Joint Publications
20
All Time
Unique Partners
40
agencies co-sealed with
Most Frequent Partner
FBI
20 joint publications

Co-Sealed With

FBI 20
CISA 18
NSA 15
NCSC-UK 12
CCCS 10
BSI 8
MIVD 7
NUKIB 7
AIVD 6
SKW 5
Other 62

Partner Frequency — All Time

FBI
20
18
NSA
15
12
10
BSI
8
7
7
6
SKW
5
NCO
5
4
4
AW
4
CNI
4
4
EC3
4
2
2
2
DOE
2
EPA
2
HHS
2
2
NIS
2
1
1
1
1
FDI
1
1
1
1
CSA
1
1
Joint Publications (20) — All Time
Date Publication Co-Sealers
2026-08-10 #StopRansomware: Gunra Ransomware Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. CISA FBI KNPA NSA USSS
2026-07-23 Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Read our joint advisory on LAUNDRY BEAR's exploitation of Zimbra Collaboration Suite. AISE AISI AIVD ANSSI ASD/ACSC AW CCCS CISA CNI DCSA DDIS DGSI EFIS FBI FDI MIVD NCIS NCSC-NZ NCSC-SE NCSC-UK NSA NUKIB SIS RM SKW SUPO Treasury
2026-04-23 Defending Against China-Nexus Covert Networks of Compromised Devices Over the past few years there has been a major shift in the tactics, techniques and procedures (TTPs) used by China-nexus cyber actors, moving away from the use of individually procured infrastructure, and towards the use of externally provisioned, large-scale networks of compromised devices. AIVD ASD/ACSC BSI CCCS CISA FBI MIVD NCO NCSC-NZ NCSC-SE NCSC-UK NSA
2026-04-23 International cyber agencies share fresh advice to defend against China-linked covert networks GCHQ’s National Cyber Security Centre with UK industry and 15 international partners shine light on best protections against methods used by China-linked threat actors. Covert networks, often made up of compromised devices such as smart devices, are being used to disguise the origins and attributions of cyber attacks. AIVD ASD/ACSC BSI CCCS CISA FBI MIVD NCO NCSC-NZ NCSC-SE NCSC-UK NSA
2025-12-09 Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure Actions for Operational Technology Owners and Operators to Take Today to Mitigate Cyber Threats Related to Pro-Russia Hacktivists Activity Reduce exposure of operational technology (OT) assets to the public-facing internet. Adopt mature asset management processes, including mapping data flows and access points. Ensure that OT assets are using robust authentication procedures. ASD/ACSC BSI CCCS CISA DOE EC3 EPA FBI NCSC-NZ NCSC-UK NSA NUKIB
2025-12-09 Pro-Russia Hacktivists Conduct Opportunistic Attacks Against U.S. and Global Critical Infrastructure FBI, CISA, National Security Agency (NSA), and the following partners—hereafter referred to as “the authoring organizations”—are releasing this joint advisory on the targeting of critical infrastructure by proRussia hacktivists: The authoring organizations assess pro-Russia hacktivist groups are conducting less sophisticated, lowerimpact attacks against critical infrastructure entities, compared to advanced persistent threat (APT) groups. ASD/ACSC BSI CCCS DOE EC3 EPA FBI NCSC-NZ NCSC-UK NSA NUKIB
2025-11-19 Bulletproof Defense: Mitigating Risks from Bulletproof Hosting Providers This document was developed through the Joint Ransomware Task Force (JRTF), a U.S. interagency body established by Congress in the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) to ensure unity of effort in combating the growing threat of ransomware attacks. ASD/ACSC CCCS CISA FBI NCSC-NL NCSC-NZ NCSC-UK NSA
2025-11-13 #StopRansomware: Akira Ransomware #StopRansomware: Akira Ransomware Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Akira  Prioritize remediating known exploited vulnerabilities.  Enable and enforce phishing-resistant multifactor authentication (MFA). CISA EC3 FBI HHS NCSC-NL
2025-08-27 Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System Executive summary People’s Republic of China (PRC) state-sponsored cyber threat actors are targeting networks globally, including, but not limited to, telecommunications, government, transportation, lodging, and military infrastructure networks. AISE AISI AIVD ASD/ACSC AW BSI CCCS CISA CNI FBI MIVD NCO NCSC-NZ NCSC-UK NSA NUKIB SKW SUPO
2025-08-27 Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks. AISE AISI AIVD ASD/ACSC AW BSI CCCS CISA CNI FBI MIVD NCO NCSC-NZ NCSC-UK NSA NUKIB SKW SUPO
