CyberzSOC

CISA, FBI, NSA, NCSC, ASD/ACSC & NCSC Cyber Intelligence Feed
‹ November 2025 ›
18 publications — sorted newest first
Date Source Type Title Author
Nov 25, 2025 CISA Alert CISA Releases Seven Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-329-01 Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share ICSA-25-329-02 Rockwell Automation Arena Simulation ICSA-25-329-03 Zenitel TCIV-3+ ICSA-25-329-04 Opto 22 groov View ICSA-25-329-05 Festo Compact Vision System, Control Block, Controller, and Operator Unit products ICSA-25-329-06 SiRcom SMART Alert (SiSA)… CISA
Nov 25, 2025 FBI Alert Account Takeover Fraud via Impersonation of Financial Institution Support The cyber criminal impersonates the financial institution's staff or website, to obtain access to the account. Cyber criminals usually gain access to accounts through social engineering techniques—including texts, calls, and emails—or through fraudulent websites. FBI
Nov 24, 2025 CISA Alert ​​Spyware Allows Cyber Threat Actors to Target Users of Messaging Applications​ 1 These cyber actors use sophisticated targeting and social engineering techniques to deliver spyware and gain unauthorized access to a victim’s messaging app, facilitating the deployment of additional malicious payloads that can further compromise the victim’s mobile device. These cyber actors use tactics such as: Phishing and malicious device-linking QR codes to compromise victim accounts and link them to actor-controlled devices. CISA
Nov 24, 2025 NCSC Guidance Choosing a managed service provider (MSP) An SME’s guide to selecting and working with managed service providers. Many small to medium-sized enterprises (SMEs) use managed service providers (MSPs) to deliver IT products and services, manage important data, and to provide cyber security. This guidance describes how to select and work effectively with MSPs, and includes a checklist you can use when sourcing MSPs. NCSC-UK
Nov 20, 2025 CISA Alert CISA Releases Six Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-324-01 Automated Logic WebCTRL Premium Server ICSA-25-324-02 ICAM365 CCTV Camera Multiple Models ICSA-25-324-03 Opto 22 GRV-EPIC and GRV-RIO ICSA-25-324-04 Festo MSE6-C2M/D2M/E2M ICSA-25-324-05 Festo Didactic products ICSA-25-324-06 Emerson Appleton UPSMON-PRO This product is provided subject to this Notification and t… CISA
Nov 19, 2025 CISA Alert CISA Releases Guide to Mitigate Risks from Bulletproof Hosting Providers Today, Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the U.S. National Security Agency, U.S. Department of Defense Cyber Crime Center, U.S. Federal Bureau of Investigation, and international partners, released the guide Bulletproof Defense: Mitigating Risks from Bulletproof Hosting Providers to help Internet Service Providers (ISPs) and network defenders mitigate cybercriminal activity enabled by Bulletproof Hosti… CISA
Nov 19, 2025 FBI Alert Bulletproof Defense: Mitigating Risks from Bulletproof Hosting Providers This document was developed through the Joint Ransomware Task Force (JRTF), a U.S. interagency body established by Congress in the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) to ensure unity of effort in combating the growing threat of ransomware attacks. ASD/ACSC, CCCS, CISA, DC3,
FBI, NCSC-NL, NCSC-NZ, NCSC-UK,
NSA
Nov 18, 2025 CISA Alert CISA Releases Six Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-322-01 Schneider Electric EcoStruxure Machine SCADA Expert & Pro-face BLUE Open Studio ICSA-25-322-04 Schneider Electric PowerChute Serial Shutdown ICSA-25-322-05 METZ CONNECT EWIO2 ICSA-25-224-03 Schneider Electric EcoStruxure (Update B) This product is provided subject to this Notification and this Privacy & Use poli… CISA
Nov 14, 2025 CISA Alert Fortinet Releases Security Advisory for Relative Path Traversal Vulnerability Affecting FortiWeb Products CISA has updated this Alert to include an additional vulnerability, CVE-2025-58034, and its relation to CVE-2025-64446, and associated resources. CISA is aware of the exploitation of two vulnerabilities, CVE-2025-64446 and CVE-2025-58034 , in Fortinet FortiWeb, a web application firewall. CISA
