| Date | Source | Type | Title | Author |
|---|---|---|---|---|
| May 29, 2025 | CISA | Alert | CISA Releases Five Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-148-02 Siemens SiPass Integrated ICSA-25-148-03 Consilium Safety CS5000 Fire Panel ICSA-25-148-04 Instantel Micromate ICSMA-25-148-01 Santesoft Sante DICOM Viewer Pro This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| May 29, 2025 | FBI | Alert | Infrastructure Used to Manage Domains Related to Cryptocurrency Investment Fraud Scams Between October 2023 and April 2025 29 May 2025 The following information is being provided by the FBI, with no guarantees or warranties, for potential use at the sole discretion of recipients to protect against cyber threats. This data is provided in order to help cyber security professionals and system administrators to guard against the persistent malicious actions of cyber actors. This FLASH was coordinated with DHS/CISA. WE NEED YOUR HELP! | FBI |
| May 27, 2025 | CISA | Alert | CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-146-01 Johnson Controls iSTAR Configuration Utility (ICU) Tool This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| May 27, 2025 | CISA | Alert | New Guidance for SIEM and SOAR Implementation Today, CISA, in collaboration with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and other international and U.S. partners, released new guidance for organizations seeking to procure Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms. | CISA |
| May 27, 2025 | NSA | Advisory | Priority Logs For SIEM Ingestion Practitioner Guidance The authors would like to acknowledge the industry partners that contributed to this publication. In this publication, the authoring agencies provide cyber security practitioners with detailed recommendations on the logs that should be prioritised for ingestion by a Security Information and Event Management (SIEM) platform. | NSA |
| May 27, 2025 | NSA | Advisory | Implementing SIEM and SOAR Platforms: Practitioners Guidance 4. Best practice principles for implementing a SIEM and/or SOAR 12 This publication provides high-level guidance for cyber security practitioners on Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms. | ASD/ACSC, NSA |
| May 23, 2025 | FBI | Alert | Silent Ransom Group Targeting Law Firms 23 May 2025 The following information is being provided by the FBI, with no guarantees or warranties, for potential use at the sole discretion of recipients to protect against cyber threats. This data is provided to help cyber security professionals and system administrators guard against the persistent malicious actions PIN Number of cyber actors. This PIN was coordinated with DHS/CISA. | FBI |
| May 22, 2025 | CISA | Alert | Advisory Update on Cyber Threat Activity Targeting Commvault’s SaaS Cloud Application (Metallic) There is no singular, authoritative, recognized way to architect an Identity, Credential, and Access Management (ICAM) capability across an enterprise, which results in many U.S. government agencies addressing this critical capability from different directions with different priorities. | CISA |
| May 22, 2025 | CISA | Alert | CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-142-01 Lantronix Device Installer ICSA-25-142-02 Rockwell Automation FactoryTalk Historian ThingWorx This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| May 22, 2025 | CISA | Alert | New Best Practices Guide for Securing AI Data Released This information sheet highlights the critical role of data security in ensuring the accuracy, integrity, and trustworthiness of AI outcomes. It outlines key risks that may arise from data security and integrity issues across all phases of the AI lifecycle, from development and testing to deployment and operation. | CISA |
| May 22, 2025 | NSA | Guidance | CSI: AI Data Security: Best Practices for Securing Data Used to Train & Operate AI Systems Joint Cybersecurity Information This Cybersecurity Information Sheet (CSI) provides essential guidance on securing data used in artificial intelligence (AI) and machine learning (ML) systems. It also highlights the importance of data security in ensuring the accuracy and integrity of AI outcomes and outlines potential risks arising from data integrity issues in various stages of AI development and deployment. | ASD/ACSC, CISA, FBI, NCSC-NZ, NCSC-UK, NSA |
| May 22, 2025 | FBI | Alert | AI Data Security Joint Cybersecurity Information Best Practices for Securing Data Used to Train & Operate AI Systems This Cybersecurity Information Sheet (CSI) provides essential guidance on securing data used in artificial intelligence (AI) and machine learning (ML) systems. | ASD/ACSC, CISA, FBI, NCSC-NZ, NCSC-UK, NSA |
| May 21, 2025 | CISA | Alert | Threat Actors Target U.S. Critical Infrastructure with LummaC2 Malware Critical Infrastructure Sectors . This advisory details the tactics, techniques, and procedures, and indicators of compromise (IOCs) linked to threat actors deploying LummaC2 malware. This malware poses a serious threat, capable of infiltrating networks and exfiltrating sensitive information, to vulnerable individuals’ and organizations’ computer networks across U.S. critical infrastructure sectors. | CISA |
