| Date | Source | Type | Title | Author |
|---|---|---|---|---|
| Nov 25, 2025 | CISA | Alert | CISA Releases Seven Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-329-01 Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share ICSA-25-329-02 Rockwell Automation Arena Simulation ICSA-25-329-03 Zenitel TCIV-3+ ICSA-25-329-04 Opto 22 groov View ICSA-25-329-05 Festo Compact Vision System, Control Block, Controller, and Operator Unit products ICSA-25-329-06 SiRcom SMART Alert (SiSA)… | CISA |
| Nov 25, 2025 | FBI | Alert | Account Takeover Fraud via Impersonation of Financial Institution Support The cyber criminal impersonates the financial institution's staff or website, to obtain access to the account. Cyber criminals usually gain access to accounts through social engineering techniques—including texts, calls, and emails—or through fraudulent websites. | FBI |
| Nov 24, 2025 | CISA | Alert | Spyware Allows Cyber Threat Actors to Target Users of Messaging Applications 1 These cyber actors use sophisticated targeting and social engineering techniques to deliver spyware and gain unauthorized access to a victim’s messaging app, facilitating the deployment of additional malicious payloads that can further compromise the victim’s mobile device. These cyber actors use tactics such as: Phishing and malicious device-linking QR codes to compromise victim accounts and link them to actor-controlled devices. | CISA |
| Nov 24, 2025 | NCSC | Guidance | Choosing a managed service provider (MSP) An SME’s guide to selecting and working with managed service providers. Many small to medium-sized enterprises (SMEs) use managed service providers (MSPs) to deliver IT products and services, manage important data, and to provide cyber security. This guidance describes how to select and work effectively with MSPs, and includes a checklist you can use when sourcing MSPs. | NCSC-UK |
| Nov 20, 2025 | CISA | Alert | CISA Releases Six Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-324-01 Automated Logic WebCTRL Premium Server ICSA-25-324-02 ICAM365 CCTV Camera Multiple Models ICSA-25-324-03 Opto 22 GRV-EPIC and GRV-RIO ICSA-25-324-04 Festo MSE6-C2M/D2M/E2M ICSA-25-324-05 Festo Didactic products ICSA-25-324-06 Emerson Appleton UPSMON-PRO This product is provided subject to this Notification and t… | CISA |
| Nov 19, 2025 | CISA | Alert | CISA Releases Guide to Mitigate Risks from Bulletproof Hosting Providers Today, Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the U.S. National Security Agency, U.S. Department of Defense Cyber Crime Center, U.S. Federal Bureau of Investigation, and international partners, released the guide Bulletproof Defense: Mitigating Risks from Bulletproof Hosting Providers to help Internet Service Providers (ISPs) and network defenders mitigate cybercriminal activity enabled by Bulletproof Hosti… | CISA |
| Nov 19, 2025 | FBI | Alert | Bulletproof Defense: Mitigating Risks from Bulletproof Hosting Providers This document was developed through the Joint Ransomware Task Force (JRTF), a U.S. interagency body established by Congress in the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) to ensure unity of effort in combating the growing threat of ransomware attacks. | ASD/ACSC, CCCS, CISA, DC3, FBI, NCSC-NL, NCSC-NZ, NCSC-UK, NSA |
| Nov 18, 2025 | CISA | Alert | CISA Releases Six Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-322-01 Schneider Electric EcoStruxure Machine SCADA Expert & Pro-face BLUE Open Studio ICSA-25-322-04 Schneider Electric PowerChute Serial Shutdown ICSA-25-322-05 METZ CONNECT EWIO2 ICSA-25-224-03 Schneider Electric EcoStruxure (Update B) This product is provided subject to this Notification and this Privacy & Use poli… | CISA |
| Nov 14, 2025 | CISA | Alert | Fortinet Releases Security Advisory for Relative Path Traversal Vulnerability Affecting FortiWeb Products CISA has updated this Alert to include an additional vulnerability, CVE-2025-58034, and its relation to CVE-2025-64446, and associated resources. CISA is aware of the exploitation of two vulnerabilities, CVE-2025-64446 and CVE-2025-58034 , in Fortinet FortiWeb, a web application firewall. | CISA |
