CyberzSOC

CISA, FBI, NSA, NCSC, ASD/ACSC & NCSC Cyber Intelligence Feed
‹ June 2026 ›
15 publications — sorted newest first
Date Source Type Title Author
Jun 26, 2026 FBI Alert Russian Intelligence Services Continue to Target Commercial Messaging Applications This PSA is an update to the March 2026 Russian Intelligence Services Target Commercial Messaging Application Accounts and provides recent tactics, recommended mitigations, and samples of phishing messages. CISA, FBI
Jun 24, 2026 CISA Advisory Using SASE in a Modern TIC 3.0 Solution Using Secure Access Service Edge in Version Date Revision Description Sections/Pages Affected 1.0 June 2026 Initial Release All CISA | DEFEND TODAY. SECURE TOMORROW. ii The Journey to Zero Trust is a series of resources on cybersecurity capabilities and architecture topics in support of organizational adoption of modern zero trust principles. CISA
Jun 22, 2026 NCSC Guidance The AI shift in cyber risk: why leaders must act now Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk. As the leaders of the Five Eyes cyber security agencies, we are united in our call to action: the evolving landscape of artificial intelligence (AI) is rapidly transforming cyber risk, and we must act swiftly to remain ahead. ASD/ACSC, CCCS, CISA, NCSC-UK,
NSA
Jun 18, 2026 CISA Alert CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure CISA is aware of global reports that malicious cyber actors have targeted internet-accessible Fortinet devices across government and private sector organizations using compromised credentials. This activity, referred to as FortiBleed, involves the exposure of leaked credentials associated with approximately 74,000 Fortinet devices, including firewalls and virtual private network (VPN) gateways. CISA
Jun 18, 2026 NCSC Guidance The 'vibe coding spectrum' approach to AI-assisted software development Different code deserves different levels of oversight, so calibrate your approach to ‘vibe coding’ accordingly. By now, most people are familiar with the term ‘vibe coding’; giving an AI agent a high-level prompt and letting it build your application with significant autonomy. You prompt, it codes, you review The NCSC have previously written about the effects this could have on cyber security. NCSC-UK
Jun 18, 2026 NCSC Advisory Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways Credential stuffing is a method where attackers use passwords stolen from one web service to try to access accounts on other services, taking advantage of any reuse of username and password combinations. Organisations using these products should prioritise investigating whether they have been affected and, as soon as possible, follow mitigation advice to help defend against the threat. NCSC-UK
Jun 17, 2026 NCSC Guidance NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK's critical systems Dr Richard Horne highlighted the scale of cyber threats against the UK’s critical infrastructure at RUSI’s Annual Security Three-quarters of cyber attacks impacting organisations within the UK’s critical infrastructure over the past year can be linked back to hostile state actors, the head of the National Cyber Security Centre (NCSC) has revealed. NCSC-UK
Jun 16, 2026 FBI Alert Silent Ransom Group Impersonating It Personnel Through Social Engineering Through phone calls and phishing emails, SRG actors pose as IT support to establish access to victim computers and exfiltrate data, usually through legitimate remote access tools or by sending an individual in-person to the victim company’s location to gain physical access to computers. FBI
Jun 16, 2026 FBI Alert First Vpn Service Used By Ransomware Actors To Compromise Systems The Federal Bureau of Investigation (FBI) is releasing this FLASH to disseminate indicators of compromise (IOCs) and identified tactics, techniques, and procedures (TTPs) associated with the First VPN Service. The service has been active since approximately 2014 and currently provides 32 exit node servers in 27 countries. FBI
Jun 10, 2026 CERT-EU Advisory 2026-008: Critical vulnerabilities in Ivanti Sentry An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device. The vulnerability CVE-2026-10520, with a CVSS score of 10, is an OS Command Injection vulnerability in Ivanti Sentry which allows a remote unauthenticated user to achieve root-level The vulnerability CVE-2026-10523, with a CVSS score of 9. CERT-EU
Jun 10, 2026 CERT-EU Advisory 2026-007: Critical Vulnerability in Windows Netlogon This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (CCB), this vulnerability is currently exploited by threat actors [2]. CERT-EU
Jun 10, 2026 JPCERT/CC Alert Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-63) Vulnerabilities exist in Adobe Acrobat, a PDF file creation and conversion software, and Adobe Acrobat Reader, a PDF file viewing software. As a result, an attacker may execute arbitrary code by convincing a user to open contents leveraging the vulnerability. JPCERT/CC
Jun 10, 2026 JPCERT/CC Alert Microsoft Releases June 2026 Security Updates Microsoft has released June 2026 Security Updates to address the vulnerabilities in their products. Attackers leveraging these vulnerabilities may be able to execute arbitrary code remotely without authentication, etc. Microsoft has announced that the following vulnerability, disclosed on May 14, has been exploited in the wild. JPCERT/CC
Jun 4, 2026 NCSC Guidance Software supply chain attacks: check your dependencies Attackers are compromising open source packages to spread malware. Cyber defenders are asked to review Modern software development has transformed how software is created, shared and reused – but recent attacks on these tools highlight the rapidly growing risks of using modern software ecosystems. Attackers are compromising open source packages at scale to spread malware in ways that can be difficult to detect and can do extensive damage. NCSC-UK
Jun 2, 2026 CISA Advisory CISA and Partners Urge Hardening Automatic Tank Gauge Systems The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the (EPA), the Transportation Security Administration (TSA), the Department of Transportation (DOT), and the U.S. Department of Agriculture (USDA)—hereafter referred to as “the authoring organizations”—are aware of malicious cyber activity targeting U.S.-based automatic tank gauge (ATG) systems. CISA, DOE, EPA, FBI,
NSA, TSA, USDA