| Date | Source | Type | Title | Author |
|---|---|---|---|---|
| Sep 30, 2025 | CISA | Alert | CISA Releases Ten Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-273-01 MegaSys Enterprises Telenium Online Web Application ICSA-25-273-02 Festo SBRD-Q/SBOC-Q/SBOI-Q ICSA-25-273-03 Festo CPX-CEC-C1 and CPX-CMXX ICSA-25-273-04 Festo Controller CECC-S,-LK,-D Family Firmware ICSA-25-273-06 National Instruments Circuit Design Suite ICSA-25-273-07 LG Innotek Camera Multiple Models ICSA-2… | CISA |
| Sep 29, 2025 | CISA | Alert | CISA and UK NCSC Release Joint Guidance for Securing OT Systems CISA, in collaboration with the Federal Bureau of Investigation, the United Kingdom’s National Cyber Security Centre, and other international partners has released new joint cybersecurity guidance: Creating and Maintaining a Definitive View of Your Operational Technology (OT) Architecture . | CISA, FBI |
| Sep 29, 2025 | CISA | Alert | CISA Strengthens Commitment to SLTT Governments CISA is supporting our SLTT partners with access to grant funding, no-cost tools, and cybersecurity expertise to be resilient and lead at the local level. CISA’s cooperative agreement with the Center for Internet Security (CIS) will reach its planned end on September 30, 2025. | CISA, DHS, FEMA |
| Sep 29, 2025 | FBI | Alert | Creating and Maintaining a Definitive View of Your Operational Technology (OT) Architecture It is aimed at cyber security professionals working in organisations that deploy or operate OT across greenfield and brownfield deployments. Integrators and device manufactures can also use these principles to ensure their solutions enable effective asset and configuration management. | ASD/ACSC, BSI, CCCS, CISA, FBI, NCSC-NL, NCSC-NZ, NCSC-UK |
| Sep 26, 2025 | CERT-EU | Advisory | 2025-036: Critical Vulnerabilities in Cisco ASA and FTD Cisco warns that some of those vulnerabilities are exploited in the wild and assesses with high confidence that this new activity is related to the same threat actor as the ArcaneDoor attack campaign that Cisco reported in early 2024 [4]. It is recommended running compromise assessment on Internet facing vulnerable devices, and The vulnerability CVE-2025-20333, with a CVSS score of 9. | CERT-EU |
| Sep 26, 2025 | CERT-EU | Advisory | 2025-035: High Vulnerability in Cisco IOS and IOS XE Software It is recommended updating as soon as possible and conduct a compromise assessment on devices that are exposing SNMP on the Internet. It is also recommended not allowing access to SNMP over untrusted network (i.e. on the Internet). | CERT-EU |
| Sep 25, 2025 | CISA | Alert | CISA Directs Federal Agencies to Identify and Mitigate Potential Compromise of Cisco Devices CISA has added vulnerabilities CVE-2025-20333 and CVE-2025-20362 to the Known Exploited Vulnerabilities Catalog . The Emergency Directive requires federal agencies to identify, analyze, and mitigate potential compromises immediately. | CISA |
| Sep 25, 2025 | CISA | Alert | CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-268-01 Dingtian DT-R002 This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Sep 24, 2025 | CERT-EU | Advisory | 2025-034: Critical Vulnerability in SolarWinds Web Help Desk The fix provided as part of this advisory is a patch bypass of CVE-24-28988, which in turn is a patch bypass of CVE-2024-28986 [1]. It is recommended updating affected assets as soon as possible. | CERT-EU |
| Sep 23, 2025 | CISA | Alert | Widespread Supply Chain Compromise Impacting npm Ecosystem CISA is releasing this Alert to provide guidance in response to a widespread software supply chain compromise involving the world’s largest JavaScript registry, npmjs.com. A self-replicating worm—publicly known as “Shai-Hulud”—has compromised over 500 packages. [i] After gaining initial access, the malicious cyber actor deployed malware that scanned the environment for sensitive credentials. | CISA |