| Nov 13, 2025 | CISA | Alert | CISA Releases 18 Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-317-01 Mitsubishi Electric MELSEC iQ-F Series ICSA-25-317-02 AVEVA Application Server IDE ICSA-25-317-04 Brightpick Mission Control / Internal Logic Control ICSA-25-317-05 Rockwell Automation Verve Asset Manager ICSA-25-317-06 Rockwell Automation Studio 5000 Simulation Interface ICSA-25-317-07 Rockwell Automation Facto… | CISA |
| Nov 13, 2025 | CISA | Alert | CISA and Partners Release Advisory Update on Akira Ransomware Today, Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Federal Bureau of Investigation, Department of Defense Cyber Crime Center, Department of Health and Human Services, and international partners, released an updated joint Cybersecurity Advisory, #StopRansomware: Akira Ransomware , to provide network defenders with the latest indicators of compromise, tactics, techniques, and procedures, and detection methods… | CISA, FBI, HHS |
| Nov 13, 2025 | FBI | Alert | Criminals Impersonate U.S. Health Insurance Providers and Chinese Law Enforcement to Target Chinese Speakers Residing in the United States health insurance providers and Chinese law enforcement. Targeted individuals receive a call from a spoofed telephone number of a legitimate U.S. health insurance provider’s claims department. The call is conducted in Chinese, and the recipient is asked about recent insurance claims for alleged surgical procedures. | FBI |
| Nov 13, 2025 | FBI | Alert | Criminals Impersonate U.S. Health Insurance Providers and Chinese Law Enforcement to Target Chinese Speakers Residing in the United States (Chinese translation) Consistent with the FBI’s Core Values, and just as the FBI is committed to serving every are equally committed to ensuring that employees work in an environment free of discrimination, harassment and retaliation. The FBI does not tolerate discrimination based on race, color, sex (to include sexual orientation and pregnancy), national origin, religion, age, physical or mental disability, genetic information, or status as a parent, nor does it tole… | FBI |
| Nov 13, 2025 | FBI | Alert | #StopRansomware: Akira Ransomware #StopRansomware: Akira Ransomware Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Akira Prioritize remediating known exploited vulnerabilities. Enable and enforce phishing-resistant multifactor authentication (MFA). | CISA, DC3, EC3, FBI, HHS, NCSC-NL |
| Nov 12, 2025 | CISA | Alert | Update: Implementation Guidance for Emergency Directive on Cisco ASA and Firepower Device Vulnerabilities Emergency Directive 25-03: Identify and Mitigate Potential Compromise of Cisco Devices , issued on Sept. 25, identified known vulnerabilities CVE-2025-20333 and CVE-2025-20362 , and mandated immediate action to mitigate risks. Threat actors continue to target these devices, posing significant risk to all organizations. | CISA |
| Nov 12, 2025 | JPCERT/CC | Alert | Microsoft Releases November 2025 Security Updates Microsoft has released November 2025 Security Updates to address the vulnerabilities in their products. Attackers leveraging these vulnerabilities may be able to gain SYSTEM privileges. According to Microsoft, among the vulnerabilities, the following vulnerability has been confirmed to be exploited in the wild. | JPCERT/CC |
| Nov 6, 2025 | CISA | Alert | CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-310-01 Advantech DeviceOn iEdge ICSA-25-310-03 ABB FLXeon Controllers ICSA-25-282-01 Hitachi Energy Asset Suite (Update A) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Nov 4, 2025 | CISA | Alert | CISA Releases Five Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-308-01 Fuji Electric Monitouch V-SFT-6 ICSA-25-308-02 Survision License Plate Recognition Camera ICSA-25-308-03 Delta Electronics CNCSoft-G2 ICSA-25-308-04 Radiometrics VizAir ICSA-25-308-05 IDIS ICM Viewer This product is provided subject to this Notification and this Privacy & Use policy. | CISA |