| Date | Source | Type | Title | Author |
|---|---|---|---|---|
| Mar 31, 2026 | NCSC | Guidance | NCSC warns of messaging app targeting The NCSC has issued actions for individuals at risk of targeted attacks against messaging apps. | NCSC-UK |
| Mar 25, 2026 | CERT-EU | Advisory | 2026-004: Critical Vulnerability in SharePoint Exploited On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint [1]. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA’s Known Exploited Vulnerabilities (KEV) catalogue on 18 March 2026 [2]. | CERT-EU |
| Mar 23, 2026 | CERT-EU | Advisory | 2026-003: Multiple Vulnerabilities in Citrix NetScaler and Citrix ADC These vulnerabilities may lead to sensitive information disclosure and user session mix-up under specific configurations. At the time of writing, there is no public evidence of active exploitation. | CERT-EU |
| Mar 20, 2026 | CISA | Advisory | Russian Intelligence Services Target Commercial Messaging Application Accounts CISA and the Federal Bureau of Investigation released a Public Service Announcement (PSA) warning about ongoing phishing campaigns by cyber actors associated with the Russian Intelligence Services targeting commercial messaging applications (CMAs). These campaigns aim to bypass encryption to compromise individual user accounts with targets including current and former U.S. | CISA, FBI |
| Mar 20, 2026 | FBI | Alert | Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targets Specifically, MOIS cyber actors are responsible for using Telegram as a command-and-control (C2) infrastructure to push malware targeting Iranian dissidents, journalists opposed to Iran, and other opposition groups around the world. This malware resulted in intelligence collection, data leaks, and reputational harm against the targeted parties. | FBI |
| Mar 19, 2026 | NCSC | Guidance | How to secure your online meetings Advice for small and medium-sized organisations on choosing, setting up and using online meeting services safely Online meetings rely on digital tools to support collaboration, but they also introduce security risks. This guidance – aimed at small and medium-sized organisations – outlines steps to keep your online meetings secure; to protect sensitive information and reduce the risk of cyber attacks. | NCSC-UK |
| Mar 18, 2026 | CISA | Alert | CISA Urges Endpoint Management System Hardening After Cyberattack Against US Organization Use principles of least privilege when designing administrative roles . Leverage Microsoft Intune’s role-based access control (RBAC) to assign the minimum permissions necessary to each role for completing day-to-day operations—permissions include what actions the role can take, and what users and devices it can apply that action to. | CISA |
| Mar 13, 2026 | NSA | Guidance | CSI: AI ML Supply Chain Risks and Mitigations Supply chain risks and mitigations 2 Artificial intelligence and machine learning Supply chain risks and mitigations Artificial intelligence and machine learning Supply chain risks and mitigations 3 Artificial intelligence (AI) and machine with this, risks outlined in this guidance are learning (ML) systems allow organisations to mapped to the National Institute of Standards improve their efficiency in many areas. | ASD/ACSC, CCCS, CSA, NCO, NCSC-NZ, NCSC-UK, NIS, NSA |
| Mar 12, 2026 | FBI | Alert | Evading Residential Proxy Networks: Protecting Your Devices from Becoming a Tool for Criminals The Federal Bureau of Investigation (FBI) is publishing this public service announcement (PSA) to raise awareness of residential proxies, the risks they pose, and steps the public can take to safeguard their devices from becoming part of a residential proxy network. | FBI |
| Mar 11, 2026 | JPCERT/CC | Alert | Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-26) Vulnerabilities exists in Adobe Acrobat, a PDF file creation and conversion software, and Adobe Acrobat Reader, a PDF file viewing software. As a result, an attacker may execute arbitrary code by convincing a user to open contents leveraging the vulnerability. | JPCERT/CC |
| Mar 11, 2026 | JPCERT/CC | Alert | Microsoft Releases March 2026 Security Updates Microsoft has released March 2026 Security Updates to address the vulnerabilities in their products. Remote attackers leveraging these vulnerabilities may be able to execute arbitrary code. Please consider applying the security update programs by referring to the information provided by Microsoft. | JPCERT/CC |