CyberzSOC

CISA, FBI, NSA, NCSC, ASD/ACSC & NCSC Cyber Intelligence Feed
‹ May 2025 ›
36 publications — sorted newest first
Date Source Type Title Author
May 29, 2025 CISA Alert CISA Releases Five Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-148-02 Siemens SiPass Integrated ICSA-25-148-03 Consilium Safety CS5000 Fire Panel ICSA-25-148-04 Instantel Micromate ICSMA-25-148-01 Santesoft Sante DICOM Viewer Pro This product is provided subject to this Notification and this Privacy & Use policy. CISA
May 29, 2025 FBI Alert Infrastructure Used to Manage Domains Related to Cryptocurrency Investment Fraud Scams Between October 2023 and April 2025 29 May 2025 The following information is being provided by the FBI, with no guarantees or warranties, for potential use at the sole discretion of recipients to protect against cyber threats. This data is provided in order to help cyber security professionals and system administrators to guard against the persistent malicious actions of cyber actors. This FLASH was coordinated with DHS/CISA. WE NEED YOUR HELP! FBI
May 27, 2025 CISA Alert CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-146-01 Johnson Controls iSTAR Configuration Utility (ICU) Tool This product is provided subject to this Notification and this Privacy & Use policy. CISA
May 27, 2025 CISA Alert New Guidance for SIEM and SOAR Implementation Today, CISA, in collaboration with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and other international and U.S. partners, released new guidance for organizations seeking to procure Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms. CISA
May 27, 2025 NSA Advisory Priority Logs For SIEM Ingestion Practitioner Guidance The authors would like to acknowledge the industry partners that contributed to this publication. In this publication, the authoring agencies provide cyber security practitioners with detailed recommendations on the logs that should be prioritised for ingestion by a Security Information and Event Management (SIEM) platform. NSA
May 27, 2025 NSA Advisory Implementing SIEM and SOAR Platforms: Practitioners Guidance 4. Best practice principles for implementing a SIEM and/or SOAR 12 This publication provides high-level guidance for cyber security practitioners on Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms. ASD/ACSC, NSA
May 23, 2025 FBI Alert Silent Ransom Group Targeting Law Firms 23 May 2025 The following information is being provided by the FBI, with no guarantees or warranties, for potential use at the sole discretion of recipients to protect against cyber threats. This data is provided to help cyber security professionals and system administrators guard against the persistent malicious actions PIN Number of cyber actors. This PIN was coordinated with DHS/CISA. FBI
May 22, 2025 CISA Alert Advisory Update on Cyber Threat Activity Targeting Commvault’s SaaS Cloud Application (Metallic) There is no singular, authoritative, recognized way to architect an Identity, Credential, and Access Management (ICAM) capability across an enterprise, which results in many U.S. government agencies addressing this critical capability from different directions with different priorities. CISA
May 22, 2025 CISA Alert CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-142-01 Lantronix Device Installer ICSA-25-142-02 Rockwell Automation FactoryTalk Historian ThingWorx This product is provided subject to this Notification and this Privacy & Use policy. CISA
May 22, 2025 CISA Alert New Best Practices Guide for Securing AI Data Released This information sheet highlights the critical role of data security in ensuring the accuracy, integrity, and trustworthiness of AI outcomes. It outlines key risks that may arise from data security and integrity issues across all phases of the AI lifecycle, from development and testing to deployment and operation. CISA
May 22, 2025 NSA Guidance CSI: AI Data Security: Best Practices for Securing Data Used to Train & Operate AI Systems Joint Cybersecurity Information This Cybersecurity Information Sheet (CSI) provides essential guidance on securing data used in artificial intelligence (AI) and machine learning (ML) systems. It also highlights the importance of data security in ensuring the accuracy and integrity of AI outcomes and outlines potential risks arising from data integrity issues in various stages of AI development and deployment. ASD/ACSC, CISA, FBI, NCSC-NZ,
NCSC-UK, NSA
May 22, 2025 FBI Alert AI Data Security Joint Cybersecurity Information Best Practices for Securing Data Used to Train & Operate AI Systems This Cybersecurity Information Sheet (CSI) provides essential guidance on securing data used in artificial intelligence (AI) and machine learning (ML) systems. ASD/ACSC, CISA, FBI, NCSC-NZ,
NCSC-UK, NSA
