CyberzSOC

CISA, FBI, NSA, NCSC, ASD/ACSC & NCSC Cyber Intelligence Feed
‹ June 2025 ›
26 publications — sorted newest first
Date Source Type Title Author
Jun 30, 2025 NSA Alert CISA and Partners Urge Critical Infrastructure to Stay Vigilant in the Current Geopolitical Environment Today, CISA, in collaboration with the Federal Bureau of Investigation (FBI), the Department of Defense Cyber Crime Center (DC3), and the National Security Agency (NSA), released a Fact Sheet urging organizations to remain vigilant against potential targeted cyber operations by Iranian state-sponsored or affiliated threat actors. CISA, DC3, FBI, NSA
Jun 30, 2025 NSA Alert Iranian Cyber Actors May Target Vulnerable U.S. Networks and Entities of Interest critical infrastructure and other U.S. entities by Iranian-affiliated cyber actors. Despite a declared ceasefire and ongoing negotiations towards a permanent solution, Iranian-affiliated cyber actors and hacktivist groups may still conduct malicious cyber activity. CISA, DC3, FBI, NSA
Jun 30, 2025 FBI Alert People's Republic of China Cyberthreat Activity The Cyber Centre previously joined our partners in warning that PRC cyber actors have compromised networks of major global telecommunications providers to conduct a broad and significant cyber espionage campaign. This cyber bulletin aims to raise awareness of the threat posed by PRC cyber threat activity, particularly to Canadian telecommunications organizations, in light of new Salt Typhoon-related compromises of entities in Canada. CCCS, FBI
Jun 27, 2025 FBI Alert Criminals Posing as Legitimate Health Insurers and Fraud Investigators to Commit Health Care Fraud The Federal Bureau of Investigation (FBI) warns the public about criminals impersonating legitimate health insurers and their investigative team members. These criminals are sending emails and text messages to patients and health care providers, disguising them as legitimate communications from trusted health care authorities. FBI
Jun 26, 2025 CISA Alert CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-177-01 Mitsubishi Electric Air Conditioning Systems ICSA-25-177-02 TrendMakers Sight Bulb Pro This product is provided subject to this Notification and this Privacy & Use policy. CISA
Jun 26, 2025 CERT-EU Advisory 2025-022: Severe Vulnerabilities in Citrix Products On 17 June 2025, Citrix released an advisory addressing two high severity vulnerabilities in NetScaler ADC and NetScaler Gateway [1]. [New] On June 25, Citrix released another advisory addressing one high severity vulnerability in NetScaler ADC and NetScaler Gateway [2]. Citrix warns that exploits of CVE-2025-6543 on unmitigated appliances have been observed. It is recommended updating affected assets as soon as possible. CERT-EU
Jun 24, 2025 CISA Alert CISA Releases Eight Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-175-01 Kaleris Navis N4 Terminal Operating System ICSA-25-175-02 Delta Electronics CNCSoft ICSA-25-175-03 Schneider Electric Modicon Controllers ICSA-25-175-04 Schneider Electric EVLink WallBox ICSA-25-175-05 ControlID iDSecure On-Premises ICSA-25-175-06 Parsons AccuWeather Widget ICSA-25-175-07 MICROSENS NMP Web+ ICSA… CISA
Jun 24, 2025 CISA Alert New Guidance Released for Reducing Memory-Related Vulnerabilities Memory safety vulnerabilities pose serious risks to national security and critical infrastructure. Adopting memory safe languages (MSLs) offers the most comprehensive mitigation against this class of vulnerabilities and provides built-in safeguards that enhance security by design. CISA, NSA
Jun 24, 2025 NSA Guidance CSI: Memory Safe Languages: Reducing Vulnerabilities in Modern Software Development In 2022, the National Security Agency (NSA) released a cybersecurity information sheet (CSI), “Software Memory Safety.” [1] In 2023, the Cybersecurity and Infrastructure Security Agency (CISA) published the joint guide, “The Case for Memory Safe Roadmaps,” [2] and in 2024, the White House issued “Back to the Building Blocks: A Path Toward Secure and Measurable Software. CISA, NSA
Jun 18, 2025 CERT-EU Advisory 2025-021: Critical Vulnerability in Veeam Backup & Replication The vulnerability CVE-2025-23121, with a CVSS score of 9.9, is a flaw allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. This vulnerability only impacts domain-joined backup servers. CERT-EU
Jun 17, 2025 CISA Alert CISA Releases Five Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-168-01 Siemens Mendix Studio Pro ICSA-25-168-04 Fuji Electric Smart Editor ICSA-25-168-05 Dover Fueling Solutions ProGauge MagLink LX Consoles ICSA-24-347-10 Siemens SENTRON Powercenter 1000 (Update A) This product is provided subject to this Notification and this Privacy & Use policy. CISA
Jun 12, 2025 CISA Alert CISA Releases Cybersecurity Advisory on SimpleHelp RMM Vulnerability Today, CISA released Cybersecurity Advisory: Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider . This advisory is in response to ransomware actors targeting customers of a utility billing software provider through unpatched vulnerabilities in SimpleHelp Remote Monitoring and Management (RMM). CISA
Jun 12, 2025 CISA Advisory Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider This incident reflects a broader pattern of ransomware actors targeting organizations through unpatched versions of SimpleHelp RMM since January 2025. SimpleHelp versions 5.5.7 and earlier contain several vulnerabilities, including CVE-2024-57727—a path traversal vulnerability.1 Ransomware actors likely leveraged CVE-2024-57727 to access downstream customers’ unpatched SimpleHelp RMM for disruption of services in double extortion compromises. CISA
