| 2026-08-10 |
#StopRansomware: Gunra Ransomware
Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid.
|
CISA
FBI
KNPA
NSA
USSS
|
| 2026-07-23 |
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Read our joint advisory on LAUNDRY BEAR's exploitation of Zimbra Collaboration Suite.
|
AISE
AISI
AIVD
ANSSI
ASD/ACSC
AW
CCCS
CISA
CNI
DCSA
DDIS
DGSI
EFIS
FBI
FDI
MIVD
NCIS
NCSC-NZ
NCSC-SE
NCSC-UK
NSA
NUKIB
SIS RM
SKW
SUPO
Treasury
|
| 2026-04-23 |
Defending Against China-Nexus Covert Networks of Compromised Devices
Over the past few years there has been a major shift in the tactics, techniques and procedures (TTPs) used by China-nexus cyber actors, moving away from the use of individually procured infrastructure, and towards the use of externally provisioned, large-scale networks of compromised devices.
|
AIVD
ASD/ACSC
BSI
CCCS
CISA
FBI
MIVD
NCO
NCSC-NZ
NCSC-SE
NCSC-UK
NSA
|
| 2026-04-23 |
International cyber agencies share fresh advice to defend against China-linked covert networks
GCHQ’s National Cyber Security Centre with UK industry and 15 international partners shine light on best protections against methods used by China-linked threat actors. Covert networks, often made up of compromised devices such as smart devices, are being used to disguise the origins and attributions of cyber attacks.
|
AIVD
ASD/ACSC
BSI
CCCS
CISA
FBI
MIVD
NCO
NCSC-NZ
NCSC-SE
NCSC-UK
NSA
|
| 2025-12-09 |
Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure
Actions for Operational Technology Owners and Operators to Take Today to Mitigate Cyber Threats Related to Pro-Russia Hacktivists Activity Reduce exposure of operational technology (OT) assets to the public-facing internet. Adopt mature asset management processes, including mapping data flows and access points. Ensure that OT assets are using robust authentication procedures.
|
ASD/ACSC
BSI
CCCS
CISA
DOE
EC3
EPA
FBI
NCSC-NZ
NCSC-UK
NSA
NUKIB
|
| 2025-12-09 |
Pro-Russia Hacktivists Conduct Opportunistic Attacks Against U.S. and Global Critical Infrastructure
FBI, CISA, National Security Agency (NSA), and the following partners—hereafter referred to as “the authoring organizations”—are releasing this joint advisory on the targeting of critical infrastructure by proRussia hacktivists: The authoring organizations assess pro-Russia hacktivist groups are conducting less sophisticated, lowerimpact attacks against critical infrastructure entities, compared to advanced persistent threat (APT) groups.
|
ASD/ACSC
BSI
CCCS
DOE
EC3
EPA
FBI
NCSC-NZ
NCSC-UK
NSA
NUKIB
|
| 2025-11-19 |
Bulletproof Defense: Mitigating Risks from Bulletproof Hosting Providers
This document was developed through the Joint Ransomware Task Force (JRTF), a U.S. interagency body established by Congress in the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) to ensure unity of effort in combating the growing threat of ransomware attacks.
|
ASD/ACSC
CCCS
CISA
FBI
NCSC-NL
NCSC-NZ
NCSC-UK
NSA
|
| 2025-11-13 |
#StopRansomware: Akira Ransomware
#StopRansomware: Akira Ransomware Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Akira Prioritize remediating known exploited vulnerabilities. Enable and enforce phishing-resistant multifactor authentication (MFA).
|
CISA
EC3
FBI
HHS
NCSC-NL
|
| 2025-08-27 |
Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System
Executive summary People’s Republic of China (PRC) state-sponsored cyber threat actors are targeting networks globally, including, but not limited to, telecommunications, government, transportation, lodging, and military infrastructure networks.
|
AISE
AISI
AIVD
ASD/ACSC
AW
BSI
CCCS
CISA
CNI
FBI
MIVD
NCO
NCSC-NZ
NCSC-UK
NSA
NUKIB
SKW
SUPO
|
| 2025-08-27 |
Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System
While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks.
|
AISE
AISI
AIVD
ASD/ACSC
AW
BSI
CCCS
CISA
CNI
FBI
MIVD
NCO
NCSC-NZ
NCSC-UK
NSA
NUKIB
SKW
SUPO
|
| 2025-08-27 |
CSA: Countering China State Actors Compromise of Networks
While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks.