May 21, 2025 CISA Alert Threat Actors Target U.S. Critical Infrastructure with LummaC2 Malware Critical Infrastructure Sectors . This advisory details the tactics, techniques, and procedures, and indicators of compromise (IOCs) linked to threat actors deploying LummaC2 malware. This malware poses a serious threat, capable of infiltrating networks and exfiltrating sensitive information, to vulnerable individuals’ and organizations’ computer networks across U.S. critical infrastructure sectors. CISA
May 21, 2025 CISA Alert Russian GRU Cyber Actors Targeting Western Logistics Entities and Tech Companies and international partners released a joint Cybersecurity Advisory, Russian GRU Targeting Western Logistics Entities and Technology Companies . This advisory details a Russian state-sponsored cyber espionage-oriented campaign targeting technology companies and logistics entities, including those involved in the coordination, transport, and delivery of foreign assistance to Ukraine. CISA
May 21, 2025 CISA Advisory Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations CISA and partners warn that threat actors are deploying LummaC2 infostealer malware to exfiltrate credentials, financial information, and sensitive data from organizations. LummaC2 is typically distributed through phishing, malvertising, and trojanized software downloads. CISA, FBI
May 21, 2025 NSA Advisory Russian GRU Targeting Western Logistics Entities and Technology Companies Executive Summary This joint cybersecurity advisory (CSA) highlights a Russian state-sponsored cyber campaign targeting Western logistics entities and technology companies. This includes those involved in the coordination, transport, and delivery of foreign assistance to Ukraine. ASD/ACSC, CCCS, CISA, FBI,
NCSC-UK, NSA, USCC
May 21, 2025 FBI Alert Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations LummaC2 malware is able to infiltrate victim computer networks and exfiltrate sensitive information, threatening vulnerable individuals’ and organizations’ computer networks across multiple U.S. critical infrastructure sectors. According to FBI information and trusted third-party reporting, this activity has been observed as recently as May 2025. CISA, FBI
May 21, 2025 FBI Alert Cybercriminal Services Target End-of-Life Routers to Launch Attacks and Hide Their Activities FBI
May 21, 2025 NSA Alert Russian GRU Targeting Western Logistics Entities and Technology Companies This joint cybersecurity advisory (CSA) highlights a Russian state-sponsored cyber those involved in the coordination, transport, and delivery of foreign assistance to Ukraine. Since 2022, Western logistics entities and IT companies have faced an elevated risk of targeting by the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (85th GTsSS), military unit 26165—tracked in the cybersecurity community under… ANSSI, ASD/ACSC, BSI, CCCS,
DC3, DDIS, EFIS, FBI,
MIVD, NCSC-UK, NSA, NUKIB,
SKW, USCC
May 20, 2025 CISA Alert CISA Releases Thirteen Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-140-01 ABUP IoT Cloud Platform ICSA-25-140-02 National Instruments Circuit Design Suite ICSA-25-140-03 Danfoss AK-SM 8xxA Series ICSA-25-140-04 Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric Products ICSA-25-140-05 Siemens Siveillance Video ICSA-25-140-06 Schneider Electric PrismaSeT Active - Wir… CISA
May 20, 2025 NCSC Guidance Decommissioning assets How to retire digital assets (such as data, software, or hardware) from operation. This guidance describes why it’s important for organisations to decommission digital assets, and how to do so securely. For advice dealing specifically with decommissioning hardware, please refer to our guidance on discontinuing obsolete products or network devices. NCSC-UK
May 16, 2025 CERT-EU Advisory 2025-018: Zero-Day Vulnerabilities in Ivanti EPMM An attacker could chain those vulnerabilities to achieve unauthenticated remote code execution on the vulnerable device. These vulnerabilities have been exploited in a [New] The analysis conducted by WatchTowr [3] provides significantly more information than the advisory issued by Ivanti in two key aspects: that they are related to third-party libraries. CERT-EU
May 15, 2025 CISA Alert CISA Releases Twenty-Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-135-01 Siemens RUGGEDCOM APE1808 Devices ICSA-25-135-02 Siemens INTRALOG WMS ICSA-25-135-03 Siemens BACnet ATEC Devices ICSA-25-135-05 Siemens SIPROTEC and SICAM ICSA-25-135-06 Siemens Teamcenter Visualization ICSA-25-135-07 Siemens IPC RS-828A ICSA-25-135-08 Siemens VersiCharge AC Series EV Chargers ICSA-25-135-09 Sie… CISA
May 15, 2025 FBI Alert Senior U.S. Officials Impersonated in Malicious Messaging Campaign Since April 2025, malicious actors have impersonated senior U.S. officials to target individuals, many of whom are current or former senior U.S. federal or state government officials and their contacts. If you receive a message claiming to be from a senior U.S. official, do not assume it is authentic. CISA, FBI
