| 2026-09-02 |
Communicating Under Pressure: Best Practices for Service Providers
Service outages impacting IT and operational technology (OT) systems can be damaging and disruptive for customers, network defenders, critical infrastructure owners and operators, and the general public. During incidents that reach or exceed established thresholds, whether caused by malicious activity or a nonmalicious event, service providers must communicate effectively so end users can minimize operational impact.
|
CCCS
CISA
FBI
NCSC-NZ
NCSC-UK
|
| 2026-07-29 |
2026 Minimum Elements for a Software Bill of Materials (SBOM)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the co-authoring organizations, updated the Minimum Elements for a Software Bill of Materials (SBOM) to reflect current SBOM needs, while preserving the core principles of the document published in 2021 by the National Telecommunications and Information Administration (NTIA).
|
CISA
FBI
NSA
NTIA
|
| 2026-07-28 |
CI Fortify – Advice for isolating vital systems
This guidance contains practical steps for critical infrastructure (CI) organizations to isolate vital operational technology and enabling systems from all other networks in the event of disruption or crisis and operate in isolation for an extended period. Developed to address escalating cyber threats, the guidance outlines key steps for identifying critical systems, mapping connections, and implementing effective separation points.
|
CISA
FBI
|
| 2026-07-23 |
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Read our joint advisory on LAUNDRY BEAR's exploitation of Zimbra Collaboration Suite.
|
AISE
AISI
AIVD
ANSSI
AW
CCCS
CISA
CNI
DC3
DCSA
DDIS
DGSI
EFIS
FBI
FDI
MIVD
NCIS
NCSC-NZ
NCSC-SE
NCSC-UK
NSA
NUKIB
SIS RM
SKW
SUPO
Treasury
|
| 2026-07-13 |
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks.
|
CCCS
CISA
FBI
NCSC-NZ
NCSC-UK
NSA
|
| 2026-06-22 |
The AI shift in cyber risk: why leaders must act now
Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk. As the leaders of the Five Eyes cyber security agencies, we are united in our call to action: the evolving landscape of artificial intelligence (AI) is rapidly transforming cyber risk, and we must act swiftly to remain ahead.
|
CCCS
CISA
NCSC-UK
NSA
|
| 2026-05-01 |
Careful Adoption of Agentic AI Services
CISA, in collaboration with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and other international and U.S. partners, released guidance for organizations on adopting agentic artificial intelligence (AI) systems. This guide outlines key security challenges and risks associated with agentic AI, and provides actionable steps for designing, deploying, and operating these systems safely.
|
CISA
|
| 2026-04-23 |
Defending Against China-Nexus Covert Networks of Compromised Devices
Over the past few years there has been a major shift in the tactics, techniques and procedures (TTPs) used by China-nexus cyber actors, moving away from the use of individually procured infrastructure, and towards the use of externally provisioned, large-scale networks of compromised devices.
|
AIVD
BSI
CCCS
CISA
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-SE
NCSC-UK
NSA
|
| 2026-04-23 |
International cyber agencies share fresh advice to defend against China-linked covert networks
GCHQ’s National Cyber Security Centre with UK industry and 15 international partners shine light on best protections against methods used by China-linked threat actors. Covert networks, often made up of compromised devices such as smart devices, are being used to disguise the origins and attributions of cyber attacks.
|
AIVD
BSI
CCCS
CISA
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-SE
NCSC-UK
NSA
|
| 2026-03-13 |
CSI: AI ML Supply Chain Risks and Mitigations
Supply chain risks and mitigations 2 Artificial intelligence and machine learning Supply chain risks and mitigations Artificial intelligence and machine learning Supply chain risks and mitigations 3 Artificial intelligence (AI) and machine with this, risks outlined in this guidance are learning (ML) systems allow organisations to mapped to the National Institute of Standards improve their efficiency in many areas.