Nov 13, 2025 CISA Alert CISA Releases 18 Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-317-01 Mitsubishi Electric MELSEC iQ-F Series ICSA-25-317-02 AVEVA Application Server IDE ICSA-25-317-04 Brightpick Mission Control / Internal Logic Control ICSA-25-317-05 Rockwell Automation Verve Asset Manager ICSA-25-317-06 Rockwell Automation Studio 5000 Simulation Interface ICSA-25-317-07 Rockwell Automation Facto… CISA
Nov 13, 2025 CISA Alert CISA and Partners Release Advisory Update on Akira Ransomware Today, Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Federal Bureau of Investigation, Department of Defense Cyber Crime Center, Department of Health and Human Services, and international partners, released an updated joint Cybersecurity Advisory, #StopRansomware: Akira Ransomware , to provide network defenders with the latest indicators of compromise, tactics, techniques, and procedures, and detection methods… CISA, FBI, HHS
Nov 13, 2025 FBI Alert Criminals Impersonate U.S. Health Insurance Providers and Chinese Law Enforcement to Target Chinese Speakers Residing in the United States health insurance providers and Chinese law enforcement. Targeted individuals receive a call from a spoofed telephone number of a legitimate U.S. health insurance provider’s claims department. The call is conducted in Chinese, and the recipient is asked about recent insurance claims for alleged surgical procedures. FBI
Nov 13, 2025 FBI Alert Criminals Impersonate U.S. Health Insurance Providers and Chinese Law Enforcement to Target Chinese Speakers Residing in the United States (Chinese translation) Consistent with the FBI’s Core Values, and just as the FBI is committed to serving every are equally committed to ensuring that employees work in an environment free of discrimination, harassment and retaliation. The FBI does not tolerate discrimination based on race, color, sex (to include sexual orientation and pregnancy), national origin, religion, age, physical or mental disability, genetic information, or status as a parent, nor does it tole… FBI
Nov 13, 2025 FBI Alert #StopRansomware: Akira Ransomware #StopRansomware: Akira Ransomware Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Akira  Prioritize remediating known exploited vulnerabilities.  Enable and enforce phishing-resistant multifactor authentication (MFA). CISA, DC3, EC3, FBI,
HHS, NCSC-NL
Nov 12, 2025 CISA Alert Update: Implementation Guidance for Emergency Directive on Cisco ASA and Firepower Device Vulnerabilities Emergency Directive 25-03: Identify and Mitigate Potential Compromise of Cisco Devices , issued on Sept. 25, identified known vulnerabilities CVE-2025-20333 and CVE-2025-20362 , and mandated immediate action to mitigate risks. Threat actors continue to target these devices, posing significant risk to all organizations. CISA
Nov 12, 2025 JPCERT/CC Alert Microsoft Releases November 2025 Security Updates Microsoft has released November 2025 Security Updates to address the vulnerabilities in their products. Attackers leveraging these vulnerabilities may be able to gain SYSTEM privileges. According to Microsoft, among the vulnerabilities, the following vulnerability has been confirmed to be exploited in the wild. JPCERT/CC
Nov 6, 2025 CISA Alert CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-310-01 Advantech DeviceOn iEdge ICSA-25-310-03 ABB FLXeon Controllers ICSA-25-282-01 Hitachi Energy Asset Suite (Update A) This product is provided subject to this Notification and this Privacy & Use policy. CISA
Nov 4, 2025 CISA Alert CISA Releases Five Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-308-01 Fuji Electric Monitouch V-SFT-6 ICSA-25-308-02 Survision License Plate Recognition Camera ICSA-25-308-03 Delta Electronics CNCSoft-G2 ICSA-25-308-04 Radiometrics VizAir ICSA-25-308-05 IDIS ICM Viewer This product is provided subject to this Notification and this Privacy & Use policy. CISA