| Date | Source | Type | Title | Author |
|---|---|---|---|---|
| Jul 31, 2025 | CISA | Alert | CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-212-01 Güralp FMUS Series Seismic Monitoring Devices ICSA-25-212-02 Rockwell Automation Lifecycle Services with VMware This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jul 31, 2025 | CISA | Alert | Thorium Platform Public Availability Thorium enhances cybersecurity teams' capabilities by automating analysis workflows through seamless integration of commercial, open-source, and custom tools. It supports various mission functions, including software analysis, digital forensics, and incident response, allowing analysts to efficiently assess complex malware threats. | CISA |
| Jul 31, 2025 | CISA | Alert | CISA and USCG Issue Joint Advisory to Strengthen Cyber Hygiene in Critical Infrastructure This follows a proactive threat hunt engagement conducted at a U.S. critical infrastructure facility. During this engagement, CISA and USCG did not find evidence of malicious cyber activity or actor presence on the organization’s network but did identify several cybersecurity risks. | CISA, USCG |
| Jul 31, 2025 | CISA | Advisory | CISA and USCG Identify Areas for Cyber Hygiene Improvement After Conducting Proactive Threat Hunt at US Critical Infrastructure Organization Summary The Cybersecurity and Infrastructure Security Agency (CISA) and U.S. Coast Guard (USCG) are issuing this Cybersecurity Advisory to present findings from a recent CISA and USCG hunt engagement. The purpose of this advisory is to highlight identified cybersecurity issues, thereby informing security defenders in other organizations of potential similar issues and encouraging them to take proactive measures to enhance their cybersecurity post… | CGCYBER, CISA, NIST, USCG |
| Jul 31, 2025 | FBI | Alert | Unsolicited Packages Containing QR Codes Used to Initiate Fraud Schemes The FBI warns the public about a scam variation in which criminals send unsolicited packages containing a QR code 1 that prompts the recipient to provide personal and financial information or unwittingly download malicious software that steals data from their phone. To encourage the victim to scan the QR code, the criminals often ship the packages without sender information to entice the victim to scan the QR code. | FBI |
| Jul 30, 2025 | CISA | Alert | Eviction Strategies Tool Released This tool includes: Cyber Eviction Strategies Playbook Next Generation (Playbook-NG) : A web-based application for next-generation operations. COUN7ER : A database of atomic post-compromise countermeasures users can execute based on adversary tactics, techniques, and procedures. | CISA |
| Jul 29, 2025 | CISA | Alert | CISA Releases Five Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-210-01 National Instruments LabVIEW ICSA-25-210-02 Samsung HVAC DMS ICSA-25-210-03 Delta Electronics DTN Soft ICSA-24-158-04 Johnson Controls Software House iStar Pro Door Controller (Update A) ICSA-24-338-06 Fuji Electric Tellus Lite V-Simulator (Update A) This product is provided subject to this Notification and this… | CISA |
| Jul 29, 2025 | CISA | Alert | CISA Releases Part One of Zero Trust Microsegmentation Guidance CISA released Microsegmentation in Zero Trust, Part One: Introduction and Planning as part of its ongoing efforts to support Federal Civilian Executive Branch (FCEB) agencies implementing zero trust architectures (ZTAs). This guidance provides a high-level overview of microsegmentation, focusing on its key concepts, associated challenges and potential benefits, and includes recommended actions to modernize network security and advance zero trust… | CISA |
| Jul 29, 2025 | CISA | Alert | CISA and Partners Release Updated Advisory on Scattered Spider Group CISA, along with the Federal Bureau of Investigation, Canadian Centre for Cyber Security, Royal Canadian Mounted Police, the Australian Cyber Security Centre’s Australian Signals Directorate, and the Australian Federal Police and National Cyber Security Centre, released an updated joint Cybersecurity Advisory on Scattered Spider—a cybercriminal group targeting commercial facilities sectors and subsectors. | AFP, ASD/ACSC, CCCS, CISA, FBI, RCMP |
| Jul 29, 2025 | FBI | Alert | Scattered Spider Actions for Organizations to Take Today to Mitigate Malicious Cyber Activity The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Royal (ACSC), Australian Federal Police (AFP), Canadian Centre for Cyber Security (CCCS), and United Kingdom’s National Cyber Security Centre (NCSC-UK)—hereafter referred to as the authoring organizations—are releasing this joint Cybersecurity Advisory in response to recen… | AFP, ASD/ACSC, CCCS, CISA, FBI, NCSC-UK |
