|
Mar 28, 2025 |
CISA
|
Analysis Report
|
CISA Releases Malware Analysis Report on RESURGE Malware Associated with Ivanti Connect Secure
CISA released a Malware Analysis Report (MAR) on RESURGE, a novel malware variant exploiting CVE-2025-0282 in Ivanti Connect Secure appliances. RESURGE combines web shell, dropper, backdoor, bootkit, and rootkit capabilities and can persist across factory resets by modifying the appliance integrity checker.
|
CISA |
|
Mar 28, 2025 |
CISA
|
Analysis Report
|
MAR-25993211-r1.v2 Ivanti Connect Secure (RESURGE)
This Malware Analysis Report (MAR-25993211) examines RESURGE malware targeting Ivanti Connect Secure via CVE-2025-0282. RESURGE establishes SSH tunnels for persistent access, harvests credentials, creates rogue administrative accounts, and modifies integrity checks to survive factory resets.
|
CISA |
|
Mar 27, 2025 |
CISA
|
Alert
|
CISA Releases One Industrial Control Systems Advisory
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-037-01 Schneider Electric EcoStruxure Power Monitoring Expert (PME) (Update A) This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |
|
Mar 27, 2025 |
CERT-EU
|
Advisory
|
2025-013: Remote Code Execution Vulnerability in Splunk
The vulnerability CVE-2025-20229, with a CVSS Score of 8.0, stems from missing authorisation checks in the file upload process to the $SPLUNK_HOME/var/run/splunk/apptemp directory. It allows low-privileged users to execute arbitrary code remotely by uploading malicious files to this specific directory on the server.
|
CERT-EU |
|
Mar 25, 2025 |
CISA
|
Alert
|
CISA Releases Four Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-084-02 Rockwell Automation Verve Asset Manager ICSA-25-084-03 Rockwell Automation 440G TLS-Z ICSA-25-084-04 Inaba Denki Sangyo CHOCO TEI WATCHER Mini This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |
|
Mar 25, 2025 |
CERT-EU
|
Advisory
|
2025-012: Critical Vulnerabilities in Kubernetes Ingress-NGINX
The vulnerabilities CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974 can be exploited to gain full cluster access, resulting in a complete compromise of the environment [1,2]. The vulnerabilities affect a widely used component in Kubernetes environments responsible for routing external traffic to internal services.
|
CERT-EU |
|
Mar 24, 2025 |
NSA
|
Advisory
|
Info Sheet: Selecting a Protective DNS Service (March 2025 Update)
Security Infrastructure Cybersecurity Information Selecting a Protective DNS Service The Domain Name System (DNS) is central to the operation of modern networks, translating human-readable domain names into machine-usable Internet Protocol (IP) addresses. DNS makes navigating to a website, sending an email, or making a secure shell connection easier, and is a key component of the Internet's resilience.
|
CISA, NCSC-UK, NSA |
|
Mar 21, 2025 |
FBI
|
Alert
|
Individuals Target Tesla Vehicles and Dealerships Nationwide with Arson, Gunfire, and Vandalism
The Federal Bureau of Investigation (FBI) is informing the public of recent nationwide incidents targeting Tesla electric vehicles (EV), dealerships, storage lots, and charging stations. Since January 2025, incidents targeting Tesla EVs have occurred in at least nine states.
|
FBI |
|
Mar 20, 2025 |
CISA
|
Alert
|
CISA Releases Five Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-079-01 Schneider Electric EcoStruxure™ ICSA-25-079-02 Schneider Electric Enerlin’X IFE and eIFE ICSA-25-079-03 Siemens Simcenter Femap ICSA-25-079-04 SMA Sunny Portal ICSMA-25-079-01 Santesoft Sante DICOM Viewer Pro This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |
|
Mar 20, 2025 |
NCSC
|
Guidance
|
Timelines for migration to post-quantum cryptography
The national migration to post-quantum cryptography (PQC), mitigating the threat from future quantum computers, is a mass technology change that will The NCSC recognises the need both to offer guidance on some of the earlystage migration activities, and to set some indicative timelines that UK industry, government and regulators can follow. In this guidance, the NCSC sets out some key target dates for migration activities.
|
NCSC-UK |
|
Mar 18, 2025 |
CISA
|
Alert
|
Supply Chain Compromise of Third-Party tj-actions/changed-files (CVE-2025-30066) and reviewdog/action-setup@v1 (CVE-2025-30154)
The supply chain compromise allows for information disclosure of secrets including, but not limited to, valid access keys, GitHub Personal Access Tokens (PATs), npm tokens, and private RSA keys. This has been patched in v46.0.1.
