Joint Publications
63
All Time
Unique Partners
47
agencies co-sealed with
Most Frequent Partner
CISA
49 joint publications

Co-Sealed With

CISA 49
CCCS 47
NSA 44
FBI 42
NCSC-NZ 37
BSI 14
DC3 12
MIVD 10
AIVD 9
EPA 8
NUKIB 7
Other 109

Partner Frequency — All Time

49
47
NSA
44
FBI
42
37
BSI
14
DC3
12
10
9
EPA
8
7
DOE
7
NCO
6
NIS
6
6
SKW
5
TSA
5
4
4
AW
4
CNI
4
4
4
3
CSA
3
3
2
2
2
2
EC3
2
NPA
2
2
1
1
FDI
1
1
1
ACN
1
AFP
1
BND
1
Joint Publications (63) — All Time
Date Publication Co-Sealers
2026-09-15 Iranian cyber targeting of dissidents, activists and journalists Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect CHOSEN BRICK is a malware family that has been used to target individuals around the world including in the UK, US and the Netherlands from at least 2025. AIVD FBI
2026-09-15 UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists state actors to target dissidents, activists and GCHQ’s National Cyber Security Centre and international partners issue warning over Iranian cyber actors’ spearphishing and spyware campaign ‘CHOSEN BRICK’ malware family used to collect information, including screen captures and messaging history, from UK and allies provide advice to help organisations and individuals at risk detect malicious activity and reduce chances of their devices falling vi… AIVD FBI
2026-09-02 Communicating Under Pressure: Best Practices for Service Providers Service outages impacting IT and operational technology (OT) systems can be damaging and disruptive for customers, network defenders, critical infrastructure owners and operators, and the general public. During incidents that reach or exceed established thresholds, whether caused by malicious activity or a nonmalicious event, service providers must communicate effectively so end users can minimize operational impact. ASD/ACSC CCCS CISA FBI NCSC-NZ
2026-07-23 Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Read our joint advisory on LAUNDRY BEAR's exploitation of Zimbra Collaboration Suite. AISE AISI AIVD ANSSI ASD/ACSC AW CCCS CISA CNI DC3 DCSA DDIS DGSI EFIS FBI FDI MIVD NCIS NCSC-NZ NCSC-SE NSA NUKIB SIS RM SKW SUPO Treasury
2026-07-15 Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers This guidance outlines best practices for suppliers to design and implement a coordinated vulnerability disclosure (CVD) program to effectively and transparently collaborate with security researchers to report and remediate vulnerabilities. CISA NCSC-NL NSA
2026-07-13 Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. ASD/ACSC CCCS CISA FBI NCSC-NZ NSA
2026-06-22 The AI shift in cyber risk: why leaders must act now Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk. As the leaders of the Five Eyes cyber security agencies, we are united in our call to action: the evolving landscape of artificial intelligence (AI) is rapidly transforming cyber risk, and we must act swiftly to remain ahead. ASD/ACSC CCCS CISA NSA
2026-05-12 Software Bill of Materials for AI - Minimum Elements A software bill of materials (SBOM) acts as an “ingredients list” for software that better positions organizations to understand their supply chains and make risk-informed decisions about how to protect their critical systems. The guidance builds on CISA’s previous work with federal and international partners to establish a shared vision for a software bill of materials and provides recommendations on minimum elements that should be included in a… ACN ANSSI BSI CCCS CERT-EU CISA NISC
2026-04-23 Defending Against China-Nexus Covert Networks of Compromised Devices Over the past few years there has been a major shift in the tactics, techniques and procedures (TTPs) used by China-nexus cyber actors, moving away from the use of individually procured infrastructure, and towards the use of externally provisioned, large-scale networks of compromised devices. AIVD ASD/ACSC BSI CCCS CISA DC3 FBI MIVD NCO NCSC-NZ NCSC-SE NSA
2026-04-23 FIRESTARTER Backdoor Malware Analysis Report at a Glance Malware Name FIRESTARTER Original Publication April 23, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) analyzed a sample of FIRESTARTER malware obtained from a forensic investigation. CISA NCSC
2026-04-23 International cyber agencies share fresh advice to defend against China-linked covert networks GCHQ’s National Cyber Security Centre with UK industry and 15 international partners shine light on best protections against methods used by China-linked threat actors. Covert networks, often made up of compromised devices such as smart devices, are being used to disguise the origins and attributions of cyber attacks. AIVD ASD/ACSC BSI CCCS CISA DC3 FBI MIVD NCO NCSC-NZ NCSC-SE NSA