| May 21, 2025 | CISA | Alert | Russian GRU Cyber Actors Targeting Western Logistics Entities and Tech Companies and international partners released a joint Cybersecurity Advisory, Russian GRU Targeting Western Logistics Entities and Technology Companies . This advisory details a Russian state-sponsored cyber espionage-oriented campaign targeting technology companies and logistics entities, including those involved in the coordination, transport, and delivery of foreign assistance to Ukraine. | CISA |
| May 21, 2025 | CISA | Advisory | Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations CISA and partners warn that threat actors are deploying LummaC2 infostealer malware to exfiltrate credentials, financial information, and sensitive data from organizations. LummaC2 is typically distributed through phishing, malvertising, and trojanized software downloads. | CISA, FBI |
| May 21, 2025 | NSA | Advisory | Russian GRU Targeting Western Logistics Entities and Technology Companies Executive Summary This joint cybersecurity advisory (CSA) highlights a Russian state-sponsored cyber campaign targeting Western logistics entities and technology companies. This includes those involved in the coordination, transport, and delivery of foreign assistance to Ukraine. | ASD/ACSC, CCCS, CISA, FBI, NCSC-UK, NSA, USCC |
| May 21, 2025 | FBI | Alert | Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations LummaC2 malware is able to infiltrate victim computer networks and exfiltrate sensitive information, threatening vulnerable individuals’ and organizations’ computer networks across multiple U.S. critical infrastructure sectors. According to FBI information and trusted third-party reporting, this activity has been observed as recently as May 2025. | CISA, FBI |
| May 21, 2025 | FBI | Alert | Cybercriminal Services Target End-of-Life Routers to Launch Attacks and Hide Their Activities | FBI |
| May 21, 2025 | NSA | Alert | Russian GRU Targeting Western Logistics Entities and Technology Companies This joint cybersecurity advisory (CSA) highlights a Russian state-sponsored cyber those involved in the coordination, transport, and delivery of foreign assistance to Ukraine. Since 2022, Western logistics entities and IT companies have faced an elevated risk of targeting by the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (85th GTsSS), military unit 26165—tracked in the cybersecurity community under… | ANSSI, ASD/ACSC, BSI, CCCS, DC3, DDIS, EFIS, FBI, MIVD, NCSC-UK, NSA, NUKIB, SKW, USCC |
| May 20, 2025 | CISA | Alert | CISA Releases Thirteen Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-140-01 ABUP IoT Cloud Platform ICSA-25-140-02 National Instruments Circuit Design Suite ICSA-25-140-03 Danfoss AK-SM 8xxA Series ICSA-25-140-04 Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric Products ICSA-25-140-05 Siemens Siveillance Video ICSA-25-140-06 Schneider Electric PrismaSeT Active - Wir… | CISA |
| May 20, 2025 | NCSC | Guidance | Decommissioning assets How to retire digital assets (such as data, software, or hardware) from operation. This guidance describes why it’s important for organisations to decommission digital assets, and how to do so securely. For advice dealing specifically with decommissioning hardware, please refer to our guidance on discontinuing obsolete products or network devices. | NCSC-UK |
| May 16, 2025 | CERT-EU | Advisory | 2025-018: Zero-Day Vulnerabilities in Ivanti EPMM An attacker could chain those vulnerabilities to achieve unauthenticated remote code execution on the vulnerable device. These vulnerabilities have been exploited in a [New] The analysis conducted by WatchTowr [3] provides significantly more information than the advisory issued by Ivanti in two key aspects: that they are related to third-party libraries. | CERT-EU |
| May 15, 2025 | CISA | Alert | CISA Releases Twenty-Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-135-01 Siemens RUGGEDCOM APE1808 Devices ICSA-25-135-02 Siemens INTRALOG WMS ICSA-25-135-03 Siemens BACnet ATEC Devices ICSA-25-135-05 Siemens SIPROTEC and SICAM ICSA-25-135-06 Siemens Teamcenter Visualization ICSA-25-135-07 Siemens IPC RS-828A ICSA-25-135-08 Siemens VersiCharge AC Series EV Chargers ICSA-25-135-09 Sie… | CISA |
| May 15, 2025 | FBI | Alert | Senior U.S. Officials Impersonated in Malicious Messaging Campaign Since April 2025, malicious actors have impersonated senior U.S. officials to target individuals, many of whom are current or former senior U.S. federal or state government officials and their contacts. If you receive a message claiming to be from a senior U.S. official, do not assume it is authentic. | CISA, FBI |