|
CISA |
|
Mar 18, 2025 |
CISA
|
Alert
|
CISA Releases Seven Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-077-01 Schneider Electric EcoStruxure Power Automation System User Interface (EPAS-UI) ICSA-25-077-02 Rockwell Automation Lifecycle Services with VMware ICSA-25-077-03 Schneider Electric EcoStruxure Power Automation System ICSA-25-077-04 Schneider Electric EcoStruxure Panel Server ICSA-25-077-05 Schneider Electric ASCO…
|
CISA |
|
Mar 14, 2025 |
CERT-EU
|
Advisory
|
2025-008: High Vulnerabilities in Fortinet Products
It is recommended updating as soon as possible. forgery vulnerability in FortiNDR that may allow a remote unauthenticated attacker to execute unauthorised actions via crafted HTTP GET requests [2]. that may allow a privileged attacker to execute unauthorised code or commands via specially crafted HTTP or HTTPS commands [3].
|
CERT-EU |
|
Mar 14, 2025 |
CERT-EU
|
Advisory
|
2025-009: Critical Vulnerabilities in Windows Remote Desktop Services
Among the critical vulnerabilities are CVE-2025-24035 and CVE-2025-24045, both Remote Code Execution (RCE) vulnerabilities in Windows Remote Desktop Services (RDS). Each vulnerability has been assigned a CVSSv3 score of 8.1 and is rated as critical [1].
|
CERT-EU |
|
Mar 14, 2025 |
CERT-EU
|
Advisory
|
2025-010: Critical Vulnerability in Cisco IOS XR Software
On March 13, 2025, CISCO released an advisory regarding a critical vulnerability identified in It is recommended updating affected assets as soon as possible. The vulnerability CVE-2025-20138, with a CVSS score of 8.8, stems from insufficient input validation in specific CLI (Command Line Interface) commands within the 64-bit version of CiscoIOSXRSoftware.
|
CERT-EU |
|
Mar 14, 2025 |
CERT-EU
|
Advisory
|
2025-011: Critical Vulnerabilities in Gitlab
It is recommended updating affected assets as soon as possible. ThecriticalvulnerabilitiesCVE-2025-25291andCVE-2025-25292affectthe ruby-saml library.
|
CERT-EU |
|
Mar 13, 2025 |
CISA
|
Alert
|
CISA Releases Thirteen Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-072-01 Siemens Teamcenter Visualization and Tecnomatrix Plant Simulation ICSA-25-072-02 Siemens SINEMA Remote Connect Server ICSA-25-072-03 Siemens SIMATIC S7-1500 TM MFP ICSA-25-072-04 Siemens SiPass integrated AC5102/ACC-G2 and ACC-AP ICSA-25-072-05 Siemens SINAMICS S200 ICSA-25-072-06 Siemens SCALANCE LPE9403 ICSA-2…
|
CISA |
|
Mar 12, 2025 |
FBI
|
Alert
|
#StopRansomware: Medusa Ransomware
Finally, the registry is modified to allow Remote Desktop connections: fDenyTSConnections /t REG_DWORD /d 0 /f Mimikatz has also been observed in use for Local Security Authority Subsystem Service (LSASS) dumping [T1003.001] to harvest credentials [TA0006] and aid lateral movement. Medusa actors install and use Rclone to facilitate exfiltration of data to the Medusa C2 servers [T1567.002] used by actors and affiliates.
|
CISA, FBI, MS-ISAC |
|
Mar 12, 2025 |
JPCERT/CC
|
Alert
|
Microsoft Releases March 2025 Security Updates
Microsoft has released March 2025 Security Updates to address the vulnerabilities in their products. Remote attackers leveraging these vulnerabilities may be able to execute arbitrary code. According to Microsoft, among the vulnerabilities, the following vulnerabilities have been confirmed to be exploited in the wild.
|
JPCERT/CC |
|
Mar 12, 2025 |
CISA
|
Advisory
|
#StopRansomware: Medusa Ransomware
CISA, FBI, and MS-ISAC warn that Medusa ransomware has targeted over 300 victims across critical infrastructure sectors since 2021 using a double-extortion model. Operators gain initial access via phishing and unpatched vulnerabilities, then encrypt systems and threaten to leak stolen data unless ransom is paid.
|
CISA, FBI, MS-ISAC |
|
Mar 12, 2025 |
CISA
|
Alert
|
CISA and Partners Release Cybersecurity Advisory on Medusa Ransomware
This advisory provides tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and detection methods associated with known Medusa ransomware activity. Medusa is a ransomware-as-a-service variant used to conduct ransomware attacks; as of December 2024, over 300 victims from critical infrastructure sectors have been impacted.
