CyberzSOC

CISA, FBI, NSA, NCSC, ASD/ACSC & NCSC Cyber Intelligence Feed
‹ April 2026 ›
21 publications — sorted newest first
Date Source Type Title Author
Apr 30, 2026 CERT-EU Advisory 2026-005: High Vulnerability in the Linux Kernel ("Copy Fail") The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. As of the date of this advisory, no distribution has shipped a fixed kernel package. CERT-EU
Apr 29, 2026 CISA Advisory Adapting Zero Trust Principles to Operational Technology Zero trust is a modern, adaptive approach to cybersecurity that eliminates implicit trust and requires continuously validating access based on identity, context, and risk. With advancements in technology, OT systems that were traditionally isolated or manually operated are now increasingly interconnected, digitally monitored, and remotely controlled. CISA, DOE, FBI
Apr 27, 2026 NCSC Guidance Could your choice of metrics be harming your SOC? Poor metrics can render a well-intentioned security operation centre entirely ineffective. Security operation centres (SOCs) are a key defence in organisations, where skilled analysts use tools to hunt for attacks in the haystacks of logs. Unsurprisingly, SOCs are usually expensive to run, with costs that include staff, licenses and storage. NCSC-UK
Apr 23, 2026 NSA Advisory Defending Against China-Nexus Covert Networks of Compromised Devices Over the past few years there has been a major shift in the tactics, techniques and procedures (TTPs) used by China-nexus cyber actors, moving away from the use of individually procured infrastructure, and towards the use of externally provisioned, large-scale networks of compromised devices. AIVD, ASD/ACSC, BSI, CCCS,
CISA, DC3, FBI, MIVD,
NCO, NCSC-NZ, NCSC-SE, NCSC-UK,
NSA
Apr 23, 2026 CISA Analysis Report FIRESTARTER Backdoor Malware Analysis Report at a Glance Malware Name FIRESTARTER Original Publication April 23, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) analyzed a sample of FIRESTARTER malware obtained from a forensic investigation. CISA, NCSC, NCSC-UK
Apr 23, 2026 NCSC Guidance Passkeys are more secure than traditional ways to log in Passkeys offer a more usable, secure replacement for passwords and are already supported by most modern devices. NCSC-UK
Apr 23, 2026 NCSC Guidance NCSC: Leave passwords in the past - passkeys are the future Passkeys are the more secure and user-friendly login method and should be the default authentication option for consumers. NCSC-UK
Apr 23, 2026 NSA Guidance International cyber agencies share fresh advice to defend against China-linked covert networks GCHQ’s National Cyber Security Centre with UK industry and 15 international partners shine light on best protections against methods used by China-linked threat actors. Covert networks, often made up of compromised devices such as smart devices, are being used to disguise the origins and attributions of cyber attacks. AIVD, ASD/ACSC, BSI, CCCS,
CISA, DC3, FBI, MIVD,
NCO, NCSC-NZ, NCSC-SE, NCSC-UK,
NSA
Apr 23, 2026 NCSC Guidance Supporting AI adoption for UK cyber defence Getting there will require time, the development of new capabilities and As the NCSC’s CEO set out in his letter to the Financial Times last week, AI can ultimately be a good thing for cyber security. In the near term, however, AI is likely to expose weaknesses in organisations that have not taken appropriate steps to secure their systems. NCSC-UK
Apr 22, 2026 NCSC Guidance World-first NCSC-engineered device secures vulnerable display links SilentGlass, a plug-and-play device, actively blocks any unexpected or malicious HDMI and Display Port connections. NCSC-UK
Apr 21, 2026 NCSC Guidance New cross domain guidance for government, industry and the wider security community Cross domain technologies play a vital role in helping organisations to move data safely between environments with different security levels. The NCSC know this area can be challenging to navigate, which is why we’ve produced new guidance on Cross domain approach and architecture. NCSC-UK
