
|
ASD/ACSC
CCCS
CISA
CNMF
FBI
MIVD
NCSC-UK
Treasury
USCC
|
| 2024-08-21 |
ASD’s ACSC, CISA, FBI, and NSA, with the support of International Partners Release Best Practices for Event Logging and Threat Detection
Logging priorities for enterprise mobility using mobile computing devices 10 Protecting event logs from unauthorised access, modification and deletion 11 This publication defines a baseline for event logging best practices to mitigate cyber threats.
|
AIVD
ASD/ACSC
CCCS
CISA
CSA
MIVD
NCSC-NZ
NCSC-UK
NIS
|
| 2024-07-25 |
North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear Programs
Cyber National Mission Force (CNMF) U.S. Cybersecurity and Infrastructure Security Agency (CISA) U.S. Department of Defense Cyber Crime Center (DC3) U.S. National Security Agency (NSA) Republic of Korea’s National Intelligence Service (NIS) Republic of Korea’s National Police Agency (NPA) United Kingdom’s National Cyber Security Centre (NCSC) The RGB 3rd Bureau includes a DPRK (aka North Korean) state-sponsored cyber group known publi…
|
CISA
CNMF
DC3
FBI
NCSC-UK
NIS
|
| 2024-07-25 |
North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs
The group primarily targets defense, aerospace, nuclear, and engineering entities to obtain sensitive and classified type of activity; number of people affected; type of equipment used for the activity; the name of the submitting company or organization; and a designated point of contact.
|
CISA
CNMF
DC3
FBI
NCSC-UK
NIS
|
| 2024-07-08 |
APT40 Advisory: PRC MSS Tradecraft in Action
Background The following Advisory provides a sample of significant case studies of this adversary’s techniques in action This advisory, authored by the Australian Signals against two victim networks. The case studies are Directorate’s Australian Cyber Security Centre consequential for cybersecurity practitioners to identify, (ASD’s ACSC), the United States Cybersecurity and prevent and remediate APT40 intrusions against their Infrastructure Secur…
|
ASD/ACSC
CCCS
FBI
NCSC-NZ
NCSC-UK
NIS
NPA
|
| 2024-07-08 |
People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action
The advisory draws on the authoring agencies’ shared understanding of the threat as well as ASD’s ACSC incident response investigations. The PRC state-sponsored cyber group has previously targeted organizations in various countries, including Australia and the United States, and the techniques highlighted below are regularly used by other PRC state-sponsored actors globally.
|
ASD/ACSC
BND
CCCS
CISA
FBI
NCSC-NZ
NCSC-UK
NIS
NISC
NPA
|
| 2024-05-22 |
CSI: Advancing Zero Trust Maturity Throughout the Application and Workload Pillar
Information Technology (IT) professionals are keenly aware of the security challenges facing applications, but workloads are every bit as important to consider in this domain. Workloads represent computational tasks, which encompass multiple programs or applications performing those tasks by utilizing computing, data, networking, and storage resources.
|
CISA
NSM
|
| 2024-05-02 |
North Korean Actors Exploit Weak DMARC Security Policies to Mask Spearphishing Efforts
Department of State, and the National Security Agency malicious activity: (NSA) are jointly issuing this advisory to highlight attempts by Democratic People’s Republic of Korea (DPRK, a.k.a. North Korea) Kimsuky cyber actors to exploit improperly configured DNS Domain-based Message Authentication, configurations found below. Reporting and Conformance (DMARC) record policies to conceal social engineering attempts.
|
FBI
|
| 2024-05-01 |
Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity
|
CCCS
CISA
DOE
EPA
FBI
MS-ISAC
NCSC-UK
USDA
|
| 2024-04-15 |
Joint Guidance on Deploying AI Systems Securely
Provide methodologies and controls to protect, detect, and respond to malicious activity against AI systems and related data and services. This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA
FBI
|
| 2024-04-09 |
CSI: Advancing Zero Trust Maturity Throughout the Data Pillar
This cybersecurity information sheet (CSI) provides recommendations for maturing data security and enforcing access to data at rest and in transit, ensuring that only those with authorization can access the data. It further discusses how these capabilities integrate into a comprehensive Zero Trust (ZT) framework, as described in Embracing a Zero Trust Security Model.
|
CISA
NSM
|
| 2024-03-21 |
PRC State-Sponsored Cyber Activity: Actions for Critical Infrastructure Leaders
This fact sheet provides an overview for executive leaders on the urgent risk posed by People’s Republic of China (PRC) state-sponsored cyber actors known as “Volt Typhoon.” CISA—along with the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and other U.S. government and international partners1—released a major advisory on Feb. 7, 2024, in which the U.S.
|
ASD/ACSC
CCCS
DOE
EPA
FBI
NCSC-NZ
NCSC-UK
TSA
Treasury
|
| 2024-03-19 |
CISA and Partners Release Joint Fact Sheet for Leaders on PRC-sponsored Volt Typhoon Cyber Activity
and international partners are issuing a joint fact sheet, People’s Republic of China State-Sponsored Cyber Activity: Actions for Critical Infrastructure Leaders . Partners of this publication include: U.S. Department of Energy (DOE) U.S. Environmental Protection Agency (EPA) U.S. Transportation Security Administration (TSA) U.S.