| May 14, 2025 | JPCERT/CC | Alert | Microsoft Releases May 2025 Security Updates Microsoft has released May 2025 Security Updates to address the vulnerabilities in their products. Remote attackers leveraging these vulnerabilities may be able to execute arbitrary code. According to Microsoft, among the vulnerabilities, the following vulnerability have been confirmed to be exploited in the wild. | JPCERT/CC |
| May 13, 2025 | FBI | Alert | Impersonation Scheme Targeting Middle Eastern Students in the United States The FBI is warning the public about a fraud scheme targeting foreign individuals lawfully residing in the United States on valid student visas. Criminal scammers impersonate US and foreign government officials claiming there is an issue with the student's immigration status and exploit this for financial gain. Thus far, we are aware scammers have targeted students from the United Arab Emirates (UAE), Saudi Arabia, Qatar, and Jordan. | FBI |
| May 13, 2025 | CERT-EU | Advisory | 2025-019: Critical Vulnerabilities in Fortinet Products The vulnerability CVE-2025-32756 [1], with a CVSS score of 9.6, is a stack-based overflow vulnerability in FortiFone, FortiVoice, FortiNDR, and FortiMail that could allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests. | CERT-EU |
| May 12, 2025 | CISA | Alert | Update to How CISA Shares Cyber-Related Alerts and Notifications Starting May 12 , CISA is changing how we announce cybersecurity updates and the release of new guidance. These announcements will only be shared through CISA social media platforms and email and will no longer be listed on our Cybersecurity Alerts & Advisories webpage . We greatly appreciate stakeholder feedback which played a part in this change and thank you for staying connected with CISA. | CISA |
| May 8, 2025 | CISA | Alert | CISA Releases Five Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-128-01 Horner Automation Cscape ICSA-25-128-02 Hitachi Energy RTU500 series ICSA-25-128-03 Mitsubishi Electric CC-Link IE TSN ICSA-25-093-01 Hitachi Energy RTU500 Series (Update A) ICSMA-25-128-01 Pixmeo OsiriX MD This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| May 7, 2025 | NCSC | Guidance | Software Security Code of Practice - Assurance Principles and Claims (APCs) Helps vendors measure how well they meet the Software Security Code of Practice, and suggests remedial actions should they fall short. This document allows technical staff to self-assess their own software practices against the Software Security Code of Practice, a set of outcomes that – if met – means the vendor can claim that their software has achieved a baseline of software security and resilience. | NCSC-UK |
| May 7, 2025 | NCSC | Analysis Report | Impact of AI on cyber threat from now to 2027 An NCSC assessment highlighting the impacts on cyber threat from AI developments NCSC Assessment (NCSC-A) is the authoritative voice on the cyber threat to the UK. We combine source information – classified intelligence, industry knowledge, academic material and open source – to provide independent key judgements that inform policy decision making and improve UK cyber security. | NCSC-UK |
| May 7, 2025 | FBI | Alert | Cybercriminal Proxy Services Exploiting End-of-Life Routers When a hardware device is end of life, the manufacturer no longer sells the product and is not actively supporting the hardware, which also means they are no longer releasing software updates or security patches for the device. Routers dated 2010 or earlier likely no longer receive software updates issued by the manufacturer and could be compromised by cyber actors exploiting known vulnerabilities. | FBI |
| May 6, 2025 | FBI | Alert | Primary Mitigations to Reduce Cyber Threats to Operational Technology The authoring organizations urge critical infrastructure entities to review and act now to improve their cybersecurity posture against cyber threat activities specifically and intentionally targeting internet connected OT and ICS. The authoring organizations recommend critical infrastructure asset owners and operators implement the following mitigations1 to defend against OT cyber threats. internet. | CISA, DOE, EPA, FBI |
| May 6, 2025 | CISA | Alert | Unsophisticated Cyber Actor(s) Targeting Operational Technology critical Infrastructure sectors (Oil and Natural Gas), specifically in Energy and Transportation Systems. Although these activities often include basic and elementary intrusion techniques, the presence of poor cyber hygiene and exposed assets can escalate these threats, leading to significant consequences such as defacement, configuration changes, operational disruptions and, in severe cases, physical damage. | CISA |
| May 6, 2025 | CISA | Alert | CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-126-01 Optigo Networks ONS NC600 ICSA-25-126-02 Milesight UG65-868M-EA ICSA-25-126-03 BrightSign Players This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| May 1, 2025 | CISA | Alert | CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-121-01 KUNBUS GmbH Revolution Pi ICSMA-25-121-01 MicroDicom DICOM Viewer This product is provided subject to this Notification and this Privacy & Use policy. | CISA |