2025-08-27 CSA: Countering China State Actors Compromise of Networks While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks. AISE AISI AIVD ASD/ACSC AW BSI CCCS CISA CNI FBI MIVD NCO NCSC-NZ NCSC-UK NSA NUKIB SKW SUPO
2025-06-30 CISA and Partners Urge Critical Infrastructure to Stay Vigilant in the Current Geopolitical Environment Today, CISA, in collaboration with the Federal Bureau of Investigation (FBI), the Department of Defense Cyber Crime Center (DC3), and the National Security Agency (NSA), released a Fact Sheet urging organizations to remain vigilant against potential targeted cyber operations by Iranian state-sponsored or affiliated threat actors. CISA FBI NSA
2025-06-30 Iranian Cyber Actors May Target Vulnerable U.S. Networks and Entities of Interest critical infrastructure and other U.S. entities by Iranian-affiliated cyber actors. Despite a declared ceasefire and ongoing negotiations towards a permanent solution, Iranian-affiliated cyber actors and hacktivist groups may still conduct malicious cyber activity. CISA FBI NSA
2025-05-21 Russian GRU Targeting Western Logistics Entities and Technology Companies This joint cybersecurity advisory (CSA) highlights a Russian state-sponsored cyber those involved in the coordination, transport, and delivery of foreign assistance to Ukraine. Since 2022, Western logistics entities and IT companies have faced an elevated risk of targeting by the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (85th GTsSS), military unit 26165—tracked in the cybersecurity community under… ANSSI ASD/ACSC BSI CCCS DDIS EFIS FBI MIVD NCSC-UK NSA NUKIB SKW USCC
2024-08-28 CISA and Partners Release Advisory on Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations Organizations . This joint advisory warns of cyber actors, known in the private sector as Pioneer Kitten, UNC757, Parisite, Rubidium, and Lemon Sandstorm, targeting and exploiting U.S. and foreign organizations across multiple sectors in the U.S. CISA FBI
2024-08-28 Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations The FBI assesses a significant percentage of these threat actors’ operations against US organizations are intended to obtain and develop network access to then collaborate with ransomware affiliate actors to deploy ransomware. The FBI further assesses these Iran-based cyber actors are associated with the Government of Iran (GOI) and—separate from the ransomware activity—conduct computer network exploitation activity in support of the GOI (such as… CISA CSA FBI
2024-08-28 Iran-Based Cyber Actors Enabling Ransomware Attacks on U.S. Organizations The FBI assesses a significant percentage of these threat actors’ operations against US organizations are intended to obtain and develop network access to then collaborate with ransomware affiliate actors to deploy ransomware. The FBI further assesses these Iran-based cyber actors are associated with the Government of Iran (GOI) and—separate from the ransomware activity—conduct computer network exploitation activity in support of the GOI (such as… CISA FBI
2024-07-25 North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear Programs Cyber National Mission Force (CNMF)  U.S. Cybersecurity and Infrastructure Security Agency (CISA)  U.S. Department of Defense Cyber Crime Center (DC3)  U.S. National Security Agency (NSA)  Republic of Korea’s National Intelligence Service (NIS)  Republic of Korea’s National Police Agency (NPA)  United Kingdom’s National Cyber Security Centre (NCSC) The RGB 3rd Bureau includes a DPRK (aka North Korean) state-sponsored cyber group known publi… CISA CNMF FBI NCSC-UK NIS NSA
2024-07-25 North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs The group primarily targets defense, aerospace, nuclear, and engineering entities to obtain sensitive and classified type of activity; number of people affected; type of equipment used for the activity; the name of the submitting company or organization; and a designated point of contact. CISA CNMF FBI NCSC-UK NIS NSA
2024-04-18 #StopRansomware: Akira Ransomware #StopRansomware: Akira Ransomware Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Akira  Prioritize remediating known exploited vulnerabilities.  Enable and enforce phishing-resistant multifactor authentication (MFA). CISA EC3 FBI HHS NCSC-NL OFAC