CyberzSOC

CISA, FBI, NSA, NCSC, ASD/ACSC & NCSC Cyber Intelligence Feed
‹ May 2026 ›
10 publications — sorted newest first
Date Source Type Title Author
May 28, 2026 CISA Alert Supply Chain Compromises Impact Nx Console and GitHub Repositories CISA is prioritizing the response to multiple emerging software supply chain intrusion campaigns targeting developer ecosystems Continuous Integration/Continuous Development (CI/CD) pipelines. These recent incidents, including the GitHub compromise via a malicious Nx Console Visual Studio Code (VS Code) extension and the “Megalodon” supply chain intrusion campaign, demonstrate how cyber threat actors are abusing tools and processes that support e… CISA
May 27, 2026 NCSC Guidance Designing secure access with ZTNA ZTNA is widely deployed, but often still built on old trust assumptions. New NCSC guidance explains how to design ZTNA architectures aligned with zero trust principles. Zero Trust Network Access (ZTNA) is often introduced to modernise access to applications. NCSC-UK
May 22, 2026 JPCERT/CC Alert [Updated] Alert Regarding Multiple Vulnerabilities in Trend Micro Products Including TrendAI Apex One On May 21, 2026, Trend Micro has released the information regarding multiple vulnerabilities in TrendAI Apex One (On Premise), Trend Micro Apex One as a Service, TrendAI Vision One Endpoint Security - Standard Endpoint Protection. JPCERT/CC
May 15, 2026 NCSC Guidance Thinking carefully before adopting agentic AI When it comes to using agentic AI, make sure you can walk before you run. Agentic AI tools are starting to appear in real organisations, not just research labs. These tools don’t just generate content or predictions; they can plan, make decisions and take actions on your behalf. NCSC-UK
May 13, 2026 JPCERT/CC Alert Microsoft Releases May 2026 Security Updates Microsoft has released May 2026 Security Updates to address the vulnerabilities in their products. Remote attackers leveraging these vulnerabilities may be able to execute arbitrary code. Please consider applying the security update programs by referring to the information provided by Microsoft. JPCERT/CC
May 12, 2026 CISA Advisory Software Bill of Materials for AI - Minimum Elements A software bill of materials (SBOM) acts as an “ingredients list” for software that better positions organizations to understand their supply chains and make risk-informed decisions about how to protect their critical systems. The guidance builds on CISA’s previous work with federal and international partners to establish a shared vision for a software bill of materials and provides recommendations on minimum elements that should be included in a… ACN, ANSSI, BSI, CCCS,
CERT-EU, CISA, NCSC-UK, NISC
May 11, 2026 NCSC Guidance 10 questions to ask when using AI models to find vulnerabilities Using Artificial Intelligence to find vulnerabilities can bring added security considerations. NCSC-UK
May 6, 2026 CERT-EU Advisory 2026-006: Critical Vulnerability in PAN-OS This vulnerability allows an unauthenticated attacker to execute arbitrary Palo Alto observed limited exploitation of this vulnerability. It is strongly recommended updating affected appliances as soon as patches will be available, and to apply workarounds and The vulnerability CVE-2026-0300, with the CVSS score of 9.3, is a buffer overflow in the UserID Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software. CERT-EU
May 1, 2026 CISA Advisory Careful Adoption of Agentic AI Services CISA, in collaboration with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and other international and U.S. partners, released guidance for organizations on adopting agentic artificial intelligence (AI) systems. This guide outlines key security challenges and risks associated with agentic AI, and provides actionable steps for designing, deploying, and operating these systems safely. ASD/ACSC, CISA
May 1, 2026 NCSC Guidance Preparing for a ‘vulnerability patch wave’ Organisations must act now to prepare for a wave of patches that will address decades of technical debt. NCSC-UK