|
CCCS
CSA
NCO
NCSC-NZ
NCSC-UK
NIS
NSA
|
| 2026-02-26 |
2026-002: Multiple Vulnerabilities in Cisco Products
If exploited, these vulnerabilities could allow attackers to gain administrative access to It is recommended to capture forensic evidence, hunt for indicators of compromise, and apply One of the vulnerabilities, CVE-2026-20127, is exploited in the wild since 2023.
|
CERT-EU
|
| 2026-02-25 |
CISA and Partners Release Guidance for Ongoing Global Exploitation of Cisco SD-WAN Systems
CISA and partners have observed malicious cyber actors targeting and compromising Cisco SD-WAN systems of organizations, globally. These actors have been observed exploiting a previously undisclosed authentication bypass vulnerability, CVE-2026-20127, for initial access before escalating privileges using CVE-2022-20775 and establishing long-term persistence in Cisco SD-WAN systems.
|
CCCS
CISA
NCSC-NZ
NCSC-UK
NSA
|
| 2026-02-25 |
CSA: Exploitation of SD-WAN Appliances
Malicious cyber threat actors are targeting Software-Defined Wide Area Networks (SDWANs) of organizations globally. These actors exploited a Cisco Catalyst SD-WAN controller authentication bypass vulnerability, CVE-2026-20127. After exploitation of this vulnerability the malicious actors add a rogue peer, and eventually gain root access to establish long-term persistence in SD-WANs.
|
CCCS
CISA
NCSC-NZ
NCSC-UK
NSA
|
| 2026-02-05 |
Reducing the Attack Surface for End-of-Support Edge Devices
The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.K.’s National Cyber Security Centre (NCSC) are releasing this fact sheet to urge defensive action against malicious cyber activity by nation-state threat actors. Nation-state threat actors exploit end-of-support (EOS) edge devices—including load balancers, firewalls, routers, and VPN gateways—to gain network access, maintain persistence, and compromise sensitive data.
|
CISA
FBI
NCSC
|
| 2026-01-14 |
Secure Connectivity Principles for Operational Technology
SSeeccuurree CCoonnnneeccttiivviittyy PPrriinncciipplleess ffoorr OOppeerraattiioonnaall TTeecchhnnoollooggyy ((OOTT)) Operational technology (OT) environments - which have long been centred on safety, uptime, and operational continuity - are now more interconnected than ever.
|
BSI
CCCS
FBI
NCSC-NL
NCSC-NZ
NCSC-UK
|
| 2025-12-15 |
Principles for the Secure Integration of Artificial Intelligence in Operational Technology
CISA | ASD’s ACSC | NSA AISC | FBI | Cyber Centre | BSI | NCSC-NL | NCSC-NZ | NCSC-UK Introduction ................................................................................................................................................................... 3 Important Terminology ....................................................................................................................................... 3 Scope ...................
|
BSI
CCCS
CISA
FBI
NCSC-NL
NCSC-NZ
NCSC-UK
NSA
|
| 2025-12-09 |
Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure
Actions for Operational Technology Owners and Operators to Take Today to Mitigate Cyber Threats Related to Pro-Russia Hacktivists Activity Reduce exposure of operational technology (OT) assets to the public-facing internet. Adopt mature asset management processes, including mapping data flows and access points. Ensure that OT assets are using robust authentication procedures.
|
BSI
CCCS
CISA
DC3
DOE
EC3
EPA
FBI
NCSC-NZ
NCSC-UK
NSA
NUKIB
|
| 2025-12-09 |
Pro-Russia Hacktivists Conduct Opportunistic Attacks Against U.S. and Global Critical Infrastructure
FBI, CISA, National Security Agency (NSA), and the following partners—hereafter referred to as “the authoring organizations”—are releasing this joint advisory on the targeting of critical infrastructure by proRussia hacktivists: The authoring organizations assess pro-Russia hacktivist groups are conducting less sophisticated, lowerimpact attacks against critical infrastructure entities, compared to advanced persistent threat (APT) groups.
