CyberzSOC

CISA, FBI, NSA, NCSC, ASD/ACSC & NCSC Cyber Intelligence Feed
‹ February 2025 ›
21 publications — sorted newest first
Date Source Type Title Author
Feb 28, 2025 FBI Alert Safety Concerns Related to Fraudulent Compounding Practices Associated with Weight Loss Drugs The Federal Bureau of Investigation (FBI) warns the public of noncompliant healthcare providers, to include pharmacies, weight loss clinics, and medical spas, engaging in fraudulent compounding practices by unlawfully misrepresenting compounded weight loss drugs. FBI
Feb 27, 2025 CISA Alert CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-058-01 Schneider Electric Communication Modules for Modicon M580 and Quantum Controllers ICSMA-25-058-01 Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application This product is provided subject to this Notification and this Privacy & Use policy. CISA
Feb 26, 2025 FBI Alert North Korea Responsible for $1.5 Billion Bybit Hack FBI refers to this specific North Korean malicious cyber activity as " TraderTraitor ." TraderTraitor actors are proceeding rapidly and have converted some of the stolen assets to Bitcoin and other virtual assets dispersed across thousands of addresses on multiple blockchains. It is expected these assets will be further laundered and eventually converted to fiat currency. FBI
Feb 25, 2025 CISA Alert CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSMA-25-030-01 Contec Health CMS8000 Patient Monitor (Update A) This product is provided subject to this Notification and this Privacy & Use policy. CISA
Feb 20, 2025 CISA Alert CISA Releases Seven Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-051-01 ABB ASPECT-Enterprise, NEXUS, and MATRIX Series ICSA-25-051-02 ABB FLXEON Controllers ICSA-25-051-04 Siemens SiPass Integrated ICSA-25-051-05 Rapid Response Monitoring My Security Account App ICSA-25-051-06 Elseta Vinci Protocol Analyzer ICSA-24-291-03 Mitsubishi Electric CNC Series (Update A) ICSMA-25-051-01 Me… CISA
Feb 19, 2025 CISA Alert CISA and Partners Release Advisory on Ghost (Cring) Ransomware Today, CISA—in partnership with the Federal Bureau of Investigation (FBI) and Multi-State Information Sharing and Analysis Center (MS-ISAC)—released a joint Cybersecurity Advisory, #StopRansomware: Ghost (Cring) Ransomware . This advisory provides network defenders with indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and detection methods associated with Ghost ransomware activity identified through FBI investigations. CISA, FBI, MS-ISAC
Feb 19, 2025 CISA Advisory #StopRansomware: Ghost (Cring) Ransomware Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Ghost CISA, FBI, MS-ISAC
Feb 19, 2025 FBI Alert #StopRansomware: Ghost (Cring) Ransomware Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Ghost CISA, FBI, MS-ISAC
Feb 18, 2025 CISA Alert CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-191-01 Delta Electronics CNCSoft-G2 (Update A) ICSA-25-035-02 Rockwell Automation GuardLogix 5380 and 5580 (Update A) This product is provided subject to this Notification and this Privacy & Use policy. CISA
Feb 13, 2025 CISA Alert CISA Releases Twenty Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-044-01 Siemens SIMATIC S7-1200 CPU Family ICSA-25-044-02 Siemens SIMATIC ICSA-25-044-05 Siemens SIPROTEC 5 Devices ICSA-25-044-06 Siemens RUGGEDCOM APE1808 Devices ICSA-25-044-07 Siemens Teamcenter ICSA-25-044-08 Siemens OpenV2G ICSA-25-044-09 Siemens SCALANCE W700 ICSA-25-044-10 Siemens Questa and ModelSim ICSA-25-044… CISA
Feb 12, 2025 CISA Alert CISA and FBI Warn of Malicious Cyber Actors Using Buffer Overflow Vulnerabilities to Compromise Software CISA and the Federal Bureau of Investigation (FBI) have released a Secure by Design Alert, Eliminating Buffer Overflow Vulnerabilities , as part of their cooperative Secure by Design Alert series —an ongoing series aimed at advancing industry-wide best practices to eliminate entire classes of vulnerabilities during the design and development phases of the product lifecycle. CISA, FBI