|
CISA
FBI
|
| 2024-03-07 |
CSI: Mitigate Risks from Managed Service Providers in Cloud Environments
The growth of the public cloud has encouraged the development of numerous MSPs that primarily provide these services within the cloud rather than in customer on-premises networks. Both cloud resellers and other IT vendors offer such third-party services.
|
ASD/ACSC
CISA
|
| 2024-03-07 |
CISA and NSA Release Cybersecurity Information Sheets on Cloud Security Best Practices
Use Secure Cloud Identity and Access Management Practices Use Secure Cloud Key Management Practices Mitigate Risks from Managed Service Providers in Cloud Environments This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA
|
| 2024-03-05 |
CSI: Advancing Zero Trust Maturity Throughout the Network and Environment Pillar
The Zero Trust network and environment pillar curtails adversarial lateral movement by employing controls and capabilities to logically and physically segment, isolate, and control access (on-premises and off-premises) through granular policy restrictions.
|
CISA
NSM
|
| 2024-02-27 |
Russian Cyber Actors Use Compromised Routers to Facilitate Cyber Operations
The Federal Bureau of Investigation (FBI), Actions EdgeRouter network defenders and Command, and international partners are releasing APT28 activity: this joint Cybersecurity Advisory (CSA) to warn of Perform a hardware factory reset. Russian state-sponsored cyber actors’ use of Upgrade to the latest firmware version.
|
FBI
|
| 2024-02-26 |
SVR Cyber Actors Adapt Tactics for Initial Cloud Access
The US National Security Agency (NSA), the US Cybersecurity and Infrastructure Security Agency (CISA), the US the Canadian Centre for Cyber Security (CCCS) and the New Zealand National Cyber Security Centre (NCSC) agree with this attribution and the details This advisory provides an overview of TTPs deployed by the actor to gain initial access into the cloud environment and includes advice to detect and mitigate The NCSC has previously detailed h…
|
ASD/ACSC
CCCS
CISA
CNMF
FBI
NCSC-UK
|
| 2024-02-26 |
SVR Cyber Actors Adapt Tactics for Initial Cloud Access
How SVR-Attributed Actors are Adapting to the Move of Government and Corporations to Cloud Infrastructure OVERVIEW This advisory details recent tactics, techniques, and procedures (TTPs) of the group commonly known as APT29, also known as Midnight Blizzard, the Dukes, or Cozy Bear.
|
CISA
FBI
|
| 2024-02-07 |
CTR: Joint Guidance: Identifying and Mitigating Living Off the Land Techniques
This guide, authored by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), agencies (hereafter referred to as the authoring agencies), provides information on common living off the land (LOTL) techniques and common gaps in cyber defense capabilities. U.S. Department of Energy (DOE) U.S. Environmental Protection Agency (EPA) U.S.
|
ASD/ACSC
CCCS
CISA
DOE
EPA
FBI
NCSC-NZ
NCSC-UK
TSA
|
| 2024-02-07 |
PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure
Prioritize patching critical sponsored cyber actors are seeking to prevulnerabilities in appliances known to be position themselves on IT networks for disruptive frequently exploited by Volt Typhoon. or destructive cyberattacks against U.S. critical infrastructure in the event of a major crisis or conflict with the United States.
|
ASD/ACSC
CCCS
CISA
DOE
EPA
FBI
NCSC-NZ
NCSC-UK
TSA
|
| 2024-02-07 |
PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure
For a downloadable copy of indicators of compromise (IOCs), see: MAR-10448362.c1.v2.CLEAR_stix2.json (JSON, 51.
|
ASD/ACSC
CCCS
CISA
DOE
EPA
FBI
NCSC-NZ
NCSC-UK
NIST
TSA
|
| 2024-02-07 |
CISA and Partners Release Advisory on PRC-sponsored Volt Typhoon Activity and Supplemental Living Off the Land Guidance
Today, CISA, the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) released a joint Cybersecurity Advisory (CSA), PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure alongside supplemental Joint Guidance: Identifying and Mitigating Living off the Land Techniques .
|
CISA
FBI
|
| 2024-01-23 |
CSI: Engaging with Artificial Intelligence
The purpose of this publication is to provide organisations with guidance on how to use AI systems securely. The paper summarises some important threats related to AI systems and prompts organisations to consider steps they can take to engage with AI while managing risk.
|
ASD/ACSC
BSI
CCCS
CISA
CSA
FBI
NCSC-NZ
NCSC-UK
|
| 2024-01-04 |
CSI: Recommendations for Software Bill of Materials (SBOM) Management (Jan 2024 Update)
Recommendations for Software Bill of Materials The dramatic increase in cyber compromises over the past five years, specifically of software supply chains, prompted intense scrutiny of measures to strengthen the resilience of supply chains for software used throughout government and critical infrastructure. Several policies and working groups at multiple levels within the U.S.
|
CISA
NSM
|