|
BSI
CCCS
DC3
DOE
EC3
EPA
FBI
NCSC-NZ
NCSC-UK
NSA
NUKIB
|
| 2025-12-03 |
CISA, Australia, and Partners Author Joint Guidance on Securely Integrating Artificial Intelligence in Operational Technology
CISA and the Australian Signals Directorate’s Australian Cyber Security Centre, in collaboration with federal and international partners, have released new cybersecurity guidance: Principles for the Secure Integration of Artificial Intelligence in Operational Technology .
|
CISA
FBI
NSA
|
| 2025-11-19 |
Bulletproof Defense: Mitigating Risks from Bulletproof Hosting Providers
This document was developed through the Joint Ransomware Task Force (JRTF), a U.S. interagency body established by Congress in the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) to ensure unity of effort in combating the growing threat of ransomware attacks.
|
CCCS
CISA
DC3
FBI
NCSC-NL
NCSC-NZ
NCSC-UK
NSA
|
| 2025-09-29 |
Creating and Maintaining a Definitive View of Your Operational Technology (OT) Architecture
It is aimed at cyber security professionals working in organisations that deploy or operate OT across greenfield and brownfield deployments. Integrators and device manufactures can also use these principles to ensure their solutions enable effective asset and configuration management.
|
BSI
CCCS
CISA
FBI
NCSC-NL
NCSC-NZ
NCSC-UK
|
| 2025-09-03 |
Joint Guidance: A Shared Vision of Software Bill Of Materials For Cybersecurity
Widespread adoption of SBOM will strengthen security, reduce risk, and Most modern software is comprised of software components, modules, and libraries from open source and proprietary software worlds, rather than developers creating it from scratch. As concerns about the security and provenance of software grow, it is critical to understand the risks in the software’s supply chain— including the risks of the underlying software components.
|
ANSSI
BSI
CCCS
CISA
CSA
NCO
NCSC-NL
NCSC-NZ
NIS
NSA
NUKIB
|
| 2025-08-27 |
CSA: Countering China State Actors Compromise of Networks
While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks.
|
AISE
AISI
AIVD
AW
BSI
CCCS
CISA
CNI
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-UK
NSA
NUKIB
SKW
SUPO
|
| 2025-08-27 |
Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System
While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks.
|
AISE
AISI
AIVD
AW
BSI
CCCS
CISA
CNI
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-UK
NSA
NUKIB
SKW
SUPO
|
| 2025-08-27 |
Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System
Executive summary People’s Republic of China (PRC) state-sponsored cyber threat actors are targeting networks globally, including, but not limited to, telecommunications, government, transportation, lodging, and military infrastructure networks.
|
AISE
AISI
AIVD
AW
BSI
CCCS
CISA
CNI
DC3
FBI
MIVD
NCO
NCSC-NZ
NCSC-UK
NSA
NUKIB
SKW
SUPO
|
| 2025-08-13 |
Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators
Using these tools helps owners and operators identify which assets in their environment should be secured and protected, and structure their defenses accordingly to reduce the risk a cybersecurity incident poses to the organization’s mission and service continuity. An asset inventory is an organized, regularly updated list of an organization’s systems, hardware, and software.
|
BSI
CCCS
CISA
DOE
EPA
FBI
NCSC-NL
NCSC-NZ
NSA
|
| 2025-07-29 |
CISA and Partners Release Updated Advisory on Scattered Spider Group
CISA, along with the Federal Bureau of Investigation, Canadian Centre for Cyber Security, Royal Canadian Mounted Police, the Australian Cyber Security Centre’s Australian Signals Directorate, and the Australian Federal Police and National Cyber Security Centre, released an updated joint Cybersecurity Advisory on Scattered Spider—a cybercriminal group targeting commercial facilities sectors and subsectors.