May 14, 2025 JPCERT/CC Alert Microsoft Releases May 2025 Security Updates Microsoft has released May 2025 Security Updates to address the vulnerabilities in their products. Remote attackers leveraging these vulnerabilities may be able to execute arbitrary code. According to Microsoft, among the vulnerabilities, the following vulnerability have been confirmed to be exploited in the wild. JPCERT/CC
May 13, 2025 FBI Alert Impersonation Scheme Targeting Middle Eastern Students in the United States The FBI is warning the public about a fraud scheme targeting foreign individuals lawfully residing in the United States on valid student visas. Criminal scammers impersonate US and foreign government officials claiming there is an issue with the student's immigration status and exploit this for financial gain. Thus far, we are aware scammers have targeted students from the United Arab Emirates (UAE), Saudi Arabia, Qatar, and Jordan. FBI
May 13, 2025 CERT-EU Advisory 2025-019: Critical Vulnerabilities in Fortinet Products The vulnerability CVE-2025-32756 [1], with a CVSS score of 9.6, is a stack-based overflow vulnerability in FortiFone, FortiVoice, FortiNDR, and FortiMail that could allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests. CERT-EU
May 12, 2025 CISA Alert Update to How CISA Shares Cyber-Related Alerts and Notifications Starting May 12 , CISA is changing how we announce cybersecurity updates and the release of new guidance. These announcements will only be shared through CISA social media platforms and email and will no longer be listed on our Cybersecurity Alerts & Advisories webpage . We greatly appreciate stakeholder feedback which played a part in this change and thank you for staying connected with CISA. CISA
May 8, 2025 CISA Alert CISA Releases Five Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-128-01 Horner Automation Cscape ICSA-25-128-02 Hitachi Energy RTU500 series ICSA-25-128-03 Mitsubishi Electric CC-Link IE TSN ICSA-25-093-01 Hitachi Energy RTU500 Series (Update A) ICSMA-25-128-01 Pixmeo OsiriX MD This product is provided subject to this Notification and this Privacy & Use policy. CISA
May 7, 2025 NCSC Guidance Software Security Code of Practice - Assurance Principles and Claims (APCs) Helps vendors measure how well they meet the Software Security Code of Practice, and suggests remedial actions should they fall short. This document allows technical staff to self-assess their own software practices against the Software Security Code of Practice, a set of outcomes that – if met – means the vendor can claim that their software has achieved a baseline of software security and resilience. NCSC-UK
May 7, 2025 NCSC Analysis Report Impact of AI on cyber threat from now to 2027 An NCSC assessment highlighting the impacts on cyber threat from AI developments NCSC Assessment (NCSC-A) is the authoritative voice on the cyber threat to the UK. We combine source information – classified intelligence, industry knowledge, academic material and open source – to provide independent key judgements that inform policy decision making and improve UK cyber security. NCSC-UK
May 7, 2025 FBI Alert Cybercriminal Proxy Services Exploiting End-of-Life Routers When a hardware device is end of life, the manufacturer no longer sells the product and is not actively supporting the hardware, which also means they are no longer releasing software updates or security patches for the device. Routers dated 2010 or earlier likely no longer receive software updates issued by the manufacturer and could be compromised by cyber actors exploiting known vulnerabilities. FBI
May 6, 2025 FBI Alert Primary Mitigations to Reduce Cyber Threats to Operational Technology The authoring organizations urge critical infrastructure entities to review and act now to improve their cybersecurity posture against cyber threat activities specifically and intentionally targeting internet connected OT and ICS. The authoring organizations recommend critical infrastructure asset owners and operators implement the following mitigations1 to defend against OT cyber threats. internet. CISA, DOE, EPA, FBI
May 6, 2025 CISA Alert Unsophisticated Cyber Actor(s) Targeting Operational Technology critical Infrastructure sectors (Oil and Natural Gas), specifically in Energy and Transportation Systems. Although these activities often include basic and elementary intrusion techniques, the presence of poor cyber hygiene and exposed assets can escalate these threats, leading to significant consequences such as defacement, configuration changes, operational disruptions and, in severe cases, physical damage. CISA
May 6, 2025 CISA Alert CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-126-01 Optigo Networks ONS NC600 ICSA-25-126-02 Milesight UG65-868M-EA ICSA-25-126-03 BrightSign Players This product is provided subject to this Notification and this Privacy & Use policy. CISA
May 1, 2025 CISA Alert CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-121-01 KUNBUS GmbH Revolution Pi ICSMA-25-121-01 MicroDicom DICOM Viewer This product is provided subject to this Notification and this Privacy & Use policy. CISA