2026-03-13 CSI: AI ML Supply Chain Risks and Mitigations Supply chain risks and mitigations 2 Artificial intelligence and machine learning Supply chain risks and mitigations Artificial intelligence and machine learning Supply chain risks and mitigations 3 Artificial intelligence (AI) and machine with this, risks outlined in this guidance are learning (ML) systems allow organisations to mapped to the National Institute of Standards improve their efficiency in many areas. ASD/ACSC CCCS CSA NCO NCSC-NZ NIS NSA
2026-02-25 CISA and Partners Release Guidance for Ongoing Global Exploitation of Cisco SD-WAN Systems CISA and partners have observed malicious cyber actors targeting and compromising Cisco SD-WAN systems of organizations, globally. These actors have been observed exploiting a previously undisclosed authentication bypass vulnerability, CVE-2026-20127, for initial access before escalating privileges using CVE-2022-20775 and establishing long-term persistence in Cisco SD-WAN systems. ASD/ACSC CCCS CISA NCSC-NZ NSA
2026-02-25 CSA: Exploitation of SD-WAN Appliances Malicious cyber threat actors are targeting Software-Defined Wide Area Networks (SDWANs) of organizations globally. These actors exploited a Cisco Catalyst SD-WAN controller authentication bypass vulnerability, CVE-2026-20127. After exploitation of this vulnerability the malicious actors add a rogue peer, and eventually gain root access to establish long-term persistence in SD-WANs. ASD/ACSC CCCS CISA NCSC-NZ NSA
2026-01-14 Secure Connectivity Principles for Operational Technology (OT) This guidance outlines eight principles to use as a framework to design, secure, and manage connectivity into OT environments. These principles are particularly critical for operators of essential services. CISA
2026-01-14 Secure Connectivity Principles for Operational Technology SSeeccuurree CCoonnnneeccttiivviittyy PPrriinncciipplleess ffoorr OOppeerraattiioonnaall TTeecchhnnoollooggyy ((OOTT)) Operational technology (OT) environments - which have long been centred on safety, uptime, and operational continuity - are now more interconnected than ever. ASD/ACSC BSI CCCS FBI NCSC-NL NCSC-NZ
2025-12-15 Principles for the Secure Integration of Artificial Intelligence in Operational Technology CISA | ASD’s ACSC | NSA AISC | FBI | Cyber Centre | BSI | NCSC-NL | NCSC-NZ | NCSC-UK Introduction ................................................................................................................................................................... 3 Important Terminology ....................................................................................................................................... 3 Scope ................... ASD/ACSC BSI CCCS CISA FBI NCSC-NL NCSC-NZ NSA
2025-12-09 Pro-Russia Hacktivists Conduct Opportunistic Attacks Against U.S. and Global Critical Infrastructure FBI, CISA, National Security Agency (NSA), and the following partners—hereafter referred to as “the authoring organizations”—are releasing this joint advisory on the targeting of critical infrastructure by proRussia hacktivists: The authoring organizations assess pro-Russia hacktivist groups are conducting less sophisticated, lowerimpact attacks against critical infrastructure entities, compared to advanced persistent threat (APT) groups. ASD/ACSC BSI CCCS DC3 DOE EC3 EPA FBI NCSC-NZ NSA NUKIB
2025-12-09 Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure Actions for Operational Technology Owners and Operators to Take Today to Mitigate Cyber Threats Related to Pro-Russia Hacktivists Activity Reduce exposure of operational technology (OT) assets to the public-facing internet. Adopt mature asset management processes, including mapping data flows and access points. Ensure that OT assets are using robust authentication procedures. ASD/ACSC BSI CCCS CISA DC3 DOE EC3 EPA FBI NCSC-NZ NSA NUKIB
2025-11-19 Bulletproof Defense: Mitigating Risks from Bulletproof Hosting Providers This document was developed through the Joint Ransomware Task Force (JRTF), a U.S. interagency body established by Congress in the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) to ensure unity of effort in combating the growing threat of ransomware attacks. ASD/ACSC CCCS CISA DC3 FBI NCSC-NL NCSC-NZ NSA
2025-09-29 Creating and Maintaining a Definitive View of Your Operational Technology (OT) Architecture It is aimed at cyber security professionals working in organisations that deploy or operate OT across greenfield and brownfield deployments. Integrators and device manufactures can also use these principles to ensure their solutions enable effective asset and configuration management. ASD/ACSC BSI CCCS CISA FBI NCSC-NL NCSC-NZ
