CyberzSOC

CISA, FBI, NSA, NCSC, ASD/ACSC & NCSC Cyber Intelligence Feed
‹ March 2026 ›
11 publications — sorted newest first
Date Source Type Title Author
Mar 31, 2026 NCSC Guidance NCSC warns of messaging app targeting The NCSC has issued actions for individuals at risk of targeted attacks against messaging apps. NCSC-UK
Mar 25, 2026 CERT-EU Advisory 2026-004: Critical Vulnerability in SharePoint Exploited On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint [1]. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA’s Known Exploited Vulnerabilities (KEV) catalogue on 18 March 2026 [2]. CERT-EU
Mar 23, 2026 CERT-EU Advisory 2026-003: Multiple Vulnerabilities in Citrix NetScaler and Citrix ADC These vulnerabilities may lead to sensitive information disclosure and user session mix-up under specific configurations. At the time of writing, there is no public evidence of active exploitation. CERT-EU
Mar 20, 2026 CISA Advisory Russian Intelligence Services Target Commercial Messaging Application Accounts CISA and the Federal Bureau of Investigation released a Public Service Announcement (PSA) warning about ongoing phishing campaigns by cyber actors associated with the Russian Intelligence Services targeting commercial messaging applications (CMAs). These campaigns aim to bypass encryption to compromise individual user accounts with targets including current and former U.S. CISA, FBI
Mar 20, 2026 FBI Alert Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targets Specifically, MOIS cyber actors are responsible for using Telegram as a command-and-control (C2) infrastructure to push malware targeting Iranian dissidents, journalists opposed to Iran, and other opposition groups around the world. This malware resulted in intelligence collection, data leaks, and reputational harm against the targeted parties. FBI
Mar 19, 2026 NCSC Guidance How to secure your online meetings Advice for small and medium-sized organisations on choosing, setting up and using online meeting services safely Online meetings rely on digital tools to support collaboration, but they also introduce security risks. This guidance – aimed at small and medium-sized organisations – outlines steps to keep your online meetings secure; to protect sensitive information and reduce the risk of cyber attacks. NCSC-UK
Mar 18, 2026 CISA Alert CISA Urges Endpoint Management System Hardening After Cyberattack Against US Organization Use principles of least privilege when designing administrative roles . Leverage Microsoft Intune’s role-based access control (RBAC) to assign the minimum permissions necessary to each role for completing day-to-day operations—permissions include what actions the role can take, and what users and devices it can apply that action to. CISA
Mar 13, 2026 NSA Guidance CSI: AI ML Supply Chain Risks and Mitigations Supply chain risks and mitigations 2 Artificial intelligence and machine learning Supply chain risks and mitigations Artificial intelligence and machine learning Supply chain risks and mitigations 3 Artificial intelligence (AI) and machine with this, risks outlined in this guidance are learning (ML) systems allow organisations to mapped to the National Institute of Standards improve their efficiency in many areas. ASD/ACSC, CCCS, CSA, NCO,
NCSC-NZ, NCSC-UK, NIS, NSA
Mar 12, 2026 FBI Alert Evading Residential Proxy Networks: Protecting Your Devices from Becoming a Tool for Criminals The Federal Bureau of Investigation (FBI) is publishing this public service announcement (PSA) to raise awareness of residential proxies, the risks they pose, and steps the public can take to safeguard their devices from becoming part of a residential proxy network. FBI
Mar 11, 2026 JPCERT/CC Alert Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-26) Vulnerabilities exists in Adobe Acrobat, a PDF file creation and conversion software, and Adobe Acrobat Reader, a PDF file viewing software. As a result, an attacker may execute arbitrary code by convincing a user to open contents leveraging the vulnerability. JPCERT/CC
Mar 11, 2026 JPCERT/CC Alert Microsoft Releases March 2026 Security Updates Microsoft has released March 2026 Security Updates to address the vulnerabilities in their products. Remote attackers leveraging these vulnerabilities may be able to execute arbitrary code. Please consider applying the security update programs by referring to the information provided by Microsoft. JPCERT/CC