| Sep 23, 2025 | CISA | Alert | CISA Releases Advisory on Lessons Learned from an Incident Response Engagement This advisory, CISA Shares Lessons Learned from an Incident Response Engagement , highlights takeaways that illuminate the urgent need for timely patching, comprehensive incident response planning, and proactive threat monitoring to mitigate risks from similar vulnerabilities. | CISA |
| Sep 23, 2025 | CISA | Alert | CISA Releases Six Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-266-01 AutomationDirect CLICK PLUS ICSA-25-266-02 Mitsubishi Electric MELSEC-Q Series CPU Module ICSA-25-266-03 Schneider Electric SESU ICSA-25-023-02 Hitachi Energy RTU500 Series Product (Update A) ICSA-25-093-01 Hitachi Energy RTU500 Series (Update B) This product is provided subject to this Notification and this Pri… | CISA |
| Sep 23, 2025 | CISA | Advisory | CISA Shares Lessons Learned from an Incident Response Engagement CISA began incident response efforts at a U.S. federal civilian executive branch (FCEB) agency following the detection of potential malicious activity identified through security alerts generated by the agency’s endpoint detection and response (EDR) tool. | CISA |
| Sep 22, 2025 | CISA | Alert | SonicWall Releases Advisory for Customers after Security Incident SonicWall’s investigation found that a malicious actor performed a series of brute force techniques against their MySonicWall.com web portal to gain access to a subset of customers’ preference files stored in their cloud backups. While credentials within the files were encrypted, the files also included information that actors can use to gain access to customers’ SonicWall Firewall devices. | CISA |
| Sep 19, 2025 | FBI | Alert | Threat Actors Spoofing the FBI IC3 Website for Possible Malicious Activity If using a search engine, avoid any "sponsored" results as these are usually paid imitators looking to deter traffic from the legitimate IC3 website. Avoid clicking on any link whose URL differs from the legitimate IC3 site to mitigate risk of fraud. Never click on links that may include suspicious artifacts or graphics, such as unprofessional or low-quality graphics used to imitate a legitimate website. | FBI |
| Sep 18, 2025 | CISA | Analysis Report | CISA Releases Malware Analysis Report on Malicious Listener Targeting Ivanti Endpoint Manager Mobile Systems Today, CISA released a Malware Analysis Report detailing the functionality of two sets of malware obtained from an organization compromised by cyber threat actors exploiting CVE-2025-4427 and CVE-2025-4428 in Ivanti Endpoint Manager Mobile (Ivanti EPMM). | CISA |
| Sep 18, 2025 | CISA | Alert | CISA Releases Nine Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-261-03 Schneider Electric Saitel DR & Saitel DP Remote Terminal Unit ICSA-25-261-04 Hitachi Energy Asset Suite ICSA-25-261-05 Hitachi Energy Service Suite ICSA-25-261-06 Cognex In-Sight Explorer and In-Sight Camera Firmware ICSA-25-261-07 Dover Fueling Solutions ProGauge MagLink LX4 Devices ICSA-25-191-10 End-of-Train… | CISA |
| Sep 18, 2025 | CISA | Analysis Report | Malicious Listener for Ivanti Endpoint Mobile Management Systems Malicious Listener for Ivanti Endpoint Publication: September 18, 2025 include the following information regarding the incident: date, time, and location of the incident; type of activity; number of people affected; type of equipment used for the activity; the name of the submitting company or organization; and a designated point of contact. | CISA |
| Sep 18, 2025 | NCSC | Guidance | External attack surface management (EASM) buyer's guide External attack surface management (EASM) is the process of identifying, monitoring, and reducing vulnerabilities within assets that are accessible from the internet. This guidance will help system owners to choose an EASM product that is appropriate for their organisation. | NCSC-UK |
| Sep 16, 2025 | CISA | Alert | CISA Releases Eight Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-259-01 Schneider Electric Altivar Products, ATVdPAC Module, ILC992 InterLink Converter ICSA-25-259-02 Hitachi Energy RTU500 Series ICSA-25-259-03 Siemens SIMATIC NET CP, SINEMA, and SCALANCE ICSA-25-259-04 Siemens RUGGEDCOM, SINEC NMS, and SINEMA ICSA-25-259-05 Siemens OpenSSL Vulnerability in Industrial Products ICSA-… | CISA |