2025-08-27 Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks. AISE AISI AIVD ASD/ACSC AW BSI CCCS CISA CNI DC3 FBI MIVD NCO NCSC-NZ NSA NUKIB SKW SUPO
2025-08-27 Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System Executive summary People’s Republic of China (PRC) state-sponsored cyber threat actors are targeting networks globally, including, but not limited to, telecommunications, government, transportation, lodging, and military infrastructure networks. AISE AISI AIVD ASD/ACSC AW BSI CCCS CISA CNI DC3 FBI MIVD NCO NCSC-NZ NSA NUKIB SKW SUPO
2025-08-27 CSA: Countering China State Actors Compromise of Networks While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks. AISE AISI AIVD ASD/ACSC AW BSI CCCS CISA CNI DC3 FBI MIVD NCO NCSC-NZ NSA NUKIB SKW SUPO
2025-07-29 Scattered Spider Actions for Organizations to Take Today to Mitigate Malicious Cyber Activity The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Royal (ACSC), Australian Federal Police (AFP), Canadian Centre for Cyber Security (CCCS), and United Kingdom’s National Cyber Security Centre (NCSC-UK)—hereafter referred to as the authoring organizations—are releasing this joint Cybersecurity Advisory in response to recen… AFP ASD/ACSC CCCS CISA FBI
2025-05-22 CSI: AI Data Security: Best Practices for Securing Data Used to Train & Operate AI Systems Joint Cybersecurity Information This Cybersecurity Information Sheet (CSI) provides essential guidance on securing data used in artificial intelligence (AI) and machine learning (ML) systems. It also highlights the importance of data security in ensuring the accuracy and integrity of AI outcomes and outlines potential risks arising from data integrity issues in various stages of AI development and deployment. ASD/ACSC CISA FBI NCSC-NZ NSA
2025-05-22 AI Data Security Joint Cybersecurity Information Best Practices for Securing Data Used to Train & Operate AI Systems This Cybersecurity Information Sheet (CSI) provides essential guidance on securing data used in artificial intelligence (AI) and machine learning (ML) systems. ASD/ACSC CISA FBI NCSC-NZ NSA
2025-05-21 Russian GRU Targeting Western Logistics Entities and Technology Companies Executive Summary This joint cybersecurity advisory (CSA) highlights a Russian state-sponsored cyber campaign targeting Western logistics entities and technology companies. This includes those involved in the coordination, transport, and delivery of foreign assistance to Ukraine. ASD/ACSC CCCS CISA FBI NSA USCC
2025-05-21 Russian GRU Targeting Western Logistics Entities and Technology Companies This joint cybersecurity advisory (CSA) highlights a Russian state-sponsored cyber those involved in the coordination, transport, and delivery of foreign assistance to Ukraine. Since 2022, Western logistics entities and IT companies have faced an elevated risk of targeting by the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (85th GTsSS), military unit 26165—tracked in the cybersecurity community under… ANSSI ASD/ACSC BSI CCCS DC3 DDIS EFIS FBI MIVD NSA NUKIB SKW USCC
2025-04-29 Info Sheet: Selecting a Protective DNS Service (April 2025 Update) Security Infrastructure Cybersecurity Information Selecting a Protective DNS Service The Domain Name System (DNS) is central to the operation of modern networks, translating human-readable domain names into machine-usable Internet Protocol (IP) addresses. DNS makes navigating to a website, sending an email, or making a secure shell connection easier, and is a key component of the Internet's resilience. CISA NSA
2025-04-09 CSA: BADBAZAAR and MOONSHINE: Technical analysis and mitigations BADBAZAAR and MOONSHINE: Technical With support from the UK Cyber League, this advisory has been jointly produced by the National Cyber Security Centre (NCSC UK) and international partners: > The Australian Cyber Security Centre, part of the Australian Signals > The Canadian Centre for Cyber Security, part of the Communications > The German Federal Intelligence Service > The German Federal Office for the Protection of the Constitution > The New Z… ASD/ACSC CCCS FBI NCSC-NZ NSA
2025-04-09 BADBAZAAR and MOONSHINE: Spyware Targeting Uyghur, Taiwanese, and Tibetan Groups and Civil Society Actors This advisory includes two case studies detailing techniques used by malicious cyber actors using spyware known as BADBAZAAR and MOONSHINE to target data on mobile devices including smartphones that could be of interest to the Chinese state. ASD/ACSC CCCS FBI NCSC-NZ NSA