| Jul 24, 2025 | CISA | Alert | CISA Releases Six Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-205-01 Mitsubishi Electric CNC Series ICSA-25-205-02 Network Thermostat X-Series WiFi Thermostats ICSA-25-205-03 Honeywell Experion PKS ICSA-25-205-04 LG Innotek Camera Model LNV5110R ICSMA-25-205-01 Medtronic MyCareLink Patient Monitor ICSA-22-202-04 ICONICS Suite and Mitsubishi Electric MC Works64 Products (Update A)… | CISA |
| Jul 24, 2025 | CERT-EU | Advisory | 2025-027: Critical Vulnerabilities in Microsoft SharePoint These vulnerabilities apply to on-premises SharePoint Servers only. These critical flaws are actively being exploited in the wild since at least 18th of July 2025 [4]. | CERT-EU |
| Jul 24, 2025 | CERT-EU | Advisory | 2025-028: CrushFTP zero-day exploited in the wild CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers [2, 3]. Threat actors were first detected exploiting the vulnerability on July 18th at 9AM CST, though it may have begun in the early hours of the previous day [1]. | CERT-EU |
| Jul 23, 2025 | FBI | Alert | Hacker Com: Cyber Criminal Subset of The Community Is a Rising Threat to Youth Online The Federal Bureau of Investigation is warning the public about Hacker Com, one of three subsets of the growing and evolving online threat group known as The Com, short for The Community. The Com is a primarily English speaking, international, online ecosystem comprised of multiple interconnected networks whose members, many of whom are minors, engage in a variety of criminal violations. | FBI |
| Jul 23, 2025 | FBI | Alert | In Real Life (IRL) Com: Violent Subset of The Community (Com) is a Rising Threat to Youth Online The Com is a primarily English speaking, international, online ecosystem comprised of multiple interconnected networks whose members, many of whom are minors, engage in a variety of criminal violations. The members within IRL Com typically have a shared interest, ideology, or goal and work together, adding others to the group and splintering when necessary, to achieve their mission. | FBI |
| Jul 23, 2025 | FBI | Alert | North Korean IT Worker Threats to U.S. Businesses The Federal Bureau of Investigation (FBI) is providing an update to previously shared guidance regarding Democratic People's Republic of Korea (North Korea) Information Technology (IT) workers to raise public awareness of the threat posed to U.S. businesses. North Korea is evading U.S. and U.N. sanctions by targeting private companies to illicitly generate substantial revenue for the regime. | FBI |
| Jul 23, 2025 | FBI | Alert | The Com: Theft, Extortion, and Violence are a Rising Threat to Youth Online The Federal Bureau of Investigation is warning the public about a growing and evolving online threat group known as The Com, short for The Community. The Com is a primarily English speaking, international, online ecosystem comprised of multiple interconnected networks whose members, many of whom are minors, engage in a variety of criminal violations. | FBI |
| Jul 22, 2025 | CISA | Alert | CISA Releases Nine Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-203-01 DuraComm DP-10iN-100-MU ICSA-25-203-02 Lantronix Provisioning Manager ICSA-25-203-03 Schneider Electric EcoStruxure ICSA-25-203-04 Schneider Electric EcoStruxure Power Operation ICSA-25-203-05 Schneider Electric System Monitor Application ICSA-25-203-06 Schneider Electric EcoStruxture IT Data Center Expert ICSA-… | CISA |
| Jul 22, 2025 | CISA | Alert | Joint Advisory Issued on Protecting Against Interlock Ransomware This advisory highlights known Interlock ransomware indicators of compromise and tactics, techniques, and procedures identified through recent FBI investigations. Actions organizations can take today to mitigate Interlock ransomware threat activity include: Preventing initial access by implementing domain name system filtering and web access firewalls and training users to spot social engineering attempts. | CISA, FBI, HHS, MS-ISAC |
| Jul 22, 2025 | CISA | Advisory | #StopRansomware: Interlock Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Interlock Prevent initial access by implementing domain name system (DNS) filtering and web access firewalls, and training users to spot social engineering attempts. | CISA, FBI, HHS, MS-ISAC, NIST |
| Jul 22, 2025 | FBI | Alert | #StopRansomware: Interlock Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Interlock Prevent initial access by implementing domain name system (DNS) filtering and web access firewalls, and training users to spot social engineering attempts. | CISA, FBI, HHS, MS-ISAC |
| Jul 20, 2025 | CISA | Alert | UPDATE: Microsoft Releases Guidance on Exploitation of SharePoint Vulnerabilities CISA is aware of active exploitation of a spoofing and RCE vulnerability chain involving CVE-2025-49706 and CVE-2025-49704 , enabling unauthorized access to on-premise SharePoint servers. While the scope and impact continue to be assessed, the chain, publicly reported as “ToolShell,” provides unauthenticated access to systems and authenticated access through network spoofing, respectively, and enables malicious actors to fully access SharePoint c… | CISA |