| Sep 12, 2025 | FBI | Alert | Cybercriminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion 12 September 2025 The following information is being provided by the FBI, with no guarantees or warranties, for potential use at the sole discretion of recipients to protect against cyber threats. This data is provided in order to help cyber security professionals and system administrators to guard against the persistent malicious actions of cyber actors. This FLASH was coordinated with DHS/CISA. WE NEED YOUR HELP! | FBI |
| Sep 11, 2025 | CISA | Alert | CISA Releases Eleven Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-254-01 Siemens SIMOTION Tools ICSA-25-254-02 Siemens SIMATIC Virtualization as a Service (SIVaaS) ICSA-25-254-03 Siemens SINAMICS Drives ICSA-25-254-04 Siemens SINEC OS ICSA-25-254-05 Siemens Apogee PXC and Talon TC Devices ICSA-25-254-06 Siemens Industrial Edge Management OS (IEM-OS) ICSA-25-254-07 Siemens User Manage… | CISA |
| Sep 10, 2025 | JPCERT/CC | Alert | Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB25-85) Vulnerabilities exists in Adobe Acrobat, a PDF file creation and conversion software, and Adobe Acrobat Reader, a PDF file viewing software. As a result, an attacker may execute arbitrary code by convincing a user to open contents leveraging the vulnerability. | JPCERT/CC |
| Sep 10, 2025 | JPCERT/CC | Alert | Microsoft Releases September 2025 Security Updates Microsoft has released September 2025 Security Updates to address the vulnerabilities in their products. Remote attackers leveraging these vulnerabilities may be able to execute arbitrary code. It is recommended to check the information provided by Microsoft and apply the updates. | JPCERT/CC |
| Sep 9, 2025 | CISA | Alert | CISA Releases Fourteen Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-252-01 Rockwell Automation ThinManager ICSA-25-252-02 ABB Cylon Aspect BMS/BAS ICSA-25-252-03 Rockwell Automation Stratix IOS ICSA-25-252-04 Rockwell Automation FactoryTalk Optix ICSA-25-252-05 Rockwell Automation FactoryTalk Activation Manager ICSA-25-252-06 Rockwell Automation CompactLogix® 5480 ICSA-25-252-07 Rockwe… | CISA |
| Sep 4, 2025 | CISA | Alert | CISA Releases Five Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-247-01 Honeywell OneWireless Wireless Device Manager (WDM) ICSA-25-217-01 Mitsubishi Electric Iconics Digital Solutions Multiple Products (Update A) ICSA-25-105-07 Delta Electronics COMMGR (Update A) ICSA-25-205-03 Honeywell Experion PKS (Update A) ICSA-25-191-10 End-of-Train and Head-of-Train Remote Linking Protocol (… | CISA |
| Sep 3, 2025 | CISA | Alert | CISA, NSA, and Global Partners Release a Shared Vision of Software Bill of Materials (SBOM) Guidance This marks a significant step forward in strengthening software supply chain transparency and security worldwide. An SBOM is a formal record detailing the components and supply chain relationships used in building software. SBOMs act as a software “ingredients list” providing organizations with essential visibility into software dependencies, enabling them to identify components, assess risks, and take proactive measures to mitigate vulnerabiliti… | CISA, NSA |
| Sep 3, 2025 | NSA | Advisory | Joint Guidance: A Shared Vision of Software Bill Of Materials For Cybersecurity Widespread adoption of SBOM will strengthen security, reduce risk, and Most modern software is comprised of software components, modules, and libraries from open source and proprietary software worlds, rather than developers creating it from scratch. As concerns about the security and provenance of software grow, it is critical to understand the risks in the software’s supply chain— including the risks of the underlying software components. | ANSSI, ASD/ACSC, BSI, CCCS, CISA, CSA, NCO, NCSC-NL, NCSC-NZ, NIS, NSA, NUKIB |
| Sep 2, 2025 | CISA | Alert | CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-245-01 Delta Electronics EIP Builder ICSA-25-182-06 Hitachi Energy Relion 670/650 and SAM600-IO Series (Update A) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |