| Date | Source | Type | Title | Author |
|---|---|---|---|---|
| Aug 28, 2025 | CISA | Alert | CISA Releases Nine Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-240-01 Mitsubishi Electric MELSEC iQ-F Series CPU Module ICSA-25-240-02 Mitsubishi Electric MELSEC iQ-F Series CPU Module ICSA-25-240-03 Schneider Electric Saitel DR & Saitel DP Remote Terminal Unit ICSA-25-240-04 Delta Electronics CNCSoft-G2 ICSA-25-240-05 Delta Electronics COMMGR ICSA-25-240-06 GE Vernova CIMPLICITY… | CISA |
| Aug 27, 2025 | NSA | Advisory | Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System Executive summary People’s Republic of China (PRC) state-sponsored cyber threat actors are targeting networks globally, including, but not limited to, telecommunications, government, transportation, lodging, and military infrastructure networks. | AISE, AISI, AIVD, ASD/ACSC, AW, BSI, CCCS, CISA, CNI, DC3, FBI, MIVD, NCO, NCSC-NZ, NCSC-UK, NSA, NUKIB, SKW, SUPO |
| Aug 27, 2025 | NSA | Alert | CISA and Partners Release Joint Advisory on Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage Systems CISA, along with the National Security Agency, Federal Bureau of Investigation, and international partners, released a joint Cybersecurity Advisory on People’s Republic of China (PRC) state-sponsored Advanced Persistent Threat (APT) actors targeting critical infrastructure across sectors and continents to maintain persistent, long-term access to networks. | CISA, FBI, NSA |
| Aug 27, 2025 | NSA | Alert | Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks. | AISE, AISI, AIVD, ASD/ACSC, AW, BSI, CCCS, CISA, CNI, DC3, FBI, MIVD, NCO, NCSC-NZ, NCSC-UK, NSA, NUKIB, SKW, SUPO |
| Aug 27, 2025 | NSA | Advisory | CSA: Countering China State Actors Compromise of Networks While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks. | AISE, AISI, AIVD, ASD/ACSC, AW, BSI, CCCS, CISA, CNI, DC3, FBI, MIVD, NCO, NCSC-NZ, NCSC-UK, NSA, NUKIB, SKW, SUPO |
| Aug 26, 2025 | CISA | Alert | CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-238-01 INVT VT-Designer and HMITool ICSA-25-238-03 Schneider Electric Modicon M340 Controller and Communication Modules ICSA-25-140-03 Danfoss AK-SM 8xxA Series (Update A) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Aug 26, 2025 | CERT-EU | Advisory | 2025-033: Critical Vulnerabilities in Citrix NetScaler Products Citrix warns that exploits of the critical vulnerability, CVE-2025-7775, have been observed on unmitigated It is recommended to update affected assets as soon as possible. The vulnerability CVE-2025-7775, with a CVSS score of 9.2, is due to improper restriction of operations within the bounds of a memory buffer, leading to Remote Code Execution (RCE) and/or Denial of Service [1]. | CERT-EU |
| Aug 22, 2025 | CISA | Alert | CISA Requests Public Comment for Updated Guidance on Software Bill of Materials These updates build on the 2021 version of the National Telecommunications and Information Administration SBOM Minimum Elements to reflect advancements in tooling and implementation. An SBOM serves as a vital inventory of software components, enabling organizations to identify vulnerabilities, manage dependencies, and mitigate risks. | CISA |
| Aug 21, 2025 | CISA | Alert | CISA Releases Three Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-233-01 Mitsubishi Electric Corporation MELSEC iQ-F Series CPU Module ICSA-25-177-01 Mitsubishi Electric Air Conditioning Systems (Update A) ICSMA-25-233-01 FUJIFILM Healthcare Americas Synapse Mobility This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Aug 20, 2025 | FBI | Alert | Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure The Federal Bureau of Investigation (FBI) is warning the public, private sector, and international community of the threat posed to computer networks and critical infrastructure by cyber actors attributed to the Russian Federal Security Service's (FSB) Center 16. | FBI |
| Aug 19, 2025 | CISA | Alert | CISA Releases Four Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-231-01 Siemens Desigo CC Product Family and SENTRON Powermanager ICSA-25-231-02 Siemens Mendix SAML Module ICSA-25-217-02 Tigo Energy Cloud Connect Advanced (Update A) ICSA-25-219-07 EG4 Electronics EG4 Inverters (Update A) This product is provided subject to this Notification and this Privacy & Use policy. | CISA |
| Aug 18, 2025 | CERT-EU | Advisory | 2025-032: Multiple Vulnerabilities in Microsoft Products OnAugust13,2025,MicrosoftreleaseditsAugust2025PatchTuesdayadvisoryaddressing111 security flows in various products among which 16 are rated as critical [1]. It is recommended updating as soon as possible, prioritising public facing and critical assets. Below are listed the notable vulnerabilities among those rated as critical by Microsoft: The vulnerability CVE-2025-50176, with a CVSS score of 7. | CERT-EU |
| Aug 18, 2025 | JPCERT/CC | Alert | [Updated]Alert Regarding Multiple OS Command Injection Vulnerabilities in Trend Micro Multiple Endpoint Security Products for Enterprises On August 6, 2025, Trend Micro has released the information regarding vulnerabilities (CVE-2025-54948, CVE-2025-54987) in the management console of multiple endpoint security products for enterprises. If these vulnerabilities are exploited, an unauthenticated attacker may execute arbitrary code. Trend Micro Incorporated has reported that attacks exploiting CVE-2025-54948 have been observed in the wild. | JPCERT/CC |
| Aug 14, 2025 | CISA | Alert | CISA Releases Thirty-Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-226-01 Siemens SIMATIC RTLS Locating Manager ICSA-25-226-03 Siemens Engineering Platforms ICSA-25-226-04 Siemens Simcenter Femap ICSA-25-226-05 Siemens Wibu CodeMeter Runtime ICSA-25-226-06 Siemens Opcenter Quality ICSA-25-226-07 Siemens Third-Party Components in SINEC OS ICSA-25-226-08 Siemens RUGGEDCOM CROSSBOW Stati… | CISA |