|
AFP
CCCS
CISA
FBI
RCMP
|
| 2025-07-29 |
Scattered Spider
Actions for Organizations to Take Today to Mitigate Malicious Cyber Activity The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Royal (ACSC), Australian Federal Police (AFP), Canadian Centre for Cyber Security (CCCS), and United Kingdom’s National Cyber Security Centre (NCSC-UK)—hereafter referred to as the authoring organizations—are releasing this joint Cybersecurity Advisory in response to recen…
|
AFP
CCCS
CISA
FBI
NCSC-UK
|
| 2025-06-04 |
#StopRansomware: Play Ransomware
Tools Leveraged by Play Ransomware Actors AdFind Used to query and retrieve information from Active Directory. Bloodhound Used to query and retrieve information from Active Directory. GMER A software tool intended to be used for detecting and removing rootkits.
|
CISA
FBI
|
| 2025-05-27 |
Implementing SIEM and SOAR Platforms: Practitioners Guidance
4. Best practice principles for implementing a SIEM and/or SOAR 12 This publication provides high-level guidance for cyber security practitioners on Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms.
|
NSA
|
| 2025-05-22 |
CSI: AI Data Security: Best Practices for Securing Data Used to Train & Operate AI Systems
Joint Cybersecurity Information This Cybersecurity Information Sheet (CSI) provides essential guidance on securing data used in artificial intelligence (AI) and machine learning (ML) systems. It also highlights the importance of data security in ensuring the accuracy and integrity of AI outcomes and outlines potential risks arising from data integrity issues in various stages of AI development and deployment.
|
CISA
FBI
NCSC-NZ
NCSC-UK
NSA
|
| 2025-05-22 |
AI Data Security
Joint Cybersecurity Information Best Practices for Securing Data Used to Train & Operate AI Systems This Cybersecurity Information Sheet (CSI) provides essential guidance on securing data used in artificial intelligence (AI) and machine learning (ML) systems.
|
CISA
FBI
NCSC-NZ
NCSC-UK
NSA
|
| 2025-05-21 |
Russian GRU Targeting Western Logistics Entities and Technology Companies
Executive Summary This joint cybersecurity advisory (CSA) highlights a Russian state-sponsored cyber campaign targeting Western logistics entities and technology companies. This includes those involved in the coordination, transport, and delivery of foreign assistance to Ukraine.
|
CCCS
CISA
FBI
NCSC-UK
NSA
USCC
|
| 2025-05-21 |
Russian GRU Targeting Western Logistics Entities and Technology Companies
This joint cybersecurity advisory (CSA) highlights a Russian state-sponsored cyber those involved in the coordination, transport, and delivery of foreign assistance to Ukraine. Since 2022, Western logistics entities and IT companies have faced an elevated risk of targeting by the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (85th GTsSS), military unit 26165—tracked in the cybersecurity community under…
|
ANSSI
BSI
CCCS
DC3
DDIS
EFIS
FBI
MIVD
NCSC-UK
NSA
NUKIB
SKW
USCC
|
| 2025-04-09 |
BADBAZAAR and MOONSHINE: Spyware Targeting Uyghur, Taiwanese, and Tibetan Groups and Civil Society Actors
This advisory includes two case studies detailing techniques used by malicious cyber actors using spyware known as BADBAZAAR and MOONSHINE to target data on mobile devices including smartphones that could be of interest to the Chinese state.
|
CCCS
FBI
NCSC-NZ
NCSC-UK
NSA
|
| 2025-04-09 |
CSA: BADBAZAAR and MOONSHINE: Technical analysis and mitigations
BADBAZAAR and MOONSHINE: Technical With support from the UK Cyber League, this advisory has been jointly produced by the National Cyber Security Centre (NCSC UK) and international partners: > The Australian Cyber Security Centre, part of the Australian Signals > The Canadian Centre for Cyber Security, part of the Communications > The German Federal Intelligence Service > The German Federal Office for the Protection of the Constitution > The New Z…
|
CCCS
FBI
NCSC-NZ
NCSC-UK
NSA
|
| 2025-04-03 |
Fast Flux: A National Security Threat
The Protective Domain Name System (DNS) Resolver service allows the Cybersecurity and Infrastructure Security Agency (CISA) to detect and prevent cyberattacks and threats targeting federal civilian executive branch (FCEB) agency networks. Protective DNS also offers a range of capabilities to safeguard assets that may otherwise be challenging to protect such as cloud, mobile, and nomadic devices.
|
CCCS
CISA
FBI
NCSC-NZ
NSA
|
| 2025-04-03 |
NSA, CISA, FBI, and International Partners Release Cybersecurity Advisory on “Fast Flux,” a National Security Threat
Today, CISA—in partnership with the National Security Agency (NSA), Federal Bureau of Investigation (FBI), Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), Canadian Centre for Cyber Security (CCCS), and New Zealand’s National Cyber Security Centre (NCSC-NZ)—released joint Cybersecurity Advisory Fast Flux: A National Security Threat (PDF, 841 KB).
|
CCCS
CISA
FBI
NCSC-NZ
NSA
|
| 2025-04-03 |
Fast Flux: A National Security Threat
Malicious cyber actors, including cybercriminals and nation-state actors, use fast flux to obfuscate the locations of malicious servers by rapidly changing Domain Name System (DNS) records. Additionally, they can create resilient, highly available command and control (C2) infrastructure, concealing their subsequent malicious operations.
|
CCCS
CISA
FBI
NCSC-NZ
NSA
|
| 2025-02-06 |
Network security fundamentals
Networks are fundamental to the operation, security and resilience of many organisations. This guidance provides an introduction to the key topics to consider when designing, maintaining, or using networks that need to be secure and resilient. It will also help you apply the NCSC’s Cyber security design principles to networks.
|
NCSC-UK
|
| 2025-02-04 |
CISA Partners with ASD’s ACSC, CCCS, NCSC-UK, and Other International and US Organizations to Release Guidance on Edge Devices
CISA—in partnership with international and U.S. organizations—released guidance to help organizations protect their network edge devices and appliances , such as firewalls, routers, virtual private networks (VPN) gateways, Internet of Things (IoT) devices, internet-facing servers, and internet-facing operational technology (OT) systems.
|
CCCS
CISA
NCSC-UK
|
| 2025-02-04 |
Guidance on digital forensics and protective monitoring specifications for producers of network devices and appliances
This guidance has been developed with contributions from partnering agencies and is included in a series of publications aiming to draw attention to the importance of edge device cyber security measures. It is produced by the UK National Cyber Security Centre (NCSC) in partnership with the Australian Signals Directorate (ASD), US Cybersecurity and Infrastructure Security Agency (CISA), the Canadian Centre for Cyber Security – part of the Communic…
|
CCCS
CISA
FBI
NCSC-NZ
NCSC-UK
|
| 2025-02-03 |
CSI: Security Considerations for Edge Devices: Executive Guidance
Mitigation strategies for edge Malicious actors are increasingly targeting internet-facing edge devices to gain unauthorised access to networks; therefore, it is vital that organisations prioritise securing edge devices in their environments. Edge devices are critical network components that serve as security boundaries between internal enterprise networks and the internet.
|
CCCS
CISA
FBI
NCSC-NZ
NCSC-UK
NSA
|
| 2025-01-29 |
CSI: Content Credentials: Strengthening Multimedia Integrity in the Generative AI Era
The ability to manipulate media is not new, but the accessibility, speed, and quality of these modifications today, powered by artificial intelligence (AI) and machine learning tools, have reached unprecedented levels and may not be caught by traditional verification methods.
|
CCCS
NCSC-UK
NSA
|
| 2025-01-13 |
Secure by Demand: Priority Considerations for Operational Technology Owners and Operators When Selecting Digital Products
Many OT products are not designed and developed with Secure by Design principles1 and commonly have weaknesses, such as weak authentication, known software vulnerabilities, limited logging, insecure default settings and passwords, and insecure legacy protocols. Cyber threat actors can easily exploit these weaknesses across multiple victims to gain access to control systems.
|
BSI
CCCS
CISA
EPA
FBI
NCSC-NL
NCSC-NZ
NCSC-UK
NSA
TSA
|
| 2024-12-05 |
ASD’s ACSC, CISA, and US and International Partners Release Guidance on Choosing Secure and Verifiable Technologies
Today, CISA—in partnership with the Australian Signals Directorate Australian Cyber Security Centre (ASD ACSC), and other international partners—released updates to a Secure by Design Alert, Choosing Secure and Verifiable Technologies . Partners that provided recommendations in this alert include: The Canadian Centre for Cyber Security (CCCS).
|
CISA
|
| 2024-12-03 |
Enhanced Visibility and Hardening Guidance for Communications Infrastructure
The authoring agencies are releasing this guide to highlight this threat and provide network engineers and defenders of communications infrastructure with best practices to strengthen their visibility and harden their network devices against successful exploitation carried out by PRC-affiliated and other malicious cyber actors.
|
CISA
FBI
NCSC-NZ
NSA
|
| 2024-11-20 |
CISA and Partners Release Update to BianLian Ransomware Cybersecurity Advisory
Today, CISA, the Federal Bureau of Investigation (FBI), and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) released updates to #StopRansomware: BianLian Ransomware Group on observed tactics, techniques, and procedures (TTPs) and indicators of compromise attributed to data extortion group, BianLian.
|
CISA
FBI
|
| 2024-11-12 |
2023 Top Routinely Exploited Vulnerabilities
Summary The following cybersecurity agencies coauthored this joint Cybersecurity Advisory (hereafter collectively referred to as the authoring agencies): United States: The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and National Security Agency (NSA) Australia: Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) Canada: Canadian Centre for Cyber Security (CCCS) New Zeal…
|
CCCS
CISA
NCSC-NZ
NCSC-UK
NIST
NSA
|
| 2024-10-24 |
CISA, US, and International Partners Release Joint Guidance to Assist Software Manufacturers with Safe Software Deployment Processes
This guide aids software manufacturers in establishing secure software deployment processes to help ensure software is reliable and safe for customers. Additionally, it offers guidance on how to deploy in an efficient manner as part of the software development lifecycle (SDLC).
|
CISA
FBI
|
| 2024-10-16 |
Iranian Cyber Actors’ Brute Force and Credential Access Activity Compromises Critical Infrastructure Organizations
Summary The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Communications Security Establishment Canada (CSE), the Australian Federal Police (AFP), and Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) are releasing this joint Cybersecurity Advisory to warn network defenders of Iranian cyber actors’ use of brute force and othe…
|
AFP
CCCS
CISA
CSE
FBI
NIST
NSA
|
| 2024-10-01 |
ASD’s ACSC, CISA, FBI, NSA, and International Partners Release Guidance on Principles of OT Cybersecurity for Critical Infrastructure Organizations
Today, the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)—in partnership with CISA, U.S. government and international partners—released the guide Principles of Operational Technology Cybersecurity . This guidance provides critical information on how to create and maintain a safe, secure operational technology (OT) environment.
|
CISA
|
| 2024-09-26 |
ASD’s ACSC, CISA, and US and International Partners Release Guidance on Detecting and Mitigating Active Directory Compromises
First published: September 2024 This guidance – authored by the Australian Signals Directorate (ASD), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NCSC-NZ), and the United Kingdom’s National Cyber Security Centre (NCSC-UK) – aims to inform organisations about 17 common techniques used to target Active…
|
CCCS
CISA
NCSC-NZ
NCSC-UK
NSA
|
| 2024-09-05 |
Russian Military Cyber Actors Target US and Global Critical Infrastructure
GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and Prioritize routine system updates and remediate known exploited vulnerabilities. Segment networks to prevent the spread of malicious activity.
