CyberzSOC

CISA, FBI, NSA, NCSC, ASD/ACSC & NCSC Cyber Intelligence Feed
‹ December 2025 ›
29 publications — sorted newest first
Date Source Type Title Author
Dec 30, 2025 CISA Alert CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-364-01: WHILL C2 Wheelchairs ICSA-25-345-03: AzeoTech DAQFactory (Update A) This product is provided subject to this Notification and this Privacy & Use policy. CISA
Dec 23, 2025 CISA Alert CISA Releases One Industrial Control Systems Advisory These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-177-01 Mitsubishi Electric Air Conditioning Systems (Update B) This product is provided subject to this Notification and this Privacy & Use policy. CISA
Dec 22, 2025 CISA Alert NIST and CISA Release Draft Interagency Report on Protecting Tokens and Assertions from Tampering Theft and Misuse for Public Comment The Cybersecurity and Infrastructure Security Agency (CISA) and National Institute of Standards and Technology (NIST) have released an initial draft of Interagency Report (IR) 8597 Protecting Tokens and Assertions from Forgery, Theft, and Misuse for public comment through January 30, 2026. CISA
Dec 19, 2025 NSA Analysis Report CISA and Partners Release Update to Malware Analysis Report BRICKSTORM Backdoor This update provides information on additional samples, including Rust-based samples. These samples demonstrate advanced persistence and defense evasion mechanisms, such as running as background services, and enhanced command and control capabilities through encrypted WebSocket connections. CCCS, CISA, NSA
Dec 19, 2025 FBI Alert Senior U.S. Officials Continue To Be Impersonated in Malicious Messaging Campaign This is an update to Public Service Announcement I-051525-PSA , released May 15, 2025. Activity dating back to 2023 reveals malicious actors have impersonated senior U.S. state government, White House, and Cabinet level officials, as well as members of Congress to target individuals, including officials' family members and personal acquaintances. If you receive a message claiming to be from a current or former senior U.S. CISA, FBI
Dec 18, 2025 CISA Alert CISA Releases Nine Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-352-01 Inductive Automation Ignition ICSA-25-352-02 Schneider Electric EcoStruxure Foxboro DCS Advisor ICSA-25-352-03 National Instruments LabView ICSA-25-352-04 Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electrics Products ICSA-25-352-05 Siemens Interniche IP-Stack ICSA-25-352-06 Advantech WebAccess/… CISA
Dec 18, 2025 CERT-EU Advisory 2025-042: Critical Vulnerability in Cisco Secure Email and Web Manager It is recommended to follow Cisco’s recommendations to check whether vulnerable appliances have been compromised, and to remediate the issue. While there is not much technical details about the vulnerability CVE-2025-20393, with a CVSS score of 10, Cisco reveals that it allows attackers to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance. CERT-EU
Dec 17, 2025 FBI Alert Great Odds, High Risk: The FBI Encourages U.S. Bettors to Know the Risks of Illegal Gambling While sports betting has become more widespread in the U.S., with 39 states and the District of Columbia legalizing some form of sports betting, illegal sportsbooks and illegal online gaming sites are still prevalent. These illegal sportsbooks and online gaming sites have significant consequences for the American public, the U.S. economy, and the integrity of sports betting in the U.S. FBI
Dec 16, 2025 CISA Alert CISA Releases Six Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-350-01 Güralp Systems FMUS (Fortimus) Series and MIN (Minimus) Series ICSA-25-350-02 Johnson Controls PowerG, IQPanel and IQHub ICSA-25-350-03 Hitachi Energy AFS, AFR and AFF Series ICSA-25-350-04 Mitsubishi Electric GT Designer3 ICSA-25-224-02 Johnson Controls iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra G2, iSTAR Ultra G… CISA
Dec 15, 2025 FBI Guidance Principles for the Secure Integration of Artificial Intelligence in Operational Technology CISA | ASD’s ACSC | NSA AISC | FBI | Cyber Centre | BSI | NCSC-NL | NCSC-NZ | NCSC-UK Introduction ................................................................................................................................................................... 3 Important Terminology ....................................................................................................................................... 3 Scope ................... ASD/ACSC, BSI, CCCS, CISA,