|
AISE
AISI
AIVD
ASD/ACSC
AW
BSI
CCCS
CISA
CNI
FBI
MIVD
NCO
NCSC-NZ
NCSC-UK
NSA
NUKIB
SKW
SUPO
|
| 2025-06-30 |
CISA and Partners Urge Critical Infrastructure to Stay Vigilant in the Current Geopolitical Environment
Today, CISA, in collaboration with the Federal Bureau of Investigation (FBI), the Department of Defense Cyber Crime Center (DC3), and the National Security Agency (NSA), released a Fact Sheet urging organizations to remain vigilant against potential targeted cyber operations by Iranian state-sponsored or affiliated threat actors.
|
CISA
FBI
NSA
|
| 2025-06-30 |
Iranian Cyber Actors May Target Vulnerable U.S. Networks and Entities of Interest
critical infrastructure and other U.S. entities by Iranian-affiliated cyber actors. Despite a declared ceasefire and ongoing negotiations towards a permanent solution, Iranian-affiliated cyber actors and hacktivist groups may still conduct malicious cyber activity.
|
CISA
FBI
NSA
|
| 2025-05-21 |
Russian GRU Targeting Western Logistics Entities and Technology Companies
This joint cybersecurity advisory (CSA) highlights a Russian state-sponsored cyber those involved in the coordination, transport, and delivery of foreign assistance to Ukraine. Since 2022, Western logistics entities and IT companies have faced an elevated risk of targeting by the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (85th GTsSS), military unit 26165—tracked in the cybersecurity community under…
|
ANSSI
ASD/ACSC
BSI
CCCS
DDIS
EFIS
FBI
MIVD
NCSC-UK
NSA
NUKIB
SKW
USCC
|
| 2024-08-28 |
CISA and Partners Release Advisory on Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations
Organizations . This joint advisory warns of cyber actors, known in the private sector as Pioneer Kitten, UNC757, Parisite, Rubidium, and Lemon Sandstorm, targeting and exploiting U.S. and foreign organizations across multiple sectors in the U.S.
|
CISA
FBI
|
| 2024-08-28 |
Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations
The FBI assesses a significant percentage of these threat actors’ operations against US organizations are intended to obtain and develop network access to then collaborate with ransomware affiliate actors to deploy ransomware. The FBI further assesses these Iran-based cyber actors are associated with the Government of Iran (GOI) and—separate from the ransomware activity—conduct computer network exploitation activity in support of the GOI (such as…
|
CISA
CSA
FBI
|
| 2024-08-28 |
Iran-Based Cyber Actors Enabling Ransomware Attacks on U.S. Organizations
The FBI assesses a significant percentage of these threat actors’ operations against US organizations are intended to obtain and develop network access to then collaborate with ransomware affiliate actors to deploy ransomware. The FBI further assesses these Iran-based cyber actors are associated with the Government of Iran (GOI) and—separate from the ransomware activity—conduct computer network exploitation activity in support of the GOI (such as…
|
CISA
FBI
|
| 2024-07-25 |
North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear Programs
Cyber National Mission Force (CNMF) U.S. Cybersecurity and Infrastructure Security Agency (CISA) U.S. Department of Defense Cyber Crime Center (DC3) U.S. National Security Agency (NSA) Republic of Korea’s National Intelligence Service (NIS) Republic of Korea’s National Police Agency (NPA) United Kingdom’s National Cyber Security Centre (NCSC) The RGB 3rd Bureau includes a DPRK (aka North Korean) state-sponsored cyber group known publi…
|
CISA
CNMF
FBI
NCSC-UK
NIS
NSA
|
| 2024-07-25 |
North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs
The group primarily targets defense, aerospace, nuclear, and engineering entities to obtain sensitive and classified type of activity; number of people affected; type of equipment used for the activity; the name of the submitting company or organization; and a designated point of contact.
|
CISA
CNMF
FBI
NCSC-UK
NIS
NSA
|
| 2024-04-18 |
#StopRansomware: Akira Ransomware
#StopRansomware: Akira Ransomware Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Akira Prioritize remediating known exploited vulnerabilities. Enable and enforce phishing-resistant multifactor authentication (MFA).
|
CISA
EC3
FBI
HHS
NCSC-NL
OFAC
|