|
CCCS
CISA
CNMF
FBI
MIVD
NCSC-UK
NIST
NSA
Treasury
USCC
|
| 2024-09-05 |
Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure
GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and Prioritize routine system updates and remediate known exploited vulnerabilities. Segment networks to prevent the spread of malicious activity.
|
CCCS
CISA
CNMF
FBI
MIVD
NCSC-UK
NSA
Treasury
USCC
|
| 2024-08-21 |
ASD’s ACSC, CISA, FBI, and NSA, with the support of International Partners Release Best Practices for Event Logging and Threat Detection
Logging priorities for enterprise mobility using mobile computing devices 10 Protecting event logs from unauthorised access, modification and deletion 11 This publication defines a baseline for event logging best practices to mitigate cyber threats.
|
AIVD
CCCS
CISA
CSA
MIVD
NCSC-NZ
NCSC-UK
NIS
NSA
|
| 2024-07-08 |
CISA and Partners join ASD’S ACSC to Release Advisory on PRC State-Sponsored Group, APT 40
CISA has collaborated with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD's ACSC) to release an advisory, People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action outlining a PRC state-sponsored cyber group’s activity.
|
CISA
|
| 2024-07-08 |
People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action
The advisory draws on the authoring agencies’ shared understanding of the threat as well as ASD’s ACSC incident response investigations. The PRC state-sponsored cyber group has previously targeted organizations in various countries, including Australia and the United States, and the techniques highlighted below are regularly used by other PRC state-sponsored actors globally.
|
BND
CCCS
CISA
FBI
NCSC-NZ
NCSC-UK
NIS
NISC
NPA
NSA
|
| 2024-07-08 |
APT40 Advisory: PRC MSS Tradecraft in Action
Background The following Advisory provides a sample of significant case studies of this adversary’s techniques in action This advisory, authored by the Australian Signals against two victim networks. The case studies are Directorate’s Australian Cyber Security Centre consequential for cybersecurity practitioners to identify, (ASD’s ACSC), the United States Cybersecurity and prevent and remediate APT40 intrusions against their Infrastructure Secur…
|
CCCS
FBI
NCSC-NZ
NCSC-UK
NIS
NPA
NSA
|
| 2024-06-26 |
CISA and Partners Release Guidance for Exploring Memory Safety in Critical Open Source Projects
Today, CISA, in partnership with the Federal Bureau of Investigation, Australian Signals Directorate’s Australian Cyber Security Centre, and Canadian Cyber Security Center, released Exploring Memory Safety in Critical Open Source Projects . This guidance was crafted to provide organizations with findings on the scale of memory safety risk in selected open source software (OSS).
|
CISA
FBI
|
| 2024-05-09 |
ASD’s ACSC, CISA, and Partners Release Secure by Design Guidance on Choosing Secure and Verifiable Technologies
Today, the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), together with CISA, the Canadian Centre for Cyber Security (CCCS), the United Kingdom’s National Cyber Security Centre (NCSC-UK), and the New Zealand National Cyber Security Centre (NCSC-NZ) are releasing the following guidance: Secure by Design Choosing Secure and Verifiable Technologies .
|
CCCS
CISA
NCSC-NZ
NCSC-UK
|
| 2024-03-21 |
PRC State-Sponsored Cyber Activity: Actions for Critical Infrastructure Leaders
This fact sheet provides an overview for executive leaders on the urgent risk posed by People’s Republic of China (PRC) state-sponsored cyber actors known as “Volt Typhoon.” CISA—along with the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and other U.S. government and international partners1—released a major advisory on Feb. 7, 2024, in which the U.S.
|
CCCS
DOE
EPA
FBI
NCSC-NZ
NCSC-UK
NSA
TSA
Treasury
|
| 2024-03-07 |
CSI: Mitigate Risks from Managed Service Providers in Cloud Environments
The growth of the public cloud has encouraged the development of numerous MSPs that primarily provide these services within the cloud rather than in customer on-premises networks. Both cloud resellers and other IT vendors offer such third-party services.