FBI, NCSC-NL, NCSC-NZ, NCSC-UK,
NSA
Dec 11, 2025 CISA Alert CISA Releases 12 Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-345-01 Johnson Controls iSTAR ICSA-25-345-02 Johnson Controls iSTAR Ultra ICSA-25-345-03 AzeoTech DAQFactory ICSA-25-345-04 Siemens IAM Client ICSA-25-345-05 Siemens Advanced Licensing (SALT) Toolkit ICSA-25-345-06 Siemens SINEMA Remote Connect Server ICSA-25-345-07 Siemens Building X - Security Manager Edge Controller… CISA
Dec 11, 2025 CISA Alert 2025 CWE Top 25 Most Dangerous Software Weaknesses The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Homeland Security Systems Engineering and Development Institute (HSSEDI), operated by the MITRE Corporation, has released the 2025 Common Weakness Enumeration (CWE) Top 25 Most Dangerous Software Weaknesses . This annual list identifies the most critical weaknesses adversaries exploit to compromise systems, steal data, or disrupt services. CISA
Dec 11, 2025 CISA Alert Cybersecurity Performance Goals 2.0 for Critical Infrastructure This update incorporates lessons learned, aligns with the most recent National Institute of Standards and Technology Cybersecurity Framework revisions, and addresses the most common and impactful threats facing critical infrastructure today. CPG 2.0 includes a new component focused on the essential role of governance in managing cybersecurity. CISA
Dec 11, 2025 NSA Guidance CSI: Guidance for Managing UEFI Secure Boot Recent vulnerabilities involving Secure Boot (e.g., PKFail [1], BlackLotus [2], BootHole [3], and similar unnamed [4]) have demonstrated the need to scrutinize the configuration of Secure Boot on enterprise devices. This document details instructions for system owners to query Secure Boot configuration, compare observed results to industry norms, and recognize and recover from misconfigurations. NSA
Dec 10, 2025 NCSC Guidance Provisioning and managing certificates in the Web PKI They are used to identify and authenticate clients and gateways at the point when encrypted connections are established. This guidance helps architects, designers and engineers to make appropriate choices when obtaining and managing certificates to authenticate their online services to users. NCSC-UK
Dec 10, 2025 JPCERT/CC Alert Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB25-119) Vulnerabilities exists in Adobe Acrobat, a PDF file creation and conversion software, and Adobe Acrobat Reader, a PDF file viewing software. As a result, an attacker may execute arbitrary code by convincing a user to open contents leveraging the vulnerability. JPCERT/CC
Dec 10, 2025 JPCERT/CC Alert Microsoft Releases December 2025 Security Updates Microsoft has released December 2025 Security Updates to address the vulnerabilities in their products. Attackers leveraging these vulnerabilities may be able to gain SYSTEM privileges. According to Microsoft, among the vulnerabilities, the following vulnerability has been confirmed to be exploited in the wild. JPCERT/CC
Dec 9, 2025 CISA Alert CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-343-01 Universal Boot Loader (U-Boot) ICSA-25-343-02 Festo LX Appliance ICSA-25-343-03 Multiple India-Based CCTV Cameras This product is provided subject to this Notification and this Privacy & Use policy. CISA
Dec 9, 2025 NSA Alert Opportunistic Pro-Russia Hacktivists Attack US and Global Critical Infrastructure This advisory, published as an addition to the joint fact sheet on Primary Mitigations to Reduce Cyber Threats to Operational Technology (OT) released in May 2025 , details that pro-Russia hacktivist groups are conducting less sophisticated, lower-impact attacks against critical infrastructure entities, compared to advanced persistent threat groups. CISA, DOE, EPA, FBI,
NSA
Dec 9, 2025 NSA Advisory Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure Actions for Operational Technology Owners and Operators to Take Today to Mitigate Cyber Threats Related to Pro-Russia Hacktivists Activity Reduce exposure of operational technology (OT) assets to the public-facing internet. Adopt mature asset management processes, including mapping data flows and access points. Ensure that OT assets are using robust authentication procedures. ASD/ACSC, BSI, CCCS, CISA,
