| Date | Source | Type | Title | Author |
|---|---|---|---|---|
| Jan 30, 2025 | CISA | Alert | CISA Releases Eight Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-030-01 Hitachi Energy UNEM ICSA-25-030-02 New Rock Technologies Cloud Connected Devices ICSA-25-030-03 Schneider Electric System Monitor Application in Harmony and Pro-face PS5000 Legacy Industrial PCs ICSA-25-030-04 Rockwell Automation KEPServer ICSA-25-030-05 Rockwell Automation FactoryTalk AssetCentre ICSMA-25-030-0… | CISA |
| Jan 30, 2025 | CISA | Alert | CISA Releases Fact Sheet Detailing Embedded Backdoor Function of Contec CMS8000 Firmware CISA released a fact sheet, Contec CMS8000 Contains a Backdoor , detailing an analysis of three firmware package versions of the Contec CMS8000, a patient monitor used by the U.S. Healthcare and Public Health (HPH) sector. Analysts discovered that an embedded backdoor function with a hard-coded IP address, CWE – 912: Hidden Functionality ( CVE-2025-0626 ), and functionality that enables patient data spillage, CWE – 359: Exposure of Private Person… | CISA |
| Jan 29, 2025 | NSA | Guidance | CSI: Content Credentials: Strengthening Multimedia Integrity in the Generative AI Era The ability to manipulate media is not new, but the accessibility, speed, and quality of these modifications today, powered by artificial intelligence (AI) and machine learning tools, have reached unprecedented levels and may not be caught by traditional verification methods. | ASD/ACSC, CCCS, NCSC-UK, NSA |
| Jan 28, 2025 | CISA | Alert | CISA Releases Seven Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-028-01 B&R Automation Runtime ICSA-25-028-02 Schneider Electric Power Logic ICSA-25-028-03 Rockwell Automation FactoryTalk ICSA-25-028-04 Rockwell Automation FactoryTalk View Site Edition ICSA-25-028-05 Rockwell Automation DataMosaix Private Cloud ICSA-25-028-06 Schneider Electric RemoteConnect and SCADAPack x70 Utilit… | CISA |
| Jan 28, 2025 | CERT-EU | Advisory | 2025-004: Critical Vulnerability in SonicWall Products An unauthenticated, remote attacker could exploit this vulnerability to execute arbitrary code on the affected appliance. Thevulnerability CVE-2025-23006,withaCVSSscoreof9.8,isadeserialisationofuntrusteddata vulnerability in the Appliance Management Console (AMC) and Central Management Console (CMC) of the SonicWall SMA 1000. | CERT-EU |
| Jan 28, 2025 | NCSC | Analysis Report | A method to assess 'forgivable' vs 'unforgivable' vulnerabilities In fact, the number of Common Vulnerabilities and Exposures (CVEs) in commodity technology continues to rise. While there are a number of factors that are driving the increasing numbers, the NCSC expect this trend to continue unless interventions are made. | CISA, NCSC-UK |
| Jan 27, 2025 | FBI | Alert | Mail Theft-Related Check Fraud is on the Rise Suspicious Activity Reports related to check fraud have nearly doubled from 2021 to 2023. 1 Fraudsters take advantage of regulations requiring financial institutions to make check funds available within specified timeframes, which is often too short a window for the consumer or financial institutions to identify and stop the fraud. | FBI |
| Jan 23, 2025 | CISA | Alert | CISA Releases Six Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-023-01 mySCADA myPRO Manager ICSA-25-023-02 Hitachi Energy RTU500 Series Product ICSA-25-023-03 Schneider Electric EVlink Home Smart and Schneider Charge ICSA-25-023-04 Schneider Electric Easergy Studio ICSA-25-023-05 Schneider Electric EcoStruxure Power Build Rapsody This product is provided subject to this Notificati… | CISA |
| Jan 23, 2025 | FBI | Alert | North Korean IT Workers Conducting Data Extortion The Federal Bureau of Investigation (FBI) is providing an update to previously shared guidance regarding Democratic People's Republic of Korea (North Korea) Information Technology (IT) workers to raise public awareness of their increasingly malicious activity, which has recently included data extortion. | FBI |
| Jan 22, 2025 | CISA | Alert | CISA and FBI Release Advisory on How Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications This advisory was crafted in response to exploitation of vulnerabilities— CVE-2024-8963 , an administrative bypass vulnerability; CVE-2024-9379 , a SQL injection vulnerability; and CVE-2024-8190 and CVE-2024-9380 , remote code execution vulnerabilities—in Ivanti Cloud Service Appliances (CSA) in September 2024. | CISA, CSA, FBI |
| Jan 22, 2025 | CISA | Advisory | Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications For more information on mitigating CVE -2025-0282 and CVE-2025-0283, see Ivanti Releases Security Updates for Connect Secure, Policy Secure, and ZTA Gateways . Summary The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) are releasing this joint Cybersecurity Advisory in response to exploitation in September 2024 of vulnerabilities in Ivanti Cloud Service Appliances (CSA): CVE-2024-8963 , an admini… | CISA, FBI |
| Jan 22, 2025 | FBI | Alert | Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications For more information on mitigating CVE-20250282 and CVE-2025-0283, see Ivanti Releases Security Updates for Connect Secure, Policy Secure, and The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) are releasing this joint Cybersecurity Advisory in response to exploitation in September 2024 of vulnerabilities in Ivanti Cloud Service Appliances (CSA): CVE-2024-8963, an administrative bypass vulnerabil… | CISA, FBI |