| Jul 18, 2025 | CERT-EU | Advisory | 2025-025: Critical Vulnerabilities in Cisco ISE It is recommended updating affected product as soon as possible. The vulnerabilities CVE-2025-20281 and CVE-2025-20337, both with a CVSS score of 10, are due to insufficient validation of user-supplied input in a specific API endpoint of the product. | CERT-EU |
| Jul 18, 2025 | CERT-EU | Advisory | 2025-026: Critical Vulnerabilities in VMWare Products It is recommended updating affected products as soon as possible, prioritising the ones hosting virtual machines that are Internet facing. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. | CERT-EU |
| Jul 17, 2025 | CISA | Alert | CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-198-01 Leviton AcquiSuite and Energy Monitoring Hub ICSMA-25-198-01 Panoramic Corporation Digital Imaging Software ICSA-24-191-05 Johnson Controls Inc. Software House C●CURE 9000 (Update B) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jul 15, 2025 | CISA | Alert | CISA Releases Six Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-196-01 Hitachi Energy Asset Suite ICSA-25-196-03 LITEON IC48A and IC80A EV Chargers ICSA-25-037-02 Schneider Electric EcoStruxure (Update B) ICSA-25-140-08 Schneider Electric Modicon Controllers (Update A) ICSA-25-070-01 Schneider Electric Uni-Telway Driver (Update A) This product is provided subject to this Notificati… | CISA |
| Jul 11, 2025 | CERT-EU | Advisory | 2025-024: Critical Vulnerability in FortiWeb The vulnerability CVE-2025-25257, with a CVSS score of 9.6, is due to an improper neutralisation of special elements used in an SQL command. It may allow an unauthenticated attacker to execute unauthorised SQL code or commands via crafted HTTP or HTTPs requests. | CERT-EU |
| Jul 10, 2025 | CISA | Alert | CISA Releases Thirteen Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-191-01 Siemens SINEC NMS ICSA-25-191-02 Siemens Solid Edge ICSA-25-191-03 Siemens TIA Administrator ICSA-25-191-04 Siemens SIMATIC CN 4100 ICSA-25-191-05 Siemens TIA Project-Server and TIA Portal ICSA-25-191-07 Delta Electronics DTM Soft ICSA-25-191-08 Advantech iView ICSA-25-191-09 KUNBUS RevPi Webstatus ICSA-25-191-1… | CISA |
| Jul 9, 2025 | JPCERT/CC | Alert | Microsoft Releases July 2025 Security Updates Microsoft has released July 2025 Security Updates to address the vulnerabilities in their products. Remote attackers leveraging these vulnerabilities may be able to execute arbitrary code. It is recommended to check the information provided by Microsoft and apply the updates. | JPCERT/CC |
| Jul 8, 2025 | CISA | Alert | CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-189-01 Emerson ValveLink Products This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jul 3, 2025 | FBI | Alert | Fraudsters Target U.S. Stock Investors through Investment Clubs Accessed on Social Media and Messaging Applications The FBI warns the public about criminals targeting US stock investors through social media platforms and messaging service applications (apps). The scheme, known as a "ramp-and-dump" stock manipulation, targets US investors through online engagement, often via social media advertisements or messages promoting an "investment club" of fellow investors, some of which may be bots or fake accounts. | FBI |
| Jul 3, 2025 | CERT-EU | Guidance | Generative AI in Cybersecurity: Balancing Innovation and Risk The integration of generative AI into cybersecurity operations represents both unprecedented opportunity and emerging risk. While these technologies offer powerful capabilities for threat analysis, incident response, and security automation, they simultaneously introduce new attack vectors that adversaries are rapidly exploiting. The cybersecurity community faces a critical challenge: how to harness AI s defensive potential whilst maintaining robust protection against AI-enabled threats. | CERT-EU |
| Jul 3, 2025 | CISA | Alert | CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-184-01 Hitachi Energy Relion 670/650 and SAM600-IO Series ICSA-25-184-02 Hitachi Energy MicroSCADA X SYS600 ICSA-25-184-03 Mitsubishi Electric MELSOFT Update Manager ICSA-25-184-04 Mitsubishi Electric MELSEC iQ-F Series This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Jul 1, 2025 | CISA | Alert | CISA Releases Seven Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-182-01 FESTO Didactic CP, MPS 200, and MPS 400 Firmware ICSA-25-182-02 FESTO Automation Suite, FluidDraw, and Festo Didactic Products ICSA-25-182-04 FESTO Hardware Controller, Hardware Servo Press Kit ICSA-25-182-05 Voltronic Power and PowerShield UPS Monitoring Software ICSA-25-182-06 Hitachi Energy Relion 670/650 and… | CISA |