Apr 21, 2026 NCSC Guidance Cyber chief: UK faces "perfect storm" for cyber security As the technology landscape develops, the definition of cyber security is expanding with it and organisations must grasp Technological change and geopolitical tensions present “tumultuous uncertainty” requiring culture shift in approach to cyber defence, says head of UK cyber agency All organisations urged to follow advice to make cyber security part of their mission, as cyberspace sits in state Threat picture ever more contested, with majority o… NCSC-UK
Apr 20, 2026 CISA Alert ​​Supply Chain Compromise Impacts Axios Node Package Manager​ The Cybersecurity and Infrastructure Security Agency (CISA) is releasing this alert to provide guidance in response to the software supply chain compromise of the Axios node package manager (npm). 1 Axios is an HTTP client for JavaScript that developers commonly use in Node.js and browser environments. On March 31, 2026, two npm packages for versions [email protected] and [email protected] of Axios npm injected the malicious dependency [email protected]. CISA
Apr 20, 2026 NCSC Guidance Preparing for severe cyber threat: why leaders must act now Disruption to those operations isn’t simply an IT issue; it’s a business continuity and national resilience issue. Recent high-profile cyber incidents demonstrate a clear and accelerating trend: highly capable threat actors are increasing both their intent and their ability to target organisations of national economic significance, to cause real-world operational disruption. NCSC-UK
Apr 17, 2026 NCSC Guidance Strengthening cyber resilience across the NHS with collaboration and innovation How the NCSC is reducing risk, improving detection, and helping to keep vital services running. We all rely on the UK’s health services, from booking a GP appointment and collecting prescriptions, to receiving life‑saving treatment in hospitals. These services increasingly depend on digital systems to operate safely and effectively. NCSC-UK
Apr 15, 2026 NCSC Guidance Retaining defensive advantage in the age of frontier AI cyber capabilities As AI accelerates vulnerability discovery, organisations must raise their security baselines to safeguard their cyber security. NCSC-UK
Apr 15, 2026 JPCERT/CC Alert Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-44) Vulnerabilities exists in Adobe Acrobat, a PDF file creation and conversion software, and Adobe Acrobat Reader, a PDF file viewing software. As a result, an attacker may execute arbitrary code by convincing a user to open contents leveraging the vulnerability. JPCERT/CC
Apr 15, 2026 JPCERT/CC Alert Microsoft Releases April 2026 Security Updates Microsoft has released April 2026 Security Updates to address the vulnerabilities in their products. Attackers leveraging these vulnerabilities may be able to perform spoofing over a network, or execute arbitrary code remotely without authentication, etc. According to Microsoft, among the vulnerabilities, the following vulnerability has been confirmed to be exploited in the wild. JPCERT/CC
Apr 7, 2026 NSA Advisory Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure This activity has led to PLC disruptions across several U.S. critical infrastructure sectors through malicious interactions with the project file and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss. U.S. CISA, CNMF, DOE, EPA,
FBI, NIST, NSA
Apr 7, 2026 NCSC Guidance APT28 exploit routers to enable DNS hijacking operations Russian cyber actor APT28 exploit vulnerable routers to hijack DNS, enabling adversary‑in‑the‑middle attacks and theft of passwords and authentication tokens. Russian cyber actors APT28 have been exploiting routers to overwrite Dynamic Host Configuration Protocol (DHCP)/Domain Name System (DNS) settings to redirect traffic through attacker-controlled DNS servers. NCSC-UK
Apr 7, 2026 NCSC Guidance UK exposes Russian military intelligence hijacking vulnerable routers for cyber attacks New advisory warns cyber threat group APT28 have exploited vulnerable edge devices to support malicious operations. The National Cyber Security Centre (NCSC) – a part of GCHQ – has published a new advisory revealing how Russian cyber actors have compromised commonly used routers , allowing them to covertly reroute users’ internet traffic through malicious servers under their control. NCSC-UK