CyberzSOC

CISA, FBI, NSA, NCSC, ASD/ACSC & NCSC Cyber Intelligence Feed
‹ April 2025 ›
32 publications — sorted newest first
Date Source Type Title Author
Apr 30, 2025 FBI Alert Emerging Discount Medical Insurance Scams Discount medical insurance scams involve misleading or fraudulent offers for medical insurance plans that promise reduced rates on legitimate medical insurance but do not provide any actual medical insurance coverage, resulting in millions of dollars in losses annually. FBI
Apr 29, 2025 CISA Alert CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-119-01 Rockwell Automation ThinManager ICSA-25-119-02 Delta Electronics ISPSoft ICSA-25-105-05 Lantronix XPort (Update A) This product is provided subject to this Notification and this Privacy & Use policy. CISA
Apr 29, 2025 NSA Advisory Info Sheet: Selecting a Protective DNS Service (April 2025 Update) Security Infrastructure Cybersecurity Information Selecting a Protective DNS Service The Domain Name System (DNS) is central to the operation of modern networks, translating human-readable domain names into machine-usable Internet Protocol (IP) addresses. DNS makes navigating to a website, sending an email, or making a secure shell connection easier, and is a key component of the Internet's resilience. CISA, NCSC-UK, NSA
Apr 29, 2025 FBI Alert Threat Actors Use Swatting to Target Victims Nationwide The Federal Bureau of Investigation (FBI) is aware of multiple recent swatting incidents. This Public Service Announcement (PSA) is intended to provide the public with information about what swatting is, how to take protective steps against swatting, and how FBI
Apr 29, 2025 FBI Alert Phishing Domains Associated with LabHost PhaaS Platform Users 29 APR 2025 The following information is being provided by the FBI, with no guarantees or warranties, for potential use at the sole discretion of recipients to protect against cyber threats. This data is provided in order to help cyber security professionals and system administrators to guard against the persistent malicious actions of cyber actors. This FLASH was coordinated with DHS/CISA. WE NEED YOUR HELP! FBI
Apr 24, 2025 FBI Alert Cybercriminals Impersonating Employee Self-Service Websites to Steal Victim Information and Funds The FBI is warning the public that cyber criminals are targeting users of employee self-service websites owned by companies and government services. The cyber criminals are using search engine advertisements to impersonate legitimate websites and steal victim information and funds. FBI
Apr 24, 2025 FBI Alert FBI Seeking Tips about PRC Targeting of U.S. Telecommunications telecommunications companies, especially information about specific individuals behind the campaign. Investigation into these actors and their activity revealed a broad and significant cyber campaign to leverage access into these networks to target victims on a global scale. FBI
Apr 24, 2025 CISA Alert CISA Releases Seven Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-114-01 Schneider Electric Modicon Controllers ICSA-25-114-02 ALBEDO Telecom Net.Time - PTP/NTP Clock ICSA-25-114-03 Vestel AC Charger ICSA-25-114-04 Nice Linear eMerge E3 ICSA-25-114-05 Johnson Controls Software House iSTAR Configuration Utility (ICU) Tool ICSA-25-114-06 Planet Technology Network Products ICSA-24-338-0… CISA
Apr 23, 2025 NSA Advisory Operational Technology Assurance Partnership: Smart Controller Security within National Security Systems Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product Cybersecurity Report Feedback: [email protected] Defense Industrial Base Inquiries and Cybersecurity Services: [email protected]. NSA
Apr 22, 2025 CISA Alert CISA Releases Five Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-112-01 Siemens TeleControl Server Basic SQL ICSA-25-112-02 Siemens TeleControl Server Basic ICSA-25-112-03 Schneider Electric Wiser Home Controller WHC-5918A ICSA-25-035-04 Schneider Electric Modicon M580 PLCs, BMENOR2200H and EVLink Pro AC (Update A) This product is provided subject to this Notification and this Priva… CISA
Apr 18, 2025 FBI Alert FBI Warns of Scammers Impersonating the IC3 Complainants report initial contact from the scammers can vary. Some individuals received an email or a phone call, while others were approached via social media or forums. Almost all complainants indicated the scammers claimed to have recovered the victim's lost funds or offered to assist in recovering funds. FBI