2025-03-24 Info Sheet: Selecting a Protective DNS Service (March 2025 Update) Security Infrastructure Cybersecurity Information Selecting a Protective DNS Service The Domain Name System (DNS) is central to the operation of modern networks, translating human-readable domain names into machine-usable Internet Protocol (IP) addresses. DNS makes navigating to a website, sending an email, or making a secure shell connection easier, and is a key component of the Internet's resilience. CISA NSA
2025-02-06 Network security fundamentals Networks are fundamental to the operation, security and resilience of many organisations. This guidance provides an introduction to the key topics to consider when designing, maintaining, or using networks that need to be secure and resilient. It will also help you apply the NCSC’s Cyber security design principles to networks. ASD/ACSC
2025-02-04 CISA Partners with ASD’s ACSC, CCCS, NCSC-UK, and Other International and US Organizations to Release Guidance on Edge Devices CISA—in partnership with international and U.S. organizations—released guidance to help organizations protect their network edge devices and appliances , such as firewalls, routers, virtual private networks (VPN) gateways, Internet of Things (IoT) devices, internet-facing servers, and internet-facing operational technology (OT) systems. ASD/ACSC CCCS CISA
2025-02-04 Guidance on digital forensics and protective monitoring specifications for producers of network devices and appliances This guidance has been developed with contributions from partnering agencies and is included in a series of publications aiming to draw attention to the importance of edge device cyber security measures. It is produced by the UK National Cyber Security Centre (NCSC) in partnership with the Australian Signals Directorate (ASD), US Cybersecurity and Infrastructure Security Agency (CISA), the Canadian Centre for Cyber Security – part of the Communic… ASD/ACSC CCCS CISA FBI NCSC-NZ
2025-02-03 CSI: Security Considerations for Edge Devices: Executive Guidance Mitigation strategies for edge Malicious actors are increasingly targeting internet-facing edge devices to gain unauthorised access to networks; therefore, it is vital that organisations prioritise securing edge devices in their environments. Edge devices are critical network components that serve as security boundaries between internal enterprise networks and the internet. ASD/ACSC CCCS CISA FBI NCSC-NZ NSA
2025-01-29 CSI: Content Credentials: Strengthening Multimedia Integrity in the Generative AI Era The ability to manipulate media is not new, but the accessibility, speed, and quality of these modifications today, powered by artificial intelligence (AI) and machine learning tools, have reached unprecedented levels and may not be caught by traditional verification methods. ASD/ACSC CCCS NSA
2025-01-28 A method to assess 'forgivable' vs 'unforgivable' vulnerabilities In fact, the number of Common Vulnerabilities and Exposures (CVEs) in commodity technology continues to rise. While there are a number of factors that are driving the increasing numbers, the NCSC expect this trend to continue unless interventions are made. CISA
2025-01-13 Secure by Demand: Priority Considerations for Operational Technology Owners and Operators When Selecting Digital Products Many OT products are not designed and developed with Secure by Design principles1 and commonly have weaknesses, such as weak authentication, known software vulnerabilities, limited logging, insecure default settings and passwords, and insecure legacy protocols. Cyber threat actors can easily exploit these weaknesses across multiple victims to gain access to control systems. ASD/ACSC BSI CCCS CISA EPA FBI NCSC-NL NCSC-NZ NSA TSA
2024-11-12 2023 Top Routinely Exploited Vulnerabilities Summary The following cybersecurity agencies coauthored this joint Cybersecurity Advisory (hereafter collectively referred to as the authoring agencies): United States: The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and National Security Agency (NSA) Australia: Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) Canada: Canadian Centre for Cyber Security (CCCS) New Zeal… ASD/ACSC CCCS CISA NCSC-NZ NIST NSA
2024-10-10 Update on SVR Cyber Operations and Vulnerability Exploitation The Federal Bureau of Investigation (FBI), the The authoring agencies recommend the following mitigations to protect their networks. Mission Force (CNMF), and the United See the Mitigations section for the complete Kingdom’s National Cyber Security Centre (NCSC-UK) are releasing this joint Cybersecurity Advisory (CSA) to highlight the tactics, • Reduce attack surface by disabling techniques, and procedures (TTPs) employed by Internet-accessible s… CNMF FBI NSA