|
CISA
NSA
|
| 2024-02-29 |
Threat Actors Exploit Multiple Vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways
CISA and authoring organizations appreciate the cooperation of Volexity, Ivanti, Mandiant and other industry partners in the development of this advisory and ongoing incident response activities. Authoring organizations: Of particular concern, the authoring organizations and industry partners have determined that cyber threat actors are able to deceive Ivanti’s internal and external Integrity Checker Tool (ICT), resulting in a failure to detect c…
|
CCCS
CISA
FBI
MS-ISAC
NCSC-NZ
NCSC-UK
|
| 2024-02-29 |
CISA and Partners Release Advisory on Threat Actors Exploiting Ivanti Connect Secure and Policy Secure Gateways Vulnerabilities
Additionally, the advisory describes two key CISA findings: The Ivanti Integrity Checker Tool is not sufficient to detect compromise due to the ability of threat actors to deceive it, and A cyber threat actor may be able to gain root-level persistence despite the victim having issued factory resets on the Ivanti device.
|
CCCS
CISA
FBI
MS-ISAC
NCSC-NZ
NCSC-UK
|
| 2024-02-26 |
SVR Cyber Actors Adapt Tactics for Initial Cloud Access
The US National Security Agency (NSA), the US Cybersecurity and Infrastructure Security Agency (CISA), the US the Canadian Centre for Cyber Security (CCCS) and the New Zealand National Cyber Security Centre (NCSC) agree with this attribution and the details This advisory provides an overview of TTPs deployed by the actor to gain initial access into the cloud environment and includes advice to detect and mitigate The NCSC has previously detailed h…
|
CCCS
CISA
CNMF
FBI
NCSC-UK
NSA
|
| 2024-02-07 |
CTR: Joint Guidance: Identifying and Mitigating Living Off the Land Techniques
This guide, authored by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), agencies (hereafter referred to as the authoring agencies), provides information on common living off the land (LOTL) techniques and common gaps in cyber defense capabilities. U.S. Department of Energy (DOE) U.S. Environmental Protection Agency (EPA) U.S.
|
CCCS
CISA
DOE
EPA
FBI
NCSC-NZ
NCSC-UK
NSA
TSA
|
| 2024-02-07 |
PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure
For a downloadable copy of indicators of compromise (IOCs), see: MAR-10448362.c1.v2.CLEAR_stix2.json (JSON, 51.
|
CCCS
CISA
DOE
EPA
FBI
NCSC-NZ
NCSC-UK
NIST
NSA
TSA
|
| 2024-02-07 |
PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure
Prioritize patching critical sponsored cyber actors are seeking to prevulnerabilities in appliances known to be position themselves on IT networks for disruptive frequently exploited by Volt Typhoon. or destructive cyberattacks against U.S. critical infrastructure in the event of a major crisis or conflict with the United States.
|
CCCS
CISA
DOE
EPA
FBI
NCSC-NZ
NCSC-UK
NSA
TSA
|
| 2024-01-23 |
CISA Joins ACSC-led Guidance on How to Use AI Systems Securely
The following organizations also collaborated with ACSC on the guidance: Israel National Cyber Directorate (INCD) Japan National Center of Incident Readiness and Strategy for Cybersecurity (NISC) and the Secretariat of Science, Technology and Innovation Policy, Cabinet Office Norway National Cyber Security Centre (NCSC-NO) Sweden National Cybersecurity Center The guidance provides AI systems users with an overview of AI-related threats as well as…
|
CISA
|
| 2024-01-23 |
CSI: Engaging with Artificial Intelligence
The purpose of this publication is to provide organisations with guidance on how to use AI systems securely. The paper summarises some important threats related to AI systems and prompts organisations to consider steps they can take to engage with AI while managing risk.
|
BSI
CCCS
CISA
CSA
FBI
NCSC-NZ
NCSC-UK
NSA
|