| Jan 21, 2025 | CISA | Alert | CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-021-01 Traffic Alert and Collision Avoidance System (TCAS) II ICSA-25-021-02 Siemens SIMATIC S7-1200 CPUs ICSA-25-021-03 ZF Roll Stability Support Plus (RSSPlus) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 17, 2025 | CISA | Alert | CISA and FBI Release Updated Guidance on Product Security Bad Practices This updated guidance incorporates public comments CISA received in response to a Request for Information, adding additional bad practices, context regarding memory-safe languages, clarifying timelines for patching Known Exploited Vulnerabilities (KEVs) , and other recommendations. | CISA, FBI |
| Jan 17, 2025 | FBI | Alert | Product Security Bad Practices Feedback incorporated from the 78 public comments CISA received in response to our Request for insecure or outdated cryptographic functions, hardcoded credentials, and product support actions to prevent SQL injection vulnerabilities. Updates actions to prevent command injection (MFA) specific to operational technology support phishing-resistant MFA. | CISA, FBI |
| Jan 16, 2025 | CISA | Alert | CISA Releases Twelve Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-016-01 Siemens Mendix LDAP ICSA-25-016-02 Siemens Industrial Edge Management ICSA-25-016-03 Siemens Siveillance Video Camera ICSA-25-016-04 Siemens SIPROTEC 5 Products ICSA-25-016-05 Fuji Electric Alpha5 SMART ICSA-25-016-06 Hitachi Energy FOX61x, FOXCST, and FOXMAN-UN Products ICSA-25-016-07 Hitachi Energy FOX61x Prod… | CISA |
| Jan 16, 2025 | CISA | Alert | CISA and Partners Release Call to Action to Close the National Software Understanding Gap Today, CISA—in partnership with the Defense Advanced Research Projects Agency (DARPA), the Office of the Under Secretary of Defense for Research and Engineering (OUSD R&E), and the National Security Agency (NSA)—published Closing the Software Understanding Gap . This report urgently implores the U.S. government to take decisive and coordinated action. Software understanding refers to assessing software-controlled systems across all conditions. | CISA, DARPA, NSA |
| Jan 16, 2025 | NSA | Guidance | CSI: Closing the Software Understanding Gap Software is embedded in countless systems responsible for providing U.S. critical infrastructure services that Americans rely on as well as systems providing national security capabilities. To maintain confidence in national security and critical infrastructure systems, mission owners and operators should be able to trust the system is functional, safe, and secure. | CISA, DOE, FBI, NSA |
| Jan 16, 2025 | FBI | Alert | Beware of Charitable Fraud Related to Mass Casualty and Disaster Events The FBI is issuing this Public Service Announcement to warn the public that scammers exploit mass casualty events and disasters, such as the New Year's Day terrorist attack in New Orleans and the ongoing wildfires in Los Angeles, to commit fraud by soliciting fake charitable donations to support victims or their families. | FBI |
| Jan 15, 2025 | CERT-EU | Advisory | 2025-002: Multiple Vulnerabilities in Microsoft Products The patches include fixes for critical and important-severity issues that could allow attackers to gain unauthorised access, execute arbitrary code, or elevate privileges. Three vulnerabilities were already being exploited The eight (8) zero-day vulnerabilities resolved in this update are: elevation of privilege vulnerabilities in Windows Hyper-V that were exploited in attacks to gain SYSTEM privileges on Windows devices. | CERT-EU |
| Jan 15, 2025 | CISA | Alert | CISA Releases Microsoft Expanded Cloud Logs Implementation Playbook This step-by-step guide enables technical personnel to better detect and defend against advanced intrusion techniques by operationalizing expanded cloud logs. The playbook details analytical methodologies tied to using these logs. | CISA |
| Jan 15, 2025 | CERT-EU | Advisory | 2025-003: Critical Vulnerabilities in Fortinet Products On January 14, Fortinet released and updated several security advisories addressing multiple vulnerabilities ranging from low to critical severity [1]. At least one critical vulnerability is known to be exploited in the wild. It recommended updating as soon as possible, and if not possible, at least applying mitigations. in Node. | CERT-EU |
| Jan 14, 2025 | CISA | Alert | CISA Releases the JCDC AI Cybersecurity Collaboration Playbook and Fact Sheet The playbook provides voluntary information-sharing processes that, if adopted, can help protect organizations from emerging AI threats. Facilitates collaboration between federal agencies, private industry, international partners, and other stakeholders to raise awareness of AI cybersecurity risks and improve the resilience of AI systems. | CISA |