Apr 17, 2025 CISA Alert CISA Releases Six Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-107-01 Schneider Electric Trio Q Licensed Data Radio ICSA-25-107-02 Schneider Electric Sage Series ICSA-25-107-03 Schneider Electric ConneXium Network Manager ICSA-25-107-04 Yokogawa Recorder Products ICSA-24-326-04 Schneider Electric Modicon M340, MC80, and Momentum Unity M1E (Update A) ICSA-25-058-01 Schneider Electr… CISA
Apr 16, 2025 CISA Alert CISA Releases Guidance on Credential Risks Associated with Potential Legacy Oracle Cloud Compromise CISA is aware of public reporting regarding potential unauthorized access to a legacy Oracle cloud environment. While the scope and impact remains unconfirmed, the nature of the reported activity presents potential risk to organizations and individuals, particularly where credential material may be exposed, reused across separate, unaffiliated systems, or embedded (i.e. CISA
Apr 15, 2025 CISA Alert CISA Releases Nine Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-105-01 Siemens Mendix Runtime ICSA-25-105-02 Siemens Industrial Edge Device Kit ICSA-25-105-03 Siemens SIMOCODE, SIMATIC, SIPLUS, SIDOOR, SIWAREX ICSA-25-105-04 Growatt Cloud Applications ICSA-25-105-05 Lantronix Xport ICSA-25-105-06 National Instruments LabVIEW ICSA-25-105-07 Delta Electronics COMMGR ICSA-25-105-08 AB… CISA
Apr 11, 2025 CISA Alert Fortinet Releases Advisory on New Post-Exploitation Technique for Known Vulnerabilities Fortinet is aware of a threat actor creating a malicious file from previously exploited Fortinet vulnerabilities (CVE-2024-21762, CVE-2023-27997, and CVE-2022-42475) within FortiGate products. This malicious file could enable read-only access to files on the device's file system, which may include configurations. CISA
Apr 11, 2025 CERT-EU Advisory 2025-017: Critical Vulnerabilitites in Microsoft Products It is recommended updating as soon as possible, prioritising critical devices and public facing This advisory describes some notable vulnerabilities addressed by the April 2025 Patch Tuesday. The vulnerability CVE-2025-29824, with a CVSS score of 7.8, is a user-after-free vulnerability in the Windows Common Log File System (CLFS) that can be exploited by attackers to elevate their privileges to SYSTEM on previously compromised Windows machines. CERT-EU
Apr 10, 2025 CISA Alert CISA Releases Ten Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-100-01 Siemens License Server ICSA-25-100-02 Siemens SIDIS Prime ICSA-25-100-03 Siemens Solid Edge ICSA-25-100-04 Siemens Industrial Edge Devices ICSA-25-100-05 Siemens Insights Hub Private Cloud ICSA-25-100-06 Siemens SENTRON 7KT PAC1260 Data Manager ICSA-25-100-07 Rockwell Automation Arena ICSA-25-100-08 Subnet Solut… CISA
Apr 9, 2025 NSA Alert BADBAZAAR and MOONSHINE: Spyware Targeting Uyghur, Taiwanese, and Tibetan Groups and Civil Society Actors This advisory includes two case studies detailing techniques used by malicious cyber actors using spyware known as BADBAZAAR and MOONSHINE to target data on mobile devices including smartphones that could be of interest to the Chinese state. ASD/ACSC, CCCS, FBI, NCSC-NZ,
NCSC-UK, NSA
Apr 9, 2025 NSA Advisory CSA: BADBAZAAR and MOONSHINE: Technical analysis and mitigations BADBAZAAR and MOONSHINE: Technical With support from the UK Cyber League, this advisory has been jointly produced by the National Cyber Security Centre (NCSC UK) and international partners: > The Australian Cyber Security Centre, part of the Australian Signals > The Canadian Centre for Cyber Security, part of the Communications > The German Federal Intelligence Service > The German Federal Office for the Protection of the Constitution > The New Z… ASD/ACSC, CCCS, FBI, NCSC-NZ,
NCSC-UK, NSA
Apr 9, 2025 JPCERT/CC Alert Microsoft Releases April 2025 Security Updates Microsoft has released April 2025 Security Updates to address the vulnerabilities in their products. Remote attackers leveraging these vulnerabilities may be able to execute arbitrary code. According to Microsoft, among the vulnerabilities, the following vulnerability have been confirmed to be exploited in the wild. JPCERT/CC
Apr 4, 2025 CISA Alert Ivanti Releases Security Updates for Connect Secure, Policy Secure & ZTA Gateways Vulnerability (CVE-2025-22457) A cyber threat actor could exploit CVE-2025-22457 to take control of an affected system. CISA has added CVE-2025-22457 to its Known Exploited Vulnerabilities Catalog . See the following resources for more guidance: April Security Update | Ivanti Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457) | Google Cloud Blog Conduct threat hunting actions: Run an external Integrity Checker T… CISA