Feb 12, 2025 FBI Alert Secure by Design Alert: Eliminating Buffer Overflow Vulnerabilities The Secure by Design initiative seeks to foster a cultural shift across the technology industry, normalizing the development of the Secure by Design Pledge, and stay informed on the latest Secure by Design Alerts. Buffer overflow vulnerabilities are a prevalent type of memory The software development community has safety software design defect that regularly lead to system compromise. CISA, FBI, NSA
Feb 12, 2025 JPCERT/CC Alert Microsoft Releases February 2025 Security Updates Microsoft has released February 2025 Security Updates to address the vulnerabilities in their products. Remote attackers leveraging these vulnerabilities may be able to execute arbitrary code. According to Microsoft, among the vulnerabilities, the following vulnerabilities have been confirmed to be exploited in the wild. JPCERT/CC
Feb 11, 2025 CISA Alert CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-319-17 2N Access Commander (Update A) ICSA-25-037-04 Trimble Cityworks (Update A) This product is provided subject to this Notification and this Privacy & Use policy. CISA
Feb 7, 2025 CISA Alert Trimble Releases Security Updates to Address a Vulnerability in Cityworks Software CISA
Feb 6, 2025 CISA Alert CISA Releases Six Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-037-01 Schneider Electric EcoStruxure Power Monitoring Expert (PME) ICSA-25-037-02 Schneider Electric EcoStruxure ICSA-25-037-03 ABB Drive Composer ICSA-25-037-04 Trimble Cityworks ICSMA-25-037-01 MicroDicom DICOM Viewer ICSMA-25-037-02 Orthanc Server This product is provided subject to this Notification and this Priva… CISA
Feb 6, 2025 NCSC Guidance Network security fundamentals Networks are fundamental to the operation, security and resilience of many organisations. This guidance provides an introduction to the key topics to consider when designing, maintaining, or using networks that need to be secure and resilient. It will also help you apply the NCSC’s Cyber security design principles to networks. ASD/ACSC, NCSC-UK
Feb 4, 2025 CISA Alert CISA Releases Nine Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-035-01 Western Telematic Inc NPS Series, DSM Series, CPM Series ICSA-25-035-02 Rockwell Automation 1756-L8zS3 and 1756-L3zS3 ICSA-25-035-03 Elber Communications Equipment ICSA-25-035-04 Schneider Electric Modicon M580 PLCs, BMENOR2200H and EVLink Pro AC ICSA-25-035-05 Schneider Electric Web Designer for Modicon ICSA-25… CISA
Feb 4, 2025 CISA Alert CISA Partners with ASD’s ACSC, CCCS, NCSC-UK, and Other International and US Organizations to Release Guidance on Edge Devices CISA—in partnership with international and U.S. organizations—released guidance to help organizations protect their network edge devices and appliances , such as firewalls, routers, virtual private networks (VPN) gateways, Internet of Things (IoT) devices, internet-facing servers, and internet-facing operational technology (OT) systems. ASD/ACSC, CCCS, CISA, NCSC-UK
Feb 4, 2025 NCSC Guidance Guidance on digital forensics and protective monitoring specifications for producers of network devices and appliances This guidance has been developed with contributions from partnering agencies and is included in a series of publications aiming to draw attention to the importance of edge device cyber security measures. It is produced by the UK National Cyber Security Centre (NCSC) in partnership with the Australian Signals Directorate (ASD), US Cybersecurity and Infrastructure Security Agency (CISA), the Canadian Centre for Cyber Security – part of the Communic… ASD/ACSC, CCCS, CISA, FBI,
NCSC-NZ, NCSC-UK
Feb 3, 2025 NSA Guidance CSI: Security Considerations for Edge Devices: Executive Guidance Mitigation strategies for edge Malicious actors are increasingly targeting internet-facing edge devices to gain unauthorised access to networks; therefore, it is vital that organisations prioritise securing edge devices in their environments. Edge devices are critical network components that serve as security boundaries between internal enterprise networks and the internet. ASD/ACSC, CCCS, CISA, FBI,
NCSC-NZ, NCSC-UK, NSA