| Jan 14, 2025 | CISA | Alert | CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-014-01 Hitachi Energy FOXMAN-UN ICSA-25-014-02 Schneider Electric Vijeo Designer ICSA-25-014-03 Schneider Electric EcoStruxure ICSA-25-014-04 Belledonne Communications Linphone-Desktop This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 14, 2025 | CISA | Alert | Fortinet Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 14, 2025 | CISA | Alert | Ivanti Releases Security Updates for Multiple Products Ivanti released security updates to address vulnerabilities in Ivanti Avalanche, Ivanti Application Control Engine, and Ivanti EPM. Ivanti Application Control Engine This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 14, 2025 | CISA | Alert | Microsoft Releases January 2025 Security Updates Microsoft released security updates to address vulnerabilities in multiple Microsoft products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Microsoft Security Update Guide for January This product is provided subject to this Notification and this Privacy & Use policy. | CISA, JPCERT/CC |
| Jan 14, 2025 | CISA | Alert | Adobe Releases Security Updates for Multiple Products A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. Adobe Product Security Updates for January This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 13, 2025 | CISA | Alert | CISA and US and International Partners Publish Guidance on Priority Considerations in Product Selection for OT Owners and Operators As part of CISA’s Secure by Demand series, this guidance focuses on helping customers identify manufacturers dedicated to continuous improvement and achieving a better cost balance, as well as how Operational Technology (OT) owners and operators should integrate secure by design elements into their procurement process. Critical infrastructure and industrial control systems are prime targets for cyberattacks. | CISA, FBI, NSA |
| Jan 13, 2025 | FBI | Alert | Secure by Demand: Priority Considerations for Operational Technology Owners and Operators When Selecting Digital Products Many OT products are not designed and developed with Secure by Design principles1 and commonly have weaknesses, such as weak authentication, known software vulnerabilities, limited logging, insecure default settings and passwords, and insecure legacy protocols. Cyber threat actors can easily exploit these weaknesses across multiple victims to gain access to control systems. | ASD/ACSC, BSI, CCCS, CISA, EPA, FBI, NCSC-NL, NCSC-NZ, NCSC-UK, NSA, TSA |
| Jan 13, 2025 | FBI | Alert | Threat of Copycat Attacks after ISIS-Inspired Vehicle Attack in New Orleans The Federal Bureau of Investigation (FBI) and Department of Homeland Security (DHS) are issuing this Public Service Announcement to highlight a potential public safety threat from violent extremists in response to the New Year’s Day attack in New Orleans, Louisiana. | DHS, FBI |
| Jan 10, 2025 | CISA | Alert | CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-010-01 Schneider Electric PowerChute Serial Shutdown ICSA-25-010-02 Schneider Electric Harmony HMI and Pro-face HMI Products ICSA-25-010-03 Delta Electronics DRASimuCAD ICSA-24-345-06 Rockwell Automation Arena (Update A) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 10, 2025 | CISA | Alert | CISA Releases the Cybersecurity Performance Goals Adoption Report As the nation’s cyber defense agency, one of CISA’s most important roles is to understand the challenges facing organizations, both large and small, in order to make progress on the shared goal of reducing cyber risk to the critical infrastructure Americans rely on every day. | CISA, NSM |
| Jan 8, 2025 | CISA | Alert | Ivanti Releases Security Updates for Connect Secure, Policy Secure, and ZTA Gateways (Updated April 8, 2025) CISA updated these mitigations based on identification of a new malware variant called RESURGE that could undermine the effectiveness of the mitigations previously provided. For more information on RESURGE, see MAR-25993211.R1.V1.CLEAR and CISA Releases Malware Analysis Report on RESURGE Malware Associated with Ivanti Connect Secure . A cyber threat actor could exploit CVE-2025-0282 to take control of an affected system. | CISA |
| Jan 8, 2025 | CISA | Alert | CISA Adds One Vulnerability to the KEV Catalog Reducing the Significant Risk of Known Exploited Vulnerabilities The impact of cybersecurity intrusions that leverage vulnerabilities in information technology and operational technology products threaten the public sector, the private sector, and ultimately the American people’s security and privacy. In 2020, industry partners identified a total of 18,358 new cybersecurity vulnerabilities, or Common Vulnerabilities and Exposures (CVEs). | CISA |
| Jan 7, 2025 | CISA | Alert | CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-007-01 ABB ASPECT-Enterprise, NEXUS, and MATRIX Series Products ICSA-25-007-02 Nedap Librix Ecoreader This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jan 6, 2025 | NSA | Analysis Report | CTR: DoD Microelectronics: Field Programmable Gate Array Security Guidance Cybersecurity Technical Report National Security Agency | Cybersecurity Technical Report DoD Microelectronics: FPGA Security Guidance January 2025 1.0 Initial Publication Disclaimer of warranties and endorsement The information and opinions contained in this document are provided "as is" and without any warranties or guarantees. | NSA |