Jun 12, 2025 CISA Alert CISA Releases Ten Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-162-01 Siemens Tecnomatix Plant Simulation ICSA-25-162-02 Siemens RUGGEDCOM APE1808 ICSA-25-162-03 Siemens SCALANCE and RUGGEDCOM ICSA-25-162-04 Siemens SCALANCE and RUGGEDCOM ICSA-25-162-05 Siemens SIMATIC S7-1500 CPU Family ICSA-25-162-06 Siemens Energy Services ICSA-25-162-07 AVEVA PI Data Archive ICSA-25-162-08 AVE… CISA
Jun 12, 2025 CERT-EU Advisory 2025-020: High Severity Vulnerabilities in Gitlab Products On 11 June 2025, Gitlab released security updates for their products addressing multiple vulnerabilities in Gitlab Community Edition (CE) and Enterprise Edition (EE) [1]. It is recommended updating affected Gitlab installations as soon as possible. The vulnerability CVE-2025-4278, with a CVSS score of 8. CERT-EU
Jun 11, 2025 JPCERT/CC Alert Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB25-57) Vulnerabilities exists in Adobe Acrobat, a PDF file creation and conversion software, and Adobe Acrobat Reader, a PDF file viewing software. As a result, an attacker may execute arbitrary code by convincing a user to open contents leveraging the vulnerability. JPCERT/CC
Jun 11, 2025 JPCERT/CC Alert Microsoft Releases June 2025 Security Updates Microsoft has released June 2025 Security Updates to address the vulnerabilities in their products. Remote attackers leveraging these vulnerabilities may be able to execute arbitrary code. According to Microsoft, among the vulnerabilities, the following vulnerability have been confirmed to be exploited in the wild. JPCERT/CC
Jun 10, 2025 CISA Alert CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-160-01 SinoTrack GPS Receiver ICSA-25-160-02 Hitachi Energy Relion 670, 650, SAM600-IO Series ICSMA-25-160-01 MicroDicom DICOM Viewer ICSA-25-140-11 Assured Telematics Inc (ATI) Fleet Management System (Update A) This product is provided subject to this Notification and this Privacy & Use policy. CISA
Jun 10, 2025 NCSC Guidance New DNS Check service in MyNCSC is being expanded to include more DNS related issues Recently, DNS Check, provided in partnership with GDS (Government Digital Service), was released in MyNCSC. The initial version of DNS Check has now been operational for 2 months, covering only dangling DNS issues. This week we are expanding the scope of the service to cover other DNS related issues, such as Nameserver and Zone Transfer issues. NCSC-UK
Jun 5, 2025 CISA Alert CISA Releases Seven Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-155-01 CyberData 011209 SIP Emergency Intercom ICSA-25-155-02 Hitachi Energy Relion 670, 650 series and SAM600-IO Product ICSA-21-049-02 Mitsubishi Electric FA Engineering Software Products (Update H) ICSA-25-133-02 Hitachi Energy Relion 670/650/SAM600-IO Series (Update A) ICSA-23-068-05 Hitachi Energy Relion 670, 650… CISA
Jun 5, 2025 FBI Alert Home Internet Connected Devices Facilitate Criminal Activity Cyber criminals gain unauthorized access to home networks through compromised IoT devices, such as TV streaming devices, digital projectors, aftermarket vehicle infotainment systems, digital picture frames and other products. Cyber criminals gain unauthorized access to home networks by either configuring the product with malicious software prior to the users purchase or infecting the device as it downloads required applications that contain backd… FBI
Jun 5, 2025 FBI Alert Recent Attacks Highlight Elevated Threat to Israeli and Jewish Communities The Federal Bureau of Investigation (FBI) and the Department of Homeland Security (DHS) are issuing this Public Service Announcement to highlight potential public safety concerns related to ongoing threats to Jewish and Israeli communities. On June 1, 2025, an individual approached several people at a pro-Israel gathering in Boulder, Colorado, and threw two Molotov cocktails at the group, injuring at least nine people. DHS, FBI
Jun 4, 2025 CISA Alert Updated Guidance on Play Ransomware This advisory highlights new tactics, techniques, and procedures used by the Play ransomware group and provides updated indicators of compromise (IOCs) to enhance threat detection. Since June 2022, Playcrypt has targeted diverse businesses and critical infrastructure across North America, South America, and Europe, becoming one of the most active ransomware groups in 2024. CISA
Jun 4, 2025 FBI Alert #StopRansomware: Play Ransomware Tools Leveraged by Play Ransomware Actors AdFind Used to query and retrieve information from Active Directory. Bloodhound Used to query and retrieve information from Active Directory. GMER A software tool intended to be used for detecting and removing rootkits. ASD/ACSC, CISA, FBI
Jun 3, 2025 CISA Alert CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-153-01 Schneider Electric Wiser Home Automation ICSA-25-153-02 Schneider Electric EcoStruxure Power Build Rapsody ICSA-25-153-03 Mitsubishi Electric MELSEC iQ-F Series This product is provided subject to this Notification and this Privacy & Use policy. CISA
Jun 3, 2025 FBI Alert Cybercriminals Defraud Hedera Hashgraph Network Non-Custodial Wallet Users Through Nonfungible Token Airdrops Disguised as Free Rewards The Federal Bureau of Investigation (FBI) is issuing this announcement to inform individuals about cyber criminals defrauding cryptocurrency users through the nonfungible token (NFT) 1 airdrop 2 feature embedded in non-custodial wallets, 3 which is disguised as free rewards or incentives for Hedera Hashgraph network users. The Hedera Hashgraph is the distributed ledger used by Hedera. FBI