| Aug 13, 2025 | CISA | Alert | CISA and Partners Release Asset Inventory Guidance for Operational Technology Owners and Operators CISA, along with the National Security Agency, the Federal Bureau of Investigation, Environmental Protection Agency, and several international partners, released comprehensive guidance to help operational technology (OT) owners and operators across all critical infrastructure sectors create and maintain OT asset inventories and supplemental taxonomies. | CISA, EPA, FBI, NSA |
| Aug 13, 2025 | FBI | Alert | Fictitious Law Firms Targeting Cryptocurrency Scam Victims Combine Multiple Exploitation Tactics While Offering to Recover Funds This scheme combines a number of exploitation tactics including targeting vulnerable populations, particularly the elderly; exploiting victims' emotional state and financial need to recover funds from a previous scam; and giving victims the sense of safety and security by impersonating or falsely affiliating themselves with multiple government entities. | FBI |
| Aug 13, 2025 | FBI | Guidance | Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators Using these tools helps owners and operators identify which assets in their environment should be secured and protected, and structure their defenses accordingly to reduce the risk a cybersecurity incident poses to the organization’s mission and service continuity. An asset inventory is an organized, regularly updated list of an organization’s systems, hardware, and software. | ASD/ACSC, BSI, CCCS, CISA, DOE, EPA, FBI, NCSC-NL, NCSC-NZ, NSA |
| Aug 13, 2025 | CERT-EU | Advisory | 2025-029: Possible Zero-Day Vulnerability in SonicWall Products A remote attacker could exploit this vulnerability to execute arbitrary code on the affected appliance. It is recommended to disable SSLVPN Services as soon as possible. | CERT-EU |
| Aug 13, 2025 | JPCERT/CC | Alert | Microsoft Releases August 2025 Security Updates Microsoft has released August 2025 Security Updates to address the vulnerabilities in their products. Remote attackers leveraging these vulnerabilities may be able to execute arbitrary code. It is recommended to check the information provided by Microsoft and apply the updates. | JPCERT/CC |
| Aug 12, 2025 | CISA | Alert | CISA Releases Seven Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-224-01 Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share ICSA-25-224-02 Johnson Controls iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR Edge G2 ICSA-25-224-03 Schneider Electric EcoStruxure Power Monitoring Expert ICSA-25-224-04 AVEVA PI Integrator ICSA-24-263-04 MegaSys Computer Technolo… | CISA |
| Aug 8, 2025 | CERT-EU | Advisory | 2025-030: High Severity Vulnerability in Microsoft Exchange The vulnerability tracked as CVE-2025-53786 allows an attacker with administrative access to an on-premises Exchange Server to escalate privileges into the connected Exchange Online environment. The vulnerability can impact the confidentiality, integrity, and availability of affected systems. | CERT-EU |
| Aug 7, 2025 | CISA | Alert | CISA Issues ED 25-02: Mitigate Microsoft Exchange Vulnerability ED 25-02 directs all Federal Civilian Executive Branch (FCEB) agencies with Microsoft Exchange hybrid environments to implement required mitigations by 9:00 AM EDT on Monday, August 11, 2025 . This vulnerability presents significant risk to all organizations operating Microsoft Exchange hybrid-joined configurations that have not yet implemented the April 2025 patch guidance. | CISA |
| Aug 7, 2025 | CISA | Alert | CISA Releases Ten Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-219-01 Delta Electronics DIAView ICSA-25-219-02 Johnson Controls FX80 and FX90 ICSA-25-219-03 Burk Technology ARC Solo ICSA-25-219-04 Rockwell Automation Arena ICSA-25-219-05 Packet Power EMX and EG ICSA-25-219-06 Dreame Technology iOS and Android Mobile Applications ICSA-25-219-07 EG4 Electronics EG4 Inverters ICSA-25… | CISA |
| Aug 6, 2025 | CISA | Alert | Microsoft Releases Guidance on High-Severity Vulnerability (CVE-2025-53786) in Hybrid Exchange Deployments CISA is aware of the newly disclosed high-severity vulnerability, CVE-2025-53786 , that allows a cyber threat actor with administrative access to an on-premise Microsoft Exchange server to escalate privileges by exploiting vulnerable hybrid-joined configurations. This vulnerability, if not addressed, could impact the identity integrity of an organization’s Exchange Online service. | CISA |
| Aug 6, 2025 | CISA | Analysis Report | CISA Releases Malware Analysis Report Associated with Microsoft SharePoint Vulnerabilities CISA released a Malware Analysis Report (MAR) on malware associated with exploitation of Microsoft SharePoint vulnerabilities, including SIGMA detection rules to help defenders identify related malicious activity in their environments. | CISA |
| Aug 6, 2025 | CISA | Analysis Report | MAR-251132.c1.v1 Exploitation of SharePoint Vulnerabilities This Malware Analysis Report (MAR-251132) details malware artifacts and indicators of compromise tied to exploitation of Microsoft SharePoint vulnerabilities, providing STIX-formatted IOCs and file hashes for threat hunting. | CISA |
| Aug 5, 2025 | CISA | Alert | CISA Releases Two Industrial Control Systems Advisories These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-217-01 Mitsubishi Electric Iconics Digital Solutions Multiple Products ICSA-25-217-02 Tigo Energy Cloud Connect Advanced This product is provided subject to this Notification and this Privacy & Use policy. | CISA |