| 2026-09-15 |
UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists
state actors to target dissidents, activists and GCHQ’s National Cyber Security Centre and international partners issue warning over Iranian cyber actors’ spearphishing and spyware campaign ‘CHOSEN BRICK’ malware family used to collect information, including screen captures and messaging history, from UK and allies provide advice to help organisations and individuals at risk detect malicious activity and reduce chances of their devices falling vi…
|
FBI
NCSC-UK
|
| 2026-09-15 |
Iranian cyber targeting of dissidents, activists and journalists
Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect CHOSEN BRICK is a malware family that has been used to target individuals around the world including in the UK, US and the Netherlands from at least 2025.
|
FBI
NCSC-UK
|
| 2026-07-23 |
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Read our joint advisory on LAUNDRY BEAR's exploitation of Zimbra Collaboration Suite.
|
AISE
AISI
ANSSI
ASD/ACSC
AW
CCCS
CISA
CNI
DC3
DCSA
DDIS
DGSI
EFIS
FBI
FDI
MIVD
NCIS
NCSC-NZ
NCSC-SE
NCSC-UK
NSA
NUKIB
SIS RM
SKW
SUPO
Treasury
|
| 2026-04-23 |
Defending Against China-Nexus Covert Networks of Compromised Devices
Over the past few years there has been a major shift in the tactics, techniques and procedures (TTPs) used by China-nexus cyber actors, moving away from the use of individually procured infrastructure, and towards the use of externally provisioned, large-scale networks of compromised devices.
|
ASD/ACSC
BSI
CCCS
CISA
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-SE
NCSC-UK
NSA
|
| 2026-04-23 |
International cyber agencies share fresh advice to defend against China-linked covert networks
GCHQ’s National Cyber Security Centre with UK industry and 15 international partners shine light on best protections against methods used by China-linked threat actors. Covert networks, often made up of compromised devices such as smart devices, are being used to disguise the origins and attributions of cyber attacks.
|
ASD/ACSC
BSI
CCCS
CISA
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-SE
NCSC-UK
NSA
|
| 2025-08-27 |
Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System
Executive summary People’s Republic of China (PRC) state-sponsored cyber threat actors are targeting networks globally, including, but not limited to, telecommunications, government, transportation, lodging, and military infrastructure networks.
|
AISE
AISI
ASD/ACSC
AW
BSI
CCCS
CISA
CNI
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-UK
NSA
NUKIB
SKW
SUPO
|
| 2025-08-27 |
Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System
While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks.
|
AISE
AISI
ASD/ACSC
AW
BSI
CCCS
CISA
CNI
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-UK
NSA
NUKIB
SKW
SUPO
|
| 2025-08-27 |
CSA: Countering China State Actors Compromise of Networks
While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks.
|
AISE
AISI
ASD/ACSC
AW
BSI
CCCS
CISA
CNI
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-UK
NSA
NUKIB
SKW
SUPO
|
| 2024-08-21 |
ASD’s ACSC, CISA, FBI, and NSA, with the support of International Partners Release Best Practices for Event Logging and Threat Detection
Logging priorities for enterprise mobility using mobile computing devices 10 Protecting event logs from unauthorised access, modification and deletion 11 This publication defines a baseline for event logging best practices to mitigate cyber threats.
|
ASD/ACSC
CCCS
CISA
CSA
MIVD
NCSC-NZ
NCSC-UK
NIS
NSA
|
| 2024-07-09 |
State-Sponsored Russian Media Leverages Meliorator Software for Foreign Malign Influence Activity
Affiliates of RT (formerly Russia Today), a Russian state-sponsored media organization, used Meliorator—a covert artificial intelligence (AI) enhanced software package—to create fictitious online personas, representing a number of nationalities, to post content on X (formerly Twitter).
|
CCCS
CNMF
FBI
MIVD
|