2024-09-26 ASD’s ACSC, CISA, and US and International Partners Release Guidance on Detecting and Mitigating Active Directory Compromises First published: September 2024 This guidance – authored by the Australian Signals Directorate (ASD), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NCSC-NZ), and the United Kingdom’s National Cyber Security Centre (NCSC-UK) – aims to inform organisations about 17 common techniques used to target Active… ASD/ACSC CCCS CISA NCSC-NZ NSA
2024-09-05 Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and  Prioritize routine system updates and remediate known exploited vulnerabilities.  Segment networks to prevent the spread of malicious activity. ASD/ACSC CCCS CISA CNMF FBI MIVD NSA Treasury USCC
2024-09-05 Russian Military Cyber Actors Target US and Global Critical Infrastructure GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and  Prioritize routine system updates and remediate known exploited vulnerabilities.  Segment networks to prevent the spread of malicious activity. ASD/ACSC CCCS CISA CNMF FBI MIVD NIST NSA Treasury USCC
2024-08-21 ASD’s ACSC, CISA, FBI, and NSA, with the support of International Partners Release Best Practices for Event Logging and Threat Detection Logging priorities for enterprise mobility using mobile computing devices 10 Protecting event logs from unauthorised access, modification and deletion 11 This publication defines a baseline for event logging best practices to mitigate cyber threats. AIVD ASD/ACSC CCCS CISA CSA MIVD NCSC-NZ NIS NSA
2024-07-25 North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs The group primarily targets defense, aerospace, nuclear, and engineering entities to obtain sensitive and classified type of activity; number of people affected; type of equipment used for the activity; the name of the submitting company or organization; and a designated point of contact. CISA CNMF DC3 FBI NIS NSA
2024-07-25 North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear Programs Cyber National Mission Force (CNMF)  U.S. Cybersecurity and Infrastructure Security Agency (CISA)  U.S. Department of Defense Cyber Crime Center (DC3)  U.S. National Security Agency (NSA)  Republic of Korea’s National Intelligence Service (NIS)  Republic of Korea’s National Police Agency (NPA)  United Kingdom’s National Cyber Security Centre (NCSC) The RGB 3rd Bureau includes a DPRK (aka North Korean) state-sponsored cyber group known publi… CISA CNMF DC3 FBI NIS NSA
2024-07-08 APT40 Advisory: PRC MSS Tradecraft in Action Background The following Advisory provides a sample of significant case studies of this adversary’s techniques in action This advisory, authored by the Australian Signals against two victim networks. The case studies are Directorate’s Australian Cyber Security Centre consequential for cybersecurity practitioners to identify, (ASD’s ACSC), the United States Cybersecurity and prevent and remediate APT40 intrusions against their Infrastructure Secur… ASD/ACSC CCCS FBI NCSC-NZ NIS NPA NSA
2024-07-08 People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action The advisory draws on the authoring agencies’ shared understanding of the threat as well as ASD’s ACSC incident response investigations. The PRC state-sponsored cyber group has previously targeted organizations in various countries, including Australia and the United States, and the techniques highlighted below are regularly used by other PRC state-sponsored actors globally. ASD/ACSC BND CCCS CISA FBI NCSC-NZ NIS NISC NPA NSA
2024-06-03 DDoS Overview and Response Guide The evolution of DDoS attack techniques and targets has been continuously followed in the past by the specialists ranging from large companies to security expert blogs. However, recently it has caught general attention due to several incidents that might mean a change of paradigm in the way such attacks have been addressed so far. Strategies to mitigate DDoS need to be adopted, and should focus initially on prevention, but eventually on designing multi-layered defense strategies. CERT-EU
2024-05-09 ASD’s ACSC, CISA, and Partners Release Secure by Design Guidance on Choosing Secure and Verifiable Technologies Today, the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), together with CISA, the Canadian Centre for Cyber Security (CCCS), the United Kingdom’s National Cyber Security Centre (NCSC-UK), and the New Zealand National Cyber Security Centre (NCSC-NZ) are releasing the following guidance: Secure by Design Choosing Secure and Verifiable Technologies . ASD/ACSC CCCS CISA NCSC-NZ