|
CISA, FBI, MS-ISAC |
|
Mar 12, 2025 |
JPCERT/CC
|
Alert
|
Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB25-14)
Vulnerabilities exists in Adobe Acrobat, a PDF file creation and conversion software, and Adobe Acrobat Reader, a PDF file viewing software. As a result, an attacker may execute arbitrary code by convincing a user to open contents leveraging the vulnerability.
|
JPCERT/CC |
|
Mar 11, 2025 |
NCSC
|
Guidance
|
New DNS Check service now available in MyNCSC
The data involved is a subset (currently limited to Dangling DNS vulnerabilities) of the vulnerability data returned by the basic monitoring undertaken within GDS’s Monitoring and sharing service . DNS Check will be available to organisations responsible for securing UK public sector domains.
|
NCSC-UK |
|
Mar 11, 2025 |
CISA
|
Alert
|
CISA Releases Two Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-070-01 Schneider Electric Uni-Telway Driver ICSA-25-070-02 Optigo Networks Visual BACnet Capture Tool/Optigo Visual Networks Capture Tool This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |
|
Mar 6, 2025 |
CISA
|
Alert
|
CISA Releases Three Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-065-01 Hitachi Energy PCU400 ICSA-25-065-02 Hitachi Energy Relion 670/650/SAM600-IO ICSA-25-037-02 Schneider Electric EcoStruxure (Update A) This product is provided subject to this Notification and this Privacy & Use policy.
|
CISA |
|
Mar 6, 2025 |
CISA
|
Alert
|
FBI Warns of Data Extortion Scam Targeting Corporate Executives
The Federal Bureau of Investigation (FBI) Internet Crime Complaint Center (IC3) has released an alert warning of a scam involving criminal actors masquerading as the “BianLian Group.” The cyber criminals target corporate executives by sending extortion letters threatening to release victims’ sensitive information unless payment is received.
|
CISA, FBI |
|
Mar 6, 2025 |
CERT-EU
|
Advisory
|
2025-007: Critical Vulnerability in Kibana
This flaw could allow an attacker to execute arbitrary code on the server. It is strongly recommended to update vulnerable Kibana instances.
|
CERT-EU |
|
Mar 6, 2025 |
FBI
|
Alert
|
Mail Scam Targeting Corporate Executives Claims Ties to Ransomware
The Federal Bureau of Investigation (FBI) is issuing this announcement to inform businesses of a scam involving letters delivered in the mail from unidentified criminal actors to corporate executives, claiming to have come from a ransomware group. Stamped “Time Sensitive Read Immediately,” the letter claims the “BianLian Group” gained access into the organization’s network and stole thousands of sensitive data files.
|
FBI |
|
Mar 5, 2025 |
FBI
|
Alert
|
Beijing Leveraging Freelance Hackers and Information Security Companies to Compromise Computer Networks Worldwide
The FBI is releasing this public service announcement to highlight that the Chinese government is using formal and informal connections with freelance hackers and information security (InfoSec) companies to compromise computer networks worldwide.
|
FBI |
|
Mar 5, 2025 |
CERT-EU
|
Advisory
|
2025-006: Critical Vulnerabilities in Mattermost
If exploited, these vulnerabilities could allow an authenticated attacker to read any file on the server, or read data directly from the It is recommended to check for potential abuse, and to update vulnerable Mattermost instances. The vulnerability CVE-2025-25279, with a CVSS score of 9.9, arises due to a failure to validate board blocks during import processes.
|
CERT-EU |
|
Mar 5, 2025 |
CERT-EU
|
Advisory
|
2025-005: Several Vulnerabilities in VMware Products
An attacker with access to a virtual machine could escape it to execute code on the host. Thevulnerability CVE-2025-22224,withaCVSSscoreof9.3,isaTOCTOU(Time-of-CheckTimeof-Use) vulnerability that leads to an out-of-bounds write.
|
CERT-EU |
|
Mar 4, 2025 |
CISA
|
Alert
|
CISA Releases Eight Industrial Control Systems Advisories
These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-063-01 Carrier Block Load ICSA-25-063-02 Keysight Ixia Vision Product Family ICSA-25-063-03 Hitachi Energy MACH PS700 ICSA-25-063-04 Hitachi Energy XMC20 ICSA-25-063-05 Hitachi Energy UNEM/ECST ICSA-25-063-06 Delta Electronics CNCSoft-G2 ICSA-25-063-08 Edimax IC-7100 IP Camera This product is provided subject to this N…
|
CISA |