Apr 4, 2025 CISA Alert CISA Adds One Vulnerability to the KEV Catalog Reducing the Significant Risk of Known Exploited Vulnerabilities The impact of cybersecurity intrusions that leverage vulnerabilities in information technology and operational technology products threaten the public sector, the private sector, and ultimately the American people’s security and privacy. In 2020, industry partners identified a total of 18,358 new cybersecurity vulnerabilities, or Common Vulnerabilities and Exposures (CVEs). CISA
Apr 3, 2025 CISA Alert CISA Releases Five Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-093-01 Hitachi Energy RTU500 Series ICSA-25-093-02 Hitachi Energy TRMTracker ICSA-25-093-03 ABB ACS880 Drives Containing CODESYS RTS ICSA-25-093-04 ABB Low Voltage DC Drives and Power Controllers CODESYS RTS This product is provided subject to this Notification and this Privacy & Use policy. CISA
Apr 3, 2025 CISA Alert NSA, CISA, FBI, and International Partners Release Cybersecurity Advisory on “Fast Flux,” a National Security Threat Today, CISA—in partnership with the National Security Agency (NSA), Federal Bureau of Investigation (FBI), Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), Canadian Centre for Cyber Security (CCCS), and New Zealand’s National Cyber Security Centre (NCSC-NZ)—released joint Cybersecurity Advisory Fast Flux: A National Security Threat (PDF, 841 KB). ASD/ACSC, CCCS, CISA, FBI,
NCSC-NZ, NSA
Apr 3, 2025 CISA Advisory Fast Flux: A National Security Threat The Protective Domain Name System (DNS) Resolver service allows the Cybersecurity and Infrastructure Security Agency (CISA) to detect and prevent cyberattacks and threats targeting federal civilian executive branch (FCEB) agency networks. Protective DNS also offers a range of capabilities to safeguard assets that may otherwise be challenging to protect such as cloud, mobile, and nomadic devices. ASD/ACSC, CCCS, CISA, FBI,
NCSC-NZ, NSA
Apr 3, 2025 FBI Alert Fast Flux: A National Security Threat Malicious cyber actors, including cybercriminals and nation-state actors, use fast flux to obfuscate the locations of malicious servers by rapidly changing Domain Name System (DNS) records. Additionally, they can create resilient, highly available command and control (C2) infrastructure, concealing their subsequent malicious operations. ASD/ACSC, CCCS, CISA, FBI,
NCSC-NZ, NSA
Apr 3, 2025 NCSC Guidance New feature: View and manage Early Warning findings in MyNCSC Early Warning alerts and the CSV attachment will continue to be sent via email, but now this same data, and more, can be viewed within the MyNCSC platform. View Early Warning findings alongside other findings you may already receive See other IP addresses in your portfolio affected by the same finding See a summary of key dates and actions affecting each Early Warning finding, including when it was found, what action was taken and by whom Find gu… NCSC-UK
Apr 3, 2025 CERT-EU Advisory 2025-016: Critical Vulnerability in Ivanti Products The vulnerability has been fixed in the February 2025 release and was initially identified as a product bug. CERT-EU recommends upgrading to a supported and fixed version of Ivanti products as soon as possible. CERT-EU
Apr 3, 2025 CERT-EU Advisory 2025-015: Critical vulnerability in CrushFTP It is recommended updating affected server as soon as possible [1,2]. Proof of concepts are available, and the vulnerability is being exploited in the wild. CERT-EU
Apr 3, 2025 CERT-EU Advisory 2025-014: Critical Vulnerability in Apache Tomcat It is recommended updating the affected assets to a fixed version of Apache Tomcat. ThevulnerabilityCVE-2025-24813,withaCVSSscoreof9.8,liesintheApacheTomcat’spartial PUT feature. CERT-EU
Apr 2, 2025 FBI Alert Criminal Actors Steal U.S. Taxpayer Identity to File False Tax Returns and Claim Refunds The IRS recommends establishing an Identity Protection Personal Identification Number (IP PIN), a six-digit number assigned to taxpayers to help prevent the misuse of a taxpayers' Social Security number on fraudulent federal income tax returns. Enrollment in the IP PIN program starts by establishing an online account at irs.gov . FBI
Apr 1, 2025 CISA Alert CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-091-01 Rockwell Automation Lifecycle Services with Veeam Backup and Replication ICSA-24-331-04 Hitachi Energy MicroSCADA Pro/X SYS600 (Update A) This product is provided subject to this Notification and this Privacy & Use policy. CISA