2024-05-01 CISA and Partners Release Fact Sheet on Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity This fact sheet provides information and mitigations associated with cyber operations conducted by pro-Russia hacktivists who seek to compromise industrial control systems (ICS) and small-scale operational technology (OT) systems in North American and European critical infrastructure sectors, including Water and Wastewater Systems, Dams, Energy, and Food and Agriculture Sectors. CCCS CISA MS-ISAC USDA
2024-05-01 Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity CCCS CISA DOE EPA FBI MS-ISAC NSA USDA
2024-03-21 PRC State-Sponsored Cyber Activity: Actions for Critical Infrastructure Leaders This fact sheet provides an overview for executive leaders on the urgent risk posed by People’s Republic of China (PRC) state-sponsored cyber actors known as “Volt Typhoon.” CISA—along with the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and other U.S. government and international partners1—released a major advisory on Feb. 7, 2024, in which the U.S. ASD/ACSC CCCS DOE EPA FBI NCSC-NZ NSA TSA Treasury
2024-02-29 CISA and Partners Release Advisory on Threat Actors Exploiting Ivanti Connect Secure and Policy Secure Gateways Vulnerabilities Additionally, the advisory describes two key CISA findings: The Ivanti Integrity Checker Tool is not sufficient to detect compromise due to the ability of threat actors to deceive it, and A cyber threat actor may be able to gain root-level persistence despite the victim having issued factory resets on the Ivanti device. ASD/ACSC CCCS CISA FBI MS-ISAC NCSC-NZ
2024-02-29 Threat Actors Exploit Multiple Vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways CISA and authoring organizations appreciate the cooperation of Volexity, Ivanti, Mandiant and other industry partners in the development of this advisory and ongoing incident response activities. Authoring organizations: Of particular concern, the authoring organizations and industry partners have determined that cyber threat actors are able to deceive Ivanti’s internal and external Integrity Checker Tool (ICT), resulting in a failure to detect c… ASD/ACSC CCCS CISA FBI MS-ISAC NCSC-NZ
2024-02-26 CISA, NCSC-UK, and Partners Release Advisory on Russian SVR Actors Targeting Cloud Infrastructure This advisory provides recent tactics, techniques, and procedures (TTPs) used by Russian Foreign Intelligence Service (SVR) cyber actors—also known as APT29, the Dukes, CozyBear, and NOBELIUM/Midnight Blizzard—to gain initial access into a cloud environment. The authoring agencies encourage network defenders and organizations review the joint advisory for recommended mitigations. CISA NCSC
2024-02-26 SVR Cyber Actors Adapt Tactics for Initial Cloud Access The US National Security Agency (NSA), the US Cybersecurity and Infrastructure Security Agency (CISA), the US the Canadian Centre for Cyber Security (CCCS) and the New Zealand National Cyber Security Centre (NCSC) agree with this attribution and the details This advisory provides an overview of TTPs deployed by the actor to gain initial access into the cloud environment and includes advice to detect and mitigate The NCSC has previously detailed h… ASD/ACSC CCCS CISA CNMF FBI NSA
2024-02-07 CTR: Joint Guidance: Identifying and Mitigating Living Off the Land Techniques This guide, authored by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), agencies (hereafter referred to as the authoring agencies), provides information on common living off the land (LOTL) techniques and common gaps in cyber defense capabilities.  U.S. Department of Energy (DOE)  U.S. Environmental Protection Agency (EPA)  U.S. ASD/ACSC CCCS CISA DOE EPA FBI NCSC-NZ NSA TSA
2024-02-07 PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure For a downloadable copy of indicators of compromise (IOCs), see: MAR-10448362.c1.v2.CLEAR_stix2.json (JSON, 51. ASD/ACSC CCCS CISA DOE EPA FBI NCSC-NZ NIST NSA TSA
2024-02-07 PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure Prioritize patching critical sponsored cyber actors are seeking to prevulnerabilities in appliances known to be position themselves on IT networks for disruptive frequently exploited by Volt Typhoon. or destructive cyberattacks against U.S. critical infrastructure in the event of a major crisis or conflict with the United States. ASD/ACSC CCCS CISA DOE EPA FBI NCSC-NZ NSA TSA
2024-01-23 CSI: Engaging with Artificial Intelligence The purpose of this publication is to provide organisations with guidance on how to use AI systems securely. The paper summarises some important threats related to AI systems and prompts organisations to consider steps they can take to engage with AI while managing risk. ASD/ACSC BSI CCCS CISA CSA FBI NCSC-NZ NSA