DC3, DOE, EC3, EPA,
FBI, NCSC-NZ, NCSC-UK, NSA,
NUKIB
Dec 9, 2025 NSA Alert Pro-Russia Hacktivists Conduct Opportunistic Attacks Against U.S. and Global Critical Infrastructure FBI, CISA, National Security Agency (NSA), and the following partners—hereafter referred to as “the authoring organizations”—are releasing this joint advisory on the targeting of critical infrastructure by proRussia hacktivists: The authoring organizations assess pro-Russia hacktivist groups are conducting less sophisticated, lowerimpact attacks against critical infrastructure entities, compared to advanced persistent threat (APT) groups. ASD/ACSC, BSI, CCCS, DC3,
DOE, EC3, EPA, FBI,
NCSC-NZ, NCSC-UK, NSA, NUKIB
Dec 5, 2025 FBI Alert Criminals Using Altered Proof-of-Life Media to Extort Victims in Virtual Kidnapping for Ransom Scams The Federal Bureau of Investigation (FBI) warns the public about criminals altering photos found on social media or other publicly available sites to use as fake proof of life photos in virtual kidnapping for ransom scams. The criminal actors pose as kidnappers and provide seemingly real photos or videos of victims along with demands for ransom payments. FBI
Dec 4, 2025 CISA Alert CISA Releases Nine Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-338-01 Mitsubishi Electric GX Works2 ICSA-25-338-03 Johnson Controls OpenBlue Mobile Web Application for OpenBlue Workplace ICSA-25-338-04 Johnson Controls iSTAR ICSA-25-338-05 Sunbird DCIM dcTrack and Power IQ ICSA-25-338-06 SolisCloud Monitoring Platform ICSA-25-338-07 Advantech iView ICSA-25-148-03 Consilium Safety… CISA
Dec 4, 2025 NSA Analysis Report BRICKSTORM Backdoor Malware Analysis at a Glance Malware Name BRICKSTORM Original Publication Dec. 4, 2025 Last Update Feb. 11, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Canadian Centre for Cyber Security (Cyber Centre) assess People’s Republic of China (PRC) state-sponsored cyber actors are using BRICKSTORM malware for long-term persistence on victim systems. CCCS, CISA, NSA
Dec 4, 2025 CISA Alert PRC State-Sponsored Actors Use BRICKSTORM Malware Across Public Sector and Information Technology Systems The Cybersecurity and Infrastructure Security Agency (CISA) is aware of ongoing intrusions by People’s Republic of China (PRC) state-sponsored cyber actors using BRICKSTORM malware for long-term persistence on victim systems. BRICKSTORM is a sophisticated backdoor for VMware vSphere 1 , 2 and Windows environments. 3 Victim organizations are primarily in the Government Services and Facilities and Information Technology Sectors. CISA
Dec 4, 2025 CERT-EU Advisory 2025-041: Critical Security Vulnerability in React Server Components The vulnerability allows for unauthenticated remote code execution (RCE) via maliciously crafted HTTP requests [1]. It is recommended to update all affected component packages and any frameworks that integrate them. CERT-EU
Dec 3, 2025 CISA Alert CISA, Australia, and Partners Author Joint Guidance on Securely Integrating Artificial Intelligence in Operational Technology CISA and the Australian Signals Directorate’s Australian Cyber Security Centre, in collaboration with federal and international partners, have released new cybersecurity guidance: Principles for the Secure Integration of Artificial Intelligence in Operational Technology . ASD/ACSC, CISA, FBI, NSA
Dec 3, 2025 NCSC Guidance New Vulnerability Monitoring Service (VMS) from GDS now available in MyNCSC VMS - from GDS, helps UK public sector organisations identify and respond to security vulnerabilities in their internet-facing digital services. VMS goes hand-in-hand with the monitoring already offered by DNS Check (also from GDS). NCSC-UK
Dec 2, 2025 CISA Alert CISA Releases Five Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-336-01 Industrial Video & Control Longwatch ICSA-25-336-02 Iskra iHUB and iHUB Lite ICSMA-25-336-01 Mirion Medical EC2 Software NMIS BioDose ICSA-25-205-01 Mitsubishi Electric CNC Series (Update A) ICSA-23-157-02 Mitsubishi Electric MELSEC iQ-R Series/iQ-F Series (Update C) This